diff --git a/advisories/github-reviewed/2022/04/GHSA-28r6-jm5h-mrgg/GHSA-28r6-jm5h-mrgg.json b/advisories/github-reviewed/2022/04/GHSA-28r6-jm5h-mrgg/GHSA-28r6-jm5h-mrgg.json index 90c550d2385..d41821c5e6e 100644 --- a/advisories/github-reviewed/2022/04/GHSA-28r6-jm5h-mrgg/GHSA-28r6-jm5h-mrgg.json +++ b/advisories/github-reviewed/2022/04/GHSA-28r6-jm5h-mrgg/GHSA-28r6-jm5h-mrgg.json @@ -8,9 +8,7 @@ ], "summary": "Access control bypass in Beego", "details": "An issue was discovered in the route lookup process in beego through 2.0.1, allows attackers to bypass access control.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -74,9 +72,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2022-04-07T18:13:46Z", diff --git a/advisories/github-reviewed/2022/04/GHSA-7944-h5rw-qmjx/GHSA-7944-h5rw-qmjx.json b/advisories/github-reviewed/2022/04/GHSA-7944-h5rw-qmjx/GHSA-7944-h5rw-qmjx.json index fb57de9dec1..d573e0e7c3f 100644 --- a/advisories/github-reviewed/2022/04/GHSA-7944-h5rw-qmjx/GHSA-7944-h5rw-qmjx.json +++ b/advisories/github-reviewed/2022/04/GHSA-7944-h5rw-qmjx/GHSA-7944-h5rw-qmjx.json @@ -8,9 +8,7 @@ ], "summary": "ZCatalog plug-in for Zope allows anonymous users to bypass access restrictions", "details": "ZCatalog plug-in index support capability for Zope 2.4.0 through 2.5.1 allows anonymous users and untrusted code to bypass access restrictions and call arbitrary methods of catalog indexes.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -62,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2024-02-12T20:33:00Z", diff --git a/advisories/github-reviewed/2022/04/GHSA-c3rp-4cjh-cp38/GHSA-c3rp-4cjh-cp38.json b/advisories/github-reviewed/2022/04/GHSA-c3rp-4cjh-cp38/GHSA-c3rp-4cjh-cp38.json index 764525a3216..60b1e517be3 100644 --- a/advisories/github-reviewed/2022/04/GHSA-c3rp-4cjh-cp38/GHSA-c3rp-4cjh-cp38.json +++ b/advisories/github-reviewed/2022/04/GHSA-c3rp-4cjh-cp38/GHSA-c3rp-4cjh-cp38.json @@ -8,9 +8,7 @@ ], "summary": "Zope does not properly verify the access for objects with proxy roles", "details": "Zope 2.2.0 through 2.5.1 does not properly verify the access for objects with proxy roles, which could allow some users to access documents in violation of the intended configuration.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2022/04/GHSA-pqr5-9v2j-44xg/GHSA-pqr5-9v2j-44xg.json b/advisories/github-reviewed/2022/04/GHSA-pqr5-9v2j-44xg/GHSA-pqr5-9v2j-44xg.json index c569306ddf2..f2093987a94 100644 --- a/advisories/github-reviewed/2022/04/GHSA-pqr5-9v2j-44xg/GHSA-pqr5-9v2j-44xg.json +++ b/advisories/github-reviewed/2022/04/GHSA-pqr5-9v2j-44xg/GHSA-pqr5-9v2j-44xg.json @@ -8,9 +8,7 @@ ], "summary": "Apache Tomcat DoS via Malicious Get Request", "details": "Tomcat 4.0 through 4.1.12, using mod_jk 1.2.1 module on Apache 1.3 through 1.3.27, allows remote attackers to cause a denial of service (desynchronized communications) via an HTTP GET request with a Transfer-Encoding chunked field with invalid values.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2022/04/GHSA-vwrc-g9q6-f675/GHSA-vwrc-g9q6-f675.json b/advisories/github-reviewed/2022/04/GHSA-vwrc-g9q6-f675/GHSA-vwrc-g9q6-f675.json index f5a2c5d485e..e0456006dbb 100644 --- a/advisories/github-reviewed/2022/04/GHSA-vwrc-g9q6-f675/GHSA-vwrc-g9q6-f675.json +++ b/advisories/github-reviewed/2022/04/GHSA-vwrc-g9q6-f675/GHSA-vwrc-g9q6-f675.json @@ -8,9 +8,7 @@ ], "summary": "Zope Server vulnerable to DoS via header injection", "details": "Zope is a Web application server for Linux. Zope versions 2.0 through 2.5.1 b1 are vulnerable to a denial of service attack, caused by a vulnerability that occurs when using the \"through the Web code\" capability. A remote attacker could inject malicious headers into a response to cause the vulnerable system to crash.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2022/04/GHSA-xmf4-j3j7-xj7q/GHSA-xmf4-j3j7-xj7q.json b/advisories/github-reviewed/2022/04/GHSA-xmf4-j3j7-xj7q/GHSA-xmf4-j3j7-xj7q.json index 71809476a36..7098764d5be 100644 --- a/advisories/github-reviewed/2022/04/GHSA-xmf4-j3j7-xj7q/GHSA-xmf4-j3j7-xj7q.json +++ b/advisories/github-reviewed/2022/04/GHSA-xmf4-j3j7-xj7q/GHSA-xmf4-j3j7-xj7q.json @@ -8,9 +8,7 @@ ], "summary": "Apache Tomcat DoS Via Requests Including Null Characters", "details": "Apache Tomcat 4.0.3, and possibly other versions before 4.1.3 beta, allows remote attackers to cause a denial of service (resource exhaustion) via a large number of requests to the server with null characters, which causes the working threads to hang.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2022/05/GHSA-5hcx-vg88-hgpm/GHSA-5hcx-vg88-hgpm.json b/advisories/github-reviewed/2022/05/GHSA-5hcx-vg88-hgpm/GHSA-5hcx-vg88-hgpm.json index fdc62914494..87f06ee949a 100644 --- a/advisories/github-reviewed/2022/05/GHSA-5hcx-vg88-hgpm/GHSA-5hcx-vg88-hgpm.json +++ b/advisories/github-reviewed/2022/05/GHSA-5hcx-vg88-hgpm/GHSA-5hcx-vg88-hgpm.json @@ -92,9 +92,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2023-08-01T22:58:28Z", diff --git a/advisories/github-reviewed/2022/05/GHSA-6qh6-v99h-vh4c/GHSA-6qh6-v99h-vh4c.json b/advisories/github-reviewed/2022/05/GHSA-6qh6-v99h-vh4c/GHSA-6qh6-v99h-vh4c.json index bf429e5573f..199028a4963 100644 --- a/advisories/github-reviewed/2022/05/GHSA-6qh6-v99h-vh4c/GHSA-6qh6-v99h-vh4c.json +++ b/advisories/github-reviewed/2022/05/GHSA-6qh6-v99h-vh4c/GHSA-6qh6-v99h-vh4c.json @@ -149,9 +149,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2023-07-17T21:47:48Z", diff --git a/advisories/github-reviewed/2022/05/GHSA-8hmh-mhqv-7638/GHSA-8hmh-mhqv-7638.json b/advisories/github-reviewed/2022/05/GHSA-8hmh-mhqv-7638/GHSA-8hmh-mhqv-7638.json index d37dcb2069a..fbc884df8b5 100644 --- a/advisories/github-reviewed/2022/05/GHSA-8hmh-mhqv-7638/GHSA-8hmh-mhqv-7638.json +++ b/advisories/github-reviewed/2022/05/GHSA-8hmh-mhqv-7638/GHSA-8hmh-mhqv-7638.json @@ -9,9 +9,7 @@ ], "summary": "PartialBufferOutputStream2 flush issues", "details": "### Withdrawn\nThis advisory has been withdrawn as there the effects of the bug would only give the caller an incomplete view of data which they would be authorized to see.\n\n### Original Advisory\nPartialBufferOutputStream2 in GeoServer before 1.6.1 and 1.7.0-beta1 attempts to flush buffer contents even when it is handling an \"in memory buffer,\" which prevents the reporting of a service exception, with unknown impact and attack vectors.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2022/05/GHSA-c5vw-342h-x5rx/GHSA-c5vw-342h-x5rx.json b/advisories/github-reviewed/2022/05/GHSA-c5vw-342h-x5rx/GHSA-c5vw-342h-x5rx.json index edcec962f99..1eb43eecc0d 100644 --- a/advisories/github-reviewed/2022/05/GHSA-c5vw-342h-x5rx/GHSA-c5vw-342h-x5rx.json +++ b/advisories/github-reviewed/2022/05/GHSA-c5vw-342h-x5rx/GHSA-c5vw-342h-x5rx.json @@ -8,9 +8,7 @@ ], "summary": "Alkacon OpenCms Exposes JSP Source Code", "details": "`system/workplace/editors/editor.jsp` in Alkacon OpenCms before 6.2.2 allows remote authenticated users to read the source code of arbitrary JSP files by specifying the file in the resource parameter, as demonstrated using `index.jsp`.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2022/05/GHSA-h5jm-jjgx-q2wf/GHSA-h5jm-jjgx-q2wf.json b/advisories/github-reviewed/2022/05/GHSA-h5jm-jjgx-q2wf/GHSA-h5jm-jjgx-q2wf.json index 369b2c51347..0054df5b652 100644 --- a/advisories/github-reviewed/2022/05/GHSA-h5jm-jjgx-q2wf/GHSA-h5jm-jjgx-q2wf.json +++ b/advisories/github-reviewed/2022/05/GHSA-h5jm-jjgx-q2wf/GHSA-h5jm-jjgx-q2wf.json @@ -8,9 +8,7 @@ ], "summary": "XWiki Remote Code Execution", "details": "PreviewAction in XWiki 0.9.543 through 0.9.1252 does not set the Author field to the identity of the user who last modified a document, which allows remote authenticated users without programming rights to execute arbitrary code by selecting a document whose author has programming rights, modifying this document to contain a script, and previewing without saving the document.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -54,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2024-02-12T17:00:03Z", diff --git a/advisories/github-reviewed/2022/05/GHSA-h9w8-4376-j344/GHSA-h9w8-4376-j344.json b/advisories/github-reviewed/2022/05/GHSA-h9w8-4376-j344/GHSA-h9w8-4376-j344.json index 376dbeb5250..76d4916164d 100644 --- a/advisories/github-reviewed/2022/05/GHSA-h9w8-4376-j344/GHSA-h9w8-4376-j344.json +++ b/advisories/github-reviewed/2022/05/GHSA-h9w8-4376-j344/GHSA-h9w8-4376-j344.json @@ -8,9 +8,7 @@ ], "summary": "Moodle does not properly validate module instance id", "details": "Moodle before 1.6.2 does not properly validate the module instance id when creating a course module object, which has unspecified impact and remote attack vectors.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2022/05/GHSA-jcwh-rj6j-vm75/GHSA-jcwh-rj6j-vm75.json b/advisories/github-reviewed/2022/05/GHSA-jcwh-rj6j-vm75/GHSA-jcwh-rj6j-vm75.json index 67079d990ea..4df436d623b 100644 --- a/advisories/github-reviewed/2022/05/GHSA-jcwh-rj6j-vm75/GHSA-jcwh-rj6j-vm75.json +++ b/advisories/github-reviewed/2022/05/GHSA-jcwh-rj6j-vm75/GHSA-jcwh-rj6j-vm75.json @@ -8,9 +8,7 @@ ], "summary": "Plone allows remote users to modify arbitrary portraits", "details": "Plone 2.0.5, 2.1.2, and 2.5-beta1 does not restrict access to the (1) changeMemberPortrait, (2) deletePersonalPortrait, and (3) testCurrentPassword methods, which allows remote attackers to modify portraits.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -90,9 +88,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2024-02-12T16:10:44Z", diff --git a/advisories/github-reviewed/2022/05/GHSA-jg2x-r643-w2ch/GHSA-jg2x-r643-w2ch.json b/advisories/github-reviewed/2022/05/GHSA-jg2x-r643-w2ch/GHSA-jg2x-r643-w2ch.json index 77f9d751f70..2aa4112288e 100644 --- a/advisories/github-reviewed/2022/05/GHSA-jg2x-r643-w2ch/GHSA-jg2x-r643-w2ch.json +++ b/advisories/github-reviewed/2022/05/GHSA-jg2x-r643-w2ch/GHSA-jg2x-r643-w2ch.json @@ -8,9 +8,7 @@ ], "summary": "Jetty Uses Predictable Session Identifiers", "details": "Jetty before 4.2.27, 5.1 before 5.1.12, 6.0 before 6.0.2, and 6.1 before 6.1.0pre3 generates predictable session identifiers using java.util.random, which makes it easier for remote attackers to guess a session identifier through brute force attacks, bypass authentication requirements, and possibly conduct cross-site request forgery attacks.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2022/05/GHSA-jpqr-vh55-xqxf/GHSA-jpqr-vh55-xqxf.json b/advisories/github-reviewed/2022/05/GHSA-jpqr-vh55-xqxf/GHSA-jpqr-vh55-xqxf.json index 6fc8039cc1b..c6fcca19d8c 100644 --- a/advisories/github-reviewed/2022/05/GHSA-jpqr-vh55-xqxf/GHSA-jpqr-vh55-xqxf.json +++ b/advisories/github-reviewed/2022/05/GHSA-jpqr-vh55-xqxf/GHSA-jpqr-vh55-xqxf.json @@ -8,9 +8,7 @@ ], "summary": "Apache Tomcat Buffer Over-Read", "details": "The AJP connector in Apache Tomcat 5.5.15 uses an incorrect length for chunks, which can cause a buffer over-read in the `ajp_process_callback` in mod_jk, which allows remote attackers to read portions of sensitive memory.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2022/05/GHSA-mw5w-cf76-73m8/GHSA-mw5w-cf76-73m8.json b/advisories/github-reviewed/2022/05/GHSA-mw5w-cf76-73m8/GHSA-mw5w-cf76-73m8.json index 5278e480293..0ae25fcf068 100644 --- a/advisories/github-reviewed/2022/05/GHSA-mw5w-cf76-73m8/GHSA-mw5w-cf76-73m8.json +++ b/advisories/github-reviewed/2022/05/GHSA-mw5w-cf76-73m8/GHSA-mw5w-cf76-73m8.json @@ -92,9 +92,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2023-07-17T20:36:37Z", diff --git a/advisories/github-reviewed/2022/05/GHSA-p57v-p3fx-qgwm/GHSA-p57v-p3fx-qgwm.json b/advisories/github-reviewed/2022/05/GHSA-p57v-p3fx-qgwm/GHSA-p57v-p3fx-qgwm.json index f91b5d352d3..8a184220d38 100644 --- a/advisories/github-reviewed/2022/05/GHSA-p57v-p3fx-qgwm/GHSA-p57v-p3fx-qgwm.json +++ b/advisories/github-reviewed/2022/05/GHSA-p57v-p3fx-qgwm/GHSA-p57v-p3fx-qgwm.json @@ -8,9 +8,7 @@ ], "summary": "Apache Tomcat XSS Vulnerability", "details": "Cross-site scripting (XSS) vulnerability in implicit-objects.jsp in Apache Tomcat 5.0.0 through 5.0.30 and 5.5.0 through 5.5.17 allows remote attackers to inject arbitrary web script or HTML via certain header values.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2022/05/GHSA-p783-gj6m-9r88/GHSA-p783-gj6m-9r88.json b/advisories/github-reviewed/2022/05/GHSA-p783-gj6m-9r88/GHSA-p783-gj6m-9r88.json index 84bb5fbd2e3..006d6fd4818 100644 --- a/advisories/github-reviewed/2022/05/GHSA-p783-gj6m-9r88/GHSA-p783-gj6m-9r88.json +++ b/advisories/github-reviewed/2022/05/GHSA-p783-gj6m-9r88/GHSA-p783-gj6m-9r88.json @@ -77,9 +77,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2023-07-18T20:00:48Z", diff --git a/advisories/github-reviewed/2022/05/GHSA-qmgj-5h75-jr67/GHSA-qmgj-5h75-jr67.json b/advisories/github-reviewed/2022/05/GHSA-qmgj-5h75-jr67/GHSA-qmgj-5h75-jr67.json index 92665cc5307..b94d07d3629 100644 --- a/advisories/github-reviewed/2022/05/GHSA-qmgj-5h75-jr67/GHSA-qmgj-5h75-jr67.json +++ b/advisories/github-reviewed/2022/05/GHSA-qmgj-5h75-jr67/GHSA-qmgj-5h75-jr67.json @@ -8,9 +8,7 @@ ], "summary": "Jetty Directory Traversal Vulnerability", "details": "Directory traversal vulnerability in jetty 6.0.x (jetty6) beta16 allows remote attackers to read arbitrary files via a `%2e%2e%5c` (encoded `../`) in the URL. NOTE: this might be the same issue as CVE-2005-3747.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2022/05/GHSA-v7cq-pq7v-mh5v/GHSA-v7cq-pq7v-mh5v.json b/advisories/github-reviewed/2022/05/GHSA-v7cq-pq7v-mh5v/GHSA-v7cq-pq7v-mh5v.json index 0f565673129..021c078e392 100644 --- a/advisories/github-reviewed/2022/05/GHSA-v7cq-pq7v-mh5v/GHSA-v7cq-pq7v-mh5v.json +++ b/advisories/github-reviewed/2022/05/GHSA-v7cq-pq7v-mh5v/GHSA-v7cq-pq7v-mh5v.json @@ -8,9 +8,7 @@ ], "summary": "Apache Derby SQL Injection", "details": "Apache Derby before 10.2.1.6 does not determine schema privilege requirements during the DropSchemaNode bind phase, which allows remote authenticated users to execute arbitrary drop schema statements in SQL authorization mode.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2022/05/GHSA-xcvr-qv8h-m7xw/GHSA-xcvr-qv8h-m7xw.json b/advisories/github-reviewed/2022/05/GHSA-xcvr-qv8h-m7xw/GHSA-xcvr-qv8h-m7xw.json index 22ffc75c6a3..528e6049186 100644 --- a/advisories/github-reviewed/2022/05/GHSA-xcvr-qv8h-m7xw/GHSA-xcvr-qv8h-m7xw.json +++ b/advisories/github-reviewed/2022/05/GHSA-xcvr-qv8h-m7xw/GHSA-xcvr-qv8h-m7xw.json @@ -100,9 +100,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2022-10-25T17:35:35Z", diff --git a/advisories/github-reviewed/2022/06/GHSA-23f2-vgr6-fwv7/GHSA-23f2-vgr6-fwv7.json b/advisories/github-reviewed/2022/06/GHSA-23f2-vgr6-fwv7/GHSA-23f2-vgr6-fwv7.json index ddeda66e966..dc3e3351cd7 100644 --- a/advisories/github-reviewed/2022/06/GHSA-23f2-vgr6-fwv7/GHSA-23f2-vgr6-fwv7.json +++ b/advisories/github-reviewed/2022/06/GHSA-23f2-vgr6-fwv7/GHSA-23f2-vgr6-fwv7.json @@ -8,9 +8,7 @@ ], "summary": "Command injection in librenms", "details": "LibreNMS v22.3.0 was discovered to contain multiple command injection vulnerabilities via the service_ip, hostname, and service_param parameters.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2022/06/GHSA-cv76-rv4h-4mqc/GHSA-cv76-rv4h-4mqc.json b/advisories/github-reviewed/2022/06/GHSA-cv76-rv4h-4mqc/GHSA-cv76-rv4h-4mqc.json index c705266e46c..f79ca74ee0e 100644 --- a/advisories/github-reviewed/2022/06/GHSA-cv76-rv4h-4mqc/GHSA-cv76-rv4h-4mqc.json +++ b/advisories/github-reviewed/2022/06/GHSA-cv76-rv4h-4mqc/GHSA-cv76-rv4h-4mqc.json @@ -8,9 +8,7 @@ ], "summary": "OS Command Injection in proctree", "details": "OS Command Injection vulnerability in allenhwkim proctree through 0.1.1 and commit 0ac10ae575459457838f14e21d5996f2fa5c7593 for Node.js, allows attackers to execute arbitrary commands via the fix function.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2024/07/GHSA-c8m8-j448-xjx7/GHSA-c8m8-j448-xjx7.json b/advisories/github-reviewed/2024/07/GHSA-c8m8-j448-xjx7/GHSA-c8m8-j448-xjx7.json index c0440fa03dc..3cf2f681eaf 100644 --- a/advisories/github-reviewed/2024/07/GHSA-c8m8-j448-xjx7/GHSA-c8m8-j448-xjx7.json +++ b/advisories/github-reviewed/2024/07/GHSA-c8m8-j448-xjx7/GHSA-c8m8-j448-xjx7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c8m8-j448-xjx7", - "modified": "2024-07-29T16:33:11Z", + "modified": "2024-11-18T16:26:56Z", "published": "2024-07-29T16:33:11Z", "aliases": [ "CVE-2024-41671" @@ -68,7 +68,7 @@ "cwe_ids": [ "CWE-444" ], - "severity": "HIGH", + "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2024-07-29T16:33:11Z", "nvd_published_at": "2024-07-29T15:15:15Z" diff --git a/advisories/github-reviewed/2024/08/GHSA-9m5j-4xx9-44j9/GHSA-9m5j-4xx9-44j9.json b/advisories/github-reviewed/2024/08/GHSA-9m5j-4xx9-44j9/GHSA-9m5j-4xx9-44j9.json index 27dda3302a9..7a854fb9aba 100644 --- a/advisories/github-reviewed/2024/08/GHSA-9m5j-4xx9-44j9/GHSA-9m5j-4xx9-44j9.json +++ b/advisories/github-reviewed/2024/08/GHSA-9m5j-4xx9-44j9/GHSA-9m5j-4xx9-44j9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9m5j-4xx9-44j9", - "modified": "2024-09-18T21:30:44Z", + "modified": "2024-11-18T16:27:01Z", "published": "2024-08-07T18:30:44Z", "aliases": [ "CVE-2024-7143" @@ -69,7 +69,7 @@ "cwe_ids": [ "CWE-277" ], - "severity": "MODERATE", + "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2024-08-07T19:45:30Z", "nvd_published_at": "2024-08-07T17:15:52Z" diff --git a/advisories/unreviewed/2022/03/GHSA-64vf-2ppg-3mgq/GHSA-64vf-2ppg-3mgq.json b/advisories/unreviewed/2022/03/GHSA-64vf-2ppg-3mgq/GHSA-64vf-2ppg-3mgq.json index d1a02f1116e..fbd9b297865 100644 --- a/advisories/unreviewed/2022/03/GHSA-64vf-2ppg-3mgq/GHSA-64vf-2ppg-3mgq.json +++ b/advisories/unreviewed/2022/03/GHSA-64vf-2ppg-3mgq/GHSA-64vf-2ppg-3mgq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/03/GHSA-8m4h-fj8c-v497/GHSA-8m4h-fj8c-v497.json b/advisories/unreviewed/2022/03/GHSA-8m4h-fj8c-v497/GHSA-8m4h-fj8c-v497.json index 53915859165..df6683d33ad 100644 --- a/advisories/unreviewed/2022/03/GHSA-8m4h-fj8c-v497/GHSA-8m4h-fj8c-v497.json +++ b/advisories/unreviewed/2022/03/GHSA-8m4h-fj8c-v497/GHSA-8m4h-fj8c-v497.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/03/GHSA-jxp3-gh83-p8qh/GHSA-jxp3-gh83-p8qh.json b/advisories/unreviewed/2022/03/GHSA-jxp3-gh83-p8qh/GHSA-jxp3-gh83-p8qh.json index ba17bf11b4a..6102499cfe8 100644 --- a/advisories/unreviewed/2022/03/GHSA-jxp3-gh83-p8qh/GHSA-jxp3-gh83-p8qh.json +++ b/advisories/unreviewed/2022/03/GHSA-jxp3-gh83-p8qh/GHSA-jxp3-gh83-p8qh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/03/GHSA-v457-62x9-vgw8/GHSA-v457-62x9-vgw8.json b/advisories/unreviewed/2022/03/GHSA-v457-62x9-vgw8/GHSA-v457-62x9-vgw8.json index e5ede39ea9f..2274bc130f9 100644 --- a/advisories/unreviewed/2022/03/GHSA-v457-62x9-vgw8/GHSA-v457-62x9-vgw8.json +++ b/advisories/unreviewed/2022/03/GHSA-v457-62x9-vgw8/GHSA-v457-62x9-vgw8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-3hc9-68hw-8q6p/GHSA-3hc9-68hw-8q6p.json b/advisories/unreviewed/2022/04/GHSA-3hc9-68hw-8q6p/GHSA-3hc9-68hw-8q6p.json index f63b707328f..c055f4de00a 100644 --- a/advisories/unreviewed/2022/04/GHSA-3hc9-68hw-8q6p/GHSA-3hc9-68hw-8q6p.json +++ b/advisories/unreviewed/2022/04/GHSA-3hc9-68hw-8q6p/GHSA-3hc9-68hw-8q6p.json @@ -7,12 +7,8 @@ "CVE-2002-1777" ], "details": "** DISPUTED ** NOTE: this issue has been disputed by the vendor. Symantec Norton AntiVirus (NAV) 2002 allows remote attackers to bypass e-mail scanning via a filename in the Content-Type field with an excluded extension such as .nch or .dbx, but a malicious extension in the Content-Disposition field, which is used by Outlook to obtain the file name. NOTE: the vendor has disputed this issue, acknowledging that the initial scan is bypassed, but Norton AntiVirus or the Office plug-in would detect the virus before it is executed.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-42w8-jq8g-mg7m/GHSA-42w8-jq8g-mg7m.json b/advisories/unreviewed/2022/04/GHSA-42w8-jq8g-mg7m/GHSA-42w8-jq8g-mg7m.json index 883a167cb05..4a48b5ecb2a 100644 --- a/advisories/unreviewed/2022/04/GHSA-42w8-jq8g-mg7m/GHSA-42w8-jq8g-mg7m.json +++ b/advisories/unreviewed/2022/04/GHSA-42w8-jq8g-mg7m/GHSA-42w8-jq8g-mg7m.json @@ -7,12 +7,8 @@ "CVE-2001-0667" ], "details": "Internet Explorer 6 and earlier, when used with the Telnet client in Services for Unix (SFU) 2.0, allows remote attackers to execute commands by spawning Telnet with a log file option on the command line and writing arbitrary code into an executable file which is later executed, aka a new variant of the Telnet Invocation vulnerability as described in CVE-2001-0150.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-4jjr-44rf-xh3q/GHSA-4jjr-44rf-xh3q.json b/advisories/unreviewed/2022/04/GHSA-4jjr-44rf-xh3q/GHSA-4jjr-44rf-xh3q.json index be889489c32..ec8957faaee 100644 --- a/advisories/unreviewed/2022/04/GHSA-4jjr-44rf-xh3q/GHSA-4jjr-44rf-xh3q.json +++ b/advisories/unreviewed/2022/04/GHSA-4jjr-44rf-xh3q/GHSA-4jjr-44rf-xh3q.json @@ -7,12 +7,8 @@ "CVE-2003-0377" ], "details": "SQL injection vulnerability in the web-based administration interface for iisPROTECT 2.2-r4, and possibly earlier versions, allows remote attackers to insert arbitrary SQL and execute code via certain variables, as demonstrated using the GroupName variable in SiteAdmin.ASP.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-4q24-rv9c-m9wm/GHSA-4q24-rv9c-m9wm.json b/advisories/unreviewed/2022/04/GHSA-4q24-rv9c-m9wm/GHSA-4q24-rv9c-m9wm.json index d080fb6be64..2d95777106e 100644 --- a/advisories/unreviewed/2022/04/GHSA-4q24-rv9c-m9wm/GHSA-4q24-rv9c-m9wm.json +++ b/advisories/unreviewed/2022/04/GHSA-4q24-rv9c-m9wm/GHSA-4q24-rv9c-m9wm.json @@ -7,12 +7,8 @@ "CVE-2003-1201" ], "details": "ldbm_back_exop_passwd in the back-ldbm backend in passwd.c for OpenLDAP 2.1.12 and earlier, when the slap_passwd_parse function does not return LDAP_SUCCESS, attempts to free an uninitialized pointer, which allows remote attackers to cause a denial of service (segmentation fault).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-67w6-36rp-6g7c/GHSA-67w6-36rp-6g7c.json b/advisories/unreviewed/2022/04/GHSA-67w6-36rp-6g7c/GHSA-67w6-36rp-6g7c.json index e41b70787e7..5cb1f3893c4 100644 --- a/advisories/unreviewed/2022/04/GHSA-67w6-36rp-6g7c/GHSA-67w6-36rp-6g7c.json +++ b/advisories/unreviewed/2022/04/GHSA-67w6-36rp-6g7c/GHSA-67w6-36rp-6g7c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-6v23-8229-rc5j/GHSA-6v23-8229-rc5j.json b/advisories/unreviewed/2022/04/GHSA-6v23-8229-rc5j/GHSA-6v23-8229-rc5j.json index 2c92f89cfbc..8aa60243380 100644 --- a/advisories/unreviewed/2022/04/GHSA-6v23-8229-rc5j/GHSA-6v23-8229-rc5j.json +++ b/advisories/unreviewed/2022/04/GHSA-6v23-8229-rc5j/GHSA-6v23-8229-rc5j.json @@ -7,12 +7,8 @@ "CVE-2004-1428" ], "details": "ArGoSoft FTP before 1.4.2.1 generates an error message if the user name does not exist instead of prompting for a password, which allows remote attackers to determine valid usernames.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-88qv-6q9j-fhvv/GHSA-88qv-6q9j-fhvv.json b/advisories/unreviewed/2022/04/GHSA-88qv-6q9j-fhvv/GHSA-88qv-6q9j-fhvv.json index 1375dd3d7e4..058cfa69e83 100644 --- a/advisories/unreviewed/2022/04/GHSA-88qv-6q9j-fhvv/GHSA-88qv-6q9j-fhvv.json +++ b/advisories/unreviewed/2022/04/GHSA-88qv-6q9j-fhvv/GHSA-88qv-6q9j-fhvv.json @@ -7,12 +7,8 @@ "CVE-2004-0121" ], "details": "Argument injection vulnerability in Microsoft Outlook 2002 does not sufficiently filter parameters of mailto: URLs when using them as arguments when calling OUTLOOK.EXE, which allows remote attackers to use script code in the Local Machine zone and execute arbitrary programs.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-98rg-95r3-8mjw/GHSA-98rg-95r3-8mjw.json b/advisories/unreviewed/2022/04/GHSA-98rg-95r3-8mjw/GHSA-98rg-95r3-8mjw.json index 2de9c10c39a..be1ec0c830c 100644 --- a/advisories/unreviewed/2022/04/GHSA-98rg-95r3-8mjw/GHSA-98rg-95r3-8mjw.json +++ b/advisories/unreviewed/2022/04/GHSA-98rg-95r3-8mjw/GHSA-98rg-95r3-8mjw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-9h96-28m7-7h3g/GHSA-9h96-28m7-7h3g.json b/advisories/unreviewed/2022/04/GHSA-9h96-28m7-7h3g/GHSA-9h96-28m7-7h3g.json index 829cbff66e4..c427ef8816f 100644 --- a/advisories/unreviewed/2022/04/GHSA-9h96-28m7-7h3g/GHSA-9h96-28m7-7h3g.json +++ b/advisories/unreviewed/2022/04/GHSA-9h96-28m7-7h3g/GHSA-9h96-28m7-7h3g.json @@ -7,12 +7,8 @@ "CVE-2003-0907" ], "details": "Help and Support Center in Microsoft Windows XP SP1 does not properly validate HCP URLs, which allows remote attackers to execute arbitrary code via quotation marks in an hcp:// URL, which are not quoted when constructing the argument list to HelpCtr.exe.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-c7vv-qr7x-g477/GHSA-c7vv-qr7x-g477.json b/advisories/unreviewed/2022/04/GHSA-c7vv-qr7x-g477/GHSA-c7vv-qr7x-g477.json index 0d91a1a025e..7007b216369 100644 --- a/advisories/unreviewed/2022/04/GHSA-c7vv-qr7x-g477/GHSA-c7vv-qr7x-g477.json +++ b/advisories/unreviewed/2022/04/GHSA-c7vv-qr7x-g477/GHSA-c7vv-qr7x-g477.json @@ -7,12 +7,8 @@ "CVE-2004-2252" ], "details": "The firewall in Astaro Security Linux before 4.024 sends responses to SYN-FIN packets, which makes it easier for remote attackers to obtain information about the system and construct specialized attacks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-f465-339w-2vhm/GHSA-f465-339w-2vhm.json b/advisories/unreviewed/2022/04/GHSA-f465-339w-2vhm/GHSA-f465-339w-2vhm.json index 259c5aab084..c42ac9e8031 100644 --- a/advisories/unreviewed/2022/04/GHSA-f465-339w-2vhm/GHSA-f465-339w-2vhm.json +++ b/advisories/unreviewed/2022/04/GHSA-f465-339w-2vhm/GHSA-f465-339w-2vhm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-gv89-cmj2-j2r6/GHSA-gv89-cmj2-j2r6.json b/advisories/unreviewed/2022/04/GHSA-gv89-cmj2-j2r6/GHSA-gv89-cmj2-j2r6.json index 9e490e9578c..8422ce987ee 100644 --- a/advisories/unreviewed/2022/04/GHSA-gv89-cmj2-j2r6/GHSA-gv89-cmj2-j2r6.json +++ b/advisories/unreviewed/2022/04/GHSA-gv89-cmj2-j2r6/GHSA-gv89-cmj2-j2r6.json @@ -7,12 +7,8 @@ "CVE-2004-0480" ], "details": "Argument injection vulnerability in IBM Lotus Notes 6.0.3 and 6.5 allows remote attackers to execute arbitrary code via a notes: URI that uses a UNC network share pathname to provide an alternate notes.ini configuration file to notes.exe.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-h5h4-cjwm-9g2f/GHSA-h5h4-cjwm-9g2f.json b/advisories/unreviewed/2022/04/GHSA-h5h4-cjwm-9g2f/GHSA-h5h4-cjwm-9g2f.json index 9318e49aadc..1c8b7c9726d 100644 --- a/advisories/unreviewed/2022/04/GHSA-h5h4-cjwm-9g2f/GHSA-h5h4-cjwm-9g2f.json +++ b/advisories/unreviewed/2022/04/GHSA-h5h4-cjwm-9g2f/GHSA-h5h4-cjwm-9g2f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-hqv4-r44g-hxcx/GHSA-hqv4-r44g-hxcx.json b/advisories/unreviewed/2022/04/GHSA-hqv4-r44g-hxcx/GHSA-hqv4-r44g-hxcx.json index a82639ada9e..e7d4dfbf27e 100644 --- a/advisories/unreviewed/2022/04/GHSA-hqv4-r44g-hxcx/GHSA-hqv4-r44g-hxcx.json +++ b/advisories/unreviewed/2022/04/GHSA-hqv4-r44g-hxcx/GHSA-hqv4-r44g-hxcx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-hrxr-54xq-7fmj/GHSA-hrxr-54xq-7fmj.json b/advisories/unreviewed/2022/04/GHSA-hrxr-54xq-7fmj/GHSA-hrxr-54xq-7fmj.json index 3df8ac75a1f..a7def319fcb 100644 --- a/advisories/unreviewed/2022/04/GHSA-hrxr-54xq-7fmj/GHSA-hrxr-54xq-7fmj.json +++ b/advisories/unreviewed/2022/04/GHSA-hrxr-54xq-7fmj/GHSA-hrxr-54xq-7fmj.json @@ -7,12 +7,8 @@ "CVE-2004-2150" ], "details": "Nettica Corporation INTELLIPEER Email Server 1.01 displays different error messages for valid and invalid account names, which allows remote attackers to determine valid account names.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-j2g6-hqhg-776g/GHSA-j2g6-hqhg-776g.json b/advisories/unreviewed/2022/04/GHSA-j2g6-hqhg-776g/GHSA-j2g6-hqhg-776g.json index d38d9657deb..7860ad02025 100644 --- a/advisories/unreviewed/2022/04/GHSA-j2g6-hqhg-776g/GHSA-j2g6-hqhg-776g.json +++ b/advisories/unreviewed/2022/04/GHSA-j2g6-hqhg-776g/GHSA-j2g6-hqhg-776g.json @@ -7,12 +7,8 @@ "CVE-2002-0495" ], "details": "csSearch.cgi in csSearch 2.3 and earlier allows remote attackers to execute arbitrary Perl code via the savesetup command and the setup parameter, which overwrites the setup.cgi configuration file that is loaded by csSearch.cgi.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-j37w-8jcg-6mcp/GHSA-j37w-8jcg-6mcp.json b/advisories/unreviewed/2022/04/GHSA-j37w-8jcg-6mcp/GHSA-j37w-8jcg-6mcp.json index fb208b0eced..c1ab0a23102 100644 --- a/advisories/unreviewed/2022/04/GHSA-j37w-8jcg-6mcp/GHSA-j37w-8jcg-6mcp.json +++ b/advisories/unreviewed/2022/04/GHSA-j37w-8jcg-6mcp/GHSA-j37w-8jcg-6mcp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-jh4f-5j2m-4v9c/GHSA-jh4f-5j2m-4v9c.json b/advisories/unreviewed/2022/04/GHSA-jh4f-5j2m-4v9c/GHSA-jh4f-5j2m-4v9c.json index 8959c60c59f..a723e99581c 100644 --- a/advisories/unreviewed/2022/04/GHSA-jh4f-5j2m-4v9c/GHSA-jh4f-5j2m-4v9c.json +++ b/advisories/unreviewed/2022/04/GHSA-jh4f-5j2m-4v9c/GHSA-jh4f-5j2m-4v9c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-m8fx-236h-qcjm/GHSA-m8fx-236h-qcjm.json b/advisories/unreviewed/2022/04/GHSA-m8fx-236h-qcjm/GHSA-m8fx-236h-qcjm.json index 46e4300fe2e..17a4f709c8b 100644 --- a/advisories/unreviewed/2022/04/GHSA-m8fx-236h-qcjm/GHSA-m8fx-236h-qcjm.json +++ b/advisories/unreviewed/2022/04/GHSA-m8fx-236h-qcjm/GHSA-m8fx-236h-qcjm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-mg29-p7mj-4wh9/GHSA-mg29-p7mj-4wh9.json b/advisories/unreviewed/2022/04/GHSA-mg29-p7mj-4wh9/GHSA-mg29-p7mj-4wh9.json index 9749ecc1c2e..798050dd848 100644 --- a/advisories/unreviewed/2022/04/GHSA-mg29-p7mj-4wh9/GHSA-mg29-p7mj-4wh9.json +++ b/advisories/unreviewed/2022/04/GHSA-mg29-p7mj-4wh9/GHSA-mg29-p7mj-4wh9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-q495-4rmw-2q38/GHSA-q495-4rmw-2q38.json b/advisories/unreviewed/2022/04/GHSA-q495-4rmw-2q38/GHSA-q495-4rmw-2q38.json index 2e10c4900d7..6aacde3914b 100644 --- a/advisories/unreviewed/2022/04/GHSA-q495-4rmw-2q38/GHSA-q495-4rmw-2q38.json +++ b/advisories/unreviewed/2022/04/GHSA-q495-4rmw-2q38/GHSA-q495-4rmw-2q38.json @@ -7,12 +7,8 @@ "CVE-2004-0489" ], "details": "Argument injection vulnerability in the SSH URI handler for Safari on Mac OS 10.3.3 and earlier allows remote attackers to (1) execute arbitrary code via the ProxyCommand option or (2) conduct port forwarding via the -R option.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-qm29-mf5j-82rg/GHSA-qm29-mf5j-82rg.json b/advisories/unreviewed/2022/04/GHSA-qm29-mf5j-82rg/GHSA-qm29-mf5j-82rg.json index c6c68872aca..9bb458fe3e3 100644 --- a/advisories/unreviewed/2022/04/GHSA-qm29-mf5j-82rg/GHSA-qm29-mf5j-82rg.json +++ b/advisories/unreviewed/2022/04/GHSA-qm29-mf5j-82rg/GHSA-qm29-mf5j-82rg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-r496-h5j2-r5vw/GHSA-r496-h5j2-r5vw.json b/advisories/unreviewed/2022/04/GHSA-r496-h5j2-r5vw/GHSA-r496-h5j2-r5vw.json index e6564fb1195..101f82d4036 100644 --- a/advisories/unreviewed/2022/04/GHSA-r496-h5j2-r5vw/GHSA-r496-h5j2-r5vw.json +++ b/advisories/unreviewed/2022/04/GHSA-r496-h5j2-r5vw/GHSA-r496-h5j2-r5vw.json @@ -7,12 +7,8 @@ "CVE-1999-0113" ], "details": "Some implementations of rlogin allow root access if given a -froot parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-rgp9-mx7h-rwqv/GHSA-rgp9-mx7h-rwqv.json b/advisories/unreviewed/2022/04/GHSA-rgp9-mx7h-rwqv/GHSA-rgp9-mx7h-rwqv.json index c5ff15a2d5c..d7ce677147e 100644 --- a/advisories/unreviewed/2022/04/GHSA-rgp9-mx7h-rwqv/GHSA-rgp9-mx7h-rwqv.json +++ b/advisories/unreviewed/2022/04/GHSA-rgp9-mx7h-rwqv/GHSA-rgp9-mx7h-rwqv.json @@ -7,12 +7,8 @@ "CVE-2004-0411" ], "details": "The URI handlers in Konqueror for KDE 3.2.2 and earlier do not properly filter \"-\" characters that begin a hostname in a (1) telnet, (2) rlogin, (3) ssh, or (4) mailto URI, which allows remote attackers to manipulate the options that are passed to the associated programs, possibly to read arbitrary files or execute arbitrary code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-v4m4-xjj4-28x3/GHSA-v4m4-xjj4-28x3.json b/advisories/unreviewed/2022/04/GHSA-v4m4-xjj4-28x3/GHSA-v4m4-xjj4-28x3.json index 5e8fadb3dc9..14cd1c77943 100644 --- a/advisories/unreviewed/2022/04/GHSA-v4m4-xjj4-28x3/GHSA-v4m4-xjj4-28x3.json +++ b/advisories/unreviewed/2022/04/GHSA-v4m4-xjj4-28x3/GHSA-v4m4-xjj4-28x3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-vxqg-r9mf-h85v/GHSA-vxqg-r9mf-h85v.json b/advisories/unreviewed/2022/04/GHSA-vxqg-r9mf-h85v/GHSA-vxqg-r9mf-h85v.json index 3e568853322..5f5f0833c5f 100644 --- a/advisories/unreviewed/2022/04/GHSA-vxqg-r9mf-h85v/GHSA-vxqg-r9mf-h85v.json +++ b/advisories/unreviewed/2022/04/GHSA-vxqg-r9mf-h85v/GHSA-vxqg-r9mf-h85v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-w99v-7jp5-46gc/GHSA-w99v-7jp5-46gc.json b/advisories/unreviewed/2022/04/GHSA-w99v-7jp5-46gc/GHSA-w99v-7jp5-46gc.json index 4ddb2c019cb..1d39d0e4d47 100644 --- a/advisories/unreviewed/2022/04/GHSA-w99v-7jp5-46gc/GHSA-w99v-7jp5-46gc.json +++ b/advisories/unreviewed/2022/04/GHSA-w99v-7jp5-46gc/GHSA-w99v-7jp5-46gc.json @@ -7,12 +7,8 @@ "CVE-2001-0150" ], "details": "Internet Explorer 5.5 and earlier executes Telnet sessions using command line arguments that are specified by the web site, which could allow remote attackers to execute arbitrary commands if the IE client is using the Telnet client provided in Services for Unix (SFU) 2.0, which creates session transcripts.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-wf6v-m5v4-phr8/GHSA-wf6v-m5v4-phr8.json b/advisories/unreviewed/2022/04/GHSA-wf6v-m5v4-phr8/GHSA-wf6v-m5v4-phr8.json index 401dfef67ab..c120ce2186f 100644 --- a/advisories/unreviewed/2022/04/GHSA-wf6v-m5v4-phr8/GHSA-wf6v-m5v4-phr8.json +++ b/advisories/unreviewed/2022/04/GHSA-wf6v-m5v4-phr8/GHSA-wf6v-m5v4-phr8.json @@ -7,12 +7,8 @@ "CVE-2003-0395" ], "details": "Ultimate PHP Board (UPB) 1.9 allows remote attackers to execute arbitrary PHP code with UPB administrator privileges via an HTTP request containing the code in the User-Agent header, which is executed when the administrator executes admin_iplog.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-wrr8-jh8j-m8r6/GHSA-wrr8-jh8j-m8r6.json b/advisories/unreviewed/2022/04/GHSA-wrr8-jh8j-m8r6/GHSA-wrr8-jh8j-m8r6.json index 2e70d8b656f..ff71154bf84 100644 --- a/advisories/unreviewed/2022/04/GHSA-wrr8-jh8j-m8r6/GHSA-wrr8-jh8j-m8r6.json +++ b/advisories/unreviewed/2022/04/GHSA-wrr8-jh8j-m8r6/GHSA-wrr8-jh8j-m8r6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-x7mq-4mr7-gj5c/GHSA-x7mq-4mr7-gj5c.json b/advisories/unreviewed/2022/04/GHSA-x7mq-4mr7-gj5c/GHSA-x7mq-4mr7-gj5c.json index 3dac76180c5..28242dc663e 100644 --- a/advisories/unreviewed/2022/04/GHSA-x7mq-4mr7-gj5c/GHSA-x7mq-4mr7-gj5c.json +++ b/advisories/unreviewed/2022/04/GHSA-x7mq-4mr7-gj5c/GHSA-x7mq-4mr7-gj5c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-22h6-79rc-rj5g/GHSA-22h6-79rc-rj5g.json b/advisories/unreviewed/2022/05/GHSA-22h6-79rc-rj5g/GHSA-22h6-79rc-rj5g.json index 8447e540adc..d3d582e4b33 100644 --- a/advisories/unreviewed/2022/05/GHSA-22h6-79rc-rj5g/GHSA-22h6-79rc-rj5g.json +++ b/advisories/unreviewed/2022/05/GHSA-22h6-79rc-rj5g/GHSA-22h6-79rc-rj5g.json @@ -7,12 +7,8 @@ "CVE-2015-3140" ], "details": "Multiple cross-site request forgery (CSRF) vulnerabilities in Synametrics Technologies SynaMan before 3.5 Build 1451, Syncrify before 3.7 Build 856, and SynTail before 1.5 Build 567", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-22rq-8f3w-579w/GHSA-22rq-8f3w-579w.json b/advisories/unreviewed/2022/05/GHSA-22rq-8f3w-579w/GHSA-22rq-8f3w-579w.json index e738c1e1409..8638fb911b5 100644 --- a/advisories/unreviewed/2022/05/GHSA-22rq-8f3w-579w/GHSA-22rq-8f3w-579w.json +++ b/advisories/unreviewed/2022/05/GHSA-22rq-8f3w-579w/GHSA-22rq-8f3w-579w.json @@ -7,12 +7,8 @@ "CVE-2019-15461" ], "details": "The Samsung J7 Neo Android device with a build fingerprint of samsung/j7velteub/j7velte:8.1.0/M1AJQ/J701MUBS6BSB4:user/release-keys contains a pre-installed app with a package name of com.samsung.android.themecenter app (versionCode=7000100, versionName=7.0.1.0) that allows other pre-installed apps to perform app installation via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions that are required by other other pre-installed apps that exported their capabilities to other pre-installed app.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-237x-6c63-mfj6/GHSA-237x-6c63-mfj6.json b/advisories/unreviewed/2022/05/GHSA-237x-6c63-mfj6/GHSA-237x-6c63-mfj6.json index 93bc6e30c91..acb1b41a40d 100644 --- a/advisories/unreviewed/2022/05/GHSA-237x-6c63-mfj6/GHSA-237x-6c63-mfj6.json +++ b/advisories/unreviewed/2022/05/GHSA-237x-6c63-mfj6/GHSA-237x-6c63-mfj6.json @@ -7,12 +7,8 @@ "CVE-2019-3866" ], "details": "An information-exposure vulnerability was discovered where openstack-mistral's undercloud log files containing clear-text information were made world readable. A malicious system user could exploit this flaw to access sensitive user information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-24r7-c5r6-xxmj/GHSA-24r7-c5r6-xxmj.json b/advisories/unreviewed/2022/05/GHSA-24r7-c5r6-xxmj/GHSA-24r7-c5r6-xxmj.json index fed905a9760..ab4fc12daba 100644 --- a/advisories/unreviewed/2022/05/GHSA-24r7-c5r6-xxmj/GHSA-24r7-c5r6-xxmj.json +++ b/advisories/unreviewed/2022/05/GHSA-24r7-c5r6-xxmj/GHSA-24r7-c5r6-xxmj.json @@ -7,12 +7,8 @@ "CVE-2019-8088" ], "details": "Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2532-p366-j2g8/GHSA-2532-p366-j2g8.json b/advisories/unreviewed/2022/05/GHSA-2532-p366-j2g8/GHSA-2532-p366-j2g8.json index ed1596094f0..cd626d48cbb 100644 --- a/advisories/unreviewed/2022/05/GHSA-2532-p366-j2g8/GHSA-2532-p366-j2g8.json +++ b/advisories/unreviewed/2022/05/GHSA-2532-p366-j2g8/GHSA-2532-p366-j2g8.json @@ -7,12 +7,8 @@ "CVE-2019-2209" ], "details": "In BTA_DmPinReply of bta_dm_api.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-139287605", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2536-j8mg-q936/GHSA-2536-j8mg-q936.json b/advisories/unreviewed/2022/05/GHSA-2536-j8mg-q936/GHSA-2536-j8mg-q936.json index 66c158e4e4c..1cdcda3fc15 100644 --- a/advisories/unreviewed/2022/05/GHSA-2536-j8mg-q936/GHSA-2536-j8mg-q936.json +++ b/advisories/unreviewed/2022/05/GHSA-2536-j8mg-q936/GHSA-2536-j8mg-q936.json @@ -7,12 +7,8 @@ "CVE-2019-8240" ], "details": "Adobe Bridge CC versions 9.1 and earlier have a memory corruption vulnerability. Successful exploitation could lead to information disclosure.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-268j-m9jh-xjx7/GHSA-268j-m9jh-xjx7.json b/advisories/unreviewed/2022/05/GHSA-268j-m9jh-xjx7/GHSA-268j-m9jh-xjx7.json index 676e2b3a8c8..b03e26ab5ce 100644 --- a/advisories/unreviewed/2022/05/GHSA-268j-m9jh-xjx7/GHSA-268j-m9jh-xjx7.json +++ b/advisories/unreviewed/2022/05/GHSA-268j-m9jh-xjx7/GHSA-268j-m9jh-xjx7.json @@ -7,12 +7,8 @@ "CVE-2019-18201" ], "details": "An issue was discovered on Fujitsu Wireless Keyboard Set LX390 GK381 devices. Because of the lack of proper encryption of 2.4 GHz communication, an attacker is able to eavesdrop on sensitive data such as passwords.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-278x-6vg6-6g42/GHSA-278x-6vg6-6g42.json b/advisories/unreviewed/2022/05/GHSA-278x-6vg6-6g42/GHSA-278x-6vg6-6g42.json index 67a1fb807c5..d197467d4ed 100644 --- a/advisories/unreviewed/2022/05/GHSA-278x-6vg6-6g42/GHSA-278x-6vg6-6g42.json +++ b/advisories/unreviewed/2022/05/GHSA-278x-6vg6-6g42/GHSA-278x-6vg6-6g42.json @@ -7,12 +7,8 @@ "CVE-2008-2374" ], "details": "src/sdp.c in bluez-libs 3.30 in BlueZ, and other bluez-libs before 3.34 and bluez-utils before 3.34 versions, does not validate string length fields in SDP packets, which allows remote SDP servers to cause a denial of service or possibly have unspecified other impact via a crafted length field that triggers excessive memory allocation or a buffer over-read.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-27vg-xj68-r4p8/GHSA-27vg-xj68-r4p8.json b/advisories/unreviewed/2022/05/GHSA-27vg-xj68-r4p8/GHSA-27vg-xj68-r4p8.json index 04d156e066f..1065c281474 100644 --- a/advisories/unreviewed/2022/05/GHSA-27vg-xj68-r4p8/GHSA-27vg-xj68-r4p8.json +++ b/advisories/unreviewed/2022/05/GHSA-27vg-xj68-r4p8/GHSA-27vg-xj68-r4p8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-29j7-fjfr-hh78/GHSA-29j7-fjfr-hh78.json b/advisories/unreviewed/2022/05/GHSA-29j7-fjfr-hh78/GHSA-29j7-fjfr-hh78.json index 1415c11b89d..c96069850a6 100644 --- a/advisories/unreviewed/2022/05/GHSA-29j7-fjfr-hh78/GHSA-29j7-fjfr-hh78.json +++ b/advisories/unreviewed/2022/05/GHSA-29j7-fjfr-hh78/GHSA-29j7-fjfr-hh78.json @@ -7,12 +7,8 @@ "CVE-2019-15392" ], "details": "The Asus ZenFone 4 Selfie Android device with a build fingerprint of Android/sdm660_64/sdm660_64:8.1.0/OPM1/14.2016.1802.247-20180419:user/release-keys contains a pre-installed app with a package name of com.log.logservice app (versionCode=1, versionName=1) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2cpf-rv8p-fqqc/GHSA-2cpf-rv8p-fqqc.json b/advisories/unreviewed/2022/05/GHSA-2cpf-rv8p-fqqc/GHSA-2cpf-rv8p-fqqc.json index 68ab57ef74c..c2f4fa444ba 100644 --- a/advisories/unreviewed/2022/05/GHSA-2cpf-rv8p-fqqc/GHSA-2cpf-rv8p-fqqc.json +++ b/advisories/unreviewed/2022/05/GHSA-2cpf-rv8p-fqqc/GHSA-2cpf-rv8p-fqqc.json @@ -7,12 +7,8 @@ "CVE-2005-4514" ], "details": "** DISPUTED ** The encapsulation script mechanism in Webwasher CSM Appliance Suite 5.x uses case-sensitive detection of malicious tokens, which allows attackers to bypass script detection by using tokens that can be upper or lower case. NOTE: the vendor has stated that this problem could not be reproduced, and has asked the researcher for more information, without a response as of 20060103.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2fcv-44qv-q3qw/GHSA-2fcv-44qv-q3qw.json b/advisories/unreviewed/2022/05/GHSA-2fcv-44qv-q3qw/GHSA-2fcv-44qv-q3qw.json index 9ffcc6210c1..6b08f7050fa 100644 --- a/advisories/unreviewed/2022/05/GHSA-2fcv-44qv-q3qw/GHSA-2fcv-44qv-q3qw.json +++ b/advisories/unreviewed/2022/05/GHSA-2fcv-44qv-q3qw/GHSA-2fcv-44qv-q3qw.json @@ -7,12 +7,8 @@ "CVE-2019-0184" ], "details": "Insufficient access control in protected memory subsystem for Intel(R) TXT for 6th, 7th, 8th and 9th Generation Intel(R) Core(TM) Processor Families; Intel(R) Xeon(R) Processor E3-1500 v5 and v6 Families; Intel(R) Xeon(R) E-2100 and E-2200 Processor Families with Intel(R) Processor Graphics and Intel(R) TXT may allow a privileged user to potentially enable information disclosure via local access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2gcf-97jm-737m/GHSA-2gcf-97jm-737m.json b/advisories/unreviewed/2022/05/GHSA-2gcf-97jm-737m/GHSA-2gcf-97jm-737m.json index 4908f8ca94f..fe9a0767258 100644 --- a/advisories/unreviewed/2022/05/GHSA-2gcf-97jm-737m/GHSA-2gcf-97jm-737m.json +++ b/advisories/unreviewed/2022/05/GHSA-2gcf-97jm-737m/GHSA-2gcf-97jm-737m.json @@ -7,12 +7,8 @@ "CVE-2019-15380" ], "details": "The Fly Photo Pro Android device with a build fingerprint of Fly/PhotoPro/Photo_Pro:8.1.0/O11019/1528117003:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2hv5-gqgx-ppf5/GHSA-2hv5-gqgx-ppf5.json b/advisories/unreviewed/2022/05/GHSA-2hv5-gqgx-ppf5/GHSA-2hv5-gqgx-ppf5.json index 8e588996dc8..aa71ccdcf05 100644 --- a/advisories/unreviewed/2022/05/GHSA-2hv5-gqgx-ppf5/GHSA-2hv5-gqgx-ppf5.json +++ b/advisories/unreviewed/2022/05/GHSA-2hv5-gqgx-ppf5/GHSA-2hv5-gqgx-ppf5.json @@ -7,12 +7,8 @@ "CVE-2019-4398" ], "details": "IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise 2.5 through 2.5.0.9 and 2.4 through 2.4.0.5 could allow a local user to obtain sensitive information from SessionManagement cookies. IBM X-Force ID: 162259.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2jrw-3wxv-fr6m/GHSA-2jrw-3wxv-fr6m.json b/advisories/unreviewed/2022/05/GHSA-2jrw-3wxv-fr6m/GHSA-2jrw-3wxv-fr6m.json index 98984c4cfcc..83d5263affa 100644 --- a/advisories/unreviewed/2022/05/GHSA-2jrw-3wxv-fr6m/GHSA-2jrw-3wxv-fr6m.json +++ b/advisories/unreviewed/2022/05/GHSA-2jrw-3wxv-fr6m/GHSA-2jrw-3wxv-fr6m.json @@ -7,12 +7,8 @@ "CVE-2019-16210" ], "details": "Brocade SANnav versions before v2.0, logs plain text database connection password while triggering support save.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2mcc-mpmm-5889/GHSA-2mcc-mpmm-5889.json b/advisories/unreviewed/2022/05/GHSA-2mcc-mpmm-5889/GHSA-2mcc-mpmm-5889.json index 7ff06cd2609..aa682679c3f 100644 --- a/advisories/unreviewed/2022/05/GHSA-2mcc-mpmm-5889/GHSA-2mcc-mpmm-5889.json +++ b/advisories/unreviewed/2022/05/GHSA-2mcc-mpmm-5889/GHSA-2mcc-mpmm-5889.json @@ -7,12 +7,8 @@ "CVE-2006-2312" ], "details": "Argument injection vulnerability in the URI handler in Skype 2.0.*.104 and 2.5.*.0 through 2.5.*.78 for Windows allows remote authorized attackers to download arbitrary files via a URL that contains certain command-line switches.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2mv9-fr3x-rh65/GHSA-2mv9-fr3x-rh65.json b/advisories/unreviewed/2022/05/GHSA-2mv9-fr3x-rh65/GHSA-2mv9-fr3x-rh65.json index db25cf86489..fd187076dd1 100644 --- a/advisories/unreviewed/2022/05/GHSA-2mv9-fr3x-rh65/GHSA-2mv9-fr3x-rh65.json +++ b/advisories/unreviewed/2022/05/GHSA-2mv9-fr3x-rh65/GHSA-2mv9-fr3x-rh65.json @@ -7,12 +7,8 @@ "CVE-2019-8219" ], "details": "Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2qpm-xf67-jj26/GHSA-2qpm-xf67-jj26.json b/advisories/unreviewed/2022/05/GHSA-2qpm-xf67-jj26/GHSA-2qpm-xf67-jj26.json index 1fb56368511..de0653f34fd 100644 --- a/advisories/unreviewed/2022/05/GHSA-2qpm-xf67-jj26/GHSA-2qpm-xf67-jj26.json +++ b/advisories/unreviewed/2022/05/GHSA-2qpm-xf67-jj26/GHSA-2qpm-xf67-jj26.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2qwq-gqpm-q83g/GHSA-2qwq-gqpm-q83g.json b/advisories/unreviewed/2022/05/GHSA-2qwq-gqpm-q83g/GHSA-2qwq-gqpm-q83g.json index 85e148a988a..1e1338b779c 100644 --- a/advisories/unreviewed/2022/05/GHSA-2qwq-gqpm-q83g/GHSA-2qwq-gqpm-q83g.json +++ b/advisories/unreviewed/2022/05/GHSA-2qwq-gqpm-q83g/GHSA-2qwq-gqpm-q83g.json @@ -14,9 +14,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2r7g-mf5h-9gcw/GHSA-2r7g-mf5h-9gcw.json b/advisories/unreviewed/2022/05/GHSA-2r7g-mf5h-9gcw/GHSA-2r7g-mf5h-9gcw.json index 74685d59069..155be378b49 100644 --- a/advisories/unreviewed/2022/05/GHSA-2r7g-mf5h-9gcw/GHSA-2r7g-mf5h-9gcw.json +++ b/advisories/unreviewed/2022/05/GHSA-2r7g-mf5h-9gcw/GHSA-2r7g-mf5h-9gcw.json @@ -7,12 +7,8 @@ "CVE-2008-1440" ], "details": "Microsoft Windows XP SP2 and SP3, and Server 2003 SP1 and SP2, does not properly validate the option length field in Pragmatic General Multicast (PGM) packets, which allows remote attackers to cause a denial of service (infinite loop and system hang) via a crafted PGM packet, aka the \"PGM Invalid Length Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2vjr-3244-hj86/GHSA-2vjr-3244-hj86.json b/advisories/unreviewed/2022/05/GHSA-2vjr-3244-hj86/GHSA-2vjr-3244-hj86.json index 9afe575e998..a57827283b2 100644 --- a/advisories/unreviewed/2022/05/GHSA-2vjr-3244-hj86/GHSA-2vjr-3244-hj86.json +++ b/advisories/unreviewed/2022/05/GHSA-2vjr-3244-hj86/GHSA-2vjr-3244-hj86.json @@ -7,12 +7,8 @@ "CVE-2019-0142" ], "details": "Insufficient access control in ilp60x64.sys driver for Intel(R) Ethernet 700 Series Controllers before version 1.33.0.0 may allow a privileged user to potentially enable escalation of privilege via local access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-34cf-vv27-5wvh/GHSA-34cf-vv27-5wvh.json b/advisories/unreviewed/2022/05/GHSA-34cf-vv27-5wvh/GHSA-34cf-vv27-5wvh.json index 0f747b30834..1d7957020f3 100644 --- a/advisories/unreviewed/2022/05/GHSA-34cf-vv27-5wvh/GHSA-34cf-vv27-5wvh.json +++ b/advisories/unreviewed/2022/05/GHSA-34cf-vv27-5wvh/GHSA-34cf-vv27-5wvh.json @@ -7,12 +7,8 @@ "CVE-2019-8215" ], "details": "Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-353j-pfv3-ppx7/GHSA-353j-pfv3-ppx7.json b/advisories/unreviewed/2022/05/GHSA-353j-pfv3-ppx7/GHSA-353j-pfv3-ppx7.json index 78372f2ba9b..4038918f7c7 100644 --- a/advisories/unreviewed/2022/05/GHSA-353j-pfv3-ppx7/GHSA-353j-pfv3-ppx7.json +++ b/advisories/unreviewed/2022/05/GHSA-353j-pfv3-ppx7/GHSA-353j-pfv3-ppx7.json @@ -7,12 +7,8 @@ "CVE-2019-18370" ], "details": "An issue was discovered on Xiaomi Mi WiFi R3G devices before 2.28.23-stable. The backup file is in tar.gz format. After uploading, the application uses the tar zxf command to decompress, so one can control the contents of the files in the decompressed directory. In addition, the application's sh script for testing upload and download speeds reads a URL list from /tmp/speedtest_urls.xml, and there is a command injection vulnerability, as demonstrated by api/xqnetdetect/netspeed.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-355h-q75c-4jj6/GHSA-355h-q75c-4jj6.json b/advisories/unreviewed/2022/05/GHSA-355h-q75c-4jj6/GHSA-355h-q75c-4jj6.json index 89ed604fbab..92002b2db87 100644 --- a/advisories/unreviewed/2022/05/GHSA-355h-q75c-4jj6/GHSA-355h-q75c-4jj6.json +++ b/advisories/unreviewed/2022/05/GHSA-355h-q75c-4jj6/GHSA-355h-q75c-4jj6.json @@ -7,12 +7,8 @@ "CVE-2019-8222" ], "details": "Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure .", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-35fh-vqwm-xx6m/GHSA-35fh-vqwm-xx6m.json b/advisories/unreviewed/2022/05/GHSA-35fh-vqwm-xx6m/GHSA-35fh-vqwm-xx6m.json index 6c63ce386d1..61b868c4699 100644 --- a/advisories/unreviewed/2022/05/GHSA-35fh-vqwm-xx6m/GHSA-35fh-vqwm-xx6m.json +++ b/advisories/unreviewed/2022/05/GHSA-35fh-vqwm-xx6m/GHSA-35fh-vqwm-xx6m.json @@ -7,12 +7,8 @@ "CVE-2019-12095" ], "details": "Horde Trean, as used in Horde Groupware Webmail Edition through 5.2.22 and other products, allows CSRF, as demonstrated by the treanBookmarkTags parameter to the trean/ URI on a webmail server.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-37cx-2gj4-qw8v/GHSA-37cx-2gj4-qw8v.json b/advisories/unreviewed/2022/05/GHSA-37cx-2gj4-qw8v/GHSA-37cx-2gj4-qw8v.json index 167e8fda5ad..7db49afdbd1 100644 --- a/advisories/unreviewed/2022/05/GHSA-37cx-2gj4-qw8v/GHSA-37cx-2gj4-qw8v.json +++ b/advisories/unreviewed/2022/05/GHSA-37cx-2gj4-qw8v/GHSA-37cx-2gj4-qw8v.json @@ -7,12 +7,8 @@ "CVE-2019-16200" ], "details": "GNU Serveez through 0.2.2 has an Information Leak. An attacker may send an HTTP POST request to the /cgi-bin/reader URI. The attacker must include a Content-length header with a large positive value that, when represented in 32 bit binary, evaluates to a negative number. The problem exists in the http_cgi_write function under http-cgi.c; however, exploitation might show svz_envblock_add in libserveez/passthrough.c as the location of the heap-based buffer over-read.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-38jr-7vx6-v3p4/GHSA-38jr-7vx6-v3p4.json b/advisories/unreviewed/2022/05/GHSA-38jr-7vx6-v3p4/GHSA-38jr-7vx6-v3p4.json index 693c93db0de..93b0234006c 100644 --- a/advisories/unreviewed/2022/05/GHSA-38jr-7vx6-v3p4/GHSA-38jr-7vx6-v3p4.json +++ b/advisories/unreviewed/2022/05/GHSA-38jr-7vx6-v3p4/GHSA-38jr-7vx6-v3p4.json @@ -7,12 +7,8 @@ "CVE-2019-18188" ], "details": "Trend Micro Apex One could be exploited by an attacker utilizing a command injection vulnerability to extract files from an arbitrary zip file to a specific folder on the Apex One server, which could potentially lead to remote code execution (RCE). The remote process execution is bound to the IUSR account, which has restricted permission and is unable to make major system changes. An attempted attack requires user authentication.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-38wh-jw2h-h2f5/GHSA-38wh-jw2h-h2f5.json b/advisories/unreviewed/2022/05/GHSA-38wh-jw2h-h2f5/GHSA-38wh-jw2h-h2f5.json index 70bc7f60e7d..3d8fd543d13 100644 --- a/advisories/unreviewed/2022/05/GHSA-38wh-jw2h-h2f5/GHSA-38wh-jw2h-h2f5.json +++ b/advisories/unreviewed/2022/05/GHSA-38wh-jw2h-h2f5/GHSA-38wh-jw2h-h2f5.json @@ -7,12 +7,8 @@ "CVE-2019-5282" ], "details": "Bastet module of some Huawei smartphones with Versions earlier than Emily-AL00A 9.0.0.182(C00E82R1P21), Versions earlier than Emily-TL00B 9.0.0.182(C01E82R1P21), Versions earlier than Emily-L09C 9.0.0.203(C432E7R1P11), Versions earlier than Emily-L29C 9.0.0.203(C432E7R1P11), Versions earlier than Emily-L29C 9.0.0.202(C185E2R1P12) have a double free vulnerability. An attacker tricks the user into installing a malicious application, which frees on the same memory address twice. Successful exploit could result in malicious code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-38x5-gc75-363x/GHSA-38x5-gc75-363x.json b/advisories/unreviewed/2022/05/GHSA-38x5-gc75-363x/GHSA-38x5-gc75-363x.json index e986c4d8af0..1704e755dac 100644 --- a/advisories/unreviewed/2022/05/GHSA-38x5-gc75-363x/GHSA-38x5-gc75-363x.json +++ b/advisories/unreviewed/2022/05/GHSA-38x5-gc75-363x/GHSA-38x5-gc75-363x.json @@ -7,12 +7,8 @@ "CVE-2019-12756" ], "details": "Symantec Endpoint Protection (SEP), prior to 14.2 RU2 may be susceptible to a password protection bypass vulnerability whereby the secondary layer of password protection could by bypassed for individuals with local administrator rights.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3f3x-rr4h-mf7f/GHSA-3f3x-rr4h-mf7f.json b/advisories/unreviewed/2022/05/GHSA-3f3x-rr4h-mf7f/GHSA-3f3x-rr4h-mf7f.json index 887c3f35c3d..04888e344f5 100644 --- a/advisories/unreviewed/2022/05/GHSA-3f3x-rr4h-mf7f/GHSA-3f3x-rr4h-mf7f.json +++ b/advisories/unreviewed/2022/05/GHSA-3f3x-rr4h-mf7f/GHSA-3f3x-rr4h-mf7f.json @@ -7,12 +7,8 @@ "CVE-2006-3545" ], "details": "** DISPUTED ** Microsoft Internet Explorer 7.0 Beta allows remote attackers to cause a denial of service (application crash) via a web page with multiple empty APPLET start tags. NOTE: a third party has disputed this issue, stating that the crash does not occur with Microsoft Internet Explorer 7.0 Beta3.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3f48-4c9c-grjq/GHSA-3f48-4c9c-grjq.json b/advisories/unreviewed/2022/05/GHSA-3f48-4c9c-grjq/GHSA-3f48-4c9c-grjq.json index e270b9f976d..4711740cda5 100644 --- a/advisories/unreviewed/2022/05/GHSA-3f48-4c9c-grjq/GHSA-3f48-4c9c-grjq.json +++ b/advisories/unreviewed/2022/05/GHSA-3f48-4c9c-grjq/GHSA-3f48-4c9c-grjq.json @@ -7,12 +7,8 @@ "CVE-2019-15341" ], "details": "The Tecno Camon iAir 2 Plus Android device with a build fingerprint of TECNO/H622/TECNO-ID3k:8.1.0/O11019/E-180914V83:user/release-keys contains a pre-installed platform app with a package name of com.lovelyfont.defcontainer (versionCode=7, versionName=7.0.11). This app contains an exported service named com.lovelyfont.manager.service.FunctionService that allows any app co-located on the device to supply the file path to a Dalvik Executable (DEX) file which it will dynamically load within its own process and execute in with its own system privileges. This app cannot be disabled by the user and the attack can be performed by a zero-permission app. Executing commands as the system user can allow a third-party app to video record the user's screen, factory reset the device, obtain the user's notifications, read the logcat logs, inject events in the Graphical User Interface (GUI), and obtains the user's text messages, and more. Executing code as the system user can allow a third-party app to factory reset the device, obtain the user's Wi-Fi passwords, obtain the user's notifications, read the logcat logs, inject events in the GUI, change the default Input Method Editor (IME) (e.g., keyboard) with one contained within the attacking app that contains keylogging functionality, and obtains the user's text messages, and more.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3f5p-w7xp-rch2/GHSA-3f5p-w7xp-rch2.json b/advisories/unreviewed/2022/05/GHSA-3f5p-w7xp-rch2/GHSA-3f5p-w7xp-rch2.json index 56ba4c06036..9a3864b5b40 100644 --- a/advisories/unreviewed/2022/05/GHSA-3f5p-w7xp-rch2/GHSA-3f5p-w7xp-rch2.json +++ b/advisories/unreviewed/2022/05/GHSA-3f5p-w7xp-rch2/GHSA-3f5p-w7xp-rch2.json @@ -7,12 +7,8 @@ "CVE-2019-18931" ], "details": "Western Digital My Cloud EX2 Ultra firmware 2.31.195 allows a Buffer Overflow with Extended Instruction Pointer (EIP) control via crafted GET/POST parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3g8j-xx34-v7jr/GHSA-3g8j-xx34-v7jr.json b/advisories/unreviewed/2022/05/GHSA-3g8j-xx34-v7jr/GHSA-3g8j-xx34-v7jr.json index 30059330c87..a6e88697dc2 100644 --- a/advisories/unreviewed/2022/05/GHSA-3g8j-xx34-v7jr/GHSA-3g8j-xx34-v7jr.json +++ b/advisories/unreviewed/2022/05/GHSA-3g8j-xx34-v7jr/GHSA-3g8j-xx34-v7jr.json @@ -7,12 +7,8 @@ "CVE-2019-15426" ], "details": "The Xiaomi 5S Plus Android device with a build fingerprint of Xiaomi/natrium/natrium:6.0.1/MXB48T/7.1.5:user/release-keys contains a pre-installed app with a package name of com.miui.powerkeeper app (versionCode=40000, versionName=4.0.00) that allows unauthorized wireless settings modification via a confused deputy attack. This capability can be accessed by any app co-located on the device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3hpc-662x-gv32/GHSA-3hpc-662x-gv32.json b/advisories/unreviewed/2022/05/GHSA-3hpc-662x-gv32/GHSA-3hpc-662x-gv32.json index b7537d1287b..c77ecc4bab3 100644 --- a/advisories/unreviewed/2022/05/GHSA-3hpc-662x-gv32/GHSA-3hpc-662x-gv32.json +++ b/advisories/unreviewed/2022/05/GHSA-3hpc-662x-gv32/GHSA-3hpc-662x-gv32.json @@ -7,12 +7,8 @@ "CVE-2019-15003" ], "details": "The Customer Context Filter in Atlassian Jira Service Desk Server and Jira Service Desk Data Center before 3.9.17, from 3.10.0 before 3.16.10, from 4.0.0 before 4.2.6, from 4.3.0 before 4.3.5, from 4.4.0 before 4.4.3, and from 4.5.0 before 4.5.1 allows remote attackers with portal access to view arbitrary issues in Jira Service Desk projects via authorization bypass. Note that when the 'Anyone can email the service desk or raise a request in the portal' setting is enabled, an attacker can grant themselves portal access, allowing them to exploit the vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3hv8-cqrj-mwg9/GHSA-3hv8-cqrj-mwg9.json b/advisories/unreviewed/2022/05/GHSA-3hv8-cqrj-mwg9/GHSA-3hv8-cqrj-mwg9.json index 50fd01319b2..ac520ef3793 100644 --- a/advisories/unreviewed/2022/05/GHSA-3hv8-cqrj-mwg9/GHSA-3hv8-cqrj-mwg9.json +++ b/advisories/unreviewed/2022/05/GHSA-3hv8-cqrj-mwg9/GHSA-3hv8-cqrj-mwg9.json @@ -7,12 +7,8 @@ "CVE-2019-15383" ], "details": "The Allview X5 Android device with a build fingerprint of ALLVIEW/X5_Soul_Mini/X5_Soul_Mini:8.1.0/O11019/1522468763:userdebug/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3jvc-mp84-rcxx/GHSA-3jvc-mp84-rcxx.json b/advisories/unreviewed/2022/05/GHSA-3jvc-mp84-rcxx/GHSA-3jvc-mp84-rcxx.json index 99ea7032813..7ba0d1c5603 100644 --- a/advisories/unreviewed/2022/05/GHSA-3jvc-mp84-rcxx/GHSA-3jvc-mp84-rcxx.json +++ b/advisories/unreviewed/2022/05/GHSA-3jvc-mp84-rcxx/GHSA-3jvc-mp84-rcxx.json @@ -7,12 +7,8 @@ "CVE-2015-1780" ], "details": "oVirt users with MANIPULATE_STORAGE_DOMAIN permissions can attach a storage domain to any data-center", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3m49-jmr4-jpx2/GHSA-3m49-jmr4-jpx2.json b/advisories/unreviewed/2022/05/GHSA-3m49-jmr4-jpx2/GHSA-3m49-jmr4-jpx2.json index 0749bb463d4..eaff3ab8f81 100644 --- a/advisories/unreviewed/2022/05/GHSA-3m49-jmr4-jpx2/GHSA-3m49-jmr4-jpx2.json +++ b/advisories/unreviewed/2022/05/GHSA-3m49-jmr4-jpx2/GHSA-3m49-jmr4-jpx2.json @@ -7,12 +7,8 @@ "CVE-2019-2199" ], "details": "In createSessionInternal of PackageInstallerService.java, there is a possible permissions bypass. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-138650665", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3mv9-9jrg-48mh/GHSA-3mv9-9jrg-48mh.json b/advisories/unreviewed/2022/05/GHSA-3mv9-9jrg-48mh/GHSA-3mv9-9jrg-48mh.json index 398a65e188a..8cd1187e769 100644 --- a/advisories/unreviewed/2022/05/GHSA-3mv9-9jrg-48mh/GHSA-3mv9-9jrg-48mh.json +++ b/advisories/unreviewed/2022/05/GHSA-3mv9-9jrg-48mh/GHSA-3mv9-9jrg-48mh.json @@ -7,12 +7,8 @@ "CVE-2006-3689" ], "details": "** DISPUTED ** PHP remote file inclusion vulnerability in user-func.php in Codeworks Gnomedia SubberZ[Lite] allows remote attackers to execute arbitrary PHP code via a URL in the myadmindir parameter. NOTE: this issue has been disputed by a third party that claims that \" the myadmindir variable is set before any GET variables are processed.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3q42-g7pm-w4xc/GHSA-3q42-g7pm-w4xc.json b/advisories/unreviewed/2022/05/GHSA-3q42-g7pm-w4xc/GHSA-3q42-g7pm-w4xc.json index 78cddb2f65c..d90363a9b5d 100644 --- a/advisories/unreviewed/2022/05/GHSA-3q42-g7pm-w4xc/GHSA-3q42-g7pm-w4xc.json +++ b/advisories/unreviewed/2022/05/GHSA-3q42-g7pm-w4xc/GHSA-3q42-g7pm-w4xc.json @@ -7,12 +7,8 @@ "CVE-2019-17332" ], "details": "The Digital Asset Manager Web Interface component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains a vulnerability that theoretically allows authenticated users to perform stored cross-site scripting (XSS) attacks. Affected releases are TIBCO Software Inc.'s TIBCO EBX Add-ons: versions up to and including 3.20.13, versions 4.1.0, 4.2.0, 4.2.1, and 4.2.2.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3q63-vj3h-7j3f/GHSA-3q63-vj3h-7j3f.json b/advisories/unreviewed/2022/05/GHSA-3q63-vj3h-7j3f/GHSA-3q63-vj3h-7j3f.json index 918432cab5e..24b1cdc0e2b 100644 --- a/advisories/unreviewed/2022/05/GHSA-3q63-vj3h-7j3f/GHSA-3q63-vj3h-7j3f.json +++ b/advisories/unreviewed/2022/05/GHSA-3q63-vj3h-7j3f/GHSA-3q63-vj3h-7j3f.json @@ -7,12 +7,8 @@ "CVE-2019-6170" ], "details": "A potential vulnerability in some Lenovo ThinkPads may allow an attacker to execute arbitrary code under SMM under certain circumstances.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3qpq-9423-wfmq/GHSA-3qpq-9423-wfmq.json b/advisories/unreviewed/2022/05/GHSA-3qpq-9423-wfmq/GHSA-3qpq-9423-wfmq.json index 489e766b0c4..d017dd6cd23 100644 --- a/advisories/unreviewed/2022/05/GHSA-3qpq-9423-wfmq/GHSA-3qpq-9423-wfmq.json +++ b/advisories/unreviewed/2022/05/GHSA-3qpq-9423-wfmq/GHSA-3qpq-9423-wfmq.json @@ -7,12 +7,8 @@ "CVE-2015-7810" ], "details": "libbluray MountManager class has a time-of-check time-of-use (TOCTOU) race when expanding JAR files", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3r38-cfr7-4765/GHSA-3r38-cfr7-4765.json b/advisories/unreviewed/2022/05/GHSA-3r38-cfr7-4765/GHSA-3r38-cfr7-4765.json index 316e57c18ef..cc98deda36c 100644 --- a/advisories/unreviewed/2022/05/GHSA-3r38-cfr7-4765/GHSA-3r38-cfr7-4765.json +++ b/advisories/unreviewed/2022/05/GHSA-3r38-cfr7-4765/GHSA-3r38-cfr7-4765.json @@ -7,12 +7,8 @@ "CVE-2019-18809" ], "details": "A memory leak in the af9005_identify_state() function in drivers/media/usb/dvb-usb/af9005.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption), aka CID-2289adbfa559.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3rh5-9p47-7947/GHSA-3rh5-9p47-7947.json b/advisories/unreviewed/2022/05/GHSA-3rh5-9p47-7947/GHSA-3rh5-9p47-7947.json index ff29a8b9dc7..9873d120811 100644 --- a/advisories/unreviewed/2022/05/GHSA-3rh5-9p47-7947/GHSA-3rh5-9p47-7947.json +++ b/advisories/unreviewed/2022/05/GHSA-3rh5-9p47-7947/GHSA-3rh5-9p47-7947.json @@ -7,12 +7,8 @@ "CVE-2019-18844" ], "details": "The Device Model in ACRN before 2019w25.5-140000p relies on assert calls in devicemodel/hw/pci/core.c and devicemodel/include/pci_core.h (instead of other mechanisms for propagating error information or diagnostic information), which might allow attackers to cause a denial of service (assertion failure) within pci core.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3vrc-g335-pcfw/GHSA-3vrc-g335-pcfw.json b/advisories/unreviewed/2022/05/GHSA-3vrc-g335-pcfw/GHSA-3vrc-g335-pcfw.json index 242255bc3df..11ec1adb577 100644 --- a/advisories/unreviewed/2022/05/GHSA-3vrc-g335-pcfw/GHSA-3vrc-g335-pcfw.json +++ b/advisories/unreviewed/2022/05/GHSA-3vrc-g335-pcfw/GHSA-3vrc-g335-pcfw.json @@ -7,12 +7,8 @@ "CVE-2019-15360" ], "details": "The Hisense U965 Android device with a build fingerprint of Hisense/U965_4G_10/HS6739MT:8.1.0/O11019/Hisense_U965_4G_10_S01:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3vxj-2mx7-gxc7/GHSA-3vxj-2mx7-gxc7.json b/advisories/unreviewed/2022/05/GHSA-3vxj-2mx7-gxc7/GHSA-3vxj-2mx7-gxc7.json index 3a2063af9bc..69f24051b09 100644 --- a/advisories/unreviewed/2022/05/GHSA-3vxj-2mx7-gxc7/GHSA-3vxj-2mx7-gxc7.json +++ b/advisories/unreviewed/2022/05/GHSA-3vxj-2mx7-gxc7/GHSA-3vxj-2mx7-gxc7.json @@ -7,12 +7,8 @@ "CVE-2019-15422" ], "details": "The Doogee Mix Android device with a build fingerprint of DOOGEE/MIX/MIX:7.0/NRD90M/1495809471:user/release-keys contains a pre-installed app with a package name of com.mediatek.factorymode app (versionCode=1, versionName=1) that allows unauthorized wireless settings modification via a confused deputy attack. This capability can be accessed by any app co-located on the device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3wc6-3hc2-3wc8/GHSA-3wc6-3hc2-3wc8.json b/advisories/unreviewed/2022/05/GHSA-3wc6-3hc2-3wc8/GHSA-3wc6-3hc2-3wc8.json index 53ec05c3517..b757b5e01c7 100644 --- a/advisories/unreviewed/2022/05/GHSA-3wc6-3hc2-3wc8/GHSA-3wc6-3hc2-3wc8.json +++ b/advisories/unreviewed/2022/05/GHSA-3wc6-3hc2-3wc8/GHSA-3wc6-3hc2-3wc8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3xcg-m3v5-m392/GHSA-3xcg-m3v5-m392.json b/advisories/unreviewed/2022/05/GHSA-3xcg-m3v5-m392/GHSA-3xcg-m3v5-m392.json index c6f37708edf..98a098fd6d1 100644 --- a/advisories/unreviewed/2022/05/GHSA-3xcg-m3v5-m392/GHSA-3xcg-m3v5-m392.json +++ b/advisories/unreviewed/2022/05/GHSA-3xcg-m3v5-m392/GHSA-3xcg-m3v5-m392.json @@ -7,12 +7,8 @@ "CVE-2019-16949" ], "details": "An issue was discovered in Enghouse Web Chat 6.1.300.31 and 6.2.284.34. A user is allowed to send an archive of their chat log to an email address specified at the beginning of the chat (where the user enters in their name and e-mail address). This POST request can be modified to change the message as well as the end recipient of the message. The e-mail address will have the same domain name and user as the product allotted. This can be used in phishing campaigns against users on the same domain.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3xxm-pww7-gf82/GHSA-3xxm-pww7-gf82.json b/advisories/unreviewed/2022/05/GHSA-3xxm-pww7-gf82/GHSA-3xxm-pww7-gf82.json index d2686c93d53..979f8b70577 100644 --- a/advisories/unreviewed/2022/05/GHSA-3xxm-pww7-gf82/GHSA-3xxm-pww7-gf82.json +++ b/advisories/unreviewed/2022/05/GHSA-3xxm-pww7-gf82/GHSA-3xxm-pww7-gf82.json @@ -7,12 +7,8 @@ "CVE-2019-2207" ], "details": "In nfa_hci_handle_admin_gate_rsp of nfa_hci_act.cc, there is a possible out of bound write due to missing bounds checks. This could lead to local escalation of privilege with system execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-124524315", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-42q3-f5fp-gpxr/GHSA-42q3-f5fp-gpxr.json b/advisories/unreviewed/2022/05/GHSA-42q3-f5fp-gpxr/GHSA-42q3-f5fp-gpxr.json index c677debf257..0ae7c4b4aea 100644 --- a/advisories/unreviewed/2022/05/GHSA-42q3-f5fp-gpxr/GHSA-42q3-f5fp-gpxr.json +++ b/advisories/unreviewed/2022/05/GHSA-42q3-f5fp-gpxr/GHSA-42q3-f5fp-gpxr.json @@ -7,12 +7,8 @@ "CVE-2006-5380" ], "details": "** DISPUTED ** Remote file inclusion vulnerability in Contenido CMS allows remote attackers to execute arbitrary PHP code via a URL in the contenido_path parameter to (1) cms/dbfs.php or (2) cms/front_content.php. NOTE: CVE disputes this issue for version 4.6.15, because $contenido_path is set to a static value.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-43rr-prv9-867f/GHSA-43rr-prv9-867f.json b/advisories/unreviewed/2022/05/GHSA-43rr-prv9-867f/GHSA-43rr-prv9-867f.json index 027a71cfe4f..ece0cf5df3d 100644 --- a/advisories/unreviewed/2022/05/GHSA-43rr-prv9-867f/GHSA-43rr-prv9-867f.json +++ b/advisories/unreviewed/2022/05/GHSA-43rr-prv9-867f/GHSA-43rr-prv9-867f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4422-p6xr-vfgh/GHSA-4422-p6xr-vfgh.json b/advisories/unreviewed/2022/05/GHSA-4422-p6xr-vfgh/GHSA-4422-p6xr-vfgh.json index adf1e1e5751..187a01b38ba 100644 --- a/advisories/unreviewed/2022/05/GHSA-4422-p6xr-vfgh/GHSA-4422-p6xr-vfgh.json +++ b/advisories/unreviewed/2022/05/GHSA-4422-p6xr-vfgh/GHSA-4422-p6xr-vfgh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-44r6-c3fm-xg2r/GHSA-44r6-c3fm-xg2r.json b/advisories/unreviewed/2022/05/GHSA-44r6-c3fm-xg2r/GHSA-44r6-c3fm-xg2r.json index 1ccc3bb55ac..32c223ff4be 100644 --- a/advisories/unreviewed/2022/05/GHSA-44r6-c3fm-xg2r/GHSA-44r6-c3fm-xg2r.json +++ b/advisories/unreviewed/2022/05/GHSA-44r6-c3fm-xg2r/GHSA-44r6-c3fm-xg2r.json @@ -7,12 +7,8 @@ "CVE-2006-4135" ], "details": "** DISPUTED ** PHP remote file inclusion vulnerability in cal_config.inc.php in Calendarix 0.7.20060401 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the calpath parameter. NOTE: this issue has been disputed by a third party, who says that the affected $calpath variable is set to a constant value in the beginning of the script. CVE concurs that the initial report is invalid.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4856-x4h7-3jpv/GHSA-4856-x4h7-3jpv.json b/advisories/unreviewed/2022/05/GHSA-4856-x4h7-3jpv/GHSA-4856-x4h7-3jpv.json index 93063a9dbdb..26367bfcdac 100644 --- a/advisories/unreviewed/2022/05/GHSA-4856-x4h7-3jpv/GHSA-4856-x4h7-3jpv.json +++ b/advisories/unreviewed/2022/05/GHSA-4856-x4h7-3jpv/GHSA-4856-x4h7-3jpv.json @@ -7,12 +7,8 @@ "CVE-2006-4156" ], "details": "** DISPUTED ** PHP remote file inclusion vulnerability in big.php in pearlabs mafia moblog 6 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the pathtotemplate parameter. NOTE: a third party claims that the researcher is incorrect, because template.php defines pathtotemplate before big.php uses pathtotemplate. CVE has not verified either claim, but during August 2006, the original researcher made several significant errors regarding this bug type.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4c2h-m2v8-77j8/GHSA-4c2h-m2v8-77j8.json b/advisories/unreviewed/2022/05/GHSA-4c2h-m2v8-77j8/GHSA-4c2h-m2v8-77j8.json index 4451eec543f..9a4e40889a2 100644 --- a/advisories/unreviewed/2022/05/GHSA-4c2h-m2v8-77j8/GHSA-4c2h-m2v8-77j8.json +++ b/advisories/unreviewed/2022/05/GHSA-4c2h-m2v8-77j8/GHSA-4c2h-m2v8-77j8.json @@ -7,12 +7,8 @@ "CVE-2006-3209" ], "details": "** DISPUTED ** The Task scheduler (at.exe) on Microsoft Windows XP spawns each scheduled process with SYSTEM permissions, which allows local users to gain privileges. NOTE: this issue has been disputed by third parties, who state that the Task scheduler is limited to the Administrators group by default upon installation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4c6r-wf9r-j46c/GHSA-4c6r-wf9r-j46c.json b/advisories/unreviewed/2022/05/GHSA-4c6r-wf9r-j46c/GHSA-4c6r-wf9r-j46c.json index cbf5fefc195..d9820b61660 100644 --- a/advisories/unreviewed/2022/05/GHSA-4c6r-wf9r-j46c/GHSA-4c6r-wf9r-j46c.json +++ b/advisories/unreviewed/2022/05/GHSA-4c6r-wf9r-j46c/GHSA-4c6r-wf9r-j46c.json @@ -7,12 +7,8 @@ "CVE-2019-15429" ], "details": "The Panasonic ELUGA_I9 Android device with a build fingerprint of Panasonic/ELUGA_I9/ELUGA_I9:7.0/NRD90M/1501740649:user/release-keys contains a pre-installed app with a package name of com.ovvi.modem app (versionCode=1, versionName=1) that allows unauthorized attacker-controlled at command via a confused deputy attack. This capability can be accessed by any app co-located on the device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4cqf-vpcq-9pvx/GHSA-4cqf-vpcq-9pvx.json b/advisories/unreviewed/2022/05/GHSA-4cqf-vpcq-9pvx/GHSA-4cqf-vpcq-9pvx.json index 1bf9559b118..0c4c7f0d0d8 100644 --- a/advisories/unreviewed/2022/05/GHSA-4cqf-vpcq-9pvx/GHSA-4cqf-vpcq-9pvx.json +++ b/advisories/unreviewed/2022/05/GHSA-4cqf-vpcq-9pvx/GHSA-4cqf-vpcq-9pvx.json @@ -7,12 +7,8 @@ "CVE-2019-16872" ], "details": "Portainer before 1.22.1 has Incorrect Access Control (issue 1 of 4).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4fwh-62fj-p4ww/GHSA-4fwh-62fj-p4ww.json b/advisories/unreviewed/2022/05/GHSA-4fwh-62fj-p4ww/GHSA-4fwh-62fj-p4ww.json index 9a139ea1be1..c0a6fa73d98 100644 --- a/advisories/unreviewed/2022/05/GHSA-4fwh-62fj-p4ww/GHSA-4fwh-62fj-p4ww.json +++ b/advisories/unreviewed/2022/05/GHSA-4fwh-62fj-p4ww/GHSA-4fwh-62fj-p4ww.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4gv8-pm5q-24x3/GHSA-4gv8-pm5q-24x3.json b/advisories/unreviewed/2022/05/GHSA-4gv8-pm5q-24x3/GHSA-4gv8-pm5q-24x3.json index 1a989146f47..68861dcfead 100644 --- a/advisories/unreviewed/2022/05/GHSA-4gv8-pm5q-24x3/GHSA-4gv8-pm5q-24x3.json +++ b/advisories/unreviewed/2022/05/GHSA-4gv8-pm5q-24x3/GHSA-4gv8-pm5q-24x3.json @@ -7,12 +7,8 @@ "CVE-2019-15393" ], "details": "The Asus ZenFone Live Android device with a build fingerprint of asus/WW_Phone/ASUS_X00LD_3:7.1.1/NMF26F/14.0400.1806.203-20180720:user/release-keys contains a pre-installed app with a package name of com.asus.atd.smmitest app (versionCode=1, versionName=1) that allows unauthorized wireless settings modification via a confused deputy attack. This capability can be accessed by any app co-located on the device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4h2j-c967-3g2g/GHSA-4h2j-c967-3g2g.json b/advisories/unreviewed/2022/05/GHSA-4h2j-c967-3g2g/GHSA-4h2j-c967-3g2g.json index 0d12413c836..5a0c4cfaf69 100644 --- a/advisories/unreviewed/2022/05/GHSA-4h2j-c967-3g2g/GHSA-4h2j-c967-3g2g.json +++ b/advisories/unreviewed/2022/05/GHSA-4h2j-c967-3g2g/GHSA-4h2j-c967-3g2g.json @@ -7,12 +7,8 @@ "CVE-2019-2210" ], "details": "In load_logging_config of qmi_vs_service.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10Android ID: A-139148442", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4hmc-9q64-h23p/GHSA-4hmc-9q64-h23p.json b/advisories/unreviewed/2022/05/GHSA-4hmc-9q64-h23p/GHSA-4hmc-9q64-h23p.json index b6d370c97cb..c18aaa2486a 100644 --- a/advisories/unreviewed/2022/05/GHSA-4hmc-9q64-h23p/GHSA-4hmc-9q64-h23p.json +++ b/advisories/unreviewed/2022/05/GHSA-4hmc-9q64-h23p/GHSA-4hmc-9q64-h23p.json @@ -7,12 +7,8 @@ "CVE-2019-11933" ], "details": "A heap buffer overflow bug in libpl_droidsonroids_gif before 1.2.19, as used in WhatsApp for Android before version 2.19.291 could allow remote attackers to execute arbitrary code or cause a denial of service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4jq9-4xm2-643v/GHSA-4jq9-4xm2-643v.json b/advisories/unreviewed/2022/05/GHSA-4jq9-4xm2-643v/GHSA-4jq9-4xm2-643v.json index 38aec5af09a..ce64073d0aa 100644 --- a/advisories/unreviewed/2022/05/GHSA-4jq9-4xm2-643v/GHSA-4jq9-4xm2-643v.json +++ b/advisories/unreviewed/2022/05/GHSA-4jq9-4xm2-643v/GHSA-4jq9-4xm2-643v.json @@ -7,12 +7,8 @@ "CVE-2019-15347" ], "details": "The Tecno Camon iClick 2 Android device with a build fingerprint of TECNO/H622/TECNO-ID6:8.1.0/O11019/F-180824V116:user/release-keys contains a pre-installed platform app with a package name of com.lovelyfont.defcontainer (versionCode=7, versionName=7.0.11). This app contains an exported service named com.lovelyfont.manager.FontCoverService that allows any app co-located on the device to supply arbitrary commands via shell script to be executed as the system user that are triggered by writing an attacker-selected message to the logcat log. This app cannot be disabled by the user and the attack can be performed by a zero-permission app. Executing commands as the system user can allow a third-party app to video record the user's screen, factory reset the device, obtain the user's notifications, read the logcat logs, inject events in the Graphical User Interface (GUI), and obtains the user's text messages, and more. Executing commands as the system user can allow a third-party app to factory reset the device, obtain the user's notifications, read the logcat logs, inject events in the GUI, change the default Input Method Editor (IME) (e.g., keyboard) with one contained within the attacking app that contains keylogging functionality, and obtains the user's text messages, and more.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4mh4-9m87-v85v/GHSA-4mh4-9m87-v85v.json b/advisories/unreviewed/2022/05/GHSA-4mh4-9m87-v85v/GHSA-4mh4-9m87-v85v.json index 4abe6ab7c39..077fc1c739d 100644 --- a/advisories/unreviewed/2022/05/GHSA-4mh4-9m87-v85v/GHSA-4mh4-9m87-v85v.json +++ b/advisories/unreviewed/2022/05/GHSA-4mh4-9m87-v85v/GHSA-4mh4-9m87-v85v.json @@ -7,12 +7,8 @@ "CVE-2019-15470" ], "details": "The Xiaomi Redmi Note 6 Pro Android device with a build fingerprint of xiaomi/tulip/tulip:8.1.0/OPM1.171019.011/V10.2.2.0.OEKMIXM:user/release-keys contains a pre-installed app with a package name of com.qualcomm.qti.callenhancement app (versionCode=27, versionName=8.1.0) that allows other pre-installed apps to perform microphone audio recording via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions that are required by other other pre-installed apps that export their capabilities to other pre-installed app. This app allows a third-party app to use its open interface to record telephone calls to external storage.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4qhx-g5hg-wvgv/GHSA-4qhx-g5hg-wvgv.json b/advisories/unreviewed/2022/05/GHSA-4qhx-g5hg-wvgv/GHSA-4qhx-g5hg-wvgv.json index 47910bd2bcb..ae98b6f1b86 100644 --- a/advisories/unreviewed/2022/05/GHSA-4qhx-g5hg-wvgv/GHSA-4qhx-g5hg-wvgv.json +++ b/advisories/unreviewed/2022/05/GHSA-4qhx-g5hg-wvgv/GHSA-4qhx-g5hg-wvgv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4r53-8549-7m3r/GHSA-4r53-8549-7m3r.json b/advisories/unreviewed/2022/05/GHSA-4r53-8549-7m3r/GHSA-4r53-8549-7m3r.json index 7ed79455a6b..44d79c2cc12 100644 --- a/advisories/unreviewed/2022/05/GHSA-4r53-8549-7m3r/GHSA-4r53-8549-7m3r.json +++ b/advisories/unreviewed/2022/05/GHSA-4r53-8549-7m3r/GHSA-4r53-8549-7m3r.json @@ -7,12 +7,8 @@ "CVE-2019-18836" ], "details": "Envoy before 1.12.1 allows a remote denial of service because of resource loops, as demonstrated by a single idle TCP connection being able to keep a worker thread in an infinite busy loop when continue_on_listener_filters_timeout is used.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "WEB", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4r64-m3cx-69p7/GHSA-4r64-m3cx-69p7.json b/advisories/unreviewed/2022/05/GHSA-4r64-m3cx-69p7/GHSA-4r64-m3cx-69p7.json index e26e5640b93..d9be027c468 100644 --- a/advisories/unreviewed/2022/05/GHSA-4r64-m3cx-69p7/GHSA-4r64-m3cx-69p7.json +++ b/advisories/unreviewed/2022/05/GHSA-4r64-m3cx-69p7/GHSA-4r64-m3cx-69p7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4vq4-x94h-7899/GHSA-4vq4-x94h-7899.json b/advisories/unreviewed/2022/05/GHSA-4vq4-x94h-7899/GHSA-4vq4-x94h-7899.json index 5dd2f0d7faa..4f3ffaed061 100644 --- a/advisories/unreviewed/2022/05/GHSA-4vq4-x94h-7899/GHSA-4vq4-x94h-7899.json +++ b/advisories/unreviewed/2022/05/GHSA-4vq4-x94h-7899/GHSA-4vq4-x94h-7899.json @@ -7,12 +7,8 @@ "CVE-2019-1383" ], "details": "An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations, aka 'Windows Data Sharing Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1379, CVE-2019-1417.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4vqj-mgvj-g5h9/GHSA-4vqj-mgvj-g5h9.json b/advisories/unreviewed/2022/05/GHSA-4vqj-mgvj-g5h9/GHSA-4vqj-mgvj-g5h9.json index a21b3a8de45..97f09d20899 100644 --- a/advisories/unreviewed/2022/05/GHSA-4vqj-mgvj-g5h9/GHSA-4vqj-mgvj-g5h9.json +++ b/advisories/unreviewed/2022/05/GHSA-4vqj-mgvj-g5h9/GHSA-4vqj-mgvj-g5h9.json @@ -7,12 +7,8 @@ "CVE-2019-15357" ], "details": "The Advan i6A Android device with a build fingerprint of ADVAN/i6A/i6A:8.1.0/O11019/1523602705:userdebug/test-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4w38-qpr9-g5qm/GHSA-4w38-qpr9-g5qm.json b/advisories/unreviewed/2022/05/GHSA-4w38-qpr9-g5qm/GHSA-4w38-qpr9-g5qm.json index 163211ddb51..d6854c5c892 100644 --- a/advisories/unreviewed/2022/05/GHSA-4w38-qpr9-g5qm/GHSA-4w38-qpr9-g5qm.json +++ b/advisories/unreviewed/2022/05/GHSA-4w38-qpr9-g5qm/GHSA-4w38-qpr9-g5qm.json @@ -7,12 +7,8 @@ "CVE-2019-18199" ], "details": "An issue was discovered on Fujitsu Wireless Keyboard Set LX390 GK381 devices. Because of the lack of proper encryption of 2.4 GHz communication, and because of password-based authentication, they are vulnerable to replay attacks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4w8p-vqv2-2g8w/GHSA-4w8p-vqv2-2g8w.json b/advisories/unreviewed/2022/05/GHSA-4w8p-vqv2-2g8w/GHSA-4w8p-vqv2-2g8w.json index 37e0866bd16..c0a56b82f09 100644 --- a/advisories/unreviewed/2022/05/GHSA-4w8p-vqv2-2g8w/GHSA-4w8p-vqv2-2g8w.json +++ b/advisories/unreviewed/2022/05/GHSA-4w8p-vqv2-2g8w/GHSA-4w8p-vqv2-2g8w.json @@ -7,12 +7,8 @@ "CVE-2015-1607" ], "details": "kbx/keybox-search.c in GnuPG before 1.4.19, 2.0.x before 2.0.27, and 2.1.x before 2.1.2 does not properly handle bitwise left-shifts, which allows remote attackers to cause a denial of service (invalid read operation) via a crafted keyring file, related to sign extensions and \"memcpy with overlapping ranges.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4x3q-cmgw-gw26/GHSA-4x3q-cmgw-gw26.json b/advisories/unreviewed/2022/05/GHSA-4x3q-cmgw-gw26/GHSA-4x3q-cmgw-gw26.json index 5d31be83bc0..05099052c5c 100644 --- a/advisories/unreviewed/2022/05/GHSA-4x3q-cmgw-gw26/GHSA-4x3q-cmgw-gw26.json +++ b/advisories/unreviewed/2022/05/GHSA-4x3q-cmgw-gw26/GHSA-4x3q-cmgw-gw26.json @@ -7,12 +7,8 @@ "CVE-2019-6846" ], "details": "A CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists in Modicon M580, Modicon M340, Modicon BMxCRA and 140CRA modules (all firmware versions), which could cause information disclosure when using the FTP protocol.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4xr9-jxv7-xpww/GHSA-4xr9-jxv7-xpww.json b/advisories/unreviewed/2022/05/GHSA-4xr9-jxv7-xpww/GHSA-4xr9-jxv7-xpww.json index 7fa649557f4..97783ba4962 100644 --- a/advisories/unreviewed/2022/05/GHSA-4xr9-jxv7-xpww/GHSA-4xr9-jxv7-xpww.json +++ b/advisories/unreviewed/2022/05/GHSA-4xr9-jxv7-xpww/GHSA-4xr9-jxv7-xpww.json @@ -7,12 +7,8 @@ "CVE-2019-15464" ], "details": "The Samsung J7 Pro Android device with a build fingerprint of samsung/j7y17lteub/j7y17lte:8.1.0/M1AJQ/J730GUBS6BSC1:user/release-keys contains a pre-installed app with a package name of com.samsung.android.themecenter app (versionCode=7000100, versionName=7.0.1.0) that allows other pre-installed apps to perform app installation via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions that are required by other other pre-installed apps that exported their capabilities to other pre-installed app.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4xw7-98v4-8gqh/GHSA-4xw7-98v4-8gqh.json b/advisories/unreviewed/2022/05/GHSA-4xw7-98v4-8gqh/GHSA-4xw7-98v4-8gqh.json index 0bc5e223c8b..d9f12a9313d 100644 --- a/advisories/unreviewed/2022/05/GHSA-4xw7-98v4-8gqh/GHSA-4xw7-98v4-8gqh.json +++ b/advisories/unreviewed/2022/05/GHSA-4xw7-98v4-8gqh/GHSA-4xw7-98v4-8gqh.json @@ -7,12 +7,8 @@ "CVE-2019-17424" ], "details": "A stack-based buffer overflow in the processPrivilage() function in IOS/process-general.c in nipper-ng 0.11.10 allows remote attackers (serving firewall configuration files) to achieve Remote Code Execution or Denial Of Service via a crafted file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-52mf-v3p6-vr9q/GHSA-52mf-v3p6-vr9q.json b/advisories/unreviewed/2022/05/GHSA-52mf-v3p6-vr9q/GHSA-52mf-v3p6-vr9q.json index c929bdad8e4..cf8cc2aba05 100644 --- a/advisories/unreviewed/2022/05/GHSA-52mf-v3p6-vr9q/GHSA-52mf-v3p6-vr9q.json +++ b/advisories/unreviewed/2022/05/GHSA-52mf-v3p6-vr9q/GHSA-52mf-v3p6-vr9q.json @@ -7,12 +7,8 @@ "CVE-2019-15372" ], "details": "The Hisense F17 Android device with a build fingerprint of Hisense/F17_4G/HS6739MT:8.1.0/O11019/Hisense_F17_4G_00_S01:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-52p3-pmr5-f54r/GHSA-52p3-pmr5-f54r.json b/advisories/unreviewed/2022/05/GHSA-52p3-pmr5-f54r/GHSA-52p3-pmr5-f54r.json index cb4b80cfbcd..b31b3e55cd6 100644 --- a/advisories/unreviewed/2022/05/GHSA-52p3-pmr5-f54r/GHSA-52p3-pmr5-f54r.json +++ b/advisories/unreviewed/2022/05/GHSA-52p3-pmr5-f54r/GHSA-52p3-pmr5-f54r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-52qr-28j9-p9j3/GHSA-52qr-28j9-p9j3.json b/advisories/unreviewed/2022/05/GHSA-52qr-28j9-p9j3/GHSA-52qr-28j9-p9j3.json index fbb80823160..29dc11d52f6 100644 --- a/advisories/unreviewed/2022/05/GHSA-52qr-28j9-p9j3/GHSA-52qr-28j9-p9j3.json +++ b/advisories/unreviewed/2022/05/GHSA-52qr-28j9-p9j3/GHSA-52qr-28j9-p9j3.json @@ -7,12 +7,8 @@ "CVE-2019-11151" ], "details": "Memory corruption issues in Intel(R) WIFI Drivers before version 21.40 may allow a privileged user to potentially enable escalation of privilege, denial of service, and information disclosure via local access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-538g-8rx5-rhf7/GHSA-538g-8rx5-rhf7.json b/advisories/unreviewed/2022/05/GHSA-538g-8rx5-rhf7/GHSA-538g-8rx5-rhf7.json index a76512a5a80..c56be89e136 100644 --- a/advisories/unreviewed/2022/05/GHSA-538g-8rx5-rhf7/GHSA-538g-8rx5-rhf7.json +++ b/advisories/unreviewed/2022/05/GHSA-538g-8rx5-rhf7/GHSA-538g-8rx5-rhf7.json @@ -7,12 +7,8 @@ "CVE-2019-3663" ], "details": "Unprotected Storage of Credentials vulnerability in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows local attacker to gain access to the root password via accessing sensitive files on the system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-53xg-795p-rwf7/GHSA-53xg-795p-rwf7.json b/advisories/unreviewed/2022/05/GHSA-53xg-795p-rwf7/GHSA-53xg-795p-rwf7.json index cf3b759577a..86c50586dc7 100644 --- a/advisories/unreviewed/2022/05/GHSA-53xg-795p-rwf7/GHSA-53xg-795p-rwf7.json +++ b/advisories/unreviewed/2022/05/GHSA-53xg-795p-rwf7/GHSA-53xg-795p-rwf7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5435-m5p6-wfgc/GHSA-5435-m5p6-wfgc.json b/advisories/unreviewed/2022/05/GHSA-5435-m5p6-wfgc/GHSA-5435-m5p6-wfgc.json index ca1494abf7f..b6eec49221a 100644 --- a/advisories/unreviewed/2022/05/GHSA-5435-m5p6-wfgc/GHSA-5435-m5p6-wfgc.json +++ b/advisories/unreviewed/2022/05/GHSA-5435-m5p6-wfgc/GHSA-5435-m5p6-wfgc.json @@ -7,12 +7,8 @@ "CVE-2019-15447" ], "details": "The Samsung S7 Edge Android device with a build fingerprint of samsung/hero2ltexx/hero2lte:8.0.0/R16NW/G935FXXS4ESC3:user/release-keys contains a pre-installed app with a package name of com.samsung.android.themecenter app (versionCode=7000000, versionName=7.0.0.0) that allows other pre-installed apps to perform app installation via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions that are required by other other pre-installed apps that exported their capabilities to other pre-installed app.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-54cf-8cmw-g4x2/GHSA-54cf-8cmw-g4x2.json b/advisories/unreviewed/2022/05/GHSA-54cf-8cmw-g4x2/GHSA-54cf-8cmw-g4x2.json index aa86130b894..4ae501c42be 100644 --- a/advisories/unreviewed/2022/05/GHSA-54cf-8cmw-g4x2/GHSA-54cf-8cmw-g4x2.json +++ b/advisories/unreviewed/2022/05/GHSA-54cf-8cmw-g4x2/GHSA-54cf-8cmw-g4x2.json @@ -7,12 +7,8 @@ "CVE-2019-15458" ], "details": "The Samsung J7 Neo Android device with a build fingerprint of samsung/j7veltedx/j7velte:8.1.0/M1AJQ/J701FXXS6BSC1:user/release-keys contains a pre-installed app with a package name of com.samsung.android.themecenter app (versionCode=7000100, versionName=7.0.1.0) that allows other pre-installed apps to perform app installation via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions that are required by other other pre-installed apps that exported their capabilities to other pre-installed app.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-553x-q83w-qp8x/GHSA-553x-q83w-qp8x.json b/advisories/unreviewed/2022/05/GHSA-553x-q83w-qp8x/GHSA-553x-q83w-qp8x.json index a9a8a4ba628..0dce53aaa9f 100644 --- a/advisories/unreviewed/2022/05/GHSA-553x-q83w-qp8x/GHSA-553x-q83w-qp8x.json +++ b/advisories/unreviewed/2022/05/GHSA-553x-q83w-qp8x/GHSA-553x-q83w-qp8x.json @@ -7,12 +7,8 @@ "CVE-2019-8211" ], "details": "Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5587-h4wr-6c27/GHSA-5587-h4wr-6c27.json b/advisories/unreviewed/2022/05/GHSA-5587-h4wr-6c27/GHSA-5587-h4wr-6c27.json index 19e0b1710be..d46406d07bf 100644 --- a/advisories/unreviewed/2022/05/GHSA-5587-h4wr-6c27/GHSA-5587-h4wr-6c27.json +++ b/advisories/unreviewed/2022/05/GHSA-5587-h4wr-6c27/GHSA-5587-h4wr-6c27.json @@ -7,12 +7,8 @@ "CVE-2019-15340" ], "details": "The Xiaomi Redmi 6 Pro Android device with a build fingerprint of xiaomi/sakura_india/sakura_india:8.1.0/OPM1.171019.019/V9.6.4.0.ODMMIFD:user/release-keys contains a pre-installed app with a package name of com.huaqin.factory app (versionCode=1, versionName=QL1715_201805292006) that allows any app co-located on the device to programmatically disable and enable Wi-Fi, Bluetooth, and GPS without the corresponding access permission through an exported interface.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-55xj-wwj5-fpc9/GHSA-55xj-wwj5-fpc9.json b/advisories/unreviewed/2022/05/GHSA-55xj-wwj5-fpc9/GHSA-55xj-wwj5-fpc9.json index dee0e814c52..f410d17d2b5 100644 --- a/advisories/unreviewed/2022/05/GHSA-55xj-wwj5-fpc9/GHSA-55xj-wwj5-fpc9.json +++ b/advisories/unreviewed/2022/05/GHSA-55xj-wwj5-fpc9/GHSA-55xj-wwj5-fpc9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-563p-6h7j-cxg6/GHSA-563p-6h7j-cxg6.json b/advisories/unreviewed/2022/05/GHSA-563p-6h7j-cxg6/GHSA-563p-6h7j-cxg6.json index 3babcc0da6c..b748b17ffe7 100644 --- a/advisories/unreviewed/2022/05/GHSA-563p-6h7j-cxg6/GHSA-563p-6h7j-cxg6.json +++ b/advisories/unreviewed/2022/05/GHSA-563p-6h7j-cxg6/GHSA-563p-6h7j-cxg6.json @@ -7,12 +7,8 @@ "CVE-2019-19204" ], "details": "An issue was discovered in Oniguruma 6.x before 6.9.4_rc2. In the function fetch_interval_quantifier (formerly known as fetch_range_quantifier) in regparse.c, PFETCH is called without checking PEND. This leads to a heap-based buffer over-read.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-56wg-2vx4-q6pc/GHSA-56wg-2vx4-q6pc.json b/advisories/unreviewed/2022/05/GHSA-56wg-2vx4-q6pc/GHSA-56wg-2vx4-q6pc.json index 91dad7b6491..f2b58e3e89e 100644 --- a/advisories/unreviewed/2022/05/GHSA-56wg-2vx4-q6pc/GHSA-56wg-2vx4-q6pc.json +++ b/advisories/unreviewed/2022/05/GHSA-56wg-2vx4-q6pc/GHSA-56wg-2vx4-q6pc.json @@ -7,12 +7,8 @@ "CVE-2006-5036" ], "details": "** DISPUTED ** MySource Matrix 3.8 and earlier, and MySource 2.x, allow remote attackers to use the application as an HTTP proxy server via the sq_remote_page_url parameter to access arbitrary sites with the server's IP address and conduct cross-site scripting (XSS) attacks. NOTE: the researcher reports that \"The vendor does not consider this a vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-57hq-h3c4-rr57/GHSA-57hq-h3c4-rr57.json b/advisories/unreviewed/2022/05/GHSA-57hq-h3c4-rr57/GHSA-57hq-h3c4-rr57.json index a9e6924827c..6ab5f13f1ca 100644 --- a/advisories/unreviewed/2022/05/GHSA-57hq-h3c4-rr57/GHSA-57hq-h3c4-rr57.json +++ b/advisories/unreviewed/2022/05/GHSA-57hq-h3c4-rr57/GHSA-57hq-h3c4-rr57.json @@ -7,12 +7,8 @@ "CVE-2019-5508" ], "details": "Clustered Data ONTAP versions 9.2 through 9.6 are susceptible to a vulnerability which allows an attacker to use l2ping to cause a Denial of Service (DoS).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5867-rmrm-f76w/GHSA-5867-rmrm-f76w.json b/advisories/unreviewed/2022/05/GHSA-5867-rmrm-f76w/GHSA-5867-rmrm-f76w.json index 41403bacc3e..b2c73b2abe0 100644 --- a/advisories/unreviewed/2022/05/GHSA-5867-rmrm-f76w/GHSA-5867-rmrm-f76w.json +++ b/advisories/unreviewed/2022/05/GHSA-5867-rmrm-f76w/GHSA-5867-rmrm-f76w.json @@ -7,12 +7,8 @@ "CVE-2019-15386" ], "details": "The Lava Z60s Android device with a build fingerprint of LAVA/Z60s/Z60s:8.1.0/O11019/1530331229:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-58jj-r56x-g9m7/GHSA-58jj-r56x-g9m7.json b/advisories/unreviewed/2022/05/GHSA-58jj-r56x-g9m7/GHSA-58jj-r56x-g9m7.json index 0561c610b7b..55b0b789e80 100644 --- a/advisories/unreviewed/2022/05/GHSA-58jj-r56x-g9m7/GHSA-58jj-r56x-g9m7.json +++ b/advisories/unreviewed/2022/05/GHSA-58jj-r56x-g9m7/GHSA-58jj-r56x-g9m7.json @@ -7,12 +7,8 @@ "CVE-2019-18884" ], "details": "index.php/team_members/add_team_member in RISE Ultimate Project Manager 2.3 has CSRF for adding authorized users.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-58rr-xmg9-55j4/GHSA-58rr-xmg9-55j4.json b/advisories/unreviewed/2022/05/GHSA-58rr-xmg9-55j4/GHSA-58rr-xmg9-55j4.json index 639c05c1e02..15519ef6f0c 100644 --- a/advisories/unreviewed/2022/05/GHSA-58rr-xmg9-55j4/GHSA-58rr-xmg9-55j4.json +++ b/advisories/unreviewed/2022/05/GHSA-58rr-xmg9-55j4/GHSA-58rr-xmg9-55j4.json @@ -7,12 +7,8 @@ "CVE-2006-5097" ], "details": "** DISPUTED ** PHP remote file inclusion vulnerability in index.php in net2ftp, possibly 0.1 through 0.62, allows remote attackers to execute arbitrary PHP code via a URL in the application_rootdir parameter. NOTE: this issue has been disputed by a third party researcher, CVE, and the vendor. The vendor says \"the variable is set in settings.inc.php, so this is not a vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-59g7-r33p-jwx9/GHSA-59g7-r33p-jwx9.json b/advisories/unreviewed/2022/05/GHSA-59g7-r33p-jwx9/GHSA-59g7-r33p-jwx9.json index a1de82f1b09..da6bc678ae5 100644 --- a/advisories/unreviewed/2022/05/GHSA-59g7-r33p-jwx9/GHSA-59g7-r33p-jwx9.json +++ b/advisories/unreviewed/2022/05/GHSA-59g7-r33p-jwx9/GHSA-59g7-r33p-jwx9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-59j5-29xr-8w22/GHSA-59j5-29xr-8w22.json b/advisories/unreviewed/2022/05/GHSA-59j5-29xr-8w22/GHSA-59j5-29xr-8w22.json index 0133dc14430..73a973c77cc 100644 --- a/advisories/unreviewed/2022/05/GHSA-59j5-29xr-8w22/GHSA-59j5-29xr-8w22.json +++ b/advisories/unreviewed/2022/05/GHSA-59j5-29xr-8w22/GHSA-59j5-29xr-8w22.json @@ -7,12 +7,8 @@ "CVE-2019-15449" ], "details": "The Samsung S7 Edge Android device with a build fingerprint of samsung/hero2ltexx/hero2lte:8.0.0/R16NW/G935FXXS4ESC3:user/release-keys contains a pre-installed app with a package name of com.samsung.android.themecenter app (versionCode=7000000, versionName=7.0.0.0) that allows other pre-installed apps to perform app installation via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions that are required by other other pre-installed apps that exported their capabilities to other pre-installed app.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5cp9-87g7-4gq9/GHSA-5cp9-87g7-4gq9.json b/advisories/unreviewed/2022/05/GHSA-5cp9-87g7-4gq9/GHSA-5cp9-87g7-4gq9.json index 42ffd7a1795..d7030c07c9d 100644 --- a/advisories/unreviewed/2022/05/GHSA-5cp9-87g7-4gq9/GHSA-5cp9-87g7-4gq9.json +++ b/advisories/unreviewed/2022/05/GHSA-5cp9-87g7-4gq9/GHSA-5cp9-87g7-4gq9.json @@ -7,12 +7,8 @@ "CVE-2019-15438" ], "details": "The Samsung XCover4 Android device with a build fingerprint of samsung/xcover4ltedo/xcover4lte:8.1.0/M1AJQ/G390YDXU2BSA1:user/release-keys contains a pre-installed app with a package name of com.samsung.android.themecenter app (versionCode=7000100, versionName=7.0.1.0) that allows other pre-installed apps to perform app installation via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions that are required by other other pre-installed apps that exported their capabilities to other pre-installed app.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5g8q-2rxm-mv77/GHSA-5g8q-2rxm-mv77.json b/advisories/unreviewed/2022/05/GHSA-5g8q-2rxm-mv77/GHSA-5g8q-2rxm-mv77.json index fbcbec64056..38e3bc66a8d 100644 --- a/advisories/unreviewed/2022/05/GHSA-5g8q-2rxm-mv77/GHSA-5g8q-2rxm-mv77.json +++ b/advisories/unreviewed/2022/05/GHSA-5g8q-2rxm-mv77/GHSA-5g8q-2rxm-mv77.json @@ -7,12 +7,8 @@ "CVE-2019-8218" ], "details": "Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure .", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5gr8-3x59-27j9/GHSA-5gr8-3x59-27j9.json b/advisories/unreviewed/2022/05/GHSA-5gr8-3x59-27j9/GHSA-5gr8-3x59-27j9.json index 99b38186e85..1be7074c4a3 100644 --- a/advisories/unreviewed/2022/05/GHSA-5gr8-3x59-27j9/GHSA-5gr8-3x59-27j9.json +++ b/advisories/unreviewed/2022/05/GHSA-5gr8-3x59-27j9/GHSA-5gr8-3x59-27j9.json @@ -7,12 +7,8 @@ "CVE-2019-15337" ], "details": "The Lava Z81 Android device with a build fingerprint of LAVA/Z81/Z81:8.1.0/O11019/1532317309:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionName=v4.0.31) that allows any app co-located on the device to programmatically disable and enable Wi-Fi without the corresponding access permission through an exported interface.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5hhg-c67q-pxx6/GHSA-5hhg-c67q-pxx6.json b/advisories/unreviewed/2022/05/GHSA-5hhg-c67q-pxx6/GHSA-5hhg-c67q-pxx6.json index 9a33f9c91d9..0b7d10be573 100644 --- a/advisories/unreviewed/2022/05/GHSA-5hhg-c67q-pxx6/GHSA-5hhg-c67q-pxx6.json +++ b/advisories/unreviewed/2022/05/GHSA-5hhg-c67q-pxx6/GHSA-5hhg-c67q-pxx6.json @@ -7,12 +7,8 @@ "CVE-2019-18929" ], "details": "Western Digital My Cloud EX2 Ultra firmware 2.31.183 allows web users (including guest accounts) to remotely execute arbitrary code via a download_mgr.cgi stack-based buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5hp5-x426-cxjg/GHSA-5hp5-x426-cxjg.json b/advisories/unreviewed/2022/05/GHSA-5hp5-x426-cxjg/GHSA-5hp5-x426-cxjg.json index 79447afb9f1..db1c5150e96 100644 --- a/advisories/unreviewed/2022/05/GHSA-5hp5-x426-cxjg/GHSA-5hp5-x426-cxjg.json +++ b/advisories/unreviewed/2022/05/GHSA-5hp5-x426-cxjg/GHSA-5hp5-x426-cxjg.json @@ -7,12 +7,8 @@ "CVE-2006-2057" ], "details": "Argument injection vulnerability in Mozilla Firefox 1.0.6 allows user-assisted remote attackers to modify command line arguments to an invoked mail client via \" (double quote) characters in a mailto: scheme handler, as demonstrated by launching Microsoft Outlook with an arbitrary filename as an attachment. NOTE: it is not clear whether this issue is implementation-specific or a problem in the Microsoft API.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5j44-68pq-m8v8/GHSA-5j44-68pq-m8v8.json b/advisories/unreviewed/2022/05/GHSA-5j44-68pq-m8v8/GHSA-5j44-68pq-m8v8.json index f65f3d6cf15..c35740813ec 100644 --- a/advisories/unreviewed/2022/05/GHSA-5j44-68pq-m8v8/GHSA-5j44-68pq-m8v8.json +++ b/advisories/unreviewed/2022/05/GHSA-5j44-68pq-m8v8/GHSA-5j44-68pq-m8v8.json @@ -7,12 +7,8 @@ "CVE-2019-15409" ], "details": "The Asus ZenFone 5Q Android device with a build fingerprint of asus/WW_Phone/ASUS_X017D_2:7.1.1/NGI77B/14.0400.1809.059-20181016:user/release-keys contains a pre-installed app with a package name of com.asus.loguploaderproxy app (versionCode=1570000020, versionName=7.0.0.4_170901) that allows other pre-installed apps to perform command execution via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions that are required by other other pre-installed apps that exported their capabilities to other pre-installed app.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5jrj-gcpg-jg2g/GHSA-5jrj-gcpg-jg2g.json b/advisories/unreviewed/2022/05/GHSA-5jrj-gcpg-jg2g/GHSA-5jrj-gcpg-jg2g.json index 5dec0c94a8f..730176bacf1 100644 --- a/advisories/unreviewed/2022/05/GHSA-5jrj-gcpg-jg2g/GHSA-5jrj-gcpg-jg2g.json +++ b/advisories/unreviewed/2022/05/GHSA-5jrj-gcpg-jg2g/GHSA-5jrj-gcpg-jg2g.json @@ -7,12 +7,8 @@ "CVE-2019-16967" ], "details": "An issue was discovered in Manager 13.x before 13.0.2.6 and 15.x before 15.0.6 before FreePBX 14.0.10.3. In the Manager module form (html\\admin\\modules\\manager\\views\\form.php), an unsanitized managerdisplay variable coming from the URL is reflected in HTML, leading to XSS. It can be requested via GET request to /config.php?type=tool&display=manager.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5m34-66pw-cq8v/GHSA-5m34-66pw-cq8v.json b/advisories/unreviewed/2022/05/GHSA-5m34-66pw-cq8v/GHSA-5m34-66pw-cq8v.json index d906f5dfd6b..4dc5004acb4 100644 --- a/advisories/unreviewed/2022/05/GHSA-5m34-66pw-cq8v/GHSA-5m34-66pw-cq8v.json +++ b/advisories/unreviewed/2022/05/GHSA-5m34-66pw-cq8v/GHSA-5m34-66pw-cq8v.json @@ -7,12 +7,8 @@ "CVE-2019-1426" ], "details": "A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge (HTML-based), aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1427, CVE-2019-1428, CVE-2019-1429.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5mw4-3wv8-9jc4/GHSA-5mw4-3wv8-9jc4.json b/advisories/unreviewed/2022/05/GHSA-5mw4-3wv8-9jc4/GHSA-5mw4-3wv8-9jc4.json index 922f6e81600..28d5a90ce16 100644 --- a/advisories/unreviewed/2022/05/GHSA-5mw4-3wv8-9jc4/GHSA-5mw4-3wv8-9jc4.json +++ b/advisories/unreviewed/2022/05/GHSA-5mw4-3wv8-9jc4/GHSA-5mw4-3wv8-9jc4.json @@ -7,12 +7,8 @@ "CVE-2019-15350" ], "details": "The Tecno Camon Android device with a build fingerprint of TECNO/H622/TECNO-ID5b:8.1.0/O11019/G-180829V31:user/release-keys contains a pre-installed platform app with a package name of com.lovelyfont.defcontainer (versionCode=7, versionName=7.0.11). This app contains an exported service named com.lovelyfont.manager.service.FunctionService that allows any app co-located on the device to supply the file path to a Dalvik Executable (DEX) file which it will dynamically load within its own process and execute in with its own system privileges. This app cannot be disabled by the user and the attack can be performed by a zero-permission app. Executing commands as the system user can allow a third-party app to video record the user's screen, factory reset the device, obtain the user's notifications, read the logcat logs, inject events in the Graphical User Interface (GUI), and obtains the user's text messages, and more. Executing code as the system user can allow a third-party app to factory reset the device, obtain the user's Wi-Fi passwords, obtain the user's notifications, read the logcat logs, inject events in the GUI, change the default Input Method Editor (IME) (e.g., keyboard) with one contained within the attacking app that contains keylogging functionality, and obtains the user's text messages, and more.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5p6f-33wg-988q/GHSA-5p6f-33wg-988q.json b/advisories/unreviewed/2022/05/GHSA-5p6f-33wg-988q/GHSA-5p6f-33wg-988q.json index c766ff46e23..95030122188 100644 --- a/advisories/unreviewed/2022/05/GHSA-5p6f-33wg-988q/GHSA-5p6f-33wg-988q.json +++ b/advisories/unreviewed/2022/05/GHSA-5p6f-33wg-988q/GHSA-5p6f-33wg-988q.json @@ -7,12 +7,8 @@ "CVE-2019-8214" ], "details": "Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5r9p-3grc-7gc5/GHSA-5r9p-3grc-7gc5.json b/advisories/unreviewed/2022/05/GHSA-5r9p-3grc-7gc5/GHSA-5r9p-3grc-7gc5.json index 8292b643290..6beacfe8465 100644 --- a/advisories/unreviewed/2022/05/GHSA-5r9p-3grc-7gc5/GHSA-5r9p-3grc-7gc5.json +++ b/advisories/unreviewed/2022/05/GHSA-5r9p-3grc-7gc5/GHSA-5r9p-3grc-7gc5.json @@ -7,12 +7,8 @@ "CVE-2019-15453" ], "details": "The Samsung J4 Android device with a build fingerprint of samsung/j4lteub/j4lte:8.0.0/R16NW/J400MUBS2ASC2:user/release-keys contains a pre-installed app with a package name of com.samsung.android.themecenter app (versionCode=7000000, versionName=7.0.0.0) that allows other pre-installed apps to perform app installation via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions that are required by other other pre-installed apps that exported their capabilities to other pre-installed app.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5v5q-rgc6-m3mx/GHSA-5v5q-rgc6-m3mx.json b/advisories/unreviewed/2022/05/GHSA-5v5q-rgc6-m3mx/GHSA-5v5q-rgc6-m3mx.json index bc65d31579d..5db3db1f028 100644 --- a/advisories/unreviewed/2022/05/GHSA-5v5q-rgc6-m3mx/GHSA-5v5q-rgc6-m3mx.json +++ b/advisories/unreviewed/2022/05/GHSA-5v5q-rgc6-m3mx/GHSA-5v5q-rgc6-m3mx.json @@ -7,12 +7,8 @@ "CVE-2019-2206" ], "details": "In rw_i93_sm_set_read_only of rw_i93.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution over NFC with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-139188579", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5vjx-25rg-wwch/GHSA-5vjx-25rg-wwch.json b/advisories/unreviewed/2022/05/GHSA-5vjx-25rg-wwch/GHSA-5vjx-25rg-wwch.json index 5fc9b5d03c5..8491e2d3562 100644 --- a/advisories/unreviewed/2022/05/GHSA-5vjx-25rg-wwch/GHSA-5vjx-25rg-wwch.json +++ b/advisories/unreviewed/2022/05/GHSA-5vjx-25rg-wwch/GHSA-5vjx-25rg-wwch.json @@ -7,12 +7,8 @@ "CVE-2019-16874" ], "details": "Portainer before 1.22.1 has Incorrect Access Control (issue 2 of 4).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5w52-qrhj-grg8/GHSA-5w52-qrhj-grg8.json b/advisories/unreviewed/2022/05/GHSA-5w52-qrhj-grg8/GHSA-5w52-qrhj-grg8.json index ae5d1aaef9e..bfc4455038d 100644 --- a/advisories/unreviewed/2022/05/GHSA-5w52-qrhj-grg8/GHSA-5w52-qrhj-grg8.json +++ b/advisories/unreviewed/2022/05/GHSA-5w52-qrhj-grg8/GHSA-5w52-qrhj-grg8.json @@ -7,12 +7,8 @@ "CVE-2019-5537" ], "details": "Sensitive information disclosure vulnerability resulting from a lack of certificate validation during the File-Based Backup and Restore operations of VMware vCenter Server Appliance (6.7 before 6.7u3a and 6.5 before 6.5u3d) may allow a malicious actor to intercept sensitive data in transit over FTPS and HTTPS. A malicious actor with man-in-the-middle positioning between vCenter Server Appliance and a backup target may be able to intercept sensitive data in transit during File-Based Backup and Restore operations.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5w77-g25x-2w9f/GHSA-5w77-g25x-2w9f.json b/advisories/unreviewed/2022/05/GHSA-5w77-g25x-2w9f/GHSA-5w77-g25x-2w9f.json index 0abed4df6c9..5df07727b4e 100644 --- a/advisories/unreviewed/2022/05/GHSA-5w77-g25x-2w9f/GHSA-5w77-g25x-2w9f.json +++ b/advisories/unreviewed/2022/05/GHSA-5w77-g25x-2w9f/GHSA-5w77-g25x-2w9f.json @@ -7,12 +7,8 @@ "CVE-2019-15376" ], "details": "The Panasonic Eluga Ray 530 Android device with a build fingerprint of Panasonic/ELUGA_Ray_530/ELUGA_Ray_530:8.1.0/O11019/1531828974:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5wfx-x267-4p7r/GHSA-5wfx-x267-4p7r.json b/advisories/unreviewed/2022/05/GHSA-5wfx-x267-4p7r/GHSA-5wfx-x267-4p7r.json index 6b61058ad0a..27a1484d1ac 100644 --- a/advisories/unreviewed/2022/05/GHSA-5wfx-x267-4p7r/GHSA-5wfx-x267-4p7r.json +++ b/advisories/unreviewed/2022/05/GHSA-5wfx-x267-4p7r/GHSA-5wfx-x267-4p7r.json @@ -7,12 +7,8 @@ "CVE-2006-3015" ], "details": "Argument injection vulnerability in WinSCP 3.8.1 build 328 allows remote attackers to upload or download arbitrary files via encoded spaces and double-quote characters in a scp or sftp URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5wq7-25gj-8g3x/GHSA-5wq7-25gj-8g3x.json b/advisories/unreviewed/2022/05/GHSA-5wq7-25gj-8g3x/GHSA-5wq7-25gj-8g3x.json index 4fb9c6400a6..4a7c6ec7106 100644 --- a/advisories/unreviewed/2022/05/GHSA-5wq7-25gj-8g3x/GHSA-5wq7-25gj-8g3x.json +++ b/advisories/unreviewed/2022/05/GHSA-5wq7-25gj-8g3x/GHSA-5wq7-25gj-8g3x.json @@ -7,12 +7,8 @@ "CVE-2019-15430" ], "details": "The Bluboo D3 Pro Android device with a build fingerprint of BLUBOO/Bluboo_D2_Pro/Bluboo_D2_Pro:7.0/NRD90M/1510370501:user/release-keys contains a pre-installed app with a package name of com.qiku.cleaner app (versionCode=2, versionName=2.0.0_VER_32516508295515) that allows other pre-installed apps to perform system properties modification via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions that are required by other other pre-installed apps that exported their capabilities to other pre-installed app.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5xrg-q368-r3h9/GHSA-5xrg-q368-r3h9.json b/advisories/unreviewed/2022/05/GHSA-5xrg-q368-r3h9/GHSA-5xrg-q368-r3h9.json index c9463f6c495..6e10273d155 100644 --- a/advisories/unreviewed/2022/05/GHSA-5xrg-q368-r3h9/GHSA-5xrg-q368-r3h9.json +++ b/advisories/unreviewed/2022/05/GHSA-5xrg-q368-r3h9/GHSA-5xrg-q368-r3h9.json @@ -7,12 +7,8 @@ "CVE-2019-17360" ], "details": "A vulnerability in Hitachi Command Suite 7.x and 8.x before 8.7.0-00 allows an unauthenticated remote user to trigger a denial of service (DoS) condition because of Uncontrolled Resource Consumption.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5xwg-wm9f-vxm7/GHSA-5xwg-wm9f-vxm7.json b/advisories/unreviewed/2022/05/GHSA-5xwg-wm9f-vxm7/GHSA-5xwg-wm9f-vxm7.json index 9d7ba660c56..9e8979f82dc 100644 --- a/advisories/unreviewed/2022/05/GHSA-5xwg-wm9f-vxm7/GHSA-5xwg-wm9f-vxm7.json +++ b/advisories/unreviewed/2022/05/GHSA-5xwg-wm9f-vxm7/GHSA-5xwg-wm9f-vxm7.json @@ -7,12 +7,8 @@ "CVE-2019-15446" ], "details": "The Samsung S7 Android device with a build fingerprint of samsung/heroltexx/herolte:8.0.0/R16NW/G930FXXU3ESAC:user/release-keys contains a pre-installed app with a package name of com.samsung.android.themecenter app (versionCode=7000000, versionName=7.0.0.0) that allows other pre-installed apps to perform app installation via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions that are required by other other pre-installed apps that exported their capabilities to other pre-installed app.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-65w5-rcgr-gxgj/GHSA-65w5-rcgr-gxgj.json b/advisories/unreviewed/2022/05/GHSA-65w5-rcgr-gxgj/GHSA-65w5-rcgr-gxgj.json index bb52584b44f..f3340582b03 100644 --- a/advisories/unreviewed/2022/05/GHSA-65w5-rcgr-gxgj/GHSA-65w5-rcgr-gxgj.json +++ b/advisories/unreviewed/2022/05/GHSA-65w5-rcgr-gxgj/GHSA-65w5-rcgr-gxgj.json @@ -7,12 +7,8 @@ "CVE-2015-3166" ], "details": "The snprintf implementation in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 does not properly handle system-call errors, which allows attackers to obtain sensitive information or have other unspecified impact via unknown vectors, as demonstrated by an out-of-memory error.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6827-9qw6-v2rx/GHSA-6827-9qw6-v2rx.json b/advisories/unreviewed/2022/05/GHSA-6827-9qw6-v2rx/GHSA-6827-9qw6-v2rx.json index f25c093aab4..469ae77b953 100644 --- a/advisories/unreviewed/2022/05/GHSA-6827-9qw6-v2rx/GHSA-6827-9qw6-v2rx.json +++ b/advisories/unreviewed/2022/05/GHSA-6827-9qw6-v2rx/GHSA-6827-9qw6-v2rx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-695w-cgfw-4hf5/GHSA-695w-cgfw-4hf5.json b/advisories/unreviewed/2022/05/GHSA-695w-cgfw-4hf5/GHSA-695w-cgfw-4hf5.json index af2668288d1..a5f83d4b2dd 100644 --- a/advisories/unreviewed/2022/05/GHSA-695w-cgfw-4hf5/GHSA-695w-cgfw-4hf5.json +++ b/advisories/unreviewed/2022/05/GHSA-695w-cgfw-4hf5/GHSA-695w-cgfw-4hf5.json @@ -7,12 +7,8 @@ "CVE-2019-11177" ], "details": "Unhandled exception in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable denial of service via network access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-69fc-9h84-j223/GHSA-69fc-9h84-j223.json b/advisories/unreviewed/2022/05/GHSA-69fc-9h84-j223/GHSA-69fc-9h84-j223.json index 6b6194b7571..2a5ba222c25 100644 --- a/advisories/unreviewed/2022/05/GHSA-69fc-9h84-j223/GHSA-69fc-9h84-j223.json +++ b/advisories/unreviewed/2022/05/GHSA-69fc-9h84-j223/GHSA-69fc-9h84-j223.json @@ -7,12 +7,8 @@ "CVE-2019-2192" ], "details": "In call of SliceProvider.java, there is a possible permissions bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10Android ID: A-138441555", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-69mx-qrf7-x3ww/GHSA-69mx-qrf7-x3ww.json b/advisories/unreviewed/2022/05/GHSA-69mx-qrf7-x3ww/GHSA-69mx-qrf7-x3ww.json index 4992c52cc99..56bd3c7258e 100644 --- a/advisories/unreviewed/2022/05/GHSA-69mx-qrf7-x3ww/GHSA-69mx-qrf7-x3ww.json +++ b/advisories/unreviewed/2022/05/GHSA-69mx-qrf7-x3ww/GHSA-69mx-qrf7-x3ww.json @@ -7,12 +7,8 @@ "CVE-2019-15336" ], "details": "The Lava Z61 Turbo Android device with a build fingerprint of LAVA/Z61_Turbo/Z61_Turbo:8.1.0/O11019/1536917928:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionName=v4.0.31) that allows any app co-located on the device to programmatically disable and enable Wi-Fi without the corresponding access permission through an exported interface.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6c5q-h46j-p8gq/GHSA-6c5q-h46j-p8gq.json b/advisories/unreviewed/2022/05/GHSA-6c5q-h46j-p8gq/GHSA-6c5q-h46j-p8gq.json index f2e292f5d5a..a9a18709c41 100644 --- a/advisories/unreviewed/2022/05/GHSA-6c5q-h46j-p8gq/GHSA-6c5q-h46j-p8gq.json +++ b/advisories/unreviewed/2022/05/GHSA-6c5q-h46j-p8gq/GHSA-6c5q-h46j-p8gq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6crv-347w-476c/GHSA-6crv-347w-476c.json b/advisories/unreviewed/2022/05/GHSA-6crv-347w-476c/GHSA-6crv-347w-476c.json index 5442d272949..34bbaf6cbf2 100644 --- a/advisories/unreviewed/2022/05/GHSA-6crv-347w-476c/GHSA-6crv-347w-476c.json +++ b/advisories/unreviewed/2022/05/GHSA-6crv-347w-476c/GHSA-6crv-347w-476c.json @@ -7,12 +7,8 @@ "CVE-2015-9535" ], "details": "The Easy Digital Downloads (EDD) Shoppette theme for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6fg6-6393-xqhq/GHSA-6fg6-6393-xqhq.json b/advisories/unreviewed/2022/05/GHSA-6fg6-6393-xqhq/GHSA-6fg6-6393-xqhq.json index c2564923886..80bd5bafc16 100644 --- a/advisories/unreviewed/2022/05/GHSA-6fg6-6393-xqhq/GHSA-6fg6-6393-xqhq.json +++ b/advisories/unreviewed/2022/05/GHSA-6fg6-6393-xqhq/GHSA-6fg6-6393-xqhq.json @@ -7,12 +7,8 @@ "CVE-2019-17391" ], "details": "An issue was discovered in the Espressif ESP32 mask ROM code 2016-06-08 0 through 2. Lack of anti-glitch mitigations in the first stage bootloader of the ESP32 chip allows an attacker (with physical access to the device) to read the contents of read-protected eFuses, such as flash encryption and secure boot keys, by injecting a glitch into the power supply of the chip shortly after reset.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6fxw-qwjv-mxvm/GHSA-6fxw-qwjv-mxvm.json b/advisories/unreviewed/2022/05/GHSA-6fxw-qwjv-mxvm/GHSA-6fxw-qwjv-mxvm.json index 65c2968f850..e6cc5557a51 100644 --- a/advisories/unreviewed/2022/05/GHSA-6fxw-qwjv-mxvm/GHSA-6fxw-qwjv-mxvm.json +++ b/advisories/unreviewed/2022/05/GHSA-6fxw-qwjv-mxvm/GHSA-6fxw-qwjv-mxvm.json @@ -7,12 +7,8 @@ "CVE-2019-15378" ], "details": "The Panasonic Eluga Ray 600 Android device with a build fingerprint of Panasonic/ELUGA_Ray_600/ELUGA_Ray_600:8.1.0/O11019/1532692680:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6hf7-c47c-6x43/GHSA-6hf7-c47c-6x43.json b/advisories/unreviewed/2022/05/GHSA-6hf7-c47c-6x43/GHSA-6hf7-c47c-6x43.json index e6f99d27a2a..f1dcc26063d 100644 --- a/advisories/unreviewed/2022/05/GHSA-6hf7-c47c-6x43/GHSA-6hf7-c47c-6x43.json +++ b/advisories/unreviewed/2022/05/GHSA-6hf7-c47c-6x43/GHSA-6hf7-c47c-6x43.json @@ -7,12 +7,8 @@ "CVE-2019-15389" ], "details": "The Haier A6 Android device with a build fingerprint of Haier/A6/A6:8.1.0/O11019/1534219877:userdebug/release-keys contains a pre-installed platform app with a package name of com.lovelyfont.defcontainer (versionCode=7, versionName=7.1.13). This app contains an exported service named com.lovelyfont.manager.FontCoverService that allows any app co-located on the device to supply arbitrary commands to be executed as the system user. This app cannot be disabled by the user and the attack can be performed by a zero-permission app. In addition to the local attack surface, its accompanying app with a package name of com.ekesoo.lovelyhifonts makes network requests using HTTP and an attacker can perform a Man-in-the-Middle (MITM) attack on the connection to inject a command in a network response that will be executed as the system user by the com.lovelyfont.defcontainer app. Executing commands as the system user can allow a third-party app to video record the user's screen, factory reset the device, obtain the user's notifications, read the logcat logs, inject events in the Graphical User Interface (GUI), and obtains the user's text messages, and more. Executing commands as the system user can allow a third-party app to factory reset the device, obtain the user's notifications, read the logcat logs, inject events in the GUI, change the default Input Method Editor (IME) (e.g., keyboard) with one contained within the attacking app that contains keylogging functionality, and obtains the user's text messages, and more.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6j4m-pp4h-r44g/GHSA-6j4m-pp4h-r44g.json b/advisories/unreviewed/2022/05/GHSA-6j4m-pp4h-r44g/GHSA-6j4m-pp4h-r44g.json index 366580555e0..cc442af215e 100644 --- a/advisories/unreviewed/2022/05/GHSA-6j4m-pp4h-r44g/GHSA-6j4m-pp4h-r44g.json +++ b/advisories/unreviewed/2022/05/GHSA-6j4m-pp4h-r44g/GHSA-6j4m-pp4h-r44g.json @@ -7,12 +7,8 @@ "CVE-2019-0391" ], "details": "Under certain conditions SAP NetWeaver AS Java (corrected in 7.10, 7.20, 7.30, 7.31, 7.40, 7.50) allows an attacker to access information which would otherwise be restricted.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6j53-rvq8-q9pr/GHSA-6j53-rvq8-q9pr.json b/advisories/unreviewed/2022/05/GHSA-6j53-rvq8-q9pr/GHSA-6j53-rvq8-q9pr.json index 58e8f024851..3dfad7de2cd 100644 --- a/advisories/unreviewed/2022/05/GHSA-6j53-rvq8-q9pr/GHSA-6j53-rvq8-q9pr.json +++ b/advisories/unreviewed/2022/05/GHSA-6j53-rvq8-q9pr/GHSA-6j53-rvq8-q9pr.json @@ -7,12 +7,8 @@ "CVE-2019-13553" ], "details": "Rittal Chiller SK 3232-Series web interface as built upon Carel pCOWeb firmware A1.5.3 ? B1.2.4. The authentication mechanism on affected systems is configured using hard-coded credentials. These credentials could allow attackers to influence the primary operations of the affected systems, namely turning the cooling unit on and off and setting the temperature set point.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6jvj-39c6-mh4m/GHSA-6jvj-39c6-mh4m.json b/advisories/unreviewed/2022/05/GHSA-6jvj-39c6-mh4m/GHSA-6jvj-39c6-mh4m.json index ff6f0b5967e..e9e6113385a 100644 --- a/advisories/unreviewed/2022/05/GHSA-6jvj-39c6-mh4m/GHSA-6jvj-39c6-mh4m.json +++ b/advisories/unreviewed/2022/05/GHSA-6jvj-39c6-mh4m/GHSA-6jvj-39c6-mh4m.json @@ -7,12 +7,8 @@ "CVE-2009-3232" ], "details": "pam-auth-update for PAM, as used in Ubuntu 8.10 and 9.4, and Debian GNU/Linux, does not properly handle an \"empty selection\" for system authentication modules in certain rare configurations, which causes any attempt to be successful and allows remote attackers to bypass authentication.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6mp7-qvw5-r9h4/GHSA-6mp7-qvw5-r9h4.json b/advisories/unreviewed/2022/05/GHSA-6mp7-qvw5-r9h4/GHSA-6mp7-qvw5-r9h4.json index c5d25acd914..c15d2fd964e 100644 --- a/advisories/unreviewed/2022/05/GHSA-6mp7-qvw5-r9h4/GHSA-6mp7-qvw5-r9h4.json +++ b/advisories/unreviewed/2022/05/GHSA-6mp7-qvw5-r9h4/GHSA-6mp7-qvw5-r9h4.json @@ -7,12 +7,8 @@ "CVE-2019-0385" ], "details": "SAP Enable Now, before version 1908, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6ph9-24mm-7chj/GHSA-6ph9-24mm-7chj.json b/advisories/unreviewed/2022/05/GHSA-6ph9-24mm-7chj/GHSA-6ph9-24mm-7chj.json index 1e07a720e1f..812d00e7658 100644 --- a/advisories/unreviewed/2022/05/GHSA-6ph9-24mm-7chj/GHSA-6ph9-24mm-7chj.json +++ b/advisories/unreviewed/2022/05/GHSA-6ph9-24mm-7chj/GHSA-6ph9-24mm-7chj.json @@ -7,12 +7,8 @@ "CVE-2019-9491" ], "details": "Trend Micro Anti-Threat Toolkit (ATTK) versions 1.62.0.1218 and below have a vulnerability that may allow an attacker to place malicious files in the same directory, potentially leading to arbitrary remote code execution (RCE) when executed.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6qgm-96gr-qq5m/GHSA-6qgm-96gr-qq5m.json b/advisories/unreviewed/2022/05/GHSA-6qgm-96gr-qq5m/GHSA-6qgm-96gr-qq5m.json index bdf3f078a5a..293fe3058a2 100644 --- a/advisories/unreviewed/2022/05/GHSA-6qgm-96gr-qq5m/GHSA-6qgm-96gr-qq5m.json +++ b/advisories/unreviewed/2022/05/GHSA-6qgm-96gr-qq5m/GHSA-6qgm-96gr-qq5m.json @@ -7,12 +7,8 @@ "CVE-2019-15004" ], "details": "The Customer Context Filter in Atlassian Jira Service Desk Server and Jira Service Desk Data Center before 3.9.17, from 3.10.0 before 3.16.10, from 4.0.0 before 4.2.6, from 4.3.0 before 4.3.5, from 4.4.0 before 4.4.3, and from 4.5.0 before 4.5.1 allows remote attackers with portal access to view arbitrary issues in Jira Service Desk projects via a path traversal vulnerability. Note that when the 'Anyone can email the service desk or raise a request in the portal' setting is enabled, an attacker can grant themselves portal access, allowing them to exploit the vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6qp9-325w-8r9j/GHSA-6qp9-325w-8r9j.json b/advisories/unreviewed/2022/05/GHSA-6qp9-325w-8r9j/GHSA-6qp9-325w-8r9j.json index 73893c835f6..e6ca9127077 100644 --- a/advisories/unreviewed/2022/05/GHSA-6qp9-325w-8r9j/GHSA-6qp9-325w-8r9j.json +++ b/advisories/unreviewed/2022/05/GHSA-6qp9-325w-8r9j/GHSA-6qp9-325w-8r9j.json @@ -7,12 +7,8 @@ "CVE-2019-15356" ], "details": "The Lava Flair Z1 Android device with a build fingerprint of LAVA/Z1/Z1:8.1.0/O11019/1536680131:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6r53-hcrv-h8mp/GHSA-6r53-hcrv-h8mp.json b/advisories/unreviewed/2022/05/GHSA-6r53-hcrv-h8mp/GHSA-6r53-hcrv-h8mp.json index 6cdf922870e..57ddc20ca14 100644 --- a/advisories/unreviewed/2022/05/GHSA-6r53-hcrv-h8mp/GHSA-6r53-hcrv-h8mp.json +++ b/advisories/unreviewed/2022/05/GHSA-6r53-hcrv-h8mp/GHSA-6r53-hcrv-h8mp.json @@ -7,12 +7,8 @@ "CVE-2019-15405" ], "details": "The Asus ASUS_X00K_1 Android device with a build fingerprint of asus/CN_X00K/ASUS_X00K_1:7.0/NRD90M/CN_X00K-14.01.1711.27-20180420:user/release-keys contains a pre-installed app with a package name of com.asus.loguploaderproxy app (versionCode=1570000015, versionName=7.0.0.3_161222) that allows other pre-installed apps to perform command execution via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions that are required by other other pre-installed apps that exported their capabilities to other pre-installed app.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6rpp-7f67-x23f/GHSA-6rpp-7f67-x23f.json b/advisories/unreviewed/2022/05/GHSA-6rpp-7f67-x23f/GHSA-6rpp-7f67-x23f.json index 68421da27fc..141d52c14d0 100644 --- a/advisories/unreviewed/2022/05/GHSA-6rpp-7f67-x23f/GHSA-6rpp-7f67-x23f.json +++ b/advisories/unreviewed/2022/05/GHSA-6rpp-7f67-x23f/GHSA-6rpp-7f67-x23f.json @@ -7,12 +7,8 @@ "CVE-2019-10503" ], "details": "Out-of-bounds access can occur in camera driver due to improper validation of array index in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, MDM9206, MDM9207C, MDM9607, MDM9640, MDM9650, MSM8905, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996AU, MSM8998, QCN7605, SDA660, SDM450, SDM630, SDM636, SDM660, SDX20", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6vg4-jcx5-wm34/GHSA-6vg4-jcx5-wm34.json b/advisories/unreviewed/2022/05/GHSA-6vg4-jcx5-wm34/GHSA-6vg4-jcx5-wm34.json index 0f5e6fff581..5f0feea2134 100644 --- a/advisories/unreviewed/2022/05/GHSA-6vg4-jcx5-wm34/GHSA-6vg4-jcx5-wm34.json +++ b/advisories/unreviewed/2022/05/GHSA-6vg4-jcx5-wm34/GHSA-6vg4-jcx5-wm34.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-723w-74pm-v4fj/GHSA-723w-74pm-v4fj.json b/advisories/unreviewed/2022/05/GHSA-723w-74pm-v4fj/GHSA-723w-74pm-v4fj.json index 0e232950c8f..4a60cc13451 100644 --- a/advisories/unreviewed/2022/05/GHSA-723w-74pm-v4fj/GHSA-723w-74pm-v4fj.json +++ b/advisories/unreviewed/2022/05/GHSA-723w-74pm-v4fj/GHSA-723w-74pm-v4fj.json @@ -7,12 +7,8 @@ "CVE-2006-5037" ], "details": "** DISPUTED ** MySource Matrix after 3.8 allows remote attackers to use the application as an HTTP proxy server via a MIME encoded URL in the sq_content_src parameter to access arbitrary sites with the server's IP address and conduct cross-site scripting (XSS) attacks. NOTE: the researcher reports that \"The vendor does not consider this a vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-725p-65w3-rpp3/GHSA-725p-65w3-rpp3.json b/advisories/unreviewed/2022/05/GHSA-725p-65w3-rpp3/GHSA-725p-65w3-rpp3.json index deb1302903b..8a5cb77a668 100644 --- a/advisories/unreviewed/2022/05/GHSA-725p-65w3-rpp3/GHSA-725p-65w3-rpp3.json +++ b/advisories/unreviewed/2022/05/GHSA-725p-65w3-rpp3/GHSA-725p-65w3-rpp3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-732q-646p-qgpp/GHSA-732q-646p-qgpp.json b/advisories/unreviewed/2022/05/GHSA-732q-646p-qgpp/GHSA-732q-646p-qgpp.json index 52a6858d791..f089f33b471 100644 --- a/advisories/unreviewed/2022/05/GHSA-732q-646p-qgpp/GHSA-732q-646p-qgpp.json +++ b/advisories/unreviewed/2022/05/GHSA-732q-646p-qgpp/GHSA-732q-646p-qgpp.json @@ -7,12 +7,8 @@ "CVE-2019-0382" ], "details": "A Cross-Site Scripting vulnerability exists in SAP BusinessObjects Business Intelligence Platform (Web Intelligence-Publication related pages); corrected in version 4.2. Privileges are required in order to exploit this vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7332-327w-xhcp/GHSA-7332-327w-xhcp.json b/advisories/unreviewed/2022/05/GHSA-7332-327w-xhcp/GHSA-7332-327w-xhcp.json index 20085d42d65..1b3d5e6bdbe 100644 --- a/advisories/unreviewed/2022/05/GHSA-7332-327w-xhcp/GHSA-7332-327w-xhcp.json +++ b/advisories/unreviewed/2022/05/GHSA-7332-327w-xhcp/GHSA-7332-327w-xhcp.json @@ -7,12 +7,8 @@ "CVE-2019-5229" ], "details": "P30 smartphones with versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1) have an insufficient verification vulnerability. The system does not verify certain parameters sufficiently, an attacker should connect to the phone and gain high privilege to launch the attack, successful exploit could cause malicious code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-73fc-m42q-9fv3/GHSA-73fc-m42q-9fv3.json b/advisories/unreviewed/2022/05/GHSA-73fc-m42q-9fv3/GHSA-73fc-m42q-9fv3.json index 0b66c6c015a..4f6988771cc 100644 --- a/advisories/unreviewed/2022/05/GHSA-73fc-m42q-9fv3/GHSA-73fc-m42q-9fv3.json +++ b/advisories/unreviewed/2022/05/GHSA-73fc-m42q-9fv3/GHSA-73fc-m42q-9fv3.json @@ -7,12 +7,8 @@ "CVE-2019-13549" ], "details": "Rittal Chiller SK 3232-Series web interface as built upon Carel pCOWeb firmware A1.5.3 ? B1.2.4. The authentication mechanism on affected systems does not provide a sufficient level of protection against unauthorized configuration changes. Primary operations, namely turning the cooling unit on and off and setting the temperature set point, can be modified without authentication.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-73fw-3gw7-gp67/GHSA-73fw-3gw7-gp67.json b/advisories/unreviewed/2022/05/GHSA-73fw-3gw7-gp67/GHSA-73fw-3gw7-gp67.json index af755f5b6cb..e823a80f632 100644 --- a/advisories/unreviewed/2022/05/GHSA-73fw-3gw7-gp67/GHSA-73fw-3gw7-gp67.json +++ b/advisories/unreviewed/2022/05/GHSA-73fw-3gw7-gp67/GHSA-73fw-3gw7-gp67.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7576-72m9-2cq9/GHSA-7576-72m9-2cq9.json b/advisories/unreviewed/2022/05/GHSA-7576-72m9-2cq9/GHSA-7576-72m9-2cq9.json index 5158ab9ef02..4ed7b814341 100644 --- a/advisories/unreviewed/2022/05/GHSA-7576-72m9-2cq9/GHSA-7576-72m9-2cq9.json +++ b/advisories/unreviewed/2022/05/GHSA-7576-72m9-2cq9/GHSA-7576-72m9-2cq9.json @@ -7,12 +7,8 @@ "CVE-2006-5067" ], "details": "** DISPUTED ** PHP remote file inclusion vulnerability in loader.php in PHP System Administration Toolkit (PHPSaTK) allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[config] parameter. NOTE: this issue is disputed by CVE; analysis shows that the GLOBALS[config] variable is initialized before being used.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-758v-5g69-m4m5/GHSA-758v-5g69-m4m5.json b/advisories/unreviewed/2022/05/GHSA-758v-5g69-m4m5/GHSA-758v-5g69-m4m5.json index 25d7f1721cd..abc967ac05b 100644 --- a/advisories/unreviewed/2022/05/GHSA-758v-5g69-m4m5/GHSA-758v-5g69-m4m5.json +++ b/advisories/unreviewed/2022/05/GHSA-758v-5g69-m4m5/GHSA-758v-5g69-m4m5.json @@ -7,12 +7,8 @@ "CVE-2019-0144" ], "details": "Unhandled exception in firmware for Intel(R) Ethernet 700 Series Controllers before version 7.0 may allow an authenticated user to potentially enable a denial of service via local access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-75rw-5mh8-g8gf/GHSA-75rw-5mh8-g8gf.json b/advisories/unreviewed/2022/05/GHSA-75rw-5mh8-g8gf/GHSA-75rw-5mh8-g8gf.json index fdcddd01a50..60d3451c30d 100644 --- a/advisories/unreviewed/2022/05/GHSA-75rw-5mh8-g8gf/GHSA-75rw-5mh8-g8gf.json +++ b/advisories/unreviewed/2022/05/GHSA-75rw-5mh8-g8gf/GHSA-75rw-5mh8-g8gf.json @@ -7,12 +7,8 @@ "CVE-2019-6172" ], "details": "A potential vulnerability in the SMI callback function in some Lenovo ThinkPad models may allow arbitrary code execution", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-767w-frrc-hwrv/GHSA-767w-frrc-hwrv.json b/advisories/unreviewed/2022/05/GHSA-767w-frrc-hwrv/GHSA-767w-frrc-hwrv.json index 0b9259ac515..84ba2c5198c 100644 --- a/advisories/unreviewed/2022/05/GHSA-767w-frrc-hwrv/GHSA-767w-frrc-hwrv.json +++ b/advisories/unreviewed/2022/05/GHSA-767w-frrc-hwrv/GHSA-767w-frrc-hwrv.json @@ -7,12 +7,8 @@ "CVE-2019-18821" ], "details": "Eximious Logo Designer 3.82 has a User Mode Write AV starting at ExiCustomPathLib!ExiCustomPathLib::CGradientColorsProfile::BuildGradientColorsTable+0x0000000000000053.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7734-vjrv-hjxq/GHSA-7734-vjrv-hjxq.json b/advisories/unreviewed/2022/05/GHSA-7734-vjrv-hjxq/GHSA-7734-vjrv-hjxq.json index 7ec5d3433a5..1574c55560d 100644 --- a/advisories/unreviewed/2022/05/GHSA-7734-vjrv-hjxq/GHSA-7734-vjrv-hjxq.json +++ b/advisories/unreviewed/2022/05/GHSA-7734-vjrv-hjxq/GHSA-7734-vjrv-hjxq.json @@ -7,12 +7,8 @@ "CVE-2019-15680" ], "details": "TightVNC code version 1.3.10 contains null pointer dereference in HandleZlibBPP function, which results Denial of System (DoS). This attack appear to be exploitable via network connectivity.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-775f-h55p-5pqf/GHSA-775f-h55p-5pqf.json b/advisories/unreviewed/2022/05/GHSA-775f-h55p-5pqf/GHSA-775f-h55p-5pqf.json index 552ac6f95aa..87400f9ada9 100644 --- a/advisories/unreviewed/2022/05/GHSA-775f-h55p-5pqf/GHSA-775f-h55p-5pqf.json +++ b/advisories/unreviewed/2022/05/GHSA-775f-h55p-5pqf/GHSA-775f-h55p-5pqf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-77cc-2mff-5mxf/GHSA-77cc-2mff-5mxf.json b/advisories/unreviewed/2022/05/GHSA-77cc-2mff-5mxf/GHSA-77cc-2mff-5mxf.json index 1f5e829078e..2f3f7be6d6b 100644 --- a/advisories/unreviewed/2022/05/GHSA-77cc-2mff-5mxf/GHSA-77cc-2mff-5mxf.json +++ b/advisories/unreviewed/2022/05/GHSA-77cc-2mff-5mxf/GHSA-77cc-2mff-5mxf.json @@ -7,12 +7,8 @@ "CVE-2019-0389" ], "details": "An administrator of SAP NetWeaver Application Server Java (J2EE-Framework), (corrected in versions 7.1, 7.2, 7.3, 7.31, 7.4, 7.5), may change privileges for all or some functions in Java Server, and enable users to execute functions, they are not allowed to execute otherwise.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-77fr-4x44-c9j8/GHSA-77fr-4x44-c9j8.json b/advisories/unreviewed/2022/05/GHSA-77fr-4x44-c9j8/GHSA-77fr-4x44-c9j8.json index 0db4c99845d..c85dacf63ab 100644 --- a/advisories/unreviewed/2022/05/GHSA-77fr-4x44-c9j8/GHSA-77fr-4x44-c9j8.json +++ b/advisories/unreviewed/2022/05/GHSA-77fr-4x44-c9j8/GHSA-77fr-4x44-c9j8.json @@ -7,12 +7,8 @@ "CVE-2019-15402" ], "details": "The Asus ASUS_A002_2 Android device with a build fingerprint of asus/WW_ASUS_A002_2/ASUS_A002_2:7.0/NRD90M/14.1610.1802.18-20180321:user/release-keys contains a pre-installed app with a package name of com.asus.loguploaderproxy app (versionCode=1570000020, versionName=7.0.0.4_170901) that allows other pre-installed apps to perform command execution via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions that are required by other other pre-installed apps that exported their capabilities to other pre-installed app.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-78f3-gcwx-6j8j/GHSA-78f3-gcwx-6j8j.json b/advisories/unreviewed/2022/05/GHSA-78f3-gcwx-6j8j/GHSA-78f3-gcwx-6j8j.json index 65bcc150239..31e81d63257 100644 --- a/advisories/unreviewed/2022/05/GHSA-78f3-gcwx-6j8j/GHSA-78f3-gcwx-6j8j.json +++ b/advisories/unreviewed/2022/05/GHSA-78f3-gcwx-6j8j/GHSA-78f3-gcwx-6j8j.json @@ -7,12 +7,8 @@ "CVE-2019-15432" ], "details": "The Evercoss U6 Android device with a build fingerprint of EVERCOSS/U6/U6:7.0/NRD90M/1504236704:user/release-keys contains a pre-installed app with a package name of com.qiku.cleaner app (versionCode=2, versionName=2.0.0_VER_32516486284094) that allows other pre-installed apps to perform system properties modification via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions that are required by other other pre-installed apps that exported their capabilities to other pre-installed app.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-78xp-fcvc-xxjx/GHSA-78xp-fcvc-xxjx.json b/advisories/unreviewed/2022/05/GHSA-78xp-fcvc-xxjx/GHSA-78xp-fcvc-xxjx.json index bf24a46dfab..5bbc665db04 100644 --- a/advisories/unreviewed/2022/05/GHSA-78xp-fcvc-xxjx/GHSA-78xp-fcvc-xxjx.json +++ b/advisories/unreviewed/2022/05/GHSA-78xp-fcvc-xxjx/GHSA-78xp-fcvc-xxjx.json @@ -7,12 +7,8 @@ "CVE-2019-15349" ], "details": "The Tecno Camon Android device with a build fingerprint of TECNO/H612/TECNO-ID5a:8.1.0/O11019/F-180828V106:user/release-keys contains a pre-installed platform app with a package name of com.lovelyfont.defcontainer (versionCode=7, versionName=7.0.11). This app contains an exported service named com.lovelyfont.manager.service.FunctionService that allows any app co-located on the device to supply the file path to a Dalvik Executable (DEX) file which it will dynamically load within its own process and execute in with its own system privileges. This app cannot be disabled by the user and the attack can be performed by a zero-permission app. Executing commands as the system user can allow a third-party app to video record the user's screen, factory reset the device, obtain the user's notifications, read the logcat logs, inject events in the Graphical User Interface (GUI), and obtains the user's text messages, and more. Executing code as the system user can allow a third-party app to factory reset the device, obtain the user's Wi-Fi passwords, obtain the user's notifications, read the logcat logs, inject events in the GUI, change the default Input Method Editor (IME) (e.g., keyboard) with one contained within the attacking app that contains keylogging functionality, and obtains the user's text messages, and more.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7979-m9mc-33w2/GHSA-7979-m9mc-33w2.json b/advisories/unreviewed/2022/05/GHSA-7979-m9mc-33w2/GHSA-7979-m9mc-33w2.json index 2297c47eebf..a3cf7ed0c94 100644 --- a/advisories/unreviewed/2022/05/GHSA-7979-m9mc-33w2/GHSA-7979-m9mc-33w2.json +++ b/advisories/unreviewed/2022/05/GHSA-7979-m9mc-33w2/GHSA-7979-m9mc-33w2.json @@ -7,12 +7,8 @@ "CVE-2006-5460" ], "details": "** DISPUTED ** Multiple PHP remote file inclusion vulnerabilities in Hinton Design phpht Topsites allow remote attackers to execute arbitrary PHP code via a URL in the phpht_real_path parameter to (1) index.php, (2) certain other scripts in the top-level directory, and (3) certain scripts in the admin/ directory. NOTE: CVE disputes this vulnerability because $phpht_real_path is defined before use in index.php and most other files except common.php, which is already covered by CVE-2006-5458.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-79qx-5345-766q/GHSA-79qx-5345-766q.json b/advisories/unreviewed/2022/05/GHSA-79qx-5345-766q/GHSA-79qx-5345-766q.json index 8811f4991fe..7637d780b62 100644 --- a/advisories/unreviewed/2022/05/GHSA-79qx-5345-766q/GHSA-79qx-5345-766q.json +++ b/advisories/unreviewed/2022/05/GHSA-79qx-5345-766q/GHSA-79qx-5345-766q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7fpg-88qf-m893/GHSA-7fpg-88qf-m893.json b/advisories/unreviewed/2022/05/GHSA-7fpg-88qf-m893/GHSA-7fpg-88qf-m893.json index 97702c0ef56..4dbbeeeedaa 100644 --- a/advisories/unreviewed/2022/05/GHSA-7fpg-88qf-m893/GHSA-7fpg-88qf-m893.json +++ b/advisories/unreviewed/2022/05/GHSA-7fpg-88qf-m893/GHSA-7fpg-88qf-m893.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7g2h-739g-xg4r/GHSA-7g2h-739g-xg4r.json b/advisories/unreviewed/2022/05/GHSA-7g2h-739g-xg4r/GHSA-7g2h-739g-xg4r.json index e2a804c39a2..314aa066a84 100644 --- a/advisories/unreviewed/2022/05/GHSA-7g2h-739g-xg4r/GHSA-7g2h-739g-xg4r.json +++ b/advisories/unreviewed/2022/05/GHSA-7g2h-739g-xg4r/GHSA-7g2h-739g-xg4r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7g98-9j5f-9393/GHSA-7g98-9j5f-9393.json b/advisories/unreviewed/2022/05/GHSA-7g98-9j5f-9393/GHSA-7g98-9j5f-9393.json index e9234d6c4fd..cefa7076e14 100644 --- a/advisories/unreviewed/2022/05/GHSA-7g98-9j5f-9393/GHSA-7g98-9j5f-9393.json +++ b/advisories/unreviewed/2022/05/GHSA-7g98-9j5f-9393/GHSA-7g98-9j5f-9393.json @@ -7,12 +7,8 @@ "CVE-2019-15444" ], "details": "The Samsung S7 Android device with a build fingerprint of samsung/heroltexx/herolte:8.0.0/R16NW/G930FXXS4ESC3:user/release-keys contains a pre-installed app with a package name of com.samsung.android.themecenter app (versionCode=7000000, versionName=7.0.0.0) that allows other pre-installed apps to perform app installation via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions that are required by other other pre-installed apps that exported their capabilities to other pre-installed app.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7j95-p764-rjw3/GHSA-7j95-p764-rjw3.json b/advisories/unreviewed/2022/05/GHSA-7j95-p764-rjw3/GHSA-7j95-p764-rjw3.json index 8144ef9e4fd..1b7dd24f011 100644 --- a/advisories/unreviewed/2022/05/GHSA-7j95-p764-rjw3/GHSA-7j95-p764-rjw3.json +++ b/advisories/unreviewed/2022/05/GHSA-7j95-p764-rjw3/GHSA-7j95-p764-rjw3.json @@ -7,12 +7,8 @@ "CVE-2019-2208" ], "details": "There is a possible out of bounds read in v8 JIT code due to a bug in code generation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9Android ID: A-138441919", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7jc6-rvvr-vcqw/GHSA-7jc6-rvvr-vcqw.json b/advisories/unreviewed/2022/05/GHSA-7jc6-rvvr-vcqw/GHSA-7jc6-rvvr-vcqw.json index 3cb1f920e3c..0b3e2335760 100644 --- a/advisories/unreviewed/2022/05/GHSA-7jc6-rvvr-vcqw/GHSA-7jc6-rvvr-vcqw.json +++ b/advisories/unreviewed/2022/05/GHSA-7jc6-rvvr-vcqw/GHSA-7jc6-rvvr-vcqw.json @@ -7,12 +7,8 @@ "CVE-2019-1392" ], "details": "An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7m4g-94qc-3prx/GHSA-7m4g-94qc-3prx.json b/advisories/unreviewed/2022/05/GHSA-7m4g-94qc-3prx/GHSA-7m4g-94qc-3prx.json index 5c8d894a4bf..f20cf8b563a 100644 --- a/advisories/unreviewed/2022/05/GHSA-7m4g-94qc-3prx/GHSA-7m4g-94qc-3prx.json +++ b/advisories/unreviewed/2022/05/GHSA-7m4g-94qc-3prx/GHSA-7m4g-94qc-3prx.json @@ -7,12 +7,8 @@ "CVE-2019-6189" ], "details": "A potential vulnerability was reported in Lenovo System Interface Foundation versions before v1.1.18.3 that could allow an administrative user to load an unsigned DLL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7q5m-7768-3xvf/GHSA-7q5m-7768-3xvf.json b/advisories/unreviewed/2022/05/GHSA-7q5m-7768-3xvf/GHSA-7q5m-7768-3xvf.json index a663cb857ea..cf1d105ae65 100644 --- a/advisories/unreviewed/2022/05/GHSA-7q5m-7768-3xvf/GHSA-7q5m-7768-3xvf.json +++ b/advisories/unreviewed/2022/05/GHSA-7q5m-7768-3xvf/GHSA-7q5m-7768-3xvf.json @@ -7,12 +7,8 @@ "CVE-2019-9699" ], "details": "Symantec Messaging Gateway (prior to 10.7.0), may be susceptible to an information disclosure issue, which is a type of vulnerability that could potentially allow unauthorized access to data.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7r5m-wjhq-mh59/GHSA-7r5m-wjhq-mh59.json b/advisories/unreviewed/2022/05/GHSA-7r5m-wjhq-mh59/GHSA-7r5m-wjhq-mh59.json index 9e437e51384..8566cf97696 100644 --- a/advisories/unreviewed/2022/05/GHSA-7r5m-wjhq-mh59/GHSA-7r5m-wjhq-mh59.json +++ b/advisories/unreviewed/2022/05/GHSA-7r5m-wjhq-mh59/GHSA-7r5m-wjhq-mh59.json @@ -7,12 +7,8 @@ "CVE-2019-15354" ], "details": "The Ulefone Armor 5 Android device with a build fingerprint of Ulefone/Ulefone_Armor_5/Ulefone_Armor_5:8.1.0/O11019/1528806701:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7r84-r685-grmg/GHSA-7r84-r685-grmg.json b/advisories/unreviewed/2022/05/GHSA-7r84-r685-grmg/GHSA-7r84-r685-grmg.json index c9b1e740ae4..98097bf7072 100644 --- a/advisories/unreviewed/2022/05/GHSA-7r84-r685-grmg/GHSA-7r84-r685-grmg.json +++ b/advisories/unreviewed/2022/05/GHSA-7r84-r685-grmg/GHSA-7r84-r685-grmg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7rqp-qm5j-jm9c/GHSA-7rqp-qm5j-jm9c.json b/advisories/unreviewed/2022/05/GHSA-7rqp-qm5j-jm9c/GHSA-7rqp-qm5j-jm9c.json index a7663192ee4..23f4d4d8263 100644 --- a/advisories/unreviewed/2022/05/GHSA-7rqp-qm5j-jm9c/GHSA-7rqp-qm5j-jm9c.json +++ b/advisories/unreviewed/2022/05/GHSA-7rqp-qm5j-jm9c/GHSA-7rqp-qm5j-jm9c.json @@ -7,12 +7,8 @@ "CVE-2019-16340" ], "details": "Belkin Linksys Velop 1.1.8.192419 devices allows remote attackers to discover the recovery key via a direct request for the /sysinfo_json.cgi URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7w6p-6wqm-42hr/GHSA-7w6p-6wqm-42hr.json b/advisories/unreviewed/2022/05/GHSA-7w6p-6wqm-42hr/GHSA-7w6p-6wqm-42hr.json index e1cae86e0f4..c3c6e1fd68f 100644 --- a/advisories/unreviewed/2022/05/GHSA-7w6p-6wqm-42hr/GHSA-7w6p-6wqm-42hr.json +++ b/advisories/unreviewed/2022/05/GHSA-7w6p-6wqm-42hr/GHSA-7w6p-6wqm-42hr.json @@ -7,12 +7,8 @@ "CVE-2019-8220" ], "details": "Adobe Acrobat and Reader versions, 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7xw4-q2jg-v79p/GHSA-7xw4-q2jg-v79p.json b/advisories/unreviewed/2022/05/GHSA-7xw4-q2jg-v79p/GHSA-7xw4-q2jg-v79p.json index 1d66a766e00..560e7eebed6 100644 --- a/advisories/unreviewed/2022/05/GHSA-7xw4-q2jg-v79p/GHSA-7xw4-q2jg-v79p.json +++ b/advisories/unreviewed/2022/05/GHSA-7xw4-q2jg-v79p/GHSA-7xw4-q2jg-v79p.json @@ -7,12 +7,8 @@ "CVE-2019-2197" ], "details": "In processPhonebookAccess of CachedBluetoothDevice.java, there is a possible permission bypass due to an insecure default value. This could lead to local information disclosure of the user's contact list with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-138529441", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-825p-7535-q5m8/GHSA-825p-7535-q5m8.json b/advisories/unreviewed/2022/05/GHSA-825p-7535-q5m8/GHSA-825p-7535-q5m8.json index db86ea78057..20e339f86e9 100644 --- a/advisories/unreviewed/2022/05/GHSA-825p-7535-q5m8/GHSA-825p-7535-q5m8.json +++ b/advisories/unreviewed/2022/05/GHSA-825p-7535-q5m8/GHSA-825p-7535-q5m8.json @@ -7,12 +7,8 @@ "CVE-2019-15743" ], "details": "The Sony Xperia Touch Android device with a build fingerprint of Sony/blanc_windy/blanc_windy:7.0/LOIRE-SMART-BLANC-1.0.0-170530-0834/1:user/dev-keys contains a pre-installed app with a package name of com.sonymobile.android.maintenancetool.testmic app (versionCode=24, versionName=7.0) that allows unauthorized microphone audio recording via a confused deputy attack. This capability can be accessed by any app co-located on the device. This app allows a third-party app to use its open interface to record audio to external storage.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-84fm-fpp9-g458/GHSA-84fm-fpp9-g458.json b/advisories/unreviewed/2022/05/GHSA-84fm-fpp9-g458/GHSA-84fm-fpp9-g458.json index 5a5241af2fa..2b053a04c8c 100644 --- a/advisories/unreviewed/2022/05/GHSA-84fm-fpp9-g458/GHSA-84fm-fpp9-g458.json +++ b/advisories/unreviewed/2022/05/GHSA-84fm-fpp9-g458/GHSA-84fm-fpp9-g458.json @@ -7,12 +7,8 @@ "CVE-2019-2196" ], "details": "In Download Provider, there is possible SQL injection. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-135269143", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-854f-h7f6-645p/GHSA-854f-h7f6-645p.json b/advisories/unreviewed/2022/05/GHSA-854f-h7f6-645p/GHSA-854f-h7f6-645p.json index fb88701e40a..1ca8e241e9a 100644 --- a/advisories/unreviewed/2022/05/GHSA-854f-h7f6-645p/GHSA-854f-h7f6-645p.json +++ b/advisories/unreviewed/2022/05/GHSA-854f-h7f6-645p/GHSA-854f-h7f6-645p.json @@ -7,12 +7,8 @@ "CVE-2019-15342" ], "details": "The Tecno Camon iAir 2 Plus Android device with a build fingerprint of TECNO/H622/TECNO-ID3k:8.1.0/O11019/E-180914V83:user/release-keys contains a pre-installed platform app with a package name of com.lovelyfont.defcontainer (versionCode=7, versionName=7.0.11). This app contains an exported service named com.lovelyfont.manager.FontCoverService that allows any app co-located on the device to supply arbitrary commands via shell script to be executed as the system user that are triggered by writing an attacker-selected message to the logcat log. This app cannot be disabled by the user and the attack can be performed by a zero-permission app. Executing commands as the system user can allow a third-party app to video record the user's screen, factory reset the device, obtain the user's notifications, read the logcat logs, inject events in the Graphical User Interface (GUI), and obtains the user's text messages, and more. Executing commands as the system user can allow a third-party app to factory reset the device, obtain the user's notifications, read the logcat logs, inject events in the GUI, change the default Input Method Editor (IME) (e.g., keyboard) with one contained within the attacking app that contains keylogging functionality, and obtains the user's text messages, and more.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-865m-p9hx-mgvh/GHSA-865m-p9hx-mgvh.json b/advisories/unreviewed/2022/05/GHSA-865m-p9hx-mgvh/GHSA-865m-p9hx-mgvh.json index a7ea82cca34..d8999a2ede2 100644 --- a/advisories/unreviewed/2022/05/GHSA-865m-p9hx-mgvh/GHSA-865m-p9hx-mgvh.json +++ b/advisories/unreviewed/2022/05/GHSA-865m-p9hx-mgvh/GHSA-865m-p9hx-mgvh.json @@ -7,12 +7,8 @@ "CVE-2019-13508" ], "details": "FreeTDS through 1.1.11 has a Buffer Overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-866g-w5rg-9c4q/GHSA-866g-w5rg-9c4q.json b/advisories/unreviewed/2022/05/GHSA-866g-w5rg-9c4q/GHSA-866g-w5rg-9c4q.json index 3f022800cd8..c79ea0ff267 100644 --- a/advisories/unreviewed/2022/05/GHSA-866g-w5rg-9c4q/GHSA-866g-w5rg-9c4q.json +++ b/advisories/unreviewed/2022/05/GHSA-866g-w5rg-9c4q/GHSA-866g-w5rg-9c4q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8684-vqvg-qxwp/GHSA-8684-vqvg-qxwp.json b/advisories/unreviewed/2022/05/GHSA-8684-vqvg-qxwp/GHSA-8684-vqvg-qxwp.json index 470a04a0bcf..bc03f5de6e6 100644 --- a/advisories/unreviewed/2022/05/GHSA-8684-vqvg-qxwp/GHSA-8684-vqvg-qxwp.json +++ b/advisories/unreviewed/2022/05/GHSA-8684-vqvg-qxwp/GHSA-8684-vqvg-qxwp.json @@ -7,12 +7,8 @@ "CVE-2006-5435" ], "details": "** DISPUTED ** PHP remote file inclusion vulnerability in groupcp.php in phpBB 2.0.10 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. NOTE: CVE and the vendor dispute this vulnerability because $phpbb_root_path is defined before use.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-86r9-2cjw-549v/GHSA-86r9-2cjw-549v.json b/advisories/unreviewed/2022/05/GHSA-86r9-2cjw-549v/GHSA-86r9-2cjw-549v.json index fcab7298bd8..fb38accbe94 100644 --- a/advisories/unreviewed/2022/05/GHSA-86r9-2cjw-549v/GHSA-86r9-2cjw-549v.json +++ b/advisories/unreviewed/2022/05/GHSA-86r9-2cjw-549v/GHSA-86r9-2cjw-549v.json @@ -7,12 +7,8 @@ "CVE-2019-10211" ], "details": "Postgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via bundled OpenSSL executing code from unprotected directory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8867-44g6-7grf/GHSA-8867-44g6-7grf.json b/advisories/unreviewed/2022/05/GHSA-8867-44g6-7grf/GHSA-8867-44g6-7grf.json index 8b98b87a7fd..44489a51a48 100644 --- a/advisories/unreviewed/2022/05/GHSA-8867-44g6-7grf/GHSA-8867-44g6-7grf.json +++ b/advisories/unreviewed/2022/05/GHSA-8867-44g6-7grf/GHSA-8867-44g6-7grf.json @@ -7,12 +7,8 @@ "CVE-2019-4036" ], "details": "IBM Security Access Manager Appliance could allow unauthenticated attacker to cause a denial of service in the reverse proxy component. IBM X-Force ID: 156159.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8885-wr7g-q9vx/GHSA-8885-wr7g-q9vx.json b/advisories/unreviewed/2022/05/GHSA-8885-wr7g-q9vx/GHSA-8885-wr7g-q9vx.json index dcf1448b3f4..ecd182f1fe7 100644 --- a/advisories/unreviewed/2022/05/GHSA-8885-wr7g-q9vx/GHSA-8885-wr7g-q9vx.json +++ b/advisories/unreviewed/2022/05/GHSA-8885-wr7g-q9vx/GHSA-8885-wr7g-q9vx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-89wx-w454-grxp/GHSA-89wx-w454-grxp.json b/advisories/unreviewed/2022/05/GHSA-89wx-w454-grxp/GHSA-89wx-w454-grxp.json index 01e1b63f458..5f6a091a7aa 100644 --- a/advisories/unreviewed/2022/05/GHSA-89wx-w454-grxp/GHSA-89wx-w454-grxp.json +++ b/advisories/unreviewed/2022/05/GHSA-89wx-w454-grxp/GHSA-89wx-w454-grxp.json @@ -7,12 +7,8 @@ "CVE-2019-18856" ], "details": "A Denial Of Service vulnerability exists in the SVG Sanitizer module through 8.x-1.0-alpha1 for Drupal because access to external resources with an SVG use element is mishandled.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8c4q-42pg-q857/GHSA-8c4q-42pg-q857.json b/advisories/unreviewed/2022/05/GHSA-8c4q-42pg-q857/GHSA-8c4q-42pg-q857.json index b42dcd5c4b7..55f7e73c408 100644 --- a/advisories/unreviewed/2022/05/GHSA-8c4q-42pg-q857/GHSA-8c4q-42pg-q857.json +++ b/advisories/unreviewed/2022/05/GHSA-8c4q-42pg-q857/GHSA-8c4q-42pg-q857.json @@ -7,12 +7,8 @@ "CVE-2015-9536" ], "details": "The Easy Digital Downloads (EDD) Twenty-Twelve theme for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8cxj-rfqf-gvv5/GHSA-8cxj-rfqf-gvv5.json b/advisories/unreviewed/2022/05/GHSA-8cxj-rfqf-gvv5/GHSA-8cxj-rfqf-gvv5.json index e0b72bc1979..8d0e9639830 100644 --- a/advisories/unreviewed/2022/05/GHSA-8cxj-rfqf-gvv5/GHSA-8cxj-rfqf-gvv5.json +++ b/advisories/unreviewed/2022/05/GHSA-8cxj-rfqf-gvv5/GHSA-8cxj-rfqf-gvv5.json @@ -7,12 +7,8 @@ "CVE-2019-15472" ], "details": "The Xiaomi Mi A2 Lite Android device with a build fingerprint of xiaomi/daisy/daisy_sprout:9/PKQ1.180917.001/V10.0.3.0.PDLMIXM:user/release-keys contains a pre-installed app with a package name of com.qualcomm.qti.callenhancement app (versionCode=28, versionName=9) that allows unauthorized microphone audio recording via a confused deputy attack. This capability can be accessed by any app co-located on the device. This app allows a third-party app to use its open interface to record telephone calls to external storage.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8mr2-wccp-xm5q/GHSA-8mr2-wccp-xm5q.json b/advisories/unreviewed/2022/05/GHSA-8mr2-wccp-xm5q/GHSA-8mr2-wccp-xm5q.json index c643cddf1db..711b4cd9489 100644 --- a/advisories/unreviewed/2022/05/GHSA-8mr2-wccp-xm5q/GHSA-8mr2-wccp-xm5q.json +++ b/advisories/unreviewed/2022/05/GHSA-8mr2-wccp-xm5q/GHSA-8mr2-wccp-xm5q.json @@ -7,12 +7,8 @@ "CVE-2019-15471" ], "details": "The Xiaomi Mi Mix 2S Android device with a build fingerprint of Xiaomi/polaris/polaris:8.0.0/OPR1.170623.032/V9.5.19.0.ODGMIFA:user/release-keys contains a pre-installed app with a package name of com.qualcomm.qti.callenhancement app (versionCode=27, versionName=8.1.0) that allows other pre-installed apps to perform microphone audio recording via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions that are required by other other pre-installed apps that export their capabilities to other pre-installed app. This app allows a third-party app to use its open interface to record telephone calls to external storage.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8mrw-m7v2-fqgm/GHSA-8mrw-m7v2-fqgm.json b/advisories/unreviewed/2022/05/GHSA-8mrw-m7v2-fqgm/GHSA-8mrw-m7v2-fqgm.json index 2a3d007eb37..d0e9d517c9c 100644 --- a/advisories/unreviewed/2022/05/GHSA-8mrw-m7v2-fqgm/GHSA-8mrw-m7v2-fqgm.json +++ b/advisories/unreviewed/2022/05/GHSA-8mrw-m7v2-fqgm/GHSA-8mrw-m7v2-fqgm.json @@ -7,12 +7,8 @@ "CVE-2019-4396" ], "details": "IBM Cloud Orchestrator 2.4 through 2.4.0.5 and 2.5 through 2.5.0.9 is vulnerable to HTTP response splitting attacks, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to inject arbitrary HTTP headers and cause the server to return a split response, once the URL is clicked. This would allow the attacker to perform further attacks, such as Web cache poisoning or cross-site scripting, and possibly obtain sensitive information. IBM X-Force ID: 162236.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8pj5-hw75-8rrf/GHSA-8pj5-hw75-8rrf.json b/advisories/unreviewed/2022/05/GHSA-8pj5-hw75-8rrf/GHSA-8pj5-hw75-8rrf.json index 2b5f7fd0df9..c3f9c8d8a55 100644 --- a/advisories/unreviewed/2022/05/GHSA-8pj5-hw75-8rrf/GHSA-8pj5-hw75-8rrf.json +++ b/advisories/unreviewed/2022/05/GHSA-8pj5-hw75-8rrf/GHSA-8pj5-hw75-8rrf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8pjv-v7pr-7pxf/GHSA-8pjv-v7pr-7pxf.json b/advisories/unreviewed/2022/05/GHSA-8pjv-v7pr-7pxf/GHSA-8pjv-v7pr-7pxf.json index fd196789b07..73860752106 100644 --- a/advisories/unreviewed/2022/05/GHSA-8pjv-v7pr-7pxf/GHSA-8pjv-v7pr-7pxf.json +++ b/advisories/unreviewed/2022/05/GHSA-8pjv-v7pr-7pxf/GHSA-8pjv-v7pr-7pxf.json @@ -7,12 +7,8 @@ "CVE-2019-15434" ], "details": "The Samsung A5 Android device with a build fingerprint of samsung/a5y17ltexx/a5y17lte:8.0.0/R16NW/A520FXXS8CSC5:user/release-keys contains a pre-installed app with a package name of com.samsung.android.themecenter app (versionCode=7000000, versionName=7.0.0.0) that allows other pre-installed apps to perform app installation via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions that are required by other other pre-installed apps that exported their capabilities to other pre-installed app.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8rmg-x7gm-3g8p/GHSA-8rmg-x7gm-3g8p.json b/advisories/unreviewed/2022/05/GHSA-8rmg-x7gm-3g8p/GHSA-8rmg-x7gm-3g8p.json index b6b9a222e84..8469ae3c6e1 100644 --- a/advisories/unreviewed/2022/05/GHSA-8rmg-x7gm-3g8p/GHSA-8rmg-x7gm-3g8p.json +++ b/advisories/unreviewed/2022/05/GHSA-8rmg-x7gm-3g8p/GHSA-8rmg-x7gm-3g8p.json @@ -7,12 +7,8 @@ "CVE-2019-15442" ], "details": "The Samsung on7xelteskt Android device with a build fingerprint of samsung/on7xelteskt/on7xelteskt:8.1.0/M1AJQ/G610SKSU2CSB1:user/release-keys contains a pre-installed app with a package name of com.samsung.android.themecenter app (versionCode=7000100, versionName=7.0.1.0) that allows other pre-installed apps to perform app installation via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions that are required by other other pre-installed apps that exported their capabilities to other pre-installed app.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8v57-95f4-cp8w/GHSA-8v57-95f4-cp8w.json b/advisories/unreviewed/2022/05/GHSA-8v57-95f4-cp8w/GHSA-8v57-95f4-cp8w.json index edd2eae69f7..7d4caeb8f09 100644 --- a/advisories/unreviewed/2022/05/GHSA-8v57-95f4-cp8w/GHSA-8v57-95f4-cp8w.json +++ b/advisories/unreviewed/2022/05/GHSA-8v57-95f4-cp8w/GHSA-8v57-95f4-cp8w.json @@ -7,12 +7,8 @@ "CVE-2019-6188" ], "details": "The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad T460p, BIOS versions up to R07ET90W, and T470p, BIOS versions up to R0FET50W, which may allow for unauthorized access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8v7q-5cpp-2jfp/GHSA-8v7q-5cpp-2jfp.json b/advisories/unreviewed/2022/05/GHSA-8v7q-5cpp-2jfp/GHSA-8v7q-5cpp-2jfp.json index 2ff442bd2c1..da9644a11f6 100644 --- a/advisories/unreviewed/2022/05/GHSA-8v7q-5cpp-2jfp/GHSA-8v7q-5cpp-2jfp.json +++ b/advisories/unreviewed/2022/05/GHSA-8v7q-5cpp-2jfp/GHSA-8v7q-5cpp-2jfp.json @@ -7,12 +7,8 @@ "CVE-2019-16876" ], "details": "Portainer before 1.22.1 allows Directory Traversal.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8wcx-3gm3-2734/GHSA-8wcx-3gm3-2734.json b/advisories/unreviewed/2022/05/GHSA-8wcx-3gm3-2734/GHSA-8wcx-3gm3-2734.json index 90c0cac774b..7a91f123704 100644 --- a/advisories/unreviewed/2022/05/GHSA-8wcx-3gm3-2734/GHSA-8wcx-3gm3-2734.json +++ b/advisories/unreviewed/2022/05/GHSA-8wcx-3gm3-2734/GHSA-8wcx-3gm3-2734.json @@ -7,12 +7,8 @@ "CVE-2019-17189" ], "details": "totemodata 3.0.0_b936 has XSS via a folder name.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8wxh-5wv6-x378/GHSA-8wxh-5wv6-x378.json b/advisories/unreviewed/2022/05/GHSA-8wxh-5wv6-x378/GHSA-8wxh-5wv6-x378.json index 46bf1df152d..fdb3afb29fa 100644 --- a/advisories/unreviewed/2022/05/GHSA-8wxh-5wv6-x378/GHSA-8wxh-5wv6-x378.json +++ b/advisories/unreviewed/2022/05/GHSA-8wxh-5wv6-x378/GHSA-8wxh-5wv6-x378.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8xfg-6grw-wvxc/GHSA-8xfg-6grw-wvxc.json b/advisories/unreviewed/2022/05/GHSA-8xfg-6grw-wvxc/GHSA-8xfg-6grw-wvxc.json index c9a2596bab6..a8a542d8b39 100644 --- a/advisories/unreviewed/2022/05/GHSA-8xfg-6grw-wvxc/GHSA-8xfg-6grw-wvxc.json +++ b/advisories/unreviewed/2022/05/GHSA-8xfg-6grw-wvxc/GHSA-8xfg-6grw-wvxc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-923p-cjh4-ch9f/GHSA-923p-cjh4-ch9f.json b/advisories/unreviewed/2022/05/GHSA-923p-cjh4-ch9f/GHSA-923p-cjh4-ch9f.json index 4aef52b8611..03d852d92c6 100644 --- a/advisories/unreviewed/2022/05/GHSA-923p-cjh4-ch9f/GHSA-923p-cjh4-ch9f.json +++ b/advisories/unreviewed/2022/05/GHSA-923p-cjh4-ch9f/GHSA-923p-cjh4-ch9f.json @@ -7,12 +7,8 @@ "CVE-2019-2195" ], "details": "In tokenize of sqlite3_android.cpp, there is a possible attacker controlled INSERT statement due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-139186193", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-928j-whg4-747q/GHSA-928j-whg4-747q.json b/advisories/unreviewed/2022/05/GHSA-928j-whg4-747q/GHSA-928j-whg4-747q.json index 0213639a776..c1870291602 100644 --- a/advisories/unreviewed/2022/05/GHSA-928j-whg4-747q/GHSA-928j-whg4-747q.json +++ b/advisories/unreviewed/2022/05/GHSA-928j-whg4-747q/GHSA-928j-whg4-747q.json @@ -7,12 +7,8 @@ "CVE-2019-15466" ], "details": "The Xiaomi Redmi 6 Pro Android device with a build fingerprint of xiaomi/sakura_india/sakura_india:8.1.0/OPM1.171019.019/V10.2.6.0.ODMMIXM:user/release-keys contains a pre-installed app with a package name of com.huaqin.factory app (versionCode=1, versionName=QL1715_201812191721) that allows unauthorized wireless settings modification via a confused deputy attack. This capability can be accessed by any app co-located on the device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-92xj-745q-j6qr/GHSA-92xj-745q-j6qr.json b/advisories/unreviewed/2022/05/GHSA-92xj-745q-j6qr/GHSA-92xj-745q-j6qr.json index 12b3e8adcd9..1b7b2d21b27 100644 --- a/advisories/unreviewed/2022/05/GHSA-92xj-745q-j6qr/GHSA-92xj-745q-j6qr.json +++ b/advisories/unreviewed/2022/05/GHSA-92xj-745q-j6qr/GHSA-92xj-745q-j6qr.json @@ -7,12 +7,8 @@ "CVE-2019-18281" ], "details": "An out-of-bounds memory access in the generateDirectionalRuns() function in qtextengine.cpp in Qt qtbase 5.11.x and 5.12.x before 5.12.5 allows attackers to cause a denial of service by crashing an application via a text file containing many directional characters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-94hw-hwqq-jwvw/GHSA-94hw-hwqq-jwvw.json b/advisories/unreviewed/2022/05/GHSA-94hw-hwqq-jwvw/GHSA-94hw-hwqq-jwvw.json index e0db9a0860f..338391bd1b0 100644 --- a/advisories/unreviewed/2022/05/GHSA-94hw-hwqq-jwvw/GHSA-94hw-hwqq-jwvw.json +++ b/advisories/unreviewed/2022/05/GHSA-94hw-hwqq-jwvw/GHSA-94hw-hwqq-jwvw.json @@ -7,12 +7,8 @@ "CVE-2019-5233" ], "details": "Huawei smartphones with versions earlier than Taurus-AL00B 10.0.0.41(SP2C00E41R3P2) have an improper authentication vulnerability. Successful exploitation may cause the attacker to access specific components.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-94mc-5f55-269r/GHSA-94mc-5f55-269r.json b/advisories/unreviewed/2022/05/GHSA-94mc-5f55-269r/GHSA-94mc-5f55-269r.json index 3e3205b5e7f..c01b3195bb0 100644 --- a/advisories/unreviewed/2022/05/GHSA-94mc-5f55-269r/GHSA-94mc-5f55-269r.json +++ b/advisories/unreviewed/2022/05/GHSA-94mc-5f55-269r/GHSA-94mc-5f55-269r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-958f-78j2-fqr6/GHSA-958f-78j2-fqr6.json b/advisories/unreviewed/2022/05/GHSA-958f-78j2-fqr6/GHSA-958f-78j2-fqr6.json index e38131d5707..4eb43b3fc3a 100644 --- a/advisories/unreviewed/2022/05/GHSA-958f-78j2-fqr6/GHSA-958f-78j2-fqr6.json +++ b/advisories/unreviewed/2022/05/GHSA-958f-78j2-fqr6/GHSA-958f-78j2-fqr6.json @@ -7,12 +7,8 @@ "CVE-2019-15803" ], "details": "An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. Through an undocumented sequence of keypresses, undocumented functionality is triggered. A diagnostics shell is triggered via CTRL-ALT-t, which prompts for the password returned by fds_sys_passDebugPasswd_ret(). The firmware contains access control checks that determine if remote users are allowed to access this functionality. The function that performs this check (fds_sys_remoteDebugEnable_ret in libfds.so) always return TRUE with no actual checks performed. The diagnostics menu allows for reading/writing arbitrary registers and various other configuration parameters which are believed to be related to the network interface chips.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9599-wjxj-x99m/GHSA-9599-wjxj-x99m.json b/advisories/unreviewed/2022/05/GHSA-9599-wjxj-x99m/GHSA-9599-wjxj-x99m.json index 4db50cf67c2..815b4206c46 100644 --- a/advisories/unreviewed/2022/05/GHSA-9599-wjxj-x99m/GHSA-9599-wjxj-x99m.json +++ b/advisories/unreviewed/2022/05/GHSA-9599-wjxj-x99m/GHSA-9599-wjxj-x99m.json @@ -7,12 +7,8 @@ "CVE-2016-5194" ], "details": "Unspecified vulnerabilities in Google Chrome before 54.0.2840.59.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-95x3-p795-5g2r/GHSA-95x3-p795-5g2r.json b/advisories/unreviewed/2022/05/GHSA-95x3-p795-5g2r/GHSA-95x3-p795-5g2r.json index 8193a76ab6e..31f54705551 100644 --- a/advisories/unreviewed/2022/05/GHSA-95x3-p795-5g2r/GHSA-95x3-p795-5g2r.json +++ b/advisories/unreviewed/2022/05/GHSA-95x3-p795-5g2r/GHSA-95x3-p795-5g2r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-97wm-hr4h-jwm3/GHSA-97wm-hr4h-jwm3.json b/advisories/unreviewed/2022/05/GHSA-97wm-hr4h-jwm3/GHSA-97wm-hr4h-jwm3.json index 4d3e6ef22c1..bcc223674b4 100644 --- a/advisories/unreviewed/2022/05/GHSA-97wm-hr4h-jwm3/GHSA-97wm-hr4h-jwm3.json +++ b/advisories/unreviewed/2022/05/GHSA-97wm-hr4h-jwm3/GHSA-97wm-hr4h-jwm3.json @@ -7,12 +7,8 @@ "CVE-2006-4562" ], "details": "** DISPUTED ** The proxy DNS service in Symantec Gateway Security (SGS) allows remote attackers to make arbitrary DNS queries to third-party DNS servers, while hiding the source IP address of the attacker. NOTE: another researcher has stated that the default configuration does not proxy DNS queries received on the external interface.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-988f-qp54-rcj2/GHSA-988f-qp54-rcj2.json b/advisories/unreviewed/2022/05/GHSA-988f-qp54-rcj2/GHSA-988f-qp54-rcj2.json index 3f945b10dfb..d49f5f4bfb4 100644 --- a/advisories/unreviewed/2022/05/GHSA-988f-qp54-rcj2/GHSA-988f-qp54-rcj2.json +++ b/advisories/unreviewed/2022/05/GHSA-988f-qp54-rcj2/GHSA-988f-qp54-rcj2.json @@ -7,12 +7,8 @@ "CVE-2019-11170" ], "details": "Authentication bypass in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable information disclosure, escalation of privilege and/or denial of service via local access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-98hp-cmc8-vgp6/GHSA-98hp-cmc8-vgp6.json b/advisories/unreviewed/2022/05/GHSA-98hp-cmc8-vgp6/GHSA-98hp-cmc8-vgp6.json index 4e95e2921d4..1fc9cdf21e7 100644 --- a/advisories/unreviewed/2022/05/GHSA-98hp-cmc8-vgp6/GHSA-98hp-cmc8-vgp6.json +++ b/advisories/unreviewed/2022/05/GHSA-98hp-cmc8-vgp6/GHSA-98hp-cmc8-vgp6.json @@ -7,12 +7,8 @@ "CVE-2019-19037" ], "details": "ext4_empty_dir in fs/ext4/namei.c in the Linux kernel through 5.3.12 allows a NULL pointer dereference because ext4_read_dirblock(inode,0,DIRENT_HTREE) can be zero.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-992m-xc3g-r7rj/GHSA-992m-xc3g-r7rj.json b/advisories/unreviewed/2022/05/GHSA-992m-xc3g-r7rj/GHSA-992m-xc3g-r7rj.json index 2b09ee39d03..97831edcd45 100644 --- a/advisories/unreviewed/2022/05/GHSA-992m-xc3g-r7rj/GHSA-992m-xc3g-r7rj.json +++ b/advisories/unreviewed/2022/05/GHSA-992m-xc3g-r7rj/GHSA-992m-xc3g-r7rj.json @@ -7,12 +7,8 @@ "CVE-2019-18837" ], "details": "An issue was discovered in crun before 0.10.5. With a crafted image, it doesn't correctly check whether a target is a symlink, resulting in access to files outside of the container. This occurs in libcrun/linux.c and libcrun/chroot_realpath.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-99xf-6j9g-6jww/GHSA-99xf-6j9g-6jww.json b/advisories/unreviewed/2022/05/GHSA-99xf-6j9g-6jww/GHSA-99xf-6j9g-6jww.json index 19786c14611..05671c65556 100644 --- a/advisories/unreviewed/2022/05/GHSA-99xf-6j9g-6jww/GHSA-99xf-6j9g-6jww.json +++ b/advisories/unreviewed/2022/05/GHSA-99xf-6j9g-6jww/GHSA-99xf-6j9g-6jww.json @@ -7,12 +7,8 @@ "CVE-2019-12719" ], "details": "An issue was discovered in Picture_Manage_mvc.aspx in AUO SunVeillance Monitoring System before v1.1.9e. There is an incorrect access control vulnerability that can allow an unauthenticated user to upload files via a modified authority parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9cg4-j3w9-fwph/GHSA-9cg4-j3w9-fwph.json b/advisories/unreviewed/2022/05/GHSA-9cg4-j3w9-fwph/GHSA-9cg4-j3w9-fwph.json index 23a3674e8b9..5aa12df8559 100644 --- a/advisories/unreviewed/2022/05/GHSA-9cg4-j3w9-fwph/GHSA-9cg4-j3w9-fwph.json +++ b/advisories/unreviewed/2022/05/GHSA-9cg4-j3w9-fwph/GHSA-9cg4-j3w9-fwph.json @@ -7,12 +7,8 @@ "CVE-2006-1865" ], "details": "Argument injection vulnerability in Beagle before 0.2.5 allows attackers to execute arbitrary commands via crafted filenames that inject command line arguments when Beagle launches external helper applications while indexing.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9hmj-qj7f-xjvv/GHSA-9hmj-qj7f-xjvv.json b/advisories/unreviewed/2022/05/GHSA-9hmj-qj7f-xjvv/GHSA-9hmj-qj7f-xjvv.json index 0d9310e013d..04c37cb657f 100644 --- a/advisories/unreviewed/2022/05/GHSA-9hmj-qj7f-xjvv/GHSA-9hmj-qj7f-xjvv.json +++ b/advisories/unreviewed/2022/05/GHSA-9hmj-qj7f-xjvv/GHSA-9hmj-qj7f-xjvv.json @@ -7,12 +7,8 @@ "CVE-2006-5473" ], "details": "** DISPUTED ** PHP remote file inclusion vulnerability in Description.php in Softerra PHP Developer Library 1.5.3 and earlier allows remote attackers to execute arbitrary PHP code via the lib_dir parameter. NOTE: this issue is disputed by CVE as of 20061023, since there is no Description.php file included in the product, and the existing \"Description\" file contains documentation, not functioning code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9jcx-c729-r5q2/GHSA-9jcx-c729-r5q2.json b/advisories/unreviewed/2022/05/GHSA-9jcx-c729-r5q2/GHSA-9jcx-c729-r5q2.json index 6d2fb285dab..778b8a3185f 100644 --- a/advisories/unreviewed/2022/05/GHSA-9jcx-c729-r5q2/GHSA-9jcx-c729-r5q2.json +++ b/advisories/unreviewed/2022/05/GHSA-9jcx-c729-r5q2/GHSA-9jcx-c729-r5q2.json @@ -7,12 +7,8 @@ "CVE-2019-11282" ], "details": "Cloud Foundry UAA, versions prior to v74.3.0, contains an endpoint that is vulnerable to SCIM injection attack. A remote authenticated malicious user with scim.invite scope can craft a request with malicious content which can leak information about users of the UAA.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9m44-5m43-4rmj/GHSA-9m44-5m43-4rmj.json b/advisories/unreviewed/2022/05/GHSA-9m44-5m43-4rmj/GHSA-9m44-5m43-4rmj.json index 8c854901521..1c2cc7aadba 100644 --- a/advisories/unreviewed/2022/05/GHSA-9m44-5m43-4rmj/GHSA-9m44-5m43-4rmj.json +++ b/advisories/unreviewed/2022/05/GHSA-9m44-5m43-4rmj/GHSA-9m44-5m43-4rmj.json @@ -7,12 +7,8 @@ "CVE-2019-18806" ], "details": "A memory leak in the ql_alloc_large_buffers() function in drivers/net/ethernet/qlogic/qla3xxx.c in the Linux kernel before 5.3.5 allows local users to cause a denial of service (memory consumption) by triggering pci_dma_mapping_error() failures, aka CID-1acb8f2a7a9f.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9m6w-5w2x-frfm/GHSA-9m6w-5w2x-frfm.json b/advisories/unreviewed/2022/05/GHSA-9m6w-5w2x-frfm/GHSA-9m6w-5w2x-frfm.json index b698067b21f..413594da250 100644 --- a/advisories/unreviewed/2022/05/GHSA-9m6w-5w2x-frfm/GHSA-9m6w-5w2x-frfm.json +++ b/advisories/unreviewed/2022/05/GHSA-9m6w-5w2x-frfm/GHSA-9m6w-5w2x-frfm.json @@ -7,12 +7,8 @@ "CVE-2018-21026" ], "details": "A vulnerability in Hitachi Command Suite 7.x and 8.x before 8.6.5-00 allows an unauthenticated remote user to read internal information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9m7g-qpx8-vh2m/GHSA-9m7g-qpx8-vh2m.json b/advisories/unreviewed/2022/05/GHSA-9m7g-qpx8-vh2m/GHSA-9m7g-qpx8-vh2m.json index 7b4cc050ee1..c4146beb899 100644 --- a/advisories/unreviewed/2022/05/GHSA-9m7g-qpx8-vh2m/GHSA-9m7g-qpx8-vh2m.json +++ b/advisories/unreviewed/2022/05/GHSA-9m7g-qpx8-vh2m/GHSA-9m7g-qpx8-vh2m.json @@ -7,12 +7,8 @@ "CVE-2006-5678" ], "details": "** DISPUTED ** PHP remote file inclusion vulnerability in common/visiteurs/include/library.inc.php in J-Pierre DEZELUS Les Visiteurs 2.0.1, as used in phpMyConferences (phpMyConference) 8.0.2 and possibly other products, allows remote attackers to execute arbitrary PHP code via a URL in the lvc_modules_dir parameter. NOTE: CVE disputes this vulnerability, because the inclusion occurs in a function that is not called during a direct request to library.inc.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9p24-m679-hv98/GHSA-9p24-m679-hv98.json b/advisories/unreviewed/2022/05/GHSA-9p24-m679-hv98/GHSA-9p24-m679-hv98.json index bfbe697a8d2..7d36399528c 100644 --- a/advisories/unreviewed/2022/05/GHSA-9p24-m679-hv98/GHSA-9p24-m679-hv98.json +++ b/advisories/unreviewed/2022/05/GHSA-9p24-m679-hv98/GHSA-9p24-m679-hv98.json @@ -7,12 +7,8 @@ "CVE-2019-18895" ], "details": "Scanguard through 2019-11-12 on Windows has Insecure Permissions for the installation directory, leading to privilege escalation via a Trojan horse executable file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9p4q-cqwc-mf63/GHSA-9p4q-cqwc-mf63.json b/advisories/unreviewed/2022/05/GHSA-9p4q-cqwc-mf63/GHSA-9p4q-cqwc-mf63.json index 31ff1aefbf8..2e5eb599bee 100644 --- a/advisories/unreviewed/2022/05/GHSA-9p4q-cqwc-mf63/GHSA-9p4q-cqwc-mf63.json +++ b/advisories/unreviewed/2022/05/GHSA-9p4q-cqwc-mf63/GHSA-9p4q-cqwc-mf63.json @@ -7,12 +7,8 @@ "CVE-2006-3544" ], "details": "** DISPUTED ** Multiple SQL injection vulnerabilities in Invision Power Board (IPB) 1.3 Final allow remote attackers to execute arbitrary SQL commands via the CODE parameter in a (1) Stats, (2) Mail, and (3) Reg action in index.php. NOTE: the developer has disputed this issue, stating that \"At no point does the CODE parameter touch the database. The CODE parameter is used in a SWITCH statement to determine which function to run.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9qr7-gxhf-7v3q/GHSA-9qr7-gxhf-7v3q.json b/advisories/unreviewed/2022/05/GHSA-9qr7-gxhf-7v3q/GHSA-9qr7-gxhf-7v3q.json index 4c616434459..e14cdc62914 100644 --- a/advisories/unreviewed/2022/05/GHSA-9qr7-gxhf-7v3q/GHSA-9qr7-gxhf-7v3q.json +++ b/advisories/unreviewed/2022/05/GHSA-9qr7-gxhf-7v3q/GHSA-9qr7-gxhf-7v3q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9rhf-h2ph-4597/GHSA-9rhf-h2ph-4597.json b/advisories/unreviewed/2022/05/GHSA-9rhf-h2ph-4597/GHSA-9rhf-h2ph-4597.json index 57cd74ef7f7..1b008f7edc8 100644 --- a/advisories/unreviewed/2022/05/GHSA-9rhf-h2ph-4597/GHSA-9rhf-h2ph-4597.json +++ b/advisories/unreviewed/2022/05/GHSA-9rhf-h2ph-4597/GHSA-9rhf-h2ph-4597.json @@ -7,12 +7,8 @@ "CVE-2019-16873" ], "details": "Portainer before 1.22.1 has XSS (issue 1 of 2).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9wfr-jr3g-m83r/GHSA-9wfr-jr3g-m83r.json b/advisories/unreviewed/2022/05/GHSA-9wfr-jr3g-m83r/GHSA-9wfr-jr3g-m83r.json index 69695283919..3bf374f9120 100644 --- a/advisories/unreviewed/2022/05/GHSA-9wfr-jr3g-m83r/GHSA-9wfr-jr3g-m83r.json +++ b/advisories/unreviewed/2022/05/GHSA-9wfr-jr3g-m83r/GHSA-9wfr-jr3g-m83r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9x4q-26cx-fr52/GHSA-9x4q-26cx-fr52.json b/advisories/unreviewed/2022/05/GHSA-9x4q-26cx-fr52/GHSA-9x4q-26cx-fr52.json index 39df1adb1fa..d140eb9df21 100644 --- a/advisories/unreviewed/2022/05/GHSA-9x4q-26cx-fr52/GHSA-9x4q-26cx-fr52.json +++ b/advisories/unreviewed/2022/05/GHSA-9x4q-26cx-fr52/GHSA-9x4q-26cx-fr52.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c22w-rvfr-jr97/GHSA-c22w-rvfr-jr97.json b/advisories/unreviewed/2022/05/GHSA-c22w-rvfr-jr97/GHSA-c22w-rvfr-jr97.json index 293b60ab644..1a0e5101554 100644 --- a/advisories/unreviewed/2022/05/GHSA-c22w-rvfr-jr97/GHSA-c22w-rvfr-jr97.json +++ b/advisories/unreviewed/2022/05/GHSA-c22w-rvfr-jr97/GHSA-c22w-rvfr-jr97.json @@ -7,12 +7,8 @@ "CVE-2019-11171" ], "details": "Heap corruption in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable information disclosure, escalation of privilege and/or denial of service via network access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c269-fcrm-h58r/GHSA-c269-fcrm-h58r.json b/advisories/unreviewed/2022/05/GHSA-c269-fcrm-h58r/GHSA-c269-fcrm-h58r.json index d3026dacdb4..102891c917f 100644 --- a/advisories/unreviewed/2022/05/GHSA-c269-fcrm-h58r/GHSA-c269-fcrm-h58r.json +++ b/advisories/unreviewed/2022/05/GHSA-c269-fcrm-h58r/GHSA-c269-fcrm-h58r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c328-8493-h9jv/GHSA-c328-8493-h9jv.json b/advisories/unreviewed/2022/05/GHSA-c328-8493-h9jv/GHSA-c328-8493-h9jv.json index 44c4c994868..b9f8ca77d52 100644 --- a/advisories/unreviewed/2022/05/GHSA-c328-8493-h9jv/GHSA-c328-8493-h9jv.json +++ b/advisories/unreviewed/2022/05/GHSA-c328-8493-h9jv/GHSA-c328-8493-h9jv.json @@ -7,12 +7,8 @@ "CVE-2019-15456" ], "details": "The Samsung J6 Android device with a build fingerprint of samsung/j6ltexx/j6lte:8.0.0/R16NW/J600FNXXU3ASC1:user/release-keys contains a pre-installed app with a package name of com.samsung.android.themecenter app (versionCode=7000000, versionName=7.0.0.0) that allows other pre-installed apps to perform app installation via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions that are required by other other pre-installed apps that exported their capabilities to other pre-installed app.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c3gx-v2m9-m8vc/GHSA-c3gx-v2m9-m8vc.json b/advisories/unreviewed/2022/05/GHSA-c3gx-v2m9-m8vc/GHSA-c3gx-v2m9-m8vc.json index 40a44051848..d57cc76f5db 100644 --- a/advisories/unreviewed/2022/05/GHSA-c3gx-v2m9-m8vc/GHSA-c3gx-v2m9-m8vc.json +++ b/advisories/unreviewed/2022/05/GHSA-c3gx-v2m9-m8vc/GHSA-c3gx-v2m9-m8vc.json @@ -7,12 +7,8 @@ "CVE-2019-5536" ], "details": "VMware ESXi (6.7 before ESXi670-201908101-SG and 6.5 before ESXi650-201910401-SG), Workstation (15.x before 15.5.0) and Fusion (11.x before 11.5.0) contain a denial-of-service vulnerability in the shader functionality. Successful exploitation of this issue may allow attackers with normal user privileges to create a denial-of-service condition on their own VM. Exploitation of this issue require an attacker to have access to a virtual machine with 3D graphics enabled. It is not enabled by default on ESXi and is enabled by default on Workstation and Fusion.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c474-f694-3xx6/GHSA-c474-f694-3xx6.json b/advisories/unreviewed/2022/05/GHSA-c474-f694-3xx6/GHSA-c474-f694-3xx6.json index 6b142dba2cc..61de99a3585 100644 --- a/advisories/unreviewed/2022/05/GHSA-c474-f694-3xx6/GHSA-c474-f694-3xx6.json +++ b/advisories/unreviewed/2022/05/GHSA-c474-f694-3xx6/GHSA-c474-f694-3xx6.json @@ -7,12 +7,8 @@ "CVE-2019-6842" ], "details": "A CWE-248: Uncaught Exception vulnerability exists in Modicon M580, Modicon M340, Modicon BMxCRA and 140CRA modules (all firmware versions), which could cause a Denial of Service attack on the PLC when upgrading the firmware with a missing web server image inside the package using FTP protocol.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c56h-5fh8-xjpv/GHSA-c56h-5fh8-xjpv.json b/advisories/unreviewed/2022/05/GHSA-c56h-5fh8-xjpv/GHSA-c56h-5fh8-xjpv.json index 433de65cdeb..27a82df6613 100644 --- a/advisories/unreviewed/2022/05/GHSA-c56h-5fh8-xjpv/GHSA-c56h-5fh8-xjpv.json +++ b/advisories/unreviewed/2022/05/GHSA-c56h-5fh8-xjpv/GHSA-c56h-5fh8-xjpv.json @@ -7,12 +7,8 @@ "CVE-2019-7960" ], "details": "Adobe Animate CC versions 19.2.1 and earlier have an insecure library loading (dll hijacking) vulnerability. Successful exploitation could lead to privilege escalation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c5rh-mmr6-c7ch/GHSA-c5rh-mmr6-c7ch.json b/advisories/unreviewed/2022/05/GHSA-c5rh-mmr6-c7ch/GHSA-c5rh-mmr6-c7ch.json index abe542850b9..78354daec02 100644 --- a/advisories/unreviewed/2022/05/GHSA-c5rh-mmr6-c7ch/GHSA-c5rh-mmr6-c7ch.json +++ b/advisories/unreviewed/2022/05/GHSA-c5rh-mmr6-c7ch/GHSA-c5rh-mmr6-c7ch.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c7jh-cm4r-w5px/GHSA-c7jh-cm4r-w5px.json b/advisories/unreviewed/2022/05/GHSA-c7jh-cm4r-w5px/GHSA-c7jh-cm4r-w5px.json index 79c304248c8..1d6608b85e6 100644 --- a/advisories/unreviewed/2022/05/GHSA-c7jh-cm4r-w5px/GHSA-c7jh-cm4r-w5px.json +++ b/advisories/unreviewed/2022/05/GHSA-c7jh-cm4r-w5px/GHSA-c7jh-cm4r-w5px.json @@ -7,12 +7,8 @@ "CVE-2019-8226" ], "details": "Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an incomplete implementation of security mechanism vulnerability. Successful exploitation could lead to information disclosure.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c8jx-2jvj-xgr3/GHSA-c8jx-2jvj-xgr3.json b/advisories/unreviewed/2022/05/GHSA-c8jx-2jvj-xgr3/GHSA-c8jx-2jvj-xgr3.json index c73ffdc2c9c..ecce5978f69 100644 --- a/advisories/unreviewed/2022/05/GHSA-c8jx-2jvj-xgr3/GHSA-c8jx-2jvj-xgr3.json +++ b/advisories/unreviewed/2022/05/GHSA-c8jx-2jvj-xgr3/GHSA-c8jx-2jvj-xgr3.json @@ -7,12 +7,8 @@ "CVE-2019-14602" ], "details": "Improper permissions in the installer for the Nuvoton* CIR Driver versions 1.02.1002 and before may allow an authenticated user to potentially enable escalation of privilege via local access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c942-cp8m-2699/GHSA-c942-cp8m-2699.json b/advisories/unreviewed/2022/05/GHSA-c942-cp8m-2699/GHSA-c942-cp8m-2699.json index 2cdb81c84cc..5307777abb9 100644 --- a/advisories/unreviewed/2022/05/GHSA-c942-cp8m-2699/GHSA-c942-cp8m-2699.json +++ b/advisories/unreviewed/2022/05/GHSA-c942-cp8m-2699/GHSA-c942-cp8m-2699.json @@ -7,12 +7,8 @@ "CVE-2019-15351" ], "details": "The Tecno Camon Android device with a build fingerprint of TECNO/H622/TECNO-ID5b:8.1.0/O11019/G-180829V31:user/release-keys contains a pre-installed platform app with a package name of com.lovelyfont.defcontainer (versionCode=7, versionName=7.0.11). This app contains an exported service named com.lovelyfont.manager.FontCoverService that allows any app co-located on the device to supply arbitrary commands via shell script to be executed as the system user that are triggered by writing an attacker-selected message to the logcat log. This app cannot be disabled by the user and the attack can be performed by a zero-permission app. Executing commands as the system user can allow a third-party app to video record the user's screen, factory reset the device, obtain the user's notifications, read the logcat logs, inject events in the Graphical User Interface (GUI), and obtains the user's text messages, and more. Executing commands as the system user can allow a third-party app to factory reset the device, obtain the user's notifications, read the logcat logs, inject events in the GUI, change the default Input Method Editor (IME) (e.g., keyboard) with one contained within the attacking app that contains keylogging functionality, and obtains the user's text messages, and more.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c968-9rc6-v8jv/GHSA-c968-9rc6-v8jv.json b/advisories/unreviewed/2022/05/GHSA-c968-9rc6-v8jv/GHSA-c968-9rc6-v8jv.json index e31c5564e68..506d12309d5 100644 --- a/advisories/unreviewed/2022/05/GHSA-c968-9rc6-v8jv/GHSA-c968-9rc6-v8jv.json +++ b/advisories/unreviewed/2022/05/GHSA-c968-9rc6-v8jv/GHSA-c968-9rc6-v8jv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cc66-59g4-2gpr/GHSA-cc66-59g4-2gpr.json b/advisories/unreviewed/2022/05/GHSA-cc66-59g4-2gpr/GHSA-cc66-59g4-2gpr.json index 97a1c2d2f9c..f64b9dae84e 100644 --- a/advisories/unreviewed/2022/05/GHSA-cc66-59g4-2gpr/GHSA-cc66-59g4-2gpr.json +++ b/advisories/unreviewed/2022/05/GHSA-cc66-59g4-2gpr/GHSA-cc66-59g4-2gpr.json @@ -7,12 +7,8 @@ "CVE-2019-15465" ], "details": "The Samsung J7 Pro Android device with a build fingerprint of samsung/j7y17lteubm/j7y17lte:8.1.0/M1AJQ/J730GMUBS6BSC1:user/release-keys contains a pre-installed app with a package name of com.samsung.android.themecenter app (versionCode=7000100, versionName=7.0.1.0) that allows other pre-installed apps to perform app installation via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions that are required by other other pre-installed apps that exported their capabilities to other pre-installed app.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cfpf-jvvq-wj6j/GHSA-cfpf-jvvq-wj6j.json b/advisories/unreviewed/2022/05/GHSA-cfpf-jvvq-wj6j/GHSA-cfpf-jvvq-wj6j.json index ced94da258e..6514bf503a2 100644 --- a/advisories/unreviewed/2022/05/GHSA-cfpf-jvvq-wj6j/GHSA-cfpf-jvvq-wj6j.json +++ b/advisories/unreviewed/2022/05/GHSA-cfpf-jvvq-wj6j/GHSA-cfpf-jvvq-wj6j.json @@ -7,12 +7,8 @@ "CVE-2019-8246" ], "details": "Adobe Media Encoder versions 13.1 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cfr7-m7j6-q7hh/GHSA-cfr7-m7j6-q7hh.json b/advisories/unreviewed/2022/05/GHSA-cfr7-m7j6-q7hh/GHSA-cfr7-m7j6-q7hh.json index 04205d4be44..4d710525953 100644 --- a/advisories/unreviewed/2022/05/GHSA-cfr7-m7j6-q7hh/GHSA-cfr7-m7j6-q7hh.json +++ b/advisories/unreviewed/2022/05/GHSA-cfr7-m7j6-q7hh/GHSA-cfr7-m7j6-q7hh.json @@ -7,12 +7,8 @@ "CVE-2006-0244" ], "details": "** DISPUTED ** Directory traversal vulnerability in workspaces.php in phpXplorer 0.9.33 allows remote attackers to include arbitrary files via a .. (dot dot) and trailing null byte (%00) in the sShare parameter. NOTE: a followup post claims that this is not a vulnerability since the functionality of phpXplorer supports the upload of PHP files, which would not cross privilege boundaries since the PHP functionality would support read access outside the web root.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cgr6-w3jj-mpwq/GHSA-cgr6-w3jj-mpwq.json b/advisories/unreviewed/2022/05/GHSA-cgr6-w3jj-mpwq/GHSA-cgr6-w3jj-mpwq.json index 1348de6cced..6e29a6f1a05 100644 --- a/advisories/unreviewed/2022/05/GHSA-cgr6-w3jj-mpwq/GHSA-cgr6-w3jj-mpwq.json +++ b/advisories/unreviewed/2022/05/GHSA-cgr6-w3jj-mpwq/GHSA-cgr6-w3jj-mpwq.json @@ -7,12 +7,8 @@ "CVE-2019-15435" ], "details": "The Samsung A7 Android device with a build fingerprint of samsung/a7y17ltexx/a7y17lte:8.0.0/R16NW/A720FXXU7CSC2:user/release-keys contains a pre-installed app with a package name of com.samsung.android.themecenter app (versionCode=7000000, versionName=7.0.0.0) that allows other pre-installed apps to perform app installation via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions that are required by other other pre-installed apps that exported their capabilities to other pre-installed app.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-ch4v-vxvm-66qf/GHSA-ch4v-vxvm-66qf.json b/advisories/unreviewed/2022/05/GHSA-ch4v-vxvm-66qf/GHSA-ch4v-vxvm-66qf.json index 930d6eeaa77..8937da248f2 100644 --- a/advisories/unreviewed/2022/05/GHSA-ch4v-vxvm-66qf/GHSA-ch4v-vxvm-66qf.json +++ b/advisories/unreviewed/2022/05/GHSA-ch4v-vxvm-66qf/GHSA-ch4v-vxvm-66qf.json @@ -7,12 +7,8 @@ "CVE-2006-4692" ], "details": "Argument injection vulnerability in the Windows Object Packager (packager.exe) in Microsoft Windows XP SP1 and SP2 and Server 2003 SP1 and earlier allows remote user-assisted attackers to execute arbitrary commands via a crafted file with a \"/\" (slash) character in the filename of the Command Line property, followed by a valid file extension, which causes the command before the slash to be executed, aka \"Object Packager Dialogue Spoofing Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cj89-fxr6-w3hf/GHSA-cj89-fxr6-w3hf.json b/advisories/unreviewed/2022/05/GHSA-cj89-fxr6-w3hf/GHSA-cj89-fxr6-w3hf.json index 2da9832d954..8b17f261677 100644 --- a/advisories/unreviewed/2022/05/GHSA-cj89-fxr6-w3hf/GHSA-cj89-fxr6-w3hf.json +++ b/advisories/unreviewed/2022/05/GHSA-cj89-fxr6-w3hf/GHSA-cj89-fxr6-w3hf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cjqj-g595-fh5j/GHSA-cjqj-g595-fh5j.json b/advisories/unreviewed/2022/05/GHSA-cjqj-g595-fh5j/GHSA-cjqj-g595-fh5j.json index b48b3408b83..e060e6e97fa 100644 --- a/advisories/unreviewed/2022/05/GHSA-cjqj-g595-fh5j/GHSA-cjqj-g595-fh5j.json +++ b/advisories/unreviewed/2022/05/GHSA-cjqj-g595-fh5j/GHSA-cjqj-g595-fh5j.json @@ -7,12 +7,8 @@ "CVE-2019-8237" ], "details": "Adobe Acrobat and Reader versions 2019.012.20034 and earlier; 2019.012.20035 and earlier versions; 2017.011.30142 and earlier versions; 2017.011.30143 and earlier versions; 2015.006.30497 and earlier versions; 2015.006.30498 and earlier versions have an Insufficiently Robust Encryption vulnerability. Successful exploitation could lead to Security feature bypass in the context of the current user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cmhc-65x4-m74h/GHSA-cmhc-65x4-m74h.json b/advisories/unreviewed/2022/05/GHSA-cmhc-65x4-m74h/GHSA-cmhc-65x4-m74h.json index 73594ef36a6..e224e2b2140 100644 --- a/advisories/unreviewed/2022/05/GHSA-cmhc-65x4-m74h/GHSA-cmhc-65x4-m74h.json +++ b/advisories/unreviewed/2022/05/GHSA-cmhc-65x4-m74h/GHSA-cmhc-65x4-m74h.json @@ -7,12 +7,8 @@ "CVE-2019-9466" ], "details": "In the Broadcom Wi-Fi driver, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-130375182", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cmhr-387m-5p4h/GHSA-cmhr-387m-5p4h.json b/advisories/unreviewed/2022/05/GHSA-cmhr-387m-5p4h/GHSA-cmhr-387m-5p4h.json index 81718eca97a..391e5b1dcbb 100644 --- a/advisories/unreviewed/2022/05/GHSA-cmhr-387m-5p4h/GHSA-cmhr-387m-5p4h.json +++ b/advisories/unreviewed/2022/05/GHSA-cmhr-387m-5p4h/GHSA-cmhr-387m-5p4h.json @@ -7,12 +7,8 @@ "CVE-2019-15459" ], "details": "The Samsung J7 Neo Android device with a build fingerprint of samsung/j7velteub/j7velte:8.1.0/M1AJQ/J701MUBS6BSB3:user/release-keys contains a pre-installed app with a package name of com.samsung.android.themecenter app (versionCode=7000100, versionName=7.0.1.0) that allows other pre-installed apps to perform app installation via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions that are required by other other pre-installed apps that exported their capabilities to other pre-installed app.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cpj8-xq5g-766p/GHSA-cpj8-xq5g-766p.json b/advisories/unreviewed/2022/05/GHSA-cpj8-xq5g-766p/GHSA-cpj8-xq5g-766p.json index 79a49796b56..aeb5940711e 100644 --- a/advisories/unreviewed/2022/05/GHSA-cpj8-xq5g-766p/GHSA-cpj8-xq5g-766p.json +++ b/advisories/unreviewed/2022/05/GHSA-cpj8-xq5g-766p/GHSA-cpj8-xq5g-766p.json @@ -7,12 +7,8 @@ "CVE-2019-8247" ], "details": "Adobe Illustrator CC versions 23.1 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution .", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cppq-h53q-89f4/GHSA-cppq-h53q-89f4.json b/advisories/unreviewed/2022/05/GHSA-cppq-h53q-89f4/GHSA-cppq-h53q-89f4.json index fbec7d23b37..17625275d65 100644 --- a/advisories/unreviewed/2022/05/GHSA-cppq-h53q-89f4/GHSA-cppq-h53q-89f4.json +++ b/advisories/unreviewed/2022/05/GHSA-cppq-h53q-89f4/GHSA-cppq-h53q-89f4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cq6j-h35c-x8gr/GHSA-cq6j-h35c-x8gr.json b/advisories/unreviewed/2022/05/GHSA-cq6j-h35c-x8gr/GHSA-cq6j-h35c-x8gr.json index 5c741eb6c5c..5841daded59 100644 --- a/advisories/unreviewed/2022/05/GHSA-cq6j-h35c-x8gr/GHSA-cq6j-h35c-x8gr.json +++ b/advisories/unreviewed/2022/05/GHSA-cq6j-h35c-x8gr/GHSA-cq6j-h35c-x8gr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cqx9-5jf7-v73f/GHSA-cqx9-5jf7-v73f.json b/advisories/unreviewed/2022/05/GHSA-cqx9-5jf7-v73f/GHSA-cqx9-5jf7-v73f.json index 605affa17f4..68dac6d33ae 100644 --- a/advisories/unreviewed/2022/05/GHSA-cqx9-5jf7-v73f/GHSA-cqx9-5jf7-v73f.json +++ b/advisories/unreviewed/2022/05/GHSA-cqx9-5jf7-v73f/GHSA-cqx9-5jf7-v73f.json @@ -7,12 +7,8 @@ "CVE-2019-15454" ], "details": "The Samsung J4 Android device with a build fingerprint of samsung/j4lteub/j4lte:8.0.0/R16NW/J400MUBU2ARL4:user/release-keys contains a pre-installed app with a package name of com.samsung.android.themecenter app (versionCode=7000000, versionName=7.0.0.0) that allows other pre-installed apps to perform app installation via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions that are required by other other pre-installed apps that exported their capabilities to other pre-installed app.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cvx9-pmx4-49qh/GHSA-cvx9-pmx4-49qh.json b/advisories/unreviewed/2022/05/GHSA-cvx9-pmx4-49qh/GHSA-cvx9-pmx4-49qh.json index 4e414850b2f..837a7f88309 100644 --- a/advisories/unreviewed/2022/05/GHSA-cvx9-pmx4-49qh/GHSA-cvx9-pmx4-49qh.json +++ b/advisories/unreviewed/2022/05/GHSA-cvx9-pmx4-49qh/GHSA-cvx9-pmx4-49qh.json @@ -7,12 +7,8 @@ "CVE-2019-15398" ], "details": "The Asus ZenFone 4 Selfie Android device with a build fingerprint of asus/WW_Z01M/ASUS_Z01M_1:7.1.1/NMF26F/WW_user_11.40.208.77_20170922:user/release-keys contains a pre-installed app with a package name of com.asus.loguploaderproxy app (versionCode=1570000015, versionName=7.0.0.3_161222) that allows other pre-installed apps to perform command execution via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions that are required by other other pre-installed apps that exported their capabilities to other pre-installed app.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cvxm-wxqh-j5rx/GHSA-cvxm-wxqh-j5rx.json b/advisories/unreviewed/2022/05/GHSA-cvxm-wxqh-j5rx/GHSA-cvxm-wxqh-j5rx.json index bfdd9edffd1..69b6544aa1d 100644 --- a/advisories/unreviewed/2022/05/GHSA-cvxm-wxqh-j5rx/GHSA-cvxm-wxqh-j5rx.json +++ b/advisories/unreviewed/2022/05/GHSA-cvxm-wxqh-j5rx/GHSA-cvxm-wxqh-j5rx.json @@ -7,12 +7,8 @@ "CVE-2015-9531" ], "details": "The Easy Digital Downloads (EDD) Wish Lists extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cwq5-hmvf-4398/GHSA-cwq5-hmvf-4398.json b/advisories/unreviewed/2022/05/GHSA-cwq5-hmvf-4398/GHSA-cwq5-hmvf-4398.json index 524be20f55b..beed1639954 100644 --- a/advisories/unreviewed/2022/05/GHSA-cwq5-hmvf-4398/GHSA-cwq5-hmvf-4398.json +++ b/advisories/unreviewed/2022/05/GHSA-cwq5-hmvf-4398/GHSA-cwq5-hmvf-4398.json @@ -7,12 +7,8 @@ "CVE-2019-10486" ], "details": "Race condition due to the lack of resource lock which will be concurrently modified in the memcpy statement leads to out of bound access in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, MDM9206, MDM9207C, MDM9607, MDM9640, MDM9650, MSM8905, MSM8909W, MSM8939, MSM8953, MSM8996AU, MSM8998, Nicobar, QCN7605, QCS405, QCS605, QM215, SDA660, SDA845, SDM429, SDM439, SDM630, SDM632, SDM636, SDM660, SDM710, SDM845, SDX20, SDX24, SM6150, SM7150, SM8150", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cxq3-92v8-cjw8/GHSA-cxq3-92v8-cjw8.json b/advisories/unreviewed/2022/05/GHSA-cxq3-92v8-cjw8/GHSA-cxq3-92v8-cjw8.json index 06ebfd98556..f4fdc6c19c1 100644 --- a/advisories/unreviewed/2022/05/GHSA-cxq3-92v8-cjw8/GHSA-cxq3-92v8-cjw8.json +++ b/advisories/unreviewed/2022/05/GHSA-cxq3-92v8-cjw8/GHSA-cxq3-92v8-cjw8.json @@ -7,12 +7,8 @@ "CVE-2006-5437" ], "details": "** DISPUTED ** Directory traversal vulnerability in upgrade.php in phpAdsNew 2.0.8 allows remote attackers to read arbitrary files via a .. (dot dot) in the phpAds_config[language] parameter. NOTE: this issue could not be reproduced by a third party.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cxqj-w53w-v37h/GHSA-cxqj-w53w-v37h.json b/advisories/unreviewed/2022/05/GHSA-cxqj-w53w-v37h/GHSA-cxqj-w53w-v37h.json index 6835d290f87..2b1b62ed573 100644 --- a/advisories/unreviewed/2022/05/GHSA-cxqj-w53w-v37h/GHSA-cxqj-w53w-v37h.json +++ b/advisories/unreviewed/2022/05/GHSA-cxqj-w53w-v37h/GHSA-cxqj-w53w-v37h.json @@ -7,12 +7,8 @@ "CVE-2019-15420" ], "details": "The Blackview BV9000Pro-F Android device with a build fingerprint of Blackview/BV9000Pro-F/BV9000Pro-F:7.1.1/N4F26M/1514363110:user/release-keys contains a pre-installed app with a package name of com.mediatek.factorymode app (versionCode=1, versionName=1) that allows unauthorized wireless settings modification via a confused deputy attack. This capability can be accessed by any app co-located on the device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f24q-c9pm-2vq6/GHSA-f24q-c9pm-2vq6.json b/advisories/unreviewed/2022/05/GHSA-f24q-c9pm-2vq6/GHSA-f24q-c9pm-2vq6.json index f8cc91ffc21..3dec39bd26f 100644 --- a/advisories/unreviewed/2022/05/GHSA-f24q-c9pm-2vq6/GHSA-f24q-c9pm-2vq6.json +++ b/advisories/unreviewed/2022/05/GHSA-f24q-c9pm-2vq6/GHSA-f24q-c9pm-2vq6.json @@ -7,12 +7,8 @@ "CVE-2019-18278" ], "details": "When executing VideoLAN VLC media player 3.0.8 with libqt on Windows, Data from a Faulting Address controls Code Flow starting at libqt_plugin!vlc_entry_license__3_0_0f+0x00000000003b9aba.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f25w-hjcw-x829/GHSA-f25w-hjcw-x829.json b/advisories/unreviewed/2022/05/GHSA-f25w-hjcw-x829/GHSA-f25w-hjcw-x829.json index adffce3ca6b..e957290a195 100644 --- a/advisories/unreviewed/2022/05/GHSA-f25w-hjcw-x829/GHSA-f25w-hjcw-x829.json +++ b/advisories/unreviewed/2022/05/GHSA-f25w-hjcw-x829/GHSA-f25w-hjcw-x829.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f3pv-9fwh-mp3x/GHSA-f3pv-9fwh-mp3x.json b/advisories/unreviewed/2022/05/GHSA-f3pv-9fwh-mp3x/GHSA-f3pv-9fwh-mp3x.json index 7751e79cf1a..b1075d07f06 100644 --- a/advisories/unreviewed/2022/05/GHSA-f3pv-9fwh-mp3x/GHSA-f3pv-9fwh-mp3x.json +++ b/advisories/unreviewed/2022/05/GHSA-f3pv-9fwh-mp3x/GHSA-f3pv-9fwh-mp3x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f4w6-q9v4-2wq7/GHSA-f4w6-q9v4-2wq7.json b/advisories/unreviewed/2022/05/GHSA-f4w6-q9v4-2wq7/GHSA-f4w6-q9v4-2wq7.json index 68c7dc6c2ab..b478cbd6a43 100644 --- a/advisories/unreviewed/2022/05/GHSA-f4w6-q9v4-2wq7/GHSA-f4w6-q9v4-2wq7.json +++ b/advisories/unreviewed/2022/05/GHSA-f4w6-q9v4-2wq7/GHSA-f4w6-q9v4-2wq7.json @@ -7,12 +7,8 @@ "CVE-2019-15346" ], "details": "The Tecno Camon iClick 2 Android device with a build fingerprint of TECNO/H622/TECNO-ID6:8.1.0/O11019/F-180824V116:user/release-keys contains a pre-installed platform app with a package name of com.lovelyfont.defcontainer (versionCode=7, versionName=7.0.11). This app contains an exported service named com.lovelyfont.manager.service.FunctionService that allows any app co-located on the device to supply the file path to a Dalvik Executable (DEX) file which it will dynamically load within its own process and execute in with its own system privileges. This app cannot be disabled by the user and the attack can be performed by a zero-permission app. Executing commands as the system user can allow a third-party app to video record the user's screen, factory reset the device, obtain the user's notifications, read the logcat logs, inject events in the Graphical User Interface (GUI), and obtains the user's text messages, and more. Executing code as the system user can allow a third-party app to factory reset the device, obtain the user's Wi-Fi passwords, obtain the user's notifications, read the logcat logs, inject events in the GUI, change the default Input Method Editor (IME) (e.g., keyboard) with one contained within the attacking app that contains keylogging functionality, and obtains the user's text messages, and more.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f4wh-c3m6-3xxv/GHSA-f4wh-c3m6-3xxv.json b/advisories/unreviewed/2022/05/GHSA-f4wh-c3m6-3xxv/GHSA-f4wh-c3m6-3xxv.json index ea84c57510e..e3f328e7c38 100644 --- a/advisories/unreviewed/2022/05/GHSA-f4wh-c3m6-3xxv/GHSA-f4wh-c3m6-3xxv.json +++ b/advisories/unreviewed/2022/05/GHSA-f4wh-c3m6-3xxv/GHSA-f4wh-c3m6-3xxv.json @@ -7,12 +7,8 @@ "CVE-2019-1398" ], "details": "A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1389, CVE-2019-1397.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f5g2-85rj-5g35/GHSA-f5g2-85rj-5g35.json b/advisories/unreviewed/2022/05/GHSA-f5g2-85rj-5g35/GHSA-f5g2-85rj-5g35.json index edff47135d1..29d17f2d804 100644 --- a/advisories/unreviewed/2022/05/GHSA-f5g2-85rj-5g35/GHSA-f5g2-85rj-5g35.json +++ b/advisories/unreviewed/2022/05/GHSA-f5g2-85rj-5g35/GHSA-f5g2-85rj-5g35.json @@ -7,12 +7,8 @@ "CVE-2019-4394" ], "details": "IBM Cloud Orchestrator 2.4 through 2.4.0.5 and 2.5 through 2.5.0.9 contain APIs that could be used by a local user to send email. IBM X-Force ID: 162232.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f5jv-2hrp-wqq3/GHSA-f5jv-2hrp-wqq3.json b/advisories/unreviewed/2022/05/GHSA-f5jv-2hrp-wqq3/GHSA-f5jv-2hrp-wqq3.json index 052b3caca4b..2d3c0eb704a 100644 --- a/advisories/unreviewed/2022/05/GHSA-f5jv-2hrp-wqq3/GHSA-f5jv-2hrp-wqq3.json +++ b/advisories/unreviewed/2022/05/GHSA-f5jv-2hrp-wqq3/GHSA-f5jv-2hrp-wqq3.json @@ -7,12 +7,8 @@ "CVE-2019-8216" ], "details": "Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure .", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f5qf-9v3x-p5j4/GHSA-f5qf-9v3x-p5j4.json b/advisories/unreviewed/2022/05/GHSA-f5qf-9v3x-p5j4/GHSA-f5qf-9v3x-p5j4.json index 29b1157a04a..ac6e4a4a7a1 100644 --- a/advisories/unreviewed/2022/05/GHSA-f5qf-9v3x-p5j4/GHSA-f5qf-9v3x-p5j4.json +++ b/advisories/unreviewed/2022/05/GHSA-f5qf-9v3x-p5j4/GHSA-f5qf-9v3x-p5j4.json @@ -7,12 +7,8 @@ "CVE-2019-2233" ], "details": "In getUserCount and getCount of UserSwitcherController.java, there is possible new user creation due to a logic error. This could lead to local escalation of privilege for an attacker who has physical access to the device with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-140486529", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f5vg-7m5w-hxcv/GHSA-f5vg-7m5w-hxcv.json b/advisories/unreviewed/2022/05/GHSA-f5vg-7m5w-hxcv/GHSA-f5vg-7m5w-hxcv.json index da9f2e7807f..1762464badb 100644 --- a/advisories/unreviewed/2022/05/GHSA-f5vg-7m5w-hxcv/GHSA-f5vg-7m5w-hxcv.json +++ b/advisories/unreviewed/2022/05/GHSA-f5vg-7m5w-hxcv/GHSA-f5vg-7m5w-hxcv.json @@ -7,12 +7,8 @@ "CVE-2006-5089" ], "details": "** DISPUTED ** PHP remote file inclusion vulnerability in mybic_server.php in Jim Plush My-BIC 0.6.5 allows remote attackers to execute arbitrary PHP code via a URL in the file parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information. CVE disputes this vulnerability because the file variable is defined before use in a way that prevents arbitrary inclusion.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f7fc-w7v7-g3q3/GHSA-f7fc-w7v7-g3q3.json b/advisories/unreviewed/2022/05/GHSA-f7fc-w7v7-g3q3/GHSA-f7fc-w7v7-g3q3.json index 21bee0c1804..d9ac7bae65e 100644 --- a/advisories/unreviewed/2022/05/GHSA-f7fc-w7v7-g3q3/GHSA-f7fc-w7v7-g3q3.json +++ b/advisories/unreviewed/2022/05/GHSA-f7fc-w7v7-g3q3/GHSA-f7fc-w7v7-g3q3.json @@ -7,12 +7,8 @@ "CVE-2019-15804" ], "details": "An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. By sending a signal to the CLI process, undocumented functionality is triggered. Specifically, a menu can be triggered by sending the SIGQUIT signal to the CLI application (e.g., through CTRL+\\ via SSH). The access control check for this menu does work and prohibits accessing the menu, which contains \"Password recovery for specific user\" options. The menu is believed to be accessible using a serial console.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f8h2-5cwx-9wvg/GHSA-f8h2-5cwx-9wvg.json b/advisories/unreviewed/2022/05/GHSA-f8h2-5cwx-9wvg/GHSA-f8h2-5cwx-9wvg.json index d80b38b9f49..37280971b70 100644 --- a/advisories/unreviewed/2022/05/GHSA-f8h2-5cwx-9wvg/GHSA-f8h2-5cwx-9wvg.json +++ b/advisories/unreviewed/2022/05/GHSA-f8h2-5cwx-9wvg/GHSA-f8h2-5cwx-9wvg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fc3j-3f83-7fhr/GHSA-fc3j-3f83-7fhr.json b/advisories/unreviewed/2022/05/GHSA-fc3j-3f83-7fhr/GHSA-fc3j-3f83-7fhr.json index 5aa6ac31e69..7714bfd6838 100644 --- a/advisories/unreviewed/2022/05/GHSA-fc3j-3f83-7fhr/GHSA-fc3j-3f83-7fhr.json +++ b/advisories/unreviewed/2022/05/GHSA-fc3j-3f83-7fhr/GHSA-fc3j-3f83-7fhr.json @@ -7,12 +7,8 @@ "CVE-2009-3107" ], "details": "Symantec Altiris Deployment Solution 6.9.x before 6.9 SP3 Build 430 does not properly restrict access to the listening port for the DBManager service, which allows remote attackers to bypass authentication and modify tasks or the Altiris Database via a connection to this service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fc87-p997-x4c5/GHSA-fc87-p997-x4c5.json b/advisories/unreviewed/2022/05/GHSA-fc87-p997-x4c5/GHSA-fc87-p997-x4c5.json index a86dd054a24..3b96dda2674 100644 --- a/advisories/unreviewed/2022/05/GHSA-fc87-p997-x4c5/GHSA-fc87-p997-x4c5.json +++ b/advisories/unreviewed/2022/05/GHSA-fc87-p997-x4c5/GHSA-fc87-p997-x4c5.json @@ -7,12 +7,8 @@ "CVE-2019-11179" ], "details": "Insufficient input validation in Intel(R) Baseboard Management Controller firmware may allow an authenticated user to potentially enable information disclosure via network access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fcfc-cp3g-xgf3/GHSA-fcfc-cp3g-xgf3.json b/advisories/unreviewed/2022/05/GHSA-fcfc-cp3g-xgf3/GHSA-fcfc-cp3g-xgf3.json index 22d0324c9c4..604c684933c 100644 --- a/advisories/unreviewed/2022/05/GHSA-fcfc-cp3g-xgf3/GHSA-fcfc-cp3g-xgf3.json +++ b/advisories/unreviewed/2022/05/GHSA-fcfc-cp3g-xgf3/GHSA-fcfc-cp3g-xgf3.json @@ -7,12 +7,8 @@ "CVE-2019-14345" ], "details": "TemaTres 3.0 allows remote unprivileged users to create an administrator account", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fcm8-q275-jqv2/GHSA-fcm8-q275-jqv2.json b/advisories/unreviewed/2022/05/GHSA-fcm8-q275-jqv2/GHSA-fcm8-q275-jqv2.json index 07669ff9f1e..10c8f694d04 100644 --- a/advisories/unreviewed/2022/05/GHSA-fcm8-q275-jqv2/GHSA-fcm8-q275-jqv2.json +++ b/advisories/unreviewed/2022/05/GHSA-fcm8-q275-jqv2/GHSA-fcm8-q275-jqv2.json @@ -7,12 +7,8 @@ "CVE-2019-18397" ], "details": "A buffer overflow in the fribidi_get_par_embedding_levels_ex() function in lib/fribidi-bidi.c of GNU FriBidi through 1.0.7 allows an attacker to cause a denial of service or possibly execute arbitrary code by delivering crafted text content to a user, when this content is then rendered by an application that uses FriBidi for text layout calculations. Examples include any GNOME or GTK+ based application that uses Pango for text layout, as this internally uses FriBidi for bidirectional text layout. For example, the attacker can construct a crafted text file to be opened in GEdit, or a crafted IRC message to be viewed in HexChat.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fcqr-w4fr-6f6x/GHSA-fcqr-w4fr-6f6x.json b/advisories/unreviewed/2022/05/GHSA-fcqr-w4fr-6f6x/GHSA-fcqr-w4fr-6f6x.json index bd811081192..152fa80635e 100644 --- a/advisories/unreviewed/2022/05/GHSA-fcqr-w4fr-6f6x/GHSA-fcqr-w4fr-6f6x.json +++ b/advisories/unreviewed/2022/05/GHSA-fcqr-w4fr-6f6x/GHSA-fcqr-w4fr-6f6x.json @@ -7,12 +7,8 @@ "CVE-2019-3636" ], "details": "A File Masquerade vulnerability in McAfee Total Protection (MTP) version 16.0.R21 and earlier in Windows client allowed an attacker to read the plaintext list of AV-Scan exclusion files from the Windows registry, and to possibly replace excluded files with potential malware without being detected.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fg7h-6rv7-89fq/GHSA-fg7h-6rv7-89fq.json b/advisories/unreviewed/2022/05/GHSA-fg7h-6rv7-89fq/GHSA-fg7h-6rv7-89fq.json index 74f8f46f950..4a44d093ef9 100644 --- a/advisories/unreviewed/2022/05/GHSA-fg7h-6rv7-89fq/GHSA-fg7h-6rv7-89fq.json +++ b/advisories/unreviewed/2022/05/GHSA-fg7h-6rv7-89fq/GHSA-fg7h-6rv7-89fq.json @@ -7,12 +7,8 @@ "CVE-2019-15334" ], "details": "The Lava Iris 88 Go Android device with a build fingerprint of LAVA/iris88_go/iris88_go:8.1.0/O11019/1538188945:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionName=v4.0.27) that allows any app co-located on the device to programmatically disable and enable Wi-Fi without the corresponding access permission through an exported interface.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fg98-c29c-pp96/GHSA-fg98-c29c-pp96.json b/advisories/unreviewed/2022/05/GHSA-fg98-c29c-pp96/GHSA-fg98-c29c-pp96.json index e1e49e63dbd..95733864556 100644 --- a/advisories/unreviewed/2022/05/GHSA-fg98-c29c-pp96/GHSA-fg98-c29c-pp96.json +++ b/advisories/unreviewed/2022/05/GHSA-fg98-c29c-pp96/GHSA-fg98-c29c-pp96.json @@ -7,12 +7,8 @@ "CVE-2019-15391" ], "details": "The Asus ZenFone 4 Selfie Android device with a build fingerprint of asus/WW_Phone/ASUS_X00LD_1:8.1.0/OPM1.171019.011/15.0400.1809.405-0:user/release-keys contains a pre-installed app with a package name of com.log.logservice app (versionCode=1, versionName=1) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fjg9-5vfm-h7wx/GHSA-fjg9-5vfm-h7wx.json b/advisories/unreviewed/2022/05/GHSA-fjg9-5vfm-h7wx/GHSA-fjg9-5vfm-h7wx.json index e20b279682d..5f7daaa49c0 100644 --- a/advisories/unreviewed/2022/05/GHSA-fjg9-5vfm-h7wx/GHSA-fjg9-5vfm-h7wx.json +++ b/advisories/unreviewed/2022/05/GHSA-fjg9-5vfm-h7wx/GHSA-fjg9-5vfm-h7wx.json @@ -7,12 +7,8 @@ "CVE-2019-8212" ], "details": "Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fpcm-j34w-8cjw/GHSA-fpcm-j34w-8cjw.json b/advisories/unreviewed/2022/05/GHSA-fpcm-j34w-8cjw/GHSA-fpcm-j34w-8cjw.json index 0c1bdd4cb66..ff0f314051b 100644 --- a/advisories/unreviewed/2022/05/GHSA-fpcm-j34w-8cjw/GHSA-fpcm-j34w-8cjw.json +++ b/advisories/unreviewed/2022/05/GHSA-fpcm-j34w-8cjw/GHSA-fpcm-j34w-8cjw.json @@ -7,12 +7,8 @@ "CVE-2019-12720" ], "details": "AUO SunVeillance Monitoring System before v1.1.9e is vulnerable to mvc_send_mail.aspx (MailAdd parameter) SQL Injection. An Attacker can carry a SQL Injection payload to the server, allowing the attacker to read privileged data. This also affects the picture_manage_mvc.aspx plant_no parameter, the swapdl_mvc.aspx plant_no parameter, and the account_management.aspx Text_Postal_Code and Text_Dis_Code parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fpp6-jfvj-93c8/GHSA-fpp6-jfvj-93c8.json b/advisories/unreviewed/2022/05/GHSA-fpp6-jfvj-93c8/GHSA-fpp6-jfvj-93c8.json index c2e85c19ee0..cceafdd9aed 100644 --- a/advisories/unreviewed/2022/05/GHSA-fpp6-jfvj-93c8/GHSA-fpp6-jfvj-93c8.json +++ b/advisories/unreviewed/2022/05/GHSA-fpp6-jfvj-93c8/GHSA-fpp6-jfvj-93c8.json @@ -7,12 +7,8 @@ "CVE-2015-9516" ], "details": "The Easy Digital Downloads (EDD) Invoices extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fq78-jw2r-hqcx/GHSA-fq78-jw2r-hqcx.json b/advisories/unreviewed/2022/05/GHSA-fq78-jw2r-hqcx/GHSA-fq78-jw2r-hqcx.json index 666b916b7c9..34ead569a91 100644 --- a/advisories/unreviewed/2022/05/GHSA-fq78-jw2r-hqcx/GHSA-fq78-jw2r-hqcx.json +++ b/advisories/unreviewed/2022/05/GHSA-fq78-jw2r-hqcx/GHSA-fq78-jw2r-hqcx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fqf6-vc5w-q8r5/GHSA-fqf6-vc5w-q8r5.json b/advisories/unreviewed/2022/05/GHSA-fqf6-vc5w-q8r5/GHSA-fqf6-vc5w-q8r5.json index 7f5f7e65429..556d876cc62 100644 --- a/advisories/unreviewed/2022/05/GHSA-fqf6-vc5w-q8r5/GHSA-fqf6-vc5w-q8r5.json +++ b/advisories/unreviewed/2022/05/GHSA-fqf6-vc5w-q8r5/GHSA-fqf6-vc5w-q8r5.json @@ -7,12 +7,8 @@ "CVE-2019-5246" ], "details": "Smartphones with software of ELLE-AL00B 9.1.0.109(C00E106R1P21), 9.1.0.113(C00E110R1P21), 9.1.0.125(C00E120R1P21), 9.1.0.135(C00E130R1P21), 9.1.0.153(C00E150R1P21), 9.1.0.155(C00E150R1P21), 9.1.0.162(C00E160R2P1) have an insufficient verification vulnerability. The system does not verify certain parameters sufficiently, an attacker should connect to the phone and gain high privilege to launch the attack. Successful exploit could cause DOS or malicious code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fr43-mxwp-f7vj/GHSA-fr43-mxwp-f7vj.json b/advisories/unreviewed/2022/05/GHSA-fr43-mxwp-f7vj/GHSA-fr43-mxwp-f7vj.json index bb9ae7525ea..99589b55219 100644 --- a/advisories/unreviewed/2022/05/GHSA-fr43-mxwp-f7vj/GHSA-fr43-mxwp-f7vj.json +++ b/advisories/unreviewed/2022/05/GHSA-fr43-mxwp-f7vj/GHSA-fr43-mxwp-f7vj.json @@ -7,12 +7,8 @@ "CVE-2019-15415" ], "details": "The Xiaomi Redmi 5 Android device with a build fingerprint of xiaomi/vince/vince:7.1.2/N2G47H/V9.5.4.0.NEGMIFA:user/release-keys contains a pre-installed app with a package name of com.huaqin.factory app (versionCode=1, versionName=QL1711_201803291645) that allows unauthorized wireless settings modification via a confused deputy attack. This capability can be accessed by any app co-located on the device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fvpf-4m7h-jg3p/GHSA-fvpf-4m7h-jg3p.json b/advisories/unreviewed/2022/05/GHSA-fvpf-4m7h-jg3p/GHSA-fvpf-4m7h-jg3p.json index e8b03d80f6c..77f49b2c7ca 100644 --- a/advisories/unreviewed/2022/05/GHSA-fvpf-4m7h-jg3p/GHSA-fvpf-4m7h-jg3p.json +++ b/advisories/unreviewed/2022/05/GHSA-fvpf-4m7h-jg3p/GHSA-fvpf-4m7h-jg3p.json @@ -7,12 +7,8 @@ "CVE-2019-15799" ], "details": "An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. User accounts created through the web interface of the device, when given non-admin level privileges, have the same level of privileged access as administrators when connecting to the device via SSH (while their permissions via the web interface are in fact restricted). This allows normal users to obtain the administrative password by running the tech-support command via the CLI: this contains the encrypted passwords for all users on the device. As these passwords are encrypted using well-known and static parameters, they can be decrypted and the original passwords (including the administrator password) can be obtained.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fvxv-fjqj-xx47/GHSA-fvxv-fjqj-xx47.json b/advisories/unreviewed/2022/05/GHSA-fvxv-fjqj-xx47/GHSA-fvxv-fjqj-xx47.json index d8c5874ce15..737c4b857dd 100644 --- a/advisories/unreviewed/2022/05/GHSA-fvxv-fjqj-xx47/GHSA-fvxv-fjqj-xx47.json +++ b/advisories/unreviewed/2022/05/GHSA-fvxv-fjqj-xx47/GHSA-fvxv-fjqj-xx47.json @@ -7,12 +7,8 @@ "CVE-2019-6191" ], "details": "A potential vulnerability in the discontinued LenovoPaper software version 1.0.0.22 may allow local privilege escalation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fx36-656m-qm32/GHSA-fx36-656m-qm32.json b/advisories/unreviewed/2022/05/GHSA-fx36-656m-qm32/GHSA-fx36-656m-qm32.json index 797fe7c04c9..65593192ac6 100644 --- a/advisories/unreviewed/2022/05/GHSA-fx36-656m-qm32/GHSA-fx36-656m-qm32.json +++ b/advisories/unreviewed/2022/05/GHSA-fx36-656m-qm32/GHSA-fx36-656m-qm32.json @@ -7,12 +7,8 @@ "CVE-2019-15344" ], "details": "The Tecno Camon iClick Android device with a build fingerprint of TECNO/H633/TECNO-IN6:8.1.0/O11019/A-180409V96:user/release-keys contains a pre-installed platform app with a package name of com.lovelyfont.defcontainer (versionCode=7, versionName=7.0.8). This app contains an exported service named com.lovelyfont.manager.FontCoverService that allows any app co-located on the device to supply arbitrary commands to be executed as the system user. This app cannot be disabled by the user and the attack can be performed by a zero-permission app. In addition to the local attack surface, its accompanying app with a package name of com.ekesoo.lovelyhifonts makes network requests using HTTP and an attacker can perform a Man-in-the-Middle (MITM) attack on the connection to inject a command in a network response that will be executed as the system user by the com.lovelyfont.defcontainer app. Executing commands as the system user can allow a third-party app to video record the user's screen, factory reset the device, obtain the user's notifications, read the logcat logs, inject events in the Graphical User Interface (GUI), and obtains the user's text messages, and more. Executing commands as the system user can allow a third-party app to factory reset the device, obtain the user's notifications, read the logcat logs, inject events in the GUI, change the default Input Method Editor (IME) (e.g., keyboard) with one contained within the attacking app that contains keylogging functionality, and obtains the user's text messages, and more.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g22q-gmqw-xvw4/GHSA-g22q-gmqw-xvw4.json b/advisories/unreviewed/2022/05/GHSA-g22q-gmqw-xvw4/GHSA-g22q-gmqw-xvw4.json index 79f2688a286..a1797463515 100644 --- a/advisories/unreviewed/2022/05/GHSA-g22q-gmqw-xvw4/GHSA-g22q-gmqw-xvw4.json +++ b/advisories/unreviewed/2022/05/GHSA-g22q-gmqw-xvw4/GHSA-g22q-gmqw-xvw4.json @@ -7,12 +7,8 @@ "CVE-2019-15801" ], "details": "An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. The firmware image contains encrypted passwords that are used to authenticate users wishing to access a diagnostics or password-recovery menu. Using the hardcoded cryptographic key found elsewhere in the firmware, these passwords can be decrypted. This is related to fds_sys_passDebugPasswd_ret() and fds_sys_passRecoveryPasswd_ret() in libfds.so.0.0.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g24r-78hm-59x2/GHSA-g24r-78hm-59x2.json b/advisories/unreviewed/2022/05/GHSA-g24r-78hm-59x2/GHSA-g24r-78hm-59x2.json index 79acbfd9cbb..02174d84b1b 100644 --- a/advisories/unreviewed/2022/05/GHSA-g24r-78hm-59x2/GHSA-g24r-78hm-59x2.json +++ b/advisories/unreviewed/2022/05/GHSA-g24r-78hm-59x2/GHSA-g24r-78hm-59x2.json @@ -7,12 +7,8 @@ "CVE-2019-15455" ], "details": "The Samsung J5 Android device with a build fingerprint of samsung/j5y17ltexx/j5y17lte:8.1.0/M1AJQ/J530FXXU3BRL1:user/release-keys contains a pre-installed app with a package name of com.samsung.android.themecenter app (versionCode=7000100, versionName=7.0.1.0) that allows other pre-installed apps to perform app installation via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions that are required by other other pre-installed apps that exported their capabilities to other pre-installed app.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g2w2-352j-xq39/GHSA-g2w2-352j-xq39.json b/advisories/unreviewed/2022/05/GHSA-g2w2-352j-xq39/GHSA-g2w2-352j-xq39.json index 118088fd3d1..e581821e763 100644 --- a/advisories/unreviewed/2022/05/GHSA-g2w2-352j-xq39/GHSA-g2w2-352j-xq39.json +++ b/advisories/unreviewed/2022/05/GHSA-g2w2-352j-xq39/GHSA-g2w2-352j-xq39.json @@ -7,12 +7,8 @@ "CVE-2005-1876" ], "details": "Direct code injection vulnerability in CuteNews 1.3.6 and earlier allows remote attackers with administrative privileges to execute arbitrary PHP code via certain inputs that are injected into a template (.tpl) file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g37x-8fq5-rmrc/GHSA-g37x-8fq5-rmrc.json b/advisories/unreviewed/2022/05/GHSA-g37x-8fq5-rmrc/GHSA-g37x-8fq5-rmrc.json index 8a917de9523..16905cad9fb 100644 --- a/advisories/unreviewed/2022/05/GHSA-g37x-8fq5-rmrc/GHSA-g37x-8fq5-rmrc.json +++ b/advisories/unreviewed/2022/05/GHSA-g37x-8fq5-rmrc/GHSA-g37x-8fq5-rmrc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g64v-qpxx-3cw6/GHSA-g64v-qpxx-3cw6.json b/advisories/unreviewed/2022/05/GHSA-g64v-qpxx-3cw6/GHSA-g64v-qpxx-3cw6.json index 63633e18fae..3ddd9313d23 100644 --- a/advisories/unreviewed/2022/05/GHSA-g64v-qpxx-3cw6/GHSA-g64v-qpxx-3cw6.json +++ b/advisories/unreviewed/2022/05/GHSA-g64v-qpxx-3cw6/GHSA-g64v-qpxx-3cw6.json @@ -7,12 +7,8 @@ "CVE-2006-4609" ], "details": "** DISPUTED ** Multiple PHP remote file inclusion vulnerabilities in the Content Management module (\"Content manager\") for PHProjekt 0.6.1, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via the path_pre parameter in (1) cm_lib.inc.php, (2) doc/br.edithelp.php, (3) doc/de.edithelp.php, (4) doc/ct.edithelp.php, (5) userrating.php, and (6) listing.php, a different set of vectors than CVE-2006-4204. NOTE: a third-party researcher has disputed the impact of the cm_lib.inc.php vector, stating that it is limited to local file inclusion. CVE analysis as of 20060905 concurs, although use of ftp URLs is also possible. The remaining five vectors have also been disputed by the same third party, stating that the path_pre variable is initialized before it is used.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g7c6-4vj7-pff3/GHSA-g7c6-4vj7-pff3.json b/advisories/unreviewed/2022/05/GHSA-g7c6-4vj7-pff3/GHSA-g7c6-4vj7-pff3.json index 3eb6ba01f96..bbacd6918bf 100644 --- a/advisories/unreviewed/2022/05/GHSA-g7c6-4vj7-pff3/GHSA-g7c6-4vj7-pff3.json +++ b/advisories/unreviewed/2022/05/GHSA-g7c6-4vj7-pff3/GHSA-g7c6-4vj7-pff3.json @@ -7,12 +7,8 @@ "CVE-2019-18648" ], "details": "When logged in as an admin user, the Untangle NG firewall 14.2.0 is vulnerable to reflected XSS at multiple places and specific user input fields.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g8vv-cwpg-wwf9/GHSA-g8vv-cwpg-wwf9.json b/advisories/unreviewed/2022/05/GHSA-g8vv-cwpg-wwf9/GHSA-g8vv-cwpg-wwf9.json index 8388e83a098..212492ca585 100644 --- a/advisories/unreviewed/2022/05/GHSA-g8vv-cwpg-wwf9/GHSA-g8vv-cwpg-wwf9.json +++ b/advisories/unreviewed/2022/05/GHSA-g8vv-cwpg-wwf9/GHSA-g8vv-cwpg-wwf9.json @@ -7,12 +7,8 @@ "CVE-2019-18881" ], "details": "WSO2 IS as Key Manager 5.7.0 allows unauthenticated reflected XSS in the dashboard user profile.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gcr4-wcqh-3624/GHSA-gcr4-wcqh-3624.json b/advisories/unreviewed/2022/05/GHSA-gcr4-wcqh-3624/GHSA-gcr4-wcqh-3624.json index b4a0f28d617..a813ca1ef1b 100644 --- a/advisories/unreviewed/2022/05/GHSA-gcr4-wcqh-3624/GHSA-gcr4-wcqh-3624.json +++ b/advisories/unreviewed/2022/05/GHSA-gcr4-wcqh-3624/GHSA-gcr4-wcqh-3624.json @@ -7,12 +7,8 @@ "CVE-2019-17596" ], "details": "Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key. There are several attack scenarios, such as traffic from a client to a server that verifies client certificates.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gf38-7ph2-hmxj/GHSA-gf38-7ph2-hmxj.json b/advisories/unreviewed/2022/05/GHSA-gf38-7ph2-hmxj/GHSA-gf38-7ph2-hmxj.json index a689a3491a9..54311478d0a 100644 --- a/advisories/unreviewed/2022/05/GHSA-gf38-7ph2-hmxj/GHSA-gf38-7ph2-hmxj.json +++ b/advisories/unreviewed/2022/05/GHSA-gf38-7ph2-hmxj/GHSA-gf38-7ph2-hmxj.json @@ -7,12 +7,8 @@ "CVE-2019-8239" ], "details": "Adobe Bridge CC versions 9.1 and earlier have a memory corruption vulnerability. Successful exploitation could lead to information disclosure.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gf47-3hhj-gv96/GHSA-gf47-3hhj-gv96.json b/advisories/unreviewed/2022/05/GHSA-gf47-3hhj-gv96/GHSA-gf47-3hhj-gv96.json index e7fd12e4cdf..b761cfa55b8 100644 --- a/advisories/unreviewed/2022/05/GHSA-gf47-3hhj-gv96/GHSA-gf47-3hhj-gv96.json +++ b/advisories/unreviewed/2022/05/GHSA-gf47-3hhj-gv96/GHSA-gf47-3hhj-gv96.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gfpw-6725-96v8/GHSA-gfpw-6725-96v8.json b/advisories/unreviewed/2022/05/GHSA-gfpw-6725-96v8/GHSA-gfpw-6725-96v8.json index 2992f3445bf..ad9fa0fe0d7 100644 --- a/advisories/unreviewed/2022/05/GHSA-gfpw-6725-96v8/GHSA-gfpw-6725-96v8.json +++ b/advisories/unreviewed/2022/05/GHSA-gfpw-6725-96v8/GHSA-gfpw-6725-96v8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gfqm-g3ff-4vcm/GHSA-gfqm-g3ff-4vcm.json b/advisories/unreviewed/2022/05/GHSA-gfqm-g3ff-4vcm/GHSA-gfqm-g3ff-4vcm.json index 779c6ba9b62..5de15c97b80 100644 --- a/advisories/unreviewed/2022/05/GHSA-gfqm-g3ff-4vcm/GHSA-gfqm-g3ff-4vcm.json +++ b/advisories/unreviewed/2022/05/GHSA-gfqm-g3ff-4vcm/GHSA-gfqm-g3ff-4vcm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gg2p-m82f-fgjg/GHSA-gg2p-m82f-fgjg.json b/advisories/unreviewed/2022/05/GHSA-gg2p-m82f-fgjg/GHSA-gg2p-m82f-fgjg.json index ee42fd475b4..70f703d46b3 100644 --- a/advisories/unreviewed/2022/05/GHSA-gg2p-m82f-fgjg/GHSA-gg2p-m82f-fgjg.json +++ b/advisories/unreviewed/2022/05/GHSA-gg2p-m82f-fgjg/GHSA-gg2p-m82f-fgjg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gjgc-pq2x-wr57/GHSA-gjgc-pq2x-wr57.json b/advisories/unreviewed/2022/05/GHSA-gjgc-pq2x-wr57/GHSA-gjgc-pq2x-wr57.json index b7f91c626fd..81c2c11f6a0 100644 --- a/advisories/unreviewed/2022/05/GHSA-gjgc-pq2x-wr57/GHSA-gjgc-pq2x-wr57.json +++ b/advisories/unreviewed/2022/05/GHSA-gjgc-pq2x-wr57/GHSA-gjgc-pq2x-wr57.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gq4x-x487-jm2q/GHSA-gq4x-x487-jm2q.json b/advisories/unreviewed/2022/05/GHSA-gq4x-x487-jm2q/GHSA-gq4x-x487-jm2q.json index 1b49bcb9a2b..a0eccfa1d40 100644 --- a/advisories/unreviewed/2022/05/GHSA-gq4x-x487-jm2q/GHSA-gq4x-x487-jm2q.json +++ b/advisories/unreviewed/2022/05/GHSA-gq4x-x487-jm2q/GHSA-gq4x-x487-jm2q.json @@ -7,12 +7,8 @@ "CVE-2019-17524" ], "details": "An XSS vulnerability on Technicolor TC7300 STFA.51.20 devices allows remote attackers to inject arbitrary web script via the \"Connected Clients\" field to /wlanAccess.asp. An intranet host can use a crafted hostname to exploit this.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gqfm-5hj3-5hpj/GHSA-gqfm-5hj3-5hpj.json b/advisories/unreviewed/2022/05/GHSA-gqfm-5hj3-5hpj/GHSA-gqfm-5hj3-5hpj.json index f017ae1a4b0..273a767a997 100644 --- a/advisories/unreviewed/2022/05/GHSA-gqfm-5hj3-5hpj/GHSA-gqfm-5hj3-5hpj.json +++ b/advisories/unreviewed/2022/05/GHSA-gqfm-5hj3-5hpj/GHSA-gqfm-5hj3-5hpj.json @@ -7,12 +7,8 @@ "CVE-2019-16206" ], "details": "The authentication mechanism, in Brocade SANnav versions before v2.0, logs plaintext account credentials at the ?trace? and the 'debug' logging level; which could allow a local authenticated attacker to access sensitive information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gqpg-3gmp-2rxm/GHSA-gqpg-3gmp-2rxm.json b/advisories/unreviewed/2022/05/GHSA-gqpg-3gmp-2rxm/GHSA-gqpg-3gmp-2rxm.json index 56eb6303bf9..2cfc863865f 100644 --- a/advisories/unreviewed/2022/05/GHSA-gqpg-3gmp-2rxm/GHSA-gqpg-3gmp-2rxm.json +++ b/advisories/unreviewed/2022/05/GHSA-gqpg-3gmp-2rxm/GHSA-gqpg-3gmp-2rxm.json @@ -7,12 +7,8 @@ "CVE-2019-15339" ], "details": "The Lava Z60s Android device with a build fingerprint of LAVA/Z60s/Z60s:8.1.0/O11019/1530331229:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionName=v4.0.27) that allows any app co-located on the device to programmatically disable and enable Wi-Fi without the corresponding access permission through an exported interface.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gqrr-28h7-96f8/GHSA-gqrr-28h7-96f8.json b/advisories/unreviewed/2022/05/GHSA-gqrr-28h7-96f8/GHSA-gqrr-28h7-96f8.json index 40656a6bac6..cb0f3e12627 100644 --- a/advisories/unreviewed/2022/05/GHSA-gqrr-28h7-96f8/GHSA-gqrr-28h7-96f8.json +++ b/advisories/unreviewed/2022/05/GHSA-gqrr-28h7-96f8/GHSA-gqrr-28h7-96f8.json @@ -7,12 +7,8 @@ "CVE-2019-18949" ], "details": "SnowHaze before 2.6.6 is sometimes too late to honor a per-site JavaScript blocking setting, which leads to unintended JavaScript execution via a chain of webpage redirections targeted to the user's browser configuration.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gr65-8p7x-pj5f/GHSA-gr65-8p7x-pj5f.json b/advisories/unreviewed/2022/05/GHSA-gr65-8p7x-pj5f/GHSA-gr65-8p7x-pj5f.json index c030226fabe..f5a35a01e27 100644 --- a/advisories/unreviewed/2022/05/GHSA-gr65-8p7x-pj5f/GHSA-gr65-8p7x-pj5f.json +++ b/advisories/unreviewed/2022/05/GHSA-gr65-8p7x-pj5f/GHSA-gr65-8p7x-pj5f.json @@ -7,12 +7,8 @@ "CVE-2019-16208" ], "details": "Password-based encryption (PBE) algorithm, of Brocade SANnav versions before v2.0, has a weakness in generating cryptographic keys that may allow an attacker to decrypt passwords used with several services (Radius, TACAS, etc.).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-grcg-hjg8-mrhw/GHSA-grcg-hjg8-mrhw.json b/advisories/unreviewed/2022/05/GHSA-grcg-hjg8-mrhw/GHSA-grcg-hjg8-mrhw.json index 7ded07851cf..065fa16738e 100644 --- a/advisories/unreviewed/2022/05/GHSA-grcg-hjg8-mrhw/GHSA-grcg-hjg8-mrhw.json +++ b/advisories/unreviewed/2022/05/GHSA-grcg-hjg8-mrhw/GHSA-grcg-hjg8-mrhw.json @@ -7,12 +7,8 @@ "CVE-2019-18811" ], "details": "A memory leak in the sof_set_get_large_ctrl_data() function in sound/soc/sof/ipc.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption) by triggering sof_get_ctrl_copy_params() failures, aka CID-45c1380358b1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-grxh-vgg4-3pff/GHSA-grxh-vgg4-3pff.json b/advisories/unreviewed/2022/05/GHSA-grxh-vgg4-3pff/GHSA-grxh-vgg4-3pff.json index b45630c0682..92066d71a58 100644 --- a/advisories/unreviewed/2022/05/GHSA-grxh-vgg4-3pff/GHSA-grxh-vgg4-3pff.json +++ b/advisories/unreviewed/2022/05/GHSA-grxh-vgg4-3pff/GHSA-grxh-vgg4-3pff.json @@ -7,12 +7,8 @@ "CVE-2006-2055" ], "details": "Argument injection vulnerability in Microsoft Outlook 2003 SP1 allows user-assisted remote attackers to modify command line arguments to an invoked mail client via \" (double quote) characters in a mailto: scheme handler, as demonstrated by launching Microsoft Outlook with an arbitrary filename as an attachment. NOTE: it is not clear whether this issue is implementation-specific or a problem in the Microsoft API.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gx72-58qg-vhx3/GHSA-gx72-58qg-vhx3.json b/advisories/unreviewed/2022/05/GHSA-gx72-58qg-vhx3/GHSA-gx72-58qg-vhx3.json index 85e0a93a74e..8b852096c3b 100644 --- a/advisories/unreviewed/2022/05/GHSA-gx72-58qg-vhx3/GHSA-gx72-58qg-vhx3.json +++ b/advisories/unreviewed/2022/05/GHSA-gx72-58qg-vhx3/GHSA-gx72-58qg-vhx3.json @@ -7,12 +7,8 @@ "CVE-2019-15374" ], "details": "The Lava Iris 88 Lite Android device with a build fingerprint of LAVA/iris88_lite/iris88_lite:8.1.0/O11019/1536323070:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h2jr-f722-chc2/GHSA-h2jr-f722-chc2.json b/advisories/unreviewed/2022/05/GHSA-h2jr-f722-chc2/GHSA-h2jr-f722-chc2.json index 9bcb15611ee..96e2d5f476d 100644 --- a/advisories/unreviewed/2022/05/GHSA-h2jr-f722-chc2/GHSA-h2jr-f722-chc2.json +++ b/advisories/unreviewed/2022/05/GHSA-h2jr-f722-chc2/GHSA-h2jr-f722-chc2.json @@ -7,12 +7,8 @@ "CVE-2019-15433" ], "details": "The Samsung A3 Android device with a build fingerprint of samsung/a3y17ltedx/a3y17lte:8.0.0/R16NW/A320YDXU4CSB3:user/release-keys contains a pre-installed app with a package name of com.samsung.android.themecenter app (versionCode=7000000, versionName=7.0.0.0) that allows other pre-installed apps to perform app installation via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions that are required by other other pre-installed apps that exported their capabilities to other pre-installed app.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h58v-f39m-6qhf/GHSA-h58v-f39m-6qhf.json b/advisories/unreviewed/2022/05/GHSA-h58v-f39m-6qhf/GHSA-h58v-f39m-6qhf.json index 7cd5f387297..33b9e12c7da 100644 --- a/advisories/unreviewed/2022/05/GHSA-h58v-f39m-6qhf/GHSA-h58v-f39m-6qhf.json +++ b/advisories/unreviewed/2022/05/GHSA-h58v-f39m-6qhf/GHSA-h58v-f39m-6qhf.json @@ -7,12 +7,8 @@ "CVE-2019-5292" ], "details": "Honor 10 Lite, Honor 8A, Huawei Y6 mobile phones with the versions before 9.1.0.217(C00E215R3P1), the versions before 9.1.0.205(C00E97R1P9), the versions before 9.1.0.205(C00E97R2P2) have an information leak vulnerability. Due to improper function error records of some module, an attacker with the access permission may exploit the vulnerability to obtain some information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h8r9-r76q-5gg8/GHSA-h8r9-r76q-5gg8.json b/advisories/unreviewed/2022/05/GHSA-h8r9-r76q-5gg8/GHSA-h8r9-r76q-5gg8.json index e0262230878..ebcdf876fcf 100644 --- a/advisories/unreviewed/2022/05/GHSA-h8r9-r76q-5gg8/GHSA-h8r9-r76q-5gg8.json +++ b/advisories/unreviewed/2022/05/GHSA-h8r9-r76q-5gg8/GHSA-h8r9-r76q-5gg8.json @@ -7,12 +7,8 @@ "CVE-2019-15744" ], "details": "The Sony Xperia Xperia XZs Android device with a build fingerprint of Sony/keyaki_softbank/keyaki_softbank:7.1.1/TONE3-3.0.0-SOFTBANK-170517-0323/1:user/dev-keys contains a pre-installed app with a package name of jp.softbank.mb.tdrl app (versionCode=1413005, versionName=1.3.0) that allows unauthorized wireless settings modification via a confused deputy attack. This capability can be accessed by any app co-located on the device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h9xv-q4jf-ww7x/GHSA-h9xv-q4jf-ww7x.json b/advisories/unreviewed/2022/05/GHSA-h9xv-q4jf-ww7x/GHSA-h9xv-q4jf-ww7x.json index ae73583aa7d..2c5564459ef 100644 --- a/advisories/unreviewed/2022/05/GHSA-h9xv-q4jf-ww7x/GHSA-h9xv-q4jf-ww7x.json +++ b/advisories/unreviewed/2022/05/GHSA-h9xv-q4jf-ww7x/GHSA-h9xv-q4jf-ww7x.json @@ -7,12 +7,8 @@ "CVE-2019-15443" ], "details": "The Samsung J7 Max Android device with a build fingerprint of samsung/j7maxlteins/j7maxlte:8.1.0/M1AJQ/G615FXXU2BSB1:user/release-keys contains a pre-installed app with a package name of com.samsung.android.themecenter app (versionCode=7000100, versionName=7.0.1.0) that allows other pre-installed apps to perform app installation via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions that are required by other other pre-installed apps that exported their capabilities to other pre-installed app.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hc66-45h3-rxg5/GHSA-hc66-45h3-rxg5.json b/advisories/unreviewed/2022/05/GHSA-hc66-45h3-rxg5/GHSA-hc66-45h3-rxg5.json index 780be95fb47..7892827e324 100644 --- a/advisories/unreviewed/2022/05/GHSA-hc66-45h3-rxg5/GHSA-hc66-45h3-rxg5.json +++ b/advisories/unreviewed/2022/05/GHSA-hc66-45h3-rxg5/GHSA-hc66-45h3-rxg5.json @@ -7,12 +7,8 @@ "CVE-2019-17523" ], "details": "An XSS vulnerability on Technicolor TC7300 STFA.51.20 devices allows remote attackers to inject arbitrary web script via the FileName parameter to /FTPDiag.asp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hf8f-9qph-rj9q/GHSA-hf8f-9qph-rj9q.json b/advisories/unreviewed/2022/05/GHSA-hf8f-9qph-rj9q/GHSA-hf8f-9qph-rj9q.json index 2c6459cd45b..99ebc2ca72d 100644 --- a/advisories/unreviewed/2022/05/GHSA-hf8f-9qph-rj9q/GHSA-hf8f-9qph-rj9q.json +++ b/advisories/unreviewed/2022/05/GHSA-hf8f-9qph-rj9q/GHSA-hf8f-9qph-rj9q.json @@ -7,12 +7,8 @@ "CVE-2019-15451" ], "details": "The Samsung J3 Android device with a build fingerprint of samsung/j3y17ltedx/j3y17lte:8.0.0/R16NW/J330GDXS3BSC1:user/release-keys contains a pre-installed app with a package name of com.samsung.android.themecenter app (versionCode=6010000, versionName=6.1.0.0) that allows other pre-installed apps to perform app installation via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions that are required by other other pre-installed apps that exported their capabilities to other pre-installed app.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hg94-7qqv-5v36/GHSA-hg94-7qqv-5v36.json b/advisories/unreviewed/2022/05/GHSA-hg94-7qqv-5v36/GHSA-hg94-7qqv-5v36.json index 1ce01985b66..e2b73798be0 100644 --- a/advisories/unreviewed/2022/05/GHSA-hg94-7qqv-5v36/GHSA-hg94-7qqv-5v36.json +++ b/advisories/unreviewed/2022/05/GHSA-hg94-7qqv-5v36/GHSA-hg94-7qqv-5v36.json @@ -7,12 +7,8 @@ "CVE-2019-0117" ], "details": "Insufficient access control in protected memory subsystem for Intel(R) SGX for 6th, 7th, 8th, 9th Generation Intel(R) Core(TM) Processor Families; Intel(R) Xeon(R) Processor E3-1500 v5, v6 Families; Intel(R) Xeon(R) E-2100 & E-2200 Processor Families with Intel(R) Processor Graphics may allow a privileged user to potentially enable information disclosure via local access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hgr7-mfwx-6c5g/GHSA-hgr7-mfwx-6c5g.json b/advisories/unreviewed/2022/05/GHSA-hgr7-mfwx-6c5g/GHSA-hgr7-mfwx-6c5g.json index 8bdd007969b..252420782a4 100644 --- a/advisories/unreviewed/2022/05/GHSA-hgr7-mfwx-6c5g/GHSA-hgr7-mfwx-6c5g.json +++ b/advisories/unreviewed/2022/05/GHSA-hgr7-mfwx-6c5g/GHSA-hgr7-mfwx-6c5g.json @@ -7,12 +7,8 @@ "CVE-2019-1449" ], "details": "A security feature bypass vulnerability exists in the way that Office Click-to-Run (C2R) components handle a specially crafted file, which could lead to a standard user, any AppContainer sandbox, and Office LPAC Protected View to escalate privileges to SYSTEM.To exploit this bug, an attacker would have to run a specially crafted file, aka 'Microsoft Office ClickToRun Security Feature Bypass Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hjj5-w5cq-mjq5/GHSA-hjj5-w5cq-mjq5.json b/advisories/unreviewed/2022/05/GHSA-hjj5-w5cq-mjq5/GHSA-hjj5-w5cq-mjq5.json index b5fccbc8fb6..e41d55c5f65 100644 --- a/advisories/unreviewed/2022/05/GHSA-hjj5-w5cq-mjq5/GHSA-hjj5-w5cq-mjq5.json +++ b/advisories/unreviewed/2022/05/GHSA-hjj5-w5cq-mjq5/GHSA-hjj5-w5cq-mjq5.json @@ -7,12 +7,8 @@ "CVE-2019-15421" ], "details": "The Blackview BV7000_Pro Android device with a build fingerprint of Blackview/BV7000_Pro/BV7000_Pro:7.0/NRD90M/1493011204:user/release-keys contains a pre-installed app with a package name of com.mediatek.factorymode app (versionCode=1, versionName=1) that allows unauthorized wireless settings modification via a confused deputy attack. This capability can be accessed by any app co-located on the device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hjv6-q2rr-rjhq/GHSA-hjv6-q2rr-rjhq.json b/advisories/unreviewed/2022/05/GHSA-hjv6-q2rr-rjhq/GHSA-hjv6-q2rr-rjhq.json index e990988ea86..80b3bb757d7 100644 --- a/advisories/unreviewed/2022/05/GHSA-hjv6-q2rr-rjhq/GHSA-hjv6-q2rr-rjhq.json +++ b/advisories/unreviewed/2022/05/GHSA-hjv6-q2rr-rjhq/GHSA-hjv6-q2rr-rjhq.json @@ -7,12 +7,8 @@ "CVE-2017-17224" ], "details": "Some Huawei smart phones with versions earlier than Harry-AL00C 9.1.0.206(C00E205R3P1) have a null pointer dereference vulnerability. An attacker crafts specific packets and sends to the affected product to exploit this vulnerability. Successful exploitation may cause the affected phone abnormal.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hr87-jrrm-jr77/GHSA-hr87-jrrm-jr77.json b/advisories/unreviewed/2022/05/GHSA-hr87-jrrm-jr77/GHSA-hr87-jrrm-jr77.json index 8a5b6d40b55..e4dc4fd9b5b 100644 --- a/advisories/unreviewed/2022/05/GHSA-hr87-jrrm-jr77/GHSA-hr87-jrrm-jr77.json +++ b/advisories/unreviewed/2022/05/GHSA-hr87-jrrm-jr77/GHSA-hr87-jrrm-jr77.json @@ -7,12 +7,8 @@ "CVE-2019-18602" ], "details": "OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to an information disclosure vulnerability because uninitialized scalars are sent over the network to a peer.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hvhv-mf3j-r564/GHSA-hvhv-mf3j-r564.json b/advisories/unreviewed/2022/05/GHSA-hvhv-mf3j-r564/GHSA-hvhv-mf3j-r564.json index ff2af0b81ca..0e12c03be0b 100644 --- a/advisories/unreviewed/2022/05/GHSA-hvhv-mf3j-r564/GHSA-hvhv-mf3j-r564.json +++ b/advisories/unreviewed/2022/05/GHSA-hvhv-mf3j-r564/GHSA-hvhv-mf3j-r564.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hvmh-jgw7-f7xg/GHSA-hvmh-jgw7-f7xg.json b/advisories/unreviewed/2022/05/GHSA-hvmh-jgw7-f7xg/GHSA-hvmh-jgw7-f7xg.json index 752f184dffa..e734724a5b6 100644 --- a/advisories/unreviewed/2022/05/GHSA-hvmh-jgw7-f7xg/GHSA-hvmh-jgw7-f7xg.json +++ b/advisories/unreviewed/2022/05/GHSA-hvmh-jgw7-f7xg/GHSA-hvmh-jgw7-f7xg.json @@ -7,12 +7,8 @@ "CVE-2019-6187" ], "details": "A stored CSV Injection vulnerability was reported in Lenovo XClarity Controller (XCC) that could allow an administrative or other appropriately permissioned user to store malformed data in certain XCC server informational fields, that could result in crafted formulas being stored in an exported CSV file. The crafted formula is not executed on XCC itself and has no effect on the server.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hvqp-9v9g-pxcq/GHSA-hvqp-9v9g-pxcq.json b/advisories/unreviewed/2022/05/GHSA-hvqp-9v9g-pxcq/GHSA-hvqp-9v9g-pxcq.json index 8e1e435e86d..0cd09082cca 100644 --- a/advisories/unreviewed/2022/05/GHSA-hvqp-9v9g-pxcq/GHSA-hvqp-9v9g-pxcq.json +++ b/advisories/unreviewed/2022/05/GHSA-hvqp-9v9g-pxcq/GHSA-hvqp-9v9g-pxcq.json @@ -7,12 +7,8 @@ "CVE-2019-15469" ], "details": "The Xiaomi Mi Pad 4 Android device with a build fingerprint of Xiaomi/clover/clover:8.1.0/OPM1.171019.019/V9.6.26.0.ODJCNFD:user/release-keys contains a pre-installed app with a package name of com.qualcomm.qti.callenhancement app (versionCode=27, versionName=8.1.0) that allows other pre-installed apps to perform microphone audio recording via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions that are required by other other pre-installed apps that export their capabilities to other pre-installed app. This app allows a third-party app to use its open interface to record telephone calls to external storage.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hwp9-jjvp-p4vg/GHSA-hwp9-jjvp-p4vg.json b/advisories/unreviewed/2022/05/GHSA-hwp9-jjvp-p4vg/GHSA-hwp9-jjvp-p4vg.json index 8b6580c44ad..7b132e8fcab 100644 --- a/advisories/unreviewed/2022/05/GHSA-hwp9-jjvp-p4vg/GHSA-hwp9-jjvp-p4vg.json +++ b/advisories/unreviewed/2022/05/GHSA-hwp9-jjvp-p4vg/GHSA-hwp9-jjvp-p4vg.json @@ -7,12 +7,8 @@ "CVE-2019-18814" ], "details": "An issue was discovered in the Linux kernel through 5.3.9. There is a use-after-free when aa_label_parse() fails in aa_audit_rule_init() in security/apparmor/audit.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hwwg-pxv4-j5f6/GHSA-hwwg-pxv4-j5f6.json b/advisories/unreviewed/2022/05/GHSA-hwwg-pxv4-j5f6/GHSA-hwwg-pxv4-j5f6.json index 50c11d3f881..e81a0c75e87 100644 --- a/advisories/unreviewed/2022/05/GHSA-hwwg-pxv4-j5f6/GHSA-hwwg-pxv4-j5f6.json +++ b/advisories/unreviewed/2022/05/GHSA-hwwg-pxv4-j5f6/GHSA-hwwg-pxv4-j5f6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hwxc-7rw6-2gqf/GHSA-hwxc-7rw6-2gqf.json b/advisories/unreviewed/2022/05/GHSA-hwxc-7rw6-2gqf/GHSA-hwxc-7rw6-2gqf.json index 00c09622569..0b0720d27a9 100644 --- a/advisories/unreviewed/2022/05/GHSA-hwxc-7rw6-2gqf/GHSA-hwxc-7rw6-2gqf.json +++ b/advisories/unreviewed/2022/05/GHSA-hwxc-7rw6-2gqf/GHSA-hwxc-7rw6-2gqf.json @@ -7,12 +7,8 @@ "CVE-2019-1389" ], "details": "A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1397, CVE-2019-1398.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hxf6-2xxx-qjw3/GHSA-hxf6-2xxx-qjw3.json b/advisories/unreviewed/2022/05/GHSA-hxf6-2xxx-qjw3/GHSA-hxf6-2xxx-qjw3.json index dbda8c90205..68f327c0729 100644 --- a/advisories/unreviewed/2022/05/GHSA-hxf6-2xxx-qjw3/GHSA-hxf6-2xxx-qjw3.json +++ b/advisories/unreviewed/2022/05/GHSA-hxf6-2xxx-qjw3/GHSA-hxf6-2xxx-qjw3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j2v6-c8rw-m58j/GHSA-j2v6-c8rw-m58j.json b/advisories/unreviewed/2022/05/GHSA-j2v6-c8rw-m58j/GHSA-j2v6-c8rw-m58j.json index 0f9dbdb2214..5aa14ccab6b 100644 --- a/advisories/unreviewed/2022/05/GHSA-j2v6-c8rw-m58j/GHSA-j2v6-c8rw-m58j.json +++ b/advisories/unreviewed/2022/05/GHSA-j2v6-c8rw-m58j/GHSA-j2v6-c8rw-m58j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j44m-w6x3-678v/GHSA-j44m-w6x3-678v.json b/advisories/unreviewed/2022/05/GHSA-j44m-w6x3-678v/GHSA-j44m-w6x3-678v.json index b0c527d98c4..13cf250c094 100644 --- a/advisories/unreviewed/2022/05/GHSA-j44m-w6x3-678v/GHSA-j44m-w6x3-678v.json +++ b/advisories/unreviewed/2022/05/GHSA-j44m-w6x3-678v/GHSA-j44m-w6x3-678v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j6qw-4r9r-2cc4/GHSA-j6qw-4r9r-2cc4.json b/advisories/unreviewed/2022/05/GHSA-j6qw-4r9r-2cc4/GHSA-j6qw-4r9r-2cc4.json index ba1ccefbb99..9a6ffaa21ad 100644 --- a/advisories/unreviewed/2022/05/GHSA-j6qw-4r9r-2cc4/GHSA-j6qw-4r9r-2cc4.json +++ b/advisories/unreviewed/2022/05/GHSA-j6qw-4r9r-2cc4/GHSA-j6qw-4r9r-2cc4.json @@ -7,12 +7,8 @@ "CVE-2019-2202" ], "details": "In CryptoPlugin::decrypt of CryptoPlugin.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10Android ID: A-137283376", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j75x-vr7m-9cch/GHSA-j75x-vr7m-9cch.json b/advisories/unreviewed/2022/05/GHSA-j75x-vr7m-9cch/GHSA-j75x-vr7m-9cch.json index de85079108e..73ae0ca35d3 100644 --- a/advisories/unreviewed/2022/05/GHSA-j75x-vr7m-9cch/GHSA-j75x-vr7m-9cch.json +++ b/advisories/unreviewed/2022/05/GHSA-j75x-vr7m-9cch/GHSA-j75x-vr7m-9cch.json @@ -7,12 +7,8 @@ "CVE-2019-18603" ], "details": "OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to information leakage upon certain error conditions because uninitialized RPC output variables are sent over the network to a peer.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j8mv-vm53-jf5g/GHSA-j8mv-vm53-jf5g.json b/advisories/unreviewed/2022/05/GHSA-j8mv-vm53-jf5g/GHSA-j8mv-vm53-jf5g.json index 1254228dbe2..2c27f4022f3 100644 --- a/advisories/unreviewed/2022/05/GHSA-j8mv-vm53-jf5g/GHSA-j8mv-vm53-jf5g.json +++ b/advisories/unreviewed/2022/05/GHSA-j8mv-vm53-jf5g/GHSA-j8mv-vm53-jf5g.json @@ -7,12 +7,8 @@ "CVE-2015-9512" ], "details": "The Easy Digital Downloads (EDD) CSV Manager extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j97g-mp7p-4fj3/GHSA-j97g-mp7p-4fj3.json b/advisories/unreviewed/2022/05/GHSA-j97g-mp7p-4fj3/GHSA-j97g-mp7p-4fj3.json index 5e37b60ad02..f3ac2871d7f 100644 --- a/advisories/unreviewed/2022/05/GHSA-j97g-mp7p-4fj3/GHSA-j97g-mp7p-4fj3.json +++ b/advisories/unreviewed/2022/05/GHSA-j97g-mp7p-4fj3/GHSA-j97g-mp7p-4fj3.json @@ -7,12 +7,8 @@ "CVE-2019-11175" ], "details": "Insufficient input validation in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable denial of service via network access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j9vr-6635-6998/GHSA-j9vr-6635-6998.json b/advisories/unreviewed/2022/05/GHSA-j9vr-6635-6998/GHSA-j9vr-6635-6998.json index 0a50825aae0..96dda67426b 100644 --- a/advisories/unreviewed/2022/05/GHSA-j9vr-6635-6998/GHSA-j9vr-6635-6998.json +++ b/advisories/unreviewed/2022/05/GHSA-j9vr-6635-6998/GHSA-j9vr-6635-6998.json @@ -7,12 +7,8 @@ "CVE-2019-18853" ], "details": "ImageMagick before 7.0.9-0 allows remote attackers to cause a denial of service because XML_PARSE_HUGE is not properly restricted in coders/svg.c, related to SVG and libxml2.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jcc6-g3rx-46fg/GHSA-jcc6-g3rx-46fg.json b/advisories/unreviewed/2022/05/GHSA-jcc6-g3rx-46fg/GHSA-jcc6-g3rx-46fg.json index d6a99f6857b..b7a7f258d1c 100644 --- a/advisories/unreviewed/2022/05/GHSA-jcc6-g3rx-46fg/GHSA-jcc6-g3rx-46fg.json +++ b/advisories/unreviewed/2022/05/GHSA-jcc6-g3rx-46fg/GHSA-jcc6-g3rx-46fg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jcj2-r7jq-h3h2/GHSA-jcj2-r7jq-h3h2.json b/advisories/unreviewed/2022/05/GHSA-jcj2-r7jq-h3h2/GHSA-jcj2-r7jq-h3h2.json index ef604a128cc..22d7db8718a 100644 --- a/advisories/unreviewed/2022/05/GHSA-jcj2-r7jq-h3h2/GHSA-jcj2-r7jq-h3h2.json +++ b/advisories/unreviewed/2022/05/GHSA-jcj2-r7jq-h3h2/GHSA-jcj2-r7jq-h3h2.json @@ -7,12 +7,8 @@ "CVE-2019-3640" ], "details": "Unprotected Transport of Credentials in ePO extension in McAfee Data Loss Prevention 11.x prior to 11.4.0 allows remote attackers with access to the network to collect login details to the LDAP server via the ePO extension not using a secure connection when testing LDAP connectivity.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jfq2-hc43-8cf8/GHSA-jfq2-hc43-8cf8.json b/advisories/unreviewed/2022/05/GHSA-jfq2-hc43-8cf8/GHSA-jfq2-hc43-8cf8.json index 374c63683c7..2820bb7b319 100644 --- a/advisories/unreviewed/2022/05/GHSA-jfq2-hc43-8cf8/GHSA-jfq2-hc43-8cf8.json +++ b/advisories/unreviewed/2022/05/GHSA-jfq2-hc43-8cf8/GHSA-jfq2-hc43-8cf8.json @@ -7,12 +7,8 @@ "CVE-2019-15375" ], "details": "The Haier G8 Android device with a build fingerprint of Haier/HM-G559-FL/G8:8.1.0/O11019/1522294799:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jfqh-pjgv-3jhm/GHSA-jfqh-pjgv-3jhm.json b/advisories/unreviewed/2022/05/GHSA-jfqh-pjgv-3jhm/GHSA-jfqh-pjgv-3jhm.json index fb7181f45f7..4840f99883b 100644 --- a/advisories/unreviewed/2022/05/GHSA-jfqh-pjgv-3jhm/GHSA-jfqh-pjgv-3jhm.json +++ b/advisories/unreviewed/2022/05/GHSA-jfqh-pjgv-3jhm/GHSA-jfqh-pjgv-3jhm.json @@ -7,12 +7,8 @@ "CVE-2019-15417" ], "details": "The Tecno Spark Pro Android device with a build fingerprint of TECNO/H3722/TECNO-K8:7.0/NRD90M/K8-H3722ABCDE-N-171229V96:user/release-keys contains a pre-installed app with a package name of com.lovelyfont.defcontainer app (versionCode=7, versionName=7.0.5) that allows unauthorized dynamic code loading via a confused deputy attack. This capability can be accessed by any app co-located on the device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jg35-9g6q-f79j/GHSA-jg35-9g6q-f79j.json b/advisories/unreviewed/2022/05/GHSA-jg35-9g6q-f79j/GHSA-jg35-9g6q-f79j.json index c37787d3d26..d67e79c6427 100644 --- a/advisories/unreviewed/2022/05/GHSA-jg35-9g6q-f79j/GHSA-jg35-9g6q-f79j.json +++ b/advisories/unreviewed/2022/05/GHSA-jg35-9g6q-f79j/GHSA-jg35-9g6q-f79j.json @@ -7,12 +7,8 @@ "CVE-2019-3648" ], "details": "A Privilege Escalation vulnerability in the Microsoft Windows client in McAfee Total Protection 16.0.R22 and earlier allows administrators to execute arbitrary code via carefully placing malicious files in specific locations protected by administrator permission.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jgfw-whrj-xw97/GHSA-jgfw-whrj-xw97.json b/advisories/unreviewed/2022/05/GHSA-jgfw-whrj-xw97/GHSA-jgfw-whrj-xw97.json index 50b92e0224c..c827a35f91d 100644 --- a/advisories/unreviewed/2022/05/GHSA-jgfw-whrj-xw97/GHSA-jgfw-whrj-xw97.json +++ b/advisories/unreviewed/2022/05/GHSA-jgfw-whrj-xw97/GHSA-jgfw-whrj-xw97.json @@ -7,12 +7,8 @@ "CVE-2019-15390" ], "details": "The Haier G8 Android device with a build fingerprint of Haier/HM-G559-FL/G8:8.1.0/O11019/1522294799:user/release-keys contains a pre-installed app with a package name of com.qiku.service.container app (versionCode=5, versionName=1.03.00_VER_32525983298984) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jj7f-f2vq-pvc7/GHSA-jj7f-f2vq-pvc7.json b/advisories/unreviewed/2022/05/GHSA-jj7f-f2vq-pvc7/GHSA-jj7f-f2vq-pvc7.json index ca4425a668f..5fc7f4b7769 100644 --- a/advisories/unreviewed/2022/05/GHSA-jj7f-f2vq-pvc7/GHSA-jj7f-f2vq-pvc7.json +++ b/advisories/unreviewed/2022/05/GHSA-jj7f-f2vq-pvc7/GHSA-jj7f-f2vq-pvc7.json @@ -7,12 +7,8 @@ "CVE-2019-5617" ], "details": "Computing For Good's Basic Laboratory Information System (also known as C4G BLIS) version 3.4 and earlier suffers from an instance of CWE-284, \"Improper Access Control.\" As a result, an unauthenticated user may change the password of any administrator-level user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jmvm-hj36-w5hc/GHSA-jmvm-hj36-w5hc.json b/advisories/unreviewed/2022/05/GHSA-jmvm-hj36-w5hc/GHSA-jmvm-hj36-w5hc.json index ca20efe4e52..61c655f6b98 100644 --- a/advisories/unreviewed/2022/05/GHSA-jmvm-hj36-w5hc/GHSA-jmvm-hj36-w5hc.json +++ b/advisories/unreviewed/2022/05/GHSA-jmvm-hj36-w5hc/GHSA-jmvm-hj36-w5hc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jp8m-cgqw-f9jm/GHSA-jp8m-cgqw-f9jm.json b/advisories/unreviewed/2022/05/GHSA-jp8m-cgqw-f9jm/GHSA-jp8m-cgqw-f9jm.json index 75b60032d18..c59f2eb57fd 100644 --- a/advisories/unreviewed/2022/05/GHSA-jp8m-cgqw-f9jm/GHSA-jp8m-cgqw-f9jm.json +++ b/advisories/unreviewed/2022/05/GHSA-jp8m-cgqw-f9jm/GHSA-jp8m-cgqw-f9jm.json @@ -7,12 +7,8 @@ "CVE-2019-16860" ], "details": "Code42 app through version 7.0.2 for Windows has an Untrusted Search Path. In certain situations, a non-administrative attacker on the local machine could create or modify a dynamic-link library (DLL). The Code42 service could then load it at runtime, and potentially execute arbitrary code at an elevated privilege on the local machine.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jqqr-xgvg-2x5c/GHSA-jqqr-xgvg-2x5c.json b/advisories/unreviewed/2022/05/GHSA-jqqr-xgvg-2x5c/GHSA-jqqr-xgvg-2x5c.json index ec4129c3b0d..10262332241 100644 --- a/advisories/unreviewed/2022/05/GHSA-jqqr-xgvg-2x5c/GHSA-jqqr-xgvg-2x5c.json +++ b/advisories/unreviewed/2022/05/GHSA-jqqr-xgvg-2x5c/GHSA-jqqr-xgvg-2x5c.json @@ -7,12 +7,8 @@ "CVE-2019-15425" ], "details": "The Kata M4s Android device with a build fingerprint of alps/full_hct6750_66_n/hct6750_66_n:7.0/NRD90M/1495624556:user/test-keys contains a pre-installed app with a package name of com.mediatek.factorymode app (versionCode=1, versionName=1) that allows unauthorized wireless settings modification via a confused deputy attack. This capability can be accessed by any app co-located on the device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jrh5-cghp-wff5/GHSA-jrh5-cghp-wff5.json b/advisories/unreviewed/2022/05/GHSA-jrh5-cghp-wff5/GHSA-jrh5-cghp-wff5.json index b6946d5bae6..e967ffd0439 100644 --- a/advisories/unreviewed/2022/05/GHSA-jrh5-cghp-wff5/GHSA-jrh5-cghp-wff5.json +++ b/advisories/unreviewed/2022/05/GHSA-jrh5-cghp-wff5/GHSA-jrh5-cghp-wff5.json @@ -7,12 +7,8 @@ "CVE-2019-4556" ], "details": "IBM QRadar Advisor 1.0.0 through 2.4.0 uses incomplete blacklisting for input validation which allows attackers to bypass application controls resulting in direct impact to the system and data integrity. IBM X-Force ID: 166205.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jrxp-96m9-v59m/GHSA-jrxp-96m9-v59m.json b/advisories/unreviewed/2022/05/GHSA-jrxp-96m9-v59m/GHSA-jrxp-96m9-v59m.json index e25e9fccdf9..46ff93d850c 100644 --- a/advisories/unreviewed/2022/05/GHSA-jrxp-96m9-v59m/GHSA-jrxp-96m9-v59m.json +++ b/advisories/unreviewed/2022/05/GHSA-jrxp-96m9-v59m/GHSA-jrxp-96m9-v59m.json @@ -7,12 +7,8 @@ "CVE-2019-15333" ], "details": "The Lava Flair Z1 Android device with a build fingerprint of LAVA/Z1/Z1:8.1.0/O11019/1536680131:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionName=v4.0.27) that allows any app co-located on the device to programmatically disable and enable Wi-Fi without the corresponding access permission through an exported interface.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jvf3-qmvq-p4gj/GHSA-jvf3-qmvq-p4gj.json b/advisories/unreviewed/2022/05/GHSA-jvf3-qmvq-p4gj/GHSA-jvf3-qmvq-p4gj.json index 94f01aeff4b..c53da990985 100644 --- a/advisories/unreviewed/2022/05/GHSA-jvf3-qmvq-p4gj/GHSA-jvf3-qmvq-p4gj.json +++ b/advisories/unreviewed/2022/05/GHSA-jvf3-qmvq-p4gj/GHSA-jvf3-qmvq-p4gj.json @@ -7,12 +7,8 @@ "CVE-2019-15384" ], "details": "The Elephone A4 Android device with a build fingerprint of Elephone/A4/A4:8.1.0/O11019/20180530.143559:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jvjw-9wvw-vw24/GHSA-jvjw-9wvw-vw24.json b/advisories/unreviewed/2022/05/GHSA-jvjw-9wvw-vw24/GHSA-jvjw-9wvw-vw24.json index 094bc34812e..f5fec7f4261 100644 --- a/advisories/unreviewed/2022/05/GHSA-jvjw-9wvw-vw24/GHSA-jvjw-9wvw-vw24.json +++ b/advisories/unreviewed/2022/05/GHSA-jvjw-9wvw-vw24/GHSA-jvjw-9wvw-vw24.json @@ -7,12 +7,8 @@ "CVE-2019-18930" ], "details": "Western Digital My Cloud EX2 Ultra firmware 2.31.183 allows web users (including guest account) to remotely execute arbitrary code via a stack-based buffer overflow. There is no size verification logic in one of functions in libscheddl.so, and download_mgr.cgi makes it possible to enter large-sized f_idx inputs.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jw56-f5mh-fpcf/GHSA-jw56-f5mh-fpcf.json b/advisories/unreviewed/2022/05/GHSA-jw56-f5mh-fpcf/GHSA-jw56-f5mh-fpcf.json index a63f0b93367..74cd58d4191 100644 --- a/advisories/unreviewed/2022/05/GHSA-jw56-f5mh-fpcf/GHSA-jw56-f5mh-fpcf.json +++ b/advisories/unreviewed/2022/05/GHSA-jw56-f5mh-fpcf/GHSA-jw56-f5mh-fpcf.json @@ -7,12 +7,8 @@ "CVE-2019-1234" ], "details": "A spoofing vulnerability exists when Azure Stack fails to validate certain requests, aka 'Azure Stack Spoofing Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jwvv-xc6h-3323/GHSA-jwvv-xc6h-3323.json b/advisories/unreviewed/2022/05/GHSA-jwvv-xc6h-3323/GHSA-jwvv-xc6h-3323.json index 1e22bfe1e16..6ea1777a144 100644 --- a/advisories/unreviewed/2022/05/GHSA-jwvv-xc6h-3323/GHSA-jwvv-xc6h-3323.json +++ b/advisories/unreviewed/2022/05/GHSA-jwvv-xc6h-3323/GHSA-jwvv-xc6h-3323.json @@ -7,12 +7,8 @@ "CVE-2015-9532" ], "details": "The Easy Digital Downloads (EDD) Digital Store theme for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jwxq-72jg-xr6j/GHSA-jwxq-72jg-xr6j.json b/advisories/unreviewed/2022/05/GHSA-jwxq-72jg-xr6j/GHSA-jwxq-72jg-xr6j.json index 236e341b43e..b2975036790 100644 --- a/advisories/unreviewed/2022/05/GHSA-jwxq-72jg-xr6j/GHSA-jwxq-72jg-xr6j.json +++ b/advisories/unreviewed/2022/05/GHSA-jwxq-72jg-xr6j/GHSA-jwxq-72jg-xr6j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jxph-qx6w-9c2j/GHSA-jxph-qx6w-9c2j.json b/advisories/unreviewed/2022/05/GHSA-jxph-qx6w-9c2j/GHSA-jxph-qx6w-9c2j.json index 1a68aed78b7..81c0b9db1ff 100644 --- a/advisories/unreviewed/2022/05/GHSA-jxph-qx6w-9c2j/GHSA-jxph-qx6w-9c2j.json +++ b/advisories/unreviewed/2022/05/GHSA-jxph-qx6w-9c2j/GHSA-jxph-qx6w-9c2j.json @@ -7,12 +7,8 @@ "CVE-2006-4163" ], "details": "** DISPUTED ** PHP remote file inclusion vulnerability in cls_fast_template.php in myWebland miniBloggie 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the fname parameter. NOTE: another researcher was unable to find a way to execute code after including it via a URL. CVE analysis as of 20060816 was inconclusive.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m2wr-v2vp-7cpf/GHSA-m2wr-v2vp-7cpf.json b/advisories/unreviewed/2022/05/GHSA-m2wr-v2vp-7cpf/GHSA-m2wr-v2vp-7cpf.json index 5f9e14a7b26..9f06f9f4a29 100644 --- a/advisories/unreviewed/2022/05/GHSA-m2wr-v2vp-7cpf/GHSA-m2wr-v2vp-7cpf.json +++ b/advisories/unreviewed/2022/05/GHSA-m2wr-v2vp-7cpf/GHSA-m2wr-v2vp-7cpf.json @@ -7,12 +7,8 @@ "CVE-2019-10535" ], "details": "Improper validation for loop variable received from firmware can lead to out of bound access in WLAN function while iterating through loop in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music in APQ8053, APQ8096AU, APQ8098, MDM9640, MSM8996AU, MSM8998, QCA6574AU, QCN7605, QCS405, QCS605, SDA845, SDM845, SDX20", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m3xq-c6mf-v376/GHSA-m3xq-c6mf-v376.json b/advisories/unreviewed/2022/05/GHSA-m3xq-c6mf-v376/GHSA-m3xq-c6mf-v376.json index 551b56df401..6877772e2f9 100644 --- a/advisories/unreviewed/2022/05/GHSA-m3xq-c6mf-v376/GHSA-m3xq-c6mf-v376.json +++ b/advisories/unreviewed/2022/05/GHSA-m3xq-c6mf-v376/GHSA-m3xq-c6mf-v376.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m558-43vf-cc6f/GHSA-m558-43vf-cc6f.json b/advisories/unreviewed/2022/05/GHSA-m558-43vf-cc6f/GHSA-m558-43vf-cc6f.json index c483a61b2fd..c20bcfb830c 100644 --- a/advisories/unreviewed/2022/05/GHSA-m558-43vf-cc6f/GHSA-m558-43vf-cc6f.json +++ b/advisories/unreviewed/2022/05/GHSA-m558-43vf-cc6f/GHSA-m558-43vf-cc6f.json @@ -7,12 +7,8 @@ "CVE-2019-5294" ], "details": "There is an out of bound read vulnerability in some Huawei products. A remote, unauthenticated attacker may send a corrupt or crafted message to the affected products. Due to a buffer read overflow error when parsing the message, successful exploit may cause some service to be abnormal.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m579-jw93-j7m5/GHSA-m579-jw93-j7m5.json b/advisories/unreviewed/2022/05/GHSA-m579-jw93-j7m5/GHSA-m579-jw93-j7m5.json index 508a3e5ed37..f87c032a675 100644 --- a/advisories/unreviewed/2022/05/GHSA-m579-jw93-j7m5/GHSA-m579-jw93-j7m5.json +++ b/advisories/unreviewed/2022/05/GHSA-m579-jw93-j7m5/GHSA-m579-jw93-j7m5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m6j8-vc6j-wp2h/GHSA-m6j8-vc6j-wp2h.json b/advisories/unreviewed/2022/05/GHSA-m6j8-vc6j-wp2h/GHSA-m6j8-vc6j-wp2h.json index fe8094d74ce..fe105d8c986 100644 --- a/advisories/unreviewed/2022/05/GHSA-m6j8-vc6j-wp2h/GHSA-m6j8-vc6j-wp2h.json +++ b/advisories/unreviewed/2022/05/GHSA-m6j8-vc6j-wp2h/GHSA-m6j8-vc6j-wp2h.json @@ -7,12 +7,8 @@ "CVE-2019-15381" ], "details": "The BQ 5515L Android device with a build fingerprint of BQru/BQru-5515L/BQru-5515L:8.1.0/O11019/20180409.195525:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m74g-79p9-m5hp/GHSA-m74g-79p9-m5hp.json b/advisories/unreviewed/2022/05/GHSA-m74g-79p9-m5hp/GHSA-m74g-79p9-m5hp.json index 7cf65b8a05d..c3e0abdab2f 100644 --- a/advisories/unreviewed/2022/05/GHSA-m74g-79p9-m5hp/GHSA-m74g-79p9-m5hp.json +++ b/advisories/unreviewed/2022/05/GHSA-m74g-79p9-m5hp/GHSA-m74g-79p9-m5hp.json @@ -7,12 +7,8 @@ "CVE-2019-15407" ], "details": "The Asus ASUS_X015_1 Android device with a build fingerprint of asus/CN_X015/ASUS_X015_1:7.0/NRD90M/CN_X015-14.00.1709.35-20171215:user/release-keys contains a pre-installed app with a package name of com.asus.loguploaderproxy app (versionCode=1570000015, versionName=7.0.0.3_161222) that allows other pre-installed apps to perform command execution via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions that are required by other other pre-installed apps that exported their capabilities to other pre-installed app.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m7xp-wxh2-67mj/GHSA-m7xp-wxh2-67mj.json b/advisories/unreviewed/2022/05/GHSA-m7xp-wxh2-67mj/GHSA-m7xp-wxh2-67mj.json index 91c4222b30c..7885de54cfd 100644 --- a/advisories/unreviewed/2022/05/GHSA-m7xp-wxh2-67mj/GHSA-m7xp-wxh2-67mj.json +++ b/advisories/unreviewed/2022/05/GHSA-m7xp-wxh2-67mj/GHSA-m7xp-wxh2-67mj.json @@ -7,12 +7,8 @@ "CVE-2019-3661" ], "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows remote authenticated attacker to execute database commands via carefully constructed time based payloads.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m8m4-mgvv-fcv9/GHSA-m8m4-mgvv-fcv9.json b/advisories/unreviewed/2022/05/GHSA-m8m4-mgvv-fcv9/GHSA-m8m4-mgvv-fcv9.json index 2bb2a5bc40f..f3f401d8c03 100644 --- a/advisories/unreviewed/2022/05/GHSA-m8m4-mgvv-fcv9/GHSA-m8m4-mgvv-fcv9.json +++ b/advisories/unreviewed/2022/05/GHSA-m8m4-mgvv-fcv9/GHSA-m8m4-mgvv-fcv9.json @@ -7,12 +7,8 @@ "CVE-2019-16964" ], "details": "app/call_centers/cmd.php in the Call Center Queue Module in FusionPBX up to 4.5.7 suffers from a command injection vulnerability due to a lack of input validation, which allows authenticated attackers (with at least the permission call_center_queue_add or call_center_queue_edit) to execute any commands on the host as www-data.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m96w-6w33-g867/GHSA-m96w-6w33-g867.json b/advisories/unreviewed/2022/05/GHSA-m96w-6w33-g867/GHSA-m96w-6w33-g867.json index 3b03f75d776..93d38fbde34 100644 --- a/advisories/unreviewed/2022/05/GHSA-m96w-6w33-g867/GHSA-m96w-6w33-g867.json +++ b/advisories/unreviewed/2022/05/GHSA-m96w-6w33-g867/GHSA-m96w-6w33-g867.json @@ -7,12 +7,8 @@ "CVE-2019-18815" ], "details": "PopojiCMS 2.0.1 allows refer= Open Redirection.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mccc-vqrp-w855/GHSA-mccc-vqrp-w855.json b/advisories/unreviewed/2022/05/GHSA-mccc-vqrp-w855/GHSA-mccc-vqrp-w855.json index f19e3bdb421..6a0f1a609e7 100644 --- a/advisories/unreviewed/2022/05/GHSA-mccc-vqrp-w855/GHSA-mccc-vqrp-w855.json +++ b/advisories/unreviewed/2022/05/GHSA-mccc-vqrp-w855/GHSA-mccc-vqrp-w855.json @@ -7,12 +7,8 @@ "CVE-2019-1397" ], "details": "A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1389, CVE-2019-1398.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mf4f-cr6h-7rxj/GHSA-mf4f-cr6h-7rxj.json b/advisories/unreviewed/2022/05/GHSA-mf4f-cr6h-7rxj/GHSA-mf4f-cr6h-7rxj.json index 10781a18911..47b23e3c6be 100644 --- a/advisories/unreviewed/2022/05/GHSA-mf4f-cr6h-7rxj/GHSA-mf4f-cr6h-7rxj.json +++ b/advisories/unreviewed/2022/05/GHSA-mf4f-cr6h-7rxj/GHSA-mf4f-cr6h-7rxj.json @@ -7,12 +7,8 @@ "CVE-2019-15382" ], "details": "The Cubot Nova Android device with a build fingerprint of CUBOT/CUBOT_NOVA/CUBOT_NOVA:8.1.0/O11019/1527060122:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mf6g-2h9h-jw37/GHSA-mf6g-2h9h-jw37.json b/advisories/unreviewed/2022/05/GHSA-mf6g-2h9h-jw37/GHSA-mf6g-2h9h-jw37.json index d6d71af18c1..21880089d9d 100644 --- a/advisories/unreviewed/2022/05/GHSA-mf6g-2h9h-jw37/GHSA-mf6g-2h9h-jw37.json +++ b/advisories/unreviewed/2022/05/GHSA-mf6g-2h9h-jw37/GHSA-mf6g-2h9h-jw37.json @@ -7,12 +7,8 @@ "CVE-2019-11283" ], "details": "Cloud Foundry SMB Volume, versions prior to v2.0.3, accidentally outputs sensitive information to the logs. A remote user with access to the SMB Volume logs can discover the username and password for volumes that have been recently created, allowing the user to take control of the SMB Volume.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mfrc-8wqr-f298/GHSA-mfrc-8wqr-f298.json b/advisories/unreviewed/2022/05/GHSA-mfrc-8wqr-f298/GHSA-mfrc-8wqr-f298.json index a5bfcbd36f1..9885b7cc369 100644 --- a/advisories/unreviewed/2022/05/GHSA-mfrc-8wqr-f298/GHSA-mfrc-8wqr-f298.json +++ b/advisories/unreviewed/2022/05/GHSA-mfrc-8wqr-f298/GHSA-mfrc-8wqr-f298.json @@ -7,12 +7,8 @@ "CVE-2005-4515" ], "details": "** DISPUTED ** SQL injection vulnerability in WebDB 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified search parameters, possibly Search0. NOTE: the vendor has disputed this issue, saying that \"WebDB is a generic online database system used by many of the clients of Lois Software. The flaw that was identified was some code that was added for a client to do some testing of his system and only certain safe commands were allowed. This code has now been removed and it is not now possible to use SQL queries as part of the query string. No installation or patch is required All clients use a common code library and have their own front end and databases and connections. So as soon as a change / upgrade / enhancement is made to the code, all users of the software begin to use the latest changes immediately.\" Since the issue appeared in a custom web site and no action is required on the part of customers, this issue should not be included in CVE.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mg5h-jxw2-63w8/GHSA-mg5h-jxw2-63w8.json b/advisories/unreviewed/2022/05/GHSA-mg5h-jxw2-63w8/GHSA-mg5h-jxw2-63w8.json index 168c0a63648..8b075f94187 100644 --- a/advisories/unreviewed/2022/05/GHSA-mg5h-jxw2-63w8/GHSA-mg5h-jxw2-63w8.json +++ b/advisories/unreviewed/2022/05/GHSA-mg5h-jxw2-63w8/GHSA-mg5h-jxw2-63w8.json @@ -7,12 +7,8 @@ "CVE-2014-0069" ], "details": "The cifs_iovec_write function in fs/cifs/file.c in the Linux kernel through 3.13.5 does not properly handle uncached write operations that copy fewer than the requested number of bytes, which allows local users to obtain sensitive information from kernel memory, cause a denial of service (memory corruption and system crash), or possibly gain privileges via a writev system call with a crafted pointer.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mgvj-94j9-x737/GHSA-mgvj-94j9-x737.json b/advisories/unreviewed/2022/05/GHSA-mgvj-94j9-x737/GHSA-mgvj-94j9-x737.json index 6d26c706822..614a5546c94 100644 --- a/advisories/unreviewed/2022/05/GHSA-mgvj-94j9-x737/GHSA-mgvj-94j9-x737.json +++ b/advisories/unreviewed/2022/05/GHSA-mgvj-94j9-x737/GHSA-mgvj-94j9-x737.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mh4r-7rfg-7p5x/GHSA-mh4r-7rfg-7p5x.json b/advisories/unreviewed/2022/05/GHSA-mh4r-7rfg-7p5x/GHSA-mh4r-7rfg-7p5x.json index a9e718d6769..7cd92ddaeea 100644 --- a/advisories/unreviewed/2022/05/GHSA-mh4r-7rfg-7p5x/GHSA-mh4r-7rfg-7p5x.json +++ b/advisories/unreviewed/2022/05/GHSA-mh4r-7rfg-7p5x/GHSA-mh4r-7rfg-7p5x.json @@ -7,12 +7,8 @@ "CVE-2019-15452" ], "details": "The Samsung J3 Android device with a build fingerprint of samsung/j3y17ltedx/j3y17lte:8.0.0/R16NW/J330GDXS3BSC1:user/release-keys contains a pre-installed app with a package name of com.samsung.android.themecenter app (versionCode=6010000, versionName=6.1.0.0) that allows other pre-installed apps to perform app installation via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions that are required by other other pre-installed apps that exported their capabilities to other pre-installed app.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mjmv-8qhx-gjhx/GHSA-mjmv-8qhx-gjhx.json b/advisories/unreviewed/2022/05/GHSA-mjmv-8qhx-gjhx/GHSA-mjmv-8qhx-gjhx.json index c943cc78afa..400c4e13327 100644 --- a/advisories/unreviewed/2022/05/GHSA-mjmv-8qhx-gjhx/GHSA-mjmv-8qhx-gjhx.json +++ b/advisories/unreviewed/2022/05/GHSA-mjmv-8qhx-gjhx/GHSA-mjmv-8qhx-gjhx.json @@ -7,12 +7,8 @@ "CVE-2019-11153" ], "details": "Memory corruption issues in Intel(R) PROSet/Wireless WiFi Software extension DLL before version 21.40 may allow an authenticated user to potentially enable escalation of privilege, information disclosure and a denial of service via local access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mjp9-35c3-rjjh/GHSA-mjp9-35c3-rjjh.json b/advisories/unreviewed/2022/05/GHSA-mjp9-35c3-rjjh/GHSA-mjp9-35c3-rjjh.json index 7660b46e4ea..82db6706d82 100644 --- a/advisories/unreviewed/2022/05/GHSA-mjp9-35c3-rjjh/GHSA-mjp9-35c3-rjjh.json +++ b/advisories/unreviewed/2022/05/GHSA-mjp9-35c3-rjjh/GHSA-mjp9-35c3-rjjh.json @@ -7,12 +7,8 @@ "CVE-2005-1894" ], "details": "Direct code injection vulnerability in FlatNuke 2.5.3 allows remote attackers to execute arbitrary PHP code by placing the code into the Referer header of an HTTP request, which causes the code to be injected into referer.php, which can then be accessed by the attacker.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mp7j-cxcw-6c89/GHSA-mp7j-cxcw-6c89.json b/advisories/unreviewed/2022/05/GHSA-mp7j-cxcw-6c89/GHSA-mp7j-cxcw-6c89.json index 1c5010588f0..7196bb39e8c 100644 --- a/advisories/unreviewed/2022/05/GHSA-mp7j-cxcw-6c89/GHSA-mp7j-cxcw-6c89.json +++ b/advisories/unreviewed/2022/05/GHSA-mp7j-cxcw-6c89/GHSA-mp7j-cxcw-6c89.json @@ -7,12 +7,8 @@ "CVE-2019-2205" ], "details": "In ProxyResolverV8::SetPacScript of proxy_resolver_v8.cc, there is a possible memory corruption due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-139806216", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mrc5-6p32-6hrm/GHSA-mrc5-6p32-6hrm.json b/advisories/unreviewed/2022/05/GHSA-mrc5-6p32-6hrm/GHSA-mrc5-6p32-6hrm.json index 848345f4510..ec4694692f8 100644 --- a/advisories/unreviewed/2022/05/GHSA-mrc5-6p32-6hrm/GHSA-mrc5-6p32-6hrm.json +++ b/advisories/unreviewed/2022/05/GHSA-mrc5-6p32-6hrm/GHSA-mrc5-6p32-6hrm.json @@ -7,12 +7,8 @@ "CVE-2015-9524" ], "details": "The Easy Digital Downloads (EDD) Recount Earnings extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mrhx-hcg2-5p6w/GHSA-mrhx-hcg2-5p6w.json b/advisories/unreviewed/2022/05/GHSA-mrhx-hcg2-5p6w/GHSA-mrhx-hcg2-5p6w.json index 4e50536a2d3..0b704f6590c 100644 --- a/advisories/unreviewed/2022/05/GHSA-mrhx-hcg2-5p6w/GHSA-mrhx-hcg2-5p6w.json +++ b/advisories/unreviewed/2022/05/GHSA-mrhx-hcg2-5p6w/GHSA-mrhx-hcg2-5p6w.json @@ -7,12 +7,8 @@ "CVE-2019-17331" ], "details": "The Data Exchange Web Interface component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains a vulnerability that theoretically allows authenticated users to perform stored cross-site scripting (XSS) attacks. Affected releases are TIBCO Software Inc.'s TIBCO EBX Add-ons: versions up to and including 3.20.13, version 4.1.0.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mrwj-9mpp-w94q/GHSA-mrwj-9mpp-w94q.json b/advisories/unreviewed/2022/05/GHSA-mrwj-9mpp-w94q/GHSA-mrwj-9mpp-w94q.json index 6790fb18906..69d988fa929 100644 --- a/advisories/unreviewed/2022/05/GHSA-mrwj-9mpp-w94q/GHSA-mrwj-9mpp-w94q.json +++ b/advisories/unreviewed/2022/05/GHSA-mrwj-9mpp-w94q/GHSA-mrwj-9mpp-w94q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mw23-8m9f-c29g/GHSA-mw23-8m9f-c29g.json b/advisories/unreviewed/2022/05/GHSA-mw23-8m9f-c29g/GHSA-mw23-8m9f-c29g.json index fb8bf17c5b7..24457f0efb7 100644 --- a/advisories/unreviewed/2022/05/GHSA-mw23-8m9f-c29g/GHSA-mw23-8m9f-c29g.json +++ b/advisories/unreviewed/2022/05/GHSA-mw23-8m9f-c29g/GHSA-mw23-8m9f-c29g.json @@ -7,12 +7,8 @@ "CVE-2019-18807" ], "details": "Two memory leaks in the sja1105_static_config_upload() function in drivers/net/dsa/sja1105/sja1105_spi.c in the Linux kernel before 5.3.5 allow attackers to cause a denial of service (memory consumption) by triggering static_config_buf_prepare_for_upload() or sja1105_inhibit_tx() failures, aka CID-68501df92d11.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mwf3-rpq5-x552/GHSA-mwf3-rpq5-x552.json b/advisories/unreviewed/2022/05/GHSA-mwf3-rpq5-x552/GHSA-mwf3-rpq5-x552.json index b166e54a035..bf9e58ea1ba 100644 --- a/advisories/unreviewed/2022/05/GHSA-mwf3-rpq5-x552/GHSA-mwf3-rpq5-x552.json +++ b/advisories/unreviewed/2022/05/GHSA-mwf3-rpq5-x552/GHSA-mwf3-rpq5-x552.json @@ -7,12 +7,8 @@ "CVE-2016-5202" ], "details": "browser/extensions/api/dial/dial_registry.cc in Google Chrome before 54.0.2840.98 on macOS, before 54.0.2840.99 on Windows, and before 54.0.2840.100 on Linux neglects to copy a device ID before an erase() call, which causes the erase operation to access data that that erase operation will destroy.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mwv8-97c7-563x/GHSA-mwv8-97c7-563x.json b/advisories/unreviewed/2022/05/GHSA-mwv8-97c7-563x/GHSA-mwv8-97c7-563x.json index ede191efccd..203a2cc0854 100644 --- a/advisories/unreviewed/2022/05/GHSA-mwv8-97c7-563x/GHSA-mwv8-97c7-563x.json +++ b/advisories/unreviewed/2022/05/GHSA-mwv8-97c7-563x/GHSA-mwv8-97c7-563x.json @@ -7,12 +7,8 @@ "CVE-2006-5549" ], "details": "** DISPUTED ** PHP remote file inclusion vulnerability in libraries/amfphp/amf-core/custom/CachedGateway.php in Adobe PHP SDK allows remote attackers to execute arbitrary PHP code via the AMFPHP_BASE parameter. NOTE: this issue has been disputed by a third-party researcher who states that AMFPHP_BASE is a constant.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mww8-4q2m-9jw9/GHSA-mww8-4q2m-9jw9.json b/advisories/unreviewed/2022/05/GHSA-mww8-4q2m-9jw9/GHSA-mww8-4q2m-9jw9.json index 0e0b520d8ac..41fba6c71da 100644 --- a/advisories/unreviewed/2022/05/GHSA-mww8-4q2m-9jw9/GHSA-mww8-4q2m-9jw9.json +++ b/advisories/unreviewed/2022/05/GHSA-mww8-4q2m-9jw9/GHSA-mww8-4q2m-9jw9.json @@ -7,12 +7,8 @@ "CVE-2019-16878" ], "details": "Portainer before 1.22.1 has XSS (issue 2 of 2).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mxr9-7gmh-7r3m/GHSA-mxr9-7gmh-7r3m.json b/advisories/unreviewed/2022/05/GHSA-mxr9-7gmh-7r3m/GHSA-mxr9-7gmh-7r3m.json index 33d349ce0b7..138141ec9ba 100644 --- a/advisories/unreviewed/2022/05/GHSA-mxr9-7gmh-7r3m/GHSA-mxr9-7gmh-7r3m.json +++ b/advisories/unreviewed/2022/05/GHSA-mxr9-7gmh-7r3m/GHSA-mxr9-7gmh-7r3m.json @@ -7,12 +7,8 @@ "CVE-2019-18647" ], "details": "The Untangle NG firewall 14.2.0 is vulnerable to an authenticated command injection when logged in as an admin user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p23f-q5pj-xhfq/GHSA-p23f-q5pj-xhfq.json b/advisories/unreviewed/2022/05/GHSA-p23f-q5pj-xhfq/GHSA-p23f-q5pj-xhfq.json index 7ed094cc5c2..1f4a15ae817 100644 --- a/advisories/unreviewed/2022/05/GHSA-p23f-q5pj-xhfq/GHSA-p23f-q5pj-xhfq.json +++ b/advisories/unreviewed/2022/05/GHSA-p23f-q5pj-xhfq/GHSA-p23f-q5pj-xhfq.json @@ -7,12 +7,8 @@ "CVE-2019-18382" ], "details": "An issue was discovered on AVStar PE204 3.10.70 IP camera devices. A denial of service can occur on open TCP port 23456. After a TELNET connection, no TCP ports are open.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p35c-m7rx-rcvq/GHSA-p35c-m7rx-rcvq.json b/advisories/unreviewed/2022/05/GHSA-p35c-m7rx-rcvq/GHSA-p35c-m7rx-rcvq.json index 1f381cc54ee..2d3abdae412 100644 --- a/advisories/unreviewed/2022/05/GHSA-p35c-m7rx-rcvq/GHSA-p35c-m7rx-rcvq.json +++ b/advisories/unreviewed/2022/05/GHSA-p35c-m7rx-rcvq/GHSA-p35c-m7rx-rcvq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p4x6-pmx2-w6pr/GHSA-p4x6-pmx2-w6pr.json b/advisories/unreviewed/2022/05/GHSA-p4x6-pmx2-w6pr/GHSA-p4x6-pmx2-w6pr.json index 0d35ebe17fd..2562ab03637 100644 --- a/advisories/unreviewed/2022/05/GHSA-p4x6-pmx2-w6pr/GHSA-p4x6-pmx2-w6pr.json +++ b/advisories/unreviewed/2022/05/GHSA-p4x6-pmx2-w6pr/GHSA-p4x6-pmx2-w6pr.json @@ -7,12 +7,8 @@ "CVE-2019-0151" ], "details": "Insufficient memory protection in Intel(R) TXT for certain Intel(R) Core Processors and Intel(R) Xeon(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p55g-m23x-9hgq/GHSA-p55g-m23x-9hgq.json b/advisories/unreviewed/2022/05/GHSA-p55g-m23x-9hgq/GHSA-p55g-m23x-9hgq.json index 339835cea17..26957f834f9 100644 --- a/advisories/unreviewed/2022/05/GHSA-p55g-m23x-9hgq/GHSA-p55g-m23x-9hgq.json +++ b/advisories/unreviewed/2022/05/GHSA-p55g-m23x-9hgq/GHSA-p55g-m23x-9hgq.json @@ -7,12 +7,8 @@ "CVE-2019-2193" ], "details": "In WelcomeActivity.java and related files, there is a possible permissions bypass due to a partially provisioned Device Policy Client. This could lead to local escalation of privilege, leaving an Admin app installed with no indication to the user, with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-132261064", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p5gp-qf83-r68v/GHSA-p5gp-qf83-r68v.json b/advisories/unreviewed/2022/05/GHSA-p5gp-qf83-r68v/GHSA-p5gp-qf83-r68v.json index 64ccdcf33ca..0f3a538154a 100644 --- a/advisories/unreviewed/2022/05/GHSA-p5gp-qf83-r68v/GHSA-p5gp-qf83-r68v.json +++ b/advisories/unreviewed/2022/05/GHSA-p5gp-qf83-r68v/GHSA-p5gp-qf83-r68v.json @@ -7,12 +7,8 @@ "CVE-2019-15424" ], "details": "The Doogee BL5000 Android device with a build fingerprint of DOOGEE/BL5000/BL5000:7.0/NRD90M/1497072355:user/release-keys contains a pre-installed app with a package name of com.mediatek.factorymode app (versionCode=1, versionName=1) that allows unauthorized wireless settings modification via a confused deputy attack. This capability can be accessed by any app co-located on the device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p6f6-w39x-f8q3/GHSA-p6f6-w39x-f8q3.json b/advisories/unreviewed/2022/05/GHSA-p6f6-w39x-f8q3/GHSA-p6f6-w39x-f8q3.json index bba5ba9f8d7..99c343281b7 100644 --- a/advisories/unreviewed/2022/05/GHSA-p6f6-w39x-f8q3/GHSA-p6f6-w39x-f8q3.json +++ b/advisories/unreviewed/2022/05/GHSA-p6f6-w39x-f8q3/GHSA-p6f6-w39x-f8q3.json @@ -7,12 +7,8 @@ "CVE-2019-15678" ], "details": "TightVNC code version 1.3.10 contains heap buffer overflow in rfbServerCutText handler, which can potentially result code execution.. This attack appear to be exploitable via network connectivity.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p6v4-55x8-jc35/GHSA-p6v4-55x8-jc35.json b/advisories/unreviewed/2022/05/GHSA-p6v4-55x8-jc35/GHSA-p6v4-55x8-jc35.json index 2eb0fe4d6ae..5205bc27e5e 100644 --- a/advisories/unreviewed/2022/05/GHSA-p6v4-55x8-jc35/GHSA-p6v4-55x8-jc35.json +++ b/advisories/unreviewed/2022/05/GHSA-p6v4-55x8-jc35/GHSA-p6v4-55x8-jc35.json @@ -7,12 +7,8 @@ "CVE-2019-3764" ], "details": "Dell EMC iDRAC8 versions prior to 2.70.70.70 and iDRAC9 versions prior to 3.36.36.36 contain an improper authorization vulnerability. A remote authenticated malicious iDRAC user with low privileges may potentially exploit this vulnerability to obtain sensitive information such as password hashes.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p87m-p5p2-q25w/GHSA-p87m-p5p2-q25w.json b/advisories/unreviewed/2022/05/GHSA-p87m-p5p2-q25w/GHSA-p87m-p5p2-q25w.json index 78bd00f2345..387d00e98fb 100644 --- a/advisories/unreviewed/2022/05/GHSA-p87m-p5p2-q25w/GHSA-p87m-p5p2-q25w.json +++ b/advisories/unreviewed/2022/05/GHSA-p87m-p5p2-q25w/GHSA-p87m-p5p2-q25w.json @@ -7,12 +7,8 @@ "CVE-2019-15423" ], "details": "The Bluboo Bluboo_S1 Android device with a build fingerprint of BLUBOO/Bluboo_S1/Bluboo_S1:7.0/NRD90M/1495809471:user/release-keys contains a pre-installed app with a package name of com.mediatek.factorymode app (versionCode=1, versionName=1) that allows unauthorized wireless settings modification via a confused deputy attack. This capability can be accessed by any app co-located on the device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p8j9-xg3x-hph5/GHSA-p8j9-xg3x-hph5.json b/advisories/unreviewed/2022/05/GHSA-p8j9-xg3x-hph5/GHSA-p8j9-xg3x-hph5.json index 69c6205fac0..4434386f1ed 100644 --- a/advisories/unreviewed/2022/05/GHSA-p8j9-xg3x-hph5/GHSA-p8j9-xg3x-hph5.json +++ b/advisories/unreviewed/2022/05/GHSA-p8j9-xg3x-hph5/GHSA-p8j9-xg3x-hph5.json @@ -7,12 +7,8 @@ "CVE-2019-0139" ], "details": "Insufficient access control in firmware for Intel(R) Ethernet 700 Series Controllers before version 7.0 may allow a privileged user to potentially enable an escalation of privilege, denial of service, or information disclosure via local access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p9cc-vhfp-h269/GHSA-p9cc-vhfp-h269.json b/advisories/unreviewed/2022/05/GHSA-p9cc-vhfp-h269/GHSA-p9cc-vhfp-h269.json index 40927dc335a..b3478f509ca 100644 --- a/advisories/unreviewed/2022/05/GHSA-p9cc-vhfp-h269/GHSA-p9cc-vhfp-h269.json +++ b/advisories/unreviewed/2022/05/GHSA-p9cc-vhfp-h269/GHSA-p9cc-vhfp-h269.json @@ -7,12 +7,8 @@ "CVE-2019-17330" ], "details": "The Web server component of TIBCO Software Inc.'s TIBCO EBX contains multiple vulnerabilities that theoretically allow authenticated users to perform stored cross-site scripting (XSS) attacks, and unauthenticated users to perform reflected cross-site scripting attacks. Affected releases are TIBCO Software Inc.'s TIBCO EBX: versions up to and including 5.8.1.fixR, versions 5.9.3, 5.9.4, 5.9.5, and 5.9.6.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pc3p-r8p6-rgcq/GHSA-pc3p-r8p6-rgcq.json b/advisories/unreviewed/2022/05/GHSA-pc3p-r8p6-rgcq/GHSA-pc3p-r8p6-rgcq.json index d0bc512607e..1ef626035bd 100644 --- a/advisories/unreviewed/2022/05/GHSA-pc3p-r8p6-rgcq/GHSA-pc3p-r8p6-rgcq.json +++ b/advisories/unreviewed/2022/05/GHSA-pc3p-r8p6-rgcq/GHSA-pc3p-r8p6-rgcq.json @@ -7,12 +7,8 @@ "CVE-2019-15437" ], "details": "The Samsung XCover4 Android device with a build fingerprint of samsung/xcover4ltexx/xcover4lte:8.1.0/M1AJQ/G390FXXU3BSA2:user/release-keys contains a pre-installed app with a package name of com.samsung.android.themecenter app (versionCode=7000100, versionName=7.0.1.0) that allows other pre-installed apps to perform app installation via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions that are required by other other pre-installed apps that exported their capabilities to other pre-installed app.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pc62-pw4x-v3r6/GHSA-pc62-pw4x-v3r6.json b/advisories/unreviewed/2022/05/GHSA-pc62-pw4x-v3r6/GHSA-pc62-pw4x-v3r6.json index ca070d5a21e..2a5ae351031 100644 --- a/advisories/unreviewed/2022/05/GHSA-pc62-pw4x-v3r6/GHSA-pc62-pw4x-v3r6.json +++ b/advisories/unreviewed/2022/05/GHSA-pc62-pw4x-v3r6/GHSA-pc62-pw4x-v3r6.json @@ -7,12 +7,8 @@ "CVE-2015-2793" ], "details": "Cross-site scripting (XSS) vulnerability in templates/openid-selector.tmpl in ikiwiki before 3.20150329 allows remote attackers to inject arbitrary web script or HTML via the openid_identifier parameter in a verify action to ikiwiki.cgi.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pcw4-835f-xfg2/GHSA-pcw4-835f-xfg2.json b/advisories/unreviewed/2022/05/GHSA-pcw4-835f-xfg2/GHSA-pcw4-835f-xfg2.json index b3972e49af6..24ad3903ff6 100644 --- a/advisories/unreviewed/2022/05/GHSA-pcw4-835f-xfg2/GHSA-pcw4-835f-xfg2.json +++ b/advisories/unreviewed/2022/05/GHSA-pcw4-835f-xfg2/GHSA-pcw4-835f-xfg2.json @@ -7,12 +7,8 @@ "CVE-2015-9514" ], "details": "The Easy Digital Downloads (EDD) Free Downloads extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pg6p-7jwx-86vp/GHSA-pg6p-7jwx-86vp.json b/advisories/unreviewed/2022/05/GHSA-pg6p-7jwx-86vp/GHSA-pg6p-7jwx-86vp.json index 96f5ceede64..8ea7a048ea8 100644 --- a/advisories/unreviewed/2022/05/GHSA-pg6p-7jwx-86vp/GHSA-pg6p-7jwx-86vp.json +++ b/advisories/unreviewed/2022/05/GHSA-pg6p-7jwx-86vp/GHSA-pg6p-7jwx-86vp.json @@ -7,12 +7,8 @@ "CVE-2019-5538" ], "details": "Sensitive information disclosure vulnerability resulting from a lack of certificate validation during the File-Based Backup and Restore operations of VMware vCenter Server Appliance (6.7 before 6.7u3a and 6.5 before 6.5u3d) may allow a malicious actor to intercept sensitive data in transit over SCP. A malicious actor with man-in-the-middle positioning between vCenter Server Appliance and a backup target may be able to intercept sensitive data in transit during File-Based Backup and Restore operations.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pm96-chg7-mq3g/GHSA-pm96-chg7-mq3g.json b/advisories/unreviewed/2022/05/GHSA-pm96-chg7-mq3g/GHSA-pm96-chg7-mq3g.json index 2043fed6b97..220eba8a71e 100644 --- a/advisories/unreviewed/2022/05/GHSA-pm96-chg7-mq3g/GHSA-pm96-chg7-mq3g.json +++ b/advisories/unreviewed/2022/05/GHSA-pm96-chg7-mq3g/GHSA-pm96-chg7-mq3g.json @@ -7,12 +7,8 @@ "CVE-2019-15072" ], "details": "The login feature in \"/cgi-bin/portal\" in MAIL2000 through version 6.0 and 7.0 has a cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code via any parameter. This vulnerability affects many mail system of governments, organizations, companies and universities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pmjh-j6vv-2xf5/GHSA-pmjh-j6vv-2xf5.json b/advisories/unreviewed/2022/05/GHSA-pmjh-j6vv-2xf5/GHSA-pmjh-j6vv-2xf5.json index 113c3baf0d8..e243430afd3 100644 --- a/advisories/unreviewed/2022/05/GHSA-pmjh-j6vv-2xf5/GHSA-pmjh-j6vv-2xf5.json +++ b/advisories/unreviewed/2022/05/GHSA-pmjh-j6vv-2xf5/GHSA-pmjh-j6vv-2xf5.json @@ -7,12 +7,8 @@ "CVE-2019-15436" ], "details": "The Samsung A8+ Android device with a build fingerprint of samsung/jackpot2ltexx/jackpot2lte:8.0.0/R16NW/A730FXXS4BSC2:user/release-keys contains a pre-installed app with a package name of com.samsung.android.themecenter app (versionCode=7000000, versionName=7.0.0.0) that allows other pre-installed apps to perform app installation via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions that are required by other other pre-installed apps that exported their capabilities to other pre-installed app.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pmpr-j5rj-6vg8/GHSA-pmpr-j5rj-6vg8.json b/advisories/unreviewed/2022/05/GHSA-pmpr-j5rj-6vg8/GHSA-pmpr-j5rj-6vg8.json index df106a46aac..59a8a96e9f8 100644 --- a/advisories/unreviewed/2022/05/GHSA-pmpr-j5rj-6vg8/GHSA-pmpr-j5rj-6vg8.json +++ b/advisories/unreviewed/2022/05/GHSA-pmpr-j5rj-6vg8/GHSA-pmpr-j5rj-6vg8.json @@ -7,12 +7,8 @@ "CVE-2019-15473" ], "details": "The Xiaomi Mi A2 Lite Android device with a build fingerprint of xiaomi/jasmine/jasmine_sprout:9/PKQ1.180904.001/V10.0.2.0.PDIMIFJ:user/release-keys contains a pre-installed app with a package name of com.qualcomm.qti.callenhancement app (versionCode=28, versionName=9) that allows unauthorized microphone audio recording via a confused deputy attack. This capability can be accessed by any app co-located on the device. This app allows a third-party app to use its open interface to record telephone calls to external storage.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-ppg5-jv44-479j/GHSA-ppg5-jv44-479j.json b/advisories/unreviewed/2022/05/GHSA-ppg5-jv44-479j/GHSA-ppg5-jv44-479j.json index 1d016cef176..20df97d4fa5 100644 --- a/advisories/unreviewed/2022/05/GHSA-ppg5-jv44-479j/GHSA-ppg5-jv44-479j.json +++ b/advisories/unreviewed/2022/05/GHSA-ppg5-jv44-479j/GHSA-ppg5-jv44-479j.json @@ -7,12 +7,8 @@ "CVE-2019-8081" ], "details": "Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have an authentication bypass vulnerability. Successful exploitation could lead to sensitive information disclosure.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-ppwm-7w85-69vv/GHSA-ppwm-7w85-69vv.json b/advisories/unreviewed/2022/05/GHSA-ppwm-7w85-69vv/GHSA-ppwm-7w85-69vv.json index fdf97740419..71566dff07a 100644 --- a/advisories/unreviewed/2022/05/GHSA-ppwm-7w85-69vv/GHSA-ppwm-7w85-69vv.json +++ b/advisories/unreviewed/2022/05/GHSA-ppwm-7w85-69vv/GHSA-ppwm-7w85-69vv.json @@ -7,12 +7,8 @@ "CVE-2019-15338" ], "details": "The Lava Iris 88 Lite Android device with a build fingerprint of LAVA/iris88_lite/iris88_lite:8.1.0/O11019/1536323070:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionName=v4.0.27) that allows any app co-located on the device to programmatically disable and enable Wi-Fi without the corresponding access permission through an exported interface.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-ppx7-mxgw-q7jx/GHSA-ppx7-mxgw-q7jx.json b/advisories/unreviewed/2022/05/GHSA-ppx7-mxgw-q7jx/GHSA-ppx7-mxgw-q7jx.json index 4a56072bee7..1edf035acb4 100644 --- a/advisories/unreviewed/2022/05/GHSA-ppx7-mxgw-q7jx/GHSA-ppx7-mxgw-q7jx.json +++ b/advisories/unreviewed/2022/05/GHSA-ppx7-mxgw-q7jx/GHSA-ppx7-mxgw-q7jx.json @@ -7,12 +7,8 @@ "CVE-2019-15419" ], "details": "The Asus ASUS_X015_1 Android device with a build fingerprint of asus/CN_X015/ASUS_X015_1:7.0/NRD90M/CN_X015-14.00.1709.35-20171215:user/release-keys contains a pre-installed app with a package name of com.lovelyfont.defcontainer app (versionCode=5, versionName=5.0.1) that allows unauthorized command execution via a confused deputy attack. This capability can be accessed by any app co-located on the device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pqjx-45r6-4gfp/GHSA-pqjx-45r6-4gfp.json b/advisories/unreviewed/2022/05/GHSA-pqjx-45r6-4gfp/GHSA-pqjx-45r6-4gfp.json index 02f8725e016..2545250a657 100644 --- a/advisories/unreviewed/2022/05/GHSA-pqjx-45r6-4gfp/GHSA-pqjx-45r6-4gfp.json +++ b/advisories/unreviewed/2022/05/GHSA-pqjx-45r6-4gfp/GHSA-pqjx-45r6-4gfp.json @@ -7,12 +7,8 @@ "CVE-2019-15335" ], "details": "The Lava Z92 Android device with a build fingerprint of LAVA/Z92/Z92:8.1.0/O11019/1535088037:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionName=v4.0.27) that allows any app co-located on the device to programmatically disable and enable Wi-Fi without the corresponding access permission through an exported interface.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pqmr-7wg9-jg7r/GHSA-pqmr-7wg9-jg7r.json b/advisories/unreviewed/2022/05/GHSA-pqmr-7wg9-jg7r/GHSA-pqmr-7wg9-jg7r.json index 42137990158..b1238ca1c48 100644 --- a/advisories/unreviewed/2022/05/GHSA-pqmr-7wg9-jg7r/GHSA-pqmr-7wg9-jg7r.json +++ b/advisories/unreviewed/2022/05/GHSA-pqmr-7wg9-jg7r/GHSA-pqmr-7wg9-jg7r.json @@ -7,12 +7,8 @@ "CVE-2019-13535" ], "details": "In Medtronic Valleylab FT10 Energy Platform (VLFT10GEN) version 2.1.0 and lower and version 2.0.3 and lower, and Valleylab LS10 Energy Platform (VLLS10GEN?not available in the United States) version 1.20.2 and lower, the RFID security mechanism does not apply read protection, allowing for full read access of the RFID security mechanism data.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pr66-x6wp-54vx/GHSA-pr66-x6wp-54vx.json b/advisories/unreviewed/2022/05/GHSA-pr66-x6wp-54vx/GHSA-pr66-x6wp-54vx.json index 2ca54563bd5..b7dc0360cdb 100644 --- a/advisories/unreviewed/2022/05/GHSA-pr66-x6wp-54vx/GHSA-pr66-x6wp-54vx.json +++ b/advisories/unreviewed/2022/05/GHSA-pr66-x6wp-54vx/GHSA-pr66-x6wp-54vx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pr6w-w2r2-gm2g/GHSA-pr6w-w2r2-gm2g.json b/advisories/unreviewed/2022/05/GHSA-pr6w-w2r2-gm2g/GHSA-pr6w-w2r2-gm2g.json index 34e455cdb24..810f0bcd9b5 100644 --- a/advisories/unreviewed/2022/05/GHSA-pr6w-w2r2-gm2g/GHSA-pr6w-w2r2-gm2g.json +++ b/advisories/unreviewed/2022/05/GHSA-pr6w-w2r2-gm2g/GHSA-pr6w-w2r2-gm2g.json @@ -7,12 +7,8 @@ "CVE-2019-11154" ], "details": "Improper directory permissions in Intel(R) PROSet/Wireless WiFi Software before version 21.40 may allow an authenticated user to potentially enable denial of service and information disclosure via local access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-prh8-wcxg-jgf2/GHSA-prh8-wcxg-jgf2.json b/advisories/unreviewed/2022/05/GHSA-prh8-wcxg-jgf2/GHSA-prh8-wcxg-jgf2.json index fa26c7035df..fbd89ae445b 100644 --- a/advisories/unreviewed/2022/05/GHSA-prh8-wcxg-jgf2/GHSA-prh8-wcxg-jgf2.json +++ b/advisories/unreviewed/2022/05/GHSA-prh8-wcxg-jgf2/GHSA-prh8-wcxg-jgf2.json @@ -7,12 +7,8 @@ "CVE-2015-9518" ], "details": "The Easy Digital Downloads (EDD) PDF Invoices extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-prq5-5f99-j98g/GHSA-prq5-5f99-j98g.json b/advisories/unreviewed/2022/05/GHSA-prq5-5f99-j98g/GHSA-prq5-5f99-j98g.json index 8cdc70e7cd7..ae040e2ac44 100644 --- a/advisories/unreviewed/2022/05/GHSA-prq5-5f99-j98g/GHSA-prq5-5f99-j98g.json +++ b/advisories/unreviewed/2022/05/GHSA-prq5-5f99-j98g/GHSA-prq5-5f99-j98g.json @@ -7,12 +7,8 @@ "CVE-2019-17515" ], "details": "The CleanTalk cleantalk-spam-protect plugin before 5.127.4 for WordPress is affected by: Cross Site Scripting (XSS). The impact is: Allows an attacker to execute arbitrary HTML and JavaScript code via the from or till parameter. The component is: inc/cleantalk-users.php and inc/cleantalk-comments.php. The attack vector is: When the Administrator is logged in, a reflected XSS may execute upon a click on a malicious URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pv2w-3wq2-7rvh/GHSA-pv2w-3wq2-7rvh.json b/advisories/unreviewed/2022/05/GHSA-pv2w-3wq2-7rvh/GHSA-pv2w-3wq2-7rvh.json index 9ed3dac15c5..dc214212d85 100644 --- a/advisories/unreviewed/2022/05/GHSA-pv2w-3wq2-7rvh/GHSA-pv2w-3wq2-7rvh.json +++ b/advisories/unreviewed/2022/05/GHSA-pv2w-3wq2-7rvh/GHSA-pv2w-3wq2-7rvh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pv5h-rq3f-gr9q/GHSA-pv5h-rq3f-gr9q.json b/advisories/unreviewed/2022/05/GHSA-pv5h-rq3f-gr9q/GHSA-pv5h-rq3f-gr9q.json index 5012131e6b8..6e60f6c8ddd 100644 --- a/advisories/unreviewed/2022/05/GHSA-pv5h-rq3f-gr9q/GHSA-pv5h-rq3f-gr9q.json +++ b/advisories/unreviewed/2022/05/GHSA-pv5h-rq3f-gr9q/GHSA-pv5h-rq3f-gr9q.json @@ -7,12 +7,8 @@ "CVE-2015-9510" ], "details": "The Easy Digital Downloads (EDD) Cross-sell Upsell extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pw8j-fmq7-g3jm/GHSA-pw8j-fmq7-g3jm.json b/advisories/unreviewed/2022/05/GHSA-pw8j-fmq7-g3jm/GHSA-pw8j-fmq7-g3jm.json index f365e1362c5..abc48e5b862 100644 --- a/advisories/unreviewed/2022/05/GHSA-pw8j-fmq7-g3jm/GHSA-pw8j-fmq7-g3jm.json +++ b/advisories/unreviewed/2022/05/GHSA-pw8j-fmq7-g3jm/GHSA-pw8j-fmq7-g3jm.json @@ -7,12 +7,8 @@ "CVE-2019-18873" ], "details": "FUDForum 3.0.9 is vulnerable to Stored XSS via the User-Agent HTTP header. This may result in remote code execution. An attacker can use a user account to fully compromise the system via a GET request. When the admin visits user information under \"User Manager\" in the control panel, the payload will execute. This will allow for PHP files to be written to the web root, and for code to execute on the remote server. The problem is in admsession.php and admuser.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-px5w-6xv9-xcqp/GHSA-px5w-6xv9-xcqp.json b/advisories/unreviewed/2022/05/GHSA-px5w-6xv9-xcqp/GHSA-px5w-6xv9-xcqp.json index f7cb4fd7d2f..ba3d4414acb 100644 --- a/advisories/unreviewed/2022/05/GHSA-px5w-6xv9-xcqp/GHSA-px5w-6xv9-xcqp.json +++ b/advisories/unreviewed/2022/05/GHSA-px5w-6xv9-xcqp/GHSA-px5w-6xv9-xcqp.json @@ -7,12 +7,8 @@ "CVE-2019-15401" ], "details": "The Asus ASUS_A002 Android device with a build fingerprint of asus/WW_ASUS_A002/ASUS_A002:7.0/NRD90M/14.1600.1805.51-20180626:user/release-keys contains a pre-installed app with a package name of com.asus.loguploaderproxy app (versionCode=1570000020, versionName=7.0.0.4_170901) that allows other pre-installed apps to perform command execution via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions that are required by other other pre-installed apps that exported their capabilities to other pre-installed app.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-px84-vp54-mpj7/GHSA-px84-vp54-mpj7.json b/advisories/unreviewed/2022/05/GHSA-px84-vp54-mpj7/GHSA-px84-vp54-mpj7.json index b2f90ee8c57..95b7a4c5458 100644 --- a/advisories/unreviewed/2022/05/GHSA-px84-vp54-mpj7/GHSA-px84-vp54-mpj7.json +++ b/advisories/unreviewed/2022/05/GHSA-px84-vp54-mpj7/GHSA-px84-vp54-mpj7.json @@ -7,12 +7,8 @@ "CVE-2019-15395" ], "details": "The Asus ZenFone 3s Max Android device with a build fingerprint of asus/IN_X00G/ASUS_X00G_1:7.0/NRD90M/IN_X00G-14.02.1807.33-20180706:user/release-keys contains a pre-installed app with a package name of com.asus.loguploaderproxy app (versionCode=1570000015, versionName=7.0.0.3_161222) that allows other pre-installed apps to perform command execution via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions that are required by other other pre-installed apps that exported their capabilities to other pre-installed app.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pxf7-7jp8-6443/GHSA-pxf7-7jp8-6443.json b/advisories/unreviewed/2022/05/GHSA-pxf7-7jp8-6443/GHSA-pxf7-7jp8-6443.json index e740d8433c1..7049b5a9f6c 100644 --- a/advisories/unreviewed/2022/05/GHSA-pxf7-7jp8-6443/GHSA-pxf7-7jp8-6443.json +++ b/advisories/unreviewed/2022/05/GHSA-pxf7-7jp8-6443/GHSA-pxf7-7jp8-6443.json @@ -7,12 +7,8 @@ "CVE-2006-6597" ], "details": "Argument injection vulnerability in HyperAccess 8.4 allows user-assisted remote attackers to execute arbitrary vbscript and commands via the /r option in a telnet:// URI, which is configured to use hawin32.exe.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q2p9-2vqw-p932/GHSA-q2p9-2vqw-p932.json b/advisories/unreviewed/2022/05/GHSA-q2p9-2vqw-p932/GHSA-q2p9-2vqw-p932.json index 97ef83e6af2..aea1edd5dfa 100644 --- a/advisories/unreviewed/2022/05/GHSA-q2p9-2vqw-p932/GHSA-q2p9-2vqw-p932.json +++ b/advisories/unreviewed/2022/05/GHSA-q2p9-2vqw-p932/GHSA-q2p9-2vqw-p932.json @@ -7,12 +7,8 @@ "CVE-2019-15352" ], "details": "The Coolpad 1851 Android device with a build fingerprint of Coolpad/android/android:8.1.0/O11019/1534834761:userdebug/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q376-xcm5-vgv5/GHSA-q376-xcm5-vgv5.json b/advisories/unreviewed/2022/05/GHSA-q376-xcm5-vgv5/GHSA-q376-xcm5-vgv5.json index ab06125b04d..46b882e2a8b 100644 --- a/advisories/unreviewed/2022/05/GHSA-q376-xcm5-vgv5/GHSA-q376-xcm5-vgv5.json +++ b/advisories/unreviewed/2022/05/GHSA-q376-xcm5-vgv5/GHSA-q376-xcm5-vgv5.json @@ -7,12 +7,8 @@ "CVE-2019-2203" ], "details": "In CryptoPlugin::decrypt of CryptoPlugin.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-137370777", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q44x-7gw2-jvgc/GHSA-q44x-7gw2-jvgc.json b/advisories/unreviewed/2022/05/GHSA-q44x-7gw2-jvgc/GHSA-q44x-7gw2-jvgc.json index 595be451af0..4b78e60d9f9 100644 --- a/advisories/unreviewed/2022/05/GHSA-q44x-7gw2-jvgc/GHSA-q44x-7gw2-jvgc.json +++ b/advisories/unreviewed/2022/05/GHSA-q44x-7gw2-jvgc/GHSA-q44x-7gw2-jvgc.json @@ -7,12 +7,8 @@ "CVE-2019-15348" ], "details": "The Tecno Camon Android device with a build fingerprint of TECNO/H612/TECNO-ID5a:8.1.0/O11019/F-180828V106:user/release-keys contains a pre-installed platform app with a package name of com.lovelyfont.defcontainer (versionCode=7, versionName=7.0.11). This app contains an exported service named com.lovelyfont.manager.FontCoverService that allows any app co-located on the device to supply arbitrary commands via shell script to be executed as the system user that are triggered by writing an attacker-selected message to the logcat log. This app cannot be disabled by the user and the attack can be performed by a zero-permission app. Executing commands as the system user can allow a third-party app to video record the user's screen, factory reset the device, obtain the user's notifications, read the logcat logs, inject events in the Graphical User Interface (GUI), and obtains the user's text messages, and more. Executing commands as the system user can allow a third-party app to factory reset the device, obtain the user's notifications, read the logcat logs, inject events in the GUI, change the default Input Method Editor (IME) (e.g., keyboard) with one contained within the attacking app that contains keylogging functionality, and obtains the user's text messages, and more.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q495-v294-p5fq/GHSA-q495-v294-p5fq.json b/advisories/unreviewed/2022/05/GHSA-q495-v294-p5fq/GHSA-q495-v294-p5fq.json index 40af557b086..a3b158dce0b 100644 --- a/advisories/unreviewed/2022/05/GHSA-q495-v294-p5fq/GHSA-q495-v294-p5fq.json +++ b/advisories/unreviewed/2022/05/GHSA-q495-v294-p5fq/GHSA-q495-v294-p5fq.json @@ -7,12 +7,8 @@ "CVE-2019-15463" ], "details": "The Samsung j7popeltemtr Android device with a build fingerprint of samsung/j7popeltemtr/j7popeltemtr:8.1.0/M1AJQ/J727T1UVS5BSC2:user/release-keys contains a pre-installed app with a package name of com.samsung.android.themecenter app (versionCode=7000100, versionName=7.0.1.0) that allows other pre-installed apps to perform app installation via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions that are required by other other pre-installed apps that exported their capabilities to other pre-installed app.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q62p-7qmj-cm9r/GHSA-q62p-7qmj-cm9r.json b/advisories/unreviewed/2022/05/GHSA-q62p-7qmj-cm9r/GHSA-q62p-7qmj-cm9r.json index 39938011ae7..c9cc77ff610 100644 --- a/advisories/unreviewed/2022/05/GHSA-q62p-7qmj-cm9r/GHSA-q62p-7qmj-cm9r.json +++ b/advisories/unreviewed/2022/05/GHSA-q62p-7qmj-cm9r/GHSA-q62p-7qmj-cm9r.json @@ -7,12 +7,8 @@ "CVE-2019-13557" ], "details": "In Tasy EMR, Tasy WebPortal Versions 3.02.1757 and prior, there is an information exposure vulnerability which may allow a remote attacker to access system and configuration information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q6vg-mgv4-jrch/GHSA-q6vg-mgv4-jrch.json b/advisories/unreviewed/2022/05/GHSA-q6vg-mgv4-jrch/GHSA-q6vg-mgv4-jrch.json index cd1b4a1b2d3..ac375331145 100644 --- a/advisories/unreviewed/2022/05/GHSA-q6vg-mgv4-jrch/GHSA-q6vg-mgv4-jrch.json +++ b/advisories/unreviewed/2022/05/GHSA-q6vg-mgv4-jrch/GHSA-q6vg-mgv4-jrch.json @@ -7,12 +7,8 @@ "CVE-2019-11182" ], "details": "Memory corruption in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable denial of service via network access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q849-p2cf-42j8/GHSA-q849-p2cf-42j8.json b/advisories/unreviewed/2022/05/GHSA-q849-p2cf-42j8/GHSA-q849-p2cf-42j8.json index a8b9c064ff9..e43e6a28411 100644 --- a/advisories/unreviewed/2022/05/GHSA-q849-p2cf-42j8/GHSA-q849-p2cf-42j8.json +++ b/advisories/unreviewed/2022/05/GHSA-q849-p2cf-42j8/GHSA-q849-p2cf-42j8.json @@ -7,12 +7,8 @@ "CVE-2019-16205" ], "details": "A vulnerability, in Brocade SANnav versions before v2.0, could allow remote attackers to brute-force a valid session ID. The vulnerability is due to an insufficiently random session ID for several post-authentication actions in the SANnav portal.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q89m-g397-f55p/GHSA-q89m-g397-f55p.json b/advisories/unreviewed/2022/05/GHSA-q89m-g397-f55p/GHSA-q89m-g397-f55p.json index 4a01c14bd35..392617454ca 100644 --- a/advisories/unreviewed/2022/05/GHSA-q89m-g397-f55p/GHSA-q89m-g397-f55p.json +++ b/advisories/unreviewed/2022/05/GHSA-q89m-g397-f55p/GHSA-q89m-g397-f55p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q8hf-p6h4-w2f9/GHSA-q8hf-p6h4-w2f9.json b/advisories/unreviewed/2022/05/GHSA-q8hf-p6h4-w2f9/GHSA-q8hf-p6h4-w2f9.json index 2d5db4201b6..e1ed99b518d 100644 --- a/advisories/unreviewed/2022/05/GHSA-q8hf-p6h4-w2f9/GHSA-q8hf-p6h4-w2f9.json +++ b/advisories/unreviewed/2022/05/GHSA-q8hf-p6h4-w2f9/GHSA-q8hf-p6h4-w2f9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q9p2-wx98-924v/GHSA-q9p2-wx98-924v.json b/advisories/unreviewed/2022/05/GHSA-q9p2-wx98-924v/GHSA-q9p2-wx98-924v.json index 3470e594172..1bd7140e3d9 100644 --- a/advisories/unreviewed/2022/05/GHSA-q9p2-wx98-924v/GHSA-q9p2-wx98-924v.json +++ b/advisories/unreviewed/2022/05/GHSA-q9p2-wx98-924v/GHSA-q9p2-wx98-924v.json @@ -7,12 +7,8 @@ "CVE-2019-18924" ], "details": "Systematic IRIS WebForms 5.4 is vulnerable to directory traversal. By manipulating variables that reference files with ../ (and variations), it is possible to list all the directories and check if a particular file exists.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q9vm-wp5f-xw8x/GHSA-q9vm-wp5f-xw8x.json b/advisories/unreviewed/2022/05/GHSA-q9vm-wp5f-xw8x/GHSA-q9vm-wp5f-xw8x.json index 02a58a0f4b0..0fb36fe0d58 100644 --- a/advisories/unreviewed/2022/05/GHSA-q9vm-wp5f-xw8x/GHSA-q9vm-wp5f-xw8x.json +++ b/advisories/unreviewed/2022/05/GHSA-q9vm-wp5f-xw8x/GHSA-q9vm-wp5f-xw8x.json @@ -7,12 +7,8 @@ "CVE-2019-2204" ], "details": "In FindSharedFunctionInfo of objects.cc, there is a possible out of bounds read due to a mistake in AST traversal. This could lead to remote code execution in the pacprocessor with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9Android ID: A-138442295", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qc6x-g3h2-596q/GHSA-qc6x-g3h2-596q.json b/advisories/unreviewed/2022/05/GHSA-qc6x-g3h2-596q/GHSA-qc6x-g3h2-596q.json index b1d796b7167..565df0903f3 100644 --- a/advisories/unreviewed/2022/05/GHSA-qc6x-g3h2-596q/GHSA-qc6x-g3h2-596q.json +++ b/advisories/unreviewed/2022/05/GHSA-qc6x-g3h2-596q/GHSA-qc6x-g3h2-596q.json @@ -7,12 +7,8 @@ "CVE-2006-2058" ], "details": "Argument injection vulnerability in Avant Browser 10.1 Build 17 allows user-assisted remote attackers to modify command line arguments to an invoked mail client via \" (double quote) characters in a mailto: scheme handler, as demonstrated by launching Microsoft Outlook with an arbitrary filename as an attachment. NOTE: it is not clear whether this issue is implementation-specific or a problem in the Microsoft API.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qcwg-qcmw-7525/GHSA-qcwg-qcmw-7525.json b/advisories/unreviewed/2022/05/GHSA-qcwg-qcmw-7525/GHSA-qcwg-qcmw-7525.json index 57d0d318500..e80d5b26bfd 100644 --- a/advisories/unreviewed/2022/05/GHSA-qcwg-qcmw-7525/GHSA-qcwg-qcmw-7525.json +++ b/advisories/unreviewed/2022/05/GHSA-qcwg-qcmw-7525/GHSA-qcwg-qcmw-7525.json @@ -7,12 +7,8 @@ "CVE-2006-3352" ], "details": "** DISPUTED ** Cross-domain vulnerability in Mozilla Firefox allows remote attackers to access restricted information from other domains via an object tag with a data parameter that references a link on the attacker's originating site that specifies a Location HTTP header that references the target site, which then makes that content available through the outerHTML attribute of the object. NOTE: this description was based on a report that has since been retracted by the original authors. The authors misinterpreted their test results. Other third parties also disputed the original report. Therefore, this is not a vulnerability. It is being assigned a candidate number to provide a clear indication of its status.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qf8x-4p92-75q9/GHSA-qf8x-4p92-75q9.json b/advisories/unreviewed/2022/05/GHSA-qf8x-4p92-75q9/GHSA-qf8x-4p92-75q9.json index ee787639a3a..78e3097f643 100644 --- a/advisories/unreviewed/2022/05/GHSA-qf8x-4p92-75q9/GHSA-qf8x-4p92-75q9.json +++ b/advisories/unreviewed/2022/05/GHSA-qf8x-4p92-75q9/GHSA-qf8x-4p92-75q9.json @@ -7,12 +7,8 @@ "CVE-2019-5542" ], "details": "VMware Workstation (15.x before 15.5.1) and Fusion (11.x before 11.5.1) contain a denial-of-service vulnerability in the RPC handler. Successful exploitation of this issue may allow attackers with normal user privileges to create a denial-of-service condition on their own VM.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qfxj-w5h6-q54f/GHSA-qfxj-w5h6-q54f.json b/advisories/unreviewed/2022/05/GHSA-qfxj-w5h6-q54f/GHSA-qfxj-w5h6-q54f.json index fc472382eec..97537b57535 100644 --- a/advisories/unreviewed/2022/05/GHSA-qfxj-w5h6-q54f/GHSA-qfxj-w5h6-q54f.json +++ b/advisories/unreviewed/2022/05/GHSA-qfxj-w5h6-q54f/GHSA-qfxj-w5h6-q54f.json @@ -7,12 +7,8 @@ "CVE-2019-3641" ], "details": "Abuse of Authorization vulnerability in APIs exposed by TIE server in McAfee Threat Intelligence Exchange Server (TIE Server) 3.0.0 allows remote authenticated users to modify stored reputation data via specially crafted messages.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qfxp-65r3-gfv7/GHSA-qfxp-65r3-gfv7.json b/advisories/unreviewed/2022/05/GHSA-qfxp-65r3-gfv7/GHSA-qfxp-65r3-gfv7.json index 8151c16667f..f84cf7b55d0 100644 --- a/advisories/unreviewed/2022/05/GHSA-qfxp-65r3-gfv7/GHSA-qfxp-65r3-gfv7.json +++ b/advisories/unreviewed/2022/05/GHSA-qfxp-65r3-gfv7/GHSA-qfxp-65r3-gfv7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -143,9 +141,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qgr4-h86c-w3g3/GHSA-qgr4-h86c-w3g3.json b/advisories/unreviewed/2022/05/GHSA-qgr4-h86c-w3g3/GHSA-qgr4-h86c-w3g3.json index 8ba21833aeb..96d41c11278 100644 --- a/advisories/unreviewed/2022/05/GHSA-qgr4-h86c-w3g3/GHSA-qgr4-h86c-w3g3.json +++ b/advisories/unreviewed/2022/05/GHSA-qgr4-h86c-w3g3/GHSA-qgr4-h86c-w3g3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qh9h-9xrj-42pc/GHSA-qh9h-9xrj-42pc.json b/advisories/unreviewed/2022/05/GHSA-qh9h-9xrj-42pc/GHSA-qh9h-9xrj-42pc.json index 18e3abc45d3..4e16236fc8c 100644 --- a/advisories/unreviewed/2022/05/GHSA-qh9h-9xrj-42pc/GHSA-qh9h-9xrj-42pc.json +++ b/advisories/unreviewed/2022/05/GHSA-qh9h-9xrj-42pc/GHSA-qh9h-9xrj-42pc.json @@ -7,12 +7,8 @@ "CVE-2019-15445" ], "details": "The Samsung S7 Android device with a build fingerprint of samsung/heroltexx/herolte:8.0.0/R16NW/G930FXXS4ESC3:user/release-keys contains a pre-installed app with a package name of com.samsung.android.themecenter app (versionCode=7000000, versionName=7.0.0.0) that allows other pre-installed apps to perform app installation via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions that are required by other other pre-installed apps that exported their capabilities to other pre-installed app.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qjj4-qwxx-xv8f/GHSA-qjj4-qwxx-xv8f.json b/advisories/unreviewed/2022/05/GHSA-qjj4-qwxx-xv8f/GHSA-qjj4-qwxx-xv8f.json index 13599e5b18c..0b2c2ef30e6 100644 --- a/advisories/unreviewed/2022/05/GHSA-qjj4-qwxx-xv8f/GHSA-qjj4-qwxx-xv8f.json +++ b/advisories/unreviewed/2022/05/GHSA-qjj4-qwxx-xv8f/GHSA-qjj4-qwxx-xv8f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qmhp-32vc-r662/GHSA-qmhp-32vc-r662.json b/advisories/unreviewed/2022/05/GHSA-qmhp-32vc-r662/GHSA-qmhp-32vc-r662.json index de7201f3306..3f85bded221 100644 --- a/advisories/unreviewed/2022/05/GHSA-qmhp-32vc-r662/GHSA-qmhp-32vc-r662.json +++ b/advisories/unreviewed/2022/05/GHSA-qmhp-32vc-r662/GHSA-qmhp-32vc-r662.json @@ -7,12 +7,8 @@ "CVE-2005-4699" ], "details": "Argument injection vulnerability in TellMe 1.2 and earlier allows remote attackers to modify command line arguments for the Whois program and obtain sensitive information via \"--\" style options in the q_Host parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qv6x-p3wp-m6hw/GHSA-qv6x-p3wp-m6hw.json b/advisories/unreviewed/2022/05/GHSA-qv6x-p3wp-m6hw/GHSA-qv6x-p3wp-m6hw.json index 005141abbea..f67fbfa276c 100644 --- a/advisories/unreviewed/2022/05/GHSA-qv6x-p3wp-m6hw/GHSA-qv6x-p3wp-m6hw.json +++ b/advisories/unreviewed/2022/05/GHSA-qv6x-p3wp-m6hw/GHSA-qv6x-p3wp-m6hw.json @@ -7,12 +7,8 @@ "CVE-2019-2198" ], "details": "In Download Provider, there is a possible SQL injection vulnerability. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-135270103", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qvf6-4fcc-xh3j/GHSA-qvf6-4fcc-xh3j.json b/advisories/unreviewed/2022/05/GHSA-qvf6-4fcc-xh3j/GHSA-qvf6-4fcc-xh3j.json index 84a844e2c0f..5d8542e9b52 100644 --- a/advisories/unreviewed/2022/05/GHSA-qvf6-4fcc-xh3j/GHSA-qvf6-4fcc-xh3j.json +++ b/advisories/unreviewed/2022/05/GHSA-qvf6-4fcc-xh3j/GHSA-qvf6-4fcc-xh3j.json @@ -7,12 +7,8 @@ "CVE-2015-9526" ], "details": "The Easy Digital Downloads (EDD) Reviews extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qwjm-gcr8-gjhw/GHSA-qwjm-gcr8-gjhw.json b/advisories/unreviewed/2022/05/GHSA-qwjm-gcr8-gjhw/GHSA-qwjm-gcr8-gjhw.json index 7e2fd6cd6e4..fe644535b9e 100644 --- a/advisories/unreviewed/2022/05/GHSA-qwjm-gcr8-gjhw/GHSA-qwjm-gcr8-gjhw.json +++ b/advisories/unreviewed/2022/05/GHSA-qwjm-gcr8-gjhw/GHSA-qwjm-gcr8-gjhw.json @@ -7,12 +7,8 @@ "CVE-2019-18951" ], "details": "SibSoft Xfilesharing through 2.5.1 allows op=page&tmpl=../ directory traversal to read arbitrary files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qwm5-ffpm-74f6/GHSA-qwm5-ffpm-74f6.json b/advisories/unreviewed/2022/05/GHSA-qwm5-ffpm-74f6/GHSA-qwm5-ffpm-74f6.json index ad2f707fb42..a6c196ce296 100644 --- a/advisories/unreviewed/2022/05/GHSA-qwm5-ffpm-74f6/GHSA-qwm5-ffpm-74f6.json +++ b/advisories/unreviewed/2022/05/GHSA-qwm5-ffpm-74f6/GHSA-qwm5-ffpm-74f6.json @@ -7,12 +7,8 @@ "CVE-2015-9529" ], "details": "The Easy Digital Downloads (EDD) Stripe extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r2h3-mjxh-65r2/GHSA-r2h3-mjxh-65r2.json b/advisories/unreviewed/2022/05/GHSA-r2h3-mjxh-65r2/GHSA-r2h3-mjxh-65r2.json index 346c6f18379..3813be72c94 100644 --- a/advisories/unreviewed/2022/05/GHSA-r2h3-mjxh-65r2/GHSA-r2h3-mjxh-65r2.json +++ b/advisories/unreviewed/2022/05/GHSA-r2h3-mjxh-65r2/GHSA-r2h3-mjxh-65r2.json @@ -7,12 +7,8 @@ "CVE-2019-1425" ], "details": "An elevation of privilege vulnerability exists when Visual Studio fails to properly validate hardlinks while extracting archived files, aka 'Visual Studio Elevation of Privilege Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r3h4-x886-29mc/GHSA-r3h4-x886-29mc.json b/advisories/unreviewed/2022/05/GHSA-r3h4-x886-29mc/GHSA-r3h4-x886-29mc.json index d43ce590615..9b5eb2fad99 100644 --- a/advisories/unreviewed/2022/05/GHSA-r3h4-x886-29mc/GHSA-r3h4-x886-29mc.json +++ b/advisories/unreviewed/2022/05/GHSA-r3h4-x886-29mc/GHSA-r3h4-x886-29mc.json @@ -7,12 +7,8 @@ "CVE-2019-8225" ], "details": "Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r476-wgfv-fmg6/GHSA-r476-wgfv-fmg6.json b/advisories/unreviewed/2022/05/GHSA-r476-wgfv-fmg6/GHSA-r476-wgfv-fmg6.json index b6a329b508c..0d333f604b8 100644 --- a/advisories/unreviewed/2022/05/GHSA-r476-wgfv-fmg6/GHSA-r476-wgfv-fmg6.json +++ b/advisories/unreviewed/2022/05/GHSA-r476-wgfv-fmg6/GHSA-r476-wgfv-fmg6.json @@ -7,12 +7,8 @@ "CVE-2019-8223" ], "details": "Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r5m6-7466-vjgj/GHSA-r5m6-7466-vjgj.json b/advisories/unreviewed/2022/05/GHSA-r5m6-7466-vjgj/GHSA-r5m6-7466-vjgj.json index 29309d986c1..a1d3a876ed7 100644 --- a/advisories/unreviewed/2022/05/GHSA-r5m6-7466-vjgj/GHSA-r5m6-7466-vjgj.json +++ b/advisories/unreviewed/2022/05/GHSA-r5m6-7466-vjgj/GHSA-r5m6-7466-vjgj.json @@ -7,12 +7,8 @@ "CVE-2019-15355" ], "details": "The Tecno Camon iClick Android device with a build fingerprint of TECNO/H633/TECNO-IN6:8.1.0/O11019/A-180409V96:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r5rh-4cpr-qxhj/GHSA-r5rh-4cpr-qxhj.json b/advisories/unreviewed/2022/05/GHSA-r5rh-4cpr-qxhj/GHSA-r5rh-4cpr-qxhj.json index 0b219a0d534..69e8aafc2c1 100644 --- a/advisories/unreviewed/2022/05/GHSA-r5rh-4cpr-qxhj/GHSA-r5rh-4cpr-qxhj.json +++ b/advisories/unreviewed/2022/05/GHSA-r5rh-4cpr-qxhj/GHSA-r5rh-4cpr-qxhj.json @@ -7,12 +7,8 @@ "CVE-2019-13555" ], "details": "In Mitsubishi Electric MELSEC-Q Series Q03/04/06/13/26UDVCPU: serial number 21081 and prior, Q04/06/13/26UDPVCPU: serial number 21081 and prior, and Q03UDECPU, Q04/06/10/13/20/26/50/100UDEHCPU: serial number 21081 and prior, MELSEC-L Series L02/06/26CPU, L26CPU-BT: serial number 21101 and prior, L02/06/26CPU-P, L26CPU-PBT: serial number 21101 and prior, and L02/06/26CPU-CM, L26CPU-BT-CM: serial number 21101 and prior, a remote attacker can cause the FTP service to enter a denial-of-service condition dependent on the timing at which a remote attacker connects to the FTP server on the above CPU modules.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r76g-8cjw-fqwr/GHSA-r76g-8cjw-fqwr.json b/advisories/unreviewed/2022/05/GHSA-r76g-8cjw-fqwr/GHSA-r76g-8cjw-fqwr.json index d3caae70c48..4a7727473ae 100644 --- a/advisories/unreviewed/2022/05/GHSA-r76g-8cjw-fqwr/GHSA-r76g-8cjw-fqwr.json +++ b/advisories/unreviewed/2022/05/GHSA-r76g-8cjw-fqwr/GHSA-r76g-8cjw-fqwr.json @@ -7,12 +7,8 @@ "CVE-2019-5213" ], "details": "Honor play smartphones with versions earlier than Cornell-AL00A 9.1.0.321(C00E320R1P1T8) have an insufficient authentication vulnerability. The system has a logic judge error under certain scenario. Successful exploit could allow the attacker to modify the alarm clock settings after a serious of uncommon operations without unlock the screen lock.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r862-p7gw-4jfm/GHSA-r862-p7gw-4jfm.json b/advisories/unreviewed/2022/05/GHSA-r862-p7gw-4jfm/GHSA-r862-p7gw-4jfm.json index 351e9f558c2..4fe610b96a7 100644 --- a/advisories/unreviewed/2022/05/GHSA-r862-p7gw-4jfm/GHSA-r862-p7gw-4jfm.json +++ b/advisories/unreviewed/2022/05/GHSA-r862-p7gw-4jfm/GHSA-r862-p7gw-4jfm.json @@ -7,12 +7,8 @@ "CVE-2005-4681" ], "details": "** DISPUTED ** Buffer overflow in mIRC 5.91, 6.03, 6.12, and 6.16 allows local users to execute arbitrary code via a long string that is entered after reaching the DCC Get Folder Dialog. NOTE: this issue has been disputed by the vendor, saying \"as far as I can tell, this is neither an exploit nor a vulnerability. The above report describes a local bug in mIRC.\" It could be that this is only exploitable by the user of the application, and thus would not cross privilege boundaries unless under an otherwise restrictive environment such as a kiosk.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r8qm-3wgq-vf9w/GHSA-r8qm-3wgq-vf9w.json b/advisories/unreviewed/2022/05/GHSA-r8qm-3wgq-vf9w/GHSA-r8qm-3wgq-vf9w.json index b259fa1b2d6..20fcda97d4c 100644 --- a/advisories/unreviewed/2022/05/GHSA-r8qm-3wgq-vf9w/GHSA-r8qm-3wgq-vf9w.json +++ b/advisories/unreviewed/2022/05/GHSA-r8qm-3wgq-vf9w/GHSA-r8qm-3wgq-vf9w.json @@ -7,12 +7,8 @@ "CVE-2019-18816" ], "details": "po-admin/route.php?mod=post&act=edit in PopojiCMS 2.0.1 allows post[1][content]= stored XSS.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r92v-6289-qqvf/GHSA-r92v-6289-qqvf.json b/advisories/unreviewed/2022/05/GHSA-r92v-6289-qqvf/GHSA-r92v-6289-qqvf.json index 93becab5682..ec748797c69 100644 --- a/advisories/unreviewed/2022/05/GHSA-r92v-6289-qqvf/GHSA-r92v-6289-qqvf.json +++ b/advisories/unreviewed/2022/05/GHSA-r92v-6289-qqvf/GHSA-r92v-6289-qqvf.json @@ -7,12 +7,8 @@ "CVE-2019-0146" ], "details": "Resource leak in i40e driver for Intel(R) Ethernet 700 Series Controllers versions before 2.8.43 may allow an authenticated user to potentially enable a denial of service via local access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r947-xpmq-5gjg/GHSA-r947-xpmq-5gjg.json b/advisories/unreviewed/2022/05/GHSA-r947-xpmq-5gjg/GHSA-r947-xpmq-5gjg.json index 798e4bb4e1f..51f91ee343e 100644 --- a/advisories/unreviewed/2022/05/GHSA-r947-xpmq-5gjg/GHSA-r947-xpmq-5gjg.json +++ b/advisories/unreviewed/2022/05/GHSA-r947-xpmq-5gjg/GHSA-r947-xpmq-5gjg.json @@ -7,12 +7,8 @@ "CVE-2019-8236" ], "details": "Creative Cloud Desktop Application version 4.6.1 and earlier versions have Security Bypass vulnerability. Successful exploitation could lead to Privilege Escalation in the context of the current user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rfmx-33qg-6pj7/GHSA-rfmx-33qg-6pj7.json b/advisories/unreviewed/2022/05/GHSA-rfmx-33qg-6pj7/GHSA-rfmx-33qg-6pj7.json index 7f30c15ccca..7a39f9cc36d 100644 --- a/advisories/unreviewed/2022/05/GHSA-rfmx-33qg-6pj7/GHSA-rfmx-33qg-6pj7.json +++ b/advisories/unreviewed/2022/05/GHSA-rfmx-33qg-6pj7/GHSA-rfmx-33qg-6pj7.json @@ -7,12 +7,8 @@ "CVE-2019-0149" ], "details": "Insufficient input validation in i40e driver for Intel(R) Ethernet 700 Series Controllers versions before 2.8.43 may allow an authenticated user to potentially enable a denial of service via local access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rhq2-6v39-r537/GHSA-rhq2-6v39-r537.json b/advisories/unreviewed/2022/05/GHSA-rhq2-6v39-r537/GHSA-rhq2-6v39-r537.json index 588dbd8778f..245e5dead71 100644 --- a/advisories/unreviewed/2022/05/GHSA-rhq2-6v39-r537/GHSA-rhq2-6v39-r537.json +++ b/advisories/unreviewed/2022/05/GHSA-rhq2-6v39-r537/GHSA-rhq2-6v39-r537.json @@ -7,12 +7,8 @@ "CVE-2015-9534" ], "details": "The Easy Digital Downloads (EDD) Quota theme for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rj2w-xmq6-8qvv/GHSA-rj2w-xmq6-8qvv.json b/advisories/unreviewed/2022/05/GHSA-rj2w-xmq6-8qvv/GHSA-rj2w-xmq6-8qvv.json index 98a8bb2e9dc..7de034a780a 100644 --- a/advisories/unreviewed/2022/05/GHSA-rj2w-xmq6-8qvv/GHSA-rj2w-xmq6-8qvv.json +++ b/advisories/unreviewed/2022/05/GHSA-rj2w-xmq6-8qvv/GHSA-rj2w-xmq6-8qvv.json @@ -7,12 +7,8 @@ "CVE-2019-15373" ], "details": "The Symphony i95 Lite Android device with a build fingerprint of LAVA/iris88_lite/iris88_lite:8.1.0/O11019/1536323070:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rv55-37hq-r98j/GHSA-rv55-37hq-r98j.json b/advisories/unreviewed/2022/05/GHSA-rv55-37hq-r98j/GHSA-rv55-37hq-r98j.json index 6b879bfef89..98bd5d09dfd 100644 --- a/advisories/unreviewed/2022/05/GHSA-rv55-37hq-r98j/GHSA-rv55-37hq-r98j.json +++ b/advisories/unreviewed/2022/05/GHSA-rv55-37hq-r98j/GHSA-rv55-37hq-r98j.json @@ -7,12 +7,8 @@ "CVE-2019-6122" ], "details": "A Username Enumeration via Error Message issue was discovered in NiceHash Miner before 2.0.3.0 because an \"EMAIL DOES NOT EXIST\" error message occurs whenever a submitted email address is incorrect, but there is a different error message for invalid credentials with a correct email address.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rvg7-hqxx-gj93/GHSA-rvg7-hqxx-gj93.json b/advisories/unreviewed/2022/05/GHSA-rvg7-hqxx-gj93/GHSA-rvg7-hqxx-gj93.json index eaacb9740f5..34b3fb04aaa 100644 --- a/advisories/unreviewed/2022/05/GHSA-rvg7-hqxx-gj93/GHSA-rvg7-hqxx-gj93.json +++ b/advisories/unreviewed/2022/05/GHSA-rvg7-hqxx-gj93/GHSA-rvg7-hqxx-gj93.json @@ -7,12 +7,8 @@ "CVE-2019-4461" ], "details": "IBM Cloud Orchestrator 2.4 through 2.4.0.5 and 2.5 through 2.5.0.9 is vulnerable to HTTP Response Splitting caused by improper caching of content. This would allow the attacker to perform further attacks, such as Web Cache poisoning, cross-site scripting and possibly obtain sensitive information. IBM X-Force ID: 163682.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rwg7-vwhm-3x8j/GHSA-rwg7-vwhm-3x8j.json b/advisories/unreviewed/2022/05/GHSA-rwg7-vwhm-3x8j/GHSA-rwg7-vwhm-3x8j.json index 18572fcb270..fd1237a38a0 100644 --- a/advisories/unreviewed/2022/05/GHSA-rwg7-vwhm-3x8j/GHSA-rwg7-vwhm-3x8j.json +++ b/advisories/unreviewed/2022/05/GHSA-rwg7-vwhm-3x8j/GHSA-rwg7-vwhm-3x8j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rwqx-wj4g-4cgq/GHSA-rwqx-wj4g-4cgq.json b/advisories/unreviewed/2022/05/GHSA-rwqx-wj4g-4cgq/GHSA-rwqx-wj4g-4cgq.json index df241db8f7b..78940e24fc9 100644 --- a/advisories/unreviewed/2022/05/GHSA-rwqx-wj4g-4cgq/GHSA-rwqx-wj4g-4cgq.json +++ b/advisories/unreviewed/2022/05/GHSA-rwqx-wj4g-4cgq/GHSA-rwqx-wj4g-4cgq.json @@ -7,12 +7,8 @@ "CVE-2019-17550" ], "details": "The Blog2Social plugin before 5.9.0 for WordPress is affected by: Cross Site Scripting (XSS). The impact is: Allows an attacker to execute arbitrary HTML and JavaScript code via the b2s_id parameter. The component is: views/b2s/post.calendar.php. The attack vector is: When the Administrator is logged in, a reflected XSS may execute upon a click on a malicious URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rx33-ppch-97cg/GHSA-rx33-ppch-97cg.json b/advisories/unreviewed/2022/05/GHSA-rx33-ppch-97cg/GHSA-rx33-ppch-97cg.json index 51ece8c786c..1d44f193429 100644 --- a/advisories/unreviewed/2022/05/GHSA-rx33-ppch-97cg/GHSA-rx33-ppch-97cg.json +++ b/advisories/unreviewed/2022/05/GHSA-rx33-ppch-97cg/GHSA-rx33-ppch-97cg.json @@ -7,12 +7,8 @@ "CVE-2006-5095" ], "details": "** DISPUTED ** PHP remote file inclusion vulnerability in index.php in MyPhotos 0.1.3b beta allows remote attackers to execute arbitrary PHP code via the includesdir parameter. NOTE: this issue is disputed by CVE on 20060927, since the includesdir is defined before being used when the product is installed according to the provided instructions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v23f-mgg7-wchc/GHSA-v23f-mgg7-wchc.json b/advisories/unreviewed/2022/05/GHSA-v23f-mgg7-wchc/GHSA-v23f-mgg7-wchc.json index 1d79f872728..28e96404611 100644 --- a/advisories/unreviewed/2022/05/GHSA-v23f-mgg7-wchc/GHSA-v23f-mgg7-wchc.json +++ b/advisories/unreviewed/2022/05/GHSA-v23f-mgg7-wchc/GHSA-v23f-mgg7-wchc.json @@ -7,12 +7,8 @@ "CVE-2019-0150" ], "details": "Insufficient access control in firmware Intel(R) Ethernet 700 Series Controllers versions before 7.0 may allow a privileged user to potentially enable a denial of service via local access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v2g5-f6wr-gmx5/GHSA-v2g5-f6wr-gmx5.json b/advisories/unreviewed/2022/05/GHSA-v2g5-f6wr-gmx5/GHSA-v2g5-f6wr-gmx5.json index 753a939ed0f..323e0c2ad52 100644 --- a/advisories/unreviewed/2022/05/GHSA-v2g5-f6wr-gmx5/GHSA-v2g5-f6wr-gmx5.json +++ b/advisories/unreviewed/2022/05/GHSA-v2g5-f6wr-gmx5/GHSA-v2g5-f6wr-gmx5.json @@ -7,12 +7,8 @@ "CVE-2019-8217" ], "details": "Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v2h3-gjcc-2xpg/GHSA-v2h3-gjcc-2xpg.json b/advisories/unreviewed/2022/05/GHSA-v2h3-gjcc-2xpg/GHSA-v2h3-gjcc-2xpg.json index 17e6a84a90d..4474cc5a619 100644 --- a/advisories/unreviewed/2022/05/GHSA-v2h3-gjcc-2xpg/GHSA-v2h3-gjcc-2xpg.json +++ b/advisories/unreviewed/2022/05/GHSA-v2h3-gjcc-2xpg/GHSA-v2h3-gjcc-2xpg.json @@ -7,12 +7,8 @@ "CVE-2019-15404" ], "details": "The Asus ZenFone Max 4 Android device with a build fingerprint of asus/WW_Phone/ASUS_X00HD_4:7.1.1/NMF26F/14.2016.1712.367-20171225:user/release-keys contains a pre-installed app with a package name of com.asus.loguploaderproxy app (versionCode=1570000020, versionName=7.0.0.4_170901) that allows other pre-installed apps to perform command execution via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions that are required by other other pre-installed apps that exported their capabilities to other pre-installed app.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v32r-ffrj-5hp3/GHSA-v32r-ffrj-5hp3.json b/advisories/unreviewed/2022/05/GHSA-v32r-ffrj-5hp3/GHSA-v32r-ffrj-5hp3.json index 68a8e2ff71a..c99624e3ef1 100644 --- a/advisories/unreviewed/2022/05/GHSA-v32r-ffrj-5hp3/GHSA-v32r-ffrj-5hp3.json +++ b/advisories/unreviewed/2022/05/GHSA-v32r-ffrj-5hp3/GHSA-v32r-ffrj-5hp3.json @@ -7,12 +7,8 @@ "CVE-2019-15353" ], "details": "The Coolpad N3C Android device with a build fingerprint of Coolpad/N3C/N3C:8.1.0/O11019/1538236809:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v3mf-9hcw-5vgh/GHSA-v3mf-9hcw-5vgh.json b/advisories/unreviewed/2022/05/GHSA-v3mf-9hcw-5vgh/GHSA-v3mf-9hcw-5vgh.json index 6928e98c948..ccd02265eff 100644 --- a/advisories/unreviewed/2022/05/GHSA-v3mf-9hcw-5vgh/GHSA-v3mf-9hcw-5vgh.json +++ b/advisories/unreviewed/2022/05/GHSA-v3mf-9hcw-5vgh/GHSA-v3mf-9hcw-5vgh.json @@ -7,12 +7,8 @@ "CVE-2019-10715" ], "details": "There is Stored XSS in Verodin Director 3.5.3.0 and earlier via input fields of certain tooltips, and on the Tags, Sequences, and Actors pages.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v5gx-pr63-p5w2/GHSA-v5gx-pr63-p5w2.json b/advisories/unreviewed/2022/05/GHSA-v5gx-pr63-p5w2/GHSA-v5gx-pr63-p5w2.json index 00b1491e765..6c2ddec9470 100644 --- a/advisories/unreviewed/2022/05/GHSA-v5gx-pr63-p5w2/GHSA-v5gx-pr63-p5w2.json +++ b/advisories/unreviewed/2022/05/GHSA-v5gx-pr63-p5w2/GHSA-v5gx-pr63-p5w2.json @@ -7,12 +7,8 @@ "CVE-2019-15475" ], "details": "The Xiaomi Mi A3 Android device with a build fingerprint of xiaomi/onc_eea/onc:9/PKQ1.181021.001/V10.2.8.0.PFLEUXM:user/release-keys contains a pre-installed app with a package name of com.qualcomm.qti.callenhancement app (versionCode=28, versionName=9) that allows unauthorized microphone audio recording via a confused deputy attack. This capability can be accessed by any app co-located on the device. This app allows a third-party app to use its open interface to record telephone calls to external storage.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v5v2-65jc-4g4f/GHSA-v5v2-65jc-4g4f.json b/advisories/unreviewed/2022/05/GHSA-v5v2-65jc-4g4f/GHSA-v5v2-65jc-4g4f.json index 98e54b9d614..06fbb2e5df9 100644 --- a/advisories/unreviewed/2022/05/GHSA-v5v2-65jc-4g4f/GHSA-v5v2-65jc-4g4f.json +++ b/advisories/unreviewed/2022/05/GHSA-v5v2-65jc-4g4f/GHSA-v5v2-65jc-4g4f.json @@ -7,12 +7,8 @@ "CVE-2019-15815" ], "details": "ZyXEL P-1302-T10D v3 devices with firmware version 2.00(ABBX.3) and earlier do not properly enforce access control and could allow an unauthorized user to access certain pages that require admin privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v6qv-7wrm-286w/GHSA-v6qv-7wrm-286w.json b/advisories/unreviewed/2022/05/GHSA-v6qv-7wrm-286w/GHSA-v6qv-7wrm-286w.json index 40053807d9c..7cb20d6a6be 100644 --- a/advisories/unreviewed/2022/05/GHSA-v6qv-7wrm-286w/GHSA-v6qv-7wrm-286w.json +++ b/advisories/unreviewed/2022/05/GHSA-v6qv-7wrm-286w/GHSA-v6qv-7wrm-286w.json @@ -7,12 +7,8 @@ "CVE-2019-18240" ], "details": "In Fuji Electric V-Server 4.0.6 and prior, several heap-based buffer overflows have been identified, which may allow an attacker to remotely execute arbitrary code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v6xq-x5f7-qxjq/GHSA-v6xq-x5f7-qxjq.json b/advisories/unreviewed/2022/05/GHSA-v6xq-x5f7-qxjq/GHSA-v6xq-x5f7-qxjq.json index f8022c0d2cf..1019ef0a66a 100644 --- a/advisories/unreviewed/2022/05/GHSA-v6xq-x5f7-qxjq/GHSA-v6xq-x5f7-qxjq.json +++ b/advisories/unreviewed/2022/05/GHSA-v6xq-x5f7-qxjq/GHSA-v6xq-x5f7-qxjq.json @@ -7,12 +7,8 @@ "CVE-2019-15388" ], "details": "The Coolpad 1851 Android device with a build fingerprint of Coolpad/android/android:8.1.0/O11019/1534834761:userdebug/release-keys contains a pre-installed platform app with a package name of com.lovelyfont.defcontainer (versionCode=7, versionName=7.1.13). This app contains an exported service named com.lovelyfont.manager.FontCoverService that allows any app co-located on the device to supply arbitrary commands to be executed as the system user. This app cannot be disabled by the user and the attack can be performed by a zero-permission app. In addition to the local attack surface, its accompanying app with a package name of com.ekesoo.lovelyhifonts makes network requests using HTTP and an attacker can perform a Man-in-the-Middle (MITM) attack on the connection to inject a command in a network response that will be executed as the system user by the com.lovelyfont.defcontainer app. Executing commands as the system user can allow a third-party app to video record the user's screen, factory reset the device, obtain the user's notifications, read the logcat logs, inject events in the Graphical User Interface (GUI), and obtains the user's text messages, and more. Executing commands as the system user can allow a third-party app to factory reset the device, obtain the user's notifications, read the logcat logs, inject events in the GUI, change the default Input Method Editor (IME) (e.g., keyboard) with one contained within the attacking app that contains keylogging functionality, and obtains the user's text messages, and more.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v948-gw9m-4v6p/GHSA-v948-gw9m-4v6p.json b/advisories/unreviewed/2022/05/GHSA-v948-gw9m-4v6p/GHSA-v948-gw9m-4v6p.json index f2530865350..ad4dc9e77c8 100644 --- a/advisories/unreviewed/2022/05/GHSA-v948-gw9m-4v6p/GHSA-v948-gw9m-4v6p.json +++ b/advisories/unreviewed/2022/05/GHSA-v948-gw9m-4v6p/GHSA-v948-gw9m-4v6p.json @@ -7,12 +7,8 @@ "CVE-2019-15474" ], "details": "The Xiaomi Cepheus Android device with a build fingerprint of Xiaomi/cepheus/cepheus:9/PKQ1.181121.001/V10.2.6.0.PFAMIXM:user/release-keys contains a pre-installed app with a package name of com.qualcomm.qti.callenhancement app (versionCode=28, versionName=9) that allows unauthorized microphone audio recording via a confused deputy attack. This capability can be accessed by any app co-located on the device. This app allows a third-party app to use its open interface to record telephone calls to external storage.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vfj7-xg8w-82vp/GHSA-vfj7-xg8w-82vp.json b/advisories/unreviewed/2022/05/GHSA-vfj7-xg8w-82vp/GHSA-vfj7-xg8w-82vp.json index 47318618eb2..d635cb3ad9e 100644 --- a/advisories/unreviewed/2022/05/GHSA-vfj7-xg8w-82vp/GHSA-vfj7-xg8w-82vp.json +++ b/advisories/unreviewed/2022/05/GHSA-vfj7-xg8w-82vp/GHSA-vfj7-xg8w-82vp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vhvr-vv9x-qw7q/GHSA-vhvr-vv9x-qw7q.json b/advisories/unreviewed/2022/05/GHSA-vhvr-vv9x-qw7q/GHSA-vhvr-vv9x-qw7q.json index 5441b288148..abb8b1e6271 100644 --- a/advisories/unreviewed/2022/05/GHSA-vhvr-vv9x-qw7q/GHSA-vhvr-vv9x-qw7q.json +++ b/advisories/unreviewed/2022/05/GHSA-vhvr-vv9x-qw7q/GHSA-vhvr-vv9x-qw7q.json @@ -7,12 +7,8 @@ "CVE-2019-6852" ], "details": "A CWE-200: Information Exposure vulnerability exists in Modicon Controllers (M340 CPUs, M340 communication modules, Premium CPUs, Premium communication modules, Quantum CPUs, Quantum communication modules - see security notification for specific versions), which could cause the disclosure of FTP hardcoded credentials when using the Web server of the controller on an unsecure network.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vq4h-pfrp-qjjj/GHSA-vq4h-pfrp-qjjj.json b/advisories/unreviewed/2022/05/GHSA-vq4h-pfrp-qjjj/GHSA-vq4h-pfrp-qjjj.json index 9cd9c59cc77..bf72ef066db 100644 --- a/advisories/unreviewed/2022/05/GHSA-vq4h-pfrp-qjjj/GHSA-vq4h-pfrp-qjjj.json +++ b/advisories/unreviewed/2022/05/GHSA-vq4h-pfrp-qjjj/GHSA-vq4h-pfrp-qjjj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vq54-fg57-v983/GHSA-vq54-fg57-v983.json b/advisories/unreviewed/2022/05/GHSA-vq54-fg57-v983/GHSA-vq54-fg57-v983.json index 1b48d34366d..5890e6963e7 100644 --- a/advisories/unreviewed/2022/05/GHSA-vq54-fg57-v983/GHSA-vq54-fg57-v983.json +++ b/advisories/unreviewed/2022/05/GHSA-vq54-fg57-v983/GHSA-vq54-fg57-v983.json @@ -7,12 +7,8 @@ "CVE-2019-15343" ], "details": "The Tecno Camon iClick Android device with a build fingerprint of TECNO/H633/TECNO-IN6:8.1.0/O11019/A-180409V96:user/release-keys contains a pre-installed platform app with a package name of com.lovelyfont.defcontainer (versionCode=7, versionName=7.0.8). This app contains an exported service named com.lovelyfont.manager.FontCoverService that allows any app co-located on the device to supply arbitrary commands via shell script to be executed as the system user that are triggered by writing an attacker-selected message to the logcat log. This app cannot be disabled by the user and the attack can be performed by a zero-permission app. Executing commands as the system user can allow a third-party app to video record the user's screen, factory reset the device, obtain the user's notifications, read the logcat logs, inject events in the Graphical User Interface (GUI), and obtains the user's text messages, and more. Executing commands as the system user can allow a third-party app to factory reset the device, obtain the user's notifications, read the logcat logs, inject events in the GUI, change the default Input Method Editor (IME) (e.g., keyboard) with one contained within the attacking app that contains keylogging functionality, and obtains the user's text messages, and more.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vvhx-5mc8-v8jv/GHSA-vvhx-5mc8-v8jv.json b/advisories/unreviewed/2022/05/GHSA-vvhx-5mc8-v8jv/GHSA-vvhx-5mc8-v8jv.json index 616edeffb95..7d5453024f5 100644 --- a/advisories/unreviewed/2022/05/GHSA-vvhx-5mc8-v8jv/GHSA-vvhx-5mc8-v8jv.json +++ b/advisories/unreviewed/2022/05/GHSA-vvhx-5mc8-v8jv/GHSA-vvhx-5mc8-v8jv.json @@ -7,12 +7,8 @@ "CVE-2019-2271" ], "details": "Buffer over read can happen while parsing downlink session management OTA messages if network sends un-intended values in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, MDM9150, MDM9205, MDM9206, MDM9607, MDM9615, MDM9625, MDM9635M, MDM9640, MDM9650, MDM9655, MSM8905, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8939, MSM8940, MSM8953, MSM8976, MSM8996AU, MSM8998, Nicobar, QCM2150, QCS605, QM215, SC8180X, SDA660, SDA845, SDM429, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX20, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, Snapdragon_High_Med_2016, SXR1130, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w238-gwcm-c55r/GHSA-w238-gwcm-c55r.json b/advisories/unreviewed/2022/05/GHSA-w238-gwcm-c55r/GHSA-w238-gwcm-c55r.json index 7ca3fd33ddd..f3d70cce8ac 100644 --- a/advisories/unreviewed/2022/05/GHSA-w238-gwcm-c55r/GHSA-w238-gwcm-c55r.json +++ b/advisories/unreviewed/2022/05/GHSA-w238-gwcm-c55r/GHSA-w238-gwcm-c55r.json @@ -7,12 +7,8 @@ "CVE-2019-15679" ], "details": "TightVNC code version 1.3.10 contains heap buffer overflow in InitialiseRFBConnection function, which can potentially result code execution. This attack appear to be exploitable via network connectivity.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w29p-9vcq-96vr/GHSA-w29p-9vcq-96vr.json b/advisories/unreviewed/2022/05/GHSA-w29p-9vcq-96vr/GHSA-w29p-9vcq-96vr.json index 2492f2138a8..179eb0ffaa3 100644 --- a/advisories/unreviewed/2022/05/GHSA-w29p-9vcq-96vr/GHSA-w29p-9vcq-96vr.json +++ b/advisories/unreviewed/2022/05/GHSA-w29p-9vcq-96vr/GHSA-w29p-9vcq-96vr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w4w3-5rjf-gvqh/GHSA-w4w3-5rjf-gvqh.json b/advisories/unreviewed/2022/05/GHSA-w4w3-5rjf-gvqh/GHSA-w4w3-5rjf-gvqh.json index 6f29a43b288..7d0da2acb34 100644 --- a/advisories/unreviewed/2022/05/GHSA-w4w3-5rjf-gvqh/GHSA-w4w3-5rjf-gvqh.json +++ b/advisories/unreviewed/2022/05/GHSA-w4w3-5rjf-gvqh/GHSA-w4w3-5rjf-gvqh.json @@ -7,12 +7,8 @@ "CVE-2006-2056" ], "details": "Argument injection vulnerability in Internet Explorer 6 for Windows XP SP2 allows user-assisted remote attackers to modify command line arguments to an invoked mail client via \" (double quote) characters in a mailto: scheme handler, as demonstrated by launching Microsoft Outlook with an arbitrary filename as an attachment. NOTE: it is not clear whether this issue is implementation-specific or a problem in the Microsoft API.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w63v-6pxv-h6xp/GHSA-w63v-6pxv-h6xp.json b/advisories/unreviewed/2022/05/GHSA-w63v-6pxv-h6xp/GHSA-w63v-6pxv-h6xp.json index d090cc44de8..40fdaba1588 100644 --- a/advisories/unreviewed/2022/05/GHSA-w63v-6pxv-h6xp/GHSA-w63v-6pxv-h6xp.json +++ b/advisories/unreviewed/2022/05/GHSA-w63v-6pxv-h6xp/GHSA-w63v-6pxv-h6xp.json @@ -7,12 +7,8 @@ "CVE-2015-9533" ], "details": "The Easy Digital Downloads (EDD) Lattice theme for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w7x8-4vjj-gc4c/GHSA-w7x8-4vjj-gc4c.json b/advisories/unreviewed/2022/05/GHSA-w7x8-4vjj-gc4c/GHSA-w7x8-4vjj-gc4c.json index 42d55342970..0e286b0ace7 100644 --- a/advisories/unreviewed/2022/05/GHSA-w7x8-4vjj-gc4c/GHSA-w7x8-4vjj-gc4c.json +++ b/advisories/unreviewed/2022/05/GHSA-w7x8-4vjj-gc4c/GHSA-w7x8-4vjj-gc4c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w8m9-ffh8-52gc/GHSA-w8m9-ffh8-52gc.json b/advisories/unreviewed/2022/05/GHSA-w8m9-ffh8-52gc/GHSA-w8m9-ffh8-52gc.json index 45fbefcafcd..b94e6521739 100644 --- a/advisories/unreviewed/2022/05/GHSA-w8m9-ffh8-52gc/GHSA-w8m9-ffh8-52gc.json +++ b/advisories/unreviewed/2022/05/GHSA-w8m9-ffh8-52gc/GHSA-w8m9-ffh8-52gc.json @@ -7,12 +7,8 @@ "CVE-2015-9530" ], "details": "The Easy Digital Downloads (EDD) Upload File extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w92p-gj6g-7rpm/GHSA-w92p-gj6g-7rpm.json b/advisories/unreviewed/2022/05/GHSA-w92p-gj6g-7rpm/GHSA-w92p-gj6g-7rpm.json index abc9d0f93a9..6e82ddad23f 100644 --- a/advisories/unreviewed/2022/05/GHSA-w92p-gj6g-7rpm/GHSA-w92p-gj6g-7rpm.json +++ b/advisories/unreviewed/2022/05/GHSA-w92p-gj6g-7rpm/GHSA-w92p-gj6g-7rpm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w9c2-rgxr-jgfg/GHSA-w9c2-rgxr-jgfg.json b/advisories/unreviewed/2022/05/GHSA-w9c2-rgxr-jgfg/GHSA-w9c2-rgxr-jgfg.json index ce19ea6c024..db96d9a225d 100644 --- a/advisories/unreviewed/2022/05/GHSA-w9c2-rgxr-jgfg/GHSA-w9c2-rgxr-jgfg.json +++ b/advisories/unreviewed/2022/05/GHSA-w9c2-rgxr-jgfg/GHSA-w9c2-rgxr-jgfg.json @@ -7,12 +7,8 @@ "CVE-2019-18200" ], "details": "An issue was discovered on Fujitsu Wireless Keyboard Set LX390 GK381 devices. Because of the lack of proper encryption of 2.4 GHz communication, they are prone to keystroke injection attacks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w9cg-q4rq-7r4j/GHSA-w9cg-q4rq-7r4j.json b/advisories/unreviewed/2022/05/GHSA-w9cg-q4rq-7r4j/GHSA-w9cg-q4rq-7r4j.json index 2b8646a7b83..55d734903aa 100644 --- a/advisories/unreviewed/2022/05/GHSA-w9cg-q4rq-7r4j/GHSA-w9cg-q4rq-7r4j.json +++ b/advisories/unreviewed/2022/05/GHSA-w9cg-q4rq-7r4j/GHSA-w9cg-q4rq-7r4j.json @@ -7,12 +7,8 @@ "CVE-2019-0148" ], "details": "Resource leak in i40e driver for Intel(R) Ethernet 700 Series Controllers versions before 7.0 may allow an authenticated user to potentially enable a denial of service via local access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w9rf-6jf8-g4w9/GHSA-w9rf-6jf8-g4w9.json b/advisories/unreviewed/2022/05/GHSA-w9rf-6jf8-g4w9/GHSA-w9rf-6jf8-g4w9.json index 34b42b006c1..a8cc767ce0b 100644 --- a/advisories/unreviewed/2022/05/GHSA-w9rf-6jf8-g4w9/GHSA-w9rf-6jf8-g4w9.json +++ b/advisories/unreviewed/2022/05/GHSA-w9rf-6jf8-g4w9/GHSA-w9rf-6jf8-g4w9.json @@ -7,12 +7,8 @@ "CVE-2019-1443" ], "details": "An information disclosure vulnerability exists in Microsoft SharePoint when an attacker uploads a specially crafted file to the SharePoint Server.An authenticated attacker who successfully exploited this vulnerability could potentially leverage SharePoint functionality to obtain SMB hashes.The security update addresses the vulnerability by correcting how SharePoint checks file content., aka 'Microsoft SharePoint Information Disclosure Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w9wf-68qp-574m/GHSA-w9wf-68qp-574m.json b/advisories/unreviewed/2022/05/GHSA-w9wf-68qp-574m/GHSA-w9wf-68qp-574m.json index 2a8e9dfe783..9ae52002b1b 100644 --- a/advisories/unreviewed/2022/05/GHSA-w9wf-68qp-574m/GHSA-w9wf-68qp-574m.json +++ b/advisories/unreviewed/2022/05/GHSA-w9wf-68qp-574m/GHSA-w9wf-68qp-574m.json @@ -7,12 +7,8 @@ "CVE-2019-18819" ], "details": "Eximious Logo Designer 3.82 has a User Mode Write AV starting at ExiVectorRender!StrokeText_Blend+0x00000000000003a7.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wcf6-rgr3-qr83/GHSA-wcf6-rgr3-qr83.json b/advisories/unreviewed/2022/05/GHSA-wcf6-rgr3-qr83/GHSA-wcf6-rgr3-qr83.json index d7933d9f493..2fee6f05f4e 100644 --- a/advisories/unreviewed/2022/05/GHSA-wcf6-rgr3-qr83/GHSA-wcf6-rgr3-qr83.json +++ b/advisories/unreviewed/2022/05/GHSA-wcf6-rgr3-qr83/GHSA-wcf6-rgr3-qr83.json @@ -7,12 +7,8 @@ "CVE-2019-0386" ], "details": "Order processing in SAP ERP Sales (corrected in SAP_APPL 6.0, 6.02, 6.03, 6.04, 6.05, 6.06, 6.16, 6.17, 6.18) and S4HANA Sales (corrected in S4CORE 1.0, 1.01, 1.02, 1.03, 1.04) does not execute the required authorization checks for an authenticated user, which can result in an escalation of privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wcqg-r9hf-8vmr/GHSA-wcqg-r9hf-8vmr.json b/advisories/unreviewed/2022/05/GHSA-wcqg-r9hf-8vmr/GHSA-wcqg-r9hf-8vmr.json index c1c542cc568..685d2133926 100644 --- a/advisories/unreviewed/2022/05/GHSA-wcqg-r9hf-8vmr/GHSA-wcqg-r9hf-8vmr.json +++ b/advisories/unreviewed/2022/05/GHSA-wcqg-r9hf-8vmr/GHSA-wcqg-r9hf-8vmr.json @@ -7,12 +7,8 @@ "CVE-2019-15410" ], "details": "The Asus ZenFone 5Q Android device with a build fingerprint of asus/WW_Phone/ASUS_X017D_2:7.1.1/NGI77B/14.0400.1809.059-20181016:user/release-keys contains a pre-installed app with a package name of com.asus.loguploaderproxy app (versionCode=1570000020, versionName=7.0.0.4_170901) that allows other pre-installed apps to perform command execution via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions that are required by other other pre-installed apps that exported their capabilities to other pre-installed app.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wf72-r867-38x7/GHSA-wf72-r867-38x7.json b/advisories/unreviewed/2022/05/GHSA-wf72-r867-38x7/GHSA-wf72-r867-38x7.json index 92df3fd0939..911954a8229 100644 --- a/advisories/unreviewed/2022/05/GHSA-wf72-r867-38x7/GHSA-wf72-r867-38x7.json +++ b/advisories/unreviewed/2022/05/GHSA-wf72-r867-38x7/GHSA-wf72-r867-38x7.json @@ -7,12 +7,8 @@ "CVE-2019-18980" ], "details": "On Signify Philips Taolight Smart Wi-Fi Wiz Connected LED Bulb 9290022656 devices, an unprotected API lets remote users control the bulb's operation. Anyone can turn the bulb on or off, or change its color or brightness remotely. There is no authentication or encryption to use the control API. The only requirement is that the attacker have network access to the bulb.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wfhp-qmf5-xqg5/GHSA-wfhp-qmf5-xqg5.json b/advisories/unreviewed/2022/05/GHSA-wfhp-qmf5-xqg5/GHSA-wfhp-qmf5-xqg5.json index 0f1c2888c38..805c3ffac92 100644 --- a/advisories/unreviewed/2022/05/GHSA-wfhp-qmf5-xqg5/GHSA-wfhp-qmf5-xqg5.json +++ b/advisories/unreviewed/2022/05/GHSA-wfhp-qmf5-xqg5/GHSA-wfhp-qmf5-xqg5.json @@ -7,12 +7,8 @@ "CVE-2015-9501" ], "details": "The Artificial Intelligence theme before 1.2.4 for WordPress has XSS because Genericons HTML files are unnecessarily placed under the web root.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wfp6-c53g-9x25/GHSA-wfp6-c53g-9x25.json b/advisories/unreviewed/2022/05/GHSA-wfp6-c53g-9x25/GHSA-wfp6-c53g-9x25.json index 59946000de9..ffd2af4818f 100644 --- a/advisories/unreviewed/2022/05/GHSA-wfp6-c53g-9x25/GHSA-wfp6-c53g-9x25.json +++ b/advisories/unreviewed/2022/05/GHSA-wfp6-c53g-9x25/GHSA-wfp6-c53g-9x25.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wg83-v62r-wh2x/GHSA-wg83-v62r-wh2x.json b/advisories/unreviewed/2022/05/GHSA-wg83-v62r-wh2x/GHSA-wg83-v62r-wh2x.json index 6cc3560b671..6cf00f117b2 100644 --- a/advisories/unreviewed/2022/05/GHSA-wg83-v62r-wh2x/GHSA-wg83-v62r-wh2x.json +++ b/advisories/unreviewed/2022/05/GHSA-wg83-v62r-wh2x/GHSA-wg83-v62r-wh2x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wgp8-78hp-3jqj/GHSA-wgp8-78hp-3jqj.json b/advisories/unreviewed/2022/05/GHSA-wgp8-78hp-3jqj/GHSA-wgp8-78hp-3jqj.json index 7585f0d167e..07d9859a808 100644 --- a/advisories/unreviewed/2022/05/GHSA-wgp8-78hp-3jqj/GHSA-wgp8-78hp-3jqj.json +++ b/advisories/unreviewed/2022/05/GHSA-wgp8-78hp-3jqj/GHSA-wgp8-78hp-3jqj.json @@ -7,12 +7,8 @@ "CVE-2019-15468" ], "details": "The Xiaomi Mi A2 Lite Android device with a build fingerprint of xiaomi/daisy/daisy_sprout:9/PKQ1.180917.001/V10.0.3.0.PDLMIXM:user/release-keys contains a pre-installed app with a package name of com.huaqin.factory app (versionCode=1, versionName=QL1715_201812071953) that allows unauthorized wireless settings modification via a confused deputy attack. This capability can be accessed by any app co-located on the device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wgw9-xjmw-x98v/GHSA-wgw9-xjmw-x98v.json b/advisories/unreviewed/2022/05/GHSA-wgw9-xjmw-x98v/GHSA-wgw9-xjmw-x98v.json index 3d3899fcb89..ece17349024 100644 --- a/advisories/unreviewed/2022/05/GHSA-wgw9-xjmw-x98v/GHSA-wgw9-xjmw-x98v.json +++ b/advisories/unreviewed/2022/05/GHSA-wgw9-xjmw-x98v/GHSA-wgw9-xjmw-x98v.json @@ -7,12 +7,8 @@ "CVE-2019-15800" ], "details": "An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. Due to lack of input validation in the cmd_sys_traceroute_exec(), cmd_sys_arp_clear(), and cmd_sys_ping_exec() functions in the libclicmd.so library contained in the firmware, an attacker could leverage these functions to call system() and execute arbitrary commands on the switches. (Note that these functions are currently not called in this version of the firmware, however an attacker could use other vulnerabilities to finally use these vulnerabilities to gain code execution.)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wh76-54fj-93q5/GHSA-wh76-54fj-93q5.json b/advisories/unreviewed/2022/05/GHSA-wh76-54fj-93q5/GHSA-wh76-54fj-93q5.json index 7039d800abf..aa94b66d7bc 100644 --- a/advisories/unreviewed/2022/05/GHSA-wh76-54fj-93q5/GHSA-wh76-54fj-93q5.json +++ b/advisories/unreviewed/2022/05/GHSA-wh76-54fj-93q5/GHSA-wh76-54fj-93q5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-whgw-3c2r-gmwc/GHSA-whgw-3c2r-gmwc.json b/advisories/unreviewed/2022/05/GHSA-whgw-3c2r-gmwc/GHSA-whgw-3c2r-gmwc.json index 0d407852c6e..e44c1e75150 100644 --- a/advisories/unreviewed/2022/05/GHSA-whgw-3c2r-gmwc/GHSA-whgw-3c2r-gmwc.json +++ b/advisories/unreviewed/2022/05/GHSA-whgw-3c2r-gmwc/GHSA-whgw-3c2r-gmwc.json @@ -7,12 +7,8 @@ "CVE-2019-8221" ], "details": "Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wph5-xqqj-x883/GHSA-wph5-xqqj-x883.json b/advisories/unreviewed/2022/05/GHSA-wph5-xqqj-x883/GHSA-wph5-xqqj-x883.json index ed0448acfe4..7dace5b5cd7 100644 --- a/advisories/unreviewed/2022/05/GHSA-wph5-xqqj-x883/GHSA-wph5-xqqj-x883.json +++ b/advisories/unreviewed/2022/05/GHSA-wph5-xqqj-x883/GHSA-wph5-xqqj-x883.json @@ -7,12 +7,8 @@ "CVE-2019-2036" ], "details": "In okToConnect of HidHostService.java, there is a possible permission bypass due to an incorrect state check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-79703832", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wpjc-hhjv-c9gh/GHSA-wpjc-hhjv-c9gh.json b/advisories/unreviewed/2022/05/GHSA-wpjc-hhjv-c9gh/GHSA-wpjc-hhjv-c9gh.json index a61d3708a74..815b85541d8 100644 --- a/advisories/unreviewed/2022/05/GHSA-wpjc-hhjv-c9gh/GHSA-wpjc-hhjv-c9gh.json +++ b/advisories/unreviewed/2022/05/GHSA-wpjc-hhjv-c9gh/GHSA-wpjc-hhjv-c9gh.json @@ -7,12 +7,8 @@ "CVE-2019-4395" ], "details": "IBM Cloud Orchestrator 2.4 through 2.4.0.5 and 2.5 through 2.5.0.9 could allow a local user to obtain sensitive information from temporary script files. IBM X-Force ID: 162333.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wpmr-vwfj-2w83/GHSA-wpmr-vwfj-2w83.json b/advisories/unreviewed/2022/05/GHSA-wpmr-vwfj-2w83/GHSA-wpmr-vwfj-2w83.json index 8cbcb70c208..c833f722916 100644 --- a/advisories/unreviewed/2022/05/GHSA-wpmr-vwfj-2w83/GHSA-wpmr-vwfj-2w83.json +++ b/advisories/unreviewed/2022/05/GHSA-wpmr-vwfj-2w83/GHSA-wpmr-vwfj-2w83.json @@ -7,12 +7,8 @@ "CVE-2019-15345" ], "details": "The Tecno Camon iClick Android device with a build fingerprint of TECNO/H633/TECNO-IN6:8.1.0/O11019/A-180409V96:user/release-keys contains a pre-installed platform app with a package name of com.lovelyfont.defcontainer (versionCode=7, versionName=7.0.8). This app contains an exported service named com.lovelyfont.manager.service.FunctionService that allows any app co-located on the device to supply the file path to a Dalvik Executable (DEX) file which it will dynamically load within its own process and execute in with its own system privileges. This app cannot be disabled by the user and the attack can be performed by a zero-permission app. Executing commands as the system user can allow a third-party app to video record the user's screen, factory reset the device, obtain the user's notifications, read the logcat logs, inject events in the Graphical User Interface (GUI), and obtains the user's text messages, and more. Executing code as the system user can allow a third-party app to factory reset the device, obtain the user's Wi-Fi passwords, obtain the user's notifications, read the logcat logs, inject events in the GUI, change the default Input Method Editor (IME) (e.g., keyboard) with one contained within the attacking app that contains keylogging functionality, and obtains the user's text messages, and more.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wpwg-9p7v-m644/GHSA-wpwg-9p7v-m644.json b/advisories/unreviewed/2022/05/GHSA-wpwg-9p7v-m644/GHSA-wpwg-9p7v-m644.json index 58cd41addeb..0aaa379ddcc 100644 --- a/advisories/unreviewed/2022/05/GHSA-wpwg-9p7v-m644/GHSA-wpwg-9p7v-m644.json +++ b/advisories/unreviewed/2022/05/GHSA-wpwg-9p7v-m644/GHSA-wpwg-9p7v-m644.json @@ -7,12 +7,8 @@ "CVE-2019-12094" ], "details": "Horde Groupware Webmail Edition through 5.2.22 allows XSS via an admin/user.php?form=update_f&user_name= or admin/user.php?form=remove_f&user_name= or admin/config/diff.php?app= URI, related to the Tag Cloud feature.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wq7q-7mr7-8f4p/GHSA-wq7q-7mr7-8f4p.json b/advisories/unreviewed/2022/05/GHSA-wq7q-7mr7-8f4p/GHSA-wq7q-7mr7-8f4p.json index 8190124bb6b..58eb378ef62 100644 --- a/advisories/unreviewed/2022/05/GHSA-wq7q-7mr7-8f4p/GHSA-wq7q-7mr7-8f4p.json +++ b/advisories/unreviewed/2022/05/GHSA-wq7q-7mr7-8f4p/GHSA-wq7q-7mr7-8f4p.json @@ -7,12 +7,8 @@ "CVE-2019-15332" ], "details": "The Lava Z61 Android device with a build fingerprint of LAVA/Z61_2GB/Z61_2GB:8.1.0/O11019/1533889281:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionName=v4.0.27) that allows any app co-located on the device to programmatically disable and enable Wi-Fi without the corresponding access permission through an exported interface.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wqjf-hq52-vg86/GHSA-wqjf-hq52-vg86.json b/advisories/unreviewed/2022/05/GHSA-wqjf-hq52-vg86/GHSA-wqjf-hq52-vg86.json index a9751ad3095..6659530fbc1 100644 --- a/advisories/unreviewed/2022/05/GHSA-wqjf-hq52-vg86/GHSA-wqjf-hq52-vg86.json +++ b/advisories/unreviewed/2022/05/GHSA-wqjf-hq52-vg86/GHSA-wqjf-hq52-vg86.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wr79-mm96-gp45/GHSA-wr79-mm96-gp45.json b/advisories/unreviewed/2022/05/GHSA-wr79-mm96-gp45/GHSA-wr79-mm96-gp45.json index 5232d17d4c3..ebf0a3622d0 100644 --- a/advisories/unreviewed/2022/05/GHSA-wr79-mm96-gp45/GHSA-wr79-mm96-gp45.json +++ b/advisories/unreviewed/2022/05/GHSA-wr79-mm96-gp45/GHSA-wr79-mm96-gp45.json @@ -7,12 +7,8 @@ "CVE-2019-15394" ], "details": "The Asus ZenFone 5 Selfie Android device with a build fingerprint of asus/WW_Phone/ASUS_X017D_1:7.1.1/NMF26F/14.0400.1810.061-20181107:user/release-keys contains a pre-installed app with a package name of com.asus.atd.smmitest app (versionCode=1, versionName=1) that allows unauthorized wireless settings modification via a confused deputy attack. This capability can be accessed by any app co-located on the device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wr8x-8mw2-c99h/GHSA-wr8x-8mw2-c99h.json b/advisories/unreviewed/2022/05/GHSA-wr8x-8mw2-c99h/GHSA-wr8x-8mw2-c99h.json index cca63ccefba..70b869c128f 100644 --- a/advisories/unreviewed/2022/05/GHSA-wr8x-8mw2-c99h/GHSA-wr8x-8mw2-c99h.json +++ b/advisories/unreviewed/2022/05/GHSA-wr8x-8mw2-c99h/GHSA-wr8x-8mw2-c99h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wrmg-46pv-747h/GHSA-wrmg-46pv-747h.json b/advisories/unreviewed/2022/05/GHSA-wrmg-46pv-747h/GHSA-wrmg-46pv-747h.json index ac118e0b367..bc03127c3bc 100644 --- a/advisories/unreviewed/2022/05/GHSA-wrmg-46pv-747h/GHSA-wrmg-46pv-747h.json +++ b/advisories/unreviewed/2022/05/GHSA-wrmg-46pv-747h/GHSA-wrmg-46pv-747h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wwqc-fg9m-7c4c/GHSA-wwqc-fg9m-7c4c.json b/advisories/unreviewed/2022/05/GHSA-wwqc-fg9m-7c4c/GHSA-wwqc-fg9m-7c4c.json index 78cad93b2c5..0a904e5df4c 100644 --- a/advisories/unreviewed/2022/05/GHSA-wwqc-fg9m-7c4c/GHSA-wwqc-fg9m-7c4c.json +++ b/advisories/unreviewed/2022/05/GHSA-wwqc-fg9m-7c4c/GHSA-wwqc-fg9m-7c4c.json @@ -7,12 +7,8 @@ "CVE-2019-15403" ], "details": "The Asus ZenFone 3s Max Android device with a build fingerprint of asus/IN_X00G/ASUS_X00G_1:7.0/NRD90M/IN_X00G-14.02.1807.33-20180706:user/release-keys contains a pre-installed app with a package name of com.asus.loguploaderproxy app (versionCode=1570000020, versionName=7.0.0.4_170901) that allows other pre-installed apps to perform command execution via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions that are required by other other pre-installed apps that exported their capabilities to other pre-installed app.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wx5h-f4j4-wx7p/GHSA-wx5h-f4j4-wx7p.json b/advisories/unreviewed/2022/05/GHSA-wx5h-f4j4-wx7p/GHSA-wx5h-f4j4-wx7p.json index befcf40d95d..f2290171f1e 100644 --- a/advisories/unreviewed/2022/05/GHSA-wx5h-f4j4-wx7p/GHSA-wx5h-f4j4-wx7p.json +++ b/advisories/unreviewed/2022/05/GHSA-wx5h-f4j4-wx7p/GHSA-wx5h-f4j4-wx7p.json @@ -7,12 +7,8 @@ "CVE-2019-15462" ], "details": "The Samsung J7 Duo Android device with a build fingerprint of samsung/j7duolteub/j7duolte:8.0.0/R16NW/J720MUBS3ASB2:user/release-keys contains a pre-installed app with a package name of com.samsung.android.themecenter app (versionCode=7000000, versionName=7.0.0.0) that allows other pre-installed apps to perform app installation via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions that are required by other other pre-installed apps that exported their capabilities to other pre-installed app.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wxhv-g8vm-4j32/GHSA-wxhv-g8vm-4j32.json b/advisories/unreviewed/2022/05/GHSA-wxhv-g8vm-4j32/GHSA-wxhv-g8vm-4j32.json index 5e2b625d335..e3866ece7e2 100644 --- a/advisories/unreviewed/2022/05/GHSA-wxhv-g8vm-4j32/GHSA-wxhv-g8vm-4j32.json +++ b/advisories/unreviewed/2022/05/GHSA-wxhv-g8vm-4j32/GHSA-wxhv-g8vm-4j32.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wxpr-w6c6-j9hv/GHSA-wxpr-w6c6-j9hv.json b/advisories/unreviewed/2022/05/GHSA-wxpr-w6c6-j9hv/GHSA-wxpr-w6c6-j9hv.json index e8d166b3ffb..a5f7c70f65b 100644 --- a/advisories/unreviewed/2022/05/GHSA-wxpr-w6c6-j9hv/GHSA-wxpr-w6c6-j9hv.json +++ b/advisories/unreviewed/2022/05/GHSA-wxpr-w6c6-j9hv/GHSA-wxpr-w6c6-j9hv.json @@ -7,12 +7,8 @@ "CVE-2019-5279" ], "details": "Huawei smart phones Emily-L29C with Versions earlier than 9.1.0.311(C10E2R1P13T8), Versions earlier than 9.1.0.311(C461E2R1P11T8), Versions earlier than 9.1.0.316(C635E2R1P11T8), Versions earlier than 9.1.0.311(C185E2R1P12T8), Versions earlier than 9.1.0.311(C605E2R1P12T8), Versions earlier than 9.1.0.311(C636E7R1P13T8) have an information leakage vulnerability. An attacker tricks the user into installing a malicious application, which can copy specific files to the sdcard, resulting in information leakage.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x23g-72hv-58qm/GHSA-x23g-72hv-58qm.json b/advisories/unreviewed/2022/05/GHSA-x23g-72hv-58qm/GHSA-x23g-72hv-58qm.json index c3a2087475a..5e03da759f3 100644 --- a/advisories/unreviewed/2022/05/GHSA-x23g-72hv-58qm/GHSA-x23g-72hv-58qm.json +++ b/advisories/unreviewed/2022/05/GHSA-x23g-72hv-58qm/GHSA-x23g-72hv-58qm.json @@ -7,12 +7,8 @@ "CVE-2006-3486" ], "details": "** DISPUTED ** Off-by-one buffer overflow in the Instance_options::complete_initialization function in instance_options.cc in the Instance Manager in MySQL before 5.0.23 and 5.1 before 5.1.12 might allow local users to cause a denial of service (application crash) via unspecified vectors, which triggers the overflow when the convert_dirname function is called. NOTE: the vendor has disputed this issue via e-mail to CVE, saying that it is only exploitable when the user has access to the configuration file or the Instance Manager daemon. Due to intended functionality, this level of access would already allow the user to disrupt program operation, so this does not cross security boundaries and is not a vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x34q-hhhp-2hp9/GHSA-x34q-hhhp-2hp9.json b/advisories/unreviewed/2022/05/GHSA-x34q-hhhp-2hp9/GHSA-x34q-hhhp-2hp9.json index 2da1e7ca3c9..f8418008475 100644 --- a/advisories/unreviewed/2022/05/GHSA-x34q-hhhp-2hp9/GHSA-x34q-hhhp-2hp9.json +++ b/advisories/unreviewed/2022/05/GHSA-x34q-hhhp-2hp9/GHSA-x34q-hhhp-2hp9.json @@ -7,12 +7,8 @@ "CVE-2019-8213" ], "details": "Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x35h-x4qj-v4pc/GHSA-x35h-x4qj-v4pc.json b/advisories/unreviewed/2022/05/GHSA-x35h-x4qj-v4pc/GHSA-x35h-x4qj-v4pc.json index c88b59f3b47..da713fa2f9f 100644 --- a/advisories/unreviewed/2022/05/GHSA-x35h-x4qj-v4pc/GHSA-x35h-x4qj-v4pc.json +++ b/advisories/unreviewed/2022/05/GHSA-x35h-x4qj-v4pc/GHSA-x35h-x4qj-v4pc.json @@ -7,12 +7,8 @@ "CVE-2019-15359" ], "details": "The Haier A6 Android device with a build fingerprint of Haier/A6/A6:8.1.0/O11019/1534219877:userdebug/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x4ph-cq89-6r82/GHSA-x4ph-cq89-6r82.json b/advisories/unreviewed/2022/05/GHSA-x4ph-cq89-6r82/GHSA-x4ph-cq89-6r82.json index 75aa71fd0cd..dff7f5f830d 100644 --- a/advisories/unreviewed/2022/05/GHSA-x4ph-cq89-6r82/GHSA-x4ph-cq89-6r82.json +++ b/advisories/unreviewed/2022/05/GHSA-x4ph-cq89-6r82/GHSA-x4ph-cq89-6r82.json @@ -7,12 +7,8 @@ "CVE-2019-0388" ], "details": "SAP UI5 HTTP Handler (corrected in SAP_UI versions 7.5, 7.51, 7.52, 7.53, 7.54 and SAP UI_700 version 2.0) allows an attacker to manipulate content due to insufficient URL validation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x7j8-893h-w4j2/GHSA-x7j8-893h-w4j2.json b/advisories/unreviewed/2022/05/GHSA-x7j8-893h-w4j2/GHSA-x7j8-893h-w4j2.json index a439131f941..109d7003d92 100644 --- a/advisories/unreviewed/2022/05/GHSA-x7j8-893h-w4j2/GHSA-x7j8-893h-w4j2.json +++ b/advisories/unreviewed/2022/05/GHSA-x7j8-893h-w4j2/GHSA-x7j8-893h-w4j2.json @@ -7,12 +7,8 @@ "CVE-2019-3649" ], "details": "Information Disclosure vulnerability in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows remote authenticated attackers to gain access to hashed credentials via carefully constructed POST request extracting incorrectly recorded data from log files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x7r6-7fqf-xh3p/GHSA-x7r6-7fqf-xh3p.json b/advisories/unreviewed/2022/05/GHSA-x7r6-7fqf-xh3p/GHSA-x7r6-7fqf-xh3p.json index 50d46b51b4a..e816b0960ee 100644 --- a/advisories/unreviewed/2022/05/GHSA-x7r6-7fqf-xh3p/GHSA-x7r6-7fqf-xh3p.json +++ b/advisories/unreviewed/2022/05/GHSA-x7r6-7fqf-xh3p/GHSA-x7r6-7fqf-xh3p.json @@ -7,12 +7,8 @@ "CVE-2019-0390" ], "details": "Under certain conditions SAP Data Hub (corrected in DH_Foundation version 2) allows an attacker to access information which would otherwise be restricted. Connection details that are maintained in Connection Manager are visible to users.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x982-ghqf-mvrf/GHSA-x982-ghqf-mvrf.json b/advisories/unreviewed/2022/05/GHSA-x982-ghqf-mvrf/GHSA-x982-ghqf-mvrf.json index cfa0539b4a5..01618986e9a 100644 --- a/advisories/unreviewed/2022/05/GHSA-x982-ghqf-mvrf/GHSA-x982-ghqf-mvrf.json +++ b/advisories/unreviewed/2022/05/GHSA-x982-ghqf-mvrf/GHSA-x982-ghqf-mvrf.json @@ -7,12 +7,8 @@ "CVE-2019-15358" ], "details": "The Dexp Z250 Android device with a build fingerprint of DEXP/Z250/Z250:8.1.0/O11019/1531130719:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x9fr-phq4-8582/GHSA-x9fr-phq4-8582.json b/advisories/unreviewed/2022/05/GHSA-x9fr-phq4-8582/GHSA-x9fr-phq4-8582.json index b1b46d97faf..4163a41d41d 100644 --- a/advisories/unreviewed/2022/05/GHSA-x9fr-phq4-8582/GHSA-x9fr-phq4-8582.json +++ b/advisories/unreviewed/2022/05/GHSA-x9fr-phq4-8582/GHSA-x9fr-phq4-8582.json @@ -7,12 +7,8 @@ "CVE-2019-11996" ], "details": "Potential security vulnerabilities have been identified with HPE Nimble Storage systems in multi array group configurations. The vulnerabilities could be remotely exploited by an attacker to gain elevated privileges or disclose information the array. Affected products and versions include: Nimble Storage Hybrid Flash Arrays - 5.1.2.0 and older, 5.0.7.0 and older, 4.5.4.0 and older, and 3.9.1.0 and older Nimble Storage All Flash Arrays - 5.1.2.0 and older, 5.0.7.0 and older, 4.5.4.0 and older, and 3.9.1.0 and older Nimble Storage Secondary Flash Arrays - 5.1.2.0 and older, 5.0.7.0 and older, 4.5.4.0 and older, and 3.9.1.0 and older", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x9wg-q72x-x5w7/GHSA-x9wg-q72x-x5w7.json b/advisories/unreviewed/2022/05/GHSA-x9wg-q72x-x5w7/GHSA-x9wg-q72x-x5w7.json index 5c5260e2b26..ae6a136cc9c 100644 --- a/advisories/unreviewed/2022/05/GHSA-x9wg-q72x-x5w7/GHSA-x9wg-q72x-x5w7.json +++ b/advisories/unreviewed/2022/05/GHSA-x9wg-q72x-x5w7/GHSA-x9wg-q72x-x5w7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xcpc-pcph-784r/GHSA-xcpc-pcph-784r.json b/advisories/unreviewed/2022/05/GHSA-xcpc-pcph-784r/GHSA-xcpc-pcph-784r.json index dbacd23a9d9..9d0a122dda3 100644 --- a/advisories/unreviewed/2022/05/GHSA-xcpc-pcph-784r/GHSA-xcpc-pcph-784r.json +++ b/advisories/unreviewed/2022/05/GHSA-xcpc-pcph-784r/GHSA-xcpc-pcph-784r.json @@ -7,12 +7,8 @@ "CVE-2019-10617" ], "details": "Low privilege users can access service configuration which contains registry data that admins uses to create or delete entries in the registry in QCA6174_9377.WIN.1.0 in QCA6174_9377", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xcv5-pjw7-mgp9/GHSA-xcv5-pjw7-mgp9.json b/advisories/unreviewed/2022/05/GHSA-xcv5-pjw7-mgp9/GHSA-xcv5-pjw7-mgp9.json index 3f18e3e3e1b..cbc6ee2d442 100644 --- a/advisories/unreviewed/2022/05/GHSA-xcv5-pjw7-mgp9/GHSA-xcv5-pjw7-mgp9.json +++ b/advisories/unreviewed/2022/05/GHSA-xcv5-pjw7-mgp9/GHSA-xcv5-pjw7-mgp9.json @@ -7,12 +7,8 @@ "CVE-2019-17421" ], "details": "Incorrect file permissions on the packaged Nipper executable file in Zoho ManageEngine OpManager 12.4.072 and Firewall Analyzer 12.4.072 allow local users to elevate privileges to root by overwriting this file with a malicious payload.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xf3m-pfq5-qf2m/GHSA-xf3m-pfq5-qf2m.json b/advisories/unreviewed/2022/05/GHSA-xf3m-pfq5-qf2m/GHSA-xf3m-pfq5-qf2m.json index a8a1018edf4..4de99a0a846 100644 --- a/advisories/unreviewed/2022/05/GHSA-xf3m-pfq5-qf2m/GHSA-xf3m-pfq5-qf2m.json +++ b/advisories/unreviewed/2022/05/GHSA-xf3m-pfq5-qf2m/GHSA-xf3m-pfq5-qf2m.json @@ -7,12 +7,8 @@ "CVE-2019-11181" ], "details": "Out of bound read in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable escalation of privilege via network access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xfwp-87xx-cqvf/GHSA-xfwp-87xx-cqvf.json b/advisories/unreviewed/2022/05/GHSA-xfwp-87xx-cqvf/GHSA-xfwp-87xx-cqvf.json index b292b1eb324..f759f32d7a7 100644 --- a/advisories/unreviewed/2022/05/GHSA-xfwp-87xx-cqvf/GHSA-xfwp-87xx-cqvf.json +++ b/advisories/unreviewed/2022/05/GHSA-xfwp-87xx-cqvf/GHSA-xfwp-87xx-cqvf.json @@ -7,12 +7,8 @@ "CVE-2019-15457" ], "details": "The Samsung J6 Android device with a build fingerprint of samsung/j6ltexx/j6lte:8.0.0/R16NW/J600FNXXU3ASC1:user/release-keys contains a pre-installed app with a package name of com.samsung.android.themecenter app (versionCode=7000000, versionName=7.0.0.0) that allows other pre-installed apps to perform app installation via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions that are required by other other pre-installed apps that exported their capabilities to other pre-installed app.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xgmf-qcp6-m7mc/GHSA-xgmf-qcp6-m7mc.json b/advisories/unreviewed/2022/05/GHSA-xgmf-qcp6-m7mc/GHSA-xgmf-qcp6-m7mc.json index af649288023..d02474902f9 100644 --- a/advisories/unreviewed/2022/05/GHSA-xgmf-qcp6-m7mc/GHSA-xgmf-qcp6-m7mc.json +++ b/advisories/unreviewed/2022/05/GHSA-xgmf-qcp6-m7mc/GHSA-xgmf-qcp6-m7mc.json @@ -7,12 +7,8 @@ "CVE-2019-8224" ], "details": "Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xjmq-x923-hrwq/GHSA-xjmq-x923-hrwq.json b/advisories/unreviewed/2022/05/GHSA-xjmq-x923-hrwq/GHSA-xjmq-x923-hrwq.json index 1572a3a7251..5438ba2eb7d 100644 --- a/advisories/unreviewed/2022/05/GHSA-xjmq-x923-hrwq/GHSA-xjmq-x923-hrwq.json +++ b/advisories/unreviewed/2022/05/GHSA-xjmq-x923-hrwq/GHSA-xjmq-x923-hrwq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xm93-639c-r743/GHSA-xm93-639c-r743.json b/advisories/unreviewed/2022/05/GHSA-xm93-639c-r743/GHSA-xm93-639c-r743.json index 44f85275849..62a340166c1 100644 --- a/advisories/unreviewed/2022/05/GHSA-xm93-639c-r743/GHSA-xm93-639c-r743.json +++ b/advisories/unreviewed/2022/05/GHSA-xm93-639c-r743/GHSA-xm93-639c-r743.json @@ -7,12 +7,8 @@ "CVE-2019-18624" ], "details": "Opera Mini for Android allows attackers to bypass intended restrictions on .apk file download/installation via an RTLO (aka Right to Left Override) approach, as demonstrated by misinterpretation of malicious%E2%80%AEtxt.apk as maliciouskpa.txt. This affects 44.1.2254.142553, 44.1.2254.142659, and 44.1.2254.143214.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xmxc-8qjw-52gx/GHSA-xmxc-8qjw-52gx.json b/advisories/unreviewed/2022/05/GHSA-xmxc-8qjw-52gx/GHSA-xmxc-8qjw-52gx.json index 526f6bf49ca..92065125c1a 100644 --- a/advisories/unreviewed/2022/05/GHSA-xmxc-8qjw-52gx/GHSA-xmxc-8qjw-52gx.json +++ b/advisories/unreviewed/2022/05/GHSA-xmxc-8qjw-52gx/GHSA-xmxc-8qjw-52gx.json @@ -7,12 +7,8 @@ "CVE-2019-18820" ], "details": "Eximious Logo Designer 3.82 has Heap Corruption starting at ntdll!RtlpNtMakeTemporaryKey+0x0000000000001a78.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xpg2-54xp-8xmf/GHSA-xpg2-54xp-8xmf.json b/advisories/unreviewed/2022/05/GHSA-xpg2-54xp-8xmf/GHSA-xpg2-54xp-8xmf.json index 08e5244fff0..218743f7141 100644 --- a/advisories/unreviewed/2022/05/GHSA-xpg2-54xp-8xmf/GHSA-xpg2-54xp-8xmf.json +++ b/advisories/unreviewed/2022/05/GHSA-xpg2-54xp-8xmf/GHSA-xpg2-54xp-8xmf.json @@ -7,12 +7,8 @@ "CVE-2019-5293" ], "details": "Some Huawei products have a memory leak vulnerability when handling some messages. A remote attacker with operation privilege could exploit the vulnerability by sending specific messages continuously. Successful exploit may cause some service to be abnormal.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xr92-rw38-fmg9/GHSA-xr92-rw38-fmg9.json b/advisories/unreviewed/2022/05/GHSA-xr92-rw38-fmg9/GHSA-xr92-rw38-fmg9.json index 4940cf54e97..b540ba21287 100644 --- a/advisories/unreviewed/2022/05/GHSA-xr92-rw38-fmg9/GHSA-xr92-rw38-fmg9.json +++ b/advisories/unreviewed/2022/05/GHSA-xr92-rw38-fmg9/GHSA-xr92-rw38-fmg9.json @@ -7,12 +7,8 @@ "CVE-2019-0396" ], "details": "SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), corrected in versions 4.1 and 4.2, does not sufficiently validate an XML document accepted from an untrusted source. An attacker can craft a message that contains malicious elements that will not be correctly filtered by Web Intelligence HTML interface in some specific workflows.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xvww-87m7-74xx/GHSA-xvww-87m7-74xx.json b/advisories/unreviewed/2022/05/GHSA-xvww-87m7-74xx/GHSA-xvww-87m7-74xx.json index d8a42d3a26c..2aee0019053 100644 --- a/advisories/unreviewed/2022/05/GHSA-xvww-87m7-74xx/GHSA-xvww-87m7-74xx.json +++ b/advisories/unreviewed/2022/05/GHSA-xvww-87m7-74xx/GHSA-xvww-87m7-74xx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xvx7-cgrp-p764/GHSA-xvx7-cgrp-p764.json b/advisories/unreviewed/2022/05/GHSA-xvx7-cgrp-p764/GHSA-xvx7-cgrp-p764.json index fd2fbc2a031..d20abda162b 100644 --- a/advisories/unreviewed/2022/05/GHSA-xvx7-cgrp-p764/GHSA-xvx7-cgrp-p764.json +++ b/advisories/unreviewed/2022/05/GHSA-xvx7-cgrp-p764/GHSA-xvx7-cgrp-p764.json @@ -7,12 +7,8 @@ "CVE-2019-11174" ], "details": "Insufficient access control in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable information disclosure via network access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xw65-g8p2-hc6q/GHSA-xw65-g8p2-hc6q.json b/advisories/unreviewed/2022/05/GHSA-xw65-g8p2-hc6q/GHSA-xw65-g8p2-hc6q.json index dff0742a59f..12a11a4023c 100644 --- a/advisories/unreviewed/2022/05/GHSA-xw65-g8p2-hc6q/GHSA-xw65-g8p2-hc6q.json +++ b/advisories/unreviewed/2022/05/GHSA-xw65-g8p2-hc6q/GHSA-xw65-g8p2-hc6q.json @@ -7,12 +7,8 @@ "CVE-2019-14860" ], "details": "It was found that the Syndesis configuration for Cross-Origin Resource Sharing was set to allow all origins. An attacker could use this lack of protection to conduct phishing attacks and further access unauthorized information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/07/GHSA-33vj-x2w7-j3gv/GHSA-33vj-x2w7-j3gv.json b/advisories/unreviewed/2022/07/GHSA-33vj-x2w7-j3gv/GHSA-33vj-x2w7-j3gv.json index c602814374b..e946382cd30 100644 --- a/advisories/unreviewed/2022/07/GHSA-33vj-x2w7-j3gv/GHSA-33vj-x2w7-j3gv.json +++ b/advisories/unreviewed/2022/07/GHSA-33vj-x2w7-j3gv/GHSA-33vj-x2w7-j3gv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/07/GHSA-359g-8g36-v6qg/GHSA-359g-8g36-v6qg.json b/advisories/unreviewed/2022/07/GHSA-359g-8g36-v6qg/GHSA-359g-8g36-v6qg.json index 88a8f770110..5f96b23cc6f 100644 --- a/advisories/unreviewed/2022/07/GHSA-359g-8g36-v6qg/GHSA-359g-8g36-v6qg.json +++ b/advisories/unreviewed/2022/07/GHSA-359g-8g36-v6qg/GHSA-359g-8g36-v6qg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/07/GHSA-37rh-j478-6h3c/GHSA-37rh-j478-6h3c.json b/advisories/unreviewed/2022/07/GHSA-37rh-j478-6h3c/GHSA-37rh-j478-6h3c.json index 5d1c09d0882..db02ab68170 100644 --- a/advisories/unreviewed/2022/07/GHSA-37rh-j478-6h3c/GHSA-37rh-j478-6h3c.json +++ b/advisories/unreviewed/2022/07/GHSA-37rh-j478-6h3c/GHSA-37rh-j478-6h3c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/07/GHSA-4p43-98m8-qxmc/GHSA-4p43-98m8-qxmc.json b/advisories/unreviewed/2022/07/GHSA-4p43-98m8-qxmc/GHSA-4p43-98m8-qxmc.json index fa7fefc44e5..f361f394b5f 100644 --- a/advisories/unreviewed/2022/07/GHSA-4p43-98m8-qxmc/GHSA-4p43-98m8-qxmc.json +++ b/advisories/unreviewed/2022/07/GHSA-4p43-98m8-qxmc/GHSA-4p43-98m8-qxmc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/07/GHSA-4pqq-wq2g-6rcm/GHSA-4pqq-wq2g-6rcm.json b/advisories/unreviewed/2022/07/GHSA-4pqq-wq2g-6rcm/GHSA-4pqq-wq2g-6rcm.json index b2fd7d44601..ff1756af96d 100644 --- a/advisories/unreviewed/2022/07/GHSA-4pqq-wq2g-6rcm/GHSA-4pqq-wq2g-6rcm.json +++ b/advisories/unreviewed/2022/07/GHSA-4pqq-wq2g-6rcm/GHSA-4pqq-wq2g-6rcm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/07/GHSA-58ww-8hxm-f99f/GHSA-58ww-8hxm-f99f.json b/advisories/unreviewed/2022/07/GHSA-58ww-8hxm-f99f/GHSA-58ww-8hxm-f99f.json index 886a0f5711b..fbb816a3703 100644 --- a/advisories/unreviewed/2022/07/GHSA-58ww-8hxm-f99f/GHSA-58ww-8hxm-f99f.json +++ b/advisories/unreviewed/2022/07/GHSA-58ww-8hxm-f99f/GHSA-58ww-8hxm-f99f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/07/GHSA-5fwv-7q7m-cgxq/GHSA-5fwv-7q7m-cgxq.json b/advisories/unreviewed/2022/07/GHSA-5fwv-7q7m-cgxq/GHSA-5fwv-7q7m-cgxq.json index 6c5be0c7415..da813e605d9 100644 --- a/advisories/unreviewed/2022/07/GHSA-5fwv-7q7m-cgxq/GHSA-5fwv-7q7m-cgxq.json +++ b/advisories/unreviewed/2022/07/GHSA-5fwv-7q7m-cgxq/GHSA-5fwv-7q7m-cgxq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/07/GHSA-6g84-gjgq-567p/GHSA-6g84-gjgq-567p.json b/advisories/unreviewed/2022/07/GHSA-6g84-gjgq-567p/GHSA-6g84-gjgq-567p.json index f418402cda7..83b15691200 100644 --- a/advisories/unreviewed/2022/07/GHSA-6g84-gjgq-567p/GHSA-6g84-gjgq-567p.json +++ b/advisories/unreviewed/2022/07/GHSA-6g84-gjgq-567p/GHSA-6g84-gjgq-567p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/07/GHSA-87p7-px4m-hqv2/GHSA-87p7-px4m-hqv2.json b/advisories/unreviewed/2022/07/GHSA-87p7-px4m-hqv2/GHSA-87p7-px4m-hqv2.json index 4a2bc0b99c7..685c893dd2d 100644 --- a/advisories/unreviewed/2022/07/GHSA-87p7-px4m-hqv2/GHSA-87p7-px4m-hqv2.json +++ b/advisories/unreviewed/2022/07/GHSA-87p7-px4m-hqv2/GHSA-87p7-px4m-hqv2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/07/GHSA-88wm-pv8r-fc9q/GHSA-88wm-pv8r-fc9q.json b/advisories/unreviewed/2022/07/GHSA-88wm-pv8r-fc9q/GHSA-88wm-pv8r-fc9q.json index 35608588a8d..2340628b6fc 100644 --- a/advisories/unreviewed/2022/07/GHSA-88wm-pv8r-fc9q/GHSA-88wm-pv8r-fc9q.json +++ b/advisories/unreviewed/2022/07/GHSA-88wm-pv8r-fc9q/GHSA-88wm-pv8r-fc9q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/07/GHSA-8fqx-rxr6-9fxc/GHSA-8fqx-rxr6-9fxc.json b/advisories/unreviewed/2022/07/GHSA-8fqx-rxr6-9fxc/GHSA-8fqx-rxr6-9fxc.json index 9cb72c5874c..a83b42f3f49 100644 --- a/advisories/unreviewed/2022/07/GHSA-8fqx-rxr6-9fxc/GHSA-8fqx-rxr6-9fxc.json +++ b/advisories/unreviewed/2022/07/GHSA-8fqx-rxr6-9fxc/GHSA-8fqx-rxr6-9fxc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/07/GHSA-8hmj-5292-j8w9/GHSA-8hmj-5292-j8w9.json b/advisories/unreviewed/2022/07/GHSA-8hmj-5292-j8w9/GHSA-8hmj-5292-j8w9.json index 695bc2eabfb..f21a0a1ae11 100644 --- a/advisories/unreviewed/2022/07/GHSA-8hmj-5292-j8w9/GHSA-8hmj-5292-j8w9.json +++ b/advisories/unreviewed/2022/07/GHSA-8hmj-5292-j8w9/GHSA-8hmj-5292-j8w9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/07/GHSA-8vjc-vph9-rg4j/GHSA-8vjc-vph9-rg4j.json b/advisories/unreviewed/2022/07/GHSA-8vjc-vph9-rg4j/GHSA-8vjc-vph9-rg4j.json index bde6283e649..8e757defedb 100644 --- a/advisories/unreviewed/2022/07/GHSA-8vjc-vph9-rg4j/GHSA-8vjc-vph9-rg4j.json +++ b/advisories/unreviewed/2022/07/GHSA-8vjc-vph9-rg4j/GHSA-8vjc-vph9-rg4j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/07/GHSA-9r87-pc5m-9w97/GHSA-9r87-pc5m-9w97.json b/advisories/unreviewed/2022/07/GHSA-9r87-pc5m-9w97/GHSA-9r87-pc5m-9w97.json index b312a33da81..30e9090d346 100644 --- a/advisories/unreviewed/2022/07/GHSA-9r87-pc5m-9w97/GHSA-9r87-pc5m-9w97.json +++ b/advisories/unreviewed/2022/07/GHSA-9r87-pc5m-9w97/GHSA-9r87-pc5m-9w97.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/07/GHSA-c4h9-r99w-3vw3/GHSA-c4h9-r99w-3vw3.json b/advisories/unreviewed/2022/07/GHSA-c4h9-r99w-3vw3/GHSA-c4h9-r99w-3vw3.json index f1219a8a715..995f5d21a97 100644 --- a/advisories/unreviewed/2022/07/GHSA-c4h9-r99w-3vw3/GHSA-c4h9-r99w-3vw3.json +++ b/advisories/unreviewed/2022/07/GHSA-c4h9-r99w-3vw3/GHSA-c4h9-r99w-3vw3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/07/GHSA-c4wx-gc8f-7fj9/GHSA-c4wx-gc8f-7fj9.json b/advisories/unreviewed/2022/07/GHSA-c4wx-gc8f-7fj9/GHSA-c4wx-gc8f-7fj9.json index 7967c50004d..f3187a8263c 100644 --- a/advisories/unreviewed/2022/07/GHSA-c4wx-gc8f-7fj9/GHSA-c4wx-gc8f-7fj9.json +++ b/advisories/unreviewed/2022/07/GHSA-c4wx-gc8f-7fj9/GHSA-c4wx-gc8f-7fj9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/07/GHSA-c6vh-r249-cvjj/GHSA-c6vh-r249-cvjj.json b/advisories/unreviewed/2022/07/GHSA-c6vh-r249-cvjj/GHSA-c6vh-r249-cvjj.json index 81416e5e512..71b2e0d9275 100644 --- a/advisories/unreviewed/2022/07/GHSA-c6vh-r249-cvjj/GHSA-c6vh-r249-cvjj.json +++ b/advisories/unreviewed/2022/07/GHSA-c6vh-r249-cvjj/GHSA-c6vh-r249-cvjj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/07/GHSA-f83w-fm29-6mfh/GHSA-f83w-fm29-6mfh.json b/advisories/unreviewed/2022/07/GHSA-f83w-fm29-6mfh/GHSA-f83w-fm29-6mfh.json index a071d29af67..0890c71a9cf 100644 --- a/advisories/unreviewed/2022/07/GHSA-f83w-fm29-6mfh/GHSA-f83w-fm29-6mfh.json +++ b/advisories/unreviewed/2022/07/GHSA-f83w-fm29-6mfh/GHSA-f83w-fm29-6mfh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/07/GHSA-f97j-qrxg-vh49/GHSA-f97j-qrxg-vh49.json b/advisories/unreviewed/2022/07/GHSA-f97j-qrxg-vh49/GHSA-f97j-qrxg-vh49.json index 3d704321ca7..92b3f6565d0 100644 --- a/advisories/unreviewed/2022/07/GHSA-f97j-qrxg-vh49/GHSA-f97j-qrxg-vh49.json +++ b/advisories/unreviewed/2022/07/GHSA-f97j-qrxg-vh49/GHSA-f97j-qrxg-vh49.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/07/GHSA-fjx2-q792-pjxm/GHSA-fjx2-q792-pjxm.json b/advisories/unreviewed/2022/07/GHSA-fjx2-q792-pjxm/GHSA-fjx2-q792-pjxm.json index 6c06afd2c42..7d43590393f 100644 --- a/advisories/unreviewed/2022/07/GHSA-fjx2-q792-pjxm/GHSA-fjx2-q792-pjxm.json +++ b/advisories/unreviewed/2022/07/GHSA-fjx2-q792-pjxm/GHSA-fjx2-q792-pjxm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/07/GHSA-h3j4-w6vx-h76j/GHSA-h3j4-w6vx-h76j.json b/advisories/unreviewed/2022/07/GHSA-h3j4-w6vx-h76j/GHSA-h3j4-w6vx-h76j.json index 467afd18c6c..76de75ab381 100644 --- a/advisories/unreviewed/2022/07/GHSA-h3j4-w6vx-h76j/GHSA-h3j4-w6vx-h76j.json +++ b/advisories/unreviewed/2022/07/GHSA-h3j4-w6vx-h76j/GHSA-h3j4-w6vx-h76j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/07/GHSA-h66r-9vjc-f9r8/GHSA-h66r-9vjc-f9r8.json b/advisories/unreviewed/2022/07/GHSA-h66r-9vjc-f9r8/GHSA-h66r-9vjc-f9r8.json index 8c21a462205..e785b2e5650 100644 --- a/advisories/unreviewed/2022/07/GHSA-h66r-9vjc-f9r8/GHSA-h66r-9vjc-f9r8.json +++ b/advisories/unreviewed/2022/07/GHSA-h66r-9vjc-f9r8/GHSA-h66r-9vjc-f9r8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/07/GHSA-hffq-2fq2-hfh5/GHSA-hffq-2fq2-hfh5.json b/advisories/unreviewed/2022/07/GHSA-hffq-2fq2-hfh5/GHSA-hffq-2fq2-hfh5.json index e22b2c0d657..60f45a18b0b 100644 --- a/advisories/unreviewed/2022/07/GHSA-hffq-2fq2-hfh5/GHSA-hffq-2fq2-hfh5.json +++ b/advisories/unreviewed/2022/07/GHSA-hffq-2fq2-hfh5/GHSA-hffq-2fq2-hfh5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/07/GHSA-hjmg-3wv2-r885/GHSA-hjmg-3wv2-r885.json b/advisories/unreviewed/2022/07/GHSA-hjmg-3wv2-r885/GHSA-hjmg-3wv2-r885.json index e2123ae012d..4d268270824 100644 --- a/advisories/unreviewed/2022/07/GHSA-hjmg-3wv2-r885/GHSA-hjmg-3wv2-r885.json +++ b/advisories/unreviewed/2022/07/GHSA-hjmg-3wv2-r885/GHSA-hjmg-3wv2-r885.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/07/GHSA-hrq4-ppwc-8jwx/GHSA-hrq4-ppwc-8jwx.json b/advisories/unreviewed/2022/07/GHSA-hrq4-ppwc-8jwx/GHSA-hrq4-ppwc-8jwx.json index 08992eca4ba..886c046ae23 100644 --- a/advisories/unreviewed/2022/07/GHSA-hrq4-ppwc-8jwx/GHSA-hrq4-ppwc-8jwx.json +++ b/advisories/unreviewed/2022/07/GHSA-hrq4-ppwc-8jwx/GHSA-hrq4-ppwc-8jwx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/07/GHSA-jh2c-mhx3-j74q/GHSA-jh2c-mhx3-j74q.json b/advisories/unreviewed/2022/07/GHSA-jh2c-mhx3-j74q/GHSA-jh2c-mhx3-j74q.json index d343c2f17cc..04cab3b4677 100644 --- a/advisories/unreviewed/2022/07/GHSA-jh2c-mhx3-j74q/GHSA-jh2c-mhx3-j74q.json +++ b/advisories/unreviewed/2022/07/GHSA-jh2c-mhx3-j74q/GHSA-jh2c-mhx3-j74q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/07/GHSA-jhvv-qgrh-gc45/GHSA-jhvv-qgrh-gc45.json b/advisories/unreviewed/2022/07/GHSA-jhvv-qgrh-gc45/GHSA-jhvv-qgrh-gc45.json index c29e572911d..7ed6c04383f 100644 --- a/advisories/unreviewed/2022/07/GHSA-jhvv-qgrh-gc45/GHSA-jhvv-qgrh-gc45.json +++ b/advisories/unreviewed/2022/07/GHSA-jhvv-qgrh-gc45/GHSA-jhvv-qgrh-gc45.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/07/GHSA-jjq6-7gx6-74fc/GHSA-jjq6-7gx6-74fc.json b/advisories/unreviewed/2022/07/GHSA-jjq6-7gx6-74fc/GHSA-jjq6-7gx6-74fc.json index 053876d9143..b46727901c7 100644 --- a/advisories/unreviewed/2022/07/GHSA-jjq6-7gx6-74fc/GHSA-jjq6-7gx6-74fc.json +++ b/advisories/unreviewed/2022/07/GHSA-jjq6-7gx6-74fc/GHSA-jjq6-7gx6-74fc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/07/GHSA-mgq5-593j-jv2x/GHSA-mgq5-593j-jv2x.json b/advisories/unreviewed/2022/07/GHSA-mgq5-593j-jv2x/GHSA-mgq5-593j-jv2x.json index a2b7dea60e6..0f29f094d5a 100644 --- a/advisories/unreviewed/2022/07/GHSA-mgq5-593j-jv2x/GHSA-mgq5-593j-jv2x.json +++ b/advisories/unreviewed/2022/07/GHSA-mgq5-593j-jv2x/GHSA-mgq5-593j-jv2x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/07/GHSA-mj46-hjj8-xr5c/GHSA-mj46-hjj8-xr5c.json b/advisories/unreviewed/2022/07/GHSA-mj46-hjj8-xr5c/GHSA-mj46-hjj8-xr5c.json index 94e79dae399..708971f2516 100644 --- a/advisories/unreviewed/2022/07/GHSA-mj46-hjj8-xr5c/GHSA-mj46-hjj8-xr5c.json +++ b/advisories/unreviewed/2022/07/GHSA-mj46-hjj8-xr5c/GHSA-mj46-hjj8-xr5c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/07/GHSA-mpv4-p366-wr6p/GHSA-mpv4-p366-wr6p.json b/advisories/unreviewed/2022/07/GHSA-mpv4-p366-wr6p/GHSA-mpv4-p366-wr6p.json index 79cca6020a3..d98c61500cc 100644 --- a/advisories/unreviewed/2022/07/GHSA-mpv4-p366-wr6p/GHSA-mpv4-p366-wr6p.json +++ b/advisories/unreviewed/2022/07/GHSA-mpv4-p366-wr6p/GHSA-mpv4-p366-wr6p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/07/GHSA-p7w2-cg47-7v79/GHSA-p7w2-cg47-7v79.json b/advisories/unreviewed/2022/07/GHSA-p7w2-cg47-7v79/GHSA-p7w2-cg47-7v79.json index 60ef1a81948..dd29dc2aa73 100644 --- a/advisories/unreviewed/2022/07/GHSA-p7w2-cg47-7v79/GHSA-p7w2-cg47-7v79.json +++ b/advisories/unreviewed/2022/07/GHSA-p7w2-cg47-7v79/GHSA-p7w2-cg47-7v79.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/07/GHSA-p954-47vj-3wxw/GHSA-p954-47vj-3wxw.json b/advisories/unreviewed/2022/07/GHSA-p954-47vj-3wxw/GHSA-p954-47vj-3wxw.json index ebdfdacaa14..79aa3f0fcc0 100644 --- a/advisories/unreviewed/2022/07/GHSA-p954-47vj-3wxw/GHSA-p954-47vj-3wxw.json +++ b/advisories/unreviewed/2022/07/GHSA-p954-47vj-3wxw/GHSA-p954-47vj-3wxw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/07/GHSA-pm9j-5fc9-5q4v/GHSA-pm9j-5fc9-5q4v.json b/advisories/unreviewed/2022/07/GHSA-pm9j-5fc9-5q4v/GHSA-pm9j-5fc9-5q4v.json index c1a73daa565..6cef464a88f 100644 --- a/advisories/unreviewed/2022/07/GHSA-pm9j-5fc9-5q4v/GHSA-pm9j-5fc9-5q4v.json +++ b/advisories/unreviewed/2022/07/GHSA-pm9j-5fc9-5q4v/GHSA-pm9j-5fc9-5q4v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/07/GHSA-pxvc-9m9j-4r9v/GHSA-pxvc-9m9j-4r9v.json b/advisories/unreviewed/2022/07/GHSA-pxvc-9m9j-4r9v/GHSA-pxvc-9m9j-4r9v.json index 756e0d17f6d..782b609f937 100644 --- a/advisories/unreviewed/2022/07/GHSA-pxvc-9m9j-4r9v/GHSA-pxvc-9m9j-4r9v.json +++ b/advisories/unreviewed/2022/07/GHSA-pxvc-9m9j-4r9v/GHSA-pxvc-9m9j-4r9v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/07/GHSA-qgc6-g85m-p5fg/GHSA-qgc6-g85m-p5fg.json b/advisories/unreviewed/2022/07/GHSA-qgc6-g85m-p5fg/GHSA-qgc6-g85m-p5fg.json index 5169993b966..85338338037 100644 --- a/advisories/unreviewed/2022/07/GHSA-qgc6-g85m-p5fg/GHSA-qgc6-g85m-p5fg.json +++ b/advisories/unreviewed/2022/07/GHSA-qgc6-g85m-p5fg/GHSA-qgc6-g85m-p5fg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/07/GHSA-r6jc-q7pg-2fgq/GHSA-r6jc-q7pg-2fgq.json b/advisories/unreviewed/2022/07/GHSA-r6jc-q7pg-2fgq/GHSA-r6jc-q7pg-2fgq.json index 2f31bc0282f..284d09d5ab3 100644 --- a/advisories/unreviewed/2022/07/GHSA-r6jc-q7pg-2fgq/GHSA-r6jc-q7pg-2fgq.json +++ b/advisories/unreviewed/2022/07/GHSA-r6jc-q7pg-2fgq/GHSA-r6jc-q7pg-2fgq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/07/GHSA-v3fp-j3f6-wq83/GHSA-v3fp-j3f6-wq83.json b/advisories/unreviewed/2022/07/GHSA-v3fp-j3f6-wq83/GHSA-v3fp-j3f6-wq83.json index 7cc74029fc7..63cbec2e5c7 100644 --- a/advisories/unreviewed/2022/07/GHSA-v3fp-j3f6-wq83/GHSA-v3fp-j3f6-wq83.json +++ b/advisories/unreviewed/2022/07/GHSA-v3fp-j3f6-wq83/GHSA-v3fp-j3f6-wq83.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/07/GHSA-w785-44wh-9wr3/GHSA-w785-44wh-9wr3.json b/advisories/unreviewed/2022/07/GHSA-w785-44wh-9wr3/GHSA-w785-44wh-9wr3.json index 64b965a8eb0..54100871f91 100644 --- a/advisories/unreviewed/2022/07/GHSA-w785-44wh-9wr3/GHSA-w785-44wh-9wr3.json +++ b/advisories/unreviewed/2022/07/GHSA-w785-44wh-9wr3/GHSA-w785-44wh-9wr3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/07/GHSA-wc5v-h4fq-4g72/GHSA-wc5v-h4fq-4g72.json b/advisories/unreviewed/2022/07/GHSA-wc5v-h4fq-4g72/GHSA-wc5v-h4fq-4g72.json index 49f5adf0f3e..f27d9c8eafd 100644 --- a/advisories/unreviewed/2022/07/GHSA-wc5v-h4fq-4g72/GHSA-wc5v-h4fq-4g72.json +++ b/advisories/unreviewed/2022/07/GHSA-wc5v-h4fq-4g72/GHSA-wc5v-h4fq-4g72.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/07/GHSA-x2fp-wfrh-r34v/GHSA-x2fp-wfrh-r34v.json b/advisories/unreviewed/2022/07/GHSA-x2fp-wfrh-r34v/GHSA-x2fp-wfrh-r34v.json index 080a0b22974..ca74e02cf45 100644 --- a/advisories/unreviewed/2022/07/GHSA-x2fp-wfrh-r34v/GHSA-x2fp-wfrh-r34v.json +++ b/advisories/unreviewed/2022/07/GHSA-x2fp-wfrh-r34v/GHSA-x2fp-wfrh-r34v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/07/GHSA-x3vr-wjhc-m9p7/GHSA-x3vr-wjhc-m9p7.json b/advisories/unreviewed/2022/07/GHSA-x3vr-wjhc-m9p7/GHSA-x3vr-wjhc-m9p7.json index f894c852941..6cb33a8fdb1 100644 --- a/advisories/unreviewed/2022/07/GHSA-x3vr-wjhc-m9p7/GHSA-x3vr-wjhc-m9p7.json +++ b/advisories/unreviewed/2022/07/GHSA-x3vr-wjhc-m9p7/GHSA-x3vr-wjhc-m9p7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/07/GHSA-x4q2-hpmw-6w22/GHSA-x4q2-hpmw-6w22.json b/advisories/unreviewed/2022/07/GHSA-x4q2-hpmw-6w22/GHSA-x4q2-hpmw-6w22.json index 25dffb84022..7c6ac4e0500 100644 --- a/advisories/unreviewed/2022/07/GHSA-x4q2-hpmw-6w22/GHSA-x4q2-hpmw-6w22.json +++ b/advisories/unreviewed/2022/07/GHSA-x4q2-hpmw-6w22/GHSA-x4q2-hpmw-6w22.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/07/GHSA-x5fh-pc22-3jcj/GHSA-x5fh-pc22-3jcj.json b/advisories/unreviewed/2022/07/GHSA-x5fh-pc22-3jcj/GHSA-x5fh-pc22-3jcj.json index 8e7bcce690e..faf8f1a035f 100644 --- a/advisories/unreviewed/2022/07/GHSA-x5fh-pc22-3jcj/GHSA-x5fh-pc22-3jcj.json +++ b/advisories/unreviewed/2022/07/GHSA-x5fh-pc22-3jcj/GHSA-x5fh-pc22-3jcj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/07/GHSA-xhv8-87mr-pw5r/GHSA-xhv8-87mr-pw5r.json b/advisories/unreviewed/2022/07/GHSA-xhv8-87mr-pw5r/GHSA-xhv8-87mr-pw5r.json index 75f474b50a8..a4c30e4f6a0 100644 --- a/advisories/unreviewed/2022/07/GHSA-xhv8-87mr-pw5r/GHSA-xhv8-87mr-pw5r.json +++ b/advisories/unreviewed/2022/07/GHSA-xhv8-87mr-pw5r/GHSA-xhv8-87mr-pw5r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/07/GHSA-xv4m-3w46-f9wh/GHSA-xv4m-3w46-f9wh.json b/advisories/unreviewed/2022/07/GHSA-xv4m-3w46-f9wh/GHSA-xv4m-3w46-f9wh.json index 71fd1d538ad..66b56859062 100644 --- a/advisories/unreviewed/2022/07/GHSA-xv4m-3w46-f9wh/GHSA-xv4m-3w46-f9wh.json +++ b/advisories/unreviewed/2022/07/GHSA-xv4m-3w46-f9wh/GHSA-xv4m-3w46-f9wh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/07/GHSA-xvf6-9729-5c9h/GHSA-xvf6-9729-5c9h.json b/advisories/unreviewed/2022/07/GHSA-xvf6-9729-5c9h/GHSA-xvf6-9729-5c9h.json index 0e4a55cac6a..cbed624b7c6 100644 --- a/advisories/unreviewed/2022/07/GHSA-xvf6-9729-5c9h/GHSA-xvf6-9729-5c9h.json +++ b/advisories/unreviewed/2022/07/GHSA-xvf6-9729-5c9h/GHSA-xvf6-9729-5c9h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/07/GHSA-xw3r-v728-68pj/GHSA-xw3r-v728-68pj.json b/advisories/unreviewed/2022/07/GHSA-xw3r-v728-68pj/GHSA-xw3r-v728-68pj.json index 7491e90f219..17f022b6828 100644 --- a/advisories/unreviewed/2022/07/GHSA-xw3r-v728-68pj/GHSA-xw3r-v728-68pj.json +++ b/advisories/unreviewed/2022/07/GHSA-xw3r-v728-68pj/GHSA-xw3r-v728-68pj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-2229-567x-2rpg/GHSA-2229-567x-2rpg.json b/advisories/unreviewed/2022/08/GHSA-2229-567x-2rpg/GHSA-2229-567x-2rpg.json index d2f3aab07cc..daeef9daa1a 100644 --- a/advisories/unreviewed/2022/08/GHSA-2229-567x-2rpg/GHSA-2229-567x-2rpg.json +++ b/advisories/unreviewed/2022/08/GHSA-2229-567x-2rpg/GHSA-2229-567x-2rpg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-2f8w-j2jp-gfr6/GHSA-2f8w-j2jp-gfr6.json b/advisories/unreviewed/2022/08/GHSA-2f8w-j2jp-gfr6/GHSA-2f8w-j2jp-gfr6.json index 4f8af635559..9b15ee13b57 100644 --- a/advisories/unreviewed/2022/08/GHSA-2f8w-j2jp-gfr6/GHSA-2f8w-j2jp-gfr6.json +++ b/advisories/unreviewed/2022/08/GHSA-2f8w-j2jp-gfr6/GHSA-2f8w-j2jp-gfr6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-2fxx-qc5h-894p/GHSA-2fxx-qc5h-894p.json b/advisories/unreviewed/2022/08/GHSA-2fxx-qc5h-894p/GHSA-2fxx-qc5h-894p.json index cd384014e30..f4b208797af 100644 --- a/advisories/unreviewed/2022/08/GHSA-2fxx-qc5h-894p/GHSA-2fxx-qc5h-894p.json +++ b/advisories/unreviewed/2022/08/GHSA-2fxx-qc5h-894p/GHSA-2fxx-qc5h-894p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-2prm-6mv4-wfqg/GHSA-2prm-6mv4-wfqg.json b/advisories/unreviewed/2022/08/GHSA-2prm-6mv4-wfqg/GHSA-2prm-6mv4-wfqg.json index abda6ab0623..523e8673741 100644 --- a/advisories/unreviewed/2022/08/GHSA-2prm-6mv4-wfqg/GHSA-2prm-6mv4-wfqg.json +++ b/advisories/unreviewed/2022/08/GHSA-2prm-6mv4-wfqg/GHSA-2prm-6mv4-wfqg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-3cp5-5cq5-76jp/GHSA-3cp5-5cq5-76jp.json b/advisories/unreviewed/2022/08/GHSA-3cp5-5cq5-76jp/GHSA-3cp5-5cq5-76jp.json index fa9d62bdcbc..ab1ab61b5fc 100644 --- a/advisories/unreviewed/2022/08/GHSA-3cp5-5cq5-76jp/GHSA-3cp5-5cq5-76jp.json +++ b/advisories/unreviewed/2022/08/GHSA-3cp5-5cq5-76jp/GHSA-3cp5-5cq5-76jp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-453h-cfq2-hp69/GHSA-453h-cfq2-hp69.json b/advisories/unreviewed/2022/08/GHSA-453h-cfq2-hp69/GHSA-453h-cfq2-hp69.json index b66baf1a604..2a7a0598d57 100644 --- a/advisories/unreviewed/2022/08/GHSA-453h-cfq2-hp69/GHSA-453h-cfq2-hp69.json +++ b/advisories/unreviewed/2022/08/GHSA-453h-cfq2-hp69/GHSA-453h-cfq2-hp69.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-4f7r-qw83-h4p8/GHSA-4f7r-qw83-h4p8.json b/advisories/unreviewed/2022/08/GHSA-4f7r-qw83-h4p8/GHSA-4f7r-qw83-h4p8.json index 82ad5a96199..0e95464cd52 100644 --- a/advisories/unreviewed/2022/08/GHSA-4f7r-qw83-h4p8/GHSA-4f7r-qw83-h4p8.json +++ b/advisories/unreviewed/2022/08/GHSA-4f7r-qw83-h4p8/GHSA-4f7r-qw83-h4p8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-5q68-9mm8-q9vm/GHSA-5q68-9mm8-q9vm.json b/advisories/unreviewed/2022/08/GHSA-5q68-9mm8-q9vm/GHSA-5q68-9mm8-q9vm.json index 7e0fda27542..62e31927c60 100644 --- a/advisories/unreviewed/2022/08/GHSA-5q68-9mm8-q9vm/GHSA-5q68-9mm8-q9vm.json +++ b/advisories/unreviewed/2022/08/GHSA-5q68-9mm8-q9vm/GHSA-5q68-9mm8-q9vm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-5vm6-mm87-jjv8/GHSA-5vm6-mm87-jjv8.json b/advisories/unreviewed/2022/08/GHSA-5vm6-mm87-jjv8/GHSA-5vm6-mm87-jjv8.json index 65372cc3e1b..5171dd9a8ca 100644 --- a/advisories/unreviewed/2022/08/GHSA-5vm6-mm87-jjv8/GHSA-5vm6-mm87-jjv8.json +++ b/advisories/unreviewed/2022/08/GHSA-5vm6-mm87-jjv8/GHSA-5vm6-mm87-jjv8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-5wpv-ch58-pr6r/GHSA-5wpv-ch58-pr6r.json b/advisories/unreviewed/2022/08/GHSA-5wpv-ch58-pr6r/GHSA-5wpv-ch58-pr6r.json index b6bad06a045..2bb9473a1ee 100644 --- a/advisories/unreviewed/2022/08/GHSA-5wpv-ch58-pr6r/GHSA-5wpv-ch58-pr6r.json +++ b/advisories/unreviewed/2022/08/GHSA-5wpv-ch58-pr6r/GHSA-5wpv-ch58-pr6r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-6ch7-g4hp-5567/GHSA-6ch7-g4hp-5567.json b/advisories/unreviewed/2022/08/GHSA-6ch7-g4hp-5567/GHSA-6ch7-g4hp-5567.json index f1b835139cf..a58049dce71 100644 --- a/advisories/unreviewed/2022/08/GHSA-6ch7-g4hp-5567/GHSA-6ch7-g4hp-5567.json +++ b/advisories/unreviewed/2022/08/GHSA-6ch7-g4hp-5567/GHSA-6ch7-g4hp-5567.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-6qmq-v879-phcg/GHSA-6qmq-v879-phcg.json b/advisories/unreviewed/2022/08/GHSA-6qmq-v879-phcg/GHSA-6qmq-v879-phcg.json index ea4abe15a2e..8959ac39dec 100644 --- a/advisories/unreviewed/2022/08/GHSA-6qmq-v879-phcg/GHSA-6qmq-v879-phcg.json +++ b/advisories/unreviewed/2022/08/GHSA-6qmq-v879-phcg/GHSA-6qmq-v879-phcg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-6r5h-x6qw-r3wc/GHSA-6r5h-x6qw-r3wc.json b/advisories/unreviewed/2022/08/GHSA-6r5h-x6qw-r3wc/GHSA-6r5h-x6qw-r3wc.json index 465cb53e40a..0461a695c54 100644 --- a/advisories/unreviewed/2022/08/GHSA-6r5h-x6qw-r3wc/GHSA-6r5h-x6qw-r3wc.json +++ b/advisories/unreviewed/2022/08/GHSA-6r5h-x6qw-r3wc/GHSA-6r5h-x6qw-r3wc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-795x-pw5q-vjfg/GHSA-795x-pw5q-vjfg.json b/advisories/unreviewed/2022/08/GHSA-795x-pw5q-vjfg/GHSA-795x-pw5q-vjfg.json index d80d476e85d..00d2a9a1c32 100644 --- a/advisories/unreviewed/2022/08/GHSA-795x-pw5q-vjfg/GHSA-795x-pw5q-vjfg.json +++ b/advisories/unreviewed/2022/08/GHSA-795x-pw5q-vjfg/GHSA-795x-pw5q-vjfg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-7cf7-6j23-48c5/GHSA-7cf7-6j23-48c5.json b/advisories/unreviewed/2022/08/GHSA-7cf7-6j23-48c5/GHSA-7cf7-6j23-48c5.json index 76cfa8c6d44..8157a4dc7f8 100644 --- a/advisories/unreviewed/2022/08/GHSA-7cf7-6j23-48c5/GHSA-7cf7-6j23-48c5.json +++ b/advisories/unreviewed/2022/08/GHSA-7cf7-6j23-48c5/GHSA-7cf7-6j23-48c5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-8m9f-86mh-w32q/GHSA-8m9f-86mh-w32q.json b/advisories/unreviewed/2022/08/GHSA-8m9f-86mh-w32q/GHSA-8m9f-86mh-w32q.json index 9367a286f83..7dddbc81489 100644 --- a/advisories/unreviewed/2022/08/GHSA-8m9f-86mh-w32q/GHSA-8m9f-86mh-w32q.json +++ b/advisories/unreviewed/2022/08/GHSA-8m9f-86mh-w32q/GHSA-8m9f-86mh-w32q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-8qq6-f3mx-chvf/GHSA-8qq6-f3mx-chvf.json b/advisories/unreviewed/2022/08/GHSA-8qq6-f3mx-chvf/GHSA-8qq6-f3mx-chvf.json index 0dbe58a0055..1ada1755d3d 100644 --- a/advisories/unreviewed/2022/08/GHSA-8qq6-f3mx-chvf/GHSA-8qq6-f3mx-chvf.json +++ b/advisories/unreviewed/2022/08/GHSA-8qq6-f3mx-chvf/GHSA-8qq6-f3mx-chvf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-8x77-rwjj-37f7/GHSA-8x77-rwjj-37f7.json b/advisories/unreviewed/2022/08/GHSA-8x77-rwjj-37f7/GHSA-8x77-rwjj-37f7.json index 821236a63f0..da542bc03d9 100644 --- a/advisories/unreviewed/2022/08/GHSA-8x77-rwjj-37f7/GHSA-8x77-rwjj-37f7.json +++ b/advisories/unreviewed/2022/08/GHSA-8x77-rwjj-37f7/GHSA-8x77-rwjj-37f7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-93wh-rmxq-9c3v/GHSA-93wh-rmxq-9c3v.json b/advisories/unreviewed/2022/08/GHSA-93wh-rmxq-9c3v/GHSA-93wh-rmxq-9c3v.json index 225b1f43633..933a9549674 100644 --- a/advisories/unreviewed/2022/08/GHSA-93wh-rmxq-9c3v/GHSA-93wh-rmxq-9c3v.json +++ b/advisories/unreviewed/2022/08/GHSA-93wh-rmxq-9c3v/GHSA-93wh-rmxq-9c3v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-9frc-28r7-wx7x/GHSA-9frc-28r7-wx7x.json b/advisories/unreviewed/2022/08/GHSA-9frc-28r7-wx7x/GHSA-9frc-28r7-wx7x.json index 1e21fe552dd..caad14f950a 100644 --- a/advisories/unreviewed/2022/08/GHSA-9frc-28r7-wx7x/GHSA-9frc-28r7-wx7x.json +++ b/advisories/unreviewed/2022/08/GHSA-9frc-28r7-wx7x/GHSA-9frc-28r7-wx7x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-9r23-xjjv-gr5j/GHSA-9r23-xjjv-gr5j.json b/advisories/unreviewed/2022/08/GHSA-9r23-xjjv-gr5j/GHSA-9r23-xjjv-gr5j.json index 4b35b16f586..0f02c1dc820 100644 --- a/advisories/unreviewed/2022/08/GHSA-9r23-xjjv-gr5j/GHSA-9r23-xjjv-gr5j.json +++ b/advisories/unreviewed/2022/08/GHSA-9r23-xjjv-gr5j/GHSA-9r23-xjjv-gr5j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-9wvv-chx5-pmx6/GHSA-9wvv-chx5-pmx6.json b/advisories/unreviewed/2022/08/GHSA-9wvv-chx5-pmx6/GHSA-9wvv-chx5-pmx6.json index 19c773db466..b7977711f08 100644 --- a/advisories/unreviewed/2022/08/GHSA-9wvv-chx5-pmx6/GHSA-9wvv-chx5-pmx6.json +++ b/advisories/unreviewed/2022/08/GHSA-9wvv-chx5-pmx6/GHSA-9wvv-chx5-pmx6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-c4xj-m5hq-4w5p/GHSA-c4xj-m5hq-4w5p.json b/advisories/unreviewed/2022/08/GHSA-c4xj-m5hq-4w5p/GHSA-c4xj-m5hq-4w5p.json index 5e24a752d89..b2a11067eb3 100644 --- a/advisories/unreviewed/2022/08/GHSA-c4xj-m5hq-4w5p/GHSA-c4xj-m5hq-4w5p.json +++ b/advisories/unreviewed/2022/08/GHSA-c4xj-m5hq-4w5p/GHSA-c4xj-m5hq-4w5p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-cfm6-wvm9-q3jc/GHSA-cfm6-wvm9-q3jc.json b/advisories/unreviewed/2022/08/GHSA-cfm6-wvm9-q3jc/GHSA-cfm6-wvm9-q3jc.json index 2651a06b317..8a313cb021d 100644 --- a/advisories/unreviewed/2022/08/GHSA-cfm6-wvm9-q3jc/GHSA-cfm6-wvm9-q3jc.json +++ b/advisories/unreviewed/2022/08/GHSA-cfm6-wvm9-q3jc/GHSA-cfm6-wvm9-q3jc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-cfq2-r39h-44gj/GHSA-cfq2-r39h-44gj.json b/advisories/unreviewed/2022/08/GHSA-cfq2-r39h-44gj/GHSA-cfq2-r39h-44gj.json index 2dd9f256d85..a0260579d18 100644 --- a/advisories/unreviewed/2022/08/GHSA-cfq2-r39h-44gj/GHSA-cfq2-r39h-44gj.json +++ b/advisories/unreviewed/2022/08/GHSA-cfq2-r39h-44gj/GHSA-cfq2-r39h-44gj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-cpfc-7gpf-g4m4/GHSA-cpfc-7gpf-g4m4.json b/advisories/unreviewed/2022/08/GHSA-cpfc-7gpf-g4m4/GHSA-cpfc-7gpf-g4m4.json index b5fcc8e75f9..186b91466e0 100644 --- a/advisories/unreviewed/2022/08/GHSA-cpfc-7gpf-g4m4/GHSA-cpfc-7gpf-g4m4.json +++ b/advisories/unreviewed/2022/08/GHSA-cpfc-7gpf-g4m4/GHSA-cpfc-7gpf-g4m4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-cvm5-7wp7-vfjv/GHSA-cvm5-7wp7-vfjv.json b/advisories/unreviewed/2022/08/GHSA-cvm5-7wp7-vfjv/GHSA-cvm5-7wp7-vfjv.json index 6914318963a..ebc368d9b80 100644 --- a/advisories/unreviewed/2022/08/GHSA-cvm5-7wp7-vfjv/GHSA-cvm5-7wp7-vfjv.json +++ b/advisories/unreviewed/2022/08/GHSA-cvm5-7wp7-vfjv/GHSA-cvm5-7wp7-vfjv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-fv39-4rvg-rg8j/GHSA-fv39-4rvg-rg8j.json b/advisories/unreviewed/2022/08/GHSA-fv39-4rvg-rg8j/GHSA-fv39-4rvg-rg8j.json index ea2b4bf1d26..c90ab87ba9c 100644 --- a/advisories/unreviewed/2022/08/GHSA-fv39-4rvg-rg8j/GHSA-fv39-4rvg-rg8j.json +++ b/advisories/unreviewed/2022/08/GHSA-fv39-4rvg-rg8j/GHSA-fv39-4rvg-rg8j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/08/GHSA-fv9h-9857-rhjv/GHSA-fv9h-9857-rhjv.json b/advisories/unreviewed/2022/08/GHSA-fv9h-9857-rhjv/GHSA-fv9h-9857-rhjv.json index 3a4bf847de4..4545e23d26e 100644 --- a/advisories/unreviewed/2022/08/GHSA-fv9h-9857-rhjv/GHSA-fv9h-9857-rhjv.json +++ b/advisories/unreviewed/2022/08/GHSA-fv9h-9857-rhjv/GHSA-fv9h-9857-rhjv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-g3w5-7c9w-jfrg/GHSA-g3w5-7c9w-jfrg.json b/advisories/unreviewed/2022/08/GHSA-g3w5-7c9w-jfrg/GHSA-g3w5-7c9w-jfrg.json index 9498453c82b..c969b3cb0d2 100644 --- a/advisories/unreviewed/2022/08/GHSA-g3w5-7c9w-jfrg/GHSA-g3w5-7c9w-jfrg.json +++ b/advisories/unreviewed/2022/08/GHSA-g3w5-7c9w-jfrg/GHSA-g3w5-7c9w-jfrg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-g97h-2vg2-chh8/GHSA-g97h-2vg2-chh8.json b/advisories/unreviewed/2022/08/GHSA-g97h-2vg2-chh8/GHSA-g97h-2vg2-chh8.json index a2ba05919d3..e1a7f662208 100644 --- a/advisories/unreviewed/2022/08/GHSA-g97h-2vg2-chh8/GHSA-g97h-2vg2-chh8.json +++ b/advisories/unreviewed/2022/08/GHSA-g97h-2vg2-chh8/GHSA-g97h-2vg2-chh8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-gg4h-m3jp-m2m9/GHSA-gg4h-m3jp-m2m9.json b/advisories/unreviewed/2022/08/GHSA-gg4h-m3jp-m2m9/GHSA-gg4h-m3jp-m2m9.json index 0b04085963e..5cde1303138 100644 --- a/advisories/unreviewed/2022/08/GHSA-gg4h-m3jp-m2m9/GHSA-gg4h-m3jp-m2m9.json +++ b/advisories/unreviewed/2022/08/GHSA-gg4h-m3jp-m2m9/GHSA-gg4h-m3jp-m2m9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-h5fr-p96x-74gc/GHSA-h5fr-p96x-74gc.json b/advisories/unreviewed/2022/08/GHSA-h5fr-p96x-74gc/GHSA-h5fr-p96x-74gc.json index 39950cce651..dd06a85acba 100644 --- a/advisories/unreviewed/2022/08/GHSA-h5fr-p96x-74gc/GHSA-h5fr-p96x-74gc.json +++ b/advisories/unreviewed/2022/08/GHSA-h5fr-p96x-74gc/GHSA-h5fr-p96x-74gc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-hfj7-fhvx-37c9/GHSA-hfj7-fhvx-37c9.json b/advisories/unreviewed/2022/08/GHSA-hfj7-fhvx-37c9/GHSA-hfj7-fhvx-37c9.json index f638b428224..1f27eaa350c 100644 --- a/advisories/unreviewed/2022/08/GHSA-hfj7-fhvx-37c9/GHSA-hfj7-fhvx-37c9.json +++ b/advisories/unreviewed/2022/08/GHSA-hfj7-fhvx-37c9/GHSA-hfj7-fhvx-37c9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-hmhj-c7jr-38rc/GHSA-hmhj-c7jr-38rc.json b/advisories/unreviewed/2022/08/GHSA-hmhj-c7jr-38rc/GHSA-hmhj-c7jr-38rc.json index cb6e652b3cf..410866691c9 100644 --- a/advisories/unreviewed/2022/08/GHSA-hmhj-c7jr-38rc/GHSA-hmhj-c7jr-38rc.json +++ b/advisories/unreviewed/2022/08/GHSA-hmhj-c7jr-38rc/GHSA-hmhj-c7jr-38rc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-hxfr-ccxh-4wcm/GHSA-hxfr-ccxh-4wcm.json b/advisories/unreviewed/2022/08/GHSA-hxfr-ccxh-4wcm/GHSA-hxfr-ccxh-4wcm.json index f8ca0312cf7..fa7df66cbd1 100644 --- a/advisories/unreviewed/2022/08/GHSA-hxfr-ccxh-4wcm/GHSA-hxfr-ccxh-4wcm.json +++ b/advisories/unreviewed/2022/08/GHSA-hxfr-ccxh-4wcm/GHSA-hxfr-ccxh-4wcm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-j2wv-pvcq-h7hf/GHSA-j2wv-pvcq-h7hf.json b/advisories/unreviewed/2022/08/GHSA-j2wv-pvcq-h7hf/GHSA-j2wv-pvcq-h7hf.json index f06f4500961..f9a1ce7c894 100644 --- a/advisories/unreviewed/2022/08/GHSA-j2wv-pvcq-h7hf/GHSA-j2wv-pvcq-h7hf.json +++ b/advisories/unreviewed/2022/08/GHSA-j2wv-pvcq-h7hf/GHSA-j2wv-pvcq-h7hf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-jjq3-r3c2-mg67/GHSA-jjq3-r3c2-mg67.json b/advisories/unreviewed/2022/08/GHSA-jjq3-r3c2-mg67/GHSA-jjq3-r3c2-mg67.json index 7409e6dcb05..da3cb263141 100644 --- a/advisories/unreviewed/2022/08/GHSA-jjq3-r3c2-mg67/GHSA-jjq3-r3c2-mg67.json +++ b/advisories/unreviewed/2022/08/GHSA-jjq3-r3c2-mg67/GHSA-jjq3-r3c2-mg67.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-m52f-f36p-hg3p/GHSA-m52f-f36p-hg3p.json b/advisories/unreviewed/2022/08/GHSA-m52f-f36p-hg3p/GHSA-m52f-f36p-hg3p.json index 6520a226d65..b300f5c41c8 100644 --- a/advisories/unreviewed/2022/08/GHSA-m52f-f36p-hg3p/GHSA-m52f-f36p-hg3p.json +++ b/advisories/unreviewed/2022/08/GHSA-m52f-f36p-hg3p/GHSA-m52f-f36p-hg3p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-mj97-cwp5-r4v9/GHSA-mj97-cwp5-r4v9.json b/advisories/unreviewed/2022/08/GHSA-mj97-cwp5-r4v9/GHSA-mj97-cwp5-r4v9.json index e252c79c090..a9d8c88c485 100644 --- a/advisories/unreviewed/2022/08/GHSA-mj97-cwp5-r4v9/GHSA-mj97-cwp5-r4v9.json +++ b/advisories/unreviewed/2022/08/GHSA-mj97-cwp5-r4v9/GHSA-mj97-cwp5-r4v9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/08/GHSA-mq2j-cpfc-hxfr/GHSA-mq2j-cpfc-hxfr.json b/advisories/unreviewed/2022/08/GHSA-mq2j-cpfc-hxfr/GHSA-mq2j-cpfc-hxfr.json index 53f54932cd9..0509584695b 100644 --- a/advisories/unreviewed/2022/08/GHSA-mq2j-cpfc-hxfr/GHSA-mq2j-cpfc-hxfr.json +++ b/advisories/unreviewed/2022/08/GHSA-mq2j-cpfc-hxfr/GHSA-mq2j-cpfc-hxfr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-p969-pj73-2v4g/GHSA-p969-pj73-2v4g.json b/advisories/unreviewed/2022/08/GHSA-p969-pj73-2v4g/GHSA-p969-pj73-2v4g.json index 0ac07f52866..5ba57e3c30c 100644 --- a/advisories/unreviewed/2022/08/GHSA-p969-pj73-2v4g/GHSA-p969-pj73-2v4g.json +++ b/advisories/unreviewed/2022/08/GHSA-p969-pj73-2v4g/GHSA-p969-pj73-2v4g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-pfjv-4pjm-jxhp/GHSA-pfjv-4pjm-jxhp.json b/advisories/unreviewed/2022/08/GHSA-pfjv-4pjm-jxhp/GHSA-pfjv-4pjm-jxhp.json index 2331038997f..5706b2ebd86 100644 --- a/advisories/unreviewed/2022/08/GHSA-pfjv-4pjm-jxhp/GHSA-pfjv-4pjm-jxhp.json +++ b/advisories/unreviewed/2022/08/GHSA-pfjv-4pjm-jxhp/GHSA-pfjv-4pjm-jxhp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/08/GHSA-qqwr-rxh6-7p7g/GHSA-qqwr-rxh6-7p7g.json b/advisories/unreviewed/2022/08/GHSA-qqwr-rxh6-7p7g/GHSA-qqwr-rxh6-7p7g.json index afe27d8b775..c72d0001909 100644 --- a/advisories/unreviewed/2022/08/GHSA-qqwr-rxh6-7p7g/GHSA-qqwr-rxh6-7p7g.json +++ b/advisories/unreviewed/2022/08/GHSA-qqwr-rxh6-7p7g/GHSA-qqwr-rxh6-7p7g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-r3qq-qfww-5775/GHSA-r3qq-qfww-5775.json b/advisories/unreviewed/2022/08/GHSA-r3qq-qfww-5775/GHSA-r3qq-qfww-5775.json index 153bb19e388..f9b49adf372 100644 --- a/advisories/unreviewed/2022/08/GHSA-r3qq-qfww-5775/GHSA-r3qq-qfww-5775.json +++ b/advisories/unreviewed/2022/08/GHSA-r3qq-qfww-5775/GHSA-r3qq-qfww-5775.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-r4hj-g29h-cqwr/GHSA-r4hj-g29h-cqwr.json b/advisories/unreviewed/2022/08/GHSA-r4hj-g29h-cqwr/GHSA-r4hj-g29h-cqwr.json index 40c78535146..15bc31e6f31 100644 --- a/advisories/unreviewed/2022/08/GHSA-r4hj-g29h-cqwr/GHSA-r4hj-g29h-cqwr.json +++ b/advisories/unreviewed/2022/08/GHSA-r4hj-g29h-cqwr/GHSA-r4hj-g29h-cqwr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-rqw2-649f-4qrh/GHSA-rqw2-649f-4qrh.json b/advisories/unreviewed/2022/08/GHSA-rqw2-649f-4qrh/GHSA-rqw2-649f-4qrh.json index 4dcd536b787..4a60fa7e131 100644 --- a/advisories/unreviewed/2022/08/GHSA-rqw2-649f-4qrh/GHSA-rqw2-649f-4qrh.json +++ b/advisories/unreviewed/2022/08/GHSA-rqw2-649f-4qrh/GHSA-rqw2-649f-4qrh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-rrp2-7qrr-978x/GHSA-rrp2-7qrr-978x.json b/advisories/unreviewed/2022/08/GHSA-rrp2-7qrr-978x/GHSA-rrp2-7qrr-978x.json index 0f4bc011a83..d590498610f 100644 --- a/advisories/unreviewed/2022/08/GHSA-rrp2-7qrr-978x/GHSA-rrp2-7qrr-978x.json +++ b/advisories/unreviewed/2022/08/GHSA-rrp2-7qrr-978x/GHSA-rrp2-7qrr-978x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-w33j-4mrg-pgc3/GHSA-w33j-4mrg-pgc3.json b/advisories/unreviewed/2022/08/GHSA-w33j-4mrg-pgc3/GHSA-w33j-4mrg-pgc3.json index 70488a4d02b..7fe0b3d2c6a 100644 --- a/advisories/unreviewed/2022/08/GHSA-w33j-4mrg-pgc3/GHSA-w33j-4mrg-pgc3.json +++ b/advisories/unreviewed/2022/08/GHSA-w33j-4mrg-pgc3/GHSA-w33j-4mrg-pgc3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-wc5h-762j-w3cx/GHSA-wc5h-762j-w3cx.json b/advisories/unreviewed/2022/08/GHSA-wc5h-762j-w3cx/GHSA-wc5h-762j-w3cx.json index 931a93f6732..16e12355fb9 100644 --- a/advisories/unreviewed/2022/08/GHSA-wc5h-762j-w3cx/GHSA-wc5h-762j-w3cx.json +++ b/advisories/unreviewed/2022/08/GHSA-wc5h-762j-w3cx/GHSA-wc5h-762j-w3cx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-wfmp-7523-fp53/GHSA-wfmp-7523-fp53.json b/advisories/unreviewed/2022/08/GHSA-wfmp-7523-fp53/GHSA-wfmp-7523-fp53.json index 5e4c91852c6..a16bde9a849 100644 --- a/advisories/unreviewed/2022/08/GHSA-wfmp-7523-fp53/GHSA-wfmp-7523-fp53.json +++ b/advisories/unreviewed/2022/08/GHSA-wfmp-7523-fp53/GHSA-wfmp-7523-fp53.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-wgj9-5g45-4hmx/GHSA-wgj9-5g45-4hmx.json b/advisories/unreviewed/2022/08/GHSA-wgj9-5g45-4hmx/GHSA-wgj9-5g45-4hmx.json index 33a49334faf..3df40f6a074 100644 --- a/advisories/unreviewed/2022/08/GHSA-wgj9-5g45-4hmx/GHSA-wgj9-5g45-4hmx.json +++ b/advisories/unreviewed/2022/08/GHSA-wgj9-5g45-4hmx/GHSA-wgj9-5g45-4hmx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-wp8p-fcqc-823w/GHSA-wp8p-fcqc-823w.json b/advisories/unreviewed/2022/08/GHSA-wp8p-fcqc-823w/GHSA-wp8p-fcqc-823w.json index 71ddf2a7059..44f606761b4 100644 --- a/advisories/unreviewed/2022/08/GHSA-wp8p-fcqc-823w/GHSA-wp8p-fcqc-823w.json +++ b/advisories/unreviewed/2022/08/GHSA-wp8p-fcqc-823w/GHSA-wp8p-fcqc-823w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-wv67-wqcj-jqr4/GHSA-wv67-wqcj-jqr4.json b/advisories/unreviewed/2022/08/GHSA-wv67-wqcj-jqr4/GHSA-wv67-wqcj-jqr4.json index 79179ed6fad..7d89be578b0 100644 --- a/advisories/unreviewed/2022/08/GHSA-wv67-wqcj-jqr4/GHSA-wv67-wqcj-jqr4.json +++ b/advisories/unreviewed/2022/08/GHSA-wv67-wqcj-jqr4/GHSA-wv67-wqcj-jqr4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-x37j-vhv4-hhjm/GHSA-x37j-vhv4-hhjm.json b/advisories/unreviewed/2022/08/GHSA-x37j-vhv4-hhjm/GHSA-x37j-vhv4-hhjm.json index b41b075ca7d..10c333b5742 100644 --- a/advisories/unreviewed/2022/08/GHSA-x37j-vhv4-hhjm/GHSA-x37j-vhv4-hhjm.json +++ b/advisories/unreviewed/2022/08/GHSA-x37j-vhv4-hhjm/GHSA-x37j-vhv4-hhjm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-x68h-gr54-m2h8/GHSA-x68h-gr54-m2h8.json b/advisories/unreviewed/2022/08/GHSA-x68h-gr54-m2h8/GHSA-x68h-gr54-m2h8.json index 313be0da5ad..0c77394c23f 100644 --- a/advisories/unreviewed/2022/08/GHSA-x68h-gr54-m2h8/GHSA-x68h-gr54-m2h8.json +++ b/advisories/unreviewed/2022/08/GHSA-x68h-gr54-m2h8/GHSA-x68h-gr54-m2h8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-xgvh-4wv3-f5h2/GHSA-xgvh-4wv3-f5h2.json b/advisories/unreviewed/2022/08/GHSA-xgvh-4wv3-f5h2/GHSA-xgvh-4wv3-f5h2.json index b355dba5ca8..5a3303fcf91 100644 --- a/advisories/unreviewed/2022/08/GHSA-xgvh-4wv3-f5h2/GHSA-xgvh-4wv3-f5h2.json +++ b/advisories/unreviewed/2022/08/GHSA-xgvh-4wv3-f5h2/GHSA-xgvh-4wv3-f5h2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-2c78-596m-9g6p/GHSA-2c78-596m-9g6p.json b/advisories/unreviewed/2024/03/GHSA-2c78-596m-9g6p/GHSA-2c78-596m-9g6p.json index 56cd43a9cab..c17fb2d0d85 100644 --- a/advisories/unreviewed/2024/03/GHSA-2c78-596m-9g6p/GHSA-2c78-596m-9g6p.json +++ b/advisories/unreviewed/2024/03/GHSA-2c78-596m-9g6p/GHSA-2c78-596m-9g6p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-2fjx-8hxj-4456/GHSA-2fjx-8hxj-4456.json b/advisories/unreviewed/2024/03/GHSA-2fjx-8hxj-4456/GHSA-2fjx-8hxj-4456.json index cd622334201..365edde35c3 100644 --- a/advisories/unreviewed/2024/03/GHSA-2fjx-8hxj-4456/GHSA-2fjx-8hxj-4456.json +++ b/advisories/unreviewed/2024/03/GHSA-2fjx-8hxj-4456/GHSA-2fjx-8hxj-4456.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-3x3h-fcc9-p4px/GHSA-3x3h-fcc9-p4px.json b/advisories/unreviewed/2024/03/GHSA-3x3h-fcc9-p4px/GHSA-3x3h-fcc9-p4px.json index aacd8b1d9be..8c92fe01d2d 100644 --- a/advisories/unreviewed/2024/03/GHSA-3x3h-fcc9-p4px/GHSA-3x3h-fcc9-p4px.json +++ b/advisories/unreviewed/2024/03/GHSA-3x3h-fcc9-p4px/GHSA-3x3h-fcc9-p4px.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-4hww-mcvx-h475/GHSA-4hww-mcvx-h475.json b/advisories/unreviewed/2024/03/GHSA-4hww-mcvx-h475/GHSA-4hww-mcvx-h475.json index 1e36ea23f61..c02d60bdde8 100644 --- a/advisories/unreviewed/2024/03/GHSA-4hww-mcvx-h475/GHSA-4hww-mcvx-h475.json +++ b/advisories/unreviewed/2024/03/GHSA-4hww-mcvx-h475/GHSA-4hww-mcvx-h475.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-4q5q-v9v4-9c33/GHSA-4q5q-v9v4-9c33.json b/advisories/unreviewed/2024/03/GHSA-4q5q-v9v4-9c33/GHSA-4q5q-v9v4-9c33.json index fd7090b5da5..272aa95beec 100644 --- a/advisories/unreviewed/2024/03/GHSA-4q5q-v9v4-9c33/GHSA-4q5q-v9v4-9c33.json +++ b/advisories/unreviewed/2024/03/GHSA-4q5q-v9v4-9c33/GHSA-4q5q-v9v4-9c33.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-5c87-f5rm-hwpp/GHSA-5c87-f5rm-hwpp.json b/advisories/unreviewed/2024/03/GHSA-5c87-f5rm-hwpp/GHSA-5c87-f5rm-hwpp.json index 70221141482..99127ca8703 100644 --- a/advisories/unreviewed/2024/03/GHSA-5c87-f5rm-hwpp/GHSA-5c87-f5rm-hwpp.json +++ b/advisories/unreviewed/2024/03/GHSA-5c87-f5rm-hwpp/GHSA-5c87-f5rm-hwpp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-5gww-24v3-qcfw/GHSA-5gww-24v3-qcfw.json b/advisories/unreviewed/2024/03/GHSA-5gww-24v3-qcfw/GHSA-5gww-24v3-qcfw.json index 6ce3d294da0..2258c7fd09f 100644 --- a/advisories/unreviewed/2024/03/GHSA-5gww-24v3-qcfw/GHSA-5gww-24v3-qcfw.json +++ b/advisories/unreviewed/2024/03/GHSA-5gww-24v3-qcfw/GHSA-5gww-24v3-qcfw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-95jq-jh69-72cq/GHSA-95jq-jh69-72cq.json b/advisories/unreviewed/2024/03/GHSA-95jq-jh69-72cq/GHSA-95jq-jh69-72cq.json index 2309a944ad1..98e5b8ddc25 100644 --- a/advisories/unreviewed/2024/03/GHSA-95jq-jh69-72cq/GHSA-95jq-jh69-72cq.json +++ b/advisories/unreviewed/2024/03/GHSA-95jq-jh69-72cq/GHSA-95jq-jh69-72cq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-f2p5-3c35-8j2x/GHSA-f2p5-3c35-8j2x.json b/advisories/unreviewed/2024/03/GHSA-f2p5-3c35-8j2x/GHSA-f2p5-3c35-8j2x.json index ff5390e2b3b..f915180fb5b 100644 --- a/advisories/unreviewed/2024/03/GHSA-f2p5-3c35-8j2x/GHSA-f2p5-3c35-8j2x.json +++ b/advisories/unreviewed/2024/03/GHSA-f2p5-3c35-8j2x/GHSA-f2p5-3c35-8j2x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-fm4v-hxhr-prfx/GHSA-fm4v-hxhr-prfx.json b/advisories/unreviewed/2024/03/GHSA-fm4v-hxhr-prfx/GHSA-fm4v-hxhr-prfx.json index cefd05652c0..ae7142b0fce 100644 --- a/advisories/unreviewed/2024/03/GHSA-fm4v-hxhr-prfx/GHSA-fm4v-hxhr-prfx.json +++ b/advisories/unreviewed/2024/03/GHSA-fm4v-hxhr-prfx/GHSA-fm4v-hxhr-prfx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-g43f-xr59-68c4/GHSA-g43f-xr59-68c4.json b/advisories/unreviewed/2024/03/GHSA-g43f-xr59-68c4/GHSA-g43f-xr59-68c4.json index 4433efae95c..77ae543e1e9 100644 --- a/advisories/unreviewed/2024/03/GHSA-g43f-xr59-68c4/GHSA-g43f-xr59-68c4.json +++ b/advisories/unreviewed/2024/03/GHSA-g43f-xr59-68c4/GHSA-g43f-xr59-68c4.json @@ -7,12 +7,8 @@ "CVE-2024-28090" ], "details": "Technicolor TC8715D TC8715D-01.EF.04.38.00-180405-S-FF9-D RSE-TC8717T devices allow a remote attacker within Wi-Fi proximity to conduct stored XSS attacks via User name in dyn_dns.asp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-hh25-cvgx-xhwx/GHSA-hh25-cvgx-xhwx.json b/advisories/unreviewed/2024/03/GHSA-hh25-cvgx-xhwx/GHSA-hh25-cvgx-xhwx.json index a767a61d4c3..4ce8983834d 100644 --- a/advisories/unreviewed/2024/03/GHSA-hh25-cvgx-xhwx/GHSA-hh25-cvgx-xhwx.json +++ b/advisories/unreviewed/2024/03/GHSA-hh25-cvgx-xhwx/GHSA-hh25-cvgx-xhwx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-j9cj-hqr5-3wcm/GHSA-j9cj-hqr5-3wcm.json b/advisories/unreviewed/2024/03/GHSA-j9cj-hqr5-3wcm/GHSA-j9cj-hqr5-3wcm.json index 0f309b8359c..d2eb0ff0199 100644 --- a/advisories/unreviewed/2024/03/GHSA-j9cj-hqr5-3wcm/GHSA-j9cj-hqr5-3wcm.json +++ b/advisories/unreviewed/2024/03/GHSA-j9cj-hqr5-3wcm/GHSA-j9cj-hqr5-3wcm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-jgcq-59jx-w43v/GHSA-jgcq-59jx-w43v.json b/advisories/unreviewed/2024/03/GHSA-jgcq-59jx-w43v/GHSA-jgcq-59jx-w43v.json index 84ad96d59b5..bc4f92e8448 100644 --- a/advisories/unreviewed/2024/03/GHSA-jgcq-59jx-w43v/GHSA-jgcq-59jx-w43v.json +++ b/advisories/unreviewed/2024/03/GHSA-jgcq-59jx-w43v/GHSA-jgcq-59jx-w43v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-jpx5-qv8q-fwxp/GHSA-jpx5-qv8q-fwxp.json b/advisories/unreviewed/2024/03/GHSA-jpx5-qv8q-fwxp/GHSA-jpx5-qv8q-fwxp.json index 8be4e0da94a..e2a21b00d3f 100644 --- a/advisories/unreviewed/2024/03/GHSA-jpx5-qv8q-fwxp/GHSA-jpx5-qv8q-fwxp.json +++ b/advisories/unreviewed/2024/03/GHSA-jpx5-qv8q-fwxp/GHSA-jpx5-qv8q-fwxp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-p65p-h8xw-f45x/GHSA-p65p-h8xw-f45x.json b/advisories/unreviewed/2024/03/GHSA-p65p-h8xw-f45x/GHSA-p65p-h8xw-f45x.json index 514f5f0aea3..032dc93eaba 100644 --- a/advisories/unreviewed/2024/03/GHSA-p65p-h8xw-f45x/GHSA-p65p-h8xw-f45x.json +++ b/advisories/unreviewed/2024/03/GHSA-p65p-h8xw-f45x/GHSA-p65p-h8xw-f45x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-pp7c-r283-qv76/GHSA-pp7c-r283-qv76.json b/advisories/unreviewed/2024/03/GHSA-pp7c-r283-qv76/GHSA-pp7c-r283-qv76.json index 0089328dfa9..4741f06ada2 100644 --- a/advisories/unreviewed/2024/03/GHSA-pp7c-r283-qv76/GHSA-pp7c-r283-qv76.json +++ b/advisories/unreviewed/2024/03/GHSA-pp7c-r283-qv76/GHSA-pp7c-r283-qv76.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-r2p4-xrgf-rxrx/GHSA-r2p4-xrgf-rxrx.json b/advisories/unreviewed/2024/03/GHSA-r2p4-xrgf-rxrx/GHSA-r2p4-xrgf-rxrx.json index 943f39e00ab..8a84d7244c3 100644 --- a/advisories/unreviewed/2024/03/GHSA-r2p4-xrgf-rxrx/GHSA-r2p4-xrgf-rxrx.json +++ b/advisories/unreviewed/2024/03/GHSA-r2p4-xrgf-rxrx/GHSA-r2p4-xrgf-rxrx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-rpvr-xch8-v9v3/GHSA-rpvr-xch8-v9v3.json b/advisories/unreviewed/2024/03/GHSA-rpvr-xch8-v9v3/GHSA-rpvr-xch8-v9v3.json index f4c6452106d..9ddb602411e 100644 --- a/advisories/unreviewed/2024/03/GHSA-rpvr-xch8-v9v3/GHSA-rpvr-xch8-v9v3.json +++ b/advisories/unreviewed/2024/03/GHSA-rpvr-xch8-v9v3/GHSA-rpvr-xch8-v9v3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-rvqv-q989-mj4r/GHSA-rvqv-q989-mj4r.json b/advisories/unreviewed/2024/03/GHSA-rvqv-q989-mj4r/GHSA-rvqv-q989-mj4r.json index 912c7751512..bafd8457358 100644 --- a/advisories/unreviewed/2024/03/GHSA-rvqv-q989-mj4r/GHSA-rvqv-q989-mj4r.json +++ b/advisories/unreviewed/2024/03/GHSA-rvqv-q989-mj4r/GHSA-rvqv-q989-mj4r.json @@ -7,12 +7,8 @@ "CVE-2023-25341" ], "details": "A Directory Traversal vulnerability in ladle dev server 2.5.1 and earlier allows an attacker on the same network to read files accessible to the user via GET requests.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-vx4h-fxv4-24pq/GHSA-vx4h-fxv4-24pq.json b/advisories/unreviewed/2024/03/GHSA-vx4h-fxv4-24pq/GHSA-vx4h-fxv4-24pq.json index 591ab82e204..9eb3bcb812e 100644 --- a/advisories/unreviewed/2024/03/GHSA-vx4h-fxv4-24pq/GHSA-vx4h-fxv4-24pq.json +++ b/advisories/unreviewed/2024/03/GHSA-vx4h-fxv4-24pq/GHSA-vx4h-fxv4-24pq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-wfvh-v5x6-6v43/GHSA-wfvh-v5x6-6v43.json b/advisories/unreviewed/2024/03/GHSA-wfvh-v5x6-6v43/GHSA-wfvh-v5x6-6v43.json index 2cb737b4308..3450679ad98 100644 --- a/advisories/unreviewed/2024/03/GHSA-wfvh-v5x6-6v43/GHSA-wfvh-v5x6-6v43.json +++ b/advisories/unreviewed/2024/03/GHSA-wfvh-v5x6-6v43/GHSA-wfvh-v5x6-6v43.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-wwmq-47hw-c7vw/GHSA-wwmq-47hw-c7vw.json b/advisories/unreviewed/2024/03/GHSA-wwmq-47hw-c7vw/GHSA-wwmq-47hw-c7vw.json index d3f22bea529..5b692a2b726 100644 --- a/advisories/unreviewed/2024/03/GHSA-wwmq-47hw-c7vw/GHSA-wwmq-47hw-c7vw.json +++ b/advisories/unreviewed/2024/03/GHSA-wwmq-47hw-c7vw/GHSA-wwmq-47hw-c7vw.json @@ -7,12 +7,8 @@ "CVE-2023-33528" ], "details": "halo v1.6.0 is vulnerable to Cross Site Scripting (XSS).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-562h-465j-vfp9/GHSA-562h-465j-vfp9.json b/advisories/unreviewed/2024/04/GHSA-562h-465j-vfp9/GHSA-562h-465j-vfp9.json index c483a19a2ef..492af4003a2 100644 --- a/advisories/unreviewed/2024/04/GHSA-562h-465j-vfp9/GHSA-562h-465j-vfp9.json +++ b/advisories/unreviewed/2024/04/GHSA-562h-465j-vfp9/GHSA-562h-465j-vfp9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-gm33-c2ph-c6cj/GHSA-gm33-c2ph-c6cj.json b/advisories/unreviewed/2024/04/GHSA-gm33-c2ph-c6cj/GHSA-gm33-c2ph-c6cj.json index 7aa6110ef30..2c2d9e01f9a 100644 --- a/advisories/unreviewed/2024/04/GHSA-gm33-c2ph-c6cj/GHSA-gm33-c2ph-c6cj.json +++ b/advisories/unreviewed/2024/04/GHSA-gm33-c2ph-c6cj/GHSA-gm33-c2ph-c6cj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-jc42-r5p9-j2vr/GHSA-jc42-r5p9-j2vr.json b/advisories/unreviewed/2024/04/GHSA-jc42-r5p9-j2vr/GHSA-jc42-r5p9-j2vr.json index 0c59a6d961c..3e663fb5997 100644 --- a/advisories/unreviewed/2024/04/GHSA-jc42-r5p9-j2vr/GHSA-jc42-r5p9-j2vr.json +++ b/advisories/unreviewed/2024/04/GHSA-jc42-r5p9-j2vr/GHSA-jc42-r5p9-j2vr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-p68r-f2j8-7389/GHSA-p68r-f2j8-7389.json b/advisories/unreviewed/2024/04/GHSA-p68r-f2j8-7389/GHSA-p68r-f2j8-7389.json index e601df8498f..d2ca422e25d 100644 --- a/advisories/unreviewed/2024/04/GHSA-p68r-f2j8-7389/GHSA-p68r-f2j8-7389.json +++ b/advisories/unreviewed/2024/04/GHSA-p68r-f2j8-7389/GHSA-p68r-f2j8-7389.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-rgqw-g866-w59h/GHSA-rgqw-g866-w59h.json b/advisories/unreviewed/2024/04/GHSA-rgqw-g866-w59h/GHSA-rgqw-g866-w59h.json index a25b3427b57..9ba5d1c2397 100644 --- a/advisories/unreviewed/2024/04/GHSA-rgqw-g866-w59h/GHSA-rgqw-g866-w59h.json +++ b/advisories/unreviewed/2024/04/GHSA-rgqw-g866-w59h/GHSA-rgqw-g866-w59h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-x6g6-grg7-wwcp/GHSA-x6g6-grg7-wwcp.json b/advisories/unreviewed/2024/04/GHSA-x6g6-grg7-wwcp/GHSA-x6g6-grg7-wwcp.json index c2a62104010..e171f3dd2f7 100644 --- a/advisories/unreviewed/2024/04/GHSA-x6g6-grg7-wwcp/GHSA-x6g6-grg7-wwcp.json +++ b/advisories/unreviewed/2024/04/GHSA-x6g6-grg7-wwcp/GHSA-x6g6-grg7-wwcp.json @@ -7,12 +7,8 @@ "CVE-2024-26905" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix data races when accessing the reserved amount of block reserves\n\nAt space_info.c we have several places where we access the ->reserved\nfield of a block reserve without taking the block reserve's spinlock\nfirst, which makes KCSAN warn about a data race since that field is\nalways updated while holding the spinlock.\n\nThe reports from KCSAN are like the following:\n\n [117.193526] BUG: KCSAN: data-race in btrfs_block_rsv_release [btrfs] / need_preemptive_reclaim [btrfs]\n\n [117.195148] read to 0x000000017f587190 of 8 bytes by task 6303 on cpu 3:\n [117.195172] need_preemptive_reclaim+0x222/0x2f0 [btrfs]\n [117.195992] __reserve_bytes+0xbb0/0xdc8 [btrfs]\n [117.196807] btrfs_reserve_metadata_bytes+0x4c/0x120 [btrfs]\n [117.197620] btrfs_block_rsv_add+0x78/0xa8 [btrfs]\n [117.198434] btrfs_delayed_update_inode+0x154/0x368 [btrfs]\n [117.199300] btrfs_update_inode+0x108/0x1c8 [btrfs]\n [117.200122] btrfs_dirty_inode+0xb4/0x140 [btrfs]\n [117.200937] btrfs_update_time+0x8c/0xb0 [btrfs]\n [117.201754] touch_atime+0x16c/0x1e0\n [117.201789] filemap_read+0x674/0x728\n [117.201823] btrfs_file_read_iter+0xf8/0x410 [btrfs]\n [117.202653] vfs_read+0x2b6/0x498\n [117.203454] ksys_read+0xa2/0x150\n [117.203473] __s390x_sys_read+0x68/0x88\n [117.203495] do_syscall+0x1c6/0x210\n [117.203517] __do_syscall+0xc8/0xf0\n [117.203539] system_call+0x70/0x98\n\n [117.203579] write to 0x000000017f587190 of 8 bytes by task 11 on cpu 0:\n [117.203604] btrfs_block_rsv_release+0x2e8/0x578 [btrfs]\n [117.204432] btrfs_delayed_inode_release_metadata+0x7c/0x1d0 [btrfs]\n [117.205259] __btrfs_update_delayed_inode+0x37c/0x5e0 [btrfs]\n [117.206093] btrfs_async_run_delayed_root+0x356/0x498 [btrfs]\n [117.206917] btrfs_work_helper+0x160/0x7a0 [btrfs]\n [117.207738] process_one_work+0x3b6/0x838\n [117.207768] worker_thread+0x75e/0xb10\n [117.207797] kthread+0x21a/0x230\n [117.207830] __ret_from_fork+0x6c/0xb8\n [117.207861] ret_from_fork+0xa/0x30\n\nSo add a helper to get the reserved amount of a block reserve while\nholding the lock. The value may be not be up to date anymore when used by\nneed_preemptive_reclaim() and btrfs_preempt_reclaim_metadata_space(), but\nthat's ok since the worst it can do is cause more reclaim work do be done\nsooner rather than later. Reading the field while holding the lock instead\nof using the data_race() annotation is used in order to prevent load\ntearing.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-29pr-hmrg-229w/GHSA-29pr-hmrg-229w.json b/advisories/unreviewed/2024/05/GHSA-29pr-hmrg-229w/GHSA-29pr-hmrg-229w.json index 400e459acd0..3622f36025b 100644 --- a/advisories/unreviewed/2024/05/GHSA-29pr-hmrg-229w/GHSA-29pr-hmrg-229w.json +++ b/advisories/unreviewed/2024/05/GHSA-29pr-hmrg-229w/GHSA-29pr-hmrg-229w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-2gq8-95rw-4qg8/GHSA-2gq8-95rw-4qg8.json b/advisories/unreviewed/2024/05/GHSA-2gq8-95rw-4qg8/GHSA-2gq8-95rw-4qg8.json index ed740ca4813..f958c16cca9 100644 --- a/advisories/unreviewed/2024/05/GHSA-2gq8-95rw-4qg8/GHSA-2gq8-95rw-4qg8.json +++ b/advisories/unreviewed/2024/05/GHSA-2gq8-95rw-4qg8/GHSA-2gq8-95rw-4qg8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-2m46-rjm4-w49x/GHSA-2m46-rjm4-w49x.json b/advisories/unreviewed/2024/05/GHSA-2m46-rjm4-w49x/GHSA-2m46-rjm4-w49x.json index ba26b65df46..2bb9bdfbc06 100644 --- a/advisories/unreviewed/2024/05/GHSA-2m46-rjm4-w49x/GHSA-2m46-rjm4-w49x.json +++ b/advisories/unreviewed/2024/05/GHSA-2m46-rjm4-w49x/GHSA-2m46-rjm4-w49x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-2m7m-jhx5-8crh/GHSA-2m7m-jhx5-8crh.json b/advisories/unreviewed/2024/05/GHSA-2m7m-jhx5-8crh/GHSA-2m7m-jhx5-8crh.json index fcecb0e7857..c64235700e6 100644 --- a/advisories/unreviewed/2024/05/GHSA-2m7m-jhx5-8crh/GHSA-2m7m-jhx5-8crh.json +++ b/advisories/unreviewed/2024/05/GHSA-2m7m-jhx5-8crh/GHSA-2m7m-jhx5-8crh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-2qcp-f55j-r9qj/GHSA-2qcp-f55j-r9qj.json b/advisories/unreviewed/2024/05/GHSA-2qcp-f55j-r9qj/GHSA-2qcp-f55j-r9qj.json index 843a4657a9b..cfc2a606011 100644 --- a/advisories/unreviewed/2024/05/GHSA-2qcp-f55j-r9qj/GHSA-2qcp-f55j-r9qj.json +++ b/advisories/unreviewed/2024/05/GHSA-2qcp-f55j-r9qj/GHSA-2qcp-f55j-r9qj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-2qj7-3x7p-9jgf/GHSA-2qj7-3x7p-9jgf.json b/advisories/unreviewed/2024/05/GHSA-2qj7-3x7p-9jgf/GHSA-2qj7-3x7p-9jgf.json index acffc903108..81f7e536e5b 100644 --- a/advisories/unreviewed/2024/05/GHSA-2qj7-3x7p-9jgf/GHSA-2qj7-3x7p-9jgf.json +++ b/advisories/unreviewed/2024/05/GHSA-2qj7-3x7p-9jgf/GHSA-2qj7-3x7p-9jgf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-2qqh-h8cp-4jfx/GHSA-2qqh-h8cp-4jfx.json b/advisories/unreviewed/2024/05/GHSA-2qqh-h8cp-4jfx/GHSA-2qqh-h8cp-4jfx.json index 970c2186046..5d068b80091 100644 --- a/advisories/unreviewed/2024/05/GHSA-2qqh-h8cp-4jfx/GHSA-2qqh-h8cp-4jfx.json +++ b/advisories/unreviewed/2024/05/GHSA-2qqh-h8cp-4jfx/GHSA-2qqh-h8cp-4jfx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-2vq7-8vvf-w66v/GHSA-2vq7-8vvf-w66v.json b/advisories/unreviewed/2024/05/GHSA-2vq7-8vvf-w66v/GHSA-2vq7-8vvf-w66v.json index 185f5ade686..508b3a0f4e4 100644 --- a/advisories/unreviewed/2024/05/GHSA-2vq7-8vvf-w66v/GHSA-2vq7-8vvf-w66v.json +++ b/advisories/unreviewed/2024/05/GHSA-2vq7-8vvf-w66v/GHSA-2vq7-8vvf-w66v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-325g-m22q-hmgj/GHSA-325g-m22q-hmgj.json b/advisories/unreviewed/2024/05/GHSA-325g-m22q-hmgj/GHSA-325g-m22q-hmgj.json index 2222e76a4e6..19cf35c61e1 100644 --- a/advisories/unreviewed/2024/05/GHSA-325g-m22q-hmgj/GHSA-325g-m22q-hmgj.json +++ b/advisories/unreviewed/2024/05/GHSA-325g-m22q-hmgj/GHSA-325g-m22q-hmgj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-385j-3cf6-7qjj/GHSA-385j-3cf6-7qjj.json b/advisories/unreviewed/2024/05/GHSA-385j-3cf6-7qjj/GHSA-385j-3cf6-7qjj.json index a316f91f6c6..b68ae6fb866 100644 --- a/advisories/unreviewed/2024/05/GHSA-385j-3cf6-7qjj/GHSA-385j-3cf6-7qjj.json +++ b/advisories/unreviewed/2024/05/GHSA-385j-3cf6-7qjj/GHSA-385j-3cf6-7qjj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-38hf-j8cf-rw67/GHSA-38hf-j8cf-rw67.json b/advisories/unreviewed/2024/05/GHSA-38hf-j8cf-rw67/GHSA-38hf-j8cf-rw67.json index ceb8573ecfa..4a795e37394 100644 --- a/advisories/unreviewed/2024/05/GHSA-38hf-j8cf-rw67/GHSA-38hf-j8cf-rw67.json +++ b/advisories/unreviewed/2024/05/GHSA-38hf-j8cf-rw67/GHSA-38hf-j8cf-rw67.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-3f29-xc6q-j293/GHSA-3f29-xc6q-j293.json b/advisories/unreviewed/2024/05/GHSA-3f29-xc6q-j293/GHSA-3f29-xc6q-j293.json index e6a970a8324..414a95ea186 100644 --- a/advisories/unreviewed/2024/05/GHSA-3f29-xc6q-j293/GHSA-3f29-xc6q-j293.json +++ b/advisories/unreviewed/2024/05/GHSA-3f29-xc6q-j293/GHSA-3f29-xc6q-j293.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-3gr6-26j4-g5xq/GHSA-3gr6-26j4-g5xq.json b/advisories/unreviewed/2024/05/GHSA-3gr6-26j4-g5xq/GHSA-3gr6-26j4-g5xq.json index 8aae878dbf1..7bced61332b 100644 --- a/advisories/unreviewed/2024/05/GHSA-3gr6-26j4-g5xq/GHSA-3gr6-26j4-g5xq.json +++ b/advisories/unreviewed/2024/05/GHSA-3gr6-26j4-g5xq/GHSA-3gr6-26j4-g5xq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-3v35-9mr3-6xr5/GHSA-3v35-9mr3-6xr5.json b/advisories/unreviewed/2024/05/GHSA-3v35-9mr3-6xr5/GHSA-3v35-9mr3-6xr5.json index c7ac210579b..1ed10e4e83e 100644 --- a/advisories/unreviewed/2024/05/GHSA-3v35-9mr3-6xr5/GHSA-3v35-9mr3-6xr5.json +++ b/advisories/unreviewed/2024/05/GHSA-3v35-9mr3-6xr5/GHSA-3v35-9mr3-6xr5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-3xfc-m583-jq9v/GHSA-3xfc-m583-jq9v.json b/advisories/unreviewed/2024/05/GHSA-3xfc-m583-jq9v/GHSA-3xfc-m583-jq9v.json index a716715b8ee..ba57068fa99 100644 --- a/advisories/unreviewed/2024/05/GHSA-3xfc-m583-jq9v/GHSA-3xfc-m583-jq9v.json +++ b/advisories/unreviewed/2024/05/GHSA-3xfc-m583-jq9v/GHSA-3xfc-m583-jq9v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-426j-23c4-55m8/GHSA-426j-23c4-55m8.json b/advisories/unreviewed/2024/05/GHSA-426j-23c4-55m8/GHSA-426j-23c4-55m8.json index 6152289e8c6..51dfdf67c32 100644 --- a/advisories/unreviewed/2024/05/GHSA-426j-23c4-55m8/GHSA-426j-23c4-55m8.json +++ b/advisories/unreviewed/2024/05/GHSA-426j-23c4-55m8/GHSA-426j-23c4-55m8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-44j3-q6p8-p422/GHSA-44j3-q6p8-p422.json b/advisories/unreviewed/2024/05/GHSA-44j3-q6p8-p422/GHSA-44j3-q6p8-p422.json index 31c81ec4279..b6a0a75311b 100644 --- a/advisories/unreviewed/2024/05/GHSA-44j3-q6p8-p422/GHSA-44j3-q6p8-p422.json +++ b/advisories/unreviewed/2024/05/GHSA-44j3-q6p8-p422/GHSA-44j3-q6p8-p422.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-45xr-qrc8-762p/GHSA-45xr-qrc8-762p.json b/advisories/unreviewed/2024/05/GHSA-45xr-qrc8-762p/GHSA-45xr-qrc8-762p.json index 19adcb6852c..dc4d24570d7 100644 --- a/advisories/unreviewed/2024/05/GHSA-45xr-qrc8-762p/GHSA-45xr-qrc8-762p.json +++ b/advisories/unreviewed/2024/05/GHSA-45xr-qrc8-762p/GHSA-45xr-qrc8-762p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-484m-45g3-cxp6/GHSA-484m-45g3-cxp6.json b/advisories/unreviewed/2024/05/GHSA-484m-45g3-cxp6/GHSA-484m-45g3-cxp6.json index 3a67af29a79..0aebb225118 100644 --- a/advisories/unreviewed/2024/05/GHSA-484m-45g3-cxp6/GHSA-484m-45g3-cxp6.json +++ b/advisories/unreviewed/2024/05/GHSA-484m-45g3-cxp6/GHSA-484m-45g3-cxp6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-4mcf-86r4-fm85/GHSA-4mcf-86r4-fm85.json b/advisories/unreviewed/2024/05/GHSA-4mcf-86r4-fm85/GHSA-4mcf-86r4-fm85.json index e8f1058659d..4395138703a 100644 --- a/advisories/unreviewed/2024/05/GHSA-4mcf-86r4-fm85/GHSA-4mcf-86r4-fm85.json +++ b/advisories/unreviewed/2024/05/GHSA-4mcf-86r4-fm85/GHSA-4mcf-86r4-fm85.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-4q63-jfmh-r5cw/GHSA-4q63-jfmh-r5cw.json b/advisories/unreviewed/2024/05/GHSA-4q63-jfmh-r5cw/GHSA-4q63-jfmh-r5cw.json index 8664b375ed9..6d598da0ee1 100644 --- a/advisories/unreviewed/2024/05/GHSA-4q63-jfmh-r5cw/GHSA-4q63-jfmh-r5cw.json +++ b/advisories/unreviewed/2024/05/GHSA-4q63-jfmh-r5cw/GHSA-4q63-jfmh-r5cw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-4q9h-rhrc-98f3/GHSA-4q9h-rhrc-98f3.json b/advisories/unreviewed/2024/05/GHSA-4q9h-rhrc-98f3/GHSA-4q9h-rhrc-98f3.json index f1b90062c38..32174ea759f 100644 --- a/advisories/unreviewed/2024/05/GHSA-4q9h-rhrc-98f3/GHSA-4q9h-rhrc-98f3.json +++ b/advisories/unreviewed/2024/05/GHSA-4q9h-rhrc-98f3/GHSA-4q9h-rhrc-98f3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-4qvm-73c7-9w94/GHSA-4qvm-73c7-9w94.json b/advisories/unreviewed/2024/05/GHSA-4qvm-73c7-9w94/GHSA-4qvm-73c7-9w94.json index be59e1ceb69..16725496c9d 100644 --- a/advisories/unreviewed/2024/05/GHSA-4qvm-73c7-9w94/GHSA-4qvm-73c7-9w94.json +++ b/advisories/unreviewed/2024/05/GHSA-4qvm-73c7-9w94/GHSA-4qvm-73c7-9w94.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-4r53-xgrq-7gx8/GHSA-4r53-xgrq-7gx8.json b/advisories/unreviewed/2024/05/GHSA-4r53-xgrq-7gx8/GHSA-4r53-xgrq-7gx8.json index ca662998806..a31828285d1 100644 --- a/advisories/unreviewed/2024/05/GHSA-4r53-xgrq-7gx8/GHSA-4r53-xgrq-7gx8.json +++ b/advisories/unreviewed/2024/05/GHSA-4r53-xgrq-7gx8/GHSA-4r53-xgrq-7gx8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-4xr8-m8jw-38p5/GHSA-4xr8-m8jw-38p5.json b/advisories/unreviewed/2024/05/GHSA-4xr8-m8jw-38p5/GHSA-4xr8-m8jw-38p5.json index d5ec423d32a..09ee366c6bb 100644 --- a/advisories/unreviewed/2024/05/GHSA-4xr8-m8jw-38p5/GHSA-4xr8-m8jw-38p5.json +++ b/advisories/unreviewed/2024/05/GHSA-4xr8-m8jw-38p5/GHSA-4xr8-m8jw-38p5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-5357-pj4w-wrc7/GHSA-5357-pj4w-wrc7.json b/advisories/unreviewed/2024/05/GHSA-5357-pj4w-wrc7/GHSA-5357-pj4w-wrc7.json index 186f3c10648..81fc9877016 100644 --- a/advisories/unreviewed/2024/05/GHSA-5357-pj4w-wrc7/GHSA-5357-pj4w-wrc7.json +++ b/advisories/unreviewed/2024/05/GHSA-5357-pj4w-wrc7/GHSA-5357-pj4w-wrc7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-542p-5xcv-3275/GHSA-542p-5xcv-3275.json b/advisories/unreviewed/2024/05/GHSA-542p-5xcv-3275/GHSA-542p-5xcv-3275.json index 7510e33798f..d65882646f5 100644 --- a/advisories/unreviewed/2024/05/GHSA-542p-5xcv-3275/GHSA-542p-5xcv-3275.json +++ b/advisories/unreviewed/2024/05/GHSA-542p-5xcv-3275/GHSA-542p-5xcv-3275.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-5789-f25c-9hq9/GHSA-5789-f25c-9hq9.json b/advisories/unreviewed/2024/05/GHSA-5789-f25c-9hq9/GHSA-5789-f25c-9hq9.json index f25415b4b26..d50b0ea5cf3 100644 --- a/advisories/unreviewed/2024/05/GHSA-5789-f25c-9hq9/GHSA-5789-f25c-9hq9.json +++ b/advisories/unreviewed/2024/05/GHSA-5789-f25c-9hq9/GHSA-5789-f25c-9hq9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-587m-rgvw-7hjj/GHSA-587m-rgvw-7hjj.json b/advisories/unreviewed/2024/05/GHSA-587m-rgvw-7hjj/GHSA-587m-rgvw-7hjj.json index 602b4024cad..65a45f3e02e 100644 --- a/advisories/unreviewed/2024/05/GHSA-587m-rgvw-7hjj/GHSA-587m-rgvw-7hjj.json +++ b/advisories/unreviewed/2024/05/GHSA-587m-rgvw-7hjj/GHSA-587m-rgvw-7hjj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-58fv-75rm-q8mv/GHSA-58fv-75rm-q8mv.json b/advisories/unreviewed/2024/05/GHSA-58fv-75rm-q8mv/GHSA-58fv-75rm-q8mv.json index 2cb9eda3231..30fb17be1bb 100644 --- a/advisories/unreviewed/2024/05/GHSA-58fv-75rm-q8mv/GHSA-58fv-75rm-q8mv.json +++ b/advisories/unreviewed/2024/05/GHSA-58fv-75rm-q8mv/GHSA-58fv-75rm-q8mv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-5hxx-p89v-jxc7/GHSA-5hxx-p89v-jxc7.json b/advisories/unreviewed/2024/05/GHSA-5hxx-p89v-jxc7/GHSA-5hxx-p89v-jxc7.json index 1a2b8a52808..242611d8dc0 100644 --- a/advisories/unreviewed/2024/05/GHSA-5hxx-p89v-jxc7/GHSA-5hxx-p89v-jxc7.json +++ b/advisories/unreviewed/2024/05/GHSA-5hxx-p89v-jxc7/GHSA-5hxx-p89v-jxc7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-5j2h-5mq2-6hqm/GHSA-5j2h-5mq2-6hqm.json b/advisories/unreviewed/2024/05/GHSA-5j2h-5mq2-6hqm/GHSA-5j2h-5mq2-6hqm.json index 070c71253c8..d730649221e 100644 --- a/advisories/unreviewed/2024/05/GHSA-5j2h-5mq2-6hqm/GHSA-5j2h-5mq2-6hqm.json +++ b/advisories/unreviewed/2024/05/GHSA-5j2h-5mq2-6hqm/GHSA-5j2h-5mq2-6hqm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-655w-j8x9-h8c8/GHSA-655w-j8x9-h8c8.json b/advisories/unreviewed/2024/05/GHSA-655w-j8x9-h8c8/GHSA-655w-j8x9-h8c8.json index c9b26cba213..e5f43c48529 100644 --- a/advisories/unreviewed/2024/05/GHSA-655w-j8x9-h8c8/GHSA-655w-j8x9-h8c8.json +++ b/advisories/unreviewed/2024/05/GHSA-655w-j8x9-h8c8/GHSA-655w-j8x9-h8c8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-65rq-3r55-x37g/GHSA-65rq-3r55-x37g.json b/advisories/unreviewed/2024/05/GHSA-65rq-3r55-x37g/GHSA-65rq-3r55-x37g.json index 8cdb4185a53..e12457b68cd 100644 --- a/advisories/unreviewed/2024/05/GHSA-65rq-3r55-x37g/GHSA-65rq-3r55-x37g.json +++ b/advisories/unreviewed/2024/05/GHSA-65rq-3r55-x37g/GHSA-65rq-3r55-x37g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-665q-2m8r-wpx6/GHSA-665q-2m8r-wpx6.json b/advisories/unreviewed/2024/05/GHSA-665q-2m8r-wpx6/GHSA-665q-2m8r-wpx6.json index 0f856416666..d3bfdde0a50 100644 --- a/advisories/unreviewed/2024/05/GHSA-665q-2m8r-wpx6/GHSA-665q-2m8r-wpx6.json +++ b/advisories/unreviewed/2024/05/GHSA-665q-2m8r-wpx6/GHSA-665q-2m8r-wpx6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-67rj-8f2h-26fc/GHSA-67rj-8f2h-26fc.json b/advisories/unreviewed/2024/05/GHSA-67rj-8f2h-26fc/GHSA-67rj-8f2h-26fc.json index 278bbcacc46..23d0242de59 100644 --- a/advisories/unreviewed/2024/05/GHSA-67rj-8f2h-26fc/GHSA-67rj-8f2h-26fc.json +++ b/advisories/unreviewed/2024/05/GHSA-67rj-8f2h-26fc/GHSA-67rj-8f2h-26fc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-6m45-rhxg-8qpr/GHSA-6m45-rhxg-8qpr.json b/advisories/unreviewed/2024/05/GHSA-6m45-rhxg-8qpr/GHSA-6m45-rhxg-8qpr.json index ac500f33549..4555ed8da08 100644 --- a/advisories/unreviewed/2024/05/GHSA-6m45-rhxg-8qpr/GHSA-6m45-rhxg-8qpr.json +++ b/advisories/unreviewed/2024/05/GHSA-6m45-rhxg-8qpr/GHSA-6m45-rhxg-8qpr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-6pww-8qmg-pgwp/GHSA-6pww-8qmg-pgwp.json b/advisories/unreviewed/2024/05/GHSA-6pww-8qmg-pgwp/GHSA-6pww-8qmg-pgwp.json index a4cceb62fd1..360dade2e5a 100644 --- a/advisories/unreviewed/2024/05/GHSA-6pww-8qmg-pgwp/GHSA-6pww-8qmg-pgwp.json +++ b/advisories/unreviewed/2024/05/GHSA-6pww-8qmg-pgwp/GHSA-6pww-8qmg-pgwp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-6q7f-8rwr-3p3h/GHSA-6q7f-8rwr-3p3h.json b/advisories/unreviewed/2024/05/GHSA-6q7f-8rwr-3p3h/GHSA-6q7f-8rwr-3p3h.json index 11be172a4e9..35de2348e2d 100644 --- a/advisories/unreviewed/2024/05/GHSA-6q7f-8rwr-3p3h/GHSA-6q7f-8rwr-3p3h.json +++ b/advisories/unreviewed/2024/05/GHSA-6q7f-8rwr-3p3h/GHSA-6q7f-8rwr-3p3h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-7crq-fr5p-gw4f/GHSA-7crq-fr5p-gw4f.json b/advisories/unreviewed/2024/05/GHSA-7crq-fr5p-gw4f/GHSA-7crq-fr5p-gw4f.json index 3ef14696270..132855fbcde 100644 --- a/advisories/unreviewed/2024/05/GHSA-7crq-fr5p-gw4f/GHSA-7crq-fr5p-gw4f.json +++ b/advisories/unreviewed/2024/05/GHSA-7crq-fr5p-gw4f/GHSA-7crq-fr5p-gw4f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-7jjm-882p-f82j/GHSA-7jjm-882p-f82j.json b/advisories/unreviewed/2024/05/GHSA-7jjm-882p-f82j/GHSA-7jjm-882p-f82j.json index bef16e18532..1f92890b5b0 100644 --- a/advisories/unreviewed/2024/05/GHSA-7jjm-882p-f82j/GHSA-7jjm-882p-f82j.json +++ b/advisories/unreviewed/2024/05/GHSA-7jjm-882p-f82j/GHSA-7jjm-882p-f82j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-7r5g-fgfp-379w/GHSA-7r5g-fgfp-379w.json b/advisories/unreviewed/2024/05/GHSA-7r5g-fgfp-379w/GHSA-7r5g-fgfp-379w.json index f8f1cf10bec..6e432fc803e 100644 --- a/advisories/unreviewed/2024/05/GHSA-7r5g-fgfp-379w/GHSA-7r5g-fgfp-379w.json +++ b/advisories/unreviewed/2024/05/GHSA-7r5g-fgfp-379w/GHSA-7r5g-fgfp-379w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-7v3w-wv8q-896w/GHSA-7v3w-wv8q-896w.json b/advisories/unreviewed/2024/05/GHSA-7v3w-wv8q-896w/GHSA-7v3w-wv8q-896w.json index 61c3a99cc89..59c2f2797f7 100644 --- a/advisories/unreviewed/2024/05/GHSA-7v3w-wv8q-896w/GHSA-7v3w-wv8q-896w.json +++ b/advisories/unreviewed/2024/05/GHSA-7v3w-wv8q-896w/GHSA-7v3w-wv8q-896w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-87mw-775v-8cmr/GHSA-87mw-775v-8cmr.json b/advisories/unreviewed/2024/05/GHSA-87mw-775v-8cmr/GHSA-87mw-775v-8cmr.json index 976124c7a9d..d9c47a95661 100644 --- a/advisories/unreviewed/2024/05/GHSA-87mw-775v-8cmr/GHSA-87mw-775v-8cmr.json +++ b/advisories/unreviewed/2024/05/GHSA-87mw-775v-8cmr/GHSA-87mw-775v-8cmr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-87xr-4v42-2rw2/GHSA-87xr-4v42-2rw2.json b/advisories/unreviewed/2024/05/GHSA-87xr-4v42-2rw2/GHSA-87xr-4v42-2rw2.json index c828084857e..bcadd4e8786 100644 --- a/advisories/unreviewed/2024/05/GHSA-87xr-4v42-2rw2/GHSA-87xr-4v42-2rw2.json +++ b/advisories/unreviewed/2024/05/GHSA-87xr-4v42-2rw2/GHSA-87xr-4v42-2rw2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-8f57-mjm2-427q/GHSA-8f57-mjm2-427q.json b/advisories/unreviewed/2024/05/GHSA-8f57-mjm2-427q/GHSA-8f57-mjm2-427q.json index 56baabadfb1..554b37bc2f0 100644 --- a/advisories/unreviewed/2024/05/GHSA-8f57-mjm2-427q/GHSA-8f57-mjm2-427q.json +++ b/advisories/unreviewed/2024/05/GHSA-8f57-mjm2-427q/GHSA-8f57-mjm2-427q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-8fq2-gxf3-72rv/GHSA-8fq2-gxf3-72rv.json b/advisories/unreviewed/2024/05/GHSA-8fq2-gxf3-72rv/GHSA-8fq2-gxf3-72rv.json index 4b07914a3ca..d1edd6c5974 100644 --- a/advisories/unreviewed/2024/05/GHSA-8fq2-gxf3-72rv/GHSA-8fq2-gxf3-72rv.json +++ b/advisories/unreviewed/2024/05/GHSA-8fq2-gxf3-72rv/GHSA-8fq2-gxf3-72rv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-8j9h-4rqp-j66g/GHSA-8j9h-4rqp-j66g.json b/advisories/unreviewed/2024/05/GHSA-8j9h-4rqp-j66g/GHSA-8j9h-4rqp-j66g.json index 75871a5b265..753d837b138 100644 --- a/advisories/unreviewed/2024/05/GHSA-8j9h-4rqp-j66g/GHSA-8j9h-4rqp-j66g.json +++ b/advisories/unreviewed/2024/05/GHSA-8j9h-4rqp-j66g/GHSA-8j9h-4rqp-j66g.json @@ -7,12 +7,8 @@ "CVE-2024-34468" ], "details": "Rukovoditel before 3.5.3 allows XSS via user_photo to My Page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-8jfc-9mv9-fvf7/GHSA-8jfc-9mv9-fvf7.json b/advisories/unreviewed/2024/05/GHSA-8jfc-9mv9-fvf7/GHSA-8jfc-9mv9-fvf7.json index 84c42eeafdb..9ad749515c7 100644 --- a/advisories/unreviewed/2024/05/GHSA-8jfc-9mv9-fvf7/GHSA-8jfc-9mv9-fvf7.json +++ b/advisories/unreviewed/2024/05/GHSA-8jfc-9mv9-fvf7/GHSA-8jfc-9mv9-fvf7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-8mf4-9xj6-7hp7/GHSA-8mf4-9xj6-7hp7.json b/advisories/unreviewed/2024/05/GHSA-8mf4-9xj6-7hp7/GHSA-8mf4-9xj6-7hp7.json index c0bb50bf896..b2ae2f73622 100644 --- a/advisories/unreviewed/2024/05/GHSA-8mf4-9xj6-7hp7/GHSA-8mf4-9xj6-7hp7.json +++ b/advisories/unreviewed/2024/05/GHSA-8mf4-9xj6-7hp7/GHSA-8mf4-9xj6-7hp7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-8rrp-366j-cc4g/GHSA-8rrp-366j-cc4g.json b/advisories/unreviewed/2024/05/GHSA-8rrp-366j-cc4g/GHSA-8rrp-366j-cc4g.json index 590b9aef22a..8dcefd78dbe 100644 --- a/advisories/unreviewed/2024/05/GHSA-8rrp-366j-cc4g/GHSA-8rrp-366j-cc4g.json +++ b/advisories/unreviewed/2024/05/GHSA-8rrp-366j-cc4g/GHSA-8rrp-366j-cc4g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-8x2f-hxv4-x362/GHSA-8x2f-hxv4-x362.json b/advisories/unreviewed/2024/05/GHSA-8x2f-hxv4-x362/GHSA-8x2f-hxv4-x362.json index f82cec725c8..d0edfe9d68f 100644 --- a/advisories/unreviewed/2024/05/GHSA-8x2f-hxv4-x362/GHSA-8x2f-hxv4-x362.json +++ b/advisories/unreviewed/2024/05/GHSA-8x2f-hxv4-x362/GHSA-8x2f-hxv4-x362.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-9285-vgjw-7xjf/GHSA-9285-vgjw-7xjf.json b/advisories/unreviewed/2024/05/GHSA-9285-vgjw-7xjf/GHSA-9285-vgjw-7xjf.json index 31f0571c612..12153397e66 100644 --- a/advisories/unreviewed/2024/05/GHSA-9285-vgjw-7xjf/GHSA-9285-vgjw-7xjf.json +++ b/advisories/unreviewed/2024/05/GHSA-9285-vgjw-7xjf/GHSA-9285-vgjw-7xjf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-9694-9888-6hj9/GHSA-9694-9888-6hj9.json b/advisories/unreviewed/2024/05/GHSA-9694-9888-6hj9/GHSA-9694-9888-6hj9.json index aeb32ca08f2..4295eb940cc 100644 --- a/advisories/unreviewed/2024/05/GHSA-9694-9888-6hj9/GHSA-9694-9888-6hj9.json +++ b/advisories/unreviewed/2024/05/GHSA-9694-9888-6hj9/GHSA-9694-9888-6hj9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-9jgf-m9xh-v64q/GHSA-9jgf-m9xh-v64q.json b/advisories/unreviewed/2024/05/GHSA-9jgf-m9xh-v64q/GHSA-9jgf-m9xh-v64q.json index e8942c7f78e..41ccc0bc2be 100644 --- a/advisories/unreviewed/2024/05/GHSA-9jgf-m9xh-v64q/GHSA-9jgf-m9xh-v64q.json +++ b/advisories/unreviewed/2024/05/GHSA-9jgf-m9xh-v64q/GHSA-9jgf-m9xh-v64q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-9mc3-x6rh-hrgg/GHSA-9mc3-x6rh-hrgg.json b/advisories/unreviewed/2024/05/GHSA-9mc3-x6rh-hrgg/GHSA-9mc3-x6rh-hrgg.json index 29dc3f54281..15370bb1574 100644 --- a/advisories/unreviewed/2024/05/GHSA-9mc3-x6rh-hrgg/GHSA-9mc3-x6rh-hrgg.json +++ b/advisories/unreviewed/2024/05/GHSA-9mc3-x6rh-hrgg/GHSA-9mc3-x6rh-hrgg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-9v77-4qpm-w3gc/GHSA-9v77-4qpm-w3gc.json b/advisories/unreviewed/2024/05/GHSA-9v77-4qpm-w3gc/GHSA-9v77-4qpm-w3gc.json index d2b91b99fbc..46a99f67f57 100644 --- a/advisories/unreviewed/2024/05/GHSA-9v77-4qpm-w3gc/GHSA-9v77-4qpm-w3gc.json +++ b/advisories/unreviewed/2024/05/GHSA-9v77-4qpm-w3gc/GHSA-9v77-4qpm-w3gc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-9vrg-cpf5-hchw/GHSA-9vrg-cpf5-hchw.json b/advisories/unreviewed/2024/05/GHSA-9vrg-cpf5-hchw/GHSA-9vrg-cpf5-hchw.json index 828a532a9c2..3990b939305 100644 --- a/advisories/unreviewed/2024/05/GHSA-9vrg-cpf5-hchw/GHSA-9vrg-cpf5-hchw.json +++ b/advisories/unreviewed/2024/05/GHSA-9vrg-cpf5-hchw/GHSA-9vrg-cpf5-hchw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-9w3w-6xhh-85vw/GHSA-9w3w-6xhh-85vw.json b/advisories/unreviewed/2024/05/GHSA-9w3w-6xhh-85vw/GHSA-9w3w-6xhh-85vw.json index fc5e49b9d4c..f44797ab469 100644 --- a/advisories/unreviewed/2024/05/GHSA-9w3w-6xhh-85vw/GHSA-9w3w-6xhh-85vw.json +++ b/advisories/unreviewed/2024/05/GHSA-9w3w-6xhh-85vw/GHSA-9w3w-6xhh-85vw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-c33g-f5fp-rpcq/GHSA-c33g-f5fp-rpcq.json b/advisories/unreviewed/2024/05/GHSA-c33g-f5fp-rpcq/GHSA-c33g-f5fp-rpcq.json index d44b3987948..2ea49c9bdf8 100644 --- a/advisories/unreviewed/2024/05/GHSA-c33g-f5fp-rpcq/GHSA-c33g-f5fp-rpcq.json +++ b/advisories/unreviewed/2024/05/GHSA-c33g-f5fp-rpcq/GHSA-c33g-f5fp-rpcq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-c433-w259-gc4x/GHSA-c433-w259-gc4x.json b/advisories/unreviewed/2024/05/GHSA-c433-w259-gc4x/GHSA-c433-w259-gc4x.json index d518f10d7f7..1cf88107b4b 100644 --- a/advisories/unreviewed/2024/05/GHSA-c433-w259-gc4x/GHSA-c433-w259-gc4x.json +++ b/advisories/unreviewed/2024/05/GHSA-c433-w259-gc4x/GHSA-c433-w259-gc4x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-c9jc-74h4-966f/GHSA-c9jc-74h4-966f.json b/advisories/unreviewed/2024/05/GHSA-c9jc-74h4-966f/GHSA-c9jc-74h4-966f.json index 7c6507fa58c..9ef86849962 100644 --- a/advisories/unreviewed/2024/05/GHSA-c9jc-74h4-966f/GHSA-c9jc-74h4-966f.json +++ b/advisories/unreviewed/2024/05/GHSA-c9jc-74h4-966f/GHSA-c9jc-74h4-966f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-cvqg-h5hx-c2m4/GHSA-cvqg-h5hx-c2m4.json b/advisories/unreviewed/2024/05/GHSA-cvqg-h5hx-c2m4/GHSA-cvqg-h5hx-c2m4.json index 08aeb5d3c5e..82dc2073963 100644 --- a/advisories/unreviewed/2024/05/GHSA-cvqg-h5hx-c2m4/GHSA-cvqg-h5hx-c2m4.json +++ b/advisories/unreviewed/2024/05/GHSA-cvqg-h5hx-c2m4/GHSA-cvqg-h5hx-c2m4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-cxq3-mwqc-vjv7/GHSA-cxq3-mwqc-vjv7.json b/advisories/unreviewed/2024/05/GHSA-cxq3-mwqc-vjv7/GHSA-cxq3-mwqc-vjv7.json index d3ca4ae826c..ddc567cf01f 100644 --- a/advisories/unreviewed/2024/05/GHSA-cxq3-mwqc-vjv7/GHSA-cxq3-mwqc-vjv7.json +++ b/advisories/unreviewed/2024/05/GHSA-cxq3-mwqc-vjv7/GHSA-cxq3-mwqc-vjv7.json @@ -7,12 +7,8 @@ "CVE-2024-34473" ], "details": "An issue was discovered in appmgr in O-RAN Near-RT RIC I-Release. An attacker could register an unintended RMR message type during xApp registration to disrupt other service components.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-f68w-vghw-39x8/GHSA-f68w-vghw-39x8.json b/advisories/unreviewed/2024/05/GHSA-f68w-vghw-39x8/GHSA-f68w-vghw-39x8.json index 05801496d4b..b777975837f 100644 --- a/advisories/unreviewed/2024/05/GHSA-f68w-vghw-39x8/GHSA-f68w-vghw-39x8.json +++ b/advisories/unreviewed/2024/05/GHSA-f68w-vghw-39x8/GHSA-f68w-vghw-39x8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-f94j-w2gr-ff6h/GHSA-f94j-w2gr-ff6h.json b/advisories/unreviewed/2024/05/GHSA-f94j-w2gr-ff6h/GHSA-f94j-w2gr-ff6h.json index abba1614d41..473a502edc1 100644 --- a/advisories/unreviewed/2024/05/GHSA-f94j-w2gr-ff6h/GHSA-f94j-w2gr-ff6h.json +++ b/advisories/unreviewed/2024/05/GHSA-f94j-w2gr-ff6h/GHSA-f94j-w2gr-ff6h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-fgjm-mh7r-2q22/GHSA-fgjm-mh7r-2q22.json b/advisories/unreviewed/2024/05/GHSA-fgjm-mh7r-2q22/GHSA-fgjm-mh7r-2q22.json index 97665861ab9..93bf9950fdf 100644 --- a/advisories/unreviewed/2024/05/GHSA-fgjm-mh7r-2q22/GHSA-fgjm-mh7r-2q22.json +++ b/advisories/unreviewed/2024/05/GHSA-fgjm-mh7r-2q22/GHSA-fgjm-mh7r-2q22.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-fmh4-p5x3-6hxh/GHSA-fmh4-p5x3-6hxh.json b/advisories/unreviewed/2024/05/GHSA-fmh4-p5x3-6hxh/GHSA-fmh4-p5x3-6hxh.json index 2a1ff0f61cf..cd46839a165 100644 --- a/advisories/unreviewed/2024/05/GHSA-fmh4-p5x3-6hxh/GHSA-fmh4-p5x3-6hxh.json +++ b/advisories/unreviewed/2024/05/GHSA-fmh4-p5x3-6hxh/GHSA-fmh4-p5x3-6hxh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-fmx6-75w7-fmgw/GHSA-fmx6-75w7-fmgw.json b/advisories/unreviewed/2024/05/GHSA-fmx6-75w7-fmgw/GHSA-fmx6-75w7-fmgw.json index 91e8ca469fb..81c32348140 100644 --- a/advisories/unreviewed/2024/05/GHSA-fmx6-75w7-fmgw/GHSA-fmx6-75w7-fmgw.json +++ b/advisories/unreviewed/2024/05/GHSA-fmx6-75w7-fmgw/GHSA-fmx6-75w7-fmgw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-fw62-fmf6-vcc9/GHSA-fw62-fmf6-vcc9.json b/advisories/unreviewed/2024/05/GHSA-fw62-fmf6-vcc9/GHSA-fw62-fmf6-vcc9.json index 302d7a9126e..b77c68c4de9 100644 --- a/advisories/unreviewed/2024/05/GHSA-fw62-fmf6-vcc9/GHSA-fw62-fmf6-vcc9.json +++ b/advisories/unreviewed/2024/05/GHSA-fw62-fmf6-vcc9/GHSA-fw62-fmf6-vcc9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-g3fv-xj43-xg82/GHSA-g3fv-xj43-xg82.json b/advisories/unreviewed/2024/05/GHSA-g3fv-xj43-xg82/GHSA-g3fv-xj43-xg82.json index 5a06d9004f4..fa53aaa8d3a 100644 --- a/advisories/unreviewed/2024/05/GHSA-g3fv-xj43-xg82/GHSA-g3fv-xj43-xg82.json +++ b/advisories/unreviewed/2024/05/GHSA-g3fv-xj43-xg82/GHSA-g3fv-xj43-xg82.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-g53j-w72m-r73h/GHSA-g53j-w72m-r73h.json b/advisories/unreviewed/2024/05/GHSA-g53j-w72m-r73h/GHSA-g53j-w72m-r73h.json index 83550c60c51..aaac875e771 100644 --- a/advisories/unreviewed/2024/05/GHSA-g53j-w72m-r73h/GHSA-g53j-w72m-r73h.json +++ b/advisories/unreviewed/2024/05/GHSA-g53j-w72m-r73h/GHSA-g53j-w72m-r73h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-g5r2-x4m4-v9rg/GHSA-g5r2-x4m4-v9rg.json b/advisories/unreviewed/2024/05/GHSA-g5r2-x4m4-v9rg/GHSA-g5r2-x4m4-v9rg.json index 2595812b448..596d3a061bd 100644 --- a/advisories/unreviewed/2024/05/GHSA-g5r2-x4m4-v9rg/GHSA-g5r2-x4m4-v9rg.json +++ b/advisories/unreviewed/2024/05/GHSA-g5r2-x4m4-v9rg/GHSA-g5r2-x4m4-v9rg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-g654-hw9f-49w6/GHSA-g654-hw9f-49w6.json b/advisories/unreviewed/2024/05/GHSA-g654-hw9f-49w6/GHSA-g654-hw9f-49w6.json index 9cc757eb5a6..5a75b802ee8 100644 --- a/advisories/unreviewed/2024/05/GHSA-g654-hw9f-49w6/GHSA-g654-hw9f-49w6.json +++ b/advisories/unreviewed/2024/05/GHSA-g654-hw9f-49w6/GHSA-g654-hw9f-49w6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-g6xj-5g63-h824/GHSA-g6xj-5g63-h824.json b/advisories/unreviewed/2024/05/GHSA-g6xj-5g63-h824/GHSA-g6xj-5g63-h824.json index c6e6983cf75..a72010cf9c8 100644 --- a/advisories/unreviewed/2024/05/GHSA-g6xj-5g63-h824/GHSA-g6xj-5g63-h824.json +++ b/advisories/unreviewed/2024/05/GHSA-g6xj-5g63-h824/GHSA-g6xj-5g63-h824.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-g73h-mh6m-fwrg/GHSA-g73h-mh6m-fwrg.json b/advisories/unreviewed/2024/05/GHSA-g73h-mh6m-fwrg/GHSA-g73h-mh6m-fwrg.json index a79d47a0c76..1cebcbfa3eb 100644 --- a/advisories/unreviewed/2024/05/GHSA-g73h-mh6m-fwrg/GHSA-g73h-mh6m-fwrg.json +++ b/advisories/unreviewed/2024/05/GHSA-g73h-mh6m-fwrg/GHSA-g73h-mh6m-fwrg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-gvj7-jfxq-jx56/GHSA-gvj7-jfxq-jx56.json b/advisories/unreviewed/2024/05/GHSA-gvj7-jfxq-jx56/GHSA-gvj7-jfxq-jx56.json index e494595c472..56f70f84438 100644 --- a/advisories/unreviewed/2024/05/GHSA-gvj7-jfxq-jx56/GHSA-gvj7-jfxq-jx56.json +++ b/advisories/unreviewed/2024/05/GHSA-gvj7-jfxq-jx56/GHSA-gvj7-jfxq-jx56.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-gwww-cpmw-jjf6/GHSA-gwww-cpmw-jjf6.json b/advisories/unreviewed/2024/05/GHSA-gwww-cpmw-jjf6/GHSA-gwww-cpmw-jjf6.json index b1ed8e50bc5..1d282613247 100644 --- a/advisories/unreviewed/2024/05/GHSA-gwww-cpmw-jjf6/GHSA-gwww-cpmw-jjf6.json +++ b/advisories/unreviewed/2024/05/GHSA-gwww-cpmw-jjf6/GHSA-gwww-cpmw-jjf6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-gxg4-ww55-59xq/GHSA-gxg4-ww55-59xq.json b/advisories/unreviewed/2024/05/GHSA-gxg4-ww55-59xq/GHSA-gxg4-ww55-59xq.json index c804ea2ca48..c268476b823 100644 --- a/advisories/unreviewed/2024/05/GHSA-gxg4-ww55-59xq/GHSA-gxg4-ww55-59xq.json +++ b/advisories/unreviewed/2024/05/GHSA-gxg4-ww55-59xq/GHSA-gxg4-ww55-59xq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-h38h-r53h-rjqg/GHSA-h38h-r53h-rjqg.json b/advisories/unreviewed/2024/05/GHSA-h38h-r53h-rjqg/GHSA-h38h-r53h-rjqg.json index 181e927537e..8d4ed3ce9c4 100644 --- a/advisories/unreviewed/2024/05/GHSA-h38h-r53h-rjqg/GHSA-h38h-r53h-rjqg.json +++ b/advisories/unreviewed/2024/05/GHSA-h38h-r53h-rjqg/GHSA-h38h-r53h-rjqg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-h5j4-2q8w-q3q4/GHSA-h5j4-2q8w-q3q4.json b/advisories/unreviewed/2024/05/GHSA-h5j4-2q8w-q3q4/GHSA-h5j4-2q8w-q3q4.json index dd0a3086177..90bf99818af 100644 --- a/advisories/unreviewed/2024/05/GHSA-h5j4-2q8w-q3q4/GHSA-h5j4-2q8w-q3q4.json +++ b/advisories/unreviewed/2024/05/GHSA-h5j4-2q8w-q3q4/GHSA-h5j4-2q8w-q3q4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-h688-4pc2-376f/GHSA-h688-4pc2-376f.json b/advisories/unreviewed/2024/05/GHSA-h688-4pc2-376f/GHSA-h688-4pc2-376f.json index b7879634dce..e1fe9e716c8 100644 --- a/advisories/unreviewed/2024/05/GHSA-h688-4pc2-376f/GHSA-h688-4pc2-376f.json +++ b/advisories/unreviewed/2024/05/GHSA-h688-4pc2-376f/GHSA-h688-4pc2-376f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-h7vg-wchh-wv3q/GHSA-h7vg-wchh-wv3q.json b/advisories/unreviewed/2024/05/GHSA-h7vg-wchh-wv3q/GHSA-h7vg-wchh-wv3q.json index b46af46b232..36ba98fba21 100644 --- a/advisories/unreviewed/2024/05/GHSA-h7vg-wchh-wv3q/GHSA-h7vg-wchh-wv3q.json +++ b/advisories/unreviewed/2024/05/GHSA-h7vg-wchh-wv3q/GHSA-h7vg-wchh-wv3q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-hhvm-xh54-j277/GHSA-hhvm-xh54-j277.json b/advisories/unreviewed/2024/05/GHSA-hhvm-xh54-j277/GHSA-hhvm-xh54-j277.json index b00539df943..596fd0ff91e 100644 --- a/advisories/unreviewed/2024/05/GHSA-hhvm-xh54-j277/GHSA-hhvm-xh54-j277.json +++ b/advisories/unreviewed/2024/05/GHSA-hhvm-xh54-j277/GHSA-hhvm-xh54-j277.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-hj9r-q6x8-gpf5/GHSA-hj9r-q6x8-gpf5.json b/advisories/unreviewed/2024/05/GHSA-hj9r-q6x8-gpf5/GHSA-hj9r-q6x8-gpf5.json index e47be599702..73d20f8b401 100644 --- a/advisories/unreviewed/2024/05/GHSA-hj9r-q6x8-gpf5/GHSA-hj9r-q6x8-gpf5.json +++ b/advisories/unreviewed/2024/05/GHSA-hj9r-q6x8-gpf5/GHSA-hj9r-q6x8-gpf5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-hpcw-47wp-rc8h/GHSA-hpcw-47wp-rc8h.json b/advisories/unreviewed/2024/05/GHSA-hpcw-47wp-rc8h/GHSA-hpcw-47wp-rc8h.json index 36d4f6a7807..04fcf4671dc 100644 --- a/advisories/unreviewed/2024/05/GHSA-hpcw-47wp-rc8h/GHSA-hpcw-47wp-rc8h.json +++ b/advisories/unreviewed/2024/05/GHSA-hpcw-47wp-rc8h/GHSA-hpcw-47wp-rc8h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-hqqq-wpr7-6m7c/GHSA-hqqq-wpr7-6m7c.json b/advisories/unreviewed/2024/05/GHSA-hqqq-wpr7-6m7c/GHSA-hqqq-wpr7-6m7c.json index 073a79e15dd..e21b61476df 100644 --- a/advisories/unreviewed/2024/05/GHSA-hqqq-wpr7-6m7c/GHSA-hqqq-wpr7-6m7c.json +++ b/advisories/unreviewed/2024/05/GHSA-hqqq-wpr7-6m7c/GHSA-hqqq-wpr7-6m7c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-hxvm-qw87-gw53/GHSA-hxvm-qw87-gw53.json b/advisories/unreviewed/2024/05/GHSA-hxvm-qw87-gw53/GHSA-hxvm-qw87-gw53.json index 52d23407d95..23e5276cb84 100644 --- a/advisories/unreviewed/2024/05/GHSA-hxvm-qw87-gw53/GHSA-hxvm-qw87-gw53.json +++ b/advisories/unreviewed/2024/05/GHSA-hxvm-qw87-gw53/GHSA-hxvm-qw87-gw53.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-j2wr-x8cm-vx8p/GHSA-j2wr-x8cm-vx8p.json b/advisories/unreviewed/2024/05/GHSA-j2wr-x8cm-vx8p/GHSA-j2wr-x8cm-vx8p.json index 117d8a8d07b..053d3ae31c6 100644 --- a/advisories/unreviewed/2024/05/GHSA-j2wr-x8cm-vx8p/GHSA-j2wr-x8cm-vx8p.json +++ b/advisories/unreviewed/2024/05/GHSA-j2wr-x8cm-vx8p/GHSA-j2wr-x8cm-vx8p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-j3pm-qhwh-63j2/GHSA-j3pm-qhwh-63j2.json b/advisories/unreviewed/2024/05/GHSA-j3pm-qhwh-63j2/GHSA-j3pm-qhwh-63j2.json index 713041860fc..988265689d5 100644 --- a/advisories/unreviewed/2024/05/GHSA-j3pm-qhwh-63j2/GHSA-j3pm-qhwh-63j2.json +++ b/advisories/unreviewed/2024/05/GHSA-j3pm-qhwh-63j2/GHSA-j3pm-qhwh-63j2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-j3q2-jvch-j544/GHSA-j3q2-jvch-j544.json b/advisories/unreviewed/2024/05/GHSA-j3q2-jvch-j544/GHSA-j3q2-jvch-j544.json index 4f372212dc5..78dd947c4d6 100644 --- a/advisories/unreviewed/2024/05/GHSA-j3q2-jvch-j544/GHSA-j3q2-jvch-j544.json +++ b/advisories/unreviewed/2024/05/GHSA-j3q2-jvch-j544/GHSA-j3q2-jvch-j544.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-j6vv-mv3c-q6jp/GHSA-j6vv-mv3c-q6jp.json b/advisories/unreviewed/2024/05/GHSA-j6vv-mv3c-q6jp/GHSA-j6vv-mv3c-q6jp.json index de6e8b0d63b..a66626a2c51 100644 --- a/advisories/unreviewed/2024/05/GHSA-j6vv-mv3c-q6jp/GHSA-j6vv-mv3c-q6jp.json +++ b/advisories/unreviewed/2024/05/GHSA-j6vv-mv3c-q6jp/GHSA-j6vv-mv3c-q6jp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-j6wg-hmpm-wvcf/GHSA-j6wg-hmpm-wvcf.json b/advisories/unreviewed/2024/05/GHSA-j6wg-hmpm-wvcf/GHSA-j6wg-hmpm-wvcf.json index 43262e4d056..cade53ff52b 100644 --- a/advisories/unreviewed/2024/05/GHSA-j6wg-hmpm-wvcf/GHSA-j6wg-hmpm-wvcf.json +++ b/advisories/unreviewed/2024/05/GHSA-j6wg-hmpm-wvcf/GHSA-j6wg-hmpm-wvcf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-j867-9253-8mrv/GHSA-j867-9253-8mrv.json b/advisories/unreviewed/2024/05/GHSA-j867-9253-8mrv/GHSA-j867-9253-8mrv.json index 958ef04e798..dc135a959c0 100644 --- a/advisories/unreviewed/2024/05/GHSA-j867-9253-8mrv/GHSA-j867-9253-8mrv.json +++ b/advisories/unreviewed/2024/05/GHSA-j867-9253-8mrv/GHSA-j867-9253-8mrv.json @@ -7,12 +7,8 @@ "CVE-2024-35943" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\npmdomain: ti: Add a null pointer check to the omap_prm_domain_init\n\ndevm_kasprintf() returns a pointer to dynamically allocated memory\nwhich can be NULL upon failure. Ensure the allocation was successful\nby checking the pointer validity.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-j9m8-qg4j-ww52/GHSA-j9m8-qg4j-ww52.json b/advisories/unreviewed/2024/05/GHSA-j9m8-qg4j-ww52/GHSA-j9m8-qg4j-ww52.json index 2af17a96469..13f8951996c 100644 --- a/advisories/unreviewed/2024/05/GHSA-j9m8-qg4j-ww52/GHSA-j9m8-qg4j-ww52.json +++ b/advisories/unreviewed/2024/05/GHSA-j9m8-qg4j-ww52/GHSA-j9m8-qg4j-ww52.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-j9xf-35v7-hf3h/GHSA-j9xf-35v7-hf3h.json b/advisories/unreviewed/2024/05/GHSA-j9xf-35v7-hf3h/GHSA-j9xf-35v7-hf3h.json index f9fa98e74fe..0d7c1654f2e 100644 --- a/advisories/unreviewed/2024/05/GHSA-j9xf-35v7-hf3h/GHSA-j9xf-35v7-hf3h.json +++ b/advisories/unreviewed/2024/05/GHSA-j9xf-35v7-hf3h/GHSA-j9xf-35v7-hf3h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-jh94-w345-vcxj/GHSA-jh94-w345-vcxj.json b/advisories/unreviewed/2024/05/GHSA-jh94-w345-vcxj/GHSA-jh94-w345-vcxj.json index a9672ef5fee..cdce43e4d7e 100644 --- a/advisories/unreviewed/2024/05/GHSA-jh94-w345-vcxj/GHSA-jh94-w345-vcxj.json +++ b/advisories/unreviewed/2024/05/GHSA-jh94-w345-vcxj/GHSA-jh94-w345-vcxj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-jhx2-vqph-538w/GHSA-jhx2-vqph-538w.json b/advisories/unreviewed/2024/05/GHSA-jhx2-vqph-538w/GHSA-jhx2-vqph-538w.json index b2b10c259a5..305c7c22852 100644 --- a/advisories/unreviewed/2024/05/GHSA-jhx2-vqph-538w/GHSA-jhx2-vqph-538w.json +++ b/advisories/unreviewed/2024/05/GHSA-jhx2-vqph-538w/GHSA-jhx2-vqph-538w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-jp6j-vw3x-6p9v/GHSA-jp6j-vw3x-6p9v.json b/advisories/unreviewed/2024/05/GHSA-jp6j-vw3x-6p9v/GHSA-jp6j-vw3x-6p9v.json index 4948e9fa94d..6113b170da3 100644 --- a/advisories/unreviewed/2024/05/GHSA-jp6j-vw3x-6p9v/GHSA-jp6j-vw3x-6p9v.json +++ b/advisories/unreviewed/2024/05/GHSA-jp6j-vw3x-6p9v/GHSA-jp6j-vw3x-6p9v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-jvmf-fpmj-52r5/GHSA-jvmf-fpmj-52r5.json b/advisories/unreviewed/2024/05/GHSA-jvmf-fpmj-52r5/GHSA-jvmf-fpmj-52r5.json index 064df5e25e5..52b69e095ae 100644 --- a/advisories/unreviewed/2024/05/GHSA-jvmf-fpmj-52r5/GHSA-jvmf-fpmj-52r5.json +++ b/advisories/unreviewed/2024/05/GHSA-jvmf-fpmj-52r5/GHSA-jvmf-fpmj-52r5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-jw44-pw3q-q93x/GHSA-jw44-pw3q-q93x.json b/advisories/unreviewed/2024/05/GHSA-jw44-pw3q-q93x/GHSA-jw44-pw3q-q93x.json index 8462937fc1c..b7e596d4a25 100644 --- a/advisories/unreviewed/2024/05/GHSA-jw44-pw3q-q93x/GHSA-jw44-pw3q-q93x.json +++ b/advisories/unreviewed/2024/05/GHSA-jw44-pw3q-q93x/GHSA-jw44-pw3q-q93x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-jwgc-2cm6-rgjp/GHSA-jwgc-2cm6-rgjp.json b/advisories/unreviewed/2024/05/GHSA-jwgc-2cm6-rgjp/GHSA-jwgc-2cm6-rgjp.json index a8295d00eb5..37dc02b80b5 100644 --- a/advisories/unreviewed/2024/05/GHSA-jwgc-2cm6-rgjp/GHSA-jwgc-2cm6-rgjp.json +++ b/advisories/unreviewed/2024/05/GHSA-jwgc-2cm6-rgjp/GHSA-jwgc-2cm6-rgjp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-jwj2-jp2f-qhfp/GHSA-jwj2-jp2f-qhfp.json b/advisories/unreviewed/2024/05/GHSA-jwj2-jp2f-qhfp/GHSA-jwj2-jp2f-qhfp.json index 58affefbf1b..d6e036580b1 100644 --- a/advisories/unreviewed/2024/05/GHSA-jwj2-jp2f-qhfp/GHSA-jwj2-jp2f-qhfp.json +++ b/advisories/unreviewed/2024/05/GHSA-jwj2-jp2f-qhfp/GHSA-jwj2-jp2f-qhfp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-jxcj-3v7x-m3q6/GHSA-jxcj-3v7x-m3q6.json b/advisories/unreviewed/2024/05/GHSA-jxcj-3v7x-m3q6/GHSA-jxcj-3v7x-m3q6.json index 981f4b66d36..ecae027c508 100644 --- a/advisories/unreviewed/2024/05/GHSA-jxcj-3v7x-m3q6/GHSA-jxcj-3v7x-m3q6.json +++ b/advisories/unreviewed/2024/05/GHSA-jxcj-3v7x-m3q6/GHSA-jxcj-3v7x-m3q6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-jxgg-x4q8-f464/GHSA-jxgg-x4q8-f464.json b/advisories/unreviewed/2024/05/GHSA-jxgg-x4q8-f464/GHSA-jxgg-x4q8-f464.json index 6a18db4cc3c..10b7e90b944 100644 --- a/advisories/unreviewed/2024/05/GHSA-jxgg-x4q8-f464/GHSA-jxgg-x4q8-f464.json +++ b/advisories/unreviewed/2024/05/GHSA-jxgg-x4q8-f464/GHSA-jxgg-x4q8-f464.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-mg36-pmfg-w8g5/GHSA-mg36-pmfg-w8g5.json b/advisories/unreviewed/2024/05/GHSA-mg36-pmfg-w8g5/GHSA-mg36-pmfg-w8g5.json index 99e54c3f2e7..63059eb313f 100644 --- a/advisories/unreviewed/2024/05/GHSA-mg36-pmfg-w8g5/GHSA-mg36-pmfg-w8g5.json +++ b/advisories/unreviewed/2024/05/GHSA-mg36-pmfg-w8g5/GHSA-mg36-pmfg-w8g5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-mh5h-w46h-67mh/GHSA-mh5h-w46h-67mh.json b/advisories/unreviewed/2024/05/GHSA-mh5h-w46h-67mh/GHSA-mh5h-w46h-67mh.json index 05e6dfd6716..f7f6fa87886 100644 --- a/advisories/unreviewed/2024/05/GHSA-mh5h-w46h-67mh/GHSA-mh5h-w46h-67mh.json +++ b/advisories/unreviewed/2024/05/GHSA-mh5h-w46h-67mh/GHSA-mh5h-w46h-67mh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-mh8x-j2pr-59w6/GHSA-mh8x-j2pr-59w6.json b/advisories/unreviewed/2024/05/GHSA-mh8x-j2pr-59w6/GHSA-mh8x-j2pr-59w6.json index 0c8c34c2188..6631613eade 100644 --- a/advisories/unreviewed/2024/05/GHSA-mh8x-j2pr-59w6/GHSA-mh8x-j2pr-59w6.json +++ b/advisories/unreviewed/2024/05/GHSA-mh8x-j2pr-59w6/GHSA-mh8x-j2pr-59w6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-mv9r-wxch-3fj4/GHSA-mv9r-wxch-3fj4.json b/advisories/unreviewed/2024/05/GHSA-mv9r-wxch-3fj4/GHSA-mv9r-wxch-3fj4.json index 84970860f77..873c9e587c2 100644 --- a/advisories/unreviewed/2024/05/GHSA-mv9r-wxch-3fj4/GHSA-mv9r-wxch-3fj4.json +++ b/advisories/unreviewed/2024/05/GHSA-mv9r-wxch-3fj4/GHSA-mv9r-wxch-3fj4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-p3jm-9qcf-m97r/GHSA-p3jm-9qcf-m97r.json b/advisories/unreviewed/2024/05/GHSA-p3jm-9qcf-m97r/GHSA-p3jm-9qcf-m97r.json index 0b2d4c91b7a..befa2a2c91b 100644 --- a/advisories/unreviewed/2024/05/GHSA-p3jm-9qcf-m97r/GHSA-p3jm-9qcf-m97r.json +++ b/advisories/unreviewed/2024/05/GHSA-p3jm-9qcf-m97r/GHSA-p3jm-9qcf-m97r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-pc82-cm8v-cj54/GHSA-pc82-cm8v-cj54.json b/advisories/unreviewed/2024/05/GHSA-pc82-cm8v-cj54/GHSA-pc82-cm8v-cj54.json index 87cc1b03a17..8ca9016e152 100644 --- a/advisories/unreviewed/2024/05/GHSA-pc82-cm8v-cj54/GHSA-pc82-cm8v-cj54.json +++ b/advisories/unreviewed/2024/05/GHSA-pc82-cm8v-cj54/GHSA-pc82-cm8v-cj54.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-pm6f-qc2w-5rvq/GHSA-pm6f-qc2w-5rvq.json b/advisories/unreviewed/2024/05/GHSA-pm6f-qc2w-5rvq/GHSA-pm6f-qc2w-5rvq.json index cf62616955a..9a70e8f8c8b 100644 --- a/advisories/unreviewed/2024/05/GHSA-pm6f-qc2w-5rvq/GHSA-pm6f-qc2w-5rvq.json +++ b/advisories/unreviewed/2024/05/GHSA-pm6f-qc2w-5rvq/GHSA-pm6f-qc2w-5rvq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-pmf3-wffg-82x2/GHSA-pmf3-wffg-82x2.json b/advisories/unreviewed/2024/05/GHSA-pmf3-wffg-82x2/GHSA-pmf3-wffg-82x2.json index 4bf7f473ef8..469668488b2 100644 --- a/advisories/unreviewed/2024/05/GHSA-pmf3-wffg-82x2/GHSA-pmf3-wffg-82x2.json +++ b/advisories/unreviewed/2024/05/GHSA-pmf3-wffg-82x2/GHSA-pmf3-wffg-82x2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-pmh3-7354-8ph4/GHSA-pmh3-7354-8ph4.json b/advisories/unreviewed/2024/05/GHSA-pmh3-7354-8ph4/GHSA-pmh3-7354-8ph4.json index 755f8c1b19c..0163e437349 100644 --- a/advisories/unreviewed/2024/05/GHSA-pmh3-7354-8ph4/GHSA-pmh3-7354-8ph4.json +++ b/advisories/unreviewed/2024/05/GHSA-pmh3-7354-8ph4/GHSA-pmh3-7354-8ph4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-ppfw-g5xc-w7x3/GHSA-ppfw-g5xc-w7x3.json b/advisories/unreviewed/2024/05/GHSA-ppfw-g5xc-w7x3/GHSA-ppfw-g5xc-w7x3.json index 470550db2cb..4774ea46cde 100644 --- a/advisories/unreviewed/2024/05/GHSA-ppfw-g5xc-w7x3/GHSA-ppfw-g5xc-w7x3.json +++ b/advisories/unreviewed/2024/05/GHSA-ppfw-g5xc-w7x3/GHSA-ppfw-g5xc-w7x3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-q35j-wcr7-44qr/GHSA-q35j-wcr7-44qr.json b/advisories/unreviewed/2024/05/GHSA-q35j-wcr7-44qr/GHSA-q35j-wcr7-44qr.json index a56628e911d..df694d72fd5 100644 --- a/advisories/unreviewed/2024/05/GHSA-q35j-wcr7-44qr/GHSA-q35j-wcr7-44qr.json +++ b/advisories/unreviewed/2024/05/GHSA-q35j-wcr7-44qr/GHSA-q35j-wcr7-44qr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-q58r-wxw5-2g3g/GHSA-q58r-wxw5-2g3g.json b/advisories/unreviewed/2024/05/GHSA-q58r-wxw5-2g3g/GHSA-q58r-wxw5-2g3g.json index 89926b65a08..36ec716e06c 100644 --- a/advisories/unreviewed/2024/05/GHSA-q58r-wxw5-2g3g/GHSA-q58r-wxw5-2g3g.json +++ b/advisories/unreviewed/2024/05/GHSA-q58r-wxw5-2g3g/GHSA-q58r-wxw5-2g3g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-q6hp-h24j-qjr9/GHSA-q6hp-h24j-qjr9.json b/advisories/unreviewed/2024/05/GHSA-q6hp-h24j-qjr9/GHSA-q6hp-h24j-qjr9.json index 99142428ffd..54974f2e2ab 100644 --- a/advisories/unreviewed/2024/05/GHSA-q6hp-h24j-qjr9/GHSA-q6hp-h24j-qjr9.json +++ b/advisories/unreviewed/2024/05/GHSA-q6hp-h24j-qjr9/GHSA-q6hp-h24j-qjr9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-qc72-qg54-95v6/GHSA-qc72-qg54-95v6.json b/advisories/unreviewed/2024/05/GHSA-qc72-qg54-95v6/GHSA-qc72-qg54-95v6.json index 61bcd0c205d..32cd60ee879 100644 --- a/advisories/unreviewed/2024/05/GHSA-qc72-qg54-95v6/GHSA-qc72-qg54-95v6.json +++ b/advisories/unreviewed/2024/05/GHSA-qc72-qg54-95v6/GHSA-qc72-qg54-95v6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-qcjh-mhmj-8r4v/GHSA-qcjh-mhmj-8r4v.json b/advisories/unreviewed/2024/05/GHSA-qcjh-mhmj-8r4v/GHSA-qcjh-mhmj-8r4v.json index ac211f24fc6..28208878d2a 100644 --- a/advisories/unreviewed/2024/05/GHSA-qcjh-mhmj-8r4v/GHSA-qcjh-mhmj-8r4v.json +++ b/advisories/unreviewed/2024/05/GHSA-qcjh-mhmj-8r4v/GHSA-qcjh-mhmj-8r4v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-qm4h-mqq2-vc43/GHSA-qm4h-mqq2-vc43.json b/advisories/unreviewed/2024/05/GHSA-qm4h-mqq2-vc43/GHSA-qm4h-mqq2-vc43.json index ef3784d1652..57dc56522da 100644 --- a/advisories/unreviewed/2024/05/GHSA-qm4h-mqq2-vc43/GHSA-qm4h-mqq2-vc43.json +++ b/advisories/unreviewed/2024/05/GHSA-qm4h-mqq2-vc43/GHSA-qm4h-mqq2-vc43.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-qw6m-c2fr-wrgr/GHSA-qw6m-c2fr-wrgr.json b/advisories/unreviewed/2024/05/GHSA-qw6m-c2fr-wrgr/GHSA-qw6m-c2fr-wrgr.json index 10d4df5e892..3f3aaf2e884 100644 --- a/advisories/unreviewed/2024/05/GHSA-qw6m-c2fr-wrgr/GHSA-qw6m-c2fr-wrgr.json +++ b/advisories/unreviewed/2024/05/GHSA-qw6m-c2fr-wrgr/GHSA-qw6m-c2fr-wrgr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-qwwj-hfjx-97wv/GHSA-qwwj-hfjx-97wv.json b/advisories/unreviewed/2024/05/GHSA-qwwj-hfjx-97wv/GHSA-qwwj-hfjx-97wv.json index e85ac1c6095..5c1da761ed2 100644 --- a/advisories/unreviewed/2024/05/GHSA-qwwj-hfjx-97wv/GHSA-qwwj-hfjx-97wv.json +++ b/advisories/unreviewed/2024/05/GHSA-qwwj-hfjx-97wv/GHSA-qwwj-hfjx-97wv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-r3cm-j3jp-3j2x/GHSA-r3cm-j3jp-3j2x.json b/advisories/unreviewed/2024/05/GHSA-r3cm-j3jp-3j2x/GHSA-r3cm-j3jp-3j2x.json index c82f5a2390d..bb35d017850 100644 --- a/advisories/unreviewed/2024/05/GHSA-r3cm-j3jp-3j2x/GHSA-r3cm-j3jp-3j2x.json +++ b/advisories/unreviewed/2024/05/GHSA-r3cm-j3jp-3j2x/GHSA-r3cm-j3jp-3j2x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-r4j8-j63p-24j8/GHSA-r4j8-j63p-24j8.json b/advisories/unreviewed/2024/05/GHSA-r4j8-j63p-24j8/GHSA-r4j8-j63p-24j8.json index 8132d9b0b0b..d2f57ee6787 100644 --- a/advisories/unreviewed/2024/05/GHSA-r4j8-j63p-24j8/GHSA-r4j8-j63p-24j8.json +++ b/advisories/unreviewed/2024/05/GHSA-r4j8-j63p-24j8/GHSA-r4j8-j63p-24j8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-r6qp-3cmm-v7xj/GHSA-r6qp-3cmm-v7xj.json b/advisories/unreviewed/2024/05/GHSA-r6qp-3cmm-v7xj/GHSA-r6qp-3cmm-v7xj.json index a39d4a3d60c..f52bf98e872 100644 --- a/advisories/unreviewed/2024/05/GHSA-r6qp-3cmm-v7xj/GHSA-r6qp-3cmm-v7xj.json +++ b/advisories/unreviewed/2024/05/GHSA-r6qp-3cmm-v7xj/GHSA-r6qp-3cmm-v7xj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-r8gh-qf5p-8r62/GHSA-r8gh-qf5p-8r62.json b/advisories/unreviewed/2024/05/GHSA-r8gh-qf5p-8r62/GHSA-r8gh-qf5p-8r62.json index ecb50cd3e11..1adba93e436 100644 --- a/advisories/unreviewed/2024/05/GHSA-r8gh-qf5p-8r62/GHSA-r8gh-qf5p-8r62.json +++ b/advisories/unreviewed/2024/05/GHSA-r8gh-qf5p-8r62/GHSA-r8gh-qf5p-8r62.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-r9f5-q3cf-pmqj/GHSA-r9f5-q3cf-pmqj.json b/advisories/unreviewed/2024/05/GHSA-r9f5-q3cf-pmqj/GHSA-r9f5-q3cf-pmqj.json index 1175b8cc235..ad4bc7677bc 100644 --- a/advisories/unreviewed/2024/05/GHSA-r9f5-q3cf-pmqj/GHSA-r9f5-q3cf-pmqj.json +++ b/advisories/unreviewed/2024/05/GHSA-r9f5-q3cf-pmqj/GHSA-r9f5-q3cf-pmqj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-rh8g-f78w-jwhw/GHSA-rh8g-f78w-jwhw.json b/advisories/unreviewed/2024/05/GHSA-rh8g-f78w-jwhw/GHSA-rh8g-f78w-jwhw.json index 2f26d2a1dad..9a1de2ddcea 100644 --- a/advisories/unreviewed/2024/05/GHSA-rh8g-f78w-jwhw/GHSA-rh8g-f78w-jwhw.json +++ b/advisories/unreviewed/2024/05/GHSA-rh8g-f78w-jwhw/GHSA-rh8g-f78w-jwhw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-rr83-9h8w-qx92/GHSA-rr83-9h8w-qx92.json b/advisories/unreviewed/2024/05/GHSA-rr83-9h8w-qx92/GHSA-rr83-9h8w-qx92.json index 24386217175..f7920b4133a 100644 --- a/advisories/unreviewed/2024/05/GHSA-rr83-9h8w-qx92/GHSA-rr83-9h8w-qx92.json +++ b/advisories/unreviewed/2024/05/GHSA-rr83-9h8w-qx92/GHSA-rr83-9h8w-qx92.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-rv7f-p2fx-hh7q/GHSA-rv7f-p2fx-hh7q.json b/advisories/unreviewed/2024/05/GHSA-rv7f-p2fx-hh7q/GHSA-rv7f-p2fx-hh7q.json index dab9364e5cf..3a7a6354ca6 100644 --- a/advisories/unreviewed/2024/05/GHSA-rv7f-p2fx-hh7q/GHSA-rv7f-p2fx-hh7q.json +++ b/advisories/unreviewed/2024/05/GHSA-rv7f-p2fx-hh7q/GHSA-rv7f-p2fx-hh7q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-rvw6-x7cr-h3hg/GHSA-rvw6-x7cr-h3hg.json b/advisories/unreviewed/2024/05/GHSA-rvw6-x7cr-h3hg/GHSA-rvw6-x7cr-h3hg.json index 60df7337c7c..0a8b7314ab2 100644 --- a/advisories/unreviewed/2024/05/GHSA-rvw6-x7cr-h3hg/GHSA-rvw6-x7cr-h3hg.json +++ b/advisories/unreviewed/2024/05/GHSA-rvw6-x7cr-h3hg/GHSA-rvw6-x7cr-h3hg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-rwpf-gxxr-mm7g/GHSA-rwpf-gxxr-mm7g.json b/advisories/unreviewed/2024/05/GHSA-rwpf-gxxr-mm7g/GHSA-rwpf-gxxr-mm7g.json index 2def64dfdd5..571972a461f 100644 --- a/advisories/unreviewed/2024/05/GHSA-rwpf-gxxr-mm7g/GHSA-rwpf-gxxr-mm7g.json +++ b/advisories/unreviewed/2024/05/GHSA-rwpf-gxxr-mm7g/GHSA-rwpf-gxxr-mm7g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-v25f-55p2-5p97/GHSA-v25f-55p2-5p97.json b/advisories/unreviewed/2024/05/GHSA-v25f-55p2-5p97/GHSA-v25f-55p2-5p97.json index c249c50348c..4c2e19ecfc1 100644 --- a/advisories/unreviewed/2024/05/GHSA-v25f-55p2-5p97/GHSA-v25f-55p2-5p97.json +++ b/advisories/unreviewed/2024/05/GHSA-v25f-55p2-5p97/GHSA-v25f-55p2-5p97.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-v4v3-mm9m-8rr5/GHSA-v4v3-mm9m-8rr5.json b/advisories/unreviewed/2024/05/GHSA-v4v3-mm9m-8rr5/GHSA-v4v3-mm9m-8rr5.json index 0eab19e0ed0..af103e7362c 100644 --- a/advisories/unreviewed/2024/05/GHSA-v4v3-mm9m-8rr5/GHSA-v4v3-mm9m-8rr5.json +++ b/advisories/unreviewed/2024/05/GHSA-v4v3-mm9m-8rr5/GHSA-v4v3-mm9m-8rr5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-v898-p95v-mpmf/GHSA-v898-p95v-mpmf.json b/advisories/unreviewed/2024/05/GHSA-v898-p95v-mpmf/GHSA-v898-p95v-mpmf.json index 3537156d260..29d57dd182b 100644 --- a/advisories/unreviewed/2024/05/GHSA-v898-p95v-mpmf/GHSA-v898-p95v-mpmf.json +++ b/advisories/unreviewed/2024/05/GHSA-v898-p95v-mpmf/GHSA-v898-p95v-mpmf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-vxm9-627c-qcvh/GHSA-vxm9-627c-qcvh.json b/advisories/unreviewed/2024/05/GHSA-vxm9-627c-qcvh/GHSA-vxm9-627c-qcvh.json index 642036a7821..6dfb52c3d7a 100644 --- a/advisories/unreviewed/2024/05/GHSA-vxm9-627c-qcvh/GHSA-vxm9-627c-qcvh.json +++ b/advisories/unreviewed/2024/05/GHSA-vxm9-627c-qcvh/GHSA-vxm9-627c-qcvh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-w6mj-2v88-p98q/GHSA-w6mj-2v88-p98q.json b/advisories/unreviewed/2024/05/GHSA-w6mj-2v88-p98q/GHSA-w6mj-2v88-p98q.json index c03c4b3c444..b6e3ec34083 100644 --- a/advisories/unreviewed/2024/05/GHSA-w6mj-2v88-p98q/GHSA-w6mj-2v88-p98q.json +++ b/advisories/unreviewed/2024/05/GHSA-w6mj-2v88-p98q/GHSA-w6mj-2v88-p98q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-w78j-w263-gjwc/GHSA-w78j-w263-gjwc.json b/advisories/unreviewed/2024/05/GHSA-w78j-w263-gjwc/GHSA-w78j-w263-gjwc.json index 71dfd4b4b9a..5c57480ce6d 100644 --- a/advisories/unreviewed/2024/05/GHSA-w78j-w263-gjwc/GHSA-w78j-w263-gjwc.json +++ b/advisories/unreviewed/2024/05/GHSA-w78j-w263-gjwc/GHSA-w78j-w263-gjwc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-w7g8-vmhg-qvwm/GHSA-w7g8-vmhg-qvwm.json b/advisories/unreviewed/2024/05/GHSA-w7g8-vmhg-qvwm/GHSA-w7g8-vmhg-qvwm.json index 2152707a63e..fb6c80fcd41 100644 --- a/advisories/unreviewed/2024/05/GHSA-w7g8-vmhg-qvwm/GHSA-w7g8-vmhg-qvwm.json +++ b/advisories/unreviewed/2024/05/GHSA-w7g8-vmhg-qvwm/GHSA-w7g8-vmhg-qvwm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-w9vj-3rvh-3783/GHSA-w9vj-3rvh-3783.json b/advisories/unreviewed/2024/05/GHSA-w9vj-3rvh-3783/GHSA-w9vj-3rvh-3783.json index 51aacb9c95a..153e16a666a 100644 --- a/advisories/unreviewed/2024/05/GHSA-w9vj-3rvh-3783/GHSA-w9vj-3rvh-3783.json +++ b/advisories/unreviewed/2024/05/GHSA-w9vj-3rvh-3783/GHSA-w9vj-3rvh-3783.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-wf86-w85g-r2f6/GHSA-wf86-w85g-r2f6.json b/advisories/unreviewed/2024/05/GHSA-wf86-w85g-r2f6/GHSA-wf86-w85g-r2f6.json index 1dbf8b961d1..2fde708a6ae 100644 --- a/advisories/unreviewed/2024/05/GHSA-wf86-w85g-r2f6/GHSA-wf86-w85g-r2f6.json +++ b/advisories/unreviewed/2024/05/GHSA-wf86-w85g-r2f6/GHSA-wf86-w85g-r2f6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-wfcp-54g6-3v3c/GHSA-wfcp-54g6-3v3c.json b/advisories/unreviewed/2024/05/GHSA-wfcp-54g6-3v3c/GHSA-wfcp-54g6-3v3c.json index 1fb94d526d9..060109ea410 100644 --- a/advisories/unreviewed/2024/05/GHSA-wfcp-54g6-3v3c/GHSA-wfcp-54g6-3v3c.json +++ b/advisories/unreviewed/2024/05/GHSA-wfcp-54g6-3v3c/GHSA-wfcp-54g6-3v3c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-whh9-qwjx-x7jq/GHSA-whh9-qwjx-x7jq.json b/advisories/unreviewed/2024/05/GHSA-whh9-qwjx-x7jq/GHSA-whh9-qwjx-x7jq.json index b8e2e2749cc..5ecff025cb3 100644 --- a/advisories/unreviewed/2024/05/GHSA-whh9-qwjx-x7jq/GHSA-whh9-qwjx-x7jq.json +++ b/advisories/unreviewed/2024/05/GHSA-whh9-qwjx-x7jq/GHSA-whh9-qwjx-x7jq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-wq92-3vm9-wjm7/GHSA-wq92-3vm9-wjm7.json b/advisories/unreviewed/2024/05/GHSA-wq92-3vm9-wjm7/GHSA-wq92-3vm9-wjm7.json index bb88899d50c..5cc588d6237 100644 --- a/advisories/unreviewed/2024/05/GHSA-wq92-3vm9-wjm7/GHSA-wq92-3vm9-wjm7.json +++ b/advisories/unreviewed/2024/05/GHSA-wq92-3vm9-wjm7/GHSA-wq92-3vm9-wjm7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-wx9r-pq2h-v9x2/GHSA-wx9r-pq2h-v9x2.json b/advisories/unreviewed/2024/05/GHSA-wx9r-pq2h-v9x2/GHSA-wx9r-pq2h-v9x2.json index d825f6f6af8..0a17d36134f 100644 --- a/advisories/unreviewed/2024/05/GHSA-wx9r-pq2h-v9x2/GHSA-wx9r-pq2h-v9x2.json +++ b/advisories/unreviewed/2024/05/GHSA-wx9r-pq2h-v9x2/GHSA-wx9r-pq2h-v9x2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-x4h9-h8xw-45f8/GHSA-x4h9-h8xw-45f8.json b/advisories/unreviewed/2024/05/GHSA-x4h9-h8xw-45f8/GHSA-x4h9-h8xw-45f8.json index 30e4e67e097..da55ef7e96c 100644 --- a/advisories/unreviewed/2024/05/GHSA-x4h9-h8xw-45f8/GHSA-x4h9-h8xw-45f8.json +++ b/advisories/unreviewed/2024/05/GHSA-x4h9-h8xw-45f8/GHSA-x4h9-h8xw-45f8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-x83v-8jx9-3xvp/GHSA-x83v-8jx9-3xvp.json b/advisories/unreviewed/2024/05/GHSA-x83v-8jx9-3xvp/GHSA-x83v-8jx9-3xvp.json index 4cd16b27dbc..e5e4d5ec38d 100644 --- a/advisories/unreviewed/2024/05/GHSA-x83v-8jx9-3xvp/GHSA-x83v-8jx9-3xvp.json +++ b/advisories/unreviewed/2024/05/GHSA-x83v-8jx9-3xvp/GHSA-x83v-8jx9-3xvp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-x94x-r6x8-8hc2/GHSA-x94x-r6x8-8hc2.json b/advisories/unreviewed/2024/05/GHSA-x94x-r6x8-8hc2/GHSA-x94x-r6x8-8hc2.json index 171d86e70ba..1e4e45ddc0b 100644 --- a/advisories/unreviewed/2024/05/GHSA-x94x-r6x8-8hc2/GHSA-x94x-r6x8-8hc2.json +++ b/advisories/unreviewed/2024/05/GHSA-x94x-r6x8-8hc2/GHSA-x94x-r6x8-8hc2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-2vx2-q9p6-5g67/GHSA-2vx2-q9p6-5g67.json b/advisories/unreviewed/2024/06/GHSA-2vx2-q9p6-5g67/GHSA-2vx2-q9p6-5g67.json index 4bc88fa1d54..bcdc4ed748d 100644 --- a/advisories/unreviewed/2024/06/GHSA-2vx2-q9p6-5g67/GHSA-2vx2-q9p6-5g67.json +++ b/advisories/unreviewed/2024/06/GHSA-2vx2-q9p6-5g67/GHSA-2vx2-q9p6-5g67.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-359q-r4g4-7qxp/GHSA-359q-r4g4-7qxp.json b/advisories/unreviewed/2024/06/GHSA-359q-r4g4-7qxp/GHSA-359q-r4g4-7qxp.json index fe9f49b92fd..388dc94cc0c 100644 --- a/advisories/unreviewed/2024/06/GHSA-359q-r4g4-7qxp/GHSA-359q-r4g4-7qxp.json +++ b/advisories/unreviewed/2024/06/GHSA-359q-r4g4-7qxp/GHSA-359q-r4g4-7qxp.json @@ -7,12 +7,8 @@ "CVE-2024-36484" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: relax socket state check at accept time.\n\nChristoph reported the following splat:\n\nWARNING: CPU: 1 PID: 772 at net/ipv4/af_inet.c:761 __inet_accept+0x1f4/0x4a0\nModules linked in:\nCPU: 1 PID: 772 Comm: syz-executor510 Not tainted 6.9.0-rc7-g7da7119fe22b #56\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.11.0-2.el7 04/01/2014\nRIP: 0010:__inet_accept+0x1f4/0x4a0 net/ipv4/af_inet.c:759\nCode: 04 38 84 c0 0f 85 87 00 00 00 41 c7 04 24 03 00 00 00 48 83 c4 10 5b 41 5c 41 5d 41 5e 41 5f 5d c3 cc cc cc cc e8 ec b7 da fd <0f> 0b e9 7f fe ff ff e8 e0 b7 da fd 0f 0b e9 fe fe ff ff 89 d9 80\nRSP: 0018:ffffc90000c2fc58 EFLAGS: 00010293\nRAX: ffffffff836bdd14 RBX: 0000000000000000 RCX: ffff888104668000\nRDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000\nRBP: dffffc0000000000 R08: ffffffff836bdb89 R09: fffff52000185f64\nR10: dffffc0000000000 R11: fffff52000185f64 R12: dffffc0000000000\nR13: 1ffff92000185f98 R14: ffff88810754d880 R15: ffff8881007b7800\nFS: 000000001c772880(0000) GS:ffff88811b280000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007fb9fcf2e178 CR3: 00000001045d2002 CR4: 0000000000770ef0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nPKRU: 55555554\nCall Trace:\n \n inet_accept+0x138/0x1d0 net/ipv4/af_inet.c:786\n do_accept+0x435/0x620 net/socket.c:1929\n __sys_accept4_file net/socket.c:1969 [inline]\n __sys_accept4+0x9b/0x110 net/socket.c:1999\n __do_sys_accept net/socket.c:2016 [inline]\n __se_sys_accept net/socket.c:2013 [inline]\n __x64_sys_accept+0x7d/0x90 net/socket.c:2013\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0x58/0x100 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\nRIP: 0033:0x4315f9\nCode: fd ff 48 81 c4 80 00 00 00 e9 f1 fe ff ff 0f 1f 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 0f 83 ab b4 fd ff c3 66 2e 0f 1f 84 00 00 00 00\nRSP: 002b:00007ffdb26d9c78 EFLAGS: 00000246 ORIG_RAX: 000000000000002b\nRAX: ffffffffffffffda RBX: 0000000000400300 RCX: 00000000004315f9\nRDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000004\nRBP: 00000000006e1018 R08: 0000000000400300 R09: 0000000000400300\nR10: 0000000000400300 R11: 0000000000000246 R12: 0000000000000000\nR13: 000000000040cdf0 R14: 000000000040ce80 R15: 0000000000000055\n \n\nThe reproducer invokes shutdown() before entering the listener status.\nAfter commit 94062790aedb (\"tcp: defer shutdown(SEND_SHUTDOWN) for\nTCP_SYN_RECV sockets\"), the above causes the child to reach the accept\nsyscall in FIN_WAIT1 status.\n\nEric noted we can relax the existing assertion in __inet_accept()", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-3x45-j72c-xqpj/GHSA-3x45-j72c-xqpj.json b/advisories/unreviewed/2024/06/GHSA-3x45-j72c-xqpj/GHSA-3x45-j72c-xqpj.json index d2ed9a0ce50..ff02445cf07 100644 --- a/advisories/unreviewed/2024/06/GHSA-3x45-j72c-xqpj/GHSA-3x45-j72c-xqpj.json +++ b/advisories/unreviewed/2024/06/GHSA-3x45-j72c-xqpj/GHSA-3x45-j72c-xqpj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-48jf-w379-p6jh/GHSA-48jf-w379-p6jh.json b/advisories/unreviewed/2024/06/GHSA-48jf-w379-p6jh/GHSA-48jf-w379-p6jh.json index 21bd5bd69da..0e8e1c15348 100644 --- a/advisories/unreviewed/2024/06/GHSA-48jf-w379-p6jh/GHSA-48jf-w379-p6jh.json +++ b/advisories/unreviewed/2024/06/GHSA-48jf-w379-p6jh/GHSA-48jf-w379-p6jh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-5cpc-fv98-27hq/GHSA-5cpc-fv98-27hq.json b/advisories/unreviewed/2024/06/GHSA-5cpc-fv98-27hq/GHSA-5cpc-fv98-27hq.json index 649e754fbcb..6d5c71f0638 100644 --- a/advisories/unreviewed/2024/06/GHSA-5cpc-fv98-27hq/GHSA-5cpc-fv98-27hq.json +++ b/advisories/unreviewed/2024/06/GHSA-5cpc-fv98-27hq/GHSA-5cpc-fv98-27hq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-86gc-q5qm-hm5q/GHSA-86gc-q5qm-hm5q.json b/advisories/unreviewed/2024/06/GHSA-86gc-q5qm-hm5q/GHSA-86gc-q5qm-hm5q.json index 45b668ab750..c41b7d94972 100644 --- a/advisories/unreviewed/2024/06/GHSA-86gc-q5qm-hm5q/GHSA-86gc-q5qm-hm5q.json +++ b/advisories/unreviewed/2024/06/GHSA-86gc-q5qm-hm5q/GHSA-86gc-q5qm-hm5q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-c7vf-6j49-jq2x/GHSA-c7vf-6j49-jq2x.json b/advisories/unreviewed/2024/06/GHSA-c7vf-6j49-jq2x/GHSA-c7vf-6j49-jq2x.json index 18ed1d5fe29..57772951867 100644 --- a/advisories/unreviewed/2024/06/GHSA-c7vf-6j49-jq2x/GHSA-c7vf-6j49-jq2x.json +++ b/advisories/unreviewed/2024/06/GHSA-c7vf-6j49-jq2x/GHSA-c7vf-6j49-jq2x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-c8f8-j53j-393c/GHSA-c8f8-j53j-393c.json b/advisories/unreviewed/2024/06/GHSA-c8f8-j53j-393c/GHSA-c8f8-j53j-393c.json index 2da00068ef0..834849bcba2 100644 --- a/advisories/unreviewed/2024/06/GHSA-c8f8-j53j-393c/GHSA-c8f8-j53j-393c.json +++ b/advisories/unreviewed/2024/06/GHSA-c8f8-j53j-393c/GHSA-c8f8-j53j-393c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-h836-7w37-2mwc/GHSA-h836-7w37-2mwc.json b/advisories/unreviewed/2024/06/GHSA-h836-7w37-2mwc/GHSA-h836-7w37-2mwc.json index c25ec3ae626..45f29d756bd 100644 --- a/advisories/unreviewed/2024/06/GHSA-h836-7w37-2mwc/GHSA-h836-7w37-2mwc.json +++ b/advisories/unreviewed/2024/06/GHSA-h836-7w37-2mwc/GHSA-h836-7w37-2mwc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-m4j9-whh9-8x9g/GHSA-m4j9-whh9-8x9g.json b/advisories/unreviewed/2024/06/GHSA-m4j9-whh9-8x9g/GHSA-m4j9-whh9-8x9g.json index a03f1fd18f7..4afac62c407 100644 --- a/advisories/unreviewed/2024/06/GHSA-m4j9-whh9-8x9g/GHSA-m4j9-whh9-8x9g.json +++ b/advisories/unreviewed/2024/06/GHSA-m4j9-whh9-8x9g/GHSA-m4j9-whh9-8x9g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-v844-p367-rm8m/GHSA-v844-p367-rm8m.json b/advisories/unreviewed/2024/06/GHSA-v844-p367-rm8m/GHSA-v844-p367-rm8m.json index 5ac4ecd13fe..212dad05bb2 100644 --- a/advisories/unreviewed/2024/06/GHSA-v844-p367-rm8m/GHSA-v844-p367-rm8m.json +++ b/advisories/unreviewed/2024/06/GHSA-v844-p367-rm8m/GHSA-v844-p367-rm8m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-wjxm-v88j-7gj4/GHSA-wjxm-v88j-7gj4.json b/advisories/unreviewed/2024/06/GHSA-wjxm-v88j-7gj4/GHSA-wjxm-v88j-7gj4.json index 5c7ea55d05c..80ec83d590c 100644 --- a/advisories/unreviewed/2024/06/GHSA-wjxm-v88j-7gj4/GHSA-wjxm-v88j-7gj4.json +++ b/advisories/unreviewed/2024/06/GHSA-wjxm-v88j-7gj4/GHSA-wjxm-v88j-7gj4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-257h-x72g-4wr7/GHSA-257h-x72g-4wr7.json b/advisories/unreviewed/2024/07/GHSA-257h-x72g-4wr7/GHSA-257h-x72g-4wr7.json index b8d4e0a19b3..c15c319419a 100644 --- a/advisories/unreviewed/2024/07/GHSA-257h-x72g-4wr7/GHSA-257h-x72g-4wr7.json +++ b/advisories/unreviewed/2024/07/GHSA-257h-x72g-4wr7/GHSA-257h-x72g-4wr7.json @@ -7,12 +7,8 @@ "CVE-2024-41017" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\njfs: don't walk off the end of ealist\n\nAdd a check before visiting the members of ea to\nmake sure each ea stays within the ealist.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-298c-rvvp-xh7q/GHSA-298c-rvvp-xh7q.json b/advisories/unreviewed/2024/07/GHSA-298c-rvvp-xh7q/GHSA-298c-rvvp-xh7q.json index afba244a5d4..a43ec92dd0f 100644 --- a/advisories/unreviewed/2024/07/GHSA-298c-rvvp-xh7q/GHSA-298c-rvvp-xh7q.json +++ b/advisories/unreviewed/2024/07/GHSA-298c-rvvp-xh7q/GHSA-298c-rvvp-xh7q.json @@ -7,12 +7,8 @@ "CVE-2024-41069" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: topology: Fix references to freed memory\n\nMost users after parsing a topology file, release memory used by it, so\nhaving pointer references directly into topology file contents is wrong.\nUse devm_kmemdup(), to allocate memory as needed.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-2hgj-xhjg-6c4p/GHSA-2hgj-xhjg-6c4p.json b/advisories/unreviewed/2024/07/GHSA-2hgj-xhjg-6c4p/GHSA-2hgj-xhjg-6c4p.json index 7b696786cc3..aedbdace401 100644 --- a/advisories/unreviewed/2024/07/GHSA-2hgj-xhjg-6c4p/GHSA-2hgj-xhjg-6c4p.json +++ b/advisories/unreviewed/2024/07/GHSA-2hgj-xhjg-6c4p/GHSA-2hgj-xhjg-6c4p.json @@ -7,12 +7,8 @@ "CVE-2024-41019" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfs/ntfs3: Validate ff offset\n\nThis adds sanity checks for ff offset. There is a check\non rt->first_free at first, but walking through by ff\nwithout any check. If the second ff is a large offset.\nWe may encounter an out-of-bound read.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-2mrp-h89g-g693/GHSA-2mrp-h89g-g693.json b/advisories/unreviewed/2024/07/GHSA-2mrp-h89g-g693/GHSA-2mrp-h89g-g693.json index e1037219b34..8518172ba87 100644 --- a/advisories/unreviewed/2024/07/GHSA-2mrp-h89g-g693/GHSA-2mrp-h89g-g693.json +++ b/advisories/unreviewed/2024/07/GHSA-2mrp-h89g-g693/GHSA-2mrp-h89g-g693.json @@ -7,12 +7,8 @@ "CVE-2024-41025" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmisc: fastrpc: Fix memory leak in audio daemon attach operation\n\nAudio PD daemon send the name as part of the init IOCTL call. This\nname needs to be copied to kernel for which memory is allocated.\nThis memory is never freed which might result in memory leak. Free\nthe memory when it is not needed.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-2rmc-r8fj-3p89/GHSA-2rmc-r8fj-3p89.json b/advisories/unreviewed/2024/07/GHSA-2rmc-r8fj-3p89/GHSA-2rmc-r8fj-3p89.json index 94205b39ed1..2faca7684bc 100644 --- a/advisories/unreviewed/2024/07/GHSA-2rmc-r8fj-3p89/GHSA-2rmc-r8fj-3p89.json +++ b/advisories/unreviewed/2024/07/GHSA-2rmc-r8fj-3p89/GHSA-2rmc-r8fj-3p89.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-2vvq-mgpq-88xw/GHSA-2vvq-mgpq-88xw.json b/advisories/unreviewed/2024/07/GHSA-2vvq-mgpq-88xw/GHSA-2vvq-mgpq-88xw.json index fbaf31fbe72..3b280c510a3 100644 --- a/advisories/unreviewed/2024/07/GHSA-2vvq-mgpq-88xw/GHSA-2vvq-mgpq-88xw.json +++ b/advisories/unreviewed/2024/07/GHSA-2vvq-mgpq-88xw/GHSA-2vvq-mgpq-88xw.json @@ -7,12 +7,8 @@ "CVE-2019-19761" ], "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -20,9 +16,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-2xcp-78pq-jqq3/GHSA-2xcp-78pq-jqq3.json b/advisories/unreviewed/2024/07/GHSA-2xcp-78pq-jqq3/GHSA-2xcp-78pq-jqq3.json index 4dd7f887a26..6e78b11df64 100644 --- a/advisories/unreviewed/2024/07/GHSA-2xcp-78pq-jqq3/GHSA-2xcp-78pq-jqq3.json +++ b/advisories/unreviewed/2024/07/GHSA-2xcp-78pq-jqq3/GHSA-2xcp-78pq-jqq3.json @@ -7,12 +7,8 @@ "CVE-2024-42091" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe: Check pat.ops before dumping PAT settings\n\nWe may leave pat.ops unset when running on brand new platform or\nwhen running as a VF. While the former is unlikely, the latter\nis valid (future) use case and will cause NPD when someone will\ntry to dump PAT settings by debugfs.\n\nIt's better to check pointer to pat.ops instead of specific .dump\nhook, as we have this hook always defined for every .ops variant.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-36gh-mcf5-3vpm/GHSA-36gh-mcf5-3vpm.json b/advisories/unreviewed/2024/07/GHSA-36gh-mcf5-3vpm/GHSA-36gh-mcf5-3vpm.json index 47c54ff4d0e..993d80dcdeb 100644 --- a/advisories/unreviewed/2024/07/GHSA-36gh-mcf5-3vpm/GHSA-36gh-mcf5-3vpm.json +++ b/advisories/unreviewed/2024/07/GHSA-36gh-mcf5-3vpm/GHSA-36gh-mcf5-3vpm.json @@ -7,12 +7,8 @@ "CVE-2024-41067" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: scrub: handle RST lookup error correctly\n\n[BUG]\nWhen running btrfs/060 with forced RST feature, it would crash the\nfollowing ASSERT() inside scrub_read_endio():\n\n\tASSERT(sector_nr < stripe->nr_sectors);\n\nBefore that, we would have tree dump from\nbtrfs_get_raid_extent_offset(), as we failed to find the RST entry for\nthe range.\n\n[CAUSE]\nInside scrub_submit_extent_sector_read() every time we allocated a new\nbbio we immediately called btrfs_map_block() to make sure there was some\nRST range covering the scrub target.\n\nBut if btrfs_map_block() fails, we immediately call endio for the bbio,\nwhile the bbio is newly allocated, it's completely empty.\n\nThen inside scrub_read_endio(), we go through the bvecs to find\nthe sector number (as bi_sector is no longer reliable if the bio is\nsubmitted to lower layers).\n\nAnd since the bio is empty, such bvecs iteration would not find any\nsector matching the sector, and return sector_nr == stripe->nr_sectors,\ntriggering the ASSERT().\n\n[FIX]\nInstead of calling btrfs_map_block() after allocating a new bbio, call\nbtrfs_map_block() first.\n\nSince our only objective of calling btrfs_map_block() is only to update\nstripe_len, there is really no need to do that after btrfs_alloc_bio().\n\nThis new timing would avoid the problem of handling empty bbio\ncompletely, and in fact fixes a possible race window for the old code,\nwhere if the submission thread is the only owner of the pending_io, the\nscrub would never finish (since we didn't decrease the pending_io\ncounter).\n\nAlthough the root cause of RST lookup failure still needs to be\naddressed.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-36wr-w868-hx2g/GHSA-36wr-w868-hx2g.json b/advisories/unreviewed/2024/07/GHSA-36wr-w868-hx2g/GHSA-36wr-w868-hx2g.json index 5bfe0fbae9b..3aaa873035e 100644 --- a/advisories/unreviewed/2024/07/GHSA-36wr-w868-hx2g/GHSA-36wr-w868-hx2g.json +++ b/advisories/unreviewed/2024/07/GHSA-36wr-w868-hx2g/GHSA-36wr-w868-hx2g.json @@ -7,12 +7,8 @@ "CVE-2024-41030" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: discard write access to the directory open\n\nmay_open() does not allow a directory to be opened with the write access.\nHowever, some writing flags set by client result in adding write access\non server, making ksmbd incompatible with FUSE file system. Simply, let's\ndiscard the write access when opening a directory.\n\nlist_add corruption. next is NULL.\n------------[ cut here ]------------\nkernel BUG at lib/list_debug.c:26!\npc : __list_add_valid+0x88/0xbc\nlr : __list_add_valid+0x88/0xbc\nCall trace:\n__list_add_valid+0x88/0xbc\nfuse_finish_open+0x11c/0x170\nfuse_open_common+0x284/0x5e8\nfuse_dir_open+0x14/0x24\ndo_dentry_open+0x2a4/0x4e0\ndentry_open+0x50/0x80\nsmb2_open+0xbe4/0x15a4\nhandle_ksmbd_work+0x478/0x5ec\nprocess_one_work+0x1b4/0x448\nworker_thread+0x25c/0x430\nkthread+0x104/0x1d4\nret_from_fork+0x10/0x20", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-376c-xjc8-68w9/GHSA-376c-xjc8-68w9.json b/advisories/unreviewed/2024/07/GHSA-376c-xjc8-68w9/GHSA-376c-xjc8-68w9.json index 449c63acb48..af0dbf93d2c 100644 --- a/advisories/unreviewed/2024/07/GHSA-376c-xjc8-68w9/GHSA-376c-xjc8-68w9.json +++ b/advisories/unreviewed/2024/07/GHSA-376c-xjc8-68w9/GHSA-376c-xjc8-68w9.json @@ -7,12 +7,8 @@ "CVE-2024-41031" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/filemap: skip to create PMD-sized page cache if needed\n\nOn ARM64, HPAGE_PMD_ORDER is 13 when the base page size is 64KB. The\nPMD-sized page cache can't be supported by xarray as the following error\nmessages indicate.\n\n------------[ cut here ]------------\nWARNING: CPU: 35 PID: 7484 at lib/xarray.c:1025 xas_split_alloc+0xf8/0x128\nModules linked in: nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib \\\nnft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct \\\nnft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 \\\nip_set rfkill nf_tables nfnetlink vfat fat virtio_balloon drm \\\nfuse xfs libcrc32c crct10dif_ce ghash_ce sha2_ce sha256_arm64 \\\nsha1_ce virtio_net net_failover virtio_console virtio_blk failover \\\ndimlib virtio_mmio\nCPU: 35 PID: 7484 Comm: test Kdump: loaded Tainted: G W 6.10.0-rc5-gavin+ #9\nHardware name: QEMU KVM Virtual Machine, BIOS edk2-20240524-1.el9 05/24/2024\npstate: 83400005 (Nzcv daif +PAN -UAO +TCO +DIT -SSBS BTYPE=--)\npc : xas_split_alloc+0xf8/0x128\nlr : split_huge_page_to_list_to_order+0x1c4/0x720\nsp : ffff800087a4f6c0\nx29: ffff800087a4f6c0 x28: ffff800087a4f720 x27: 000000001fffffff\nx26: 0000000000000c40 x25: 000000000000000d x24: ffff00010625b858\nx23: ffff800087a4f720 x22: ffffffdfc0780000 x21: 0000000000000000\nx20: 0000000000000000 x19: ffffffdfc0780000 x18: 000000001ff40000\nx17: 00000000ffffffff x16: 0000018000000000 x15: 51ec004000000000\nx14: 0000e00000000000 x13: 0000000000002000 x12: 0000000000000020\nx11: 51ec000000000000 x10: 51ece1c0ffff8000 x9 : ffffbeb961a44d28\nx8 : 0000000000000003 x7 : ffffffdfc0456420 x6 : ffff0000e1aa6eb8\nx5 : 20bf08b4fe778fca x4 : ffffffdfc0456420 x3 : 0000000000000c40\nx2 : 000000000000000d x1 : 000000000000000c x0 : 0000000000000000\nCall trace:\n xas_split_alloc+0xf8/0x128\n split_huge_page_to_list_to_order+0x1c4/0x720\n truncate_inode_partial_folio+0xdc/0x160\n truncate_inode_pages_range+0x1b4/0x4a8\n truncate_pagecache_range+0x84/0xa0\n xfs_flush_unmap_range+0x70/0x90 [xfs]\n xfs_file_fallocate+0xfc/0x4d8 [xfs]\n vfs_fallocate+0x124/0x2e8\n ksys_fallocate+0x4c/0xa0\n __arm64_sys_fallocate+0x24/0x38\n invoke_syscall.constprop.0+0x7c/0xd8\n do_el0_svc+0xb4/0xd0\n el0_svc+0x44/0x1d8\n el0t_64_sync_handler+0x134/0x150\n el0t_64_sync+0x17c/0x180\n\nFix it by skipping to allocate PMD-sized page cache when its size is\nlarger than MAX_PAGECACHE_ORDER. For this specific case, we will fall to\nregular path where the readahead window is determined by BDI's sysfs file\n(read_ahead_kb).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-3f49-4398-jj66/GHSA-3f49-4398-jj66.json b/advisories/unreviewed/2024/07/GHSA-3f49-4398-jj66/GHSA-3f49-4398-jj66.json index e85691dd225..31e28b67abf 100644 --- a/advisories/unreviewed/2024/07/GHSA-3f49-4398-jj66/GHSA-3f49-4398-jj66.json +++ b/advisories/unreviewed/2024/07/GHSA-3f49-4398-jj66/GHSA-3f49-4398-jj66.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-3g2p-rjfc-78cj/GHSA-3g2p-rjfc-78cj.json b/advisories/unreviewed/2024/07/GHSA-3g2p-rjfc-78cj/GHSA-3g2p-rjfc-78cj.json index e580e663c96..35e656bb070 100644 --- a/advisories/unreviewed/2024/07/GHSA-3g2p-rjfc-78cj/GHSA-3g2p-rjfc-78cj.json +++ b/advisories/unreviewed/2024/07/GHSA-3g2p-rjfc-78cj/GHSA-3g2p-rjfc-78cj.json @@ -7,12 +7,8 @@ "CVE-2024-41072" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: cfg80211: wext: add extra SIOCSIWSCAN data check\n\nIn 'cfg80211_wext_siwscan()', add extra check whether number of\nchannels passed via 'ioctl(sock, SIOCSIWSCAN, ...)' doesn't exceed\nIW_MAX_FREQUENCIES and reject invalid request with -EINVAL otherwise.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-3v9v-qj74-rc8h/GHSA-3v9v-qj74-rc8h.json b/advisories/unreviewed/2024/07/GHSA-3v9v-qj74-rc8h/GHSA-3v9v-qj74-rc8h.json index a3275b97053..2339cded604 100644 --- a/advisories/unreviewed/2024/07/GHSA-3v9v-qj74-rc8h/GHSA-3v9v-qj74-rc8h.json +++ b/advisories/unreviewed/2024/07/GHSA-3v9v-qj74-rc8h/GHSA-3v9v-qj74-rc8h.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-4794-rjc7-hpw2/GHSA-4794-rjc7-hpw2.json b/advisories/unreviewed/2024/07/GHSA-4794-rjc7-hpw2/GHSA-4794-rjc7-hpw2.json index efa8440a2d4..a01e6e700ac 100644 --- a/advisories/unreviewed/2024/07/GHSA-4794-rjc7-hpw2/GHSA-4794-rjc7-hpw2.json +++ b/advisories/unreviewed/2024/07/GHSA-4794-rjc7-hpw2/GHSA-4794-rjc7-hpw2.json @@ -7,12 +7,8 @@ "CVE-2024-42098" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: ecdh - explicitly zeroize private_key\n\nprivate_key is overwritten with the key parameter passed in by the\ncaller (if present), or alternatively a newly generated private key.\nHowever, it is possible that the caller provides a key (or the newly\ngenerated key) which is shorter than the previous key. In that\nscenario, some key material from the previous key would not be\noverwritten. The easiest solution is to explicitly zeroize the entire\nprivate_key array first.\n\nNote that this patch slightly changes the behavior of this function:\npreviously, if the ecc_gen_privkey failed, the old private_key would\nremain. Now, the private_key is always zeroized. This behavior is\nconsistent with the case where params.key is set and ecc_is_key_valid\nfails.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-4cvc-j8gf-mg3g/GHSA-4cvc-j8gf-mg3g.json b/advisories/unreviewed/2024/07/GHSA-4cvc-j8gf-mg3g/GHSA-4cvc-j8gf-mg3g.json index 550311986a1..043a67baeb7 100644 --- a/advisories/unreviewed/2024/07/GHSA-4cvc-j8gf-mg3g/GHSA-4cvc-j8gf-mg3g.json +++ b/advisories/unreviewed/2024/07/GHSA-4cvc-j8gf-mg3g/GHSA-4cvc-j8gf-mg3g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-5p8g-h9f2-v3vj/GHSA-5p8g-h9f2-v3vj.json b/advisories/unreviewed/2024/07/GHSA-5p8g-h9f2-v3vj/GHSA-5p8g-h9f2-v3vj.json index bc68e25eff0..f9fc34e9b58 100644 --- a/advisories/unreviewed/2024/07/GHSA-5p8g-h9f2-v3vj/GHSA-5p8g-h9f2-v3vj.json +++ b/advisories/unreviewed/2024/07/GHSA-5p8g-h9f2-v3vj/GHSA-5p8g-h9f2-v3vj.json @@ -7,12 +7,8 @@ "CVE-2024-41075" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncachefiles: add consistency check for copen/cread\n\nThis prevents malicious processes from completing random copen/cread\nrequests and crashing the system. Added checks are listed below:\n\n * Generic, copen can only complete open requests, and cread can only\n complete read requests.\n * For copen, ondemand_id must not be 0, because this indicates that the\n request has not been read by the daemon.\n * For cread, the object corresponding to fd and req should be the same.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-6f6m-xj5v-j35q/GHSA-6f6m-xj5v-j35q.json b/advisories/unreviewed/2024/07/GHSA-6f6m-xj5v-j35q/GHSA-6f6m-xj5v-j35q.json index f3fa043b9bc..26f5f00e479 100644 --- a/advisories/unreviewed/2024/07/GHSA-6f6m-xj5v-j35q/GHSA-6f6m-xj5v-j35q.json +++ b/advisories/unreviewed/2024/07/GHSA-6f6m-xj5v-j35q/GHSA-6f6m-xj5v-j35q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-6fw4-4fx8-78rj/GHSA-6fw4-4fx8-78rj.json b/advisories/unreviewed/2024/07/GHSA-6fw4-4fx8-78rj/GHSA-6fw4-4fx8-78rj.json index be8fc363435..de723790069 100644 --- a/advisories/unreviewed/2024/07/GHSA-6fw4-4fx8-78rj/GHSA-6fw4-4fx8-78rj.json +++ b/advisories/unreviewed/2024/07/GHSA-6fw4-4fx8-78rj/GHSA-6fw4-4fx8-78rj.json @@ -7,12 +7,8 @@ "CVE-2023-52887" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: can: j1939: enhanced error handling for tightly received RTS messages in xtp_rx_rts_session_new\n\nThis patch enhances error handling in scenarios with RTS (Request to\nSend) messages arriving closely. It replaces the less informative WARN_ON_ONCE\nbacktraces with a new error handling method. This provides clearer error\nmessages and allows for the early termination of problematic sessions.\nPreviously, sessions were only released at the end of j1939_xtp_rx_rts().\n\nPotentially this could be reproduced with something like:\ntestj1939 -r vcan0:0x80 &\nwhile true; do\n\t# send first RTS\n\tcansend vcan0 18EC8090#1014000303002301;\n\t# send second RTS\n\tcansend vcan0 18EC8090#1014000303002301;\n\t# send abort\n\tcansend vcan0 18EC8090#ff00000000002301;\ndone", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-83hh-pj86-jr69/GHSA-83hh-pj86-jr69.json b/advisories/unreviewed/2024/07/GHSA-83hh-pj86-jr69/GHSA-83hh-pj86-jr69.json index df5214efaa3..0e663bddb6d 100644 --- a/advisories/unreviewed/2024/07/GHSA-83hh-pj86-jr69/GHSA-83hh-pj86-jr69.json +++ b/advisories/unreviewed/2024/07/GHSA-83hh-pj86-jr69/GHSA-83hh-pj86-jr69.json @@ -7,12 +7,8 @@ "CVE-2024-41051" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncachefiles: wait for ondemand_object_worker to finish when dropping object\n\nWhen queuing ondemand_object_worker() to re-open the object,\ncachefiles_object is not pinned. The cachefiles_object may be freed when\nthe pending read request is completed intentionally and the related\nerofs is umounted. If ondemand_object_worker() runs after the object is\nfreed, it will incur use-after-free problem as shown below.\n\nprocess A processs B process C process D\n\ncachefiles_ondemand_send_req()\n// send a read req X\n// wait for its completion\n\n // close ondemand fd\n cachefiles_ondemand_fd_release()\n // set object as CLOSE\n\n cachefiles_ondemand_daemon_read()\n // set object as REOPENING\n queue_work(fscache_wq, &info->ondemand_work)\n\n // close /dev/cachefiles\n cachefiles_daemon_release\n cachefiles_flush_reqs\n complete(&req->done)\n\n// read req X is completed\n// umount the erofs fs\ncachefiles_put_object()\n// object will be freed\ncachefiles_ondemand_deinit_obj_info()\nkmem_cache_free(object)\n // both info and object are freed\n ondemand_object_worker()\n\nWhen dropping an object, it is no longer necessary to reopen the object,\nso use cancel_work_sync() to cancel or wait for ondemand_object_worker()\nto finish.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-86q3-fjwx-gw6h/GHSA-86q3-fjwx-gw6h.json b/advisories/unreviewed/2024/07/GHSA-86q3-fjwx-gw6h/GHSA-86q3-fjwx-gw6h.json index 29a60819c72..89bf72fdc3f 100644 --- a/advisories/unreviewed/2024/07/GHSA-86q3-fjwx-gw6h/GHSA-86q3-fjwx-gw6h.json +++ b/advisories/unreviewed/2024/07/GHSA-86q3-fjwx-gw6h/GHSA-86q3-fjwx-gw6h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-9gjm-j93v-m992/GHSA-9gjm-j93v-m992.json b/advisories/unreviewed/2024/07/GHSA-9gjm-j93v-m992/GHSA-9gjm-j93v-m992.json index 3dd86fc918c..8d4da80ecb3 100644 --- a/advisories/unreviewed/2024/07/GHSA-9gjm-j93v-m992/GHSA-9gjm-j93v-m992.json +++ b/advisories/unreviewed/2024/07/GHSA-9gjm-j93v-m992/GHSA-9gjm-j93v-m992.json @@ -7,12 +7,8 @@ "CVE-2024-41032" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm: vmalloc: check if a hash-index is in cpu_possible_mask\n\nThe problem is that there are systems where cpu_possible_mask has gaps\nbetween set CPUs, for example SPARC. In this scenario addr_to_vb_xa()\nhash function can return an index which accesses to not-possible and not\nsetup CPU area using per_cpu() macro. This results in an oops on SPARC.\n\nA per-cpu vmap_block_queue is also used as hash table, incorrectly\nassuming the cpu_possible_mask has no gaps. Fix it by adjusting an index\nto a next possible CPU.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-9w68-2pr9-7g2r/GHSA-9w68-2pr9-7g2r.json b/advisories/unreviewed/2024/07/GHSA-9w68-2pr9-7g2r/GHSA-9w68-2pr9-7g2r.json index cfac1ad8e60..8690cbce81c 100644 --- a/advisories/unreviewed/2024/07/GHSA-9w68-2pr9-7g2r/GHSA-9w68-2pr9-7g2r.json +++ b/advisories/unreviewed/2024/07/GHSA-9w68-2pr9-7g2r/GHSA-9w68-2pr9-7g2r.json @@ -7,12 +7,8 @@ "CVE-2024-41065" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\npowerpc/pseries: Whitelist dtl slub object for copying to userspace\n\nReading the dispatch trace log from /sys/kernel/debug/powerpc/dtl/cpu-*\nresults in a BUG() when the config CONFIG_HARDENED_USERCOPY is enabled as\nshown below.\n\n kernel BUG at mm/usercopy.c:102!\n Oops: Exception in kernel mode, sig: 5 [#1]\n LE PAGE_SIZE=64K MMU=Radix SMP NR_CPUS=2048 NUMA pSeries\n Modules linked in: xfs libcrc32c dm_service_time sd_mod t10_pi sg ibmvfc\n scsi_transport_fc ibmveth pseries_wdt dm_multipath dm_mirror dm_region_hash dm_log dm_mod fuse\n CPU: 27 PID: 1815 Comm: python3 Not tainted 6.10.0-rc3 #85\n Hardware name: IBM,9040-MRX POWER10 (raw) 0x800200 0xf000006 of:IBM,FW1060.00 (NM1060_042) hv:phyp pSeries\n NIP: c0000000005d23d4 LR: c0000000005d23d0 CTR: 00000000006ee6f8\n REGS: c000000120c078c0 TRAP: 0700 Not tainted (6.10.0-rc3)\n MSR: 8000000000029033 CR: 2828220f XER: 0000000e\n CFAR: c0000000001fdc80 IRQMASK: 0\n [ ... GPRs omitted ... ]\n NIP [c0000000005d23d4] usercopy_abort+0x78/0xb0\n LR [c0000000005d23d0] usercopy_abort+0x74/0xb0\n Call Trace:\n usercopy_abort+0x74/0xb0 (unreliable)\n __check_heap_object+0xf8/0x120\n check_heap_object+0x218/0x240\n __check_object_size+0x84/0x1a4\n dtl_file_read+0x17c/0x2c4\n full_proxy_read+0x8c/0x110\n vfs_read+0xdc/0x3a0\n ksys_read+0x84/0x144\n system_call_exception+0x124/0x330\n system_call_vectored_common+0x15c/0x2ec\n --- interrupt: 3000 at 0x7fff81f3ab34\n\nCommit 6d07d1cd300f (\"usercopy: Restrict non-usercopy caches to size 0\")\nrequires that only whitelisted areas in slab/slub objects can be copied to\nuserspace when usercopy hardening is enabled using CONFIG_HARDENED_USERCOPY.\nDtl contains hypervisor dispatch events which are expected to be read by\nprivileged users. Hence mark this safe for user access.\nSpecify useroffset=0 and usersize=DISPATCH_LOG_BYTES to whitelist the\nentire object.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-cc7h-jmr5-hg42/GHSA-cc7h-jmr5-hg42.json b/advisories/unreviewed/2024/07/GHSA-cc7h-jmr5-hg42/GHSA-cc7h-jmr5-hg42.json index 4dab23507ed..47d3433ca79 100644 --- a/advisories/unreviewed/2024/07/GHSA-cc7h-jmr5-hg42/GHSA-cc7h-jmr5-hg42.json +++ b/advisories/unreviewed/2024/07/GHSA-cc7h-jmr5-hg42/GHSA-cc7h-jmr5-hg42.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-fphh-62qm-fm76/GHSA-fphh-62qm-fm76.json b/advisories/unreviewed/2024/07/GHSA-fphh-62qm-fm76/GHSA-fphh-62qm-fm76.json index 87078bb6cb5..3c076872b6f 100644 --- a/advisories/unreviewed/2024/07/GHSA-fphh-62qm-fm76/GHSA-fphh-62qm-fm76.json +++ b/advisories/unreviewed/2024/07/GHSA-fphh-62qm-fm76/GHSA-fphh-62qm-fm76.json @@ -7,12 +7,8 @@ "CVE-2024-42089" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: fsl-asoc-card: set priv->pdev before using it\n\npriv->pdev pointer was set after being used in\nfsl_asoc_card_audmux_init().\nMove this assignment at the start of the probe function, so\nsub-functions can correctly use pdev through priv.\n\nfsl_asoc_card_audmux_init() dereferences priv->pdev to get access to the\ndev struct, used with dev_err macros.\nAs priv is zero-initialised, there would be a NULL pointer dereference.\nNote that if priv->dev is dereferenced before assignment but never used,\nfor example if there is no error to be printed, the driver won't crash\nprobably due to compiler optimisations.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-fxx9-q7vv-g6p2/GHSA-fxx9-q7vv-g6p2.json b/advisories/unreviewed/2024/07/GHSA-fxx9-q7vv-g6p2/GHSA-fxx9-q7vv-g6p2.json index 804336bfd1c..b2be6e5bff9 100644 --- a/advisories/unreviewed/2024/07/GHSA-fxx9-q7vv-g6p2/GHSA-fxx9-q7vv-g6p2.json +++ b/advisories/unreviewed/2024/07/GHSA-fxx9-q7vv-g6p2/GHSA-fxx9-q7vv-g6p2.json @@ -7,12 +7,8 @@ "CVE-2024-41077" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnull_blk: fix validation of block size\n\nBlock size should be between 512 and PAGE_SIZE and be a power of 2. The current\ncheck does not validate this, so update the check.\n\nWithout this patch, null_blk would Oops due to a null pointer deref when\nloaded with bs=1536 [1].\n\n\n[axboe: remove unnecessary braces and != 0 check]", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-h3gf-rw88-73j5/GHSA-h3gf-rw88-73j5.json b/advisories/unreviewed/2024/07/GHSA-h3gf-rw88-73j5/GHSA-h3gf-rw88-73j5.json index e8761e48b7d..1a35e7558b6 100644 --- a/advisories/unreviewed/2024/07/GHSA-h3gf-rw88-73j5/GHSA-h3gf-rw88-73j5.json +++ b/advisories/unreviewed/2024/07/GHSA-h3gf-rw88-73j5/GHSA-h3gf-rw88-73j5.json @@ -7,12 +7,8 @@ "CVE-2024-42086" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\niio: chemical: bme680: Fix overflows in compensate() functions\n\nThere are cases in the compensate functions of the driver that\nthere could be overflows of variables due to bit shifting ops.\nThese implications were initially discussed here [1] and they\nwere mentioned in log message of Commit 1b3bd8592780 (\"iio:\nchemical: Add support for Bosch BME680 sensor\").\n\n[1]: https://lore.kernel.org/linux-iio/20180728114028.3c1bbe81@archlinux/", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-h4v4-8v96-h2hw/GHSA-h4v4-8v96-h2hw.json b/advisories/unreviewed/2024/07/GHSA-h4v4-8v96-h2hw/GHSA-h4v4-8v96-h2hw.json index d9453998ea6..fc3f97ae6fe 100644 --- a/advisories/unreviewed/2024/07/GHSA-h4v4-8v96-h2hw/GHSA-h4v4-8v96-h2hw.json +++ b/advisories/unreviewed/2024/07/GHSA-h4v4-8v96-h2hw/GHSA-h4v4-8v96-h2hw.json @@ -7,12 +7,8 @@ "CVE-2024-42087" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/panel: ilitek-ili9881c: Fix warning with GPIO controllers that sleep\n\nThe ilitek-ili9881c controls the reset GPIO using the non-sleeping\ngpiod_set_value() function. This complains loudly when the GPIO\ncontroller needs to sleep. As the caller can sleep, use\ngpiod_set_value_cansleep() to fix the issue.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-hgr9-4345-8p9r/GHSA-hgr9-4345-8p9r.json b/advisories/unreviewed/2024/07/GHSA-hgr9-4345-8p9r/GHSA-hgr9-4345-8p9r.json index e1036ff034c..066cf9b446a 100644 --- a/advisories/unreviewed/2024/07/GHSA-hgr9-4345-8p9r/GHSA-hgr9-4345-8p9r.json +++ b/advisories/unreviewed/2024/07/GHSA-hgr9-4345-8p9r/GHSA-hgr9-4345-8p9r.json @@ -7,12 +7,8 @@ "CVE-2024-42095" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nserial: 8250_omap: Implementation of Errata i2310\n\nAs per Errata i2310[0], Erroneous timeout can be triggered,\nif this Erroneous interrupt is not cleared then it may leads\nto storm of interrupts, therefore apply Errata i2310 solution.\n\n[0] https://www.ti.com/lit/pdf/sprz536 page 23", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-hvh8-3m3h-pr4g/GHSA-hvh8-3m3h-pr4g.json b/advisories/unreviewed/2024/07/GHSA-hvh8-3m3h-pr4g/GHSA-hvh8-3m3h-pr4g.json index 63e1447d759..0c1977283ae 100644 --- a/advisories/unreviewed/2024/07/GHSA-hvh8-3m3h-pr4g/GHSA-hvh8-3m3h-pr4g.json +++ b/advisories/unreviewed/2024/07/GHSA-hvh8-3m3h-pr4g/GHSA-hvh8-3m3h-pr4g.json @@ -7,12 +7,8 @@ "CVE-2024-41056" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfirmware: cs_dsp: Use strnlen() on name fields in V1 wmfw files\n\nUse strnlen() instead of strlen() on the algorithm and coefficient name\nstring arrays in V1 wmfw files.\n\nIn V1 wmfw files the name is a NUL-terminated string in a fixed-size\narray. cs_dsp should protect against overrunning the array if the NUL\nterminator is missing.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-j29f-xrw6-fm6c/GHSA-j29f-xrw6-fm6c.json b/advisories/unreviewed/2024/07/GHSA-j29f-xrw6-fm6c/GHSA-j29f-xrw6-fm6c.json index bab7f524005..507c537ed73 100644 --- a/advisories/unreviewed/2024/07/GHSA-j29f-xrw6-fm6c/GHSA-j29f-xrw6-fm6c.json +++ b/advisories/unreviewed/2024/07/GHSA-j29f-xrw6-fm6c/GHSA-j29f-xrw6-fm6c.json @@ -7,12 +7,8 @@ "CVE-2024-41020" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfilelock: Fix fcntl/close race recovery compat path\n\nWhen I wrote commit 3cad1bc01041 (\"filelock: Remove locks reliably when\nfcntl/close race is detected\"), I missed that there are two copies of the\ncode I was patching: The normal version, and the version for 64-bit offsets\non 32-bit kernels.\nThanks to Greg KH for stumbling over this while doing the stable\nbackport...\n\nApply exactly the same fix to the compat path for 32-bit kernels.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-jpvx-wrqv-j9x2/GHSA-jpvx-wrqv-j9x2.json b/advisories/unreviewed/2024/07/GHSA-jpvx-wrqv-j9x2/GHSA-jpvx-wrqv-j9x2.json index ad7efdd2c26..e71f85e7677 100644 --- a/advisories/unreviewed/2024/07/GHSA-jpvx-wrqv-j9x2/GHSA-jpvx-wrqv-j9x2.json +++ b/advisories/unreviewed/2024/07/GHSA-jpvx-wrqv-j9x2/GHSA-jpvx-wrqv-j9x2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-jrqm-457g-p76m/GHSA-jrqm-457g-p76m.json b/advisories/unreviewed/2024/07/GHSA-jrqm-457g-p76m/GHSA-jrqm-457g-p76m.json index 12190b3ef5d..5a82c670842 100644 --- a/advisories/unreviewed/2024/07/GHSA-jrqm-457g-p76m/GHSA-jrqm-457g-p76m.json +++ b/advisories/unreviewed/2024/07/GHSA-jrqm-457g-p76m/GHSA-jrqm-457g-p76m.json @@ -7,12 +7,8 @@ "CVE-2024-4848" ], "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -20,9 +16,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-m6vw-xffc-mq69/GHSA-m6vw-xffc-mq69.json b/advisories/unreviewed/2024/07/GHSA-m6vw-xffc-mq69/GHSA-m6vw-xffc-mq69.json index eaa708f5f1e..0915d051f19 100644 --- a/advisories/unreviewed/2024/07/GHSA-m6vw-xffc-mq69/GHSA-m6vw-xffc-mq69.json +++ b/advisories/unreviewed/2024/07/GHSA-m6vw-xffc-mq69/GHSA-m6vw-xffc-mq69.json @@ -7,12 +7,8 @@ "CVE-2024-41022" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: Fix signedness bug in sdma_v4_0_process_trap_irq()\n\nThe \"instance\" variable needs to be signed for the error handling to work.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-mr66-qfpc-4h9r/GHSA-mr66-qfpc-4h9r.json b/advisories/unreviewed/2024/07/GHSA-mr66-qfpc-4h9r/GHSA-mr66-qfpc-4h9r.json index 225a18078ac..95adec2bff1 100644 --- a/advisories/unreviewed/2024/07/GHSA-mr66-qfpc-4h9r/GHSA-mr66-qfpc-4h9r.json +++ b/advisories/unreviewed/2024/07/GHSA-mr66-qfpc-4h9r/GHSA-mr66-qfpc-4h9r.json @@ -7,12 +7,8 @@ "CVE-2024-41013" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nxfs: don't walk off the end of a directory data block\n\nThis adds sanity checks for xfs_dir2_data_unused and xfs_dir2_data_entry\nto make sure don't stray beyond valid memory region. Before patching, the\nloop simply checks that the start offset of the dup and dep is within the\nrange. So in a crafted image, if last entry is xfs_dir2_data_unused, we\ncan change dup->length to dup->length-1 and leave 1 byte of space. In the\nnext traversal, this space will be considered as dup or dep. We may\nencounter an out of bound read when accessing the fixed members.\n\nIn the patch, we make sure that the remaining bytes large enough to hold\nan unused entry before accessing xfs_dir2_data_unused and\nxfs_dir2_data_unused is XFS_DIR2_DATA_ALIGN byte aligned. We also make\nsure that the remaining bytes large enough to hold a dirent with a\nsingle-byte name before accessing xfs_dir2_data_entry.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-p33r-c638-j6rh/GHSA-p33r-c638-j6rh.json b/advisories/unreviewed/2024/07/GHSA-p33r-c638-j6rh/GHSA-p33r-c638-j6rh.json index 4441aff6e40..a88eb2de5f0 100644 --- a/advisories/unreviewed/2024/07/GHSA-p33r-c638-j6rh/GHSA-p33r-c638-j6rh.json +++ b/advisories/unreviewed/2024/07/GHSA-p33r-c638-j6rh/GHSA-p33r-c638-j6rh.json @@ -7,12 +7,8 @@ "CVE-2024-41027" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nFix userfaultfd_api to return EINVAL as expected\n\nCurrently if we request a feature that is not set in the Kernel config we\nfail silently and return all the available features. However, the man\npage indicates we should return an EINVAL.\n\nWe need to fix this issue since we can end up with a Kernel warning should\na program request the feature UFFD_FEATURE_WP_UNPOPULATED on a kernel with\nthe config not set with this feature.\n\n [ 200.812896] WARNING: CPU: 91 PID: 13634 at mm/memory.c:1660 zap_pte_range+0x43d/0x660\n [ 200.820738] Modules linked in:\n [ 200.869387] CPU: 91 PID: 13634 Comm: userfaultfd Kdump: loaded Not tainted 6.9.0-rc5+ #8\n [ 200.877477] Hardware name: Dell Inc. PowerEdge R6525/0N7YGH, BIOS 2.7.3 03/30/2022\n [ 200.885052] RIP: 0010:zap_pte_range+0x43d/0x660", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-pw84-w4v5-39jj/GHSA-pw84-w4v5-39jj.json b/advisories/unreviewed/2024/07/GHSA-pw84-w4v5-39jj/GHSA-pw84-w4v5-39jj.json index 9a4f9a0cf0b..f7d5e7981f4 100644 --- a/advisories/unreviewed/2024/07/GHSA-pw84-w4v5-39jj/GHSA-pw84-w4v5-39jj.json +++ b/advisories/unreviewed/2024/07/GHSA-pw84-w4v5-39jj/GHSA-pw84-w4v5-39jj.json @@ -7,12 +7,8 @@ "CVE-2024-41078" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: qgroup: fix quota root leak after quota disable failure\n\nIf during the quota disable we fail when cleaning the quota tree or when\ndeleting the root from the root tree, we jump to the 'out' label without\never dropping the reference on the quota root, resulting in a leak of the\nroot since fs_info->quota_root is no longer pointing to the root (we have\nset it to NULL just before those steps).\n\nFix this by always doing a btrfs_put_root() call under the 'out' label.\nThis is a problem that exists since qgroups were first added in 2012 by\ncommit bed92eae26cc (\"Btrfs: qgroup implementation and prototypes\"), but\nback then we missed a kfree on the quota root and free_extent_buffer()\ncalls on its root and commit root nodes, since back then roots were not\nyet reference counted.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-q7ch-p7wx-7pf8/GHSA-q7ch-p7wx-7pf8.json b/advisories/unreviewed/2024/07/GHSA-q7ch-p7wx-7pf8/GHSA-q7ch-p7wx-7pf8.json index 800dd019266..6cd1f8c32c5 100644 --- a/advisories/unreviewed/2024/07/GHSA-q7ch-p7wx-7pf8/GHSA-q7ch-p7wx-7pf8.json +++ b/advisories/unreviewed/2024/07/GHSA-q7ch-p7wx-7pf8/GHSA-q7ch-p7wx-7pf8.json @@ -7,12 +7,8 @@ "CVE-2024-41081" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nila: block BH in ila_output()\n\nAs explained in commit 1378817486d6 (\"tipc: block BH\nbefore using dst_cache\"), net/core/dst_cache.c\nhelpers need to be called with BH disabled.\n\nila_output() is called from lwtunnel_output()\npossibly from process context, and under rcu_read_lock().\n\nWe might be interrupted by a softirq, re-enter ila_output()\nand corrupt dst_cache data structures.\n\nFix the race by using local_bh_disable().", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-rf4m-wr4c-xxf4/GHSA-rf4m-wr4c-xxf4.json b/advisories/unreviewed/2024/07/GHSA-rf4m-wr4c-xxf4/GHSA-rf4m-wr4c-xxf4.json index f9ee282b6d6..13f242355c7 100644 --- a/advisories/unreviewed/2024/07/GHSA-rf4m-wr4c-xxf4/GHSA-rf4m-wr4c-xxf4.json +++ b/advisories/unreviewed/2024/07/GHSA-rf4m-wr4c-xxf4/GHSA-rf4m-wr4c-xxf4.json @@ -7,12 +7,8 @@ "CVE-2024-6761" ], "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -20,9 +16,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-rjr4-cj33-9qjx/GHSA-rjr4-cj33-9qjx.json b/advisories/unreviewed/2024/07/GHSA-rjr4-cj33-9qjx/GHSA-rjr4-cj33-9qjx.json index eb79e06102e..b759c6e72b2 100644 --- a/advisories/unreviewed/2024/07/GHSA-rjr4-cj33-9qjx/GHSA-rjr4-cj33-9qjx.json +++ b/advisories/unreviewed/2024/07/GHSA-rjr4-cj33-9qjx/GHSA-rjr4-cj33-9qjx.json @@ -7,12 +7,8 @@ "CVE-2024-42088" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: mediatek: mt8195: Add platform entry for ETDM1_OUT_BE dai link\n\nCommit e70b8dd26711 (\"ASoC: mediatek: mt8195: Remove afe-dai component\nand rework codec link\") removed the codec entry for the ETDM1_OUT_BE\ndai link entirely instead of replacing it with COMP_EMPTY(). This worked\nby accident as the remaining COMP_EMPTY() platform entry became the codec\nentry, and the platform entry became completely empty, effectively the\nsame as COMP_DUMMY() since snd_soc_fill_dummy_dai() doesn't do anything\nfor platform entries.\n\nThis causes a KASAN out-of-bounds warning in mtk_soundcard_common_probe()\nin sound/soc/mediatek/common/mtk-soundcard-driver.c:\n\n\tfor_each_card_prelinks(card, i, dai_link) {\n\t\tif (adsp_node && !strncmp(dai_link->name, \"AFE_SOF\", strlen(\"AFE_SOF\")))\n\t\t\tdai_link->platforms->of_node = adsp_node;\n\t\telse if (!dai_link->platforms->name && !dai_link->platforms->of_node)\n\t\t\tdai_link->platforms->of_node = platform_node;\n\t}\n\nwhere the code expects the platforms array to have space for at least one entry.\n\nAdd an COMP_EMPTY() entry so that dai_link->platforms has space.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-v6cc-wq79-7rwj/GHSA-v6cc-wq79-7rwj.json b/advisories/unreviewed/2024/07/GHSA-v6cc-wq79-7rwj/GHSA-v6cc-wq79-7rwj.json index 508681dad98..c4c9cc8bdfe 100644 --- a/advisories/unreviewed/2024/07/GHSA-v6cc-wq79-7rwj/GHSA-v6cc-wq79-7rwj.json +++ b/advisories/unreviewed/2024/07/GHSA-v6cc-wq79-7rwj/GHSA-v6cc-wq79-7rwj.json @@ -7,12 +7,8 @@ "CVE-2024-41068" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ns390/sclp: Fix sclp_init() cleanup on failure\n\nIf sclp_init() fails it only partially cleans up: if there are multiple\nfailing calls to sclp_init() sclp_state_change_event will be added several\ntimes to sclp_reg_list, which results in the following warning:\n\n------------[ cut here ]------------\nlist_add double add: new=000003ffe1598c10, prev=000003ffe1598bf0, next=000003ffe1598c10.\nWARNING: CPU: 0 PID: 1 at lib/list_debug.c:35 __list_add_valid_or_report+0xde/0xf8\nCPU: 0 PID: 1 Comm: swapper/0 Not tainted 6.10.0-rc3\nKrnl PSW : 0404c00180000000 000003ffe0d6076a (__list_add_valid_or_report+0xe2/0xf8)\n R:0 T:1 IO:0 EX:0 Key:0 M:1 W:0 P:0 AS:3 CC:0 PM:0 RI:0 EA:3\n...\nCall Trace:\n [<000003ffe0d6076a>] __list_add_valid_or_report+0xe2/0xf8\n([<000003ffe0d60766>] __list_add_valid_or_report+0xde/0xf8)\n [<000003ffe0a8d37e>] sclp_init+0x40e/0x450\n [<000003ffe00009f2>] do_one_initcall+0x42/0x1e0\n [<000003ffe15b77a6>] do_initcalls+0x126/0x150\n [<000003ffe15b7a0a>] kernel_init_freeable+0x1ba/0x1f8\n [<000003ffe0d6650e>] kernel_init+0x2e/0x180\n [<000003ffe000301c>] __ret_from_fork+0x3c/0x60\n [<000003ffe0d759ca>] ret_from_fork+0xa/0x30\n\nFix this by removing sclp_state_change_event from sclp_reg_list when\nsclp_init() fails.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-v75f-hc9p-6g26/GHSA-v75f-hc9p-6g26.json b/advisories/unreviewed/2024/07/GHSA-v75f-hc9p-6g26/GHSA-v75f-hc9p-6g26.json index 3a26cd34fd5..1ba6a4fefe3 100644 --- a/advisories/unreviewed/2024/07/GHSA-v75f-hc9p-6g26/GHSA-v75f-hc9p-6g26.json +++ b/advisories/unreviewed/2024/07/GHSA-v75f-hc9p-6g26/GHSA-v75f-hc9p-6g26.json @@ -7,12 +7,8 @@ "CVE-2024-41023" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsched/deadline: Fix task_struct reference leak\n\nDuring the execution of the following stress test with linux-rt:\n\nstress-ng --cyclic 30 --timeout 30 --minimize --quiet\n\nkmemleak frequently reported a memory leak concerning the task_struct:\n\nunreferenced object 0xffff8881305b8000 (size 16136):\n comm \"stress-ng\", pid 614, jiffies 4294883961 (age 286.412s)\n object hex dump (first 32 bytes):\n 02 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 .@..............\n 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n debug hex dump (first 16 bytes):\n 53 09 00 00 00 00 00 00 00 00 00 00 00 00 00 00 S...............\n backtrace:\n [<00000000046b6790>] dup_task_struct+0x30/0x540\n [<00000000c5ca0f0b>] copy_process+0x3d9/0x50e0\n [<00000000ced59777>] kernel_clone+0xb0/0x770\n [<00000000a50befdc>] __do_sys_clone+0xb6/0xf0\n [<000000001dbf2008>] do_syscall_64+0x5d/0xf0\n [<00000000552900ff>] entry_SYSCALL_64_after_hwframe+0x6e/0x76\n\nThe issue occurs in start_dl_timer(), which increments the task_struct\nreference count and sets a timer. The timer callback, dl_task_timer,\nis supposed to decrement the reference count upon expiration. However,\nif enqueue_task_dl() is called before the timer expires and cancels it,\nthe reference count is not decremented, leading to the leak.\n\nThis patch fixes the reference leak by ensuring the task_struct\nreference count is properly decremented when the timer is canceled.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-v799-6j2c-ph3p/GHSA-v799-6j2c-ph3p.json b/advisories/unreviewed/2024/07/GHSA-v799-6j2c-ph3p/GHSA-v799-6j2c-ph3p.json index 49f2c4b4d84..afce3024168 100644 --- a/advisories/unreviewed/2024/07/GHSA-v799-6j2c-ph3p/GHSA-v799-6j2c-ph3p.json +++ b/advisories/unreviewed/2024/07/GHSA-v799-6j2c-ph3p/GHSA-v799-6j2c-ph3p.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-v9jh-p7m3-3577/GHSA-v9jh-p7m3-3577.json b/advisories/unreviewed/2024/07/GHSA-v9jh-p7m3-3577/GHSA-v9jh-p7m3-3577.json index fb4df1014f3..bb4dbff33c4 100644 --- a/advisories/unreviewed/2024/07/GHSA-v9jh-p7m3-3577/GHSA-v9jh-p7m3-3577.json +++ b/advisories/unreviewed/2024/07/GHSA-v9jh-p7m3-3577/GHSA-v9jh-p7m3-3577.json @@ -7,12 +7,8 @@ "CVE-2024-42092" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ngpio: davinci: Validate the obtained number of IRQs\n\nValue of pdata->gpio_unbanked is taken from Device Tree. In case of broken\nDT due to any error this value can be any. Without this value validation\nthere can be out of chips->irqs array boundaries access in\ndavinci_gpio_probe().\n\nValidate the obtained nirq value so that it won't exceed the maximum\nnumber of IRQs per bank.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-vjj3-m2jf-2pfq/GHSA-vjj3-m2jf-2pfq.json b/advisories/unreviewed/2024/07/GHSA-vjj3-m2jf-2pfq/GHSA-vjj3-m2jf-2pfq.json index 97da2177682..29f3f0fa87e 100644 --- a/advisories/unreviewed/2024/07/GHSA-vjj3-m2jf-2pfq/GHSA-vjj3-m2jf-2pfq.json +++ b/advisories/unreviewed/2024/07/GHSA-vjj3-m2jf-2pfq/GHSA-vjj3-m2jf-2pfq.json @@ -7,12 +7,8 @@ "CVE-2024-42096" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86: stop playing stack games in profile_pc()\n\nThe 'profile_pc()' function is used for timer-based profiling, which\nisn't really all that relevant any more to begin with, but it also ends\nup making assumptions based on the stack layout that aren't necessarily\nvalid.\n\nBasically, the code tries to account the time spent in spinlocks to the\ncaller rather than the spinlock, and while I support that as a concept,\nit's not worth the code complexity or the KASAN warnings when no serious\nprofiling is done using timers anyway these days.\n\nAnd the code really does depend on stack layout that is only true in the\nsimplest of cases. We've lost the comment at some point (I think when\nthe 32-bit and 64-bit code was unified), but it used to say:\n\n\tAssume the lock function has either no stack frame or a copy\n\tof eflags from PUSHF.\n\nwhich explains why it just blindly loads a word or two straight off the\nstack pointer and then takes a minimal look at the values to just check\nif they might be eflags or the return pc:\n\n\tEflags always has bits 22 and up cleared unlike kernel addresses\n\nbut that basic stack layout assumption assumes that there isn't any lock\ndebugging etc going on that would complicate the code and cause a stack\nframe.\n\nIt causes KASAN unhappiness reported for years by syzkaller [1] and\nothers [2].\n\nWith no real practical reason for this any more, just remove the code.\n\nJust for historical interest, here's some background commits relating to\nthis code from 2006:\n\n 0cb91a229364 (\"i386: Account spinlocks to the caller during profiling for !FP kernels\")\n 31679f38d886 (\"Simplify profile_pc on x86-64\")\n\nand a code unification from 2009:\n\n ef4512882dbe (\"x86: time_32/64.c unify profile_pc\")\n\nbut the basics of this thing actually goes back to before the git tree.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-vm6p-m28p-wq32/GHSA-vm6p-m28p-wq32.json b/advisories/unreviewed/2024/07/GHSA-vm6p-m28p-wq32/GHSA-vm6p-m28p-wq32.json index 593253190f6..d4bcdfef756 100644 --- a/advisories/unreviewed/2024/07/GHSA-vm6p-m28p-wq32/GHSA-vm6p-m28p-wq32.json +++ b/advisories/unreviewed/2024/07/GHSA-vm6p-m28p-wq32/GHSA-vm6p-m28p-wq32.json @@ -7,12 +7,8 @@ "CVE-2024-41026" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmmc: davinci_mmc: Prevent transmitted data size from exceeding sgm's length\n\nNo check is done on the size of the data to be transmiited. This causes\na kernel panic when this size exceeds the sg_miter's length.\n\nLimit the number of transmitted bytes to sgm->length.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-vq8p-qg57-9728/GHSA-vq8p-qg57-9728.json b/advisories/unreviewed/2024/07/GHSA-vq8p-qg57-9728/GHSA-vq8p-qg57-9728.json index d1e1cf85764..6a6cb4b85b8 100644 --- a/advisories/unreviewed/2024/07/GHSA-vq8p-qg57-9728/GHSA-vq8p-qg57-9728.json +++ b/advisories/unreviewed/2024/07/GHSA-vq8p-qg57-9728/GHSA-vq8p-qg57-9728.json @@ -7,12 +7,8 @@ "CVE-2024-41079" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet: always initialize cqe.result\n\nThe spec doesn't mandate that the first two double words (aka results)\nfor the command queue entry need to be set to 0 when they are not\nused (not specified). Though, the target implemention returns 0 for TCP\nand FC but not for RDMA.\n\nLet's make RDMA behave the same and thus explicitly initializing the\nresult field. This prevents leaking any data from the stack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-vxvf-4cm8-pmg9/GHSA-vxvf-4cm8-pmg9.json b/advisories/unreviewed/2024/07/GHSA-vxvf-4cm8-pmg9/GHSA-vxvf-4cm8-pmg9.json index da1d3a2a2e8..71156184860 100644 --- a/advisories/unreviewed/2024/07/GHSA-vxvf-4cm8-pmg9/GHSA-vxvf-4cm8-pmg9.json +++ b/advisories/unreviewed/2024/07/GHSA-vxvf-4cm8-pmg9/GHSA-vxvf-4cm8-pmg9.json @@ -7,12 +7,8 @@ "CVE-2024-41074" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncachefiles: Set object to close if ondemand_id < 0 in copen\n\nIf copen is maliciously called in the user mode, it may delete the request\ncorresponding to the random id. And the request may have not been read yet.\n\nNote that when the object is set to reopen, the open request will be done\nwith the still reopen state in above case. As a result, the request\ncorresponding to this object is always skipped in select_req function, so\nthe read request is never completed and blocks other process.\n\nFix this issue by simply set object to close if its id < 0 in copen.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-w2qq-x44h-xp8c/GHSA-w2qq-x44h-xp8c.json b/advisories/unreviewed/2024/07/GHSA-w2qq-x44h-xp8c/GHSA-w2qq-x44h-xp8c.json index 2c7261c3872..8fb8706004a 100644 --- a/advisories/unreviewed/2024/07/GHSA-w2qq-x44h-xp8c/GHSA-w2qq-x44h-xp8c.json +++ b/advisories/unreviewed/2024/07/GHSA-w2qq-x44h-xp8c/GHSA-w2qq-x44h-xp8c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-w7f6-93r9-8m94/GHSA-w7f6-93r9-8m94.json b/advisories/unreviewed/2024/07/GHSA-w7f6-93r9-8m94/GHSA-w7f6-93r9-8m94.json index f16dfc9b37e..e4d039e9100 100644 --- a/advisories/unreviewed/2024/07/GHSA-w7f6-93r9-8m94/GHSA-w7f6-93r9-8m94.json +++ b/advisories/unreviewed/2024/07/GHSA-w7f6-93r9-8m94/GHSA-w7f6-93r9-8m94.json @@ -7,12 +7,8 @@ "CVE-2024-41028" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86: toshiba_acpi: Fix array out-of-bounds access\n\nIn order to use toshiba_dmi_quirks[] together with the standard DMI\nmatching functions, it must be terminated by a empty entry.\n\nSince this entry is missing, an array out-of-bounds access occurs\nevery time the quirk list is processed.\n\nFix this by adding the terminating empty entry.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-xgw8-wc8h-j56g/GHSA-xgw8-wc8h-j56g.json b/advisories/unreviewed/2024/07/GHSA-xgw8-wc8h-j56g/GHSA-xgw8-wc8h-j56g.json index a1d52dec9de..93011b278b0 100644 --- a/advisories/unreviewed/2024/07/GHSA-xgw8-wc8h-j56g/GHSA-xgw8-wc8h-j56g.json +++ b/advisories/unreviewed/2024/07/GHSA-xgw8-wc8h-j56g/GHSA-xgw8-wc8h-j56g.json @@ -7,12 +7,8 @@ "CVE-2019-19759" ], "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -20,9 +16,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/08/GHSA-6phv-2frh-h52x/GHSA-6phv-2frh-h52x.json b/advisories/unreviewed/2024/08/GHSA-6phv-2frh-h52x/GHSA-6phv-2frh-h52x.json index 939b05a5516..c7cc630ce9d 100644 --- a/advisories/unreviewed/2024/08/GHSA-6phv-2frh-h52x/GHSA-6phv-2frh-h52x.json +++ b/advisories/unreviewed/2024/08/GHSA-6phv-2frh-h52x/GHSA-6phv-2frh-h52x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-cwwj-4w92-qq6h/GHSA-cwwj-4w92-qq6h.json b/advisories/unreviewed/2024/08/GHSA-cwwj-4w92-qq6h/GHSA-cwwj-4w92-qq6h.json index d066a46a853..a76c32b0942 100644 --- a/advisories/unreviewed/2024/08/GHSA-cwwj-4w92-qq6h/GHSA-cwwj-4w92-qq6h.json +++ b/advisories/unreviewed/2024/08/GHSA-cwwj-4w92-qq6h/GHSA-cwwj-4w92-qq6h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-42h3-v86m-8hc5/GHSA-42h3-v86m-8hc5.json b/advisories/unreviewed/2024/09/GHSA-42h3-v86m-8hc5/GHSA-42h3-v86m-8hc5.json index c7c0336bb78..c907c8db190 100644 --- a/advisories/unreviewed/2024/09/GHSA-42h3-v86m-8hc5/GHSA-42h3-v86m-8hc5.json +++ b/advisories/unreviewed/2024/09/GHSA-42h3-v86m-8hc5/GHSA-42h3-v86m-8hc5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-5qfp-r7q3-257g/GHSA-5qfp-r7q3-257g.json b/advisories/unreviewed/2024/09/GHSA-5qfp-r7q3-257g/GHSA-5qfp-r7q3-257g.json index 584fbf997b9..15a63ddfd26 100644 --- a/advisories/unreviewed/2024/09/GHSA-5qfp-r7q3-257g/GHSA-5qfp-r7q3-257g.json +++ b/advisories/unreviewed/2024/09/GHSA-5qfp-r7q3-257g/GHSA-5qfp-r7q3-257g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-68hw-g496-55x6/GHSA-68hw-g496-55x6.json b/advisories/unreviewed/2024/09/GHSA-68hw-g496-55x6/GHSA-68hw-g496-55x6.json index 9aea7dfbb1c..de056e54170 100644 --- a/advisories/unreviewed/2024/09/GHSA-68hw-g496-55x6/GHSA-68hw-g496-55x6.json +++ b/advisories/unreviewed/2024/09/GHSA-68hw-g496-55x6/GHSA-68hw-g496-55x6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-68ww-7h9f-48qx/GHSA-68ww-7h9f-48qx.json b/advisories/unreviewed/2024/09/GHSA-68ww-7h9f-48qx/GHSA-68ww-7h9f-48qx.json index 29936bd5a9f..b54d4a9490a 100644 --- a/advisories/unreviewed/2024/09/GHSA-68ww-7h9f-48qx/GHSA-68ww-7h9f-48qx.json +++ b/advisories/unreviewed/2024/09/GHSA-68ww-7h9f-48qx/GHSA-68ww-7h9f-48qx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-8xm2-mrh9-q3x9/GHSA-8xm2-mrh9-q3x9.json b/advisories/unreviewed/2024/09/GHSA-8xm2-mrh9-q3x9/GHSA-8xm2-mrh9-q3x9.json index 5fae5d07a86..3125033a201 100644 --- a/advisories/unreviewed/2024/09/GHSA-8xm2-mrh9-q3x9/GHSA-8xm2-mrh9-q3x9.json +++ b/advisories/unreviewed/2024/09/GHSA-8xm2-mrh9-q3x9/GHSA-8xm2-mrh9-q3x9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-mq89-7cwq-chfg/GHSA-mq89-7cwq-chfg.json b/advisories/unreviewed/2024/09/GHSA-mq89-7cwq-chfg/GHSA-mq89-7cwq-chfg.json index ebbd9c1872d..f1e2f7f7a3c 100644 --- a/advisories/unreviewed/2024/09/GHSA-mq89-7cwq-chfg/GHSA-mq89-7cwq-chfg.json +++ b/advisories/unreviewed/2024/09/GHSA-mq89-7cwq-chfg/GHSA-mq89-7cwq-chfg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-p47w-6xhw-hhxj/GHSA-p47w-6xhw-hhxj.json b/advisories/unreviewed/2024/09/GHSA-p47w-6xhw-hhxj/GHSA-p47w-6xhw-hhxj.json index cae3c28c6f6..9e43e0bd2ee 100644 --- a/advisories/unreviewed/2024/09/GHSA-p47w-6xhw-hhxj/GHSA-p47w-6xhw-hhxj.json +++ b/advisories/unreviewed/2024/09/GHSA-p47w-6xhw-hhxj/GHSA-p47w-6xhw-hhxj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-q74x-f8wx-jrgv/GHSA-q74x-f8wx-jrgv.json b/advisories/unreviewed/2024/09/GHSA-q74x-f8wx-jrgv/GHSA-q74x-f8wx-jrgv.json index aa42a4a7895..b6fc462f289 100644 --- a/advisories/unreviewed/2024/09/GHSA-q74x-f8wx-jrgv/GHSA-q74x-f8wx-jrgv.json +++ b/advisories/unreviewed/2024/09/GHSA-q74x-f8wx-jrgv/GHSA-q74x-f8wx-jrgv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-q9mj-qff3-9v4j/GHSA-q9mj-qff3-9v4j.json b/advisories/unreviewed/2024/09/GHSA-q9mj-qff3-9v4j/GHSA-q9mj-qff3-9v4j.json index 251e9aed120..c724e3fe1f6 100644 --- a/advisories/unreviewed/2024/09/GHSA-q9mj-qff3-9v4j/GHSA-q9mj-qff3-9v4j.json +++ b/advisories/unreviewed/2024/09/GHSA-q9mj-qff3-9v4j/GHSA-q9mj-qff3-9v4j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-qf89-78m6-x24m/GHSA-qf89-78m6-x24m.json b/advisories/unreviewed/2024/09/GHSA-qf89-78m6-x24m/GHSA-qf89-78m6-x24m.json index 69a200be01d..31d6a0f954c 100644 --- a/advisories/unreviewed/2024/09/GHSA-qf89-78m6-x24m/GHSA-qf89-78m6-x24m.json +++ b/advisories/unreviewed/2024/09/GHSA-qf89-78m6-x24m/GHSA-qf89-78m6-x24m.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-v3gc-cff3-2vg3/GHSA-v3gc-cff3-2vg3.json b/advisories/unreviewed/2024/09/GHSA-v3gc-cff3-2vg3/GHSA-v3gc-cff3-2vg3.json index 9236303e9f0..36c313ab935 100644 --- a/advisories/unreviewed/2024/09/GHSA-v3gc-cff3-2vg3/GHSA-v3gc-cff3-2vg3.json +++ b/advisories/unreviewed/2024/09/GHSA-v3gc-cff3-2vg3/GHSA-v3gc-cff3-2vg3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-wpr3-95vq-q76j/GHSA-wpr3-95vq-q76j.json b/advisories/unreviewed/2024/09/GHSA-wpr3-95vq-q76j/GHSA-wpr3-95vq-q76j.json index 0f6882d7693..d207e74e783 100644 --- a/advisories/unreviewed/2024/09/GHSA-wpr3-95vq-q76j/GHSA-wpr3-95vq-q76j.json +++ b/advisories/unreviewed/2024/09/GHSA-wpr3-95vq-q76j/GHSA-wpr3-95vq-q76j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-x6p2-rpj7-w423/GHSA-x6p2-rpj7-w423.json b/advisories/unreviewed/2024/09/GHSA-x6p2-rpj7-w423/GHSA-x6p2-rpj7-w423.json index 4cf977ba082..5bf0eb362c2 100644 --- a/advisories/unreviewed/2024/09/GHSA-x6p2-rpj7-w423/GHSA-x6p2-rpj7-w423.json +++ b/advisories/unreviewed/2024/09/GHSA-x6p2-rpj7-w423/GHSA-x6p2-rpj7-w423.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-x7c7-rpwp-w6fw/GHSA-x7c7-rpwp-w6fw.json b/advisories/unreviewed/2024/09/GHSA-x7c7-rpwp-w6fw/GHSA-x7c7-rpwp-w6fw.json index c77b50fae0c..25c683ae57c 100644 --- a/advisories/unreviewed/2024/09/GHSA-x7c7-rpwp-w6fw/GHSA-x7c7-rpwp-w6fw.json +++ b/advisories/unreviewed/2024/09/GHSA-x7c7-rpwp-w6fw/GHSA-x7c7-rpwp-w6fw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-xr4c-mmrv-3h6c/GHSA-xr4c-mmrv-3h6c.json b/advisories/unreviewed/2024/09/GHSA-xr4c-mmrv-3h6c/GHSA-xr4c-mmrv-3h6c.json index 18d1392ccc8..9b159140233 100644 --- a/advisories/unreviewed/2024/09/GHSA-xr4c-mmrv-3h6c/GHSA-xr4c-mmrv-3h6c.json +++ b/advisories/unreviewed/2024/09/GHSA-xr4c-mmrv-3h6c/GHSA-xr4c-mmrv-3h6c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null,