diff --git a/advisories/github-reviewed/2017/10/GHSA-98mf-8f57-64qf/GHSA-98mf-8f57-64qf.json b/advisories/github-reviewed/2017/10/GHSA-98mf-8f57-64qf/GHSA-98mf-8f57-64qf.json index 8ad90bbdcf3..e8f76422303 100644 --- a/advisories/github-reviewed/2017/10/GHSA-98mf-8f57-64qf/GHSA-98mf-8f57-64qf.json +++ b/advisories/github-reviewed/2017/10/GHSA-98mf-8f57-64qf/GHSA-98mf-8f57-64qf.json @@ -8,9 +8,7 @@ ], "summary": "actionpack Cross-site Scripting vulnerability", "details": "Cross-site scripting (XSS) vulnerability in `actionpack/lib/action_view/helpers/form_tag_helper.rb` in Ruby on Rails 3.x before 3.0.17, 3.1.x before 3.1.8, and 3.2.x before 3.2.8 allows remote attackers to inject arbitrary web script or HTML via the `prompt` field to the `select_tag` helper.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2017/10/GHSA-cf36-985g-v73c/GHSA-cf36-985g-v73c.json b/advisories/github-reviewed/2017/10/GHSA-cf36-985g-v73c/GHSA-cf36-985g-v73c.json index f59213ce324..10046cbc869 100644 --- a/advisories/github-reviewed/2017/10/GHSA-cf36-985g-v73c/GHSA-cf36-985g-v73c.json +++ b/advisories/github-reviewed/2017/10/GHSA-cf36-985g-v73c/GHSA-cf36-985g-v73c.json @@ -8,9 +8,7 @@ ], "summary": "omniauth-facebook Cross-Site Request Forgery vulnerability", "details": "The omniauth-facebook gem 1.4.1 before 1.5.0 does not properly store the session parameter, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks via the state parameter.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2017/10/GHSA-j838-vfpq-fmf2/GHSA-j838-vfpq-fmf2.json b/advisories/github-reviewed/2017/10/GHSA-j838-vfpq-fmf2/GHSA-j838-vfpq-fmf2.json index a560e6f0460..b37dfe17520 100644 --- a/advisories/github-reviewed/2017/10/GHSA-j838-vfpq-fmf2/GHSA-j838-vfpq-fmf2.json +++ b/advisories/github-reviewed/2017/10/GHSA-j838-vfpq-fmf2/GHSA-j838-vfpq-fmf2.json @@ -8,9 +8,7 @@ ], "summary": "actionpack Cross-site Scripting vulnerability", "details": "The sanitize helper in `lib/action_controller/vendor/html-scanner/html/sanitizer.rb` in the Action Pack component in Ruby on Rails before 2.3.18, 3.0.x and 3.1.x before 3.1.12, and 3.2.x before 3.2.13 does not properly handle encoded `:` (colon) characters in URLs, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted scheme name, as demonstrated by including a `:` sequence.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2017/10/GHSA-j96r-xvjq-r9pg/GHSA-j96r-xvjq-r9pg.json b/advisories/github-reviewed/2017/10/GHSA-j96r-xvjq-r9pg/GHSA-j96r-xvjq-r9pg.json index 6657ea8dc0e..be83d3cf8bf 100644 --- a/advisories/github-reviewed/2017/10/GHSA-j96r-xvjq-r9pg/GHSA-j96r-xvjq-r9pg.json +++ b/advisories/github-reviewed/2017/10/GHSA-j96r-xvjq-r9pg/GHSA-j96r-xvjq-r9pg.json @@ -8,9 +8,7 @@ ], "summary": "activesupport vulnerable to Denial of Service via large XML document depth", "details": "The (1) `jdom.rb` and (2) `rexml.rb` components in Active Support in Ruby on Rails before 4.1.11 and 4.2.x before 4.2.2, when JDOM or REXML is enabled, allow remote attackers to cause a denial of service (SystemStackError) via a large XML document depth.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -82,9 +80,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2020-06-16T21:42:52Z", diff --git a/advisories/github-reviewed/2017/10/GHSA-mx9f-w8qq-q5jf/GHSA-mx9f-w8qq-q5jf.json b/advisories/github-reviewed/2017/10/GHSA-mx9f-w8qq-q5jf/GHSA-mx9f-w8qq-q5jf.json index 4f6deff5e85..4b284781216 100644 --- a/advisories/github-reviewed/2017/10/GHSA-mx9f-w8qq-q5jf/GHSA-mx9f-w8qq-q5jf.json +++ b/advisories/github-reviewed/2017/10/GHSA-mx9f-w8qq-q5jf/GHSA-mx9f-w8qq-q5jf.json @@ -8,9 +8,7 @@ ], "summary": "rest-client allows local users to obtain sensitive information by reading the log", "details": "REST client for Ruby (aka rest-client) before 1.7.3 logs usernames and passwords, which allows local users to obtain sensitive information by reading the log.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2017/10/GHSA-p463-639r-q9g9/GHSA-p463-639r-q9g9.json b/advisories/github-reviewed/2017/10/GHSA-p463-639r-q9g9/GHSA-p463-639r-q9g9.json index 404b02c785b..b7896fd9658 100644 --- a/advisories/github-reviewed/2017/10/GHSA-p463-639r-q9g9/GHSA-p463-639r-q9g9.json +++ b/advisories/github-reviewed/2017/10/GHSA-p463-639r-q9g9/GHSA-p463-639r-q9g9.json @@ -8,9 +8,7 @@ ], "summary": "Dragonfly Code Injection vulnerability", "details": "The Dragonfly gem 0.7 before 0.8.6 and 0.9.x before 0.9.13 for Ruby, when used with Ruby on Rails, allows remote attackers to execute arbitrary code via a crafted request.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2017/10/GHSA-qv8p-v9qw-wc7g/GHSA-qv8p-v9qw-wc7g.json b/advisories/github-reviewed/2017/10/GHSA-qv8p-v9qw-wc7g/GHSA-qv8p-v9qw-wc7g.json index c803ba1eeab..b63776421bb 100644 --- a/advisories/github-reviewed/2017/10/GHSA-qv8p-v9qw-wc7g/GHSA-qv8p-v9qw-wc7g.json +++ b/advisories/github-reviewed/2017/10/GHSA-qv8p-v9qw-wc7g/GHSA-qv8p-v9qw-wc7g.json @@ -8,9 +8,7 @@ ], "summary": "activesupport Cross-site Scripting vulnerability", "details": "Cross-site scripting (XSS) vulnerability in Ruby on Rails 3.0.x before 3.0.12, 3.1.x before 3.1.4, and 3.2.x before 3.2.2 allows remote attackers to inject arbitrary web script or HTML via vectors involving a SafeBuffer object that is manipulated through certain methods.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2017/10/GHSA-vxvp-4xwc-jpp6/GHSA-vxvp-4xwc-jpp6.json b/advisories/github-reviewed/2017/10/GHSA-vxvp-4xwc-jpp6/GHSA-vxvp-4xwc-jpp6.json index 4c4b119bfef..d3d8322c2be 100644 --- a/advisories/github-reviewed/2017/10/GHSA-vxvp-4xwc-jpp6/GHSA-vxvp-4xwc-jpp6.json +++ b/advisories/github-reviewed/2017/10/GHSA-vxvp-4xwc-jpp6/GHSA-vxvp-4xwc-jpp6.json @@ -8,9 +8,7 @@ ], "summary": "activesupport Cross-site Scripting vulnerability", "details": "Cross-site scripting (XSS) vulnerability in `json/encoding.rb` in Active Support in Ruby on Rails 3.x and 4.1.x before 4.1.11 and 4.2.x before 4.2.2 allows remote attackers to inject arbitrary web script or HTML via a crafted Hash that is mishandled during JSON encoding.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2017/11/GHSA-hxhj-hp9m-qwc4/GHSA-hxhj-hp9m-qwc4.json b/advisories/github-reviewed/2017/11/GHSA-hxhj-hp9m-qwc4/GHSA-hxhj-hp9m-qwc4.json index d9faddf6418..0204b826602 100644 --- a/advisories/github-reviewed/2017/11/GHSA-hxhj-hp9m-qwc4/GHSA-hxhj-hp9m-qwc4.json +++ b/advisories/github-reviewed/2017/11/GHSA-hxhj-hp9m-qwc4/GHSA-hxhj-hp9m-qwc4.json @@ -8,9 +8,7 @@ ], "summary": "private_address_check vulnerable to bypass of Resolv.getaddresses method", "details": "The private_address_check ruby gem before 0.4.0 is vulnerable to a bypass due to use of Ruby's `Resolv.getaddresses` method, which is OS-dependent and should not be relied upon for security measures, such as when used to blacklist private network addresses to prevent server-side request forgery.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2024/10/GHSA-wcx9-ccpj-hx3c/GHSA-wcx9-ccpj-hx3c.json b/advisories/github-reviewed/2024/10/GHSA-wcx9-ccpj-hx3c/GHSA-wcx9-ccpj-hx3c.json index 3005c2dbf89..ebc28a229ef 100644 --- a/advisories/github-reviewed/2024/10/GHSA-wcx9-ccpj-hx3c/GHSA-wcx9-ccpj-hx3c.json +++ b/advisories/github-reviewed/2024/10/GHSA-wcx9-ccpj-hx3c/GHSA-wcx9-ccpj-hx3c.json @@ -3,9 +3,7 @@ "id": "GHSA-wcx9-ccpj-hx3c", "modified": "2024-10-30T18:50:39Z", "published": "2024-10-28T18:31:57Z", - "aliases": [ - - ], + "aliases": [], "summary": "Coder vulnerable to post-auth URL redirection to untrusted site ('Open Redirect')", "details": "### Summary\nAn issue on Coder's login page allows attackers to craft a Coder URL that when clicked by a logged in user could redirect them to a website the attacker controls, e.g. https://google.com.\n\n### Details\nOn the login page, Coder checks for the presence of a `redirect` query parameter. On successful login, the user would be redirected to the location of the parameter. Improper sanitization allows attackers to specify a URL outside of the Coder application to redirect users to.\n\n### Impact\nCoder users could potentially be redirected to a untrusted website if tricked into clicking a URL crafted by the attacker. Coder authentication tokens are **not** leaked to the resulting website.\n\nTo check if your deployment is vulnerable, visit the following URL for your Coder deployment:\n- `https:///login?redirect=https%3A%2F%2Fcoder.com%2Fdocs`\n\n### Patched Versions\nThis vulnerability is remedied in\n- v2.16.1\n- v2.15.3\n- v2.14.4\n\nAll versions prior to 2.3.1 are not affected.\n\n### Thanks\n- https://github.com/jchristov\n\n### References\nhttps://github.com/coder/coder/security/advisories/GHSA-wcx9-ccpj-hx3c\nhttps://github.com/coder/coder/commit/69c1d981e3131e50d52b01f6a360abadaad699e6", "severity": [ diff --git a/advisories/unreviewed/2022/03/GHSA-3pc4-pj89-2j67/GHSA-3pc4-pj89-2j67.json b/advisories/unreviewed/2022/03/GHSA-3pc4-pj89-2j67/GHSA-3pc4-pj89-2j67.json index 63487c9a2f9..e741f709c67 100644 --- a/advisories/unreviewed/2022/03/GHSA-3pc4-pj89-2j67/GHSA-3pc4-pj89-2j67.json +++ b/advisories/unreviewed/2022/03/GHSA-3pc4-pj89-2j67/GHSA-3pc4-pj89-2j67.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/03/GHSA-3vpg-mwgf-4jvj/GHSA-3vpg-mwgf-4jvj.json b/advisories/unreviewed/2022/03/GHSA-3vpg-mwgf-4jvj/GHSA-3vpg-mwgf-4jvj.json index 221223f9f34..fc84e303958 100644 --- a/advisories/unreviewed/2022/03/GHSA-3vpg-mwgf-4jvj/GHSA-3vpg-mwgf-4jvj.json +++ b/advisories/unreviewed/2022/03/GHSA-3vpg-mwgf-4jvj/GHSA-3vpg-mwgf-4jvj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/03/GHSA-45j5-gmrp-65wr/GHSA-45j5-gmrp-65wr.json b/advisories/unreviewed/2022/03/GHSA-45j5-gmrp-65wr/GHSA-45j5-gmrp-65wr.json index 4f271f6f065..f2c509fdb60 100644 --- a/advisories/unreviewed/2022/03/GHSA-45j5-gmrp-65wr/GHSA-45j5-gmrp-65wr.json +++ b/advisories/unreviewed/2022/03/GHSA-45j5-gmrp-65wr/GHSA-45j5-gmrp-65wr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/03/GHSA-g7cf-5cjw-6ppm/GHSA-g7cf-5cjw-6ppm.json b/advisories/unreviewed/2022/03/GHSA-g7cf-5cjw-6ppm/GHSA-g7cf-5cjw-6ppm.json index 3be56ea7246..77ed4dfa501 100644 --- a/advisories/unreviewed/2022/03/GHSA-g7cf-5cjw-6ppm/GHSA-g7cf-5cjw-6ppm.json +++ b/advisories/unreviewed/2022/03/GHSA-g7cf-5cjw-6ppm/GHSA-g7cf-5cjw-6ppm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/03/GHSA-xcrq-6rjw-5chw/GHSA-xcrq-6rjw-5chw.json b/advisories/unreviewed/2022/03/GHSA-xcrq-6rjw-5chw/GHSA-xcrq-6rjw-5chw.json index 167d3847ed1..2da77d1e937 100644 --- a/advisories/unreviewed/2022/03/GHSA-xcrq-6rjw-5chw/GHSA-xcrq-6rjw-5chw.json +++ b/advisories/unreviewed/2022/03/GHSA-xcrq-6rjw-5chw/GHSA-xcrq-6rjw-5chw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-35m2-7wwc-q3px/GHSA-35m2-7wwc-q3px.json b/advisories/unreviewed/2022/04/GHSA-35m2-7wwc-q3px/GHSA-35m2-7wwc-q3px.json index 7a9f4687134..f62c9df16fc 100644 --- a/advisories/unreviewed/2022/04/GHSA-35m2-7wwc-q3px/GHSA-35m2-7wwc-q3px.json +++ b/advisories/unreviewed/2022/04/GHSA-35m2-7wwc-q3px/GHSA-35m2-7wwc-q3px.json @@ -7,12 +7,8 @@ "CVE-2004-0183" ], "details": "TCPDUMP 3.8.1 and earlier allows remote attackers to cause a denial of service (crash) via ISAKMP packets containing a Delete payload with a large number of SPI's, which causes an out-of-bounds read, as demonstrated by the Striker ISAKMP Protocol Test Suite.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-6c7r-27gf-58jj/GHSA-6c7r-27gf-58jj.json b/advisories/unreviewed/2022/04/GHSA-6c7r-27gf-58jj/GHSA-6c7r-27gf-58jj.json index 2bba4fc4978..6f8f9de4972 100644 --- a/advisories/unreviewed/2022/04/GHSA-6c7r-27gf-58jj/GHSA-6c7r-27gf-58jj.json +++ b/advisories/unreviewed/2022/04/GHSA-6c7r-27gf-58jj/GHSA-6c7r-27gf-58jj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-gvmp-gr98-mp6j/GHSA-gvmp-gr98-mp6j.json b/advisories/unreviewed/2022/04/GHSA-gvmp-gr98-mp6j/GHSA-gvmp-gr98-mp6j.json index 8d913dc31c5..1ac8b69946f 100644 --- a/advisories/unreviewed/2022/04/GHSA-gvmp-gr98-mp6j/GHSA-gvmp-gr98-mp6j.json +++ b/advisories/unreviewed/2022/04/GHSA-gvmp-gr98-mp6j/GHSA-gvmp-gr98-mp6j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-jm2p-9h9p-vg22/GHSA-jm2p-9h9p-vg22.json b/advisories/unreviewed/2022/04/GHSA-jm2p-9h9p-vg22/GHSA-jm2p-9h9p-vg22.json index 9afca627fb0..36c6cb311bc 100644 --- a/advisories/unreviewed/2022/04/GHSA-jm2p-9h9p-vg22/GHSA-jm2p-9h9p-vg22.json +++ b/advisories/unreviewed/2022/04/GHSA-jm2p-9h9p-vg22/GHSA-jm2p-9h9p-vg22.json @@ -7,12 +7,8 @@ "CVE-2004-0594" ], "details": "The memory_limit functionality in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, under certain conditions such as when register_globals is enabled, allows remote attackers to execute arbitrary code by triggering a memory_limit abort during execution of the zend_hash_init function and overwriting a HashTable destructor pointer before the initialization of key data structures is complete.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-q4w6-wqgp-2r7m/GHSA-q4w6-wqgp-2r7m.json b/advisories/unreviewed/2022/04/GHSA-q4w6-wqgp-2r7m/GHSA-q4w6-wqgp-2r7m.json index 5dba1b7360c..96ee17be336 100644 --- a/advisories/unreviewed/2022/04/GHSA-q4w6-wqgp-2r7m/GHSA-q4w6-wqgp-2r7m.json +++ b/advisories/unreviewed/2022/04/GHSA-q4w6-wqgp-2r7m/GHSA-q4w6-wqgp-2r7m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-rc8v-wc74-5x2x/GHSA-rc8v-wc74-5x2x.json b/advisories/unreviewed/2022/04/GHSA-rc8v-wc74-5x2x/GHSA-rc8v-wc74-5x2x.json index 3dae8f7d5bc..2811e5f9b24 100644 --- a/advisories/unreviewed/2022/04/GHSA-rc8v-wc74-5x2x/GHSA-rc8v-wc74-5x2x.json +++ b/advisories/unreviewed/2022/04/GHSA-rc8v-wc74-5x2x/GHSA-rc8v-wc74-5x2x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-rm38-jqfm-qmjm/GHSA-rm38-jqfm-qmjm.json b/advisories/unreviewed/2022/04/GHSA-rm38-jqfm-qmjm/GHSA-rm38-jqfm-qmjm.json index 6ddd9d87994..467a0db8ea4 100644 --- a/advisories/unreviewed/2022/04/GHSA-rm38-jqfm-qmjm/GHSA-rm38-jqfm-qmjm.json +++ b/advisories/unreviewed/2022/04/GHSA-rm38-jqfm-qmjm/GHSA-rm38-jqfm-qmjm.json @@ -7,12 +7,8 @@ "CVE-2004-0184" ], "details": "Integer underflow in the isakmp_id_print for TCPDUMP 3.8.1 and earlier allows remote attackers to cause a denial of service (crash) via an ISAKMP packet with an Identification payload with a length that becomes less than 8 during byte order conversion, which causes an out-of-bounds read, as demonstrated by the Striker ISAKMP Protocol Test Suite.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-vpwh-45x6-9gjg/GHSA-vpwh-45x6-9gjg.json b/advisories/unreviewed/2022/04/GHSA-vpwh-45x6-9gjg/GHSA-vpwh-45x6-9gjg.json index 5aee81777e1..33fcbc57fc0 100644 --- a/advisories/unreviewed/2022/04/GHSA-vpwh-45x6-9gjg/GHSA-vpwh-45x6-9gjg.json +++ b/advisories/unreviewed/2022/04/GHSA-vpwh-45x6-9gjg/GHSA-vpwh-45x6-9gjg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-w82g-fr7x-r9m9/GHSA-w82g-fr7x-r9m9.json b/advisories/unreviewed/2022/04/GHSA-w82g-fr7x-r9m9/GHSA-w82g-fr7x-r9m9.json index ba70e26f7b0..ebe3590276f 100644 --- a/advisories/unreviewed/2022/04/GHSA-w82g-fr7x-r9m9/GHSA-w82g-fr7x-r9m9.json +++ b/advisories/unreviewed/2022/04/GHSA-w82g-fr7x-r9m9/GHSA-w82g-fr7x-r9m9.json @@ -7,12 +7,8 @@ "CVE-2004-0221" ], "details": "isakmpd in OpenBSD 3.4 and earlier allows remote attackers to cause a denial of service (crash) via an ISAKMP packet with a delete payload containing a large number of SPIs, which triggers an out-of-bounds read error, as demonstrated by the Striker ISAKMP Protocol Test Suite.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-wqpg-fcg8-gq9p/GHSA-wqpg-fcg8-gq9p.json b/advisories/unreviewed/2022/04/GHSA-wqpg-fcg8-gq9p/GHSA-wqpg-fcg8-gq9p.json index 40208a49c4a..2e4fd7329c9 100644 --- a/advisories/unreviewed/2022/04/GHSA-wqpg-fcg8-gq9p/GHSA-wqpg-fcg8-gq9p.json +++ b/advisories/unreviewed/2022/04/GHSA-wqpg-fcg8-gq9p/GHSA-wqpg-fcg8-gq9p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-22c3-jmcx-576g/GHSA-22c3-jmcx-576g.json b/advisories/unreviewed/2022/05/GHSA-22c3-jmcx-576g/GHSA-22c3-jmcx-576g.json index 5bb27037636..af252227a6c 100644 --- a/advisories/unreviewed/2022/05/GHSA-22c3-jmcx-576g/GHSA-22c3-jmcx-576g.json +++ b/advisories/unreviewed/2022/05/GHSA-22c3-jmcx-576g/GHSA-22c3-jmcx-576g.json @@ -7,12 +7,8 @@ "CVE-2005-2035" ], "details": "SQL injection vulnerability in login.asp for Cool Cafe (Cool Café) Chat 1.2.1 allows remote attackers to execute arbitrary SQL commands via the password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-25x6-2hgw-h5x4/GHSA-25x6-2hgw-h5x4.json b/advisories/unreviewed/2022/05/GHSA-25x6-2hgw-h5x4/GHSA-25x6-2hgw-h5x4.json index f71c9805d57..8e1e1fdc380 100644 --- a/advisories/unreviewed/2022/05/GHSA-25x6-2hgw-h5x4/GHSA-25x6-2hgw-h5x4.json +++ b/advisories/unreviewed/2022/05/GHSA-25x6-2hgw-h5x4/GHSA-25x6-2hgw-h5x4.json @@ -7,12 +7,8 @@ "CVE-2020-18446" ], "details": "Cross Site Scripting (XSS) vulnerability exists in YUNUCMS 1.1.9 via the param parameter in the insertContent function in ContentModel.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-26f9-v8xg-pg4g/GHSA-26f9-v8xg-pg4g.json b/advisories/unreviewed/2022/05/GHSA-26f9-v8xg-pg4g/GHSA-26f9-v8xg-pg4g.json index 6761f6549ff..00168af9abf 100644 --- a/advisories/unreviewed/2022/05/GHSA-26f9-v8xg-pg4g/GHSA-26f9-v8xg-pg4g.json +++ b/advisories/unreviewed/2022/05/GHSA-26f9-v8xg-pg4g/GHSA-26f9-v8xg-pg4g.json @@ -7,12 +7,8 @@ "CVE-2021-34638" ], "details": "Authenticated Directory Traversal in WordPress Download Manager <= 3.1.24 allows authenticated (Contributor+) users to obtain sensitive configuration file information, as well as allowing Author+ users to perform XSS attacks, by setting Download template to a file containing configuration information or an uploaded JavaScript with an image extension This issue affects: WordPress Download Manager version 3.1.24 and prior versions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-28wg-r79p-3484/GHSA-28wg-r79p-3484.json b/advisories/unreviewed/2022/05/GHSA-28wg-r79p-3484/GHSA-28wg-r79p-3484.json index 5bf5abfb3ed..c9dec66abb5 100644 --- a/advisories/unreviewed/2022/05/GHSA-28wg-r79p-3484/GHSA-28wg-r79p-3484.json +++ b/advisories/unreviewed/2022/05/GHSA-28wg-r79p-3484/GHSA-28wg-r79p-3484.json @@ -7,12 +7,8 @@ "CVE-2005-1971" ], "details": "Directory traversal vulnerability in InteractivePHP FusionBB .11 Beta and earlier allows remote attackers to include arbitrary local files via \"..\" sequences in the language parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-28wx-23q4-6c7c/GHSA-28wx-23q4-6c7c.json b/advisories/unreviewed/2022/05/GHSA-28wx-23q4-6c7c/GHSA-28wx-23q4-6c7c.json index 4180e845316..db45c9dabf7 100644 --- a/advisories/unreviewed/2022/05/GHSA-28wx-23q4-6c7c/GHSA-28wx-23q4-6c7c.json +++ b/advisories/unreviewed/2022/05/GHSA-28wx-23q4-6c7c/GHSA-28wx-23q4-6c7c.json @@ -7,12 +7,8 @@ "CVE-2020-21930" ], "details": "A stored cross site scripting (XSS) vulnerability in the web_attr_2 field of Eyoucms v1.4.1 allows authenticated attackers to execute arbitrary web scripts or HTML.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2cmm-2h32-f727/GHSA-2cmm-2h32-f727.json b/advisories/unreviewed/2022/05/GHSA-2cmm-2h32-f727/GHSA-2cmm-2h32-f727.json index decbe925cd3..4a443ba6f0f 100644 --- a/advisories/unreviewed/2022/05/GHSA-2cmm-2h32-f727/GHSA-2cmm-2h32-f727.json +++ b/advisories/unreviewed/2022/05/GHSA-2cmm-2h32-f727/GHSA-2cmm-2h32-f727.json @@ -7,12 +7,8 @@ "CVE-2005-2191" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Comersus shopping cart allow remote attackers to inject arbitrary web script or HTML via the (1) name parameter to comersus_backoffice_listAssignedPricesToCustomer.asp or (2) message parameter to comersus_backoffice_message.asp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2cww-cxmg-44cc/GHSA-2cww-cxmg-44cc.json b/advisories/unreviewed/2022/05/GHSA-2cww-cxmg-44cc/GHSA-2cww-cxmg-44cc.json index 717d1e9ec62..a00b1c490fe 100644 --- a/advisories/unreviewed/2022/05/GHSA-2cww-cxmg-44cc/GHSA-2cww-cxmg-44cc.json +++ b/advisories/unreviewed/2022/05/GHSA-2cww-cxmg-44cc/GHSA-2cww-cxmg-44cc.json @@ -7,12 +7,8 @@ "CVE-2005-2234" ], "details": "Buffer overflow in the getlvname command in IBM AIX 5.1, 5.2 and 5.3, might allow local users to execute arbitrary code via long command line arguments.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2f3x-7hhc-wrjh/GHSA-2f3x-7hhc-wrjh.json b/advisories/unreviewed/2022/05/GHSA-2f3x-7hhc-wrjh/GHSA-2f3x-7hhc-wrjh.json index cf230d2c7bb..01dd9b84400 100644 --- a/advisories/unreviewed/2022/05/GHSA-2f3x-7hhc-wrjh/GHSA-2f3x-7hhc-wrjh.json +++ b/advisories/unreviewed/2022/05/GHSA-2f3x-7hhc-wrjh/GHSA-2f3x-7hhc-wrjh.json @@ -7,12 +7,8 @@ "CVE-2005-2021" ], "details": "Cross-site scripting (XSS) vulnerability in cPanel 9.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the user parameter in the login page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2f44-722h-c7qc/GHSA-2f44-722h-c7qc.json b/advisories/unreviewed/2022/05/GHSA-2f44-722h-c7qc/GHSA-2f44-722h-c7qc.json index 07fd188e7da..87d3e17c288 100644 --- a/advisories/unreviewed/2022/05/GHSA-2f44-722h-c7qc/GHSA-2f44-722h-c7qc.json +++ b/advisories/unreviewed/2022/05/GHSA-2f44-722h-c7qc/GHSA-2f44-722h-c7qc.json @@ -7,12 +7,8 @@ "CVE-2021-33702" ], "details": "Under certain conditions, NetWeaver Enterprise Portal, versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode report data. An attacker can craft malicious data and print it to the report. In a successful attack, a victim opens the report, and the malicious script gets executed in the victim's browser, resulting in a Stored Cross-Site Scripting (XSS) vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2g3c-qcgf-24jv/GHSA-2g3c-qcgf-24jv.json b/advisories/unreviewed/2022/05/GHSA-2g3c-qcgf-24jv/GHSA-2g3c-qcgf-24jv.json index e37f2a15e76..77e08567628 100644 --- a/advisories/unreviewed/2022/05/GHSA-2g3c-qcgf-24jv/GHSA-2g3c-qcgf-24jv.json +++ b/advisories/unreviewed/2022/05/GHSA-2g3c-qcgf-24jv/GHSA-2g3c-qcgf-24jv.json @@ -7,12 +7,8 @@ "CVE-2021-34660" ], "details": "The WP Fusion Lite WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the startdate parameter found in the ~/includes/admin/logging/class-log-table-list.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 3.37.18.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2g67-cxmx-v5g5/GHSA-2g67-cxmx-v5g5.json b/advisories/unreviewed/2022/05/GHSA-2g67-cxmx-v5g5/GHSA-2g67-cxmx-v5g5.json index 2d826173d09..7085ba32f94 100644 --- a/advisories/unreviewed/2022/05/GHSA-2g67-cxmx-v5g5/GHSA-2g67-cxmx-v5g5.json +++ b/advisories/unreviewed/2022/05/GHSA-2g67-cxmx-v5g5/GHSA-2g67-cxmx-v5g5.json @@ -7,12 +7,8 @@ "CVE-2005-1875" ], "details": "Multiple SQL injection vulnerabilities in list.php in Exhibit Engine (EE) 1.22 allow remote attackers to execute arbitrary SQL commands via the (1) search_row, (2) sort_row, (3) order or (4) perpage parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2gq3-8655-788g/GHSA-2gq3-8655-788g.json b/advisories/unreviewed/2022/05/GHSA-2gq3-8655-788g/GHSA-2gq3-8655-788g.json index 5a1b3e32d08..87d6a36c0be 100644 --- a/advisories/unreviewed/2022/05/GHSA-2gq3-8655-788g/GHSA-2gq3-8655-788g.json +++ b/advisories/unreviewed/2022/05/GHSA-2gq3-8655-788g/GHSA-2gq3-8655-788g.json @@ -7,12 +7,8 @@ "CVE-2005-2217" ], "details": "Dansie Shopping Cart stores the vars.dat file under the web root with insufficient access control, which might allow remote attackers to obtain sensitive information such as program variables.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2mcv-gpfj-ffp5/GHSA-2mcv-gpfj-ffp5.json b/advisories/unreviewed/2022/05/GHSA-2mcv-gpfj-ffp5/GHSA-2mcv-gpfj-ffp5.json index 8c141d651b0..76d08521148 100644 --- a/advisories/unreviewed/2022/05/GHSA-2mcv-gpfj-ffp5/GHSA-2mcv-gpfj-ffp5.json +++ b/advisories/unreviewed/2022/05/GHSA-2mcv-gpfj-ffp5/GHSA-2mcv-gpfj-ffp5.json @@ -7,12 +7,8 @@ "CVE-2005-1974" ], "details": "Unspecified vulnerability in Java 2 Platform, Standard Edition (J2SE) 5.0 and 5.0 Update 1 and J2SE 1.4.2 up to 1.4.2_07, as used in multiple products and platforms including (1) HP-UX and (2) APC PowerChute, allows applications to assign permissions to themselves and gain privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2mjh-g772-crpf/GHSA-2mjh-g772-crpf.json b/advisories/unreviewed/2022/05/GHSA-2mjh-g772-crpf/GHSA-2mjh-g772-crpf.json index b1f1787105d..3f1b20bd8b4 100644 --- a/advisories/unreviewed/2022/05/GHSA-2mjh-g772-crpf/GHSA-2mjh-g772-crpf.json +++ b/advisories/unreviewed/2022/05/GHSA-2mjh-g772-crpf/GHSA-2mjh-g772-crpf.json @@ -7,12 +7,8 @@ "CVE-2005-2104" ], "details": "sysreport before 1.3.7 allows local users to obtain sensitive information via a symlink attack on a temporary directory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2mwj-qcpg-4642/GHSA-2mwj-qcpg-4642.json b/advisories/unreviewed/2022/05/GHSA-2mwj-qcpg-4642/GHSA-2mwj-qcpg-4642.json index fbda40f1a27..56e11aef295 100644 --- a/advisories/unreviewed/2022/05/GHSA-2mwj-qcpg-4642/GHSA-2mwj-qcpg-4642.json +++ b/advisories/unreviewed/2022/05/GHSA-2mwj-qcpg-4642/GHSA-2mwj-qcpg-4642.json @@ -7,12 +7,8 @@ "CVE-2005-1985" ], "details": "The Client Service for NetWare (CSNW) on Microsoft Windows 2000 SP4, XP SP1 and Sp2, and Server 2003 SP1 and earlier, allows remote attackers to execute arbitrary code due to an \"unchecked buffer\" when processing certain crafted network messages.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2p24-ppfc-qr69/GHSA-2p24-ppfc-qr69.json b/advisories/unreviewed/2022/05/GHSA-2p24-ppfc-qr69/GHSA-2p24-ppfc-qr69.json index ef1b96d3bb0..9049862f53b 100644 --- a/advisories/unreviewed/2022/05/GHSA-2p24-ppfc-qr69/GHSA-2p24-ppfc-qr69.json +++ b/advisories/unreviewed/2022/05/GHSA-2p24-ppfc-qr69/GHSA-2p24-ppfc-qr69.json @@ -7,12 +7,8 @@ "CVE-2021-38549" ], "details": "MIRACASE MHUB500 USB splitters through 2021-08-09, in certain specific use cases in which the device supplies power to audio-output equipment, allow remote attackers to recover speech signals from an LED on the device, via a telescope and an electro-optical sensor, aka a \"Glowworm\" attack. We assume that the USB splitter supplies power to some speakers. The power indicator LED of the USB splitter is connected directly to the power line, as a result, the intensity of the USB splitter's power indicator LED is correlative to its power consumption. The sound played by the connected speakers affects the USB splitter's power consumption and as a result is also correlative to the light intensity of the LED. By analyzing measurements obtained from an electro-optical sensor directed at the power indicator LED of the USB splitter, we can recover the sound played by the connected speakers.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2p42-xc4w-2gjf/GHSA-2p42-xc4w-2gjf.json b/advisories/unreviewed/2022/05/GHSA-2p42-xc4w-2gjf/GHSA-2p42-xc4w-2gjf.json index 39658ce18ad..9a5e21d36f3 100644 --- a/advisories/unreviewed/2022/05/GHSA-2p42-xc4w-2gjf/GHSA-2p42-xc4w-2gjf.json +++ b/advisories/unreviewed/2022/05/GHSA-2p42-xc4w-2gjf/GHSA-2p42-xc4w-2gjf.json @@ -7,12 +7,8 @@ "CVE-2021-38530" ], "details": "Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK40 before 2.5.1.16, RBR40 before 2.5.1.16, RBS40 before 2.5.1.16, RBK20 before 2.5.1.16, RBR20 before 2.5.1.16, RBS20 before 2.5.1.16, RBK50 before 2.5.1.16, RBR50 before 2.5.1.16, RBS50 before 2.5.1.16, and RBS50Y before 2.6.1.40.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2q83-hhgc-9wfr/GHSA-2q83-hhgc-9wfr.json b/advisories/unreviewed/2022/05/GHSA-2q83-hhgc-9wfr/GHSA-2q83-hhgc-9wfr.json index 13b4a8abf09..99206565629 100644 --- a/advisories/unreviewed/2022/05/GHSA-2q83-hhgc-9wfr/GHSA-2q83-hhgc-9wfr.json +++ b/advisories/unreviewed/2022/05/GHSA-2q83-hhgc-9wfr/GHSA-2q83-hhgc-9wfr.json @@ -7,12 +7,8 @@ "CVE-2005-2138" ], "details": "Cross-site scripting (XSS) vulnerability in index.php in Comdev eCommerce 3.0 and 3.1 allows remote attackers to inject arbitrary web script or HTML via Javascript in the onMouseOver event of an \"A\" tag in a review message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2qf6-qjgx-9hpj/GHSA-2qf6-qjgx-9hpj.json b/advisories/unreviewed/2022/05/GHSA-2qf6-qjgx-9hpj/GHSA-2qf6-qjgx-9hpj.json index 4e34c5bc113..aa4331f692b 100644 --- a/advisories/unreviewed/2022/05/GHSA-2qf6-qjgx-9hpj/GHSA-2qf6-qjgx-9hpj.json +++ b/advisories/unreviewed/2022/05/GHSA-2qf6-qjgx-9hpj/GHSA-2qf6-qjgx-9hpj.json @@ -7,12 +7,8 @@ "CVE-2005-2041" ], "details": "Buffer overflow in addschup in HAURI ViRobot 2.0, and possibly other products, allows remote attackers to execute arbitrary code via a long ViRobot_ID cookie (HTTP_COOKIE).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2r5q-64p8-g7p3/GHSA-2r5q-64p8-g7p3.json b/advisories/unreviewed/2022/05/GHSA-2r5q-64p8-g7p3/GHSA-2r5q-64p8-g7p3.json index 2b2b61efe89..511ad0883f4 100644 --- a/advisories/unreviewed/2022/05/GHSA-2r5q-64p8-g7p3/GHSA-2r5q-64p8-g7p3.json +++ b/advisories/unreviewed/2022/05/GHSA-2r5q-64p8-g7p3/GHSA-2r5q-64p8-g7p3.json @@ -7,12 +7,8 @@ "CVE-2005-1984" ], "details": "Buffer overflow in the Print Spooler service (Spoolsv.exe) for Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code via a malicious message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2r5v-rg6v-8xg5/GHSA-2r5v-rg6v-8xg5.json b/advisories/unreviewed/2022/05/GHSA-2r5v-rg6v-8xg5/GHSA-2r5v-rg6v-8xg5.json index 764b578d7a2..94cdf382b53 100644 --- a/advisories/unreviewed/2022/05/GHSA-2r5v-rg6v-8xg5/GHSA-2r5v-rg6v-8xg5.json +++ b/advisories/unreviewed/2022/05/GHSA-2r5v-rg6v-8xg5/GHSA-2r5v-rg6v-8xg5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2wmg-9g29-r2rp/GHSA-2wmg-9g29-r2rp.json b/advisories/unreviewed/2022/05/GHSA-2wmg-9g29-r2rp/GHSA-2wmg-9g29-r2rp.json index 285949a007e..03c36c7c661 100644 --- a/advisories/unreviewed/2022/05/GHSA-2wmg-9g29-r2rp/GHSA-2wmg-9g29-r2rp.json +++ b/advisories/unreviewed/2022/05/GHSA-2wmg-9g29-r2rp/GHSA-2wmg-9g29-r2rp.json @@ -7,12 +7,8 @@ "CVE-2021-32437" ], "details": "The gf_hinter_finalize function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2xjr-g6rh-fxqf/GHSA-2xjr-g6rh-fxqf.json b/advisories/unreviewed/2022/05/GHSA-2xjr-g6rh-fxqf/GHSA-2xjr-g6rh-fxqf.json index 6c9808ad16a..4d9ec160275 100644 --- a/advisories/unreviewed/2022/05/GHSA-2xjr-g6rh-fxqf/GHSA-2xjr-g6rh-fxqf.json +++ b/advisories/unreviewed/2022/05/GHSA-2xjr-g6rh-fxqf/GHSA-2xjr-g6rh-fxqf.json @@ -7,12 +7,8 @@ "CVE-2005-2232" ], "details": "Buffer overflow in invscout in IBM AIX 5.1.0 through 5.3.0 might allow local users to execute arbitrary code via a long command line argument.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3633-56c2-jr9x/GHSA-3633-56c2-jr9x.json b/advisories/unreviewed/2022/05/GHSA-3633-56c2-jr9x/GHSA-3633-56c2-jr9x.json index 124360e3a87..c57428776e0 100644 --- a/advisories/unreviewed/2022/05/GHSA-3633-56c2-jr9x/GHSA-3633-56c2-jr9x.json +++ b/advisories/unreviewed/2022/05/GHSA-3633-56c2-jr9x/GHSA-3633-56c2-jr9x.json @@ -7,12 +7,8 @@ "CVE-2021-20509" ], "details": "IBM Maximo Asset Management 7.6.0 and 7.6.1 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 198243.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3643-vfjq-qr3j/GHSA-3643-vfjq-qr3j.json b/advisories/unreviewed/2022/05/GHSA-3643-vfjq-qr3j/GHSA-3643-vfjq-qr3j.json index 3a82b50d597..117ff944fbd 100644 --- a/advisories/unreviewed/2022/05/GHSA-3643-vfjq-qr3j/GHSA-3643-vfjq-qr3j.json +++ b/advisories/unreviewed/2022/05/GHSA-3643-vfjq-qr3j/GHSA-3643-vfjq-qr3j.json @@ -7,12 +7,8 @@ "CVE-2005-2244" ], "details": "The aupair service (aupair.exe) in Cisco CallManager (CCM) 3.2 and earlier, 3.3 before 3.3(5), 4.0 before 4.0(2a)SR2b, and 4.1 4.1 before 4.1(3)SR1 allows remote attackers to execute arbitrary code or corrupt memory via crafted packets that trigger a memory allocation failure and lead to a buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-36mf-8q8h-hjmg/GHSA-36mf-8q8h-hjmg.json b/advisories/unreviewed/2022/05/GHSA-36mf-8q8h-hjmg/GHSA-36mf-8q8h-hjmg.json index 146a61f7b50..42273fe12d4 100644 --- a/advisories/unreviewed/2022/05/GHSA-36mf-8q8h-hjmg/GHSA-36mf-8q8h-hjmg.json +++ b/advisories/unreviewed/2022/05/GHSA-36mf-8q8h-hjmg/GHSA-36mf-8q8h-hjmg.json @@ -7,12 +7,8 @@ "CVE-2021-38531" ], "details": "Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects D6200 before 1.1.00.40, D7000 before 1.0.1.78, R6020 before 1.0.0.42, R6080 before 1.0.0.42, R6120 before 1.0.0.66, R6260 before 1.1.0.78, R6700v2 before 1.2.0.76, R6800 before 1.2.0.76, R6900v2 before 1.2.0.76, R7450 before 1.2.0.76, AC2100 before 1.2.0.76, and AC2400 before 1.2.0.76.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-37f4-hx4j-c54c/GHSA-37f4-hx4j-c54c.json b/advisories/unreviewed/2022/05/GHSA-37f4-hx4j-c54c/GHSA-37f4-hx4j-c54c.json index 5b7b3974d56..a9b250a1f2a 100644 --- a/advisories/unreviewed/2022/05/GHSA-37f4-hx4j-c54c/GHSA-37f4-hx4j-c54c.json +++ b/advisories/unreviewed/2022/05/GHSA-37f4-hx4j-c54c/GHSA-37f4-hx4j-c54c.json @@ -7,12 +7,8 @@ "CVE-2021-32122" ], "details": "Certain NETGEAR devices are affected by CSRF. This affects EX3700 before 1.0.0.90, EX3800 before 1.0.0.90, EX6120 before 1.0.0.64, and EX6130 before 1.0.0.44.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3823-wj6r-jpc9/GHSA-3823-wj6r-jpc9.json b/advisories/unreviewed/2022/05/GHSA-3823-wj6r-jpc9/GHSA-3823-wj6r-jpc9.json index e24d8c06dda..fc84648b414 100644 --- a/advisories/unreviewed/2022/05/GHSA-3823-wj6r-jpc9/GHSA-3823-wj6r-jpc9.json +++ b/advisories/unreviewed/2022/05/GHSA-3823-wj6r-jpc9/GHSA-3823-wj6r-jpc9.json @@ -7,12 +7,8 @@ "CVE-2005-1853" ], "details": "gopher.c in the Gopher client 3.0.5 does not properly create temporary files, which allows local users to gain privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3892-fhf4-9jgg/GHSA-3892-fhf4-9jgg.json b/advisories/unreviewed/2022/05/GHSA-3892-fhf4-9jgg/GHSA-3892-fhf4-9jgg.json index 34caa18a2db..62302337c14 100644 --- a/advisories/unreviewed/2022/05/GHSA-3892-fhf4-9jgg/GHSA-3892-fhf4-9jgg.json +++ b/advisories/unreviewed/2022/05/GHSA-3892-fhf4-9jgg/GHSA-3892-fhf4-9jgg.json @@ -7,12 +7,8 @@ "CVE-2005-2047" ], "details": "Multiple SQL injection vulnerabilities in DUware DUpaypal Pro 3.0 allow remote attackers to execute arbitrary SQL commands via the (1) iCat parameter to cat.asp, (2) iPro parameter to detail.asp, (3) iSub parameter to sub.asp, (4) iCat parameter to catEdit.asp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3937-9m84-64gp/GHSA-3937-9m84-64gp.json b/advisories/unreviewed/2022/05/GHSA-3937-9m84-64gp/GHSA-3937-9m84-64gp.json index 76f5549dfbf..2d0e6177d75 100644 --- a/advisories/unreviewed/2022/05/GHSA-3937-9m84-64gp/GHSA-3937-9m84-64gp.json +++ b/advisories/unreviewed/2022/05/GHSA-3937-9m84-64gp/GHSA-3937-9m84-64gp.json @@ -7,12 +7,8 @@ "CVE-2005-2268" ], "details": "Firefox before 1.0.5 and Mozilla before 1.7.9 does not clearly associate a Javascript dialog box with the web page that generated it, which allows remote attackers to spoof a dialog box from a trusted site and facilitates phishing attacks, aka the \"Dialog Origin Spoofing Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -80,9 +76,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3942-ccxx-8xqv/GHSA-3942-ccxx-8xqv.json b/advisories/unreviewed/2022/05/GHSA-3942-ccxx-8xqv/GHSA-3942-ccxx-8xqv.json index 17593400c07..a497f0e3db7 100644 --- a/advisories/unreviewed/2022/05/GHSA-3942-ccxx-8xqv/GHSA-3942-ccxx-8xqv.json +++ b/advisories/unreviewed/2022/05/GHSA-3942-ccxx-8xqv/GHSA-3942-ccxx-8xqv.json @@ -7,12 +7,8 @@ "CVE-2005-2117" ], "details": "Web View in Windows Explorer on Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 does not properly handle certain HTML characters in preview fields, which allows remote user-assisted attackers to execute arbitrary code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3965-7vwp-wr38/GHSA-3965-7vwp-wr38.json b/advisories/unreviewed/2022/05/GHSA-3965-7vwp-wr38/GHSA-3965-7vwp-wr38.json index 8ab87f86354..bc4ab9f77fc 100644 --- a/advisories/unreviewed/2022/05/GHSA-3965-7vwp-wr38/GHSA-3965-7vwp-wr38.json +++ b/advisories/unreviewed/2022/05/GHSA-3965-7vwp-wr38/GHSA-3965-7vwp-wr38.json @@ -7,12 +7,8 @@ "CVE-2005-2183" ], "details": "class.xmail.php in PhpXmail 0.7 through 1.1 does not properly handle large passwords, which prevents an error message from being returned and allows remote attackers to bypass authentication and gain unauthorized access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-39mv-7vmg-f2x8/GHSA-39mv-7vmg-f2x8.json b/advisories/unreviewed/2022/05/GHSA-39mv-7vmg-f2x8/GHSA-39mv-7vmg-f2x8.json index 73a79219fba..4a77b1f3bcc 100644 --- a/advisories/unreviewed/2022/05/GHSA-39mv-7vmg-f2x8/GHSA-39mv-7vmg-f2x8.json +++ b/advisories/unreviewed/2022/05/GHSA-39mv-7vmg-f2x8/GHSA-39mv-7vmg-f2x8.json @@ -7,12 +7,8 @@ "CVE-2005-2076" ], "details": "HP Version Control Repository Manager (VCRM) before 2.1.1.730 does not properly handle the \"@\" character in a proxy password, which could allow attackers with physical access to obtain portions of the password when it is displayed to the screen.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3c67-g3rm-28pr/GHSA-3c67-g3rm-28pr.json b/advisories/unreviewed/2022/05/GHSA-3c67-g3rm-28pr/GHSA-3c67-g3rm-28pr.json index 7f62cf91251..7430fc41f19 100644 --- a/advisories/unreviewed/2022/05/GHSA-3c67-g3rm-28pr/GHSA-3c67-g3rm-28pr.json +++ b/advisories/unreviewed/2022/05/GHSA-3c67-g3rm-28pr/GHSA-3c67-g3rm-28pr.json @@ -7,12 +7,8 @@ "CVE-2005-2239" ], "details": "oftpd 0.3.7 allows remote attackers to cause a denial of service via a USER command with a large number of null (\\0) characters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3f45-3hqf-qx7m/GHSA-3f45-3hqf-qx7m.json b/advisories/unreviewed/2022/05/GHSA-3f45-3hqf-qx7m/GHSA-3f45-3hqf-qx7m.json index 828f0ad8c23..3f236bd5130 100644 --- a/advisories/unreviewed/2022/05/GHSA-3f45-3hqf-qx7m/GHSA-3f45-3hqf-qx7m.json +++ b/advisories/unreviewed/2022/05/GHSA-3f45-3hqf-qx7m/GHSA-3f45-3hqf-qx7m.json @@ -7,12 +7,8 @@ "CVE-2005-2164" ], "details": "SQL injection vulnerability in Covide Groupware-CRM allows remote attackers to execute arbitrary SQL commands via unknown attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3f6g-6p3h-q27p/GHSA-3f6g-6p3h-q27p.json b/advisories/unreviewed/2022/05/GHSA-3f6g-6p3h-q27p/GHSA-3f6g-6p3h-q27p.json index 0595222cc82..a9b24cd7815 100644 --- a/advisories/unreviewed/2022/05/GHSA-3f6g-6p3h-q27p/GHSA-3f6g-6p3h-q27p.json +++ b/advisories/unreviewed/2022/05/GHSA-3f6g-6p3h-q27p/GHSA-3f6g-6p3h-q27p.json @@ -7,12 +7,8 @@ "CVE-2005-2179" ], "details": "PHP remote file inclusion vulnerability in BlogModel.php in Jaws 0.5.2 and earlier allows remote attackers to execute arbitrary PHP code via the path parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3fvg-g788-h5q8/GHSA-3fvg-g788-h5q8.json b/advisories/unreviewed/2022/05/GHSA-3fvg-g788-h5q8/GHSA-3fvg-g788-h5q8.json index 5cb0e021d54..d928e3e7fb4 100644 --- a/advisories/unreviewed/2022/05/GHSA-3fvg-g788-h5q8/GHSA-3fvg-g788-h5q8.json +++ b/advisories/unreviewed/2022/05/GHSA-3fvg-g788-h5q8/GHSA-3fvg-g788-h5q8.json @@ -7,12 +7,8 @@ "CVE-2005-2002" ], "details": "SQL injection vulnerability in content.php in Mambo 4.5.2.2 and earlier allows remote attackers to execute arbitrary SQL commands via the user_rating parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3j9h-ppgw-76q9/GHSA-3j9h-ppgw-76q9.json b/advisories/unreviewed/2022/05/GHSA-3j9h-ppgw-76q9/GHSA-3j9h-ppgw-76q9.json index 5c94d703b69..d9ffa76dda3 100644 --- a/advisories/unreviewed/2022/05/GHSA-3j9h-ppgw-76q9/GHSA-3j9h-ppgw-76q9.json +++ b/advisories/unreviewed/2022/05/GHSA-3j9h-ppgw-76q9/GHSA-3j9h-ppgw-76q9.json @@ -7,12 +7,8 @@ "CVE-2021-31655" ], "details": "Cross Site Scripting (XSS) vulnerability in TRENDnet TV-IP110WN V1.2.2.64 V1.2.2.65 V1.2.2.68 via the profile parameter. in a GET request in view.cgi.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3mpj-92q9-pvw2/GHSA-3mpj-92q9-pvw2.json b/advisories/unreviewed/2022/05/GHSA-3mpj-92q9-pvw2/GHSA-3mpj-92q9-pvw2.json index 4adf3c976c0..f7a80e2c5d6 100644 --- a/advisories/unreviewed/2022/05/GHSA-3mpj-92q9-pvw2/GHSA-3mpj-92q9-pvw2.json +++ b/advisories/unreviewed/2022/05/GHSA-3mpj-92q9-pvw2/GHSA-3mpj-92q9-pvw2.json @@ -7,12 +7,8 @@ "CVE-2005-1982" ], "details": "Unknown vulnerability in the PKINIT Protocol for Microsoft Windows 2000, Windows XP, and Windows Server 2003 could allow a local user to obtain information and spoof a server via a man-in-the-middle (MITM) attack between a client and a domain controller when PKINIT smart card authentication is being used.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3mpj-h64q-x7gf/GHSA-3mpj-h64q-x7gf.json b/advisories/unreviewed/2022/05/GHSA-3mpj-h64q-x7gf/GHSA-3mpj-h64q-x7gf.json index 79c5afcba70..6f105a8f20d 100644 --- a/advisories/unreviewed/2022/05/GHSA-3mpj-h64q-x7gf/GHSA-3mpj-h64q-x7gf.json +++ b/advisories/unreviewed/2022/05/GHSA-3mpj-h64q-x7gf/GHSA-3mpj-h64q-x7gf.json @@ -7,12 +7,8 @@ "CVE-2021-36765" ], "details": "In CODESYS EtherNetIP before 4.1.0.0, specific EtherNet/IP requests may cause a null pointer dereference in the downloaded vulnerable EtherNet/IP stack that is executed by the CODESYS Control runtime system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3phc-v747-949q/GHSA-3phc-v747-949q.json b/advisories/unreviewed/2022/05/GHSA-3phc-v747-949q/GHSA-3phc-v747-949q.json index 34e211007ff..e773002d5f1 100644 --- a/advisories/unreviewed/2022/05/GHSA-3phc-v747-949q/GHSA-3phc-v747-949q.json +++ b/advisories/unreviewed/2022/05/GHSA-3phc-v747-949q/GHSA-3phc-v747-949q.json @@ -7,12 +7,8 @@ "CVE-2020-23171" ], "details": "A vulnerability in all versions of Nim-lang allows unauthenticated attackers to write files to arbitrary directories via a crafted zip file with dot-slash characters included in the name of the crafted file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3pr4-6x9m-839x/GHSA-3pr4-6x9m-839x.json b/advisories/unreviewed/2022/05/GHSA-3pr4-6x9m-839x/GHSA-3pr4-6x9m-839x.json index 093189181c6..b2e05aa9dcc 100644 --- a/advisories/unreviewed/2022/05/GHSA-3pr4-6x9m-839x/GHSA-3pr4-6x9m-839x.json +++ b/advisories/unreviewed/2022/05/GHSA-3pr4-6x9m-839x/GHSA-3pr4-6x9m-839x.json @@ -7,12 +7,8 @@ "CVE-2021-37178" ], "details": "A vulnerability has been identified in Solid Edge SE2021 (All Versions < SE2021MP7). An XML external entity injection vulnerability in the underlying XML parser could cause the affected application to disclose arbitrary files to remote attackers by loading a specially crafted xml file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3q3q-qxg4-v82q/GHSA-3q3q-qxg4-v82q.json b/advisories/unreviewed/2022/05/GHSA-3q3q-qxg4-v82q/GHSA-3q3q-qxg4-v82q.json index 97a98c35d60..25cf5593fca 100644 --- a/advisories/unreviewed/2022/05/GHSA-3q3q-qxg4-v82q/GHSA-3q3q-qxg4-v82q.json +++ b/advisories/unreviewed/2022/05/GHSA-3q3q-qxg4-v82q/GHSA-3q3q-qxg4-v82q.json @@ -7,12 +7,8 @@ "CVE-2021-0084" ], "details": "Improper input validation in the Intel(R) Ethernet Controllers X722 and 800 series Linux RMDA driver before version 1.3.19 may allow an authenticated user to potentially enable escalation of privilege via local access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3q54-c9pf-r635/GHSA-3q54-c9pf-r635.json b/advisories/unreviewed/2022/05/GHSA-3q54-c9pf-r635/GHSA-3q54-c9pf-r635.json index a159bf1f7dd..f3047f73bd2 100644 --- a/advisories/unreviewed/2022/05/GHSA-3q54-c9pf-r635/GHSA-3q54-c9pf-r635.json +++ b/advisories/unreviewed/2022/05/GHSA-3q54-c9pf-r635/GHSA-3q54-c9pf-r635.json @@ -7,12 +7,8 @@ "CVE-2005-2113" ], "details": "SQL injection vulnerability in the loginUser function in the XMLRPC server in XOOPS 2.0.11 and earlier allows remote attackers to execute arbitrary SQL commands and bypass authentication via crafted values in an XML file, as demonstrated using the blogger.getPost method.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3rrm-g9g7-qh35/GHSA-3rrm-g9g7-qh35.json b/advisories/unreviewed/2022/05/GHSA-3rrm-g9g7-qh35/GHSA-3rrm-g9g7-qh35.json index 5f6eb16a447..c7dcd73cc12 100644 --- a/advisories/unreviewed/2022/05/GHSA-3rrm-g9g7-qh35/GHSA-3rrm-g9g7-qh35.json +++ b/advisories/unreviewed/2022/05/GHSA-3rrm-g9g7-qh35/GHSA-3rrm-g9g7-qh35.json @@ -7,12 +7,8 @@ "CVE-2005-2037" ], "details": "Multiple SQL injection vulnerabilities in Fortibus CMS 4.0.0 allow remote attackers to execute arbitrary SQL commands via (1) the username or password to logon.asp, (2) WeeklyNotesDisplay.asp, or (3) the Search page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3v3m-cp4r-m942/GHSA-3v3m-cp4r-m942.json b/advisories/unreviewed/2022/05/GHSA-3v3m-cp4r-m942/GHSA-3v3m-cp4r-m942.json index a8093bd7f72..35a36e4057a 100644 --- a/advisories/unreviewed/2022/05/GHSA-3v3m-cp4r-m942/GHSA-3v3m-cp4r-m942.json +++ b/advisories/unreviewed/2022/05/GHSA-3v3m-cp4r-m942/GHSA-3v3m-cp4r-m942.json @@ -7,12 +7,8 @@ "CVE-2021-38382" ], "details": "Live555 through 1.08 does not handle Matroska and Ogg files properly. Sending two successive RTSP SETUP commands for the same track causes a Use-After-Free and daemon crash.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3vvx-rwp5-c7c5/GHSA-3vvx-rwp5-c7c5.json b/advisories/unreviewed/2022/05/GHSA-3vvx-rwp5-c7c5/GHSA-3vvx-rwp5-c7c5.json index 422b42e76ee..af2701de7bc 100644 --- a/advisories/unreviewed/2022/05/GHSA-3vvx-rwp5-c7c5/GHSA-3vvx-rwp5-c7c5.json +++ b/advisories/unreviewed/2022/05/GHSA-3vvx-rwp5-c7c5/GHSA-3vvx-rwp5-c7c5.json @@ -7,12 +7,8 @@ "CVE-2021-38380" ], "details": "Live555 through 1.08 mishandles huge requests for the same MP3 stream, leading to recursion and s stack-based buffer over-read. An attacker can leverage this to launch a DoS attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3wjh-xpx4-2h8c/GHSA-3wjh-xpx4-2h8c.json b/advisories/unreviewed/2022/05/GHSA-3wjh-xpx4-2h8c/GHSA-3wjh-xpx4-2h8c.json index d6e6763a848..9b7712a8b59 100644 --- a/advisories/unreviewed/2022/05/GHSA-3wjh-xpx4-2h8c/GHSA-3wjh-xpx4-2h8c.json +++ b/advisories/unreviewed/2022/05/GHSA-3wjh-xpx4-2h8c/GHSA-3wjh-xpx4-2h8c.json @@ -7,12 +7,8 @@ "CVE-2005-2157" ], "details": "PHP remote file inclusion vulnerability in survey.inc.php for nabopoll 1.2 allows remote attackers to execute arbitrary PHP code via the path parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3wmj-p44f-xcmr/GHSA-3wmj-p44f-xcmr.json b/advisories/unreviewed/2022/05/GHSA-3wmj-p44f-xcmr/GHSA-3wmj-p44f-xcmr.json index e8859021711..d68f7385cea 100644 --- a/advisories/unreviewed/2022/05/GHSA-3wmj-p44f-xcmr/GHSA-3wmj-p44f-xcmr.json +++ b/advisories/unreviewed/2022/05/GHSA-3wmj-p44f-xcmr/GHSA-3wmj-p44f-xcmr.json @@ -7,12 +7,8 @@ "CVE-2005-1951" ], "details": "Multiple HTTP Response Splitting vulnerabilities in osCommerce 2.2 Milestone 2 and earlier allow remote attackers to spoof web content and poison web caches via hex-encoded CRLF (\"%0d%0a\") sequences in the (1) products_id or (2) pid parameter to index.php or (3) goto parameter to banner.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4339-x2hw-2985/GHSA-4339-x2hw-2985.json b/advisories/unreviewed/2022/05/GHSA-4339-x2hw-2985/GHSA-4339-x2hw-2985.json index 707b2d9a05b..00dd8d47bb6 100644 --- a/advisories/unreviewed/2022/05/GHSA-4339-x2hw-2985/GHSA-4339-x2hw-2985.json +++ b/advisories/unreviewed/2022/05/GHSA-4339-x2hw-2985/GHSA-4339-x2hw-2985.json @@ -7,12 +7,8 @@ "CVE-2005-2211" ], "details": "Backup Manager 0.5.8a creates temporary files insecurely, which allows local users to conduct unauthorized file operations when a user is burning a CDR.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-43wf-2x8g-fwx4/GHSA-43wf-2x8g-fwx4.json b/advisories/unreviewed/2022/05/GHSA-43wf-2x8g-fwx4/GHSA-43wf-2x8g-fwx4.json index 6cc902ad680..b1e25104e6a 100644 --- a/advisories/unreviewed/2022/05/GHSA-43wf-2x8g-fwx4/GHSA-43wf-2x8g-fwx4.json +++ b/advisories/unreviewed/2022/05/GHSA-43wf-2x8g-fwx4/GHSA-43wf-2x8g-fwx4.json @@ -7,12 +7,8 @@ "CVE-2005-2190" ], "details": "Multiple SQL injection vulnerabilities in Comersus shopping cart allow remote attackers to execute arbitrary SQL commands via the (1) email parameter to comersus_optAffiliateRegistrationExec.asp or (2) idProduct parameter to comersus_optReviewReadExec.asp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-44gm-f5rv-c627/GHSA-44gm-f5rv-c627.json b/advisories/unreviewed/2022/05/GHSA-44gm-f5rv-c627/GHSA-44gm-f5rv-c627.json index b145c1780dc..8d92c344bf8 100644 --- a/advisories/unreviewed/2022/05/GHSA-44gm-f5rv-c627/GHSA-44gm-f5rv-c627.json +++ b/advisories/unreviewed/2022/05/GHSA-44gm-f5rv-c627/GHSA-44gm-f5rv-c627.json @@ -7,12 +7,8 @@ "CVE-2021-3046" ], "details": "An improper authentication vulnerability exists in Palo Alto Networks PAN-OS software that enables a SAML authenticated attacker to impersonate any other user in the GlobalProtect Portal and GlobalProtect Gateway when they are configured to use SAML authentication. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.19; PAN-OS 9.0 versions earlier than PAN-OS 9.0.14; PAN-OS 9.1 versions earlier than PAN-OS 9.1.9; PAN-OS 10.0 versions earlier than PAN-OS 10.0.5. PAN-OS 10.1 versions are not impacted.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-454x-8f5c-p2fv/GHSA-454x-8f5c-p2fv.json b/advisories/unreviewed/2022/05/GHSA-454x-8f5c-p2fv/GHSA-454x-8f5c-p2fv.json index 7027de11945..473270635e5 100644 --- a/advisories/unreviewed/2022/05/GHSA-454x-8f5c-p2fv/GHSA-454x-8f5c-p2fv.json +++ b/advisories/unreviewed/2022/05/GHSA-454x-8f5c-p2fv/GHSA-454x-8f5c-p2fv.json @@ -7,12 +7,8 @@ "CVE-2021-26605" ], "details": "An improper input validation vulnerability in the service of ezPDFReader allows attacker to execute arbitrary command. This issue occurred when the ezPDF launcher received and executed crafted input values through JSON-RPC communication.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-46wf-9g94-ph2c/GHSA-46wf-9g94-ph2c.json b/advisories/unreviewed/2022/05/GHSA-46wf-9g94-ph2c/GHSA-46wf-9g94-ph2c.json index d62888968d0..a96c26650a2 100644 --- a/advisories/unreviewed/2022/05/GHSA-46wf-9g94-ph2c/GHSA-46wf-9g94-ph2c.json +++ b/advisories/unreviewed/2022/05/GHSA-46wf-9g94-ph2c/GHSA-46wf-9g94-ph2c.json @@ -7,12 +7,8 @@ "CVE-2021-29739" ], "details": "IBM Planning Analytics Local 2.0 could allow a remote attacker to obtain sensitive information when a stack trace is returned in the browser. X-Force ID: 198846.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-474g-rpfh-xcf7/GHSA-474g-rpfh-xcf7.json b/advisories/unreviewed/2022/05/GHSA-474g-rpfh-xcf7/GHSA-474g-rpfh-xcf7.json index 2c785da7682..2e03708802c 100644 --- a/advisories/unreviewed/2022/05/GHSA-474g-rpfh-xcf7/GHSA-474g-rpfh-xcf7.json +++ b/advisories/unreviewed/2022/05/GHSA-474g-rpfh-xcf7/GHSA-474g-rpfh-xcf7.json @@ -7,12 +7,8 @@ "CVE-2005-2100" ], "details": "The rw_vm function in usercopy.c in the 4GB split patch for the Linux kernel in Red Hat Enterprise Linux 4 does not perform proper bounds checking, which allows local users to cause a denial of service (crash).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4845-jm5w-pm5q/GHSA-4845-jm5w-pm5q.json b/advisories/unreviewed/2022/05/GHSA-4845-jm5w-pm5q/GHSA-4845-jm5w-pm5q.json index 630d04389f7..8cf8d58e027 100644 --- a/advisories/unreviewed/2022/05/GHSA-4845-jm5w-pm5q/GHSA-4845-jm5w-pm5q.json +++ b/advisories/unreviewed/2022/05/GHSA-4845-jm5w-pm5q/GHSA-4845-jm5w-pm5q.json @@ -7,12 +7,8 @@ "CVE-2005-1967" ], "details": "Multiple SQL injection vulnerabilities in ProductCart Ecommerce before 2.7 allow remote attackers to execute arbitrary SQL commands via the (1) idcategory parameter to viewPrd.asp, (2) lid parameter to editCategories.asp, (3) icd parameter to modCustomCardPaymentOpt.asp, or (4) idccr parameter to OptionFieldsEdit.asp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-48m4-p7hc-9m25/GHSA-48m4-p7hc-9m25.json b/advisories/unreviewed/2022/05/GHSA-48m4-p7hc-9m25/GHSA-48m4-p7hc-9m25.json index 7468d8e6f0e..67aadd8f065 100644 --- a/advisories/unreviewed/2022/05/GHSA-48m4-p7hc-9m25/GHSA-48m4-p7hc-9m25.json +++ b/advisories/unreviewed/2022/05/GHSA-48m4-p7hc-9m25/GHSA-48m4-p7hc-9m25.json @@ -7,12 +7,8 @@ "CVE-2005-2051" ], "details": "Buffer overflow in the VERITAS Backup Exec Web Administration Console (BEWAC) 9.0 4367 through 10.0 rev. 5484 allows remote attackers to execute arbitrary code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4936-5whp-r639/GHSA-4936-5whp-r639.json b/advisories/unreviewed/2022/05/GHSA-4936-5whp-r639/GHSA-4936-5whp-r639.json index 8b207ea38b1..17132a6613b 100644 --- a/advisories/unreviewed/2022/05/GHSA-4936-5whp-r639/GHSA-4936-5whp-r639.json +++ b/advisories/unreviewed/2022/05/GHSA-4936-5whp-r639/GHSA-4936-5whp-r639.json @@ -7,12 +7,8 @@ "CVE-2005-2200" ], "details": "Multiple unknown vulnerabilities in the MicroServer Web Server for Xerox WorkCentre Pro Color 2128, 2636, and 3545, version 0.001.04.044 through 0.001.04.504, allow attackers to bypass authentication.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-49pf-p4w2-92m4/GHSA-49pf-p4w2-92m4.json b/advisories/unreviewed/2022/05/GHSA-49pf-p4w2-92m4/GHSA-49pf-p4w2-92m4.json index 931f1fa91c6..d4449e05437 100644 --- a/advisories/unreviewed/2022/05/GHSA-49pf-p4w2-92m4/GHSA-49pf-p4w2-92m4.json +++ b/advisories/unreviewed/2022/05/GHSA-49pf-p4w2-92m4/GHSA-49pf-p4w2-92m4.json @@ -7,12 +7,8 @@ "CVE-2021-38533" ], "details": "NETGEAR RAX40 devices before 1.0.3.64 are affected by stored XSS.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4c5m-hq9w-97xw/GHSA-4c5m-hq9w-97xw.json b/advisories/unreviewed/2022/05/GHSA-4c5m-hq9w-97xw/GHSA-4c5m-hq9w-97xw.json index 10a8bda2b54..e2be2aea3be 100644 --- a/advisories/unreviewed/2022/05/GHSA-4c5m-hq9w-97xw/GHSA-4c5m-hq9w-97xw.json +++ b/advisories/unreviewed/2022/05/GHSA-4c5m-hq9w-97xw/GHSA-4c5m-hq9w-97xw.json @@ -7,12 +7,8 @@ "CVE-2005-2198" ], "details": "PHP remote file inclusion vulnerability in lang.php in SPiD before 1.3.1 allows remote attackers to execute arbitrary code via the lang_path parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4f5g-544m-849j/GHSA-4f5g-544m-849j.json b/advisories/unreviewed/2022/05/GHSA-4f5g-544m-849j/GHSA-4f5g-544m-849j.json index 01e401ee730..9dd20578f71 100644 --- a/advisories/unreviewed/2022/05/GHSA-4f5g-544m-849j/GHSA-4f5g-544m-849j.json +++ b/advisories/unreviewed/2022/05/GHSA-4f5g-544m-849j/GHSA-4f5g-544m-849j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4fj7-2258-8pjp/GHSA-4fj7-2258-8pjp.json b/advisories/unreviewed/2022/05/GHSA-4fj7-2258-8pjp/GHSA-4fj7-2258-8pjp.json index e3e0de23899..9fda00c4655 100644 --- a/advisories/unreviewed/2022/05/GHSA-4fj7-2258-8pjp/GHSA-4fj7-2258-8pjp.json +++ b/advisories/unreviewed/2022/05/GHSA-4fj7-2258-8pjp/GHSA-4fj7-2258-8pjp.json @@ -7,12 +7,8 @@ "CVE-2021-38140" ], "details": "The set_user extension module before 2.0.1 for PostgreSQL allows a potential privilege escalation using RESET SESSION AUTHORIZATION after set_user().", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4fr3-j6rq-cggr/GHSA-4fr3-j6rq-cggr.json b/advisories/unreviewed/2022/05/GHSA-4fr3-j6rq-cggr/GHSA-4fr3-j6rq-cggr.json index 26d820313cb..2a3e6d67843 100644 --- a/advisories/unreviewed/2022/05/GHSA-4fr3-j6rq-cggr/GHSA-4fr3-j6rq-cggr.json +++ b/advisories/unreviewed/2022/05/GHSA-4fr3-j6rq-cggr/GHSA-4fr3-j6rq-cggr.json @@ -7,12 +7,8 @@ "CVE-2005-2207" ], "details": "Cross-site scripting (XSS) vulnerability in store/login.asp in CartWIZ allows remote attackers to inject arbitrary web script or HTML via the message parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4frg-rpx6-96qh/GHSA-4frg-rpx6-96qh.json b/advisories/unreviewed/2022/05/GHSA-4frg-rpx6-96qh/GHSA-4frg-rpx6-96qh.json index 131af1b5230..edb91c41097 100644 --- a/advisories/unreviewed/2022/05/GHSA-4frg-rpx6-96qh/GHSA-4frg-rpx6-96qh.json +++ b/advisories/unreviewed/2022/05/GHSA-4frg-rpx6-96qh/GHSA-4frg-rpx6-96qh.json @@ -7,12 +7,8 @@ "CVE-2021-33338" ], "details": "The Layout module in Liferay Portal 7.1.0 through 7.3.2, and Liferay DXP 7.1 before fix pack 19, and 7.2 before fix pack 6, exposes the CSRF token in URLs, which allows man-in-the-middle attackers to obtain the token and conduct Cross-Site Request Forgery (CSRF) attacks via the p_auth parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4fvp-59hc-xj4m/GHSA-4fvp-59hc-xj4m.json b/advisories/unreviewed/2022/05/GHSA-4fvp-59hc-xj4m/GHSA-4fvp-59hc-xj4m.json index da60ff4a395..48428c91e3d 100644 --- a/advisories/unreviewed/2022/05/GHSA-4fvp-59hc-xj4m/GHSA-4fvp-59hc-xj4m.json +++ b/advisories/unreviewed/2022/05/GHSA-4fvp-59hc-xj4m/GHSA-4fvp-59hc-xj4m.json @@ -7,12 +7,8 @@ "CVE-2005-1964" ], "details": "PHP remote file inclusion vulnerability in utilit.php for Ovidentia Portal allows remote attackers to execute arbitrary PHP code via the babInstallPath parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4m66-r8x2-p4r9/GHSA-4m66-r8x2-p4r9.json b/advisories/unreviewed/2022/05/GHSA-4m66-r8x2-p4r9/GHSA-4m66-r8x2-p4r9.json index bdb0faa38b2..4bee7f6892b 100644 --- a/advisories/unreviewed/2022/05/GHSA-4m66-r8x2-p4r9/GHSA-4m66-r8x2-p4r9.json +++ b/advisories/unreviewed/2022/05/GHSA-4m66-r8x2-p4r9/GHSA-4m66-r8x2-p4r9.json @@ -7,12 +7,8 @@ "CVE-2005-1887" ], "details": "Unknown vulnerability in the Sun Solaris C library (libc and libproject) in Solaris 10 allows local users to gain privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4p74-rhx5-4m8c/GHSA-4p74-rhx5-4m8c.json b/advisories/unreviewed/2022/05/GHSA-4p74-rhx5-4m8c/GHSA-4p74-rhx5-4m8c.json index 38da38041ad..f16cccb2454 100644 --- a/advisories/unreviewed/2022/05/GHSA-4p74-rhx5-4m8c/GHSA-4p74-rhx5-4m8c.json +++ b/advisories/unreviewed/2022/05/GHSA-4p74-rhx5-4m8c/GHSA-4p74-rhx5-4m8c.json @@ -7,12 +7,8 @@ "CVE-2005-2128" ], "details": "QUARTZ.DLL in Microsoft Windows Media Player 9 allows remote attackers to write a null byte to arbitrary memory via an AVI file with a crafted strn element with a modified length value.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -80,9 +76,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4p87-7p4x-rwg8/GHSA-4p87-7p4x-rwg8.json b/advisories/unreviewed/2022/05/GHSA-4p87-7p4x-rwg8/GHSA-4p87-7p4x-rwg8.json index 776bf3e362f..f44058a2d7b 100644 --- a/advisories/unreviewed/2022/05/GHSA-4p87-7p4x-rwg8/GHSA-4p87-7p4x-rwg8.json +++ b/advisories/unreviewed/2022/05/GHSA-4p87-7p4x-rwg8/GHSA-4p87-7p4x-rwg8.json @@ -7,12 +7,8 @@ "CVE-2021-22674" ], "details": "The affected product is vulnerable to a relative path traversal condition, which may allow an attacker access to unauthorized files and directories on the WebAccess/SCADA (WebAccess/SCADA versions prior to 8.4.5, WebAccess/SCADA versions prior to 9.0.1).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4q7c-2w2g-hrfp/GHSA-4q7c-2w2g-hrfp.json b/advisories/unreviewed/2022/05/GHSA-4q7c-2w2g-hrfp/GHSA-4q7c-2w2g-hrfp.json index e6bb6a55959..54cd4164b5d 100644 --- a/advisories/unreviewed/2022/05/GHSA-4q7c-2w2g-hrfp/GHSA-4q7c-2w2g-hrfp.json +++ b/advisories/unreviewed/2022/05/GHSA-4q7c-2w2g-hrfp/GHSA-4q7c-2w2g-hrfp.json @@ -7,12 +7,8 @@ "CVE-2021-3050" ], "details": "An OS command injection vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator to execute arbitrary OS commands to escalate privileges. This issue impacts: PAN-OS 9.0 version 9.0.10 through PAN-OS 9.0.14; PAN-OS 9.1 version 9.1.4 through PAN-OS 9.1.10; PAN-OS 10.0 version 10.0.7 and earlier PAN-OS 10.0 versions; PAN-OS 10.1 version 10.1.0 through PAN-OS 10.1.1. Prisma Access firewalls and firewalls running PAN-OS 8.1 versions are not impacted by this issue.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4qjf-wh3w-cj2j/GHSA-4qjf-wh3w-cj2j.json b/advisories/unreviewed/2022/05/GHSA-4qjf-wh3w-cj2j/GHSA-4qjf-wh3w-cj2j.json index 54e9b945ff3..d1810d534f7 100644 --- a/advisories/unreviewed/2022/05/GHSA-4qjf-wh3w-cj2j/GHSA-4qjf-wh3w-cj2j.json +++ b/advisories/unreviewed/2022/05/GHSA-4qjf-wh3w-cj2j/GHSA-4qjf-wh3w-cj2j.json @@ -7,12 +7,8 @@ "CVE-2005-1856" ], "details": "The CD-burning feature in backup-manager 0.5.8 and earlier uses a fixed filename in a world-writable directory for logging, which allows local users to overwrite files via a symlink attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4r3v-6fhp-p4mw/GHSA-4r3v-6fhp-p4mw.json b/advisories/unreviewed/2022/05/GHSA-4r3v-6fhp-p4mw/GHSA-4r3v-6fhp-p4mw.json index 688b40e54b0..d18b8d4f4cf 100644 --- a/advisories/unreviewed/2022/05/GHSA-4r3v-6fhp-p4mw/GHSA-4r3v-6fhp-p4mw.json +++ b/advisories/unreviewed/2022/05/GHSA-4r3v-6fhp-p4mw/GHSA-4r3v-6fhp-p4mw.json @@ -7,12 +7,8 @@ "CVE-2021-24495" ], "details": "The Marmoset Viewer WordPress plugin before 1.9.3 does not property sanitize, validate or escape the 'id' parameter before outputting back in the page, leading to a reflected Cross-Site Scripting issue.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4w99-5j2p-3cwf/GHSA-4w99-5j2p-3cwf.json b/advisories/unreviewed/2022/05/GHSA-4w99-5j2p-3cwf/GHSA-4w99-5j2p-3cwf.json index b22c9fc2a9f..3ecfa28a9e2 100644 --- a/advisories/unreviewed/2022/05/GHSA-4w99-5j2p-3cwf/GHSA-4w99-5j2p-3cwf.json +++ b/advisories/unreviewed/2022/05/GHSA-4w99-5j2p-3cwf/GHSA-4w99-5j2p-3cwf.json @@ -7,12 +7,8 @@ "CVE-2005-2150" ], "details": "Windows NT 4.0 and Windows 2000 before URP1 for Windows 2000 SP4 does not properly prevent NULL sessions from accessing certain alternate named pipes, which allows remote attackers to (1) list Windows services via svcctl or (2) read eventlogs via eventlog.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4whj-x3m6-3cq3/GHSA-4whj-x3m6-3cq3.json b/advisories/unreviewed/2022/05/GHSA-4whj-x3m6-3cq3/GHSA-4whj-x3m6-3cq3.json index 65d09c176bf..f40e2c26639 100644 --- a/advisories/unreviewed/2022/05/GHSA-4whj-x3m6-3cq3/GHSA-4whj-x3m6-3cq3.json +++ b/advisories/unreviewed/2022/05/GHSA-4whj-x3m6-3cq3/GHSA-4whj-x3m6-3cq3.json @@ -7,12 +7,8 @@ "CVE-2005-2304" ], "details": "Microsoft MSN Messenger 9.0 and Internet Explorer 6.0 allows remote attackers to cause a denial of service (crash) via an image with an ICC Profile with a large Tag Count.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4whp-mjjp-cg26/GHSA-4whp-mjjp-cg26.json b/advisories/unreviewed/2022/05/GHSA-4whp-mjjp-cg26/GHSA-4whp-mjjp-cg26.json index 8bcca365fad..abf670c49ff 100644 --- a/advisories/unreviewed/2022/05/GHSA-4whp-mjjp-cg26/GHSA-4whp-mjjp-cg26.json +++ b/advisories/unreviewed/2022/05/GHSA-4whp-mjjp-cg26/GHSA-4whp-mjjp-cg26.json @@ -7,12 +7,8 @@ "CVE-2005-2078" ], "details": "BisonFTP Server V4R1 allows remote authenticated users to cause a denial of service via an invalid command with a long argument.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4x4q-c47m-2xv4/GHSA-4x4q-c47m-2xv4.json b/advisories/unreviewed/2022/05/GHSA-4x4q-c47m-2xv4/GHSA-4x4q-c47m-2xv4.json index bf4913d2413..f0fce66421f 100644 --- a/advisories/unreviewed/2022/05/GHSA-4x4q-c47m-2xv4/GHSA-4x4q-c47m-2xv4.json +++ b/advisories/unreviewed/2022/05/GHSA-4x4q-c47m-2xv4/GHSA-4x4q-c47m-2xv4.json @@ -7,12 +7,8 @@ "CVE-2005-1858" ], "details": "FUSE 2.x before 2.3.0 does not properly clear previously used memory from unfilled pages when the filesystem returns a short byte count to a read request, which may allow local users to obtain sensitive information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4x69-qp93-p8fv/GHSA-4x69-qp93-p8fv.json b/advisories/unreviewed/2022/05/GHSA-4x69-qp93-p8fv/GHSA-4x69-qp93-p8fv.json index b630fc69a1a..84640a36e93 100644 --- a/advisories/unreviewed/2022/05/GHSA-4x69-qp93-p8fv/GHSA-4x69-qp93-p8fv.json +++ b/advisories/unreviewed/2022/05/GHSA-4x69-qp93-p8fv/GHSA-4x69-qp93-p8fv.json @@ -7,12 +7,8 @@ "CVE-2005-2300" ], "details": "Skype 1.1.0.20 and earlier allows local users to overwrite arbitrary files via a symlink attack on the skype_profile.jpg temporary file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4x72-5g49-gxph/GHSA-4x72-5g49-gxph.json b/advisories/unreviewed/2022/05/GHSA-4x72-5g49-gxph/GHSA-4x72-5g49-gxph.json index 1a9880d5da3..172f8ba5693 100644 --- a/advisories/unreviewed/2022/05/GHSA-4x72-5g49-gxph/GHSA-4x72-5g49-gxph.json +++ b/advisories/unreviewed/2022/05/GHSA-4x72-5g49-gxph/GHSA-4x72-5g49-gxph.json @@ -7,12 +7,8 @@ "CVE-2005-2250" ], "details": "Buffer overflow in Bluetooth FTP client (BTFTP) in Nokia Affix 2.1.2 and 3.2.0 allows remote attackers to execute arbitrary code via a long filename in an OBEX file share.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4x9j-662f-4xw7/GHSA-4x9j-662f-4xw7.json b/advisories/unreviewed/2022/05/GHSA-4x9j-662f-4xw7/GHSA-4x9j-662f-4xw7.json index 38eb588a340..7d33594445d 100644 --- a/advisories/unreviewed/2022/05/GHSA-4x9j-662f-4xw7/GHSA-4x9j-662f-4xw7.json +++ b/advisories/unreviewed/2022/05/GHSA-4x9j-662f-4xw7/GHSA-4x9j-662f-4xw7.json @@ -7,12 +7,8 @@ "CVE-2021-38544" ], "details": "Sony SRS-XB33 and SRS-XB43 devices through 2021-08-09 allow remote attackers to recover speech signals from an LED on the device, via a telescope and an electro-optical sensor, aka a \"Glowworm\" attack. The power indicator LED of the speakers is connected directly to the power line, as a result, the intensity of a device's power indicator LED is correlative to the power consumption. The sound played by the speakers affects their power consumption and as a result is also correlative to the light intensity of the LEDs. By analyzing measurements obtained from an electro-optical sensor directed at the power indicator LEDs of the speakers, we can recover the sound played by them.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4xr8-wp6v-66q2/GHSA-4xr8-wp6v-66q2.json b/advisories/unreviewed/2022/05/GHSA-4xr8-wp6v-66q2/GHSA-4xr8-wp6v-66q2.json index 0a052fd9a33..273d3095888 100644 --- a/advisories/unreviewed/2022/05/GHSA-4xr8-wp6v-66q2/GHSA-4xr8-wp6v-66q2.json +++ b/advisories/unreviewed/2022/05/GHSA-4xr8-wp6v-66q2/GHSA-4xr8-wp6v-66q2.json @@ -7,12 +7,8 @@ "CVE-2021-22386" ], "details": "A component of the Huawei smartphone has a Double Free vulnerability. Local attackers may exploit this vulnerability to cause Root Elevation of Privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-52jm-4fm7-m5g4/GHSA-52jm-4fm7-m5g4.json b/advisories/unreviewed/2022/05/GHSA-52jm-4fm7-m5g4/GHSA-52jm-4fm7-m5g4.json index 6c749489d7d..97abfa85cb4 100644 --- a/advisories/unreviewed/2022/05/GHSA-52jm-4fm7-m5g4/GHSA-52jm-4fm7-m5g4.json +++ b/advisories/unreviewed/2022/05/GHSA-52jm-4fm7-m5g4/GHSA-52jm-4fm7-m5g4.json @@ -7,12 +7,8 @@ "CVE-2005-2141" ], "details": "TCP Chat 1.0 allows remote attackers to cause a denial of service (crash) via a long string to the chat service, possibly triggering a buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-52mv-qf8x-gmxx/GHSA-52mv-qf8x-gmxx.json b/advisories/unreviewed/2022/05/GHSA-52mv-qf8x-gmxx/GHSA-52mv-qf8x-gmxx.json index 93420a9f636..3864899da79 100644 --- a/advisories/unreviewed/2022/05/GHSA-52mv-qf8x-gmxx/GHSA-52mv-qf8x-gmxx.json +++ b/advisories/unreviewed/2022/05/GHSA-52mv-qf8x-gmxx/GHSA-52mv-qf8x-gmxx.json @@ -7,12 +7,8 @@ "CVE-2005-2282" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in WebEOC before 6.0.2 allow remote attackers to inject arbitrary web script and HTML via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-52ph-jf97-p27x/GHSA-52ph-jf97-p27x.json b/advisories/unreviewed/2022/05/GHSA-52ph-jf97-p27x/GHSA-52ph-jf97-p27x.json index 9b9bba8840d..cb60351d835 100644 --- a/advisories/unreviewed/2022/05/GHSA-52ph-jf97-p27x/GHSA-52ph-jf97-p27x.json +++ b/advisories/unreviewed/2022/05/GHSA-52ph-jf97-p27x/GHSA-52ph-jf97-p27x.json @@ -7,12 +7,8 @@ "CVE-2021-0006" ], "details": "Improper conditions check in firmware for Intel(R) Ethernet Adapters 800 Series Controllers and associated adapters before version 1.5.4.0 may allow a privileged user to potentially enable denial of service via local access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5368-22cm-w5cv/GHSA-5368-22cm-w5cv.json b/advisories/unreviewed/2022/05/GHSA-5368-22cm-w5cv/GHSA-5368-22cm-w5cv.json index 5c958dfcde6..d4e2752d358 100644 --- a/advisories/unreviewed/2022/05/GHSA-5368-22cm-w5cv/GHSA-5368-22cm-w5cv.json +++ b/advisories/unreviewed/2022/05/GHSA-5368-22cm-w5cv/GHSA-5368-22cm-w5cv.json @@ -7,12 +7,8 @@ "CVE-2020-24821" ], "details": "A vulnerability in the dwarf::cursor::skip_form function of Libelfin v0.3 allows attackers to cause a denial of service (DOS) through a segmentation fault via a crafted ELF file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-538j-p5p8-25h2/GHSA-538j-p5p8-25h2.json b/advisories/unreviewed/2022/05/GHSA-538j-p5p8-25h2/GHSA-538j-p5p8-25h2.json index 84727351bc1..f4c2d0e1096 100644 --- a/advisories/unreviewed/2022/05/GHSA-538j-p5p8-25h2/GHSA-538j-p5p8-25h2.json +++ b/advisories/unreviewed/2022/05/GHSA-538j-p5p8-25h2/GHSA-538j-p5p8-25h2.json @@ -7,12 +7,8 @@ "CVE-2005-2012" ], "details": "Multiple SQL injection vulnerabilities in login in paFAQ 1.0 Beta 4 allow remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username or (2) id parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-55fv-m3cp-6c7g/GHSA-55fv-m3cp-6c7g.json b/advisories/unreviewed/2022/05/GHSA-55fv-m3cp-6c7g/GHSA-55fv-m3cp-6c7g.json index 83f6990c3ad..cd29bd8ddbb 100644 --- a/advisories/unreviewed/2022/05/GHSA-55fv-m3cp-6c7g/GHSA-55fv-m3cp-6c7g.json +++ b/advisories/unreviewed/2022/05/GHSA-55fv-m3cp-6c7g/GHSA-55fv-m3cp-6c7g.json @@ -7,12 +7,8 @@ "CVE-2005-2222" ], "details": "Unknown vulnerability in the HTTPMail service in MailEnable Professional before 1.6 has unknown impact and attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-55xh-mvgj-c3j6/GHSA-55xh-mvgj-c3j6.json b/advisories/unreviewed/2022/05/GHSA-55xh-mvgj-c3j6/GHSA-55xh-mvgj-c3j6.json index fa2eefd8f96..d26acbf7e08 100644 --- a/advisories/unreviewed/2022/05/GHSA-55xh-mvgj-c3j6/GHSA-55xh-mvgj-c3j6.json +++ b/advisories/unreviewed/2022/05/GHSA-55xh-mvgj-c3j6/GHSA-55xh-mvgj-c3j6.json @@ -7,12 +7,8 @@ "CVE-2005-2258" ], "details": "PHP remote file inclusion vulnerability in photolist.inc.php in Squito Gallery 1.33 allows remote attackers to execute arbitrary code via the photoroot parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5638-47w9-74r6/GHSA-5638-47w9-74r6.json b/advisories/unreviewed/2022/05/GHSA-5638-47w9-74r6/GHSA-5638-47w9-74r6.json index d4a5764c830..ff8a1e80cfb 100644 --- a/advisories/unreviewed/2022/05/GHSA-5638-47w9-74r6/GHSA-5638-47w9-74r6.json +++ b/advisories/unreviewed/2022/05/GHSA-5638-47w9-74r6/GHSA-5638-47w9-74r6.json @@ -7,12 +7,8 @@ "CVE-2005-2186" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in McAfee IntruShield Security Management System allow remote authenticated users to inject arbitrary web script or HTML via the (1) thirdMenuName or (2) resourceName parameter to SystemEvent.jsp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-566m-3pvx-3xvx/GHSA-566m-3pvx-3xvx.json b/advisories/unreviewed/2022/05/GHSA-566m-3pvx-3xvx/GHSA-566m-3pvx-3xvx.json index 2a4b0506ac0..6bde09925dc 100644 --- a/advisories/unreviewed/2022/05/GHSA-566m-3pvx-3xvx/GHSA-566m-3pvx-3xvx.json +++ b/advisories/unreviewed/2022/05/GHSA-566m-3pvx-3xvx/GHSA-566m-3pvx-3xvx.json @@ -7,12 +7,8 @@ "CVE-2021-32438" ], "details": "The gf_media_export_filters function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-56c4-gr7v-2c69/GHSA-56c4-gr7v-2c69.json b/advisories/unreviewed/2022/05/GHSA-56c4-gr7v-2c69/GHSA-56c4-gr7v-2c69.json index b3a90682b26..baa0200f250 100644 --- a/advisories/unreviewed/2022/05/GHSA-56c4-gr7v-2c69/GHSA-56c4-gr7v-2c69.json +++ b/advisories/unreviewed/2022/05/GHSA-56c4-gr7v-2c69/GHSA-56c4-gr7v-2c69.json @@ -7,12 +7,8 @@ "CVE-2005-1882" ], "details": "PHP remote file inclusion vulnerability in last_gallery.php in YaPiG 0.93u and 0.94u allows remote attackers to execute arbitrary PHP code via the YAPIG_PATH parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-56j5-fr4h-4c8q/GHSA-56j5-fr4h-4c8q.json b/advisories/unreviewed/2022/05/GHSA-56j5-fr4h-4c8q/GHSA-56j5-fr4h-4c8q.json index aeb71093071..c4ee10f5d20 100644 --- a/advisories/unreviewed/2022/05/GHSA-56j5-fr4h-4c8q/GHSA-56j5-fr4h-4c8q.json +++ b/advisories/unreviewed/2022/05/GHSA-56j5-fr4h-4c8q/GHSA-56j5-fr4h-4c8q.json @@ -7,12 +7,8 @@ "CVE-2021-26606" ], "details": "A vulnerability in PKI Security Solution of Dream Security could allow arbitrary command execution. This vulnerability is due to insufficient validation of the authorization certificate. An attacker could exploit this vulnerability by sending a crafted HTTP request an affected program. A successful exploit could allow the attacker to remotely execute arbitrary code on a target system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5759-5xq5-qw22/GHSA-5759-5xq5-qw22.json b/advisories/unreviewed/2022/05/GHSA-5759-5xq5-qw22/GHSA-5759-5xq5-qw22.json index 5fc6cd5a428..16bc1bbbb8c 100644 --- a/advisories/unreviewed/2022/05/GHSA-5759-5xq5-qw22/GHSA-5759-5xq5-qw22.json +++ b/advisories/unreviewed/2022/05/GHSA-5759-5xq5-qw22/GHSA-5759-5xq5-qw22.json @@ -7,12 +7,8 @@ "CVE-2005-2168" ], "details": "delete.php in Plague News System 0.6 and earlier allows remote unauthenticated attackers to delete news, comments, and shoutbox posts by modifying the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-578w-c3rg-xx4q/GHSA-578w-c3rg-xx4q.json b/advisories/unreviewed/2022/05/GHSA-578w-c3rg-xx4q/GHSA-578w-c3rg-xx4q.json index 2a9d823a4af..5f76375065a 100644 --- a/advisories/unreviewed/2022/05/GHSA-578w-c3rg-xx4q/GHSA-578w-c3rg-xx4q.json +++ b/advisories/unreviewed/2022/05/GHSA-578w-c3rg-xx4q/GHSA-578w-c3rg-xx4q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-57g7-mrgr-h796/GHSA-57g7-mrgr-h796.json b/advisories/unreviewed/2022/05/GHSA-57g7-mrgr-h796/GHSA-57g7-mrgr-h796.json index 1de515615aa..d8b4350b577 100644 --- a/advisories/unreviewed/2022/05/GHSA-57g7-mrgr-h796/GHSA-57g7-mrgr-h796.json +++ b/advisories/unreviewed/2022/05/GHSA-57g7-mrgr-h796/GHSA-57g7-mrgr-h796.json @@ -7,12 +7,8 @@ "CVE-2005-2107" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in post.php in WordPress 1.5.1.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) p or (2) comment parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5874-jrx9-mcpx/GHSA-5874-jrx9-mcpx.json b/advisories/unreviewed/2022/05/GHSA-5874-jrx9-mcpx/GHSA-5874-jrx9-mcpx.json index 9237ec342b4..78c330d3e1d 100644 --- a/advisories/unreviewed/2022/05/GHSA-5874-jrx9-mcpx/GHSA-5874-jrx9-mcpx.json +++ b/advisories/unreviewed/2022/05/GHSA-5874-jrx9-mcpx/GHSA-5874-jrx9-mcpx.json @@ -7,12 +7,8 @@ "CVE-2005-2223" ], "details": "Unknown vulnerability in the SMTP service in MailEnable Standard before 1.9 and Professional before 1.6 allows remote attackers to cause a denial of service (crash) during authentication.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-588w-3hxj-v2wx/GHSA-588w-3hxj-v2wx.json b/advisories/unreviewed/2022/05/GHSA-588w-3hxj-v2wx/GHSA-588w-3hxj-v2wx.json index 4db1504f76a..af6bba90b7c 100644 --- a/advisories/unreviewed/2022/05/GHSA-588w-3hxj-v2wx/GHSA-588w-3hxj-v2wx.json +++ b/advisories/unreviewed/2022/05/GHSA-588w-3hxj-v2wx/GHSA-588w-3hxj-v2wx.json @@ -7,12 +7,8 @@ "CVE-2021-37365" ], "details": "CTparental before 4.45.03 is vulnerable to cross-site scripting (XSS) in the CTparental admin panel. In bl_categires_help.php, the 'categories' variable is assigned with the content of the query string param 'cat' without sanitization or encoding, enabling an attacker to inject malicious code into the output webpage.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-59cp-cwvf-86j6/GHSA-59cp-cwvf-86j6.json b/advisories/unreviewed/2022/05/GHSA-59cp-cwvf-86j6/GHSA-59cp-cwvf-86j6.json index 670156c71b7..fe47ae75846 100644 --- a/advisories/unreviewed/2022/05/GHSA-59cp-cwvf-86j6/GHSA-59cp-cwvf-86j6.json +++ b/advisories/unreviewed/2022/05/GHSA-59cp-cwvf-86j6/GHSA-59cp-cwvf-86j6.json @@ -7,12 +7,8 @@ "CVE-2021-38528" ], "details": "Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D8500 before 1.0.3.58, R6900P before 1.3.2.132, R7000P before 1.3.2.132, R7100LG before 1.0.0.64, WNDR3400v3 before 1.0.1.38, and XR300 before 1.0.3.56.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5ccq-2ww6-7c9w/GHSA-5ccq-2ww6-7c9w.json b/advisories/unreviewed/2022/05/GHSA-5ccq-2ww6-7c9w/GHSA-5ccq-2ww6-7c9w.json index 499b4b7b718..602dfd78360 100644 --- a/advisories/unreviewed/2022/05/GHSA-5ccq-2ww6-7c9w/GHSA-5ccq-2ww6-7c9w.json +++ b/advisories/unreviewed/2022/05/GHSA-5ccq-2ww6-7c9w/GHSA-5ccq-2ww6-7c9w.json @@ -7,12 +7,8 @@ "CVE-2021-28843" ], "details": "Null Pointer Dereference vulnerability exists in TRENDnet TEW-755AP 1.11B03, TEW-755AP2KAC 1.11B03, TEW-821DAP2KAC 1.11B03, and TEW-825DAP 1.11B03 by sending the POST request to apply_cgi with an unknown action name.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5f2v-qqcm-fwfx/GHSA-5f2v-qqcm-fwfx.json b/advisories/unreviewed/2022/05/GHSA-5f2v-qqcm-fwfx/GHSA-5f2v-qqcm-fwfx.json index 4a21fcd411e..f0ea5327b63 100644 --- a/advisories/unreviewed/2022/05/GHSA-5f2v-qqcm-fwfx/GHSA-5f2v-qqcm-fwfx.json +++ b/advisories/unreviewed/2022/05/GHSA-5f2v-qqcm-fwfx/GHSA-5f2v-qqcm-fwfx.json @@ -7,12 +7,8 @@ "CVE-2020-21690" ], "details": "A memory leak in the grow_array function in cmdutils.c og Ffmpeg 4.2 allows attackers to cause a denial of service (DOS) via a crafted ogg file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5f5c-9qpc-p4vg/GHSA-5f5c-9qpc-p4vg.json b/advisories/unreviewed/2022/05/GHSA-5f5c-9qpc-p4vg/GHSA-5f5c-9qpc-p4vg.json index 4544dea39d1..50c35fa7a69 100644 --- a/advisories/unreviewed/2022/05/GHSA-5f5c-9qpc-p4vg/GHSA-5f5c-9qpc-p4vg.json +++ b/advisories/unreviewed/2022/05/GHSA-5f5c-9qpc-p4vg/GHSA-5f5c-9qpc-p4vg.json @@ -7,12 +7,8 @@ "CVE-2005-1884" ], "details": "Directory traversal vulnerability in the (1) rmdir or (2) mkdir commands in upload.php in YaPiG 0.92b, 0.93u and 0.94u allows remote attackers to create or delete arbitrary directories via a .. (dot dot) in the dir parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5gg7-f3mp-cf84/GHSA-5gg7-f3mp-cf84.json b/advisories/unreviewed/2022/05/GHSA-5gg7-f3mp-cf84/GHSA-5gg7-f3mp-cf84.json index 6c36e1a16c8..e9f8544eedc 100644 --- a/advisories/unreviewed/2022/05/GHSA-5gg7-f3mp-cf84/GHSA-5gg7-f3mp-cf84.json +++ b/advisories/unreviewed/2022/05/GHSA-5gg7-f3mp-cf84/GHSA-5gg7-f3mp-cf84.json @@ -7,12 +7,8 @@ "CVE-2021-29973" ], "details": "Password autofill was enabled without user interaction on insecure websites on Firefox for Android. This was corrected to require user interaction with the page before a user's password would be entered by the browser's autofill functionality *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 90.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5h7j-rcch-xpjh/GHSA-5h7j-rcch-xpjh.json b/advisories/unreviewed/2022/05/GHSA-5h7j-rcch-xpjh/GHSA-5h7j-rcch-xpjh.json index 92691e172cd..c8f57d902fa 100644 --- a/advisories/unreviewed/2022/05/GHSA-5h7j-rcch-xpjh/GHSA-5h7j-rcch-xpjh.json +++ b/advisories/unreviewed/2022/05/GHSA-5h7j-rcch-xpjh/GHSA-5h7j-rcch-xpjh.json @@ -7,12 +7,8 @@ "CVE-2005-2235" ], "details": "Buffer overflow in the diagTasksWebSM command in IBM AIX 5.1, 5.2 and 5.3, might allow local users to execute arbitrary code via long command line arguments.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5hpc-wgg9-2q88/GHSA-5hpc-wgg9-2q88.json b/advisories/unreviewed/2022/05/GHSA-5hpc-wgg9-2q88/GHSA-5hpc-wgg9-2q88.json index 7721be26efb..57b2282639b 100644 --- a/advisories/unreviewed/2022/05/GHSA-5hpc-wgg9-2q88/GHSA-5hpc-wgg9-2q88.json +++ b/advisories/unreviewed/2022/05/GHSA-5hpc-wgg9-2q88/GHSA-5hpc-wgg9-2q88.json @@ -7,12 +7,8 @@ "CVE-2005-2152" ], "details": "SQL injection vulnerability in Geeklog before 1.3.11 allows remote attackers to execute arbitrary SQL commands via user comments for an article.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5pgg-4c5c-9j5p/GHSA-5pgg-4c5c-9j5p.json b/advisories/unreviewed/2022/05/GHSA-5pgg-4c5c-9j5p/GHSA-5pgg-4c5c-9j5p.json index b4e99effb79..1ea35798aa5 100644 --- a/advisories/unreviewed/2022/05/GHSA-5pgg-4c5c-9j5p/GHSA-5pgg-4c5c-9j5p.json +++ b/advisories/unreviewed/2022/05/GHSA-5pgg-4c5c-9j5p/GHSA-5pgg-4c5c-9j5p.json @@ -7,12 +7,8 @@ "CVE-2005-2265" ], "details": "Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 and 7.2 allows remote attackers to cause a denial of service (access violation and crash), and possibly execute arbitrary code, by calling InstallVersion.compareTo with an object instead of a string.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -108,9 +104,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5ph3-gq38-phg6/GHSA-5ph3-gq38-phg6.json b/advisories/unreviewed/2022/05/GHSA-5ph3-gq38-phg6/GHSA-5ph3-gq38-phg6.json index 8ce22e469cf..c1c9b771031 100644 --- a/advisories/unreviewed/2022/05/GHSA-5ph3-gq38-phg6/GHSA-5ph3-gq38-phg6.json +++ b/advisories/unreviewed/2022/05/GHSA-5ph3-gq38-phg6/GHSA-5ph3-gq38-phg6.json @@ -7,12 +7,8 @@ "CVE-2021-24507" ], "details": "The Astra Pro Addon WordPress plugin before 3.5.2 did not properly sanitise or escape some of the POST parameters from the astra_pagination_infinite and astra_shop_pagination_infinite AJAX action (available to both unauthenticated and authenticated user) before using them in SQL statement, leading to an SQL Injection issues", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5phw-pq6g-29m4/GHSA-5phw-pq6g-29m4.json b/advisories/unreviewed/2022/05/GHSA-5phw-pq6g-29m4/GHSA-5phw-pq6g-29m4.json index e57c102cd78..23a029852bc 100644 --- a/advisories/unreviewed/2022/05/GHSA-5phw-pq6g-29m4/GHSA-5phw-pq6g-29m4.json +++ b/advisories/unreviewed/2022/05/GHSA-5phw-pq6g-29m4/GHSA-5phw-pq6g-29m4.json @@ -7,12 +7,8 @@ "CVE-2005-2023" ], "details": "The send_pinentry_environment function in asshelp.c in gpg2 on SUSE Linux 9.3 does not properly handle certain options, which can prevent pinentry from being found and causes S/MIME signing to fail.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5qxh-3wqv-72qp/GHSA-5qxh-3wqv-72qp.json b/advisories/unreviewed/2022/05/GHSA-5qxh-3wqv-72qp/GHSA-5qxh-3wqv-72qp.json index 37914fee6bf..c9f4dc3814a 100644 --- a/advisories/unreviewed/2022/05/GHSA-5qxh-3wqv-72qp/GHSA-5qxh-3wqv-72qp.json +++ b/advisories/unreviewed/2022/05/GHSA-5qxh-3wqv-72qp/GHSA-5qxh-3wqv-72qp.json @@ -7,12 +7,8 @@ "CVE-2005-2230" ], "details": "Electronic Mail Operator (elmo) 1.3.2-r1 and earlier creates the elmostats temporary file insecurely, which allows local users to overwrite arbitrary files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5v2f-8gvc-fq7x/GHSA-5v2f-8gvc-fq7x.json b/advisories/unreviewed/2022/05/GHSA-5v2f-8gvc-fq7x/GHSA-5v2f-8gvc-fq7x.json index 15cd867d41e..98184897033 100644 --- a/advisories/unreviewed/2022/05/GHSA-5v2f-8gvc-fq7x/GHSA-5v2f-8gvc-fq7x.json +++ b/advisories/unreviewed/2022/05/GHSA-5v2f-8gvc-fq7x/GHSA-5v2f-8gvc-fq7x.json @@ -7,12 +7,8 @@ "CVE-2005-2123" ], "details": "Multiple integer overflows in the Graphics Rendering Engine (GDI32.DLL) in Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allow remote attackers to execute arbitrary code via crafted Windows Metafile (WMF) and Enhanced Metafile (EMF) format images that lead to heap-based buffer overflows, as demonstrated using MRBP16::bCheckRecord.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -84,9 +80,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5v32-c9r7-7rcp/GHSA-5v32-c9r7-7rcp.json b/advisories/unreviewed/2022/05/GHSA-5v32-c9r7-7rcp/GHSA-5v32-c9r7-7rcp.json index f9017ceee7b..c5380ff2ae8 100644 --- a/advisories/unreviewed/2022/05/GHSA-5v32-c9r7-7rcp/GHSA-5v32-c9r7-7rcp.json +++ b/advisories/unreviewed/2022/05/GHSA-5v32-c9r7-7rcp/GHSA-5v32-c9r7-7rcp.json @@ -7,12 +7,8 @@ "CVE-2005-2274" ], "details": "Microsoft Internet Explorer 6.0 does not clearly associate a Javascript dialog box with the web page that generated it, which allows remote attackers to spoof a dialog box from a trusted site and facilitates phishing attacks, aka the \"Dialog Origin Spoofing Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5v66-4mqr-49xj/GHSA-5v66-4mqr-49xj.json b/advisories/unreviewed/2022/05/GHSA-5v66-4mqr-49xj/GHSA-5v66-4mqr-49xj.json index 92ba34b14e1..7ece8d2d213 100644 --- a/advisories/unreviewed/2022/05/GHSA-5v66-4mqr-49xj/GHSA-5v66-4mqr-49xj.json +++ b/advisories/unreviewed/2022/05/GHSA-5v66-4mqr-49xj/GHSA-5v66-4mqr-49xj.json @@ -7,12 +7,8 @@ "CVE-2005-2263" ], "details": "The InstallTrigger.install method in Firefox before 1.0.5 and Mozilla before 1.7.9 allows remote attackers to execute a callback function in the context of another domain by forcing a page navigation after the install method has been called, which causes the callback to be run in the context of the new page and results in a same origin violation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -92,9 +88,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5vcw-xjjc-658q/GHSA-5vcw-xjjc-658q.json b/advisories/unreviewed/2022/05/GHSA-5vcw-xjjc-658q/GHSA-5vcw-xjjc-658q.json index 49f5243d5f3..293c347fe78 100644 --- a/advisories/unreviewed/2022/05/GHSA-5vcw-xjjc-658q/GHSA-5vcw-xjjc-658q.json +++ b/advisories/unreviewed/2022/05/GHSA-5vcw-xjjc-658q/GHSA-5vcw-xjjc-658q.json @@ -7,12 +7,8 @@ "CVE-2005-2085" ], "details": "Buffer overflow in Inframail Advantage Server Edition 6.0 through 6.7 allows remote attackers to cause a denial of service (process crash) via a long (1) SMTP FROM field or possibly (2) FTP NLST command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5vhx-7rf7-r3w3/GHSA-5vhx-7rf7-r3w3.json b/advisories/unreviewed/2022/05/GHSA-5vhx-7rf7-r3w3/GHSA-5vhx-7rf7-r3w3.json index 2c571c4503d..7d9da59cfad 100644 --- a/advisories/unreviewed/2022/05/GHSA-5vhx-7rf7-r3w3/GHSA-5vhx-7rf7-r3w3.json +++ b/advisories/unreviewed/2022/05/GHSA-5vhx-7rf7-r3w3/GHSA-5vhx-7rf7-r3w3.json @@ -7,12 +7,8 @@ "CVE-2005-2227" ], "details": "Softiacom wMailserver 1.0 stores passwords in plaintext in the Darsite\\MAILSRV\\Admin key, which allows local users to gain administrator privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5x7c-pp2h-6vmg/GHSA-5x7c-pp2h-6vmg.json b/advisories/unreviewed/2022/05/GHSA-5x7c-pp2h-6vmg/GHSA-5x7c-pp2h-6vmg.json index 8c03b465df2..e78e2bc65d9 100644 --- a/advisories/unreviewed/2022/05/GHSA-5x7c-pp2h-6vmg/GHSA-5x7c-pp2h-6vmg.json +++ b/advisories/unreviewed/2022/05/GHSA-5x7c-pp2h-6vmg/GHSA-5x7c-pp2h-6vmg.json @@ -7,12 +7,8 @@ "CVE-2005-2034" ], "details": "Cross-site scripting (XSS) vulnerability in folderview.asp for BlueCollar iGallery 3.3 allows remote attackers to inject arbitrary web script or HTML via the folder parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5xp5-grfw-76h9/GHSA-5xp5-grfw-76h9.json b/advisories/unreviewed/2022/05/GHSA-5xp5-grfw-76h9/GHSA-5xp5-grfw-76h9.json index 03aeaece124..25b642f547d 100644 --- a/advisories/unreviewed/2022/05/GHSA-5xp5-grfw-76h9/GHSA-5xp5-grfw-76h9.json +++ b/advisories/unreviewed/2022/05/GHSA-5xp5-grfw-76h9/GHSA-5xp5-grfw-76h9.json @@ -7,12 +7,8 @@ "CVE-2005-2027" ], "details": "Enterasys Vertical Horizon VH-2402S before firmware 2.05.05.09 does not properly restrict certain debugging commands to the ADMIN account, which could allow attackers to obtain sensitive information or modify the registry.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5xqf-3mwv-q7gm/GHSA-5xqf-3mwv-q7gm.json b/advisories/unreviewed/2022/05/GHSA-5xqf-3mwv-q7gm/GHSA-5xqf-3mwv-q7gm.json index 98aee8b93e1..fb8482b5b1d 100644 --- a/advisories/unreviewed/2022/05/GHSA-5xqf-3mwv-q7gm/GHSA-5xqf-3mwv-q7gm.json +++ b/advisories/unreviewed/2022/05/GHSA-5xqf-3mwv-q7gm/GHSA-5xqf-3mwv-q7gm.json @@ -7,12 +7,8 @@ "CVE-2005-2247" ], "details": "Multiple unknown vulnerabilities in Moodle before 1.5.1 have unknown impact and attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-63fx-pgp7-mcff/GHSA-63fx-pgp7-mcff.json b/advisories/unreviewed/2022/05/GHSA-63fx-pgp7-mcff/GHSA-63fx-pgp7-mcff.json index 18bf2bc4aa7..f4d8fa5f042 100644 --- a/advisories/unreviewed/2022/05/GHSA-63fx-pgp7-mcff/GHSA-63fx-pgp7-mcff.json +++ b/advisories/unreviewed/2022/05/GHSA-63fx-pgp7-mcff/GHSA-63fx-pgp7-mcff.json @@ -7,12 +7,8 @@ "CVE-2005-2284" ], "details": "Multiple SQL injection vulnerabilities in WebEOC before 6.0.2 allow remote attackers to modify SQL statements via unknown attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-63vq-qp86-c7m4/GHSA-63vq-qp86-c7m4.json b/advisories/unreviewed/2022/05/GHSA-63vq-qp86-c7m4/GHSA-63vq-qp86-c7m4.json index 96184e2ce8d..da737f7ee98 100644 --- a/advisories/unreviewed/2022/05/GHSA-63vq-qp86-c7m4/GHSA-63vq-qp86-c7m4.json +++ b/advisories/unreviewed/2022/05/GHSA-63vq-qp86-c7m4/GHSA-63vq-qp86-c7m4.json @@ -7,12 +7,8 @@ "CVE-2005-2153" ], "details": "SQL injection vulnerability in class.ticket.php in osTicket 1.3.1 beta and earlier allows remote attackers to execute arbitrary SQL commands via the ticket variable.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-64rg-cj2r-7j3g/GHSA-64rg-cj2r-7j3g.json b/advisories/unreviewed/2022/05/GHSA-64rg-cj2r-7j3g/GHSA-64rg-cj2r-7j3g.json index 5c5f031b015..4150e2a3ae8 100644 --- a/advisories/unreviewed/2022/05/GHSA-64rg-cj2r-7j3g/GHSA-64rg-cj2r-7j3g.json +++ b/advisories/unreviewed/2022/05/GHSA-64rg-cj2r-7j3g/GHSA-64rg-cj2r-7j3g.json @@ -7,12 +7,8 @@ "CVE-2021-33738" ], "details": "A vulnerability has been identified in JT2Go (All versions < V13.2.0.2), Teamcenter Visualization (All versions < V13.2.0.2). The plmxmlAdapterSE70.dll library in affected applications lacks proper validation of user-supplied data when parsing PAR files. This could result in an out of bounds read past the end of an allocated buffer. An attacker could leverage this vulnerability to leak information in the context of the current process. (ZDI-CAN-13405)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-674w-r289-4237/GHSA-674w-r289-4237.json b/advisories/unreviewed/2022/05/GHSA-674w-r289-4237/GHSA-674w-r289-4237.json index 2dc2cf2528a..7cd33d8a9e9 100644 --- a/advisories/unreviewed/2022/05/GHSA-674w-r289-4237/GHSA-674w-r289-4237.json +++ b/advisories/unreviewed/2022/05/GHSA-674w-r289-4237/GHSA-674w-r289-4237.json @@ -7,12 +7,8 @@ "CVE-2021-32947" ], "details": "FATEK Automation FvDesigner, Versions 1.5.88 and prior is vulnerable to a stack-based buffer overflow, which may allow an attacker to execute arbitrary code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-67j3-xh78-hg76/GHSA-67j3-xh78-hg76.json b/advisories/unreviewed/2022/05/GHSA-67j3-xh78-hg76/GHSA-67j3-xh78-hg76.json index 775f3c48b83..e066c345bbf 100644 --- a/advisories/unreviewed/2022/05/GHSA-67j3-xh78-hg76/GHSA-67j3-xh78-hg76.json +++ b/advisories/unreviewed/2022/05/GHSA-67j3-xh78-hg76/GHSA-67j3-xh78-hg76.json @@ -7,12 +7,8 @@ "CVE-2005-2079" ], "details": "Heap-based buffer overflow in the Admin Plus Pack Option for VERITAS Backup Exec 9.0 through 10.0 for Windows Servers allows remote attackers to execute arbitrary code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-69hh-3rwj-cw4w/GHSA-69hh-3rwj-cw4w.json b/advisories/unreviewed/2022/05/GHSA-69hh-3rwj-cw4w/GHSA-69hh-3rwj-cw4w.json index 9619eb83565..88f2a3768cd 100644 --- a/advisories/unreviewed/2022/05/GHSA-69hh-3rwj-cw4w/GHSA-69hh-3rwj-cw4w.json +++ b/advisories/unreviewed/2022/05/GHSA-69hh-3rwj-cw4w/GHSA-69hh-3rwj-cw4w.json @@ -7,12 +7,8 @@ "CVE-2005-2030" ], "details": "Ultimate PHP Board (UPB) 1.9.6 GOLD uses weak encryption for passwords in the users.dat file, which allows attackers to easily decrypt the passwords and gain privileges, possibly after exploiting CVE-2005-2005 to obtain users.dat.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-69wp-9456-2p9w/GHSA-69wp-9456-2p9w.json b/advisories/unreviewed/2022/05/GHSA-69wp-9456-2p9w/GHSA-69wp-9456-2p9w.json index 2bb200d2a98..b3c00c635a8 100644 --- a/advisories/unreviewed/2022/05/GHSA-69wp-9456-2p9w/GHSA-69wp-9456-2p9w.json +++ b/advisories/unreviewed/2022/05/GHSA-69wp-9456-2p9w/GHSA-69wp-9456-2p9w.json @@ -7,12 +7,8 @@ "CVE-2021-35397" ], "details": "A path traversal vulnerability in the static router for Drogon from 1.0.0-beta14 to 1.6.0 could allow an unauthenticated, remote attacker to arbitrarily read files. The vulnerability is due to lack of proper input validation for requested path. An attacker could exploit this vulnerability by sending crafted HTTP request with specific path to read. Successful exploitation could allow the attacker to read files that should be restricted.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6ch7-6xxg-vw5p/GHSA-6ch7-6xxg-vw5p.json b/advisories/unreviewed/2022/05/GHSA-6ch7-6xxg-vw5p/GHSA-6ch7-6xxg-vw5p.json index a2fcf723273..97b22a7be3a 100644 --- a/advisories/unreviewed/2022/05/GHSA-6ch7-6xxg-vw5p/GHSA-6ch7-6xxg-vw5p.json +++ b/advisories/unreviewed/2022/05/GHSA-6ch7-6xxg-vw5p/GHSA-6ch7-6xxg-vw5p.json @@ -7,12 +7,8 @@ "CVE-2005-2006" ], "details": "JBOSS 3.2.2 through 3.2.7 and 4.0.2 allows remote attackers to obtain sensitive information via a GET request (1) with a \"%.\" (percent dot), which reveals the installation path or (2) with a % (percent) before a filename, which reveals the contents of the file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6fhf-7rm6-v2w4/GHSA-6fhf-7rm6-v2w4.json b/advisories/unreviewed/2022/05/GHSA-6fhf-7rm6-v2w4/GHSA-6fhf-7rm6-v2w4.json index d51cb87ec2f..8dad853ec99 100644 --- a/advisories/unreviewed/2022/05/GHSA-6fhf-7rm6-v2w4/GHSA-6fhf-7rm6-v2w4.json +++ b/advisories/unreviewed/2022/05/GHSA-6fhf-7rm6-v2w4/GHSA-6fhf-7rm6-v2w4.json @@ -7,12 +7,8 @@ "CVE-2021-37614" ], "details": "In certain Progress MOVEit Transfer versions before 2021.0.3 (aka 13.0.3), SQL injection in the MOVEit Transfer web application could allow an authenticated remote attacker to gain access to the database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database, or execute SQL statements that alter or delete database elements, via crafted strings sent to unique MOVEit Transfer transaction types. The fixed versions are 2019.0.7 (11.0.7), 2019.1.6 (11.1.6), 2019.2.3 (11.2.3), 2020.0.6 (12.0.6), 2020.1.5 (12.1.5), and 2021.0.3 (13.0.3).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6fw4-x9r3-mvgh/GHSA-6fw4-x9r3-mvgh.json b/advisories/unreviewed/2022/05/GHSA-6fw4-x9r3-mvgh/GHSA-6fw4-x9r3-mvgh.json index 65f6f114c31..fe259745e17 100644 --- a/advisories/unreviewed/2022/05/GHSA-6fw4-x9r3-mvgh/GHSA-6fw4-x9r3-mvgh.json +++ b/advisories/unreviewed/2022/05/GHSA-6fw4-x9r3-mvgh/GHSA-6fw4-x9r3-mvgh.json @@ -7,12 +7,8 @@ "CVE-2021-32581" ], "details": "Acronis True Image prior to 2021 Update 4 for Windows, Acronis True Image prior to 2021 Update 5 for Mac, Acronis Agent prior to build 26653, Acronis Cyber Protect prior to build 27009 did not implement SSL certificate validation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6g7p-3fmx-8jh6/GHSA-6g7p-3fmx-8jh6.json b/advisories/unreviewed/2022/05/GHSA-6g7p-3fmx-8jh6/GHSA-6g7p-3fmx-8jh6.json index b73b36273d3..3eee00c36df 100644 --- a/advisories/unreviewed/2022/05/GHSA-6g7p-3fmx-8jh6/GHSA-6g7p-3fmx-8jh6.json +++ b/advisories/unreviewed/2022/05/GHSA-6g7p-3fmx-8jh6/GHSA-6g7p-3fmx-8jh6.json @@ -7,12 +7,8 @@ "CVE-2005-2169" ], "details": "Directory traversal vulnerability in source.php in Quick & Dirty PHPSource Printer 1.1 and earlier allows remote attackers to read arbitrary files via \".../...//\" sequences in the file parameter, which are reduced to \"../\" when PHPSource Printer uses a regular expression to remove \"../\" sequences.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6g87-jg5m-ppfq/GHSA-6g87-jg5m-ppfq.json b/advisories/unreviewed/2022/05/GHSA-6g87-jg5m-ppfq/GHSA-6g87-jg5m-ppfq.json index 64bb43998b6..2bcc8d1fad9 100644 --- a/advisories/unreviewed/2022/05/GHSA-6g87-jg5m-ppfq/GHSA-6g87-jg5m-ppfq.json +++ b/advisories/unreviewed/2022/05/GHSA-6g87-jg5m-ppfq/GHSA-6g87-jg5m-ppfq.json @@ -7,12 +7,8 @@ "CVE-2021-26098" ], "details": "An instance of small space of random values in the RPC API of FortiSandbox before 4.0.0 may allow an attacker in possession of a few information pieces about the state of the device to possibly predict valid session IDs.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6m28-x6m6-65jr/GHSA-6m28-x6m6-65jr.json b/advisories/unreviewed/2022/05/GHSA-6m28-x6m6-65jr/GHSA-6m28-x6m6-65jr.json index 63115020d89..af0ec5ea7dd 100644 --- a/advisories/unreviewed/2022/05/GHSA-6m28-x6m6-65jr/GHSA-6m28-x6m6-65jr.json +++ b/advisories/unreviewed/2022/05/GHSA-6m28-x6m6-65jr/GHSA-6m28-x6m6-65jr.json @@ -7,12 +7,8 @@ "CVE-2005-1963" ], "details": "Cerberus Helpdesk 0.97.3 allows remote attackers to obtain sensitive information via certain requests to (1) reports.php, (2) knowledgebase.php, or (3) configuration.php, which leaks the information in a PHP error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6q3r-3xj4-6598/GHSA-6q3r-3xj4-6598.json b/advisories/unreviewed/2022/05/GHSA-6q3r-3xj4-6598/GHSA-6q3r-3xj4-6598.json index e447fbfc12e..3a649b2df30 100644 --- a/advisories/unreviewed/2022/05/GHSA-6q3r-3xj4-6598/GHSA-6q3r-3xj4-6598.json +++ b/advisories/unreviewed/2022/05/GHSA-6q3r-3xj4-6598/GHSA-6q3r-3xj4-6598.json @@ -7,12 +7,8 @@ "CVE-2005-2176" ], "details": "Novell NetMail automatically processes HTML in an attachment without prompting the user to save or open it, which makes it easier for remote attackers to conduct web-based attacks and steal cookies.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6vg8-8jg2-mmpm/GHSA-6vg8-8jg2-mmpm.json b/advisories/unreviewed/2022/05/GHSA-6vg8-8jg2-mmpm/GHSA-6vg8-8jg2-mmpm.json index 7e8d4c2dc9c..f92a7f0f9b1 100644 --- a/advisories/unreviewed/2022/05/GHSA-6vg8-8jg2-mmpm/GHSA-6vg8-8jg2-mmpm.json +++ b/advisories/unreviewed/2022/05/GHSA-6vg8-8jg2-mmpm/GHSA-6vg8-8jg2-mmpm.json @@ -7,12 +7,8 @@ "CVE-2005-2106" ], "details": "Unknown vulnerability in Drupal 4.5.0 through 4.5.3, 4.6.0, and 4.6.1 allows remote attackers to execute arbitrary PHP code via a public comment or posting.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6vhg-vrw5-pm3f/GHSA-6vhg-vrw5-pm3f.json b/advisories/unreviewed/2022/05/GHSA-6vhg-vrw5-pm3f/GHSA-6vhg-vrw5-pm3f.json index bf5df96486b..8769dd4ca2f 100644 --- a/advisories/unreviewed/2022/05/GHSA-6vhg-vrw5-pm3f/GHSA-6vhg-vrw5-pm3f.json +++ b/advisories/unreviewed/2022/05/GHSA-6vhg-vrw5-pm3f/GHSA-6vhg-vrw5-pm3f.json @@ -7,12 +7,8 @@ "CVE-2021-36798" ], "details": "A Denial-of-Service (DoS) vulnerability was discovered in Team Server in HelpSystems Cobalt Strike 4.2 and 4.3. It allows remote attackers to crash the C2 server thread and block beacons' communication with it.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6vrg-wjcc-x5jv/GHSA-6vrg-wjcc-x5jv.json b/advisories/unreviewed/2022/05/GHSA-6vrg-wjcc-x5jv/GHSA-6vrg-wjcc-x5jv.json index a95ed4b5521..93045af9e46 100644 --- a/advisories/unreviewed/2022/05/GHSA-6vrg-wjcc-x5jv/GHSA-6vrg-wjcc-x5jv.json +++ b/advisories/unreviewed/2022/05/GHSA-6vrg-wjcc-x5jv/GHSA-6vrg-wjcc-x5jv.json @@ -7,12 +7,8 @@ "CVE-2005-2322" ], "details": "Cross-site scripting (XSS) vulnerability in Class-1 Forum 0.24.4 and 0.23.2, and Clever Copy with forums installed, allows remote attackers to inject arbitrary web script or HTML via the (1) viewuser_id or (2) group parameter to users.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6w24-r92j-wj7q/GHSA-6w24-r92j-wj7q.json b/advisories/unreviewed/2022/05/GHSA-6w24-r92j-wj7q/GHSA-6w24-r92j-wj7q.json index 67ead3aa147..37deb85d6d0 100644 --- a/advisories/unreviewed/2022/05/GHSA-6w24-r92j-wj7q/GHSA-6w24-r92j-wj7q.json +++ b/advisories/unreviewed/2022/05/GHSA-6w24-r92j-wj7q/GHSA-6w24-r92j-wj7q.json @@ -7,12 +7,8 @@ "CVE-2005-2302" ], "details": "PowerDNS before 2.9.18, when allowing recursion to a restricted range of IP addresses, does not properly handle questions from clients that are denied recursion, which could cause a \"blank out\" of answers to those clients that are allowed to use recursion.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-723r-mjxx-m5hf/GHSA-723r-mjxx-m5hf.json b/advisories/unreviewed/2022/05/GHSA-723r-mjxx-m5hf/GHSA-723r-mjxx-m5hf.json index f43a7bccb68..ff4ac30cb3d 100644 --- a/advisories/unreviewed/2022/05/GHSA-723r-mjxx-m5hf/GHSA-723r-mjxx-m5hf.json +++ b/advisories/unreviewed/2022/05/GHSA-723r-mjxx-m5hf/GHSA-723r-mjxx-m5hf.json @@ -7,12 +7,8 @@ "CVE-2005-2184" ], "details": "eRoom 6.x does not properly restrict files that can be attached, which allows remote attackers to execute arbitrary commands via a .lnk file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-72m8-2j54-r5xg/GHSA-72m8-2j54-r5xg.json b/advisories/unreviewed/2022/05/GHSA-72m8-2j54-r5xg/GHSA-72m8-2j54-r5xg.json index 7cf7fb8e923..4cfc5596fe6 100644 --- a/advisories/unreviewed/2022/05/GHSA-72m8-2j54-r5xg/GHSA-72m8-2j54-r5xg.json +++ b/advisories/unreviewed/2022/05/GHSA-72m8-2j54-r5xg/GHSA-72m8-2j54-r5xg.json @@ -7,12 +7,8 @@ "CVE-2005-2314" ], "details": "inc.login.php in PHPsFTPd 0.2 through 0.4 allows remote attackers to obtain the administrator's username and password by setting the do_login parameter and performing an edit action using user.php, which causes the login check to be bypassed and leaks the password in the response.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-734c-27p8-w93p/GHSA-734c-27p8-w93p.json b/advisories/unreviewed/2022/05/GHSA-734c-27p8-w93p/GHSA-734c-27p8-w93p.json index 404947481c1..30662438161 100644 --- a/advisories/unreviewed/2022/05/GHSA-734c-27p8-w93p/GHSA-734c-27p8-w93p.json +++ b/advisories/unreviewed/2022/05/GHSA-734c-27p8-w93p/GHSA-734c-27p8-w93p.json @@ -7,12 +7,8 @@ "CVE-2005-1873" ], "details": "Multiple buffer overflows in Crob FTP 3.6.1, and possibly earlier versions, allow remote attackers to execute arbitrary code via (1) an FTP command with a large string followed by the RMD command with a long string or (2) a globbing (\"*\") character followed by a long string.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-73j5-q9c3-466j/GHSA-73j5-q9c3-466j.json b/advisories/unreviewed/2022/05/GHSA-73j5-q9c3-466j/GHSA-73j5-q9c3-466j.json index 1eb77a8d7d8..3eb2767111a 100644 --- a/advisories/unreviewed/2022/05/GHSA-73j5-q9c3-466j/GHSA-73j5-q9c3-466j.json +++ b/advisories/unreviewed/2022/05/GHSA-73j5-q9c3-466j/GHSA-73j5-q9c3-466j.json @@ -7,12 +7,8 @@ "CVE-2005-1872" ], "details": "Buffer overflow in the administrative console in IBM WebSphere Application Server 5.x, when the global security option is enabled, allows remote attackers to execute arbitrary code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-742p-65hp-7vgf/GHSA-742p-65hp-7vgf.json b/advisories/unreviewed/2022/05/GHSA-742p-65hp-7vgf/GHSA-742p-65hp-7vgf.json index f18526616a8..b2cd1cbdb0f 100644 --- a/advisories/unreviewed/2022/05/GHSA-742p-65hp-7vgf/GHSA-742p-65hp-7vgf.json +++ b/advisories/unreviewed/2022/05/GHSA-742p-65hp-7vgf/GHSA-742p-65hp-7vgf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-743q-jjrj-pgrc/GHSA-743q-jjrj-pgrc.json b/advisories/unreviewed/2022/05/GHSA-743q-jjrj-pgrc/GHSA-743q-jjrj-pgrc.json index 41566f609b7..f6d0669462c 100644 --- a/advisories/unreviewed/2022/05/GHSA-743q-jjrj-pgrc/GHSA-743q-jjrj-pgrc.json +++ b/advisories/unreviewed/2022/05/GHSA-743q-jjrj-pgrc/GHSA-743q-jjrj-pgrc.json @@ -7,12 +7,8 @@ "CVE-2021-20420" ], "details": "IBM Security Guardium 11.2 could disclose sensitive information due to reliance on untrusted inputs that could aid in further attacks against the system. IBM X-Force ID: 196281.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7452-wr2x-p4vw/GHSA-7452-wr2x-p4vw.json b/advisories/unreviewed/2022/05/GHSA-7452-wr2x-p4vw/GHSA-7452-wr2x-p4vw.json index 84588cd1d42..b094dd79d86 100644 --- a/advisories/unreviewed/2022/05/GHSA-7452-wr2x-p4vw/GHSA-7452-wr2x-p4vw.json +++ b/advisories/unreviewed/2022/05/GHSA-7452-wr2x-p4vw/GHSA-7452-wr2x-p4vw.json @@ -7,12 +7,8 @@ "CVE-2021-34631" ], "details": "The NewsPlugin WordPress plugin is vulnerable to Cross-Site Request Forgery via the handle_save_style function found in the ~/news-plugin.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.18.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7492-ggfx-8x9r/GHSA-7492-ggfx-8x9r.json b/advisories/unreviewed/2022/05/GHSA-7492-ggfx-8x9r/GHSA-7492-ggfx-8x9r.json index fbf3feeea7c..319066cbb9c 100644 --- a/advisories/unreviewed/2022/05/GHSA-7492-ggfx-8x9r/GHSA-7492-ggfx-8x9r.json +++ b/advisories/unreviewed/2022/05/GHSA-7492-ggfx-8x9r/GHSA-7492-ggfx-8x9r.json @@ -7,12 +7,8 @@ "CVE-2021-38547" ], "details": "Logitech Z120 and S120 speakers through 2021-08-09 allow remote attackers to recover speech signals from an LED on the device, via a telescope and an electro-optical sensor, aka a \"Glowworm\" attack. The power indicator LED of the speakers is connected directly to the power line, as a result, the intensity of a device's power indicator LED is correlative to the power consumption. The sound played by the speakers affects their power consumption and as a result is also correlative to the light intensity of the LEDs. By analyzing measurements obtained from an electro-optical sensor directed at the power indicator LEDs of the speakers, we can recover the sound played by them.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7545-65cx-3rpp/GHSA-7545-65cx-3rpp.json b/advisories/unreviewed/2022/05/GHSA-7545-65cx-3rpp/GHSA-7545-65cx-3rpp.json index 32c089b5fae..eb73d3cfa15 100644 --- a/advisories/unreviewed/2022/05/GHSA-7545-65cx-3rpp/GHSA-7545-65cx-3rpp.json +++ b/advisories/unreviewed/2022/05/GHSA-7545-65cx-3rpp/GHSA-7545-65cx-3rpp.json @@ -7,12 +7,8 @@ "CVE-2005-2253" ], "details": "SQL injection vulnerability in PhpAuction 2.5 allow remote attackers to modify SQL queries via the category parameter to adsearch.php. NOTE: there is evidence that viewnews.php may not be part of the PhpAuction product, so it is not included in this description.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-75fv-95x6-q4w4/GHSA-75fv-95x6-q4w4.json b/advisories/unreviewed/2022/05/GHSA-75fv-95x6-q4w4/GHSA-75fv-95x6-q4w4.json index 0134f050310..bcd399bc477 100644 --- a/advisories/unreviewed/2022/05/GHSA-75fv-95x6-q4w4/GHSA-75fv-95x6-q4w4.json +++ b/advisories/unreviewed/2022/05/GHSA-75fv-95x6-q4w4/GHSA-75fv-95x6-q4w4.json @@ -7,12 +7,8 @@ "CVE-2021-32580" ], "details": "Acronis True Image prior to 2021 Update 4 for Windows allowed local privilege escalation due to DLL hijacking.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-769r-vr4x-8x6c/GHSA-769r-vr4x-8x6c.json b/advisories/unreviewed/2022/05/GHSA-769r-vr4x-8x6c/GHSA-769r-vr4x-8x6c.json index 6695c247fe6..729f2d0237d 100644 --- a/advisories/unreviewed/2022/05/GHSA-769r-vr4x-8x6c/GHSA-769r-vr4x-8x6c.json +++ b/advisories/unreviewed/2022/05/GHSA-769r-vr4x-8x6c/GHSA-769r-vr4x-8x6c.json @@ -7,12 +7,8 @@ "CVE-2005-2196" ], "details": "The Apple AirPort card uses a default WEP key when not connected to a known or trusted network, which can cause it to automatically connect to a malicious network.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-77c5-mgrx-7m2v/GHSA-77c5-mgrx-7m2v.json b/advisories/unreviewed/2022/05/GHSA-77c5-mgrx-7m2v/GHSA-77c5-mgrx-7m2v.json index 4605798edc6..a746656897e 100644 --- a/advisories/unreviewed/2022/05/GHSA-77c5-mgrx-7m2v/GHSA-77c5-mgrx-7m2v.json +++ b/advisories/unreviewed/2022/05/GHSA-77c5-mgrx-7m2v/GHSA-77c5-mgrx-7m2v.json @@ -7,12 +7,8 @@ "CVE-2021-33699" ], "details": "Task Hijacking is a vulnerability that affects the applications running on Android devices due to a misconfiguration in their AndroidManifest.xml with their Task Control features. This allows an unauthorized attacker or malware to takeover legitimate apps and to steal user's sensitive information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-77qf-7v4v-3v74/GHSA-77qf-7v4v-3v74.json b/advisories/unreviewed/2022/05/GHSA-77qf-7v4v-3v74/GHSA-77qf-7v4v-3v74.json index a002b5d0632..82fe1a8511c 100644 --- a/advisories/unreviewed/2022/05/GHSA-77qf-7v4v-3v74/GHSA-77qf-7v4v-3v74.json +++ b/advisories/unreviewed/2022/05/GHSA-77qf-7v4v-3v74/GHSA-77qf-7v4v-3v74.json @@ -7,12 +7,8 @@ "CVE-2005-2049" ], "details": "Multiple SQL injection vulnerabilities in DUware DUclassmate 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) iState parameter to default.asp or (2) iPro parameter to edit.asp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-78gh-fjr2-xgcp/GHSA-78gh-fjr2-xgcp.json b/advisories/unreviewed/2022/05/GHSA-78gh-fjr2-xgcp/GHSA-78gh-fjr2-xgcp.json index d59ac3bc42b..9a158d92111 100644 --- a/advisories/unreviewed/2022/05/GHSA-78gh-fjr2-xgcp/GHSA-78gh-fjr2-xgcp.json +++ b/advisories/unreviewed/2022/05/GHSA-78gh-fjr2-xgcp/GHSA-78gh-fjr2-xgcp.json @@ -7,12 +7,8 @@ "CVE-2021-38515" ], "details": "Certain NETGEAR devices are affected by denial of service. This affects R6400v2 before 1.0.4.98, R6700v3 before 1.0.4.98, R7900 before 1.0.3.18, and R8000 before 1.0.4.46.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7f62-cq2q-qjc7/GHSA-7f62-cq2q-qjc7.json b/advisories/unreviewed/2022/05/GHSA-7f62-cq2q-qjc7/GHSA-7f62-cq2q-qjc7.json index 495147e9f8c..087aa4a56a5 100644 --- a/advisories/unreviewed/2022/05/GHSA-7f62-cq2q-qjc7/GHSA-7f62-cq2q-qjc7.json +++ b/advisories/unreviewed/2022/05/GHSA-7f62-cq2q-qjc7/GHSA-7f62-cq2q-qjc7.json @@ -7,12 +7,8 @@ "CVE-2021-38519" ], "details": "Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6250 before 1.0.4.36, R6300v2 before 1.0.4.36, R6400 before 1.0.1.50, R6400v2 before 1.0.2.66, R6700v3 before 1.0.2.66, R6700 before 1.0.2.8, R6900 before 1.0.2.8, R7000 before 1.0.9.88, R6900P before 1.3.2.132, R7100LG before 1.0.0.52, R7900 before 1.0.3.10, R8000 before 1.0.4.46, R7900P before 1.4.1.50, R8000P before 1.4.1.50, and RAX80 before 1.0.1.40.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7fj6-cw4m-wqw7/GHSA-7fj6-cw4m-wqw7.json b/advisories/unreviewed/2022/05/GHSA-7fj6-cw4m-wqw7/GHSA-7fj6-cw4m-wqw7.json index 322f8b9caf3..b716bab2942 100644 --- a/advisories/unreviewed/2022/05/GHSA-7fj6-cw4m-wqw7/GHSA-7fj6-cw4m-wqw7.json +++ b/advisories/unreviewed/2022/05/GHSA-7fj6-cw4m-wqw7/GHSA-7fj6-cw4m-wqw7.json @@ -7,12 +7,8 @@ "CVE-2005-2294" ], "details": "Oracle Forms 4.5, 6.0, 6i, and 9i on Unix, when a large number of records are retrieved by an Oracle form, stores a copy of the database tables in a world-readable temporary file, which allows local users to gain sensitive information such as credit card numbers.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7fm7-3fm9-2j98/GHSA-7fm7-3fm9-2j98.json b/advisories/unreviewed/2022/05/GHSA-7fm7-3fm9-2j98/GHSA-7fm7-3fm9-2j98.json index 6052140244f..42c06b76dd3 100644 --- a/advisories/unreviewed/2022/05/GHSA-7fm7-3fm9-2j98/GHSA-7fm7-3fm9-2j98.json +++ b/advisories/unreviewed/2022/05/GHSA-7fm7-3fm9-2j98/GHSA-7fm7-3fm9-2j98.json @@ -7,12 +7,8 @@ "CVE-2021-33707" ], "details": "SAP NetWeaver Knowledge Management allows remote attackers to redirect users to arbitrary websites and conduct phishing attacks via a URL stored in a component. This could enable the attacker to compromise the user's confidentiality and integrity.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7g34-h582-vgj9/GHSA-7g34-h582-vgj9.json b/advisories/unreviewed/2022/05/GHSA-7g34-h582-vgj9/GHSA-7g34-h582-vgj9.json index e646a5c6556..72fc3967e0c 100644 --- a/advisories/unreviewed/2022/05/GHSA-7g34-h582-vgj9/GHSA-7g34-h582-vgj9.json +++ b/advisories/unreviewed/2022/05/GHSA-7g34-h582-vgj9/GHSA-7g34-h582-vgj9.json @@ -7,12 +7,8 @@ "CVE-2005-2313" ], "details": "Check Point SecuRemote NG with Application Intelligence R54 allows attackers to obtain credentials and gain privileges via unknown attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7g4v-hh23-cj4q/GHSA-7g4v-hh23-cj4q.json b/advisories/unreviewed/2022/05/GHSA-7g4v-hh23-cj4q/GHSA-7g4v-hh23-cj4q.json index 5bc5d993b73..09e7c250956 100644 --- a/advisories/unreviewed/2022/05/GHSA-7g4v-hh23-cj4q/GHSA-7g4v-hh23-cj4q.json +++ b/advisories/unreviewed/2022/05/GHSA-7g4v-hh23-cj4q/GHSA-7g4v-hh23-cj4q.json @@ -7,12 +7,8 @@ "CVE-2021-0062" ], "details": "Improper input validation in some Intel(R) Graphics Drivers before version 27.20.100.8935 may allow an authenticated user to potentially enable escalation of privilege via local access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7ggc-r92q-wv9h/GHSA-7ggc-r92q-wv9h.json b/advisories/unreviewed/2022/05/GHSA-7ggc-r92q-wv9h/GHSA-7ggc-r92q-wv9h.json index 60f99ce5595..d0e8abe57c3 100644 --- a/advisories/unreviewed/2022/05/GHSA-7ggc-r92q-wv9h/GHSA-7ggc-r92q-wv9h.json +++ b/advisories/unreviewed/2022/05/GHSA-7ggc-r92q-wv9h/GHSA-7ggc-r92q-wv9h.json @@ -7,12 +7,8 @@ "CVE-2005-2145" ], "details": "The kernel driver in Prevx Pro 2005 1.0 does not verify the source of certain messages, which allows local users to bypass protection by sending certain messages to the driver, as demonstrated by sending an \"allow\" message to bypass a warning message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7hcc-mq7f-h4mv/GHSA-7hcc-mq7f-h4mv.json b/advisories/unreviewed/2022/05/GHSA-7hcc-mq7f-h4mv/GHSA-7hcc-mq7f-h4mv.json index 5923ee1ef41..2890a5e064f 100644 --- a/advisories/unreviewed/2022/05/GHSA-7hcc-mq7f-h4mv/GHSA-7hcc-mq7f-h4mv.json +++ b/advisories/unreviewed/2022/05/GHSA-7hcc-mq7f-h4mv/GHSA-7hcc-mq7f-h4mv.json @@ -7,12 +7,8 @@ "CVE-2021-24502" ], "details": "The WP Google Map WordPress plugin before 1.7.7 did not sanitise or escape the Map Title before outputting them in the page, leading to a Stored Cross-Site Scripting issue by high privilege users, even when the unfiltered_html capability is disallowed", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7hhp-9v6r-9h4x/GHSA-7hhp-9v6r-9h4x.json b/advisories/unreviewed/2022/05/GHSA-7hhp-9v6r-9h4x/GHSA-7hhp-9v6r-9h4x.json index 35bf6b82db6..6171d454445 100644 --- a/advisories/unreviewed/2022/05/GHSA-7hhp-9v6r-9h4x/GHSA-7hhp-9v6r-9h4x.json +++ b/advisories/unreviewed/2022/05/GHSA-7hhp-9v6r-9h4x/GHSA-7hhp-9v6r-9h4x.json @@ -7,12 +7,8 @@ "CVE-2021-38290" ], "details": "A host header attack vulnerability exists in FUEL CMS 1.5.0 through fuel/modules/fuel/config/fuel_constants.php and fuel/modules/fuel/libraries/Asset.php. An attacker can use a man in the middle attack such as phishing.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7hxc-hm2f-r4g3/GHSA-7hxc-hm2f-r4g3.json b/advisories/unreviewed/2022/05/GHSA-7hxc-hm2f-r4g3/GHSA-7hxc-hm2f-r4g3.json index 5d3257a3e89..d9441fee22c 100644 --- a/advisories/unreviewed/2022/05/GHSA-7hxc-hm2f-r4g3/GHSA-7hxc-hm2f-r4g3.json +++ b/advisories/unreviewed/2022/05/GHSA-7hxc-hm2f-r4g3/GHSA-7hxc-hm2f-r4g3.json @@ -7,12 +7,8 @@ "CVE-2005-2309" ], "details": "Opera 8.01 allows remote attackers to cause a denial of service (CPU consumption) via a crafted JPEG image, as demonstrated using random.jpg.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7m28-prvw-2j2x/GHSA-7m28-prvw-2j2x.json b/advisories/unreviewed/2022/05/GHSA-7m28-prvw-2j2x/GHSA-7m28-prvw-2j2x.json index f1d38cefc12..07c9392e852 100644 --- a/advisories/unreviewed/2022/05/GHSA-7m28-prvw-2j2x/GHSA-7m28-prvw-2j2x.json +++ b/advisories/unreviewed/2022/05/GHSA-7m28-prvw-2j2x/GHSA-7m28-prvw-2j2x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7pvf-533w-5xpj/GHSA-7pvf-533w-5xpj.json b/advisories/unreviewed/2022/05/GHSA-7pvf-533w-5xpj/GHSA-7pvf-533w-5xpj.json index 86d86a4c7a1..cf07a5a752e 100644 --- a/advisories/unreviewed/2022/05/GHSA-7pvf-533w-5xpj/GHSA-7pvf-533w-5xpj.json +++ b/advisories/unreviewed/2022/05/GHSA-7pvf-533w-5xpj/GHSA-7pvf-533w-5xpj.json @@ -7,12 +7,8 @@ "CVE-2005-1871" ], "details": "Unknown vulnerability in the privilege system in Drupal 4.4.0 through 4.6.0, when public registration is enabled, allows remote attackers to gain privileges, due to an \"input check\" that \"is not implemented properly.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7pxh-q6jw-6xj8/GHSA-7pxh-q6jw-6xj8.json b/advisories/unreviewed/2022/05/GHSA-7pxh-q6jw-6xj8/GHSA-7pxh-q6jw-6xj8.json index af91c5b4574..a199e8fbdaa 100644 --- a/advisories/unreviewed/2022/05/GHSA-7pxh-q6jw-6xj8/GHSA-7pxh-q6jw-6xj8.json +++ b/advisories/unreviewed/2022/05/GHSA-7pxh-q6jw-6xj8/GHSA-7pxh-q6jw-6xj8.json @@ -7,12 +7,8 @@ "CVE-2021-33339" ], "details": "Cross-site scripting (XSS) vulnerability in the Fragment module in Liferay Portal 7.2.1 through 7.3.4, and Liferay DXP 7.2 before fix pack 9 allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_site_admin_web_portlet_SiteAdminPortlet_name parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7qwq-qrqh-hx2m/GHSA-7qwq-qrqh-hx2m.json b/advisories/unreviewed/2022/05/GHSA-7qwq-qrqh-hx2m/GHSA-7qwq-qrqh-hx2m.json index b98125ebb9f..c1dc5d4e6b6 100644 --- a/advisories/unreviewed/2022/05/GHSA-7qwq-qrqh-hx2m/GHSA-7qwq-qrqh-hx2m.json +++ b/advisories/unreviewed/2022/05/GHSA-7qwq-qrqh-hx2m/GHSA-7qwq-qrqh-hx2m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7qxc-g673-56cv/GHSA-7qxc-g673-56cv.json b/advisories/unreviewed/2022/05/GHSA-7qxc-g673-56cv/GHSA-7qxc-g673-56cv.json index 75a01bd6244..ae71cbb5497 100644 --- a/advisories/unreviewed/2022/05/GHSA-7qxc-g673-56cv/GHSA-7qxc-g673-56cv.json +++ b/advisories/unreviewed/2022/05/GHSA-7qxc-g673-56cv/GHSA-7qxc-g673-56cv.json @@ -7,12 +7,8 @@ "CVE-2005-1948" ], "details": "Multiple SQL injection vulnerabilities in Invision Gallery before 1.3.1 allow remote attackers to execute arbitrary SQL commands via (1) the comment parameter in an editcomment action or (2) the rating parameter when voting on a photo.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7rfv-x23q-gmxq/GHSA-7rfv-x23q-gmxq.json b/advisories/unreviewed/2022/05/GHSA-7rfv-x23q-gmxq/GHSA-7rfv-x23q-gmxq.json index 4a15a3f7a1c..1e2afb18cc8 100644 --- a/advisories/unreviewed/2022/05/GHSA-7rfv-x23q-gmxq/GHSA-7rfv-x23q-gmxq.json +++ b/advisories/unreviewed/2022/05/GHSA-7rfv-x23q-gmxq/GHSA-7rfv-x23q-gmxq.json @@ -7,12 +7,8 @@ "CVE-2005-1980" ], "details": "Distributed Transaction Controller in Microsoft Windows allows remote servers to cause a denial of service (MSDTC service hang) via a crafted Transaction Internet Protocol (TIP) message that causes DTC to repeatedly connect to a target IP and port number after an error occurs, aka the \"Distributed TIP Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -80,9 +76,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7v55-666w-j6m4/GHSA-7v55-666w-j6m4.json b/advisories/unreviewed/2022/05/GHSA-7v55-666w-j6m4/GHSA-7v55-666w-j6m4.json index 99a4af669bc..d5e20e3db1c 100644 --- a/advisories/unreviewed/2022/05/GHSA-7v55-666w-j6m4/GHSA-7v55-666w-j6m4.json +++ b/advisories/unreviewed/2022/05/GHSA-7v55-666w-j6m4/GHSA-7v55-666w-j6m4.json @@ -7,12 +7,8 @@ "CVE-2005-1972" ], "details": "Multiple SQL injection vulnerabilities in InteractivePHP FusionBB .11 Beta and earlier allow remote attackers to execute arbitrary SQL commands via (1) the username, which is not properly handled by the insertUser function, or (2) the bb_session_id value in a cookie.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7vq4-gm9q-gv7j/GHSA-7vq4-gm9q-gv7j.json b/advisories/unreviewed/2022/05/GHSA-7vq4-gm9q-gv7j/GHSA-7vq4-gm9q-gv7j.json index 98b58c3ff92..43a0d336f55 100644 --- a/advisories/unreviewed/2022/05/GHSA-7vq4-gm9q-gv7j/GHSA-7vq4-gm9q-gv7j.json +++ b/advisories/unreviewed/2022/05/GHSA-7vq4-gm9q-gv7j/GHSA-7vq4-gm9q-gv7j.json @@ -7,12 +7,8 @@ "CVE-2005-2163" ], "details": "Cross-site scripting (XSS) vulnerability in index.php in AutoIndex PHP Script 1.5.2 allows remote attackers to inject arbitrary web script or HTML via the search parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7x9m-x8x2-59rx/GHSA-7x9m-x8x2-59rx.json b/advisories/unreviewed/2022/05/GHSA-7x9m-x8x2-59rx/GHSA-7x9m-x8x2-59rx.json index 1a7f8dc6006..d82162876b0 100644 --- a/advisories/unreviewed/2022/05/GHSA-7x9m-x8x2-59rx/GHSA-7x9m-x8x2-59rx.json +++ b/advisories/unreviewed/2022/05/GHSA-7x9m-x8x2-59rx/GHSA-7x9m-x8x2-59rx.json @@ -7,12 +7,8 @@ "CVE-2005-2238" ], "details": "ftpd in IBM AIX 5.1, 5.2 and 5.3 allows remote authenticated users to cause a denial of service (port exhaustion and memory consumption) by using all ephemeral ports.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7xcf-8vfw-jvw5/GHSA-7xcf-8vfw-jvw5.json b/advisories/unreviewed/2022/05/GHSA-7xcf-8vfw-jvw5/GHSA-7xcf-8vfw-jvw5.json index 91afb3559d2..fd908768663 100644 --- a/advisories/unreviewed/2022/05/GHSA-7xcf-8vfw-jvw5/GHSA-7xcf-8vfw-jvw5.json +++ b/advisories/unreviewed/2022/05/GHSA-7xcf-8vfw-jvw5/GHSA-7xcf-8vfw-jvw5.json @@ -7,12 +7,8 @@ "CVE-2021-34661" ], "details": "The WP Fusion Lite WordPress plugin is vulnerable to Cross-Site Request Forgery via the `show_logs_section` function found in the ~/includes/admin/logging/class-log-handler.php file which allows attackers to drop all logs for the plugin, in versions up to and including 3.37.18.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7xq3-xc97-hhr3/GHSA-7xq3-xc97-hhr3.json b/advisories/unreviewed/2022/05/GHSA-7xq3-xc97-hhr3/GHSA-7xq3-xc97-hhr3.json index e0ee9f20983..4e4be7b0fcf 100644 --- a/advisories/unreviewed/2022/05/GHSA-7xq3-xc97-hhr3/GHSA-7xq3-xc97-hhr3.json +++ b/advisories/unreviewed/2022/05/GHSA-7xq3-xc97-hhr3/GHSA-7xq3-xc97-hhr3.json @@ -7,12 +7,8 @@ "CVE-2021-28846" ], "details": "A Format String vulnerablity exists in TRENDnet TEW-755AP 1.11B03, TEW-755AP2KAC 1.11B03, TEW-821DAP2KAC 1.11B03, and TEW-825DAP 1.11B03, which could let a remote malicious user cause a denial of service due to a logic bug at address 0x40dcd0 when calling fprintf with \"%s: key len = %d, too long\\n\" format. The two variables seem to be put in the wrong order. The vulnerability could be triggered by sending the POST request to apply_cgi with a long and unknown key in the request body.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-822v-pgr4-6w5g/GHSA-822v-pgr4-6w5g.json b/advisories/unreviewed/2022/05/GHSA-822v-pgr4-6w5g/GHSA-822v-pgr4-6w5g.json index 60fd6926b0a..96eac3a7c99 100644 --- a/advisories/unreviewed/2022/05/GHSA-822v-pgr4-6w5g/GHSA-822v-pgr4-6w5g.json +++ b/advisories/unreviewed/2022/05/GHSA-822v-pgr4-6w5g/GHSA-822v-pgr4-6w5g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-82xp-mp67-7f8p/GHSA-82xp-mp67-7f8p.json b/advisories/unreviewed/2022/05/GHSA-82xp-mp67-7f8p/GHSA-82xp-mp67-7f8p.json index 2fef77e5add..496f3c47256 100644 --- a/advisories/unreviewed/2022/05/GHSA-82xp-mp67-7f8p/GHSA-82xp-mp67-7f8p.json +++ b/advisories/unreviewed/2022/05/GHSA-82xp-mp67-7f8p/GHSA-82xp-mp67-7f8p.json @@ -7,12 +7,8 @@ "CVE-2005-2257" ], "details": "The saveProfile function in PhpSlash 0.8.0 allows remote attackers to modify arbitrary profiles and gain privileges by modifying the author_id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8374-7847-gp4w/GHSA-8374-7847-gp4w.json b/advisories/unreviewed/2022/05/GHSA-8374-7847-gp4w/GHSA-8374-7847-gp4w.json index f14729f1702..3696cd807ee 100644 --- a/advisories/unreviewed/2022/05/GHSA-8374-7847-gp4w/GHSA-8374-7847-gp4w.json +++ b/advisories/unreviewed/2022/05/GHSA-8374-7847-gp4w/GHSA-8374-7847-gp4w.json @@ -7,12 +7,8 @@ "CVE-2021-38381" ], "details": "Live555 through 1.08 does not handle MPEG-1 or 2 files properly. Sending two successive RTSP SETUP commands for the same track causes a Use-After-Free and daemon crash.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-837p-9vr8-qcqc/GHSA-837p-9vr8-qcqc.json b/advisories/unreviewed/2022/05/GHSA-837p-9vr8-qcqc/GHSA-837p-9vr8-qcqc.json index 3754b8aa3db..8bd0f735a66 100644 --- a/advisories/unreviewed/2022/05/GHSA-837p-9vr8-qcqc/GHSA-837p-9vr8-qcqc.json +++ b/advisories/unreviewed/2022/05/GHSA-837p-9vr8-qcqc/GHSA-837p-9vr8-qcqc.json @@ -7,12 +7,8 @@ "CVE-2005-2077" ], "details": "Cross-site scripting (XSS) vulnerability in error.asp for Hosting Controller allows remote attackers to inject arbitrary web script or HTML via the error parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-83jq-pfpr-f4x2/GHSA-83jq-pfpr-f4x2.json b/advisories/unreviewed/2022/05/GHSA-83jq-pfpr-f4x2/GHSA-83jq-pfpr-f4x2.json index 240145f949c..4ff04cdf93e 100644 --- a/advisories/unreviewed/2022/05/GHSA-83jq-pfpr-f4x2/GHSA-83jq-pfpr-f4x2.json +++ b/advisories/unreviewed/2022/05/GHSA-83jq-pfpr-f4x2/GHSA-83jq-pfpr-f4x2.json @@ -7,12 +7,8 @@ "CVE-2005-1852" ], "details": "Multiple integer overflows in libgadu, as used in Kopete in KDE 3.2.3 to 3.4.1, ekg before 1.6rc3, GNU Gadu, CenterICQ, Kadu, and other packages, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an incoming message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -72,9 +68,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8439-jh82-pcq5/GHSA-8439-jh82-pcq5.json b/advisories/unreviewed/2022/05/GHSA-8439-jh82-pcq5/GHSA-8439-jh82-pcq5.json index 86db6078045..d50c7bd23f5 100644 --- a/advisories/unreviewed/2022/05/GHSA-8439-jh82-pcq5/GHSA-8439-jh82-pcq5.json +++ b/advisories/unreviewed/2022/05/GHSA-8439-jh82-pcq5/GHSA-8439-jh82-pcq5.json @@ -7,12 +7,8 @@ "CVE-2021-0160" ], "details": "Uncontrolled search path in some Intel(R) NUC Pro Chassis Element AverMedia Capture Card drivers before version 3.0.64.143 may allow an authenticated user to potentially enable escalation of privilege via local access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-84wp-p749-mr24/GHSA-84wp-p749-mr24.json b/advisories/unreviewed/2022/05/GHSA-84wp-p749-mr24/GHSA-84wp-p749-mr24.json index 15cf5da1da6..4c7029be881 100644 --- a/advisories/unreviewed/2022/05/GHSA-84wp-p749-mr24/GHSA-84wp-p749-mr24.json +++ b/advisories/unreviewed/2022/05/GHSA-84wp-p749-mr24/GHSA-84wp-p749-mr24.json @@ -7,12 +7,8 @@ "CVE-2005-1956" ], "details": "File Upload Manager allows remote attackers to upload arbitrary files by modifying the test variable to contain a value of '~~~~~~' (six tildes), which bypasses the file extension checks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-85cf-px78-q8mx/GHSA-85cf-px78-q8mx.json b/advisories/unreviewed/2022/05/GHSA-85cf-px78-q8mx/GHSA-85cf-px78-q8mx.json index 4e6079e9c28..2fc51f5c909 100644 --- a/advisories/unreviewed/2022/05/GHSA-85cf-px78-q8mx/GHSA-85cf-px78-q8mx.json +++ b/advisories/unreviewed/2022/05/GHSA-85cf-px78-q8mx/GHSA-85cf-px78-q8mx.json @@ -7,12 +7,8 @@ "CVE-2005-2166" ], "details": "SQL injection vulnerability in index.php in Plague News System 0.6 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-86cq-6fm2-9w8h/GHSA-86cq-6fm2-9w8h.json b/advisories/unreviewed/2022/05/GHSA-86cq-6fm2-9w8h/GHSA-86cq-6fm2-9w8h.json index a3ab2e2c461..1d2df19426a 100644 --- a/advisories/unreviewed/2022/05/GHSA-86cq-6fm2-9w8h/GHSA-86cq-6fm2-9w8h.json +++ b/advisories/unreviewed/2022/05/GHSA-86cq-6fm2-9w8h/GHSA-86cq-6fm2-9w8h.json @@ -7,12 +7,8 @@ "CVE-2005-1965" ], "details": "PHP remote file inclusion vulnerability in siteframe.php for Broadpool Siteframe allows remote attackers to execute arbitrary code via a URL in the LOCAL_PATH parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-88qw-9cpf-73vx/GHSA-88qw-9cpf-73vx.json b/advisories/unreviewed/2022/05/GHSA-88qw-9cpf-73vx/GHSA-88qw-9cpf-73vx.json index 24c8f9fd107..a7f690d03df 100644 --- a/advisories/unreviewed/2022/05/GHSA-88qw-9cpf-73vx/GHSA-88qw-9cpf-73vx.json +++ b/advisories/unreviewed/2022/05/GHSA-88qw-9cpf-73vx/GHSA-88qw-9cpf-73vx.json @@ -7,12 +7,8 @@ "CVE-2005-1981" ], "details": "Unknown vulnerability in Microsoft Windows 2000 Server and Windows Server 2003 domain controllers allows remote authenticated users to cause a denial of service (system crash) via a crafted Kerberos message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-892v-2jhr-535f/GHSA-892v-2jhr-535f.json b/advisories/unreviewed/2022/05/GHSA-892v-2jhr-535f/GHSA-892v-2jhr-535f.json index 5096dd70186..635088859e7 100644 --- a/advisories/unreviewed/2022/05/GHSA-892v-2jhr-535f/GHSA-892v-2jhr-535f.json +++ b/advisories/unreviewed/2022/05/GHSA-892v-2jhr-535f/GHSA-892v-2jhr-535f.json @@ -7,12 +7,8 @@ "CVE-2021-37391" ], "details": "A user without privileges in Chamilo LMS 1.11.14 can send an invitation message to another user, e.g., the administrator, through main/social/search.php, main/inc/lib/social.lib.php and steal cookies or execute arbitrary code on the administration side via a stored XSS vulnerability via social network the send invitation feature.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8fcx-wwjr-3g5r/GHSA-8fcx-wwjr-3g5r.json b/advisories/unreviewed/2022/05/GHSA-8fcx-wwjr-3g5r/GHSA-8fcx-wwjr-3g5r.json index c63f237574a..41b3e7add36 100644 --- a/advisories/unreviewed/2022/05/GHSA-8fcx-wwjr-3g5r/GHSA-8fcx-wwjr-3g5r.json +++ b/advisories/unreviewed/2022/05/GHSA-8fcx-wwjr-3g5r/GHSA-8fcx-wwjr-3g5r.json @@ -7,12 +7,8 @@ "CVE-2005-1946" ], "details": "Multiple SQL injection vulnerabilities in Invision Blog before 1.1.2 Final allow remote attackers to execute arbitrary SQL commands via the (1) eid parameter to an editentry, replyentry, or editcomment action, or (2) the mid parameter to an aboutme action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8fj3-j232-6cpg/GHSA-8fj3-j232-6cpg.json b/advisories/unreviewed/2022/05/GHSA-8fj3-j232-6cpg/GHSA-8fj3-j232-6cpg.json index 2464ddb7419..3ab9210cab7 100644 --- a/advisories/unreviewed/2022/05/GHSA-8fj3-j232-6cpg/GHSA-8fj3-j232-6cpg.json +++ b/advisories/unreviewed/2022/05/GHSA-8fj3-j232-6cpg/GHSA-8fj3-j232-6cpg.json @@ -7,12 +7,8 @@ "CVE-2005-2197" ], "details": "SQL injection vulnerability in sql.cls.php in Id Board 1.1.3 allows remote attackers to modify SQL queries, as demonstrated using the f parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8fj3-r29c-jc2q/GHSA-8fj3-r29c-jc2q.json b/advisories/unreviewed/2022/05/GHSA-8fj3-r29c-jc2q/GHSA-8fj3-r29c-jc2q.json index 9d6fce07bdb..ff945142a96 100644 --- a/advisories/unreviewed/2022/05/GHSA-8fj3-r29c-jc2q/GHSA-8fj3-r29c-jc2q.json +++ b/advisories/unreviewed/2022/05/GHSA-8fj3-r29c-jc2q/GHSA-8fj3-r29c-jc2q.json @@ -7,12 +7,8 @@ "CVE-2020-18449" ], "details": "Cross Site Scripting (XSS) vulnerability exists in UKCMS v1.1.10 via data in the index function in Single.php", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8g37-cfrg-rm37/GHSA-8g37-cfrg-rm37.json b/advisories/unreviewed/2022/05/GHSA-8g37-cfrg-rm37/GHSA-8g37-cfrg-rm37.json index 498864fa021..4fe11cbbb88 100644 --- a/advisories/unreviewed/2022/05/GHSA-8g37-cfrg-rm37/GHSA-8g37-cfrg-rm37.json +++ b/advisories/unreviewed/2022/05/GHSA-8g37-cfrg-rm37/GHSA-8g37-cfrg-rm37.json @@ -7,12 +7,8 @@ "CVE-2005-1864" ], "details": "PHP remote file inclusion vulnerability in cal_admintop.php in Calendarix Advanced 1.5 allows remote attackers to execute arbitrary PHP code via the calpath parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8g53-w3hm-63c4/GHSA-8g53-w3hm-63c4.json b/advisories/unreviewed/2022/05/GHSA-8g53-w3hm-63c4/GHSA-8g53-w3hm-63c4.json index 85f0321767e..fee06795b59 100644 --- a/advisories/unreviewed/2022/05/GHSA-8g53-w3hm-63c4/GHSA-8g53-w3hm-63c4.json +++ b/advisories/unreviewed/2022/05/GHSA-8g53-w3hm-63c4/GHSA-8g53-w3hm-63c4.json @@ -7,12 +7,8 @@ "CVE-2021-0005" ], "details": "Uncaught exception in firmware for Intel(R) Ethernet Adapters 800 Series Controllers and associated adapters before version 1.5.3.0 may allow a privileged user to potentially enable denial of service via local access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8gf7-vr5p-pm49/GHSA-8gf7-vr5p-pm49.json b/advisories/unreviewed/2022/05/GHSA-8gf7-vr5p-pm49/GHSA-8gf7-vr5p-pm49.json index d2d5688dbab..5d733e37f77 100644 --- a/advisories/unreviewed/2022/05/GHSA-8gf7-vr5p-pm49/GHSA-8gf7-vr5p-pm49.json +++ b/advisories/unreviewed/2022/05/GHSA-8gf7-vr5p-pm49/GHSA-8gf7-vr5p-pm49.json @@ -7,12 +7,8 @@ "CVE-2005-2057" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to inject arbitrary web script or HTML via the (1) Searchpage parameter to dosearch.php, (2) Number, (3) what, or (4) page parameter to newreply.php, (5) Number, (6) Board, or (7) what parameter to showprofile.php, (8) fpart or (9) page parameter to showflat.php, or (10) like parameter to showmembers.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8gh2-336j-g8v7/GHSA-8gh2-336j-g8v7.json b/advisories/unreviewed/2022/05/GHSA-8gh2-336j-g8v7/GHSA-8gh2-336j-g8v7.json index 8e635de4ce3..819a25c4ce2 100644 --- a/advisories/unreviewed/2022/05/GHSA-8gh2-336j-g8v7/GHSA-8gh2-336j-g8v7.json +++ b/advisories/unreviewed/2022/05/GHSA-8gh2-336j-g8v7/GHSA-8gh2-336j-g8v7.json @@ -7,12 +7,8 @@ "CVE-2021-38371" ], "details": "The STARTTLS feature in Exim through 4.94.2 allows response injection (buffering) during MTA SMTP sending.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8gv5-94ph-p3x6/GHSA-8gv5-94ph-p3x6.json b/advisories/unreviewed/2022/05/GHSA-8gv5-94ph-p3x6/GHSA-8gv5-94ph-p3x6.json index dba5ff2b204..568623ec021 100644 --- a/advisories/unreviewed/2022/05/GHSA-8gv5-94ph-p3x6/GHSA-8gv5-94ph-p3x6.json +++ b/advisories/unreviewed/2022/05/GHSA-8gv5-94ph-p3x6/GHSA-8gv5-94ph-p3x6.json @@ -7,12 +7,8 @@ "CVE-2005-2082" ], "details": "im_trbbs.cgi in imTRSET 1.02 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the df parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8hh6-j7m7-vh6q/GHSA-8hh6-j7m7-vh6q.json b/advisories/unreviewed/2022/05/GHSA-8hh6-j7m7-vh6q/GHSA-8hh6-j7m7-vh6q.json index fe72d0d864a..6f2f1dfa69e 100644 --- a/advisories/unreviewed/2022/05/GHSA-8hh6-j7m7-vh6q/GHSA-8hh6-j7m7-vh6q.json +++ b/advisories/unreviewed/2022/05/GHSA-8hh6-j7m7-vh6q/GHSA-8hh6-j7m7-vh6q.json @@ -7,12 +7,8 @@ "CVE-2021-38517" ], "details": "Certain NETGEAR devices are affected by out-of-bounds reads and writes. This affects R6400 before 1.0.1.70, RAX75 before 1.0.4.120, RAX80 before 1.0.4.120, and XR300 before 1.0.3.50.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8j5x-g5rj-7pjj/GHSA-8j5x-g5rj-7pjj.json b/advisories/unreviewed/2022/05/GHSA-8j5x-g5rj-7pjj/GHSA-8j5x-g5rj-7pjj.json index 5af318769da..8c95d875b7b 100644 --- a/advisories/unreviewed/2022/05/GHSA-8j5x-g5rj-7pjj/GHSA-8j5x-g5rj-7pjj.json +++ b/advisories/unreviewed/2022/05/GHSA-8j5x-g5rj-7pjj/GHSA-8j5x-g5rj-7pjj.json @@ -7,12 +7,8 @@ "CVE-2005-1883" ], "details": "global.php in YaPiG 0.92b allows remote attackers to include arbitrary local files via the BASE_DIR parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8jpx-qvww-893m/GHSA-8jpx-qvww-893m.json b/advisories/unreviewed/2022/05/GHSA-8jpx-qvww-893m/GHSA-8jpx-qvww-893m.json index 972c2380dbd..4f365f21c0d 100644 --- a/advisories/unreviewed/2022/05/GHSA-8jpx-qvww-893m/GHSA-8jpx-qvww-893m.json +++ b/advisories/unreviewed/2022/05/GHSA-8jpx-qvww-893m/GHSA-8jpx-qvww-893m.json @@ -7,12 +7,8 @@ "CVE-2005-2143" ], "details": "Microsoft Front Page allows attackers to cause a denial of service (crash) via a crafted style tag in a web page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8p69-hfjg-c7fw/GHSA-8p69-hfjg-c7fw.json b/advisories/unreviewed/2022/05/GHSA-8p69-hfjg-c7fw/GHSA-8p69-hfjg-c7fw.json index 45eee9071ea..2c44f4275f8 100644 --- a/advisories/unreviewed/2022/05/GHSA-8p69-hfjg-c7fw/GHSA-8p69-hfjg-c7fw.json +++ b/advisories/unreviewed/2022/05/GHSA-8p69-hfjg-c7fw/GHSA-8p69-hfjg-c7fw.json @@ -7,12 +7,8 @@ "CVE-2005-1998" ], "details": "Directory traversal vulnerability in admin.php in McGallery 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the lang parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8q3v-p32x-2pq7/GHSA-8q3v-p32x-2pq7.json b/advisories/unreviewed/2022/05/GHSA-8q3v-p32x-2pq7/GHSA-8q3v-p32x-2pq7.json index d17fe044d58..42dfc47ea20 100644 --- a/advisories/unreviewed/2022/05/GHSA-8q3v-p32x-2pq7/GHSA-8q3v-p32x-2pq7.json +++ b/advisories/unreviewed/2022/05/GHSA-8q3v-p32x-2pq7/GHSA-8q3v-p32x-2pq7.json @@ -7,12 +7,8 @@ "CVE-2005-1993" ], "details": "Race condition in sudo 1.3.1 up to 1.6.8p8, when the ALL pseudo-command is used after a user entry in the sudoers file, allows local users to gain privileges via a symlink attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -92,9 +88,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8r5c-7jg4-q74j/GHSA-8r5c-7jg4-q74j.json b/advisories/unreviewed/2022/05/GHSA-8r5c-7jg4-q74j/GHSA-8r5c-7jg4-q74j.json index cc9f02e2443..6f68e0a42ab 100644 --- a/advisories/unreviewed/2022/05/GHSA-8r5c-7jg4-q74j/GHSA-8r5c-7jg4-q74j.json +++ b/advisories/unreviewed/2022/05/GHSA-8r5c-7jg4-q74j/GHSA-8r5c-7jg4-q74j.json @@ -7,12 +7,8 @@ "CVE-2005-2295" ], "details": "NetPanzer 0.8 and earlier allows remote attackers to cause a denial of service (infinite loop) via a packet with a zero datablock size.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8rpw-v8vj-5g5v/GHSA-8rpw-v8vj-5g5v.json b/advisories/unreviewed/2022/05/GHSA-8rpw-v8vj-5g5v/GHSA-8rpw-v8vj-5g5v.json index c49d19ef649..a1eb0aff7cd 100644 --- a/advisories/unreviewed/2022/05/GHSA-8rpw-v8vj-5g5v/GHSA-8rpw-v8vj-5g5v.json +++ b/advisories/unreviewed/2022/05/GHSA-8rpw-v8vj-5g5v/GHSA-8rpw-v8vj-5g5v.json @@ -7,12 +7,8 @@ "CVE-2005-1870" ], "details": "PHP remote file inclusion vulnerability in childwindow.inc.php in Popper 1.41-r2 and earlier allows remote attackers to execute arbitrary PHP code via the form parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8v5q-r6pr-xg3j/GHSA-8v5q-r6pr-xg3j.json b/advisories/unreviewed/2022/05/GHSA-8v5q-r6pr-xg3j/GHSA-8v5q-r6pr-xg3j.json index f2cfe6543ff..9cdc5bb1d45 100644 --- a/advisories/unreviewed/2022/05/GHSA-8v5q-r6pr-xg3j/GHSA-8v5q-r6pr-xg3j.json +++ b/advisories/unreviewed/2022/05/GHSA-8v5q-r6pr-xg3j/GHSA-8v5q-r6pr-xg3j.json @@ -7,12 +7,8 @@ "CVE-2021-22919" ], "details": "A vulnerability has been discovered in Citrix ADC (formerly known as NetScaler ADC) and Citrix Gateway (formerly known as NetScaler Gateway), and Citrix SD-WAN WANOP Edition models 4000-WO, 4100-WO, 5000-WO, and 5100-WO. These vulnerabilities, if exploited, could lead to the limited available disk space on the appliances being fully consumed.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8vfv-hc9g-64w9/GHSA-8vfv-hc9g-64w9.json b/advisories/unreviewed/2022/05/GHSA-8vfv-hc9g-64w9/GHSA-8vfv-hc9g-64w9.json index 95adc03ed0b..4d286949135 100644 --- a/advisories/unreviewed/2022/05/GHSA-8vfv-hc9g-64w9/GHSA-8vfv-hc9g-64w9.json +++ b/advisories/unreviewed/2022/05/GHSA-8vfv-hc9g-64w9/GHSA-8vfv-hc9g-64w9.json @@ -7,12 +7,8 @@ "CVE-2005-2005" ], "details": "Ultimate PHP Board (UPB) 1.9.6 GOLD and earlier stores the users.dat file under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information on registered users via a direct request to db/users.dat.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8x79-xcgh-ghvm/GHSA-8x79-xcgh-ghvm.json b/advisories/unreviewed/2022/05/GHSA-8x79-xcgh-ghvm/GHSA-8x79-xcgh-ghvm.json index 7d186a92cd1..9293c725122 100644 --- a/advisories/unreviewed/2022/05/GHSA-8x79-xcgh-ghvm/GHSA-8x79-xcgh-ghvm.json +++ b/advisories/unreviewed/2022/05/GHSA-8x79-xcgh-ghvm/GHSA-8x79-xcgh-ghvm.json @@ -7,12 +7,8 @@ "CVE-2021-38490" ], "details": "Altova MobileTogether Server before 7.3 SP1 allows XML exponential entity expansion, a different vulnerability than CVE-2021-37425.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8xv9-v9wx-p6j6/GHSA-8xv9-v9wx-p6j6.json b/advisories/unreviewed/2022/05/GHSA-8xv9-v9wx-p6j6/GHSA-8xv9-v9wx-p6j6.json index 71630866177..4c32c37172f 100644 --- a/advisories/unreviewed/2022/05/GHSA-8xv9-v9wx-p6j6/GHSA-8xv9-v9wx-p6j6.json +++ b/advisories/unreviewed/2022/05/GHSA-8xv9-v9wx-p6j6/GHSA-8xv9-v9wx-p6j6.json @@ -7,12 +7,8 @@ "CVE-2005-2296" ], "details": "YabbSE 1.5.5c allows remote attackers to obtain sensitive information via a direct request to ssi_examples.php, which reveals the path.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9277-v8gr-qjq4/GHSA-9277-v8gr-qjq4.json b/advisories/unreviewed/2022/05/GHSA-9277-v8gr-qjq4/GHSA-9277-v8gr-qjq4.json index 7721e69173b..2e6488e5358 100644 --- a/advisories/unreviewed/2022/05/GHSA-9277-v8gr-qjq4/GHSA-9277-v8gr-qjq4.json +++ b/advisories/unreviewed/2022/05/GHSA-9277-v8gr-qjq4/GHSA-9277-v8gr-qjq4.json @@ -7,12 +7,8 @@ "CVE-2005-2122" ], "details": "Windows Shell for Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote attackers to execute arbitrary commands via a shortcut (.lnk) file with long font properties that lead to a buffer overflow in the Client/Server Runtime Server Subsystem (CSRSS), a different vulnerability than CVE-2005-2118.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -84,9 +80,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-92cm-c6mv-gcx5/GHSA-92cm-c6mv-gcx5.json b/advisories/unreviewed/2022/05/GHSA-92cm-c6mv-gcx5/GHSA-92cm-c6mv-gcx5.json index c99e6b2ba32..b54120688b4 100644 --- a/advisories/unreviewed/2022/05/GHSA-92cm-c6mv-gcx5/GHSA-92cm-c6mv-gcx5.json +++ b/advisories/unreviewed/2022/05/GHSA-92cm-c6mv-gcx5/GHSA-92cm-c6mv-gcx5.json @@ -7,12 +7,8 @@ "CVE-2005-2165" ], "details": "read.cgi in GlobalNoteScript allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-92m4-g4mr-whg7/GHSA-92m4-g4mr-whg7.json b/advisories/unreviewed/2022/05/GHSA-92m4-g4mr-whg7/GHSA-92m4-g4mr-whg7.json index 585b2a01c1c..5ea7a7dae98 100644 --- a/advisories/unreviewed/2022/05/GHSA-92m4-g4mr-whg7/GHSA-92m4-g4mr-whg7.json +++ b/advisories/unreviewed/2022/05/GHSA-92m4-g4mr-whg7/GHSA-92m4-g4mr-whg7.json @@ -7,12 +7,8 @@ "CVE-2005-2001" ], "details": "Directory traversal vulnerability in pafiledb.php in paFileDB 3.1 and earlier allows remote attackers to include arbitrary files via a .. (dot dot) in the action parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-92x2-j38r-mm83/GHSA-92x2-j38r-mm83.json b/advisories/unreviewed/2022/05/GHSA-92x2-j38r-mm83/GHSA-92x2-j38r-mm83.json index 09e9c4f32cb..e011a11c157 100644 --- a/advisories/unreviewed/2022/05/GHSA-92x2-j38r-mm83/GHSA-92x2-j38r-mm83.json +++ b/advisories/unreviewed/2022/05/GHSA-92x2-j38r-mm83/GHSA-92x2-j38r-mm83.json @@ -7,12 +7,8 @@ "CVE-2005-1979" ], "details": "Distributed Transaction Controller in Microsoft Windows allows remote servers to cause a denial of service (MSDTC service exception and exit) via an \"unexpected protocol command during the reconnection request,\" which is not properly handled by the Transaction Internet Protocol (TIP) functionality.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -80,9 +76,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-95cm-jhq2-c7fg/GHSA-95cm-jhq2-c7fg.json b/advisories/unreviewed/2022/05/GHSA-95cm-jhq2-c7fg/GHSA-95cm-jhq2-c7fg.json index 60a78c59c85..62e354cab78 100644 --- a/advisories/unreviewed/2022/05/GHSA-95cm-jhq2-c7fg/GHSA-95cm-jhq2-c7fg.json +++ b/advisories/unreviewed/2022/05/GHSA-95cm-jhq2-c7fg/GHSA-95cm-jhq2-c7fg.json @@ -7,12 +7,8 @@ "CVE-2021-33199" ], "details": "In Expression Engine before 6.0.3, addonIcon in Addons/file/mod.file.php relies on the untrusted input value of input->get('file') instead of the fixed file names of icon.png and icon.svg.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-95gq-8mqg-648v/GHSA-95gq-8mqg-648v.json b/advisories/unreviewed/2022/05/GHSA-95gq-8mqg-648v/GHSA-95gq-8mqg-648v.json index b11fccd3429..8f13bbee2cd 100644 --- a/advisories/unreviewed/2022/05/GHSA-95gq-8mqg-648v/GHSA-95gq-8mqg-648v.json +++ b/advisories/unreviewed/2022/05/GHSA-95gq-8mqg-648v/GHSA-95gq-8mqg-648v.json @@ -7,12 +7,8 @@ "CVE-2005-2038" ], "details": "Fortibus CMS 4.0.0 allows remote attackers to modify information of other users, including Admin, via the \"My info\" page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-95r2-8mp6-63g7/GHSA-95r2-8mp6-63g7.json b/advisories/unreviewed/2022/05/GHSA-95r2-8mp6-63g7/GHSA-95r2-8mp6-63g7.json index faf7765e79a..7135c4266da 100644 --- a/advisories/unreviewed/2022/05/GHSA-95r2-8mp6-63g7/GHSA-95r2-8mp6-63g7.json +++ b/advisories/unreviewed/2022/05/GHSA-95r2-8mp6-63g7/GHSA-95r2-8mp6-63g7.json @@ -7,12 +7,8 @@ "CVE-2005-2070" ], "details": "The ClamAV Mail fILTER (clamav-milter) 0.84 through 0.85d, when used in Sendmail using long timeouts, allows remote attackers to cause a denial of service by keeping an open connection, which prevents ClamAV from reloading.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9646-qh5v-2ffc/GHSA-9646-qh5v-2ffc.json b/advisories/unreviewed/2022/05/GHSA-9646-qh5v-2ffc/GHSA-9646-qh5v-2ffc.json index ce0a5368623..45e66a9b305 100644 --- a/advisories/unreviewed/2022/05/GHSA-9646-qh5v-2ffc/GHSA-9646-qh5v-2ffc.json +++ b/advisories/unreviewed/2022/05/GHSA-9646-qh5v-2ffc/GHSA-9646-qh5v-2ffc.json @@ -7,12 +7,8 @@ "CVE-2020-21929" ], "details": "A stored cross site scripting (XSS) vulnerability in the web_copyright field of Eyoucms v1.4.1 allows authenticated attackers to execute arbitrary web scripts or HTML.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-96wg-fpj2-qvcg/GHSA-96wg-fpj2-qvcg.json b/advisories/unreviewed/2022/05/GHSA-96wg-fpj2-qvcg/GHSA-96wg-fpj2-qvcg.json index 7fa8afcecb3..af92329fa93 100644 --- a/advisories/unreviewed/2022/05/GHSA-96wg-fpj2-qvcg/GHSA-96wg-fpj2-qvcg.json +++ b/advisories/unreviewed/2022/05/GHSA-96wg-fpj2-qvcg/GHSA-96wg-fpj2-qvcg.json @@ -7,12 +7,8 @@ "CVE-2005-2226" ], "details": "Microsoft Outlook Express 6.0 leaks the default news server account when a user responds to a \"watched\" conversation thread, which could allow remote attackers to obtain sensitive information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-975m-vmx3-xq93/GHSA-975m-vmx3-xq93.json b/advisories/unreviewed/2022/05/GHSA-975m-vmx3-xq93/GHSA-975m-vmx3-xq93.json index 052fe192fdd..9bb862806e9 100644 --- a/advisories/unreviewed/2022/05/GHSA-975m-vmx3-xq93/GHSA-975m-vmx3-xq93.json +++ b/advisories/unreviewed/2022/05/GHSA-975m-vmx3-xq93/GHSA-975m-vmx3-xq93.json @@ -7,12 +7,8 @@ "CVE-2005-2311" ], "details": "SMS 1.9.2m and earlier allows local users to overwrite arbitrary files via a symlink attack on the (1) request1 or (2) request2 temporary files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-976x-h88h-fcf5/GHSA-976x-h88h-fcf5.json b/advisories/unreviewed/2022/05/GHSA-976x-h88h-fcf5/GHSA-976x-h88h-fcf5.json index 89d7776b45f..f8a0715faab 100644 --- a/advisories/unreviewed/2022/05/GHSA-976x-h88h-fcf5/GHSA-976x-h88h-fcf5.json +++ b/advisories/unreviewed/2022/05/GHSA-976x-h88h-fcf5/GHSA-976x-h88h-fcf5.json @@ -7,12 +7,8 @@ "CVE-2005-2325" ], "details": "Clever Copy 2.0 and 2.0a allows remote attackers to obtain the full path of the web root via a direct request to (1) ticker.php, (2) menu.php, (3) banned.php, (4) endlayout.php, (5) randomhlinesblock.php, (6) showlast.php, (7) showlast5class1.php, (8) showlast5phorum.php, (9) showlast5phorumblock.php, (10) showlastforumbb2.php, or (11) showlastforumbb2block.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9794-w9r7-gpfh/GHSA-9794-w9r7-gpfh.json b/advisories/unreviewed/2022/05/GHSA-9794-w9r7-gpfh/GHSA-9794-w9r7-gpfh.json index 9138b4dbfe5..96214e3043a 100644 --- a/advisories/unreviewed/2022/05/GHSA-9794-w9r7-gpfh/GHSA-9794-w9r7-gpfh.json +++ b/advisories/unreviewed/2022/05/GHSA-9794-w9r7-gpfh/GHSA-9794-w9r7-gpfh.json @@ -7,12 +7,8 @@ "CVE-2005-1983" ], "details": "Stack-based buffer overflow in the Plug and Play (PnP) service for Microsoft Windows 2000 and Windows XP Service Pack 1 allows remote attackers to execute arbitrary code via a crafted packet, and local users to gain privileges via a malicious application, as exploited by the Zotob (aka Mytob) worm.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -104,9 +100,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-98vw-9c74-q7qj/GHSA-98vw-9c74-q7qj.json b/advisories/unreviewed/2022/05/GHSA-98vw-9c74-q7qj/GHSA-98vw-9c74-q7qj.json index d20c6120749..f971ddc3df8 100644 --- a/advisories/unreviewed/2022/05/GHSA-98vw-9c74-q7qj/GHSA-98vw-9c74-q7qj.json +++ b/advisories/unreviewed/2022/05/GHSA-98vw-9c74-q7qj/GHSA-98vw-9c74-q7qj.json @@ -7,12 +7,8 @@ "CVE-2005-1997" ], "details": "show.php in McGallery 1.1 allows remote attackers to connect to arbitrary databases, or gain sensitive information by triggering an error, via a modified host parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9ch3-rm27-g282/GHSA-9ch3-rm27-g282.json b/advisories/unreviewed/2022/05/GHSA-9ch3-rm27-g282/GHSA-9ch3-rm27-g282.json index d2339fa22ca..cb4e34e2b20 100644 --- a/advisories/unreviewed/2022/05/GHSA-9ch3-rm27-g282/GHSA-9ch3-rm27-g282.json +++ b/advisories/unreviewed/2022/05/GHSA-9ch3-rm27-g282/GHSA-9ch3-rm27-g282.json @@ -7,12 +7,8 @@ "CVE-2005-2011" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in paFAQ 1.0 Beta 4 allow remote attackers to inject arbitrary web script or HTML, as demonstrated via the id parameter in a Question action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9crg-g7r6-784v/GHSA-9crg-g7r6-784v.json b/advisories/unreviewed/2022/05/GHSA-9crg-g7r6-784v/GHSA-9crg-g7r6-784v.json index 24c9e4e82ef..c013d1ceab2 100644 --- a/advisories/unreviewed/2022/05/GHSA-9crg-g7r6-784v/GHSA-9crg-g7r6-784v.json +++ b/advisories/unreviewed/2022/05/GHSA-9crg-g7r6-784v/GHSA-9crg-g7r6-784v.json @@ -7,12 +7,8 @@ "CVE-2021-33595" ], "details": "A address bar spoofing vulnerability was discovered in Safe Browser for iOS. Showing the legitimate URL in the address bar while loading the content from other domain. This makes the user believe that the content is served by a legit domain. A remote attacker can leverage this to perform address bar spoofing attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9fqh-jpcp-95fv/GHSA-9fqh-jpcp-95fv.json b/advisories/unreviewed/2022/05/GHSA-9fqh-jpcp-95fv/GHSA-9fqh-jpcp-95fv.json index b5f5454b0ba..e932e96defc 100644 --- a/advisories/unreviewed/2022/05/GHSA-9fqh-jpcp-95fv/GHSA-9fqh-jpcp-95fv.json +++ b/advisories/unreviewed/2022/05/GHSA-9fqh-jpcp-95fv/GHSA-9fqh-jpcp-95fv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9g4g-449x-h99g/GHSA-9g4g-449x-h99g.json b/advisories/unreviewed/2022/05/GHSA-9g4g-449x-h99g/GHSA-9g4g-449x-h99g.json index 0def59f6edc..05e7aec9e0b 100644 --- a/advisories/unreviewed/2022/05/GHSA-9g4g-449x-h99g/GHSA-9g4g-449x-h99g.json +++ b/advisories/unreviewed/2022/05/GHSA-9g4g-449x-h99g/GHSA-9g4g-449x-h99g.json @@ -7,12 +7,8 @@ "CVE-2021-3048" ], "details": "Certain invalid URL entries contained in an External Dynamic List (EDL) cause the Device Server daemon (devsrvr) to stop responding. This condition causes subsequent commits on the firewall to fail and prevents administrators from performing commits and configuration changes even though the firewall remains otherwise functional. If the firewall then restarts, it results in a denial-of-service (DoS) condition and the firewall stops processing traffic. This issue impacts: PAN-OS 9.0 versions earlier than PAN-OS 9.0.14; PAN-OS 9.1 versions earlier than PAN-OS 9.1.9; PAN-OS 10.0 versions earlier than PAN-OS 10.0.5. PAN-OS 8.1 and PAN-OS 10.1 versions are not impacted.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9g7g-grc6-f65g/GHSA-9g7g-grc6-f65g.json b/advisories/unreviewed/2022/05/GHSA-9g7g-grc6-f65g/GHSA-9g7g-grc6-f65g.json index a763c03800a..cf0ef26c349 100644 --- a/advisories/unreviewed/2022/05/GHSA-9g7g-grc6-f65g/GHSA-9g7g-grc6-f65g.json +++ b/advisories/unreviewed/2022/05/GHSA-9g7g-grc6-f65g/GHSA-9g7g-grc6-f65g.json @@ -7,12 +7,8 @@ "CVE-2005-2195" ], "details": "Apple Darwin Streaming Server 5.5 and earlier allows remote attackers to cause a denial of service (application crash) via a URL with a filename containing a .cgi extension and an MS-DOS device name such as AUX, CON, PRN, COM1, or LPT1, a different vulnerability than CVE-2003-0421 and CVE-2003-0502.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9hr8-4f6w-73f6/GHSA-9hr8-4f6w-73f6.json b/advisories/unreviewed/2022/05/GHSA-9hr8-4f6w-73f6/GHSA-9hr8-4f6w-73f6.json index 4a351dd1dab..8f3ca44cb8a 100644 --- a/advisories/unreviewed/2022/05/GHSA-9hr8-4f6w-73f6/GHSA-9hr8-4f6w-73f6.json +++ b/advisories/unreviewed/2022/05/GHSA-9hr8-4f6w-73f6/GHSA-9hr8-4f6w-73f6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9hrp-p3jf-w6mv/GHSA-9hrp-p3jf-w6mv.json b/advisories/unreviewed/2022/05/GHSA-9hrp-p3jf-w6mv/GHSA-9hrp-p3jf-w6mv.json index 0c2f55d3287..b6f327140ec 100644 --- a/advisories/unreviewed/2022/05/GHSA-9hrp-p3jf-w6mv/GHSA-9hrp-p3jf-w6mv.json +++ b/advisories/unreviewed/2022/05/GHSA-9hrp-p3jf-w6mv/GHSA-9hrp-p3jf-w6mv.json @@ -7,12 +7,8 @@ "CVE-2005-2071" ], "details": "traceroute in Sun Solaris 10 on x86 systems allows local users to execute arbitrary code with PRIV_NET_RAWACCESS privileges via (1) a large number of -g arguments or (2) a malformed -s argument with a trailing . (dot).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9hwp-rpp5-h296/GHSA-9hwp-rpp5-h296.json b/advisories/unreviewed/2022/05/GHSA-9hwp-rpp5-h296/GHSA-9hwp-rpp5-h296.json index d3185c58403..2b5cf1548d9 100644 --- a/advisories/unreviewed/2022/05/GHSA-9hwp-rpp5-h296/GHSA-9hwp-rpp5-h296.json +++ b/advisories/unreviewed/2022/05/GHSA-9hwp-rpp5-h296/GHSA-9hwp-rpp5-h296.json @@ -7,12 +7,8 @@ "CVE-2005-2086" ], "details": "PHP remote file inclusion vulnerability in viewtopic.php in phpBB 2.0.15 and earlier allows remote attackers to execute arbitrary PHP code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9hww-3h52-phxp/GHSA-9hww-3h52-phxp.json b/advisories/unreviewed/2022/05/GHSA-9hww-3h52-phxp/GHSA-9hww-3h52-phxp.json index ca6c3f9a13d..88103ec8987 100644 --- a/advisories/unreviewed/2022/05/GHSA-9hww-3h52-phxp/GHSA-9hww-3h52-phxp.json +++ b/advisories/unreviewed/2022/05/GHSA-9hww-3h52-phxp/GHSA-9hww-3h52-phxp.json @@ -7,12 +7,8 @@ "CVE-2021-35307" ], "details": "An issue was discovered in Bento4 through v1.6.0-636. A NULL pointer dereference exists in the AP4_DescriptorFinder::Test component located in /Core/Ap4Descriptor.h. It allows an attacker to cause a denial of service (DOS).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9j2g-v2pj-p54f/GHSA-9j2g-v2pj-p54f.json b/advisories/unreviewed/2022/05/GHSA-9j2g-v2pj-p54f/GHSA-9j2g-v2pj-p54f.json index ae25286299d..bc31fdab364 100644 --- a/advisories/unreviewed/2022/05/GHSA-9j2g-v2pj-p54f/GHSA-9j2g-v2pj-p54f.json +++ b/advisories/unreviewed/2022/05/GHSA-9j2g-v2pj-p54f/GHSA-9j2g-v2pj-p54f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9jxv-v2v3-cmwc/GHSA-9jxv-v2v3-cmwc.json b/advisories/unreviewed/2022/05/GHSA-9jxv-v2v3-cmwc/GHSA-9jxv-v2v3-cmwc.json index e4aec9496d1..d96bf8d3717 100644 --- a/advisories/unreviewed/2022/05/GHSA-9jxv-v2v3-cmwc/GHSA-9jxv-v2v3-cmwc.json +++ b/advisories/unreviewed/2022/05/GHSA-9jxv-v2v3-cmwc/GHSA-9jxv-v2v3-cmwc.json @@ -7,12 +7,8 @@ "CVE-2021-37367" ], "details": "CTparental before 4.45.07 is affected by a code execution vulnerability in the CTparental admin panel. Because The file \"bl_categories_help.php\" is vulnerable to directory traversal, an attacker can create a file that contains scripts and run arbitrary commands.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9q4j-627x-95w7/GHSA-9q4j-627x-95w7.json b/advisories/unreviewed/2022/05/GHSA-9q4j-627x-95w7/GHSA-9q4j-627x-95w7.json index 441a16dd746..fc59d0e1ad9 100644 --- a/advisories/unreviewed/2022/05/GHSA-9q4j-627x-95w7/GHSA-9q4j-627x-95w7.json +++ b/advisories/unreviewed/2022/05/GHSA-9q4j-627x-95w7/GHSA-9q4j-627x-95w7.json @@ -7,12 +7,8 @@ "CVE-2005-2058" ], "details": "Multiple SQL injection vulnerabilities in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to execute arbitrary SQL commands via the Number parameter to (1) download.php, (2) modifypost.php, (3) mailthread.php, or (4) notifymod.php, (5) month or (6) year parameter to calendar.php, (7) message parameter to viewmessage.php, (8) main parameter to addfav.php, or (9) posted parameter to grabnext.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9q57-c7wq-mf86/GHSA-9q57-c7wq-mf86.json b/advisories/unreviewed/2022/05/GHSA-9q57-c7wq-mf86/GHSA-9q57-c7wq-mf86.json index 8f46676fd19..6a1d57fc2ab 100644 --- a/advisories/unreviewed/2022/05/GHSA-9q57-c7wq-mf86/GHSA-9q57-c7wq-mf86.json +++ b/advisories/unreviewed/2022/05/GHSA-9q57-c7wq-mf86/GHSA-9q57-c7wq-mf86.json @@ -7,12 +7,8 @@ "CVE-2005-2316" ], "details": "Domain Name Relay Daemon (DNRD) before 2.19.1 allows remote attackers to cause a denial of service (infinite recursion) via a DNS packet that uses message compression in the QNAME and two pointers that point to each other (circular buffer).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9qmx-57jw-hm4c/GHSA-9qmx-57jw-hm4c.json b/advisories/unreviewed/2022/05/GHSA-9qmx-57jw-hm4c/GHSA-9qmx-57jw-hm4c.json index 6e787c8eaa1..8026eef332e 100644 --- a/advisories/unreviewed/2022/05/GHSA-9qmx-57jw-hm4c/GHSA-9qmx-57jw-hm4c.json +++ b/advisories/unreviewed/2022/05/GHSA-9qmx-57jw-hm4c/GHSA-9qmx-57jw-hm4c.json @@ -7,12 +7,8 @@ "CVE-2005-2289" ], "details": "PHPCounter 7.2 allows remote attackers to obtain sensitive information via a direct request to prelims.php, which reveals the path in an error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9v8g-v94x-q7jp/GHSA-9v8g-v94x-q7jp.json b/advisories/unreviewed/2022/05/GHSA-9v8g-v94x-q7jp/GHSA-9v8g-v94x-q7jp.json index 7533bbf00fd..698a80f14a6 100644 --- a/advisories/unreviewed/2022/05/GHSA-9v8g-v94x-q7jp/GHSA-9v8g-v94x-q7jp.json +++ b/advisories/unreviewed/2022/05/GHSA-9v8g-v94x-q7jp/GHSA-9v8g-v94x-q7jp.json @@ -7,12 +7,8 @@ "CVE-2005-2318" ], "details": "Cross-site scripting (XSS) vulnerability in showerr.asp in DVBBS 7.1 SP2 allows remote attackers to inject arbitrary web script or HTML via the action parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9vmm-wmjj-7h4g/GHSA-9vmm-wmjj-7h4g.json b/advisories/unreviewed/2022/05/GHSA-9vmm-wmjj-7h4g/GHSA-9vmm-wmjj-7h4g.json index 5e4516ca048..abe6de7448b 100644 --- a/advisories/unreviewed/2022/05/GHSA-9vmm-wmjj-7h4g/GHSA-9vmm-wmjj-7h4g.json +++ b/advisories/unreviewed/2022/05/GHSA-9vmm-wmjj-7h4g/GHSA-9vmm-wmjj-7h4g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9vw3-3p2j-mww8/GHSA-9vw3-3p2j-mww8.json b/advisories/unreviewed/2022/05/GHSA-9vw3-3p2j-mww8/GHSA-9vw3-3p2j-mww8.json index d82bb9cbfe8..6e1940741d7 100644 --- a/advisories/unreviewed/2022/05/GHSA-9vw3-3p2j-mww8/GHSA-9vw3-3p2j-mww8.json +++ b/advisories/unreviewed/2022/05/GHSA-9vw3-3p2j-mww8/GHSA-9vw3-3p2j-mww8.json @@ -7,12 +7,8 @@ "CVE-2005-2205" ], "details": "The ReadLog function in kaiseki.cgi in pngren allows remote attackers to execute arbitrary commands via shell metacharacters in the query string.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9wwc-x3wq-537q/GHSA-9wwc-x3wq-537q.json b/advisories/unreviewed/2022/05/GHSA-9wwc-x3wq-537q/GHSA-9wwc-x3wq-537q.json index e6a91e34701..356f6770361 100644 --- a/advisories/unreviewed/2022/05/GHSA-9wwc-x3wq-537q/GHSA-9wwc-x3wq-537q.json +++ b/advisories/unreviewed/2022/05/GHSA-9wwc-x3wq-537q/GHSA-9wwc-x3wq-537q.json @@ -7,12 +7,8 @@ "CVE-2005-2280" ], "details": "Cisco Security Agent (CSA) 4.5 allows remote attackers to cause a denial of service (system crash) via a crafted IP packet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c2jx-4wpj-p7f6/GHSA-c2jx-4wpj-p7f6.json b/advisories/unreviewed/2022/05/GHSA-c2jx-4wpj-p7f6/GHSA-c2jx-4wpj-p7f6.json index d68760f93b2..e28587e6aac 100644 --- a/advisories/unreviewed/2022/05/GHSA-c2jx-4wpj-p7f6/GHSA-c2jx-4wpj-p7f6.json +++ b/advisories/unreviewed/2022/05/GHSA-c2jx-4wpj-p7f6/GHSA-c2jx-4wpj-p7f6.json @@ -7,12 +7,8 @@ "CVE-2005-2202" ], "details": "Cross-site scripting (XSS) vulnerability in the MicroServer Web Server for Xerox WorkCentre Pro Color 2128, 2636, and 3545, version 0.001.04.044 through 0.001.04.504, allows remote attackers to inject arbitrary web script or HTML via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c38r-j6hj-cp53/GHSA-c38r-j6hj-cp53.json b/advisories/unreviewed/2022/05/GHSA-c38r-j6hj-cp53/GHSA-c38r-j6hj-cp53.json index e313a33b8e7..0a281ac0bee 100644 --- a/advisories/unreviewed/2022/05/GHSA-c38r-j6hj-cp53/GHSA-c38r-j6hj-cp53.json +++ b/advisories/unreviewed/2022/05/GHSA-c38r-j6hj-cp53/GHSA-c38r-j6hj-cp53.json @@ -7,12 +7,8 @@ "CVE-2005-2045" ], "details": "Multiple SQL injection vulnerabilities in DUware DUportal PRO 3.4.3 allow remote attackers to execute arbitrary SQL commands via the (1) iChannel parameter to default.asp, (2) iData parameter to detail.asp, (3) iMem parameter to members.asp, (4) iCat parameter to cat.asp, (5) offset parameter to members_listing_approval.asp, or (6) iChannel parameter to channels_edit.asp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c3qc-rxmw-c875/GHSA-c3qc-rxmw-c875.json b/advisories/unreviewed/2022/05/GHSA-c3qc-rxmw-c875/GHSA-c3qc-rxmw-c875.json index a0fd01caab9..dc2bcb6d260 100644 --- a/advisories/unreviewed/2022/05/GHSA-c3qc-rxmw-c875/GHSA-c3qc-rxmw-c875.json +++ b/advisories/unreviewed/2022/05/GHSA-c3qc-rxmw-c875/GHSA-c3qc-rxmw-c875.json @@ -7,12 +7,8 @@ "CVE-2005-2287" ], "details": "SoftiaCom wMailServer 1.0 and 2.0 allows remote attackers to cause a denial of service (application crash) via a large TCP packet with a leading space, possibly triggering a buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c3qr-cx32-288c/GHSA-c3qr-cx32-288c.json b/advisories/unreviewed/2022/05/GHSA-c3qr-cx32-288c/GHSA-c3qr-cx32-288c.json index cbddd02acb7..dff57229427 100644 --- a/advisories/unreviewed/2022/05/GHSA-c3qr-cx32-288c/GHSA-c3qr-cx32-288c.json +++ b/advisories/unreviewed/2022/05/GHSA-c3qr-cx32-288c/GHSA-c3qr-cx32-288c.json @@ -7,12 +7,8 @@ "CVE-2020-25082" ], "details": "An attacker with physical access to Nuvoton Trusted Platform Module (NPCT75x 7.2.x before 7.2.2.0) could extract an Elliptic Curve Cryptography (ECC) private key via a side-channel attack against ECDSA, because of an Observable Timing Discrepancy.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c448-9mp8-6cgc/GHSA-c448-9mp8-6cgc.json b/advisories/unreviewed/2022/05/GHSA-c448-9mp8-6cgc/GHSA-c448-9mp8-6cgc.json index a8e3bbc85b0..15b664e2220 100644 --- a/advisories/unreviewed/2022/05/GHSA-c448-9mp8-6cgc/GHSA-c448-9mp8-6cgc.json +++ b/advisories/unreviewed/2022/05/GHSA-c448-9mp8-6cgc/GHSA-c448-9mp8-6cgc.json @@ -7,12 +7,8 @@ "CVE-2005-2044" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in ATutor 1.4.3 and 1.5 RC 1 allow remote attackers to inject arbitrary web script or HTML via the (1) show_course parameter to browse.php, (2) subject parameter to contact.php, (3) cid parameter to content.php, (4) l parameter to inbox/send_message.php, the (5) search, (6) words, (7) include, (8) find_in, (9) display_as, or (10) search parameter to search.php, the (11) submit, (12) query, or (13) field parameter to tile.php, the (14) us parameter to forum/subscribe_forum.php, or the (15) roles[], (16) status, (17) submit, or (18) reset_filter parameters to directory.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c49h-jv3f-mrwc/GHSA-c49h-jv3f-mrwc.json b/advisories/unreviewed/2022/05/GHSA-c49h-jv3f-mrwc/GHSA-c49h-jv3f-mrwc.json index 2d722ffc538..d05dbaeae67 100644 --- a/advisories/unreviewed/2022/05/GHSA-c49h-jv3f-mrwc/GHSA-c49h-jv3f-mrwc.json +++ b/advisories/unreviewed/2022/05/GHSA-c49h-jv3f-mrwc/GHSA-c49h-jv3f-mrwc.json @@ -7,12 +7,8 @@ "CVE-2021-21598" ], "details": "Dell Wyse ThinOS, versions 9.0, 9.1, and 9.1 MR1, contain a Sensitive Information Disclosure Vulnerability. An authenticated attacker with physical access to the system could exploit this vulnerability to read sensitive Smartcard data in log files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c4pq-7f26-f57v/GHSA-c4pq-7f26-f57v.json b/advisories/unreviewed/2022/05/GHSA-c4pq-7f26-f57v/GHSA-c4pq-7f26-f57v.json index 4d86462506c..cfec4f55ae6 100644 --- a/advisories/unreviewed/2022/05/GHSA-c4pq-7f26-f57v/GHSA-c4pq-7f26-f57v.json +++ b/advisories/unreviewed/2022/05/GHSA-c4pq-7f26-f57v/GHSA-c4pq-7f26-f57v.json @@ -7,12 +7,8 @@ "CVE-2005-2120" ], "details": "Stack-based buffer overflow in the Plug and Play (PnP) service (UMPNPMGR.DLL) in Microsoft Windows 2000 SP4, and XP SP1 and SP2, allows remote or local authenticated attackers to execute arbitrary code via a large number of \"\\\" (backslash) characters in a registry key name, which triggers the overflow in a wsprintfW function call.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -80,9 +76,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c5q5-p78r-jpgv/GHSA-c5q5-p78r-jpgv.json b/advisories/unreviewed/2022/05/GHSA-c5q5-p78r-jpgv/GHSA-c5q5-p78r-jpgv.json index 15a5e08a111..7cfbe27d6cf 100644 --- a/advisories/unreviewed/2022/05/GHSA-c5q5-p78r-jpgv/GHSA-c5q5-p78r-jpgv.json +++ b/advisories/unreviewed/2022/05/GHSA-c5q5-p78r-jpgv/GHSA-c5q5-p78r-jpgv.json @@ -7,12 +7,8 @@ "CVE-2021-38535" ], "details": "Certain NETGEAR devices are affected by stored XSS. This affects D6200 before 1.1.00.40, D7000 before 1.0.1.78, R6020 before 1.0.0.48, R6080 before 1.0.0.48, R6120 before 1.0.0.76, R6260 before 1.1.0.78, R6700v2 before 1.2.0.76, R6800 before 1.2.0.76, R6900v2 before 1.2.0.76, R6850 before 1.1.0.78, R7200 before 1.2.0.76, R7350 before 1.2.0.76, R7400 before 1.2.0.76, R7450 before 1.2.0.76, AC2100 before 1.2.0.76, AC2400 before 1.2.0.76, AC2600 before 1.2.0.76, RAX35 before 1.0.3.62, and RAX40 before 1.0.3.62.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c5x3-p9mj-9gv6/GHSA-c5x3-p9mj-9gv6.json b/advisories/unreviewed/2022/05/GHSA-c5x3-p9mj-9gv6/GHSA-c5x3-p9mj-9gv6.json index 6c38a8e096b..7de6e84562f 100644 --- a/advisories/unreviewed/2022/05/GHSA-c5x3-p9mj-9gv6/GHSA-c5x3-p9mj-9gv6.json +++ b/advisories/unreviewed/2022/05/GHSA-c5x3-p9mj-9gv6/GHSA-c5x3-p9mj-9gv6.json @@ -7,12 +7,8 @@ "CVE-2021-21597" ], "details": "Dell Wyse ThinOS, version 9.0, contains a Sensitive Information Disclosure Vulnerability. An authenticated malicious user with physical access to the system could exploit this vulnerability to read sensitive information written to the log files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c69q-mgj9-mpv4/GHSA-c69q-mgj9-mpv4.json b/advisories/unreviewed/2022/05/GHSA-c69q-mgj9-mpv4/GHSA-c69q-mgj9-mpv4.json index 856add67aca..18c7ca11d9a 100644 --- a/advisories/unreviewed/2022/05/GHSA-c69q-mgj9-mpv4/GHSA-c69q-mgj9-mpv4.json +++ b/advisories/unreviewed/2022/05/GHSA-c69q-mgj9-mpv4/GHSA-c69q-mgj9-mpv4.json @@ -7,12 +7,8 @@ "CVE-2021-36601" ], "details": "GetSimpleCMS 3.3.16 contains a cross-site Scripting (XSS) vulnerability, where Function TSL does not filter check settings.php Website URL: \"siteURL\" parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c73h-35x4-2493/GHSA-c73h-35x4-2493.json b/advisories/unreviewed/2022/05/GHSA-c73h-35x4-2493/GHSA-c73h-35x4-2493.json index d31bff11d73..d03a36fff6b 100644 --- a/advisories/unreviewed/2022/05/GHSA-c73h-35x4-2493/GHSA-c73h-35x4-2493.json +++ b/advisories/unreviewed/2022/05/GHSA-c73h-35x4-2493/GHSA-c73h-35x4-2493.json @@ -7,12 +7,8 @@ "CVE-2021-38365" ], "details": "Winner (aka ToneWinner) desktop speakers through 2021-08-09 allow remote attackers to recover speech signals from the power-indicator LED via a telescope and an electro-optical sensor, aka a \"Glowworm\" attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c774-q263-4qv6/GHSA-c774-q263-4qv6.json b/advisories/unreviewed/2022/05/GHSA-c774-q263-4qv6/GHSA-c774-q263-4qv6.json index b54abad8f2e..476e9b67d58 100644 --- a/advisories/unreviewed/2022/05/GHSA-c774-q263-4qv6/GHSA-c774-q263-4qv6.json +++ b/advisories/unreviewed/2022/05/GHSA-c774-q263-4qv6/GHSA-c774-q263-4qv6.json @@ -7,12 +7,8 @@ "CVE-2021-33403" ], "details": "An integer overflow in the transfer function of a smart contract implementation for Lancer Token, an Ethereum ERC20 token, allows the owner to cause unexpected financial losses between two large accounts during a transaction.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c7q8-wf85-wcvw/GHSA-c7q8-wf85-wcvw.json b/advisories/unreviewed/2022/05/GHSA-c7q8-wf85-wcvw/GHSA-c7q8-wf85-wcvw.json index d64dd6d2b4f..fb7a242c6df 100644 --- a/advisories/unreviewed/2022/05/GHSA-c7q8-wf85-wcvw/GHSA-c7q8-wf85-wcvw.json +++ b/advisories/unreviewed/2022/05/GHSA-c7q8-wf85-wcvw/GHSA-c7q8-wf85-wcvw.json @@ -7,12 +7,8 @@ "CVE-2021-33794" ], "details": "Foxit Reader before 10.1.4 and PhantomPDF before 10.1.4 allow information disclosure or an application crash after mishandling the Tab key during XFA form interaction.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c86q-px74-v8w3/GHSA-c86q-px74-v8w3.json b/advisories/unreviewed/2022/05/GHSA-c86q-px74-v8w3/GHSA-c86q-px74-v8w3.json index ce5ca400e0a..89c33b2ce97 100644 --- a/advisories/unreviewed/2022/05/GHSA-c86q-px74-v8w3/GHSA-c86q-px74-v8w3.json +++ b/advisories/unreviewed/2022/05/GHSA-c86q-px74-v8w3/GHSA-c86q-px74-v8w3.json @@ -7,12 +7,8 @@ "CVE-2005-2022" ], "details": "Unknown vulnerability in Webmail in iPlanet Messaging Server 5.2 Patch 1 and Sun ONE Messaging Server 6.2 allows remote attackers to execute arbitrary Javascript, possibly due to a cross-site scripting (XSS) vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cc43-2hj7-x446/GHSA-cc43-2hj7-x446.json b/advisories/unreviewed/2022/05/GHSA-cc43-2hj7-x446/GHSA-cc43-2hj7-x446.json index 1e08470571b..f82f4e55d2e 100644 --- a/advisories/unreviewed/2022/05/GHSA-cc43-2hj7-x446/GHSA-cc43-2hj7-x446.json +++ b/advisories/unreviewed/2022/05/GHSA-cc43-2hj7-x446/GHSA-cc43-2hj7-x446.json @@ -7,12 +7,8 @@ "CVE-2021-38529" ], "details": "Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D7800 before 1.0.1.56, R7800 before 1.0.2.68, R8900 before 1.0.4.26, and R9000 before 1.0.4.26.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cc54-98gr-63gg/GHSA-cc54-98gr-63gg.json b/advisories/unreviewed/2022/05/GHSA-cc54-98gr-63gg/GHSA-cc54-98gr-63gg.json index a52638b61cb..11537c469f8 100644 --- a/advisories/unreviewed/2022/05/GHSA-cc54-98gr-63gg/GHSA-cc54-98gr-63gg.json +++ b/advisories/unreviewed/2022/05/GHSA-cc54-98gr-63gg/GHSA-cc54-98gr-63gg.json @@ -7,12 +7,8 @@ "CVE-2005-1996" ], "details": "PHP remote file inclusion vulnerability in start.php in Bitrix Site Manager 4.0.x allows remote attackers to execute arbitrary PHP code via the _SERVER[DOCUMENT_ROOT] parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ccf7-wjfg-qw67/GHSA-ccf7-wjfg-qw67.json b/advisories/unreviewed/2022/05/GHSA-ccf7-wjfg-qw67/GHSA-ccf7-wjfg-qw67.json index 5dc997c8cd9..13b92ef3ac4 100644 --- a/advisories/unreviewed/2022/05/GHSA-ccf7-wjfg-qw67/GHSA-ccf7-wjfg-qw67.json +++ b/advisories/unreviewed/2022/05/GHSA-ccf7-wjfg-qw67/GHSA-ccf7-wjfg-qw67.json @@ -7,12 +7,8 @@ "CVE-2021-38522" ], "details": "NETGEAR R6400 devices before 1.0.1.52 are affected by a stack-based buffer overflow by an authenticated user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cf42-v5r9-fg8j/GHSA-cf42-v5r9-fg8j.json b/advisories/unreviewed/2022/05/GHSA-cf42-v5r9-fg8j/GHSA-cf42-v5r9-fg8j.json index 169fa475301..238a3c0a491 100644 --- a/advisories/unreviewed/2022/05/GHSA-cf42-v5r9-fg8j/GHSA-cf42-v5r9-fg8j.json +++ b/advisories/unreviewed/2022/05/GHSA-cf42-v5r9-fg8j/GHSA-cf42-v5r9-fg8j.json @@ -7,12 +7,8 @@ "CVE-2005-2193" ], "details": "SQL injection vulnerability in the user profile edit module in profile.php for PunBB 1.2.5 and earlier allows remote attackers to execute arbitrary SQL statements via the temp array, which is not initialized before it is used and prevents the attacker-supplied portions of the array from being properly escaped.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cf6x-xwjf-hfh7/GHSA-cf6x-xwjf-hfh7.json b/advisories/unreviewed/2022/05/GHSA-cf6x-xwjf-hfh7/GHSA-cf6x-xwjf-hfh7.json index cdb61444bb8..80aba41b613 100644 --- a/advisories/unreviewed/2022/05/GHSA-cf6x-xwjf-hfh7/GHSA-cf6x-xwjf-hfh7.json +++ b/advisories/unreviewed/2022/05/GHSA-cf6x-xwjf-hfh7/GHSA-cf6x-xwjf-hfh7.json @@ -7,12 +7,8 @@ "CVE-2005-1966" ], "details": "The eTrace_validaddr function in eTrace plugin for e107 portal allows remote attackers to execute arbitrary commands via shell metacharacters after a valid argument to the etrace_host parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cfm8-ggjg-q9mj/GHSA-cfm8-ggjg-q9mj.json b/advisories/unreviewed/2022/05/GHSA-cfm8-ggjg-q9mj/GHSA-cfm8-ggjg-q9mj.json index 57adfd900af..4ad8d5b7e7a 100644 --- a/advisories/unreviewed/2022/05/GHSA-cfm8-ggjg-q9mj/GHSA-cfm8-ggjg-q9mj.json +++ b/advisories/unreviewed/2022/05/GHSA-cfm8-ggjg-q9mj/GHSA-cfm8-ggjg-q9mj.json @@ -7,12 +7,8 @@ "CVE-2021-32590" ], "details": "Multiple improper neutralization of special elements used in an SQL command vulnerabilities in FortiPortal 6.0.0 through 6.0.4, 5.3.0 through 5.3.5, 5.2.0 through 5.2.5, and 4.2.2 and earlier may allow an attacker with regular user's privileges to execute arbitrary commands on the underlying SQL database via specifically crafted HTTP requests.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cgwp-53w9-wx8r/GHSA-cgwp-53w9-wx8r.json b/advisories/unreviewed/2022/05/GHSA-cgwp-53w9-wx8r/GHSA-cgwp-53w9-wx8r.json index d473470b1f0..6e5c526f64a 100644 --- a/advisories/unreviewed/2022/05/GHSA-cgwp-53w9-wx8r/GHSA-cgwp-53w9-wx8r.json +++ b/advisories/unreviewed/2022/05/GHSA-cgwp-53w9-wx8r/GHSA-cgwp-53w9-wx8r.json @@ -7,12 +7,8 @@ "CVE-2005-2271" ], "details": "iCab 2.9.8 does not clearly associate a Javascript dialog box with the web page that generated it, which allows remote attackers to spoof a dialog box from a trusted site and facilitates phishing attacks, aka the \"Dialog Origin Spoofing Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-chv5-257q-w5jx/GHSA-chv5-257q-w5jx.json b/advisories/unreviewed/2022/05/GHSA-chv5-257q-w5jx/GHSA-chv5-257q-w5jx.json index 818204c82e7..3c9b7975a8c 100644 --- a/advisories/unreviewed/2022/05/GHSA-chv5-257q-w5jx/GHSA-chv5-257q-w5jx.json +++ b/advisories/unreviewed/2022/05/GHSA-chv5-257q-w5jx/GHSA-chv5-257q-w5jx.json @@ -7,12 +7,8 @@ "CVE-2021-24505" ], "details": "The Forms WordPress plugin before 1.12.3 did not sanitise its input fields, leading to Stored Cross-Site scripting issues. The plugin was vulnerable to an Authenticated Stored Cross-Site Scripting (XSS) vulnerability within the Forms \"Add new\" field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cj9w-4xvw-x6fp/GHSA-cj9w-4xvw-x6fp.json b/advisories/unreviewed/2022/05/GHSA-cj9w-4xvw-x6fp/GHSA-cj9w-4xvw-x6fp.json index fe6b7363081..dc8b5794699 100644 --- a/advisories/unreviewed/2022/05/GHSA-cj9w-4xvw-x6fp/GHSA-cj9w-4xvw-x6fp.json +++ b/advisories/unreviewed/2022/05/GHSA-cj9w-4xvw-x6fp/GHSA-cj9w-4xvw-x6fp.json @@ -7,12 +7,8 @@ "CVE-2005-1874" ], "details": "Directory traversal vulnerability in Dzip before 2.9 allows remote attackers to create arbitrary files via a filename containing a .. (dot dot) in a .dz archive.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cjfj-chgf-fcwf/GHSA-cjfj-chgf-fcwf.json b/advisories/unreviewed/2022/05/GHSA-cjfj-chgf-fcwf/GHSA-cjfj-chgf-fcwf.json index 09f0783516d..2647e70fe40 100644 --- a/advisories/unreviewed/2022/05/GHSA-cjfj-chgf-fcwf/GHSA-cjfj-chgf-fcwf.json +++ b/advisories/unreviewed/2022/05/GHSA-cjfj-chgf-fcwf/GHSA-cjfj-chgf-fcwf.json @@ -7,12 +7,8 @@ "CVE-2005-1949" ], "details": "The eping_validaddr function in functions.php for the ePing plugin for e107 portal allows remote attackers to execute arbitrary commands via shell metacharacters after a valid argument to the eping_host parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cjjh-pf8g-r49f/GHSA-cjjh-pf8g-r49f.json b/advisories/unreviewed/2022/05/GHSA-cjjh-pf8g-r49f/GHSA-cjjh-pf8g-r49f.json index b6fee82e354..36ff31aa7ac 100644 --- a/advisories/unreviewed/2022/05/GHSA-cjjh-pf8g-r49f/GHSA-cjjh-pf8g-r49f.json +++ b/advisories/unreviewed/2022/05/GHSA-cjjh-pf8g-r49f/GHSA-cjjh-pf8g-r49f.json @@ -7,12 +7,8 @@ "CVE-2005-2283" ], "details": "WebEOC before 6.0.2 does not properly restrict the size of an uploaded file, which allows remote authenticated users to cause a denial of service (system and database resource consumption) via a large file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cm49-f24p-g723/GHSA-cm49-f24p-g723.json b/advisories/unreviewed/2022/05/GHSA-cm49-f24p-g723/GHSA-cm49-f24p-g723.json index 5218ea33bd1..5fde8e1bc93 100644 --- a/advisories/unreviewed/2022/05/GHSA-cm49-f24p-g723/GHSA-cm49-f24p-g723.json +++ b/advisories/unreviewed/2022/05/GHSA-cm49-f24p-g723/GHSA-cm49-f24p-g723.json @@ -7,12 +7,8 @@ "CVE-2005-2065" ], "details": "HTTP response splitting vulnerability in language_select.asp in ASP Nuke 0.80 allows remote attackers to spoof web content and poison web caches via CRLF (\"%0d%0a\") sequences in the LangCode parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cp6r-6r55-g22c/GHSA-cp6r-6r55-g22c.json b/advisories/unreviewed/2022/05/GHSA-cp6r-6r55-g22c/GHSA-cp6r-6r55-g22c.json index 18e9dc9d0f9..49d6f12b673 100644 --- a/advisories/unreviewed/2022/05/GHSA-cp6r-6r55-g22c/GHSA-cp6r-6r55-g22c.json +++ b/advisories/unreviewed/2022/05/GHSA-cp6r-6r55-g22c/GHSA-cp6r-6r55-g22c.json @@ -7,12 +7,8 @@ "CVE-2005-2194" ], "details": "Unspecified vulnerability in the Apple Mac OS X kernel before 10.4.2 allows remote attackers to cause a denial of service (kernel panic) via a crafted TCP packet, possibly related to source routing or loose source routing.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cq7c-xqh4-2wgw/GHSA-cq7c-xqh4-2wgw.json b/advisories/unreviewed/2022/05/GHSA-cq7c-xqh4-2wgw/GHSA-cq7c-xqh4-2wgw.json index 1bf46039782..652afbc9bc4 100644 --- a/advisories/unreviewed/2022/05/GHSA-cq7c-xqh4-2wgw/GHSA-cq7c-xqh4-2wgw.json +++ b/advisories/unreviewed/2022/05/GHSA-cq7c-xqh4-2wgw/GHSA-cq7c-xqh4-2wgw.json @@ -7,12 +7,8 @@ "CVE-2005-1961" ], "details": "Unknown vulnerability in ObjectWeb Consortium C-JDBC before 1.3.1 allows local users to bypass intended access restrictions and obtain the cache results from another user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cqf2-qf4h-jgpj/GHSA-cqf2-qf4h-jgpj.json b/advisories/unreviewed/2022/05/GHSA-cqf2-qf4h-jgpj/GHSA-cqf2-qf4h-jgpj.json index 37ea98bdd44..e50d7201d2f 100644 --- a/advisories/unreviewed/2022/05/GHSA-cqf2-qf4h-jgpj/GHSA-cqf2-qf4h-jgpj.json +++ b/advisories/unreviewed/2022/05/GHSA-cqf2-qf4h-jgpj/GHSA-cqf2-qf4h-jgpj.json @@ -7,12 +7,8 @@ "CVE-2021-37366" ], "details": "CTparental before 4.45.03 is vulnerable to cross-site request forgery (CSRF) in the CTparental admin panel. By combining CSRF with XSS, an attacker can trick the administrator into clicking a link that cancels the filtering for all standard users.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cqhx-q2jc-7rj5/GHSA-cqhx-q2jc-7rj5.json b/advisories/unreviewed/2022/05/GHSA-cqhx-q2jc-7rj5/GHSA-cqhx-q2jc-7rj5.json index 940b033bd5a..4b45525f99f 100644 --- a/advisories/unreviewed/2022/05/GHSA-cqhx-q2jc-7rj5/GHSA-cqhx-q2jc-7rj5.json +++ b/advisories/unreviewed/2022/05/GHSA-cqhx-q2jc-7rj5/GHSA-cqhx-q2jc-7rj5.json @@ -7,12 +7,8 @@ "CVE-2005-2177" ], "details": "Net-SNMP 5.0.x before 5.0.10.2, 5.2.x before 5.2.1.2, and 5.1.3, when net-snmp is using stream sockets such as TCP, allows remote attackers to cause a denial of service (daemon hang and CPU consumption) via a TCP packet of length 1, which triggers an infinite loop.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cqpx-grv2-8p3h/GHSA-cqpx-grv2-8p3h.json b/advisories/unreviewed/2022/05/GHSA-cqpx-grv2-8p3h/GHSA-cqpx-grv2-8p3h.json index 17fd57d4353..a6ee0243449 100644 --- a/advisories/unreviewed/2022/05/GHSA-cqpx-grv2-8p3h/GHSA-cqpx-grv2-8p3h.json +++ b/advisories/unreviewed/2022/05/GHSA-cqpx-grv2-8p3h/GHSA-cqpx-grv2-8p3h.json @@ -7,12 +7,8 @@ "CVE-2005-2148" ], "details": "Cacti 0.8.6e and earlier does not perform proper input validation to protect against common attacks, which allows remote attackers to execute arbitrary commands or SQL by sending a legitimate value in a POST request or cookie, then specifying the attack string in the URL, which causes the get_request_var function to return the wrong value in the $_REQUEST variable, which is cleansed while the original malicious $_GET value remains unmodified, as demonstrated in (1) graph_image.php and (2) graph.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -76,9 +72,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cqrq-3x4q-gjcp/GHSA-cqrq-3x4q-gjcp.json b/advisories/unreviewed/2022/05/GHSA-cqrq-3x4q-gjcp/GHSA-cqrq-3x4q-gjcp.json index 91f24003ba4..d48dd307694 100644 --- a/advisories/unreviewed/2022/05/GHSA-cqrq-3x4q-gjcp/GHSA-cqrq-3x4q-gjcp.json +++ b/advisories/unreviewed/2022/05/GHSA-cqrq-3x4q-gjcp/GHSA-cqrq-3x4q-gjcp.json @@ -7,12 +7,8 @@ "CVE-2005-2010" ], "details": "Cross-site scripting (XSS) vulnerability in trackback.asp in Ublog Reload 1.0.5 allows remote attackers to inject arbitrary web script or HTML via the btitle parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cr2f-3p35-224p/GHSA-cr2f-3p35-224p.json b/advisories/unreviewed/2022/05/GHSA-cr2f-3p35-224p/GHSA-cr2f-3p35-224p.json index a6d59fd1c2e..bebf797f8cd 100644 --- a/advisories/unreviewed/2022/05/GHSA-cr2f-3p35-224p/GHSA-cr2f-3p35-224p.json +++ b/advisories/unreviewed/2022/05/GHSA-cr2f-3p35-224p/GHSA-cr2f-3p35-224p.json @@ -7,12 +7,8 @@ "CVE-2005-1865" ], "details": "Multiple SQL injection vulnerabilities in Calendarix Advanced 1.5 allow remote attackers to execute arbitrary SQL commands via the catview parameter to (1) cal_week.php, (2) cal_cat.php, or (3) cal_day.php, or (4) id parameter to cal_pophols.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cx7x-p2rh-c2m2/GHSA-cx7x-p2rh-c2m2.json b/advisories/unreviewed/2022/05/GHSA-cx7x-p2rh-c2m2/GHSA-cx7x-p2rh-c2m2.json index 6e16b086582..7a4c332d45c 100644 --- a/advisories/unreviewed/2022/05/GHSA-cx7x-p2rh-c2m2/GHSA-cx7x-p2rh-c2m2.json +++ b/advisories/unreviewed/2022/05/GHSA-cx7x-p2rh-c2m2/GHSA-cx7x-p2rh-c2m2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cxw5-72vp-8h54/GHSA-cxw5-72vp-8h54.json b/advisories/unreviewed/2022/05/GHSA-cxw5-72vp-8h54/GHSA-cxw5-72vp-8h54.json index d8a88c42be0..78a05679ff7 100644 --- a/advisories/unreviewed/2022/05/GHSA-cxw5-72vp-8h54/GHSA-cxw5-72vp-8h54.json +++ b/advisories/unreviewed/2022/05/GHSA-cxw5-72vp-8h54/GHSA-cxw5-72vp-8h54.json @@ -7,12 +7,8 @@ "CVE-2005-2269" ], "details": "Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 does not properly verify the associated types of DOM node names within the context of their namespaces, which allows remote attackers to modify certain tag properties, possibly leading to execution of arbitrary script or code, as demonstrated using an XHTML document with IMG tags with custom properties (\"XHTML node spoofing\").", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -116,9 +112,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f489-394v-4j27/GHSA-f489-394v-4j27.json b/advisories/unreviewed/2022/05/GHSA-f489-394v-4j27/GHSA-f489-394v-4j27.json index 1fc0e34e91c..0d4fbee432d 100644 --- a/advisories/unreviewed/2022/05/GHSA-f489-394v-4j27/GHSA-f489-394v-4j27.json +++ b/advisories/unreviewed/2022/05/GHSA-f489-394v-4j27/GHSA-f489-394v-4j27.json @@ -7,12 +7,8 @@ "CVE-2005-2288" ], "details": "Cross-site scripting (XSS) vulnerability in PHPCounter 7.2 allows remote attackers to inject arbitrary web script or HTML via the EpochPrefix parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f4qw-3w39-pxmv/GHSA-f4qw-3w39-pxmv.json b/advisories/unreviewed/2022/05/GHSA-f4qw-3w39-pxmv/GHSA-f4qw-3w39-pxmv.json index c9bdba8d096..daf0f3de5b1 100644 --- a/advisories/unreviewed/2022/05/GHSA-f4qw-3w39-pxmv/GHSA-f4qw-3w39-pxmv.json +++ b/advisories/unreviewed/2022/05/GHSA-f4qw-3w39-pxmv/GHSA-f4qw-3w39-pxmv.json @@ -7,12 +7,8 @@ "CVE-2005-1969" ], "details": "Cross-site scripting (XSS) vulnerability in Pragma Systems Telnetserver 6.0 allows remote attackers to inject arbitrary web script or HTML, and hide activities in log files, via a \"