diff --git a/advisories/github-reviewed/2021/10/GHSA-v988-828w-xvf2/GHSA-v988-828w-xvf2.json b/advisories/github-reviewed/2021/10/GHSA-v988-828w-xvf2/GHSA-v988-828w-xvf2.json index da01cdb8537..b2b1fdcdfc3 100644 --- a/advisories/github-reviewed/2021/10/GHSA-v988-828w-xvf2/GHSA-v988-828w-xvf2.json +++ b/advisories/github-reviewed/2021/10/GHSA-v988-828w-xvf2/GHSA-v988-828w-xvf2.json @@ -3,14 +3,10 @@ "id": "GHSA-v988-828w-xvf2", "modified": "2021-10-21T21:36:22Z", "published": "2021-10-22T16:21:07Z", - "aliases": [ - - ], + "aliases": [], "summary": "Authentication Bypass Using an Alternate Path or Channel and Authentication Bypass by Primary Weakness in rucio-webui", "details": "### Impact\n`rucio-webui` installations of the `1.26` release line potentially leak the contents of cookies to other sessions within a wsgi container. Impact is that Rucio authentication tokens are leaked to other users accessing the `webui` within a close timeframe, thus allowing users to access the `webui` with the leaked authentication token. Privileges are therefore also escalated.\n\nRucio server / daemons are not affected by this issue, it is isolated to the webui.\n\n### Patches\nThis issue is fixed in the `1.26.7` release of the `rucio-webui`.\n\n### Workarounds\nInstallation of the `1.25.7` `webui` release. The `1.25` and previous webui release lines are not affected by this issue.\n\n### References\nhttps://github.com/rucio/rucio/issues/4928", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2021/12/GHSA-94g7-hpv8-h9qm/GHSA-94g7-hpv8-h9qm.json b/advisories/github-reviewed/2021/12/GHSA-94g7-hpv8-h9qm/GHSA-94g7-hpv8-h9qm.json index ca9f5789636..c28b2df5986 100644 --- a/advisories/github-reviewed/2021/12/GHSA-94g7-hpv8-h9qm/GHSA-94g7-hpv8-h9qm.json +++ b/advisories/github-reviewed/2021/12/GHSA-94g7-hpv8-h9qm/GHSA-94g7-hpv8-h9qm.json @@ -3,14 +3,10 @@ "id": "GHSA-94g7-hpv8-h9qm", "modified": "2021-12-14T20:00:34Z", "published": "2021-12-14T21:46:35Z", - "aliases": [ - - ], + "aliases": [], "summary": "Remote code injection in Log4j", "details": "### Impact\nLogging untrusted or user controlled data with a vulnerable version of Log4J may result in Remote Code Execution (RCE) against your application. This includes untrusted data included in logged errors such as exception traces, authentication failures, and other unexpected vectors of user controlled input.\n\nMore Details:\nhttps://github.com/advisories/GHSA-jfh8-c2jp-5v3q\n\n### Patches\nVersion 1.11.1 of the Splunk Logging for Java library.\n\nThere is also a backport to version 1.6.2 released as a patch: 1.6.2-0-0.\n\n### Workarounds\nIf upgrading is not possible, then ensure the -Dlog4j2.formatMsgNoLookups=true system property is set on both client- and server-side components.\n\n### References\nhttps://github.com/advisories/GHSA-jfh8-c2jp-5v3q\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in https://github.com/splunk/splunk-library-javalogging/issues\n* Email us at [devinfo@splunk.com](mailto:devinfo@splunk.com)\n", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -43,9 +39,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2021-12-14T20:00:34Z", diff --git a/advisories/github-reviewed/2022/05/GHSA-gcv6-2v9c-rj48/GHSA-gcv6-2v9c-rj48.json b/advisories/github-reviewed/2022/05/GHSA-gcv6-2v9c-rj48/GHSA-gcv6-2v9c-rj48.json index 4177f68d82b..d51f06edfee 100644 --- a/advisories/github-reviewed/2022/05/GHSA-gcv6-2v9c-rj48/GHSA-gcv6-2v9c-rj48.json +++ b/advisories/github-reviewed/2022/05/GHSA-gcv6-2v9c-rj48/GHSA-gcv6-2v9c-rj48.json @@ -62,9 +62,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2023-07-07T13:52:40Z", diff --git a/advisories/github-reviewed/2023/03/GHSA-xc93-587g-mxm7/GHSA-xc93-587g-mxm7.json b/advisories/github-reviewed/2023/03/GHSA-xc93-587g-mxm7/GHSA-xc93-587g-mxm7.json index 3b78c58c0a8..566eb5ae2e3 100644 --- a/advisories/github-reviewed/2023/03/GHSA-xc93-587g-mxm7/GHSA-xc93-587g-mxm7.json +++ b/advisories/github-reviewed/2023/03/GHSA-xc93-587g-mxm7/GHSA-xc93-587g-mxm7.json @@ -50,9 +50,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2023-04-10T16:38:33Z", diff --git a/advisories/unreviewed/2021/12/GHSA-22hj-9cx7-p2hw/GHSA-22hj-9cx7-p2hw.json b/advisories/unreviewed/2021/12/GHSA-22hj-9cx7-p2hw/GHSA-22hj-9cx7-p2hw.json index 8da3cae07f4..77ffb18be34 100644 --- a/advisories/unreviewed/2021/12/GHSA-22hj-9cx7-p2hw/GHSA-22hj-9cx7-p2hw.json +++ b/advisories/unreviewed/2021/12/GHSA-22hj-9cx7-p2hw/GHSA-22hj-9cx7-p2hw.json @@ -7,12 +7,8 @@ "CVE-2021-39935" ], "details": "An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Unauthorized external users could perform Server Side Requests via the CI Lint API", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-23cq-6739-c6x5/GHSA-23cq-6739-c6x5.json b/advisories/unreviewed/2021/12/GHSA-23cq-6739-c6x5/GHSA-23cq-6739-c6x5.json index ecd94c402e1..99025e135b9 100644 --- a/advisories/unreviewed/2021/12/GHSA-23cq-6739-c6x5/GHSA-23cq-6739-c6x5.json +++ b/advisories/unreviewed/2021/12/GHSA-23cq-6739-c6x5/GHSA-23cq-6739-c6x5.json @@ -7,12 +7,8 @@ "CVE-2021-43071" ], "details": "A heap-based buffer overflow in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.3.15 and below, version 6.2.6 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests to the LogReport API controller.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-26gp-9jcj-gh27/GHSA-26gp-9jcj-gh27.json b/advisories/unreviewed/2021/12/GHSA-26gp-9jcj-gh27/GHSA-26gp-9jcj-gh27.json index ea57827d4c1..37fa76627f8 100644 --- a/advisories/unreviewed/2021/12/GHSA-26gp-9jcj-gh27/GHSA-26gp-9jcj-gh27.json +++ b/advisories/unreviewed/2021/12/GHSA-26gp-9jcj-gh27/GHSA-26gp-9jcj-gh27.json @@ -7,12 +7,8 @@ "CVE-2021-42070" ], "details": "When a user opens manipulated Jupiter Tessellation (.jt) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the application crashes and becomes temporarily unavailable to the user until restart of the application", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-26w6-gvvp-6v5v/GHSA-26w6-gvvp-6v5v.json b/advisories/unreviewed/2021/12/GHSA-26w6-gvvp-6v5v/GHSA-26w6-gvvp-6v5v.json index 467a55069fc..da7b07f5167 100644 --- a/advisories/unreviewed/2021/12/GHSA-26w6-gvvp-6v5v/GHSA-26w6-gvvp-6v5v.json +++ b/advisories/unreviewed/2021/12/GHSA-26w6-gvvp-6v5v/GHSA-26w6-gvvp-6v5v.json @@ -7,12 +7,8 @@ "CVE-2021-40280" ], "details": "An SQL Injection vulnerablitly exits in zzcms 8.2, 8.3, 2020, and 2021 via the id parameter in admin/dl_sendmail.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-2824-3r6m-mjx4/GHSA-2824-3r6m-mjx4.json b/advisories/unreviewed/2021/12/GHSA-2824-3r6m-mjx4/GHSA-2824-3r6m-mjx4.json index a03877f1986..f99541bdd01 100644 --- a/advisories/unreviewed/2021/12/GHSA-2824-3r6m-mjx4/GHSA-2824-3r6m-mjx4.json +++ b/advisories/unreviewed/2021/12/GHSA-2824-3r6m-mjx4/GHSA-2824-3r6m-mjx4.json @@ -7,12 +7,8 @@ "CVE-2021-39058" ], "details": "IBM Spectrum Copy Data Management 2.2.13 and earlier uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 214617.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-282m-cc46-hh73/GHSA-282m-cc46-hh73.json b/advisories/unreviewed/2021/12/GHSA-282m-cc46-hh73/GHSA-282m-cc46-hh73.json index 63ca6fc305b..669cec95e2f 100644 --- a/advisories/unreviewed/2021/12/GHSA-282m-cc46-hh73/GHSA-282m-cc46-hh73.json +++ b/advisories/unreviewed/2021/12/GHSA-282m-cc46-hh73/GHSA-282m-cc46-hh73.json @@ -7,12 +7,8 @@ "CVE-2021-20140" ], "details": "An unauthenticated command injection vulnerability exists in the parameters of operation 10 in the controller_server service on Gryphon Tower routers. An unauthenticated remote attacker on the same network can execute commands as root on the device by sending a specially crafted malicious packet to the controller_server service on port 9999.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-2c7w-qmwm-xgjp/GHSA-2c7w-qmwm-xgjp.json b/advisories/unreviewed/2021/12/GHSA-2c7w-qmwm-xgjp/GHSA-2c7w-qmwm-xgjp.json index c0f9d03f75c..1ae3936cd40 100644 --- a/advisories/unreviewed/2021/12/GHSA-2c7w-qmwm-xgjp/GHSA-2c7w-qmwm-xgjp.json +++ b/advisories/unreviewed/2021/12/GHSA-2c7w-qmwm-xgjp/GHSA-2c7w-qmwm-xgjp.json @@ -7,12 +7,8 @@ "CVE-2021-40008" ], "details": "There is a memory leak vulnerability in CloudEngine 12800 V200R019C00SPC800, CloudEngine 5800 V200R019C00SPC800, CloudEngine 6800 V200R019C00SPC800 and CloudEngine 7800 V200R019C00SPC800. The software does not sufficiently track and release allocated memory while parse a series of crafted binary messages, which could consume remaining memory. Successful exploit could cause memory exhaust.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-2m67-46qp-5j9w/GHSA-2m67-46qp-5j9w.json b/advisories/unreviewed/2021/12/GHSA-2m67-46qp-5j9w/GHSA-2m67-46qp-5j9w.json index 68fa1de5088..3e1cf0a4acc 100644 --- a/advisories/unreviewed/2021/12/GHSA-2m67-46qp-5j9w/GHSA-2m67-46qp-5j9w.json +++ b/advisories/unreviewed/2021/12/GHSA-2m67-46qp-5j9w/GHSA-2m67-46qp-5j9w.json @@ -7,12 +7,8 @@ "CVE-2021-41066" ], "details": "An issue was discovered in Listary through 6. When Listary is configured as admin, Listary will not ask for permissions again if a user tries to access files on the system from Listary itself (it will bypass UAC protection; there is no privilege validation of the current user that runs via Listary).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-2mq8-26cv-3wh3/GHSA-2mq8-26cv-3wh3.json b/advisories/unreviewed/2021/12/GHSA-2mq8-26cv-3wh3/GHSA-2mq8-26cv-3wh3.json index 260abb35827..60661ddfa44 100644 --- a/advisories/unreviewed/2021/12/GHSA-2mq8-26cv-3wh3/GHSA-2mq8-26cv-3wh3.json +++ b/advisories/unreviewed/2021/12/GHSA-2mq8-26cv-3wh3/GHSA-2mq8-26cv-3wh3.json @@ -7,12 +7,8 @@ "CVE-2021-25513" ], "details": "An improper privilege management vulnerability in Apps Edge application prior to SMR Dec-2021 Release 1 allows unauthorized access to some device data on the lockscreen.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-2pv7-4f3r-r2rg/GHSA-2pv7-4f3r-r2rg.json b/advisories/unreviewed/2021/12/GHSA-2pv7-4f3r-r2rg/GHSA-2pv7-4f3r-r2rg.json index 49acddf0b10..d82318730ab 100644 --- a/advisories/unreviewed/2021/12/GHSA-2pv7-4f3r-r2rg/GHSA-2pv7-4f3r-r2rg.json +++ b/advisories/unreviewed/2021/12/GHSA-2pv7-4f3r-r2rg/GHSA-2pv7-4f3r-r2rg.json @@ -7,12 +7,8 @@ "CVE-2021-39319" ], "details": "The duoFAQ - Responsive, Flat, Simple FAQ WordPess plugin is vulnerable to Reflected Cross-Site Scripting via the msg parameter found in the ~/duogeek/duogeek-panel.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.4.8.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-2qcc-m9fg-9v5h/GHSA-2qcc-m9fg-9v5h.json b/advisories/unreviewed/2021/12/GHSA-2qcc-m9fg-9v5h/GHSA-2qcc-m9fg-9v5h.json index 326795af561..2402b62fe0d 100644 --- a/advisories/unreviewed/2021/12/GHSA-2qcc-m9fg-9v5h/GHSA-2qcc-m9fg-9v5h.json +++ b/advisories/unreviewed/2021/12/GHSA-2qcc-m9fg-9v5h/GHSA-2qcc-m9fg-9v5h.json @@ -7,12 +7,8 @@ "CVE-2021-40281" ], "details": "An SQL Injection vulnerability exists in zzcms 8.2, 8.3, 2020, and 2021 in dl/dl_print.php when registering ordinary users.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-2qrq-4qxf-6cfm/GHSA-2qrq-4qxf-6cfm.json b/advisories/unreviewed/2021/12/GHSA-2qrq-4qxf-6cfm/GHSA-2qrq-4qxf-6cfm.json index e975e4c1b91..0b30fb41d9e 100644 --- a/advisories/unreviewed/2021/12/GHSA-2qrq-4qxf-6cfm/GHSA-2qrq-4qxf-6cfm.json +++ b/advisories/unreviewed/2021/12/GHSA-2qrq-4qxf-6cfm/GHSA-2qrq-4qxf-6cfm.json @@ -7,12 +7,8 @@ "CVE-2021-37052" ], "details": "There is an Exception log vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause address information leakage.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-2v2m-jqm3-cq3x/GHSA-2v2m-jqm3-cq3x.json b/advisories/unreviewed/2021/12/GHSA-2v2m-jqm3-cq3x/GHSA-2v2m-jqm3-cq3x.json index bb364a8911f..aadf3a3e57b 100644 --- a/advisories/unreviewed/2021/12/GHSA-2v2m-jqm3-cq3x/GHSA-2v2m-jqm3-cq3x.json +++ b/advisories/unreviewed/2021/12/GHSA-2v2m-jqm3-cq3x/GHSA-2v2m-jqm3-cq3x.json @@ -7,12 +7,8 @@ "CVE-2021-40095" ], "details": "An issue was discovered in SquaredUp for SCOM 5.2.1.6654. The Download Log feature in System / Maintenance was susceptible to a local file inclusion vulnerability (when processing remote input in the log files downloaded by an authenticated administrator user), leading to the ability to read arbitrary files on the server filesystems.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2021/12/GHSA-2x2v-ccf2-cqcf/GHSA-2x2v-ccf2-cqcf.json b/advisories/unreviewed/2021/12/GHSA-2x2v-ccf2-cqcf/GHSA-2x2v-ccf2-cqcf.json index 2d333d07925..7eb50c1c754 100644 --- a/advisories/unreviewed/2021/12/GHSA-2x2v-ccf2-cqcf/GHSA-2x2v-ccf2-cqcf.json +++ b/advisories/unreviewed/2021/12/GHSA-2x2v-ccf2-cqcf/GHSA-2x2v-ccf2-cqcf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-3858-cvv4-qvj7/GHSA-3858-cvv4-qvj7.json b/advisories/unreviewed/2021/12/GHSA-3858-cvv4-qvj7/GHSA-3858-cvv4-qvj7.json index f761c7baa0a..6bc3e864436 100644 --- a/advisories/unreviewed/2021/12/GHSA-3858-cvv4-qvj7/GHSA-3858-cvv4-qvj7.json +++ b/advisories/unreviewed/2021/12/GHSA-3858-cvv4-qvj7/GHSA-3858-cvv4-qvj7.json @@ -7,12 +7,8 @@ "CVE-2021-4073" ], "details": "The RegistrationMagic WordPress plugin made it possible for unauthenticated users to log in as any site user, including administrators, if they knew a valid username on the site due to missing identity validation in the social login function social_login_using_email() of the plugin. This affects versions equal to, and less than, 5.0.1.7.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-39jf-9gqp-rjmj/GHSA-39jf-9gqp-rjmj.json b/advisories/unreviewed/2021/12/GHSA-39jf-9gqp-rjmj/GHSA-39jf-9gqp-rjmj.json index bb7c26f4b98..97de7ec9408 100644 --- a/advisories/unreviewed/2021/12/GHSA-39jf-9gqp-rjmj/GHSA-39jf-9gqp-rjmj.json +++ b/advisories/unreviewed/2021/12/GHSA-39jf-9gqp-rjmj/GHSA-39jf-9gqp-rjmj.json @@ -7,12 +7,8 @@ "CVE-2021-40834" ], "details": "A user interface overlay vulnerability was discovered in F-secure SAFE Browser for Android. When user click on a specially crafted seemingly legitimate URL SAFE browser goes into full screen and hides the user interface. A remote attacker can leverage this to perform spoofing attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-3cm3-9ccj-7mvq/GHSA-3cm3-9ccj-7mvq.json b/advisories/unreviewed/2021/12/GHSA-3cm3-9ccj-7mvq/GHSA-3cm3-9ccj-7mvq.json index e323a1225d0..3986349f2bd 100644 --- a/advisories/unreviewed/2021/12/GHSA-3cm3-9ccj-7mvq/GHSA-3cm3-9ccj-7mvq.json +++ b/advisories/unreviewed/2021/12/GHSA-3cm3-9ccj-7mvq/GHSA-3cm3-9ccj-7mvq.json @@ -7,12 +7,8 @@ "CVE-2021-39945" ], "details": "Improper access control in the GitLab CE/EE API affecting all versions starting from 9.4 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an author of a Merge Request to approve the Merge Request even after having their project access revoked", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-3h3c-qxj3-9h67/GHSA-3h3c-qxj3-9h67.json b/advisories/unreviewed/2021/12/GHSA-3h3c-qxj3-9h67/GHSA-3h3c-qxj3-9h67.json index e5e60e8d26a..343e5a64131 100644 --- a/advisories/unreviewed/2021/12/GHSA-3h3c-qxj3-9h67/GHSA-3h3c-qxj3-9h67.json +++ b/advisories/unreviewed/2021/12/GHSA-3h3c-qxj3-9h67/GHSA-3h3c-qxj3-9h67.json @@ -7,12 +7,8 @@ "CVE-2021-42061" ], "details": "SAP BusinessObjects Business Intelligence Platform (Web Intelligence) - version 420, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. This allows a low privileged attacker to retrieve some data from the victim but will never be able to modify the document and publish these modifications to the server. It impacts the \"Quick Prompt\" workflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-3h77-rgfr-6455/GHSA-3h77-rgfr-6455.json b/advisories/unreviewed/2021/12/GHSA-3h77-rgfr-6455/GHSA-3h77-rgfr-6455.json index 8ef4e191ff5..df22883daf7 100644 --- a/advisories/unreviewed/2021/12/GHSA-3h77-rgfr-6455/GHSA-3h77-rgfr-6455.json +++ b/advisories/unreviewed/2021/12/GHSA-3h77-rgfr-6455/GHSA-3h77-rgfr-6455.json @@ -7,12 +7,8 @@ "CVE-2020-12890" ], "details": "Improper handling of pointers in the System Management Mode (SMM) handling code may allow for a privileged attacker with physical or administrative access to potentially manipulate the AMD Generic Encapsulated Software Architecture (AGESA) to execute arbitrary code undetected by the operating system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2021/12/GHSA-3m6f-2h66-fxv5/GHSA-3m6f-2h66-fxv5.json b/advisories/unreviewed/2021/12/GHSA-3m6f-2h66-fxv5/GHSA-3m6f-2h66-fxv5.json index 7d233dfb4fb..a8425483975 100644 --- a/advisories/unreviewed/2021/12/GHSA-3m6f-2h66-fxv5/GHSA-3m6f-2h66-fxv5.json +++ b/advisories/unreviewed/2021/12/GHSA-3m6f-2h66-fxv5/GHSA-3m6f-2h66-fxv5.json @@ -7,12 +7,8 @@ "CVE-2021-20137" ], "details": "A reflected cross-site scripting vulnerability exists in the url parameter of the /cgi-bin/luci/site_access/ page on the Gryphon Tower router's web interface. An attacker could exploit this issue by tricking a user into following a specially crafted link, granting the attacker javascript execution in the context of the victim's browser.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-3p95-f3g8-fcgq/GHSA-3p95-f3g8-fcgq.json b/advisories/unreviewed/2021/12/GHSA-3p95-f3g8-fcgq/GHSA-3p95-f3g8-fcgq.json index 9914fd5cbd8..0bbb5fff894 100644 --- a/advisories/unreviewed/2021/12/GHSA-3p95-f3g8-fcgq/GHSA-3p95-f3g8-fcgq.json +++ b/advisories/unreviewed/2021/12/GHSA-3p95-f3g8-fcgq/GHSA-3p95-f3g8-fcgq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-3q7v-v6cr-7gf4/GHSA-3q7v-v6cr-7gf4.json b/advisories/unreviewed/2021/12/GHSA-3q7v-v6cr-7gf4/GHSA-3q7v-v6cr-7gf4.json index 7c7aca03f8b..7189fc45ed4 100644 --- a/advisories/unreviewed/2021/12/GHSA-3q7v-v6cr-7gf4/GHSA-3q7v-v6cr-7gf4.json +++ b/advisories/unreviewed/2021/12/GHSA-3q7v-v6cr-7gf4/GHSA-3q7v-v6cr-7gf4.json @@ -7,12 +7,8 @@ "CVE-2021-37049" ], "details": "There is a Heap-based buffer overflow vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may rewrite the memory of adjacent objects.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-3qxf-882j-fq36/GHSA-3qxf-882j-fq36.json b/advisories/unreviewed/2021/12/GHSA-3qxf-882j-fq36/GHSA-3qxf-882j-fq36.json index 7ee0d56e473..f8110b0aaa7 100644 --- a/advisories/unreviewed/2021/12/GHSA-3qxf-882j-fq36/GHSA-3qxf-882j-fq36.json +++ b/advisories/unreviewed/2021/12/GHSA-3qxf-882j-fq36/GHSA-3qxf-882j-fq36.json @@ -7,12 +7,8 @@ "CVE-2021-24972" ], "details": "The Pixel Cat WordPress plugin before 2.6.3 does not escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-3r39-xhjj-cwp2/GHSA-3r39-xhjj-cwp2.json b/advisories/unreviewed/2021/12/GHSA-3r39-xhjj-cwp2/GHSA-3r39-xhjj-cwp2.json index 7f64c66253c..196f8adf5d2 100644 --- a/advisories/unreviewed/2021/12/GHSA-3r39-xhjj-cwp2/GHSA-3r39-xhjj-cwp2.json +++ b/advisories/unreviewed/2021/12/GHSA-3r39-xhjj-cwp2/GHSA-3r39-xhjj-cwp2.json @@ -7,12 +7,8 @@ "CVE-2021-3836" ], "details": "dbeaver is vulnerable to Improper Restriction of XML External Entity Reference", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-3vp4-6x9x-47fg/GHSA-3vp4-6x9x-47fg.json b/advisories/unreviewed/2021/12/GHSA-3vp4-6x9x-47fg/GHSA-3vp4-6x9x-47fg.json index 5ca396ac70a..b95ecbccd85 100644 --- a/advisories/unreviewed/2021/12/GHSA-3vp4-6x9x-47fg/GHSA-3vp4-6x9x-47fg.json +++ b/advisories/unreviewed/2021/12/GHSA-3vp4-6x9x-47fg/GHSA-3vp4-6x9x-47fg.json @@ -7,12 +7,8 @@ "CVE-2021-25517" ], "details": "An improper input validation vulnerability in LDFW prior to SMR Dec-2021 Release 1 allows attackers to perform arbitrary code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-3w7f-3j97-hfv4/GHSA-3w7f-3j97-hfv4.json b/advisories/unreviewed/2021/12/GHSA-3w7f-3j97-hfv4/GHSA-3w7f-3j97-hfv4.json index ee66a6a4de4..d7e546bb96e 100644 --- a/advisories/unreviewed/2021/12/GHSA-3w7f-3j97-hfv4/GHSA-3w7f-3j97-hfv4.json +++ b/advisories/unreviewed/2021/12/GHSA-3w7f-3j97-hfv4/GHSA-3w7f-3j97-hfv4.json @@ -7,12 +7,8 @@ "CVE-2021-41029" ], "details": "A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWLM version 8.6.1 and below allows attacker to store malicious javascript code in the device and trigger it via crafted HTTP requests", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-439r-cm94-hfg5/GHSA-439r-cm94-hfg5.json b/advisories/unreviewed/2021/12/GHSA-439r-cm94-hfg5/GHSA-439r-cm94-hfg5.json index 5e8ca5f747d..54233c6ebab 100644 --- a/advisories/unreviewed/2021/12/GHSA-439r-cm94-hfg5/GHSA-439r-cm94-hfg5.json +++ b/advisories/unreviewed/2021/12/GHSA-439r-cm94-hfg5/GHSA-439r-cm94-hfg5.json @@ -7,12 +7,8 @@ "CVE-2021-20142" ], "details": "An unauthenticated command injection vulnerability exists in the parameters of operation 41 in the controller_server service on Gryphon Tower routers. An unauthenticated remote attacker on the same network can execute commands as root on the device by sending a specially crafted malicious packet to the controller_server service on port 9999.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-442w-3vhj-m8rc/GHSA-442w-3vhj-m8rc.json b/advisories/unreviewed/2021/12/GHSA-442w-3vhj-m8rc/GHSA-442w-3vhj-m8rc.json index 236780ab50c..23c726eb1aa 100644 --- a/advisories/unreviewed/2021/12/GHSA-442w-3vhj-m8rc/GHSA-442w-3vhj-m8rc.json +++ b/advisories/unreviewed/2021/12/GHSA-442w-3vhj-m8rc/GHSA-442w-3vhj-m8rc.json @@ -7,12 +7,8 @@ "CVE-2021-41015" ], "details": "A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests to SAML login handler", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-459r-h7r8-fv25/GHSA-459r-h7r8-fv25.json b/advisories/unreviewed/2021/12/GHSA-459r-h7r8-fv25/GHSA-459r-h7r8-fv25.json index be72f375466..ebed9017f70 100644 --- a/advisories/unreviewed/2021/12/GHSA-459r-h7r8-fv25/GHSA-459r-h7r8-fv25.json +++ b/advisories/unreviewed/2021/12/GHSA-459r-h7r8-fv25/GHSA-459r-h7r8-fv25.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-47vr-crpx-w72f/GHSA-47vr-crpx-w72f.json b/advisories/unreviewed/2021/12/GHSA-47vr-crpx-w72f/GHSA-47vr-crpx-w72f.json index fbc3c1ebc18..d160fc4bf7f 100644 --- a/advisories/unreviewed/2021/12/GHSA-47vr-crpx-w72f/GHSA-47vr-crpx-w72f.json +++ b/advisories/unreviewed/2021/12/GHSA-47vr-crpx-w72f/GHSA-47vr-crpx-w72f.json @@ -7,12 +7,8 @@ "CVE-2018-25022" ], "details": "The Onion module in toxcore before 0.2.2 doesn't restrict which packets can be onion-routed, which allows a remote attacker to discover a target user's IP address (when knowing only their Tox Id) by positioning themselves close to target's Tox Id in the DHT for the target to establish an onion connection with the attacker, guessing the target's DHT public key and creating a DHT node with public key close to it, and finally onion-routing a NAT Ping Request to the target, requesting it to ping the just created DHT node.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-4fr3-cmqh-r8mx/GHSA-4fr3-cmqh-r8mx.json b/advisories/unreviewed/2021/12/GHSA-4fr3-cmqh-r8mx/GHSA-4fr3-cmqh-r8mx.json index 0f4f561b02f..47b51e92fb6 100644 --- a/advisories/unreviewed/2021/12/GHSA-4fr3-cmqh-r8mx/GHSA-4fr3-cmqh-r8mx.json +++ b/advisories/unreviewed/2021/12/GHSA-4fr3-cmqh-r8mx/GHSA-4fr3-cmqh-r8mx.json @@ -7,12 +7,8 @@ "CVE-2021-24817" ], "details": "The Ultimate NoFollow WordPress plugin through 1.4.8 does not sanitise and escape the href attribute of its shortcodes, allowing users with a role as low as contributor to perform Cross-Site Scripting attacks", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-4g5h-vp8c-mrhf/GHSA-4g5h-vp8c-mrhf.json b/advisories/unreviewed/2021/12/GHSA-4g5h-vp8c-mrhf/GHSA-4g5h-vp8c-mrhf.json index e0d776a5036..60ef9972026 100644 --- a/advisories/unreviewed/2021/12/GHSA-4g5h-vp8c-mrhf/GHSA-4g5h-vp8c-mrhf.json +++ b/advisories/unreviewed/2021/12/GHSA-4g5h-vp8c-mrhf/GHSA-4g5h-vp8c-mrhf.json @@ -7,12 +7,8 @@ "CVE-2021-44232" ], "details": "SAF-T Framework Transaction SAFTN_G allows an attacker to exploit insufficient validation of path information provided by normal user, leading to full server directory access. The attacker can see the whole filesystem structure but cannot overwrite, delete, or corrupt arbitrary files on the server.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-4j93-782c-r8vm/GHSA-4j93-782c-r8vm.json b/advisories/unreviewed/2021/12/GHSA-4j93-782c-r8vm/GHSA-4j93-782c-r8vm.json index 2b5904c88ad..c8a6e56c236 100644 --- a/advisories/unreviewed/2021/12/GHSA-4j93-782c-r8vm/GHSA-4j93-782c-r8vm.json +++ b/advisories/unreviewed/2021/12/GHSA-4j93-782c-r8vm/GHSA-4j93-782c-r8vm.json @@ -7,12 +7,8 @@ "CVE-2021-42548" ], "details": "Insufficient Input Validation in the search functionality of Wordpress plugin Share-one-Drive prior to 1.15.3 allows unauthenticated user to craft a reflected Cross-Site Scripting attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-4rfr-wr94-r2xv/GHSA-4rfr-wr94-r2xv.json b/advisories/unreviewed/2021/12/GHSA-4rfr-wr94-r2xv/GHSA-4rfr-wr94-r2xv.json index e5f16006258..de9df9209e7 100644 --- a/advisories/unreviewed/2021/12/GHSA-4rfr-wr94-r2xv/GHSA-4rfr-wr94-r2xv.json +++ b/advisories/unreviewed/2021/12/GHSA-4rfr-wr94-r2xv/GHSA-4rfr-wr94-r2xv.json @@ -7,12 +7,8 @@ "CVE-2021-41836" ], "details": "The Fathom Analytics WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and escaping via the $site_id parameter found in the ~/fathom-analytics.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 3.0.4. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-4xc7-pr98-5x4c/GHSA-4xc7-pr98-5x4c.json b/advisories/unreviewed/2021/12/GHSA-4xc7-pr98-5x4c/GHSA-4xc7-pr98-5x4c.json index 6ec056fcae8..63c9568c78e 100644 --- a/advisories/unreviewed/2021/12/GHSA-4xc7-pr98-5x4c/GHSA-4xc7-pr98-5x4c.json +++ b/advisories/unreviewed/2021/12/GHSA-4xc7-pr98-5x4c/GHSA-4xc7-pr98-5x4c.json @@ -7,12 +7,8 @@ "CVE-2021-42068" ], "details": "When a user opens a manipulated GIF (.gif) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the application crashes and becomes temporarily unavailable to the user until restart of the application.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-4xf6-p33h-wqwp/GHSA-4xf6-p33h-wqwp.json b/advisories/unreviewed/2021/12/GHSA-4xf6-p33h-wqwp/GHSA-4xf6-p33h-wqwp.json index b5187a91992..c7bfa04f44c 100644 --- a/advisories/unreviewed/2021/12/GHSA-4xf6-p33h-wqwp/GHSA-4xf6-p33h-wqwp.json +++ b/advisories/unreviewed/2021/12/GHSA-4xf6-p33h-wqwp/GHSA-4xf6-p33h-wqwp.json @@ -7,12 +7,8 @@ "CVE-2021-37051" ], "details": "There is an Out-of-bounds read vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause out-of-bounds memory access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-529g-jxw5-837v/GHSA-529g-jxw5-837v.json b/advisories/unreviewed/2021/12/GHSA-529g-jxw5-837v/GHSA-529g-jxw5-837v.json index fe5103052b9..d793ca086b3 100644 --- a/advisories/unreviewed/2021/12/GHSA-529g-jxw5-837v/GHSA-529g-jxw5-837v.json +++ b/advisories/unreviewed/2021/12/GHSA-529g-jxw5-837v/GHSA-529g-jxw5-837v.json @@ -7,12 +7,8 @@ "CVE-2021-42064" ], "details": "If configured to use an Oracle database and if a query is created using the flexible search java api with a parameterized \"in\" clause, SAP Commerce - versions 1905, 2005, 2105, 2011, allows attacker to execute crafted database queries, exposing backend database. The vulnerability is present if the parameterized \"in\" clause accepts more than 1000 values.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-557v-6mgr-fw76/GHSA-557v-6mgr-fw76.json b/advisories/unreviewed/2021/12/GHSA-557v-6mgr-fw76/GHSA-557v-6mgr-fw76.json index 0973781f4bb..f271d17b685 100644 --- a/advisories/unreviewed/2021/12/GHSA-557v-6mgr-fw76/GHSA-557v-6mgr-fw76.json +++ b/advisories/unreviewed/2021/12/GHSA-557v-6mgr-fw76/GHSA-557v-6mgr-fw76.json @@ -7,12 +7,8 @@ "CVE-2021-40882" ], "details": "A Cross Site Scripting (XSS) vulnerability exists in Piwigo 11.5.0 via the system album name and description of the location.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-55c9-ghph-fqp6/GHSA-55c9-ghph-fqp6.json b/advisories/unreviewed/2021/12/GHSA-55c9-ghph-fqp6/GHSA-55c9-ghph-fqp6.json index 3337073d02d..ecd42a4372c 100644 --- a/advisories/unreviewed/2021/12/GHSA-55c9-ghph-fqp6/GHSA-55c9-ghph-fqp6.json +++ b/advisories/unreviewed/2021/12/GHSA-55c9-ghph-fqp6/GHSA-55c9-ghph-fqp6.json @@ -7,12 +7,8 @@ "CVE-2021-37053" ], "details": "There is a Service logic vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause WLAN DoS.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2021/12/GHSA-568v-wj37-w729/GHSA-568v-wj37-w729.json b/advisories/unreviewed/2021/12/GHSA-568v-wj37-w729/GHSA-568v-wj37-w729.json index 7807edde0a8..01682f043ff 100644 --- a/advisories/unreviewed/2021/12/GHSA-568v-wj37-w729/GHSA-568v-wj37-w729.json +++ b/advisories/unreviewed/2021/12/GHSA-568v-wj37-w729/GHSA-568v-wj37-w729.json @@ -7,12 +7,8 @@ "CVE-2021-22279" ], "details": "A Missing Authentication vulnerability in RobotWare for the OmniCore robot controller allows an attacker to read and modify files on the robot controller if the attacker has access to the Connected Services Gateway Ethernet port.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-56m9-2h59-x23m/GHSA-56m9-2h59-x23m.json b/advisories/unreviewed/2021/12/GHSA-56m9-2h59-x23m/GHSA-56m9-2h59-x23m.json index d262588e788..750a8427307 100644 --- a/advisories/unreviewed/2021/12/GHSA-56m9-2h59-x23m/GHSA-56m9-2h59-x23m.json +++ b/advisories/unreviewed/2021/12/GHSA-56m9-2h59-x23m/GHSA-56m9-2h59-x23m.json @@ -7,12 +7,8 @@ "CVE-2021-43064" ], "details": "A url redirection to untrusted site ('open redirect') in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.3.15 and below, version 6.2.6 and below allows attacker to use the device as a proxy and reach external or protected hosts via redirection handlers.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-56mj-58m7-xhxx/GHSA-56mj-58m7-xhxx.json b/advisories/unreviewed/2021/12/GHSA-56mj-58m7-xhxx/GHSA-56mj-58m7-xhxx.json index e1b24dcaecb..3ed10533332 100644 --- a/advisories/unreviewed/2021/12/GHSA-56mj-58m7-xhxx/GHSA-56mj-58m7-xhxx.json +++ b/advisories/unreviewed/2021/12/GHSA-56mj-58m7-xhxx/GHSA-56mj-58m7-xhxx.json @@ -7,12 +7,8 @@ "CVE-2021-41695" ], "details": "An SQL Injection vulnerability exists in Premiumdatingscript 4.2.7.7 via the ip parameter in connect.php. .", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-58fc-493g-jfwj/GHSA-58fc-493g-jfwj.json b/advisories/unreviewed/2021/12/GHSA-58fc-493g-jfwj/GHSA-58fc-493g-jfwj.json index c36372cc3d0..97febd123db 100644 --- a/advisories/unreviewed/2021/12/GHSA-58fc-493g-jfwj/GHSA-58fc-493g-jfwj.json +++ b/advisories/unreviewed/2021/12/GHSA-58fc-493g-jfwj/GHSA-58fc-493g-jfwj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-5gjg-f3cq-cmwg/GHSA-5gjg-f3cq-cmwg.json b/advisories/unreviewed/2021/12/GHSA-5gjg-f3cq-cmwg/GHSA-5gjg-f3cq-cmwg.json index 96d4ff6e20f..a8f67d69cc3 100644 --- a/advisories/unreviewed/2021/12/GHSA-5gjg-f3cq-cmwg/GHSA-5gjg-f3cq-cmwg.json +++ b/advisories/unreviewed/2021/12/GHSA-5gjg-f3cq-cmwg/GHSA-5gjg-f3cq-cmwg.json @@ -7,12 +7,8 @@ "CVE-2021-37069" ], "details": "There is a Race Condition vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to availability affected.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-5gw5-j62r-rfx2/GHSA-5gw5-j62r-rfx2.json b/advisories/unreviewed/2021/12/GHSA-5gw5-j62r-rfx2/GHSA-5gw5-j62r-rfx2.json index d412cb1a160..0bcbd052332 100644 --- a/advisories/unreviewed/2021/12/GHSA-5gw5-j62r-rfx2/GHSA-5gw5-j62r-rfx2.json +++ b/advisories/unreviewed/2021/12/GHSA-5gw5-j62r-rfx2/GHSA-5gw5-j62r-rfx2.json @@ -7,12 +7,8 @@ "CVE-2021-24780" ], "details": "The Single Post Exporter WordPress plugin through 1.1.1 does not have CSRF checks when saving its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and give access to the export feature to any role such as subscriber. Subscriber users would then be able to export an arbitrary post/page (such as private and password protected) via a direct URL", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-5jx7-f25h-w96j/GHSA-5jx7-f25h-w96j.json b/advisories/unreviewed/2021/12/GHSA-5jx7-f25h-w96j/GHSA-5jx7-f25h-w96j.json index 0f229a61f62..63fac4b68d2 100644 --- a/advisories/unreviewed/2021/12/GHSA-5jx7-f25h-w96j/GHSA-5jx7-f25h-w96j.json +++ b/advisories/unreviewed/2021/12/GHSA-5jx7-f25h-w96j/GHSA-5jx7-f25h-w96j.json @@ -7,12 +7,8 @@ "CVE-2021-25525" ], "details": "Improper check or handling of exception conditions vulnerability in Samsung Pay (US only) prior to version 4.0.65 allows attacker to use NFC without user recognition.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-5w4g-f682-43cr/GHSA-5w4g-f682-43cr.json b/advisories/unreviewed/2021/12/GHSA-5w4g-f682-43cr/GHSA-5w4g-f682-43cr.json index 71738347501..216c642f95c 100644 --- a/advisories/unreviewed/2021/12/GHSA-5w4g-f682-43cr/GHSA-5w4g-f682-43cr.json +++ b/advisories/unreviewed/2021/12/GHSA-5w4g-f682-43cr/GHSA-5w4g-f682-43cr.json @@ -7,12 +7,8 @@ "CVE-2018-10228" ], "details": "Cross-site scripting (XSS) vulnerability in /application/controller/admin/theme.php in LimeSurvey 3.6.2+180406 allows remote attackers to inject arbitrary web script or HTML via the changes_cp parameter to the index.php/admin/themes/sa/templatesavechanges URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-5x86-xgvw-j25w/GHSA-5x86-xgvw-j25w.json b/advisories/unreviewed/2021/12/GHSA-5x86-xgvw-j25w/GHSA-5x86-xgvw-j25w.json index 6d0c298b8f1..da244ce7492 100644 --- a/advisories/unreviewed/2021/12/GHSA-5x86-xgvw-j25w/GHSA-5x86-xgvw-j25w.json +++ b/advisories/unreviewed/2021/12/GHSA-5x86-xgvw-j25w/GHSA-5x86-xgvw-j25w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-5xj4-c9mm-32pr/GHSA-5xj4-c9mm-32pr.json b/advisories/unreviewed/2021/12/GHSA-5xj4-c9mm-32pr/GHSA-5xj4-c9mm-32pr.json index d91e0e29ad5..04413ba644d 100644 --- a/advisories/unreviewed/2021/12/GHSA-5xj4-c9mm-32pr/GHSA-5xj4-c9mm-32pr.json +++ b/advisories/unreviewed/2021/12/GHSA-5xj4-c9mm-32pr/GHSA-5xj4-c9mm-32pr.json @@ -7,12 +7,8 @@ "CVE-2021-37189" ], "details": "An issue was discovered on Digi TransPort Gateway devices through 5.2.13.4. They do not set the Secure attribute for sensitive cookies in HTTPS sessions, which could cause the user agent to send those cookies in cleartext over an HTTP session.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-62hx-qw5f-w62x/GHSA-62hx-qw5f-w62x.json b/advisories/unreviewed/2021/12/GHSA-62hx-qw5f-w62x/GHSA-62hx-qw5f-w62x.json index 5929018e95d..fcc139497b7 100644 --- a/advisories/unreviewed/2021/12/GHSA-62hx-qw5f-w62x/GHSA-62hx-qw5f-w62x.json +++ b/advisories/unreviewed/2021/12/GHSA-62hx-qw5f-w62x/GHSA-62hx-qw5f-w62x.json @@ -7,12 +7,8 @@ "CVE-2021-41014" ], "details": "A uncontrolled resource consumption in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows an unauthenticated attacker to make the httpsd daemon unresponsive via huge HTTP packets", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-62p6-2538-mvjg/GHSA-62p6-2538-mvjg.json b/advisories/unreviewed/2021/12/GHSA-62p6-2538-mvjg/GHSA-62p6-2538-mvjg.json index f64778c8801..9dd4c93f552 100644 --- a/advisories/unreviewed/2021/12/GHSA-62p6-2538-mvjg/GHSA-62p6-2538-mvjg.json +++ b/advisories/unreviewed/2021/12/GHSA-62p6-2538-mvjg/GHSA-62p6-2538-mvjg.json @@ -7,12 +7,8 @@ "CVE-2021-35978" ], "details": "An issue was discovered in Digi TransPort DR64, SR44 VC74, and WR. The ZING protocol allows arbitrary remote command execution with SUPER privileges. This allows an attacker (with knowledge of the protocol) to execute arbitrary code on the controller including overwriting firmware, adding/removing users, disabling the internal firewall, etc.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-65cr-jw24-wv57/GHSA-65cr-jw24-wv57.json b/advisories/unreviewed/2021/12/GHSA-65cr-jw24-wv57/GHSA-65cr-jw24-wv57.json index aa1a0bfe3aa..9797a9fbd47 100644 --- a/advisories/unreviewed/2021/12/GHSA-65cr-jw24-wv57/GHSA-65cr-jw24-wv57.json +++ b/advisories/unreviewed/2021/12/GHSA-65cr-jw24-wv57/GHSA-65cr-jw24-wv57.json @@ -7,12 +7,8 @@ "CVE-2021-44948" ], "details": "glFusion CMS 1.7.9 is affected by a Cross Site Request Forgery (CSRF) vulnerability in /public_html/admin/plugins/bad_behavior2/blacklist.php. Using the CSRF vulnerability to trick the administrator to click, an attacker can add a blacklist.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-675q-g72p-gc3c/GHSA-675q-g72p-gc3c.json b/advisories/unreviewed/2021/12/GHSA-675q-g72p-gc3c/GHSA-675q-g72p-gc3c.json index 002d6cdc422..c9455a80cc9 100644 --- a/advisories/unreviewed/2021/12/GHSA-675q-g72p-gc3c/GHSA-675q-g72p-gc3c.json +++ b/advisories/unreviewed/2021/12/GHSA-675q-g72p-gc3c/GHSA-675q-g72p-gc3c.json @@ -7,12 +7,8 @@ "CVE-2021-43410" ], "details": "Apache Airavata Django Portal allows CRLF log injection because of lack of escaping log statements. In particular, some HTTP request parameters are logged without first being escaped. Versions affected: master branch before commit 3c5d8c7 [1] of airavata-django-portal [1] https://github.com/apache/airavata-django-portal/commit/3c5d8c72bfc3eb0af8693a655a5d60f9273f8170", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-6c9w-8fw5-p82r/GHSA-6c9w-8fw5-p82r.json b/advisories/unreviewed/2021/12/GHSA-6c9w-8fw5-p82r/GHSA-6c9w-8fw5-p82r.json index 8936f78359d..49947a1dbb0 100644 --- a/advisories/unreviewed/2021/12/GHSA-6c9w-8fw5-p82r/GHSA-6c9w-8fw5-p82r.json +++ b/advisories/unreviewed/2021/12/GHSA-6c9w-8fw5-p82r/GHSA-6c9w-8fw5-p82r.json @@ -7,12 +7,8 @@ "CVE-2021-25512" ], "details": "An improper validation vulnerability in telephony prior to SMR Dec-2021 Release 1 allows attackers to launch certain activities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-6f9g-vc76-v447/GHSA-6f9g-vc76-v447.json b/advisories/unreviewed/2021/12/GHSA-6f9g-vc76-v447/GHSA-6f9g-vc76-v447.json index d0e92dbd827..f4129d2654d 100644 --- a/advisories/unreviewed/2021/12/GHSA-6f9g-vc76-v447/GHSA-6f9g-vc76-v447.json +++ b/advisories/unreviewed/2021/12/GHSA-6f9g-vc76-v447/GHSA-6f9g-vc76-v447.json @@ -7,12 +7,8 @@ "CVE-2021-43983" ], "details": "WECON LeviStudioU Versions 2019-09-21 and prior are vulnerable to multiple stack-based buffer overflow instances while parsing project files, which may allow an attacker to execute arbitrary code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-6h38-5hx8-g8v2/GHSA-6h38-5hx8-g8v2.json b/advisories/unreviewed/2021/12/GHSA-6h38-5hx8-g8v2/GHSA-6h38-5hx8-g8v2.json index 55cc693f623..eb3ccca362e 100644 --- a/advisories/unreviewed/2021/12/GHSA-6h38-5hx8-g8v2/GHSA-6h38-5hx8-g8v2.json +++ b/advisories/unreviewed/2021/12/GHSA-6h38-5hx8-g8v2/GHSA-6h38-5hx8-g8v2.json @@ -7,12 +7,8 @@ "CVE-2021-24784" ], "details": "The WP Admin Logo Changer WordPress plugin through 1.0 does not have CSRF check when saving its settings, which could allow attackers to make a logged in admin update them via a CSRF attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-6j73-7mgq-98hj/GHSA-6j73-7mgq-98hj.json b/advisories/unreviewed/2021/12/GHSA-6j73-7mgq-98hj/GHSA-6j73-7mgq-98hj.json index c0f05140b4e..c73072cc11d 100644 --- a/advisories/unreviewed/2021/12/GHSA-6j73-7mgq-98hj/GHSA-6j73-7mgq-98hj.json +++ b/advisories/unreviewed/2021/12/GHSA-6j73-7mgq-98hj/GHSA-6j73-7mgq-98hj.json @@ -7,12 +7,8 @@ "CVE-2021-43388" ], "details": "Unisys Cargo Mobile Application before 1.2.29 uses cleartext to store sensitive information, which might be revealed in a backup. The issue is addressed by ensuring that the allowBackup flag (in the manifest) is False.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-6qgr-35g2-ph79/GHSA-6qgr-35g2-ph79.json b/advisories/unreviewed/2021/12/GHSA-6qgr-35g2-ph79/GHSA-6qgr-35g2-ph79.json index 56eef5ea557..f6f71441147 100644 --- a/advisories/unreviewed/2021/12/GHSA-6qgr-35g2-ph79/GHSA-6qgr-35g2-ph79.json +++ b/advisories/unreviewed/2021/12/GHSA-6qgr-35g2-ph79/GHSA-6qgr-35g2-ph79.json @@ -7,12 +7,8 @@ "CVE-2021-24855" ], "details": "The Display Post Metadata WordPress plugin before 1.5.0 adds a shortcode to print out custom fields, however their content is not sanitised or escaped which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-6qmc-gxp3-22f6/GHSA-6qmc-gxp3-22f6.json b/advisories/unreviewed/2021/12/GHSA-6qmc-gxp3-22f6/GHSA-6qmc-gxp3-22f6.json index 6b5c77721e8..54796975e1c 100644 --- a/advisories/unreviewed/2021/12/GHSA-6qmc-gxp3-22f6/GHSA-6qmc-gxp3-22f6.json +++ b/advisories/unreviewed/2021/12/GHSA-6qmc-gxp3-22f6/GHSA-6qmc-gxp3-22f6.json @@ -7,12 +7,8 @@ "CVE-2021-36720" ], "details": "PineApp - Mail Secure - Attacker sending a request to :/blocking.php?url= and stealing cookies .", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-6r6w-66x9-r2cx/GHSA-6r6w-66x9-r2cx.json b/advisories/unreviewed/2021/12/GHSA-6r6w-66x9-r2cx/GHSA-6r6w-66x9-r2cx.json index 90f6c7e9d55..70d69c011ec 100644 --- a/advisories/unreviewed/2021/12/GHSA-6r6w-66x9-r2cx/GHSA-6r6w-66x9-r2cx.json +++ b/advisories/unreviewed/2021/12/GHSA-6r6w-66x9-r2cx/GHSA-6r6w-66x9-r2cx.json @@ -7,12 +7,8 @@ "CVE-2021-39050" ], "details": "IBM i2 Analyst's Notebook 9.2.0, 9.2.1, and 9.2.2 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local attacker could overflow a buffer and gain lower level privileges. IBM X-Force ID: 214440.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-6wc6-p7fm-qqjp/GHSA-6wc6-p7fm-qqjp.json b/advisories/unreviewed/2021/12/GHSA-6wc6-p7fm-qqjp/GHSA-6wc6-p7fm-qqjp.json index 7a6ef62d473..ec39f788cb6 100644 --- a/advisories/unreviewed/2021/12/GHSA-6wc6-p7fm-qqjp/GHSA-6wc6-p7fm-qqjp.json +++ b/advisories/unreviewed/2021/12/GHSA-6wc6-p7fm-qqjp/GHSA-6wc6-p7fm-qqjp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-6xx3-7c4w-v79g/GHSA-6xx3-7c4w-v79g.json b/advisories/unreviewed/2021/12/GHSA-6xx3-7c4w-v79g/GHSA-6xx3-7c4w-v79g.json index 55dbe793795..5b87fadd9f1 100644 --- a/advisories/unreviewed/2021/12/GHSA-6xx3-7c4w-v79g/GHSA-6xx3-7c4w-v79g.json +++ b/advisories/unreviewed/2021/12/GHSA-6xx3-7c4w-v79g/GHSA-6xx3-7c4w-v79g.json @@ -7,12 +7,8 @@ "CVE-2021-44942" ], "details": "glFusion CMS 1.7.9 is affected by a Cross Site Request Forgery (CSRF) vulnerability in /public_html/admin/plugins/bad_behavior2/blacklist.php. Using the CSRF vulnerability to trick the administrator to click, an attacker can add a blacklist.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-724p-rm8h-wjx7/GHSA-724p-rm8h-wjx7.json b/advisories/unreviewed/2021/12/GHSA-724p-rm8h-wjx7/GHSA-724p-rm8h-wjx7.json index 275de88b4a6..0150782ed94 100644 --- a/advisories/unreviewed/2021/12/GHSA-724p-rm8h-wjx7/GHSA-724p-rm8h-wjx7.json +++ b/advisories/unreviewed/2021/12/GHSA-724p-rm8h-wjx7/GHSA-724p-rm8h-wjx7.json @@ -7,12 +7,8 @@ "CVE-2021-42835" ], "details": "An issue was discovered in Plex Media Server through 1.24.4.5081-e362dc1ee. An attacker (with a foothold in a endpoint via a low-privileged user account) can access the exposed RPC service of the update service component. This RPC functionality allows the attacker to interact with the RPC functionality and execute code from a path of his choice (local, or remote via SMB) because of a TOCTOU race condition. This code execution is in the context of the Plex update service (which runs as SYSTEM).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-72q7-8432-wmmm/GHSA-72q7-8432-wmmm.json b/advisories/unreviewed/2021/12/GHSA-72q7-8432-wmmm/GHSA-72q7-8432-wmmm.json index 61ca79f5e6e..ac785ab5548 100644 --- a/advisories/unreviewed/2021/12/GHSA-72q7-8432-wmmm/GHSA-72q7-8432-wmmm.json +++ b/advisories/unreviewed/2021/12/GHSA-72q7-8432-wmmm/GHSA-72q7-8432-wmmm.json @@ -7,12 +7,8 @@ "CVE-2021-24872" ], "details": "The Get Custom Field Values WordPress plugin before 4.0 allows users with a role as low as Contributor to access other posts metadata without validating the permissions. Eg. contributors can access admin posts metadata.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-7493-f24p-jv53/GHSA-7493-f24p-jv53.json b/advisories/unreviewed/2021/12/GHSA-7493-f24p-jv53/GHSA-7493-f24p-jv53.json index 7c9e82bb19c..7c7dee358be 100644 --- a/advisories/unreviewed/2021/12/GHSA-7493-f24p-jv53/GHSA-7493-f24p-jv53.json +++ b/advisories/unreviewed/2021/12/GHSA-7493-f24p-jv53/GHSA-7493-f24p-jv53.json @@ -7,12 +7,8 @@ "CVE-2021-24045" ], "details": "A type confusion vulnerability could be triggered when resolving the \"typeof\" unary operator in Facebook Hermes prior to v0.10.0. Note that this is only exploitable if the application using Hermes permits evaluation of untrusted JavaScript. Hence, most React Native applications are not affected.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-7532-2whq-rwqh/GHSA-7532-2whq-rwqh.json b/advisories/unreviewed/2021/12/GHSA-7532-2whq-rwqh/GHSA-7532-2whq-rwqh.json index eccf2e9771f..6c0db30bf76 100644 --- a/advisories/unreviewed/2021/12/GHSA-7532-2whq-rwqh/GHSA-7532-2whq-rwqh.json +++ b/advisories/unreviewed/2021/12/GHSA-7532-2whq-rwqh/GHSA-7532-2whq-rwqh.json @@ -7,12 +7,8 @@ "CVE-2021-41063" ], "details": "SQL injection vulnerability was discovered in Aanderaa GeoView Webservice prior to version 2.1.3 that could allow an unauthenticated attackers to execute arbitrary commands.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-777j-8c2c-w27p/GHSA-777j-8c2c-w27p.json b/advisories/unreviewed/2021/12/GHSA-777j-8c2c-w27p/GHSA-777j-8c2c-w27p.json index 715a5f5f1f3..67437192e5b 100644 --- a/advisories/unreviewed/2021/12/GHSA-777j-8c2c-w27p/GHSA-777j-8c2c-w27p.json +++ b/advisories/unreviewed/2021/12/GHSA-777j-8c2c-w27p/GHSA-777j-8c2c-w27p.json @@ -7,12 +7,8 @@ "CVE-2021-39318" ], "details": "The H5P CSS Editor WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the h5p-css-file parameter found in the ~/h5p-css-editor.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-78qc-9ppm-3v8r/GHSA-78qc-9ppm-3v8r.json b/advisories/unreviewed/2021/12/GHSA-78qc-9ppm-3v8r/GHSA-78qc-9ppm-3v8r.json index 072906bc90a..2bb41b00365 100644 --- a/advisories/unreviewed/2021/12/GHSA-78qc-9ppm-3v8r/GHSA-78qc-9ppm-3v8r.json +++ b/advisories/unreviewed/2021/12/GHSA-78qc-9ppm-3v8r/GHSA-78qc-9ppm-3v8r.json @@ -7,12 +7,8 @@ "CVE-2021-40282" ], "details": "An SQL Injection vulnerability exists in zzcms 8.2, 8.3, 2020, abd 2021 in dl/dl_download.php. when registering ordinary users.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-78rc-hmp8-p646/GHSA-78rc-hmp8-p646.json b/advisories/unreviewed/2021/12/GHSA-78rc-hmp8-p646/GHSA-78rc-hmp8-p646.json index 876a7742acf..cb6b6afffdb 100644 --- a/advisories/unreviewed/2021/12/GHSA-78rc-hmp8-p646/GHSA-78rc-hmp8-p646.json +++ b/advisories/unreviewed/2021/12/GHSA-78rc-hmp8-p646/GHSA-78rc-hmp8-p646.json @@ -7,12 +7,8 @@ "CVE-2021-41013" ], "details": "An improper access control vulnerability [CWE-284] in FortiWeb versions 6.4.1 and below and 6.3.15 and below in the Report Browse section of Log & Report may allow an unauthorized and unauthenticated user to access the Log reports via their URLs.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-79jv-mx3j-g9vr/GHSA-79jv-mx3j-g9vr.json b/advisories/unreviewed/2021/12/GHSA-79jv-mx3j-g9vr/GHSA-79jv-mx3j-g9vr.json index f1394c0d397..e1f9f438769 100644 --- a/advisories/unreviewed/2021/12/GHSA-79jv-mx3j-g9vr/GHSA-79jv-mx3j-g9vr.json +++ b/advisories/unreviewed/2021/12/GHSA-79jv-mx3j-g9vr/GHSA-79jv-mx3j-g9vr.json @@ -7,12 +7,8 @@ "CVE-2021-39002" ], "details": "IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-7c29-x43x-h624/GHSA-7c29-x43x-h624.json b/advisories/unreviewed/2021/12/GHSA-7c29-x43x-h624/GHSA-7c29-x43x-h624.json index fc86807b644..15e537e27ea 100644 --- a/advisories/unreviewed/2021/12/GHSA-7c29-x43x-h624/GHSA-7c29-x43x-h624.json +++ b/advisories/unreviewed/2021/12/GHSA-7c29-x43x-h624/GHSA-7c29-x43x-h624.json @@ -7,12 +7,8 @@ "CVE-2020-19683" ], "details": "A Cross Site Scripting (XSS) exists in ZZZCMS V1.7.1 via an editfile action in save.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-7c2g-m3j2-jrgq/GHSA-7c2g-m3j2-jrgq.json b/advisories/unreviewed/2021/12/GHSA-7c2g-m3j2-jrgq/GHSA-7c2g-m3j2-jrgq.json index 7fde0034fb9..06f940781df 100644 --- a/advisories/unreviewed/2021/12/GHSA-7c2g-m3j2-jrgq/GHSA-7c2g-m3j2-jrgq.json +++ b/advisories/unreviewed/2021/12/GHSA-7c2g-m3j2-jrgq/GHSA-7c2g-m3j2-jrgq.json @@ -7,12 +7,8 @@ "CVE-2020-16155" ], "details": "The CPAN::Checksums package 2.12 for Perl does not uniquely define signed data.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2021/12/GHSA-7c78-24gm-9rqf/GHSA-7c78-24gm-9rqf.json b/advisories/unreviewed/2021/12/GHSA-7c78-24gm-9rqf/GHSA-7c78-24gm-9rqf.json index c040449988b..77d9b9081a0 100644 --- a/advisories/unreviewed/2021/12/GHSA-7c78-24gm-9rqf/GHSA-7c78-24gm-9rqf.json +++ b/advisories/unreviewed/2021/12/GHSA-7c78-24gm-9rqf/GHSA-7c78-24gm-9rqf.json @@ -7,12 +7,8 @@ "CVE-2021-43068" ], "details": "A improper authentication in Fortinet FortiAuthenticator version 6.4.0 allows user to bypass the second factor of authentication via a RADIUS login portal.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-7cw2-xhmh-jqc7/GHSA-7cw2-xhmh-jqc7.json b/advisories/unreviewed/2021/12/GHSA-7cw2-xhmh-jqc7/GHSA-7cw2-xhmh-jqc7.json index 6553d412c6e..bec4d302132 100644 --- a/advisories/unreviewed/2021/12/GHSA-7cw2-xhmh-jqc7/GHSA-7cw2-xhmh-jqc7.json +++ b/advisories/unreviewed/2021/12/GHSA-7cw2-xhmh-jqc7/GHSA-7cw2-xhmh-jqc7.json @@ -7,12 +7,8 @@ "CVE-2021-25520" ], "details": "Insecure caller check and input validation vulnerabilities in SearchKeyword deeplink logic prior to Samsung Internet 16.0.2 allows unstrusted applications to execute script codes in Samsung Internet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-7f2f-4pm3-cv4p/GHSA-7f2f-4pm3-cv4p.json b/advisories/unreviewed/2021/12/GHSA-7f2f-4pm3-cv4p/GHSA-7f2f-4pm3-cv4p.json index 12dcd8bd9de..a49fade23c0 100644 --- a/advisories/unreviewed/2021/12/GHSA-7f2f-4pm3-cv4p/GHSA-7f2f-4pm3-cv4p.json +++ b/advisories/unreviewed/2021/12/GHSA-7f2f-4pm3-cv4p/GHSA-7f2f-4pm3-cv4p.json @@ -7,12 +7,8 @@ "CVE-2020-27416" ], "details": "Mahavitaran android application 7.50 and prior are affected by account takeover due to improper OTP validation, allows remote attackers to control a users account.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-7ghq-32xm-6hpm/GHSA-7ghq-32xm-6hpm.json b/advisories/unreviewed/2021/12/GHSA-7ghq-32xm-6hpm/GHSA-7ghq-32xm-6hpm.json index ff599938af0..ec3d5fcefbf 100644 --- a/advisories/unreviewed/2021/12/GHSA-7ghq-32xm-6hpm/GHSA-7ghq-32xm-6hpm.json +++ b/advisories/unreviewed/2021/12/GHSA-7ghq-32xm-6hpm/GHSA-7ghq-32xm-6hpm.json @@ -7,12 +7,8 @@ "CVE-2021-25510" ], "details": "An improper validation vulnerability in FilterProvider prior to SMR Dec-2021 Release 1 allows local arbitrary code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-7h9v-7266-h9v7/GHSA-7h9v-7266-h9v7.json b/advisories/unreviewed/2021/12/GHSA-7h9v-7266-h9v7/GHSA-7h9v-7266-h9v7.json index 3427436da53..571adac0642 100644 --- a/advisories/unreviewed/2021/12/GHSA-7h9v-7266-h9v7/GHSA-7h9v-7266-h9v7.json +++ b/advisories/unreviewed/2021/12/GHSA-7h9v-7266-h9v7/GHSA-7h9v-7266-h9v7.json @@ -7,12 +7,8 @@ "CVE-2021-44041" ], "details": "UiPath Assistant 21.4.4 will load and execute attacker controlled data from the file path supplied to the --dev-widget argument of the URI handler for uipath-assistant://. This allows an attacker to execute code on a victim's machine or capture NTLM credentials by supplying a networked or WebDAV file path.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-7pv6-jghj-vwmc/GHSA-7pv6-jghj-vwmc.json b/advisories/unreviewed/2021/12/GHSA-7pv6-jghj-vwmc/GHSA-7pv6-jghj-vwmc.json index 5f362d93122..88bbfa2ab75 100644 --- a/advisories/unreviewed/2021/12/GHSA-7pv6-jghj-vwmc/GHSA-7pv6-jghj-vwmc.json +++ b/advisories/unreviewed/2021/12/GHSA-7pv6-jghj-vwmc/GHSA-7pv6-jghj-vwmc.json @@ -7,12 +7,8 @@ "CVE-2021-24863" ], "details": "The WP Block and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection Plugin StopBadBots WordPress plugin before 6.67 does not sanitise and escape the User Agent before using it in a SQL statement to save it, leading to a SQL injection", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-7qvh-g2f7-ww52/GHSA-7qvh-g2f7-ww52.json b/advisories/unreviewed/2021/12/GHSA-7qvh-g2f7-ww52/GHSA-7qvh-g2f7-ww52.json index 255cfe1baa2..6d86dfbbbce 100644 --- a/advisories/unreviewed/2021/12/GHSA-7qvh-g2f7-ww52/GHSA-7qvh-g2f7-ww52.json +++ b/advisories/unreviewed/2021/12/GHSA-7qvh-g2f7-ww52/GHSA-7qvh-g2f7-ww52.json @@ -7,12 +7,8 @@ "CVE-2021-25511" ], "details": "An improper validation vulnerability in FilterProvider prior to SMR Dec-2021 Release 1 allows attackers to write arbitrary files via a path traversal vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-7rr4-2h5v-8fm6/GHSA-7rr4-2h5v-8fm6.json b/advisories/unreviewed/2021/12/GHSA-7rr4-2h5v-8fm6/GHSA-7rr4-2h5v-8fm6.json index f9aa21a7126..6d13195a9b6 100644 --- a/advisories/unreviewed/2021/12/GHSA-7rr4-2h5v-8fm6/GHSA-7rr4-2h5v-8fm6.json +++ b/advisories/unreviewed/2021/12/GHSA-7rr4-2h5v-8fm6/GHSA-7rr4-2h5v-8fm6.json @@ -7,12 +7,8 @@ "CVE-2021-3370" ], "details": "DouPHP v1.6 was discovered to contain a cross-site scripting (XSS) vulnerability via /admin/cloud.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-7w2r-8gq9-28xx/GHSA-7w2r-8gq9-28xx.json b/advisories/unreviewed/2021/12/GHSA-7w2r-8gq9-28xx/GHSA-7w2r-8gq9-28xx.json index 4ad2a049a12..2c536c9b583 100644 --- a/advisories/unreviewed/2021/12/GHSA-7w2r-8gq9-28xx/GHSA-7w2r-8gq9-28xx.json +++ b/advisories/unreviewed/2021/12/GHSA-7w2r-8gq9-28xx/GHSA-7w2r-8gq9-28xx.json @@ -7,12 +7,8 @@ "CVE-2021-43544" ], "details": "When receiving a URL through a SEND intent, Firefox would have searched for the text, but subsequent usages of the address bar might have caused the URL to load unintentionally, which could lead to XSS and spoofing attacks. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 95.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-7ww6-pfhx-xq3v/GHSA-7ww6-pfhx-xq3v.json b/advisories/unreviewed/2021/12/GHSA-7ww6-pfhx-xq3v/GHSA-7ww6-pfhx-xq3v.json index f54802fd537..7f4f8657133 100644 --- a/advisories/unreviewed/2021/12/GHSA-7ww6-pfhx-xq3v/GHSA-7ww6-pfhx-xq3v.json +++ b/advisories/unreviewed/2021/12/GHSA-7ww6-pfhx-xq3v/GHSA-7ww6-pfhx-xq3v.json @@ -7,12 +7,8 @@ "CVE-2021-24795" ], "details": "The Filter Portfolio Gallery WordPress plugin through 1.5 is lacking Cross-Site Request Forgery (CSRF) check when deleting a Gallery, which could allow attackers to make a logged in admin delete arbitrary Gallery.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-7x28-3j26-66f5/GHSA-7x28-3j26-66f5.json b/advisories/unreviewed/2021/12/GHSA-7x28-3j26-66f5/GHSA-7x28-3j26-66f5.json index 1ef8a28ecc8..2b629689087 100644 --- a/advisories/unreviewed/2021/12/GHSA-7x28-3j26-66f5/GHSA-7x28-3j26-66f5.json +++ b/advisories/unreviewed/2021/12/GHSA-7x28-3j26-66f5/GHSA-7x28-3j26-66f5.json @@ -7,12 +7,8 @@ "CVE-2021-24922" ], "details": "The Pixel Cat WordPress plugin before 2.6.2 does not have CSRF check when saving its settings, and did not sanitise as well as escape some of them, which could allow attacker to make a logged in admin change them and perform Cross-Site Scripting attacks", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-823p-4g73-2fv5/GHSA-823p-4g73-2fv5.json b/advisories/unreviewed/2021/12/GHSA-823p-4g73-2fv5/GHSA-823p-4g73-2fv5.json index 5b50411a2a8..1dabc5aa1ab 100644 --- a/advisories/unreviewed/2021/12/GHSA-823p-4g73-2fv5/GHSA-823p-4g73-2fv5.json +++ b/advisories/unreviewed/2021/12/GHSA-823p-4g73-2fv5/GHSA-823p-4g73-2fv5.json @@ -7,12 +7,8 @@ "CVE-2021-42547" ], "details": "Insufficient Input Validation in the search functionality of Wordpress plugin Out-of-the-Box prior to 1.20.3 allows unauthenticated user to craft a reflected Cross-Site Scripting attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-82fw-x9gr-vc6q/GHSA-82fw-x9gr-vc6q.json b/advisories/unreviewed/2021/12/GHSA-82fw-x9gr-vc6q/GHSA-82fw-x9gr-vc6q.json index e5b48bba440..553297abce9 100644 --- a/advisories/unreviewed/2021/12/GHSA-82fw-x9gr-vc6q/GHSA-82fw-x9gr-vc6q.json +++ b/advisories/unreviewed/2021/12/GHSA-82fw-x9gr-vc6q/GHSA-82fw-x9gr-vc6q.json @@ -7,12 +7,8 @@ "CVE-2021-20138" ], "details": "An unauthenticated command injection vulnerability exists in multiple parameters in the Gryphon Tower router’s web interface at /cgi-bin/luci/rc. An unauthenticated remote attacker on the same network can execute commands as root on the device by sending a specially crafted malicious packet to the web interface.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-853q-qp3f-8m3v/GHSA-853q-qp3f-8m3v.json b/advisories/unreviewed/2021/12/GHSA-853q-qp3f-8m3v/GHSA-853q-qp3f-8m3v.json index 4fd329aa17c..4ccf045789a 100644 --- a/advisories/unreviewed/2021/12/GHSA-853q-qp3f-8m3v/GHSA-853q-qp3f-8m3v.json +++ b/advisories/unreviewed/2021/12/GHSA-853q-qp3f-8m3v/GHSA-853q-qp3f-8m3v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-857m-46rq-rj5c/GHSA-857m-46rq-rj5c.json b/advisories/unreviewed/2021/12/GHSA-857m-46rq-rj5c/GHSA-857m-46rq-rj5c.json index a22f56ce328..14282ba3d46 100644 --- a/advisories/unreviewed/2021/12/GHSA-857m-46rq-rj5c/GHSA-857m-46rq-rj5c.json +++ b/advisories/unreviewed/2021/12/GHSA-857m-46rq-rj5c/GHSA-857m-46rq-rj5c.json @@ -7,12 +7,8 @@ "CVE-2021-20043" ], "details": "A Heap-based buffer overflow vulnerability in SonicWall SMA100 getBookmarks method allows a remote authenticated attacker to potentially execute code as the nobody user in the appliance. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-85xx-79fp-6rmf/GHSA-85xx-79fp-6rmf.json b/advisories/unreviewed/2021/12/GHSA-85xx-79fp-6rmf/GHSA-85xx-79fp-6rmf.json index 4cce7dff9ea..b23992cf616 100644 --- a/advisories/unreviewed/2021/12/GHSA-85xx-79fp-6rmf/GHSA-85xx-79fp-6rmf.json +++ b/advisories/unreviewed/2021/12/GHSA-85xx-79fp-6rmf/GHSA-85xx-79fp-6rmf.json @@ -7,12 +7,8 @@ "CVE-2021-42758" ], "details": "An improper access control vulnerability [CWE-284] in FortiWLC 8.6.1 and below may allow an authenticated and remote attacker with low privileges to execute any command as an admin user with full access rights via bypassing the GUI restrictions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-86j2-r9c9-2h84/GHSA-86j2-r9c9-2h84.json b/advisories/unreviewed/2021/12/GHSA-86j2-r9c9-2h84/GHSA-86j2-r9c9-2h84.json index 9c707af6393..4777bad6f58 100644 --- a/advisories/unreviewed/2021/12/GHSA-86j2-r9c9-2h84/GHSA-86j2-r9c9-2h84.json +++ b/advisories/unreviewed/2021/12/GHSA-86j2-r9c9-2h84/GHSA-86j2-r9c9-2h84.json @@ -7,12 +7,8 @@ "CVE-2021-39917" ], "details": "An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.9 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. A regular expression related to quick actions features was susceptible to catastrophic backtracking that could cause a DOS attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-8737-w627-mrv7/GHSA-8737-w627-mrv7.json b/advisories/unreviewed/2021/12/GHSA-8737-w627-mrv7/GHSA-8737-w627-mrv7.json index 2ffd44d756b..037a8689e04 100644 --- a/advisories/unreviewed/2021/12/GHSA-8737-w627-mrv7/GHSA-8737-w627-mrv7.json +++ b/advisories/unreviewed/2021/12/GHSA-8737-w627-mrv7/GHSA-8737-w627-mrv7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-8885-3g6h-5g9c/GHSA-8885-3g6h-5g9c.json b/advisories/unreviewed/2021/12/GHSA-8885-3g6h-5g9c/GHSA-8885-3g6h-5g9c.json index ef6684c54bb..85d8799b682 100644 --- a/advisories/unreviewed/2021/12/GHSA-8885-3g6h-5g9c/GHSA-8885-3g6h-5g9c.json +++ b/advisories/unreviewed/2021/12/GHSA-8885-3g6h-5g9c/GHSA-8885-3g6h-5g9c.json @@ -7,12 +7,8 @@ "CVE-2021-43063" ], "details": "A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.3.15 and below, version 6.2.6 and below allows attacker to execute unauthorized code or commands via crafted HTTP GET requests to the login webpage.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-898q-2c92-wcv4/GHSA-898q-2c92-wcv4.json b/advisories/unreviewed/2021/12/GHSA-898q-2c92-wcv4/GHSA-898q-2c92-wcv4.json index 895da8e2d86..f254baa4208 100644 --- a/advisories/unreviewed/2021/12/GHSA-898q-2c92-wcv4/GHSA-898q-2c92-wcv4.json +++ b/advisories/unreviewed/2021/12/GHSA-898q-2c92-wcv4/GHSA-898q-2c92-wcv4.json @@ -7,12 +7,8 @@ "CVE-2021-25514" ], "details": "An improper intent redirection handling in Tags prior to SMR Dec-2021 Release 1 allows attackers to access sensitive information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2021/12/GHSA-8cmg-w5hw-x6p6/GHSA-8cmg-w5hw-x6p6.json b/advisories/unreviewed/2021/12/GHSA-8cmg-w5hw-x6p6/GHSA-8cmg-w5hw-x6p6.json index a520ccd2cf1..aa50ad1b8a3 100644 --- a/advisories/unreviewed/2021/12/GHSA-8cmg-w5hw-x6p6/GHSA-8cmg-w5hw-x6p6.json +++ b/advisories/unreviewed/2021/12/GHSA-8cmg-w5hw-x6p6/GHSA-8cmg-w5hw-x6p6.json @@ -7,12 +7,8 @@ "CVE-2021-24946" ], "details": "The Modern Events Calendar Lite WordPress plugin before 6.1.5 does not sanitise and escape the time parameter before using it in a SQL statement in the mec_load_single_page AJAX action, available to unauthenticated users, leading to an unauthenticated SQL injection issue", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-8pg9-567c-mmc6/GHSA-8pg9-567c-mmc6.json b/advisories/unreviewed/2021/12/GHSA-8pg9-567c-mmc6/GHSA-8pg9-567c-mmc6.json index f68f74b5870..1b20fd6b84e 100644 --- a/advisories/unreviewed/2021/12/GHSA-8pg9-567c-mmc6/GHSA-8pg9-567c-mmc6.json +++ b/advisories/unreviewed/2021/12/GHSA-8pg9-567c-mmc6/GHSA-8pg9-567c-mmc6.json @@ -7,12 +7,8 @@ "CVE-2021-20045" ], "details": "A buffer overflow vulnerability in SMA100 sonicfiles RAC_COPY_TO (RacNumber 36) method allows a remote unauthenticated attacker to potentially execute code as the 'nobody' user in the appliance. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-8qrv-qg3h-g8m6/GHSA-8qrv-qg3h-g8m6.json b/advisories/unreviewed/2021/12/GHSA-8qrv-qg3h-g8m6/GHSA-8qrv-qg3h-g8m6.json index d9cc28e0880..63597f4bdc3 100644 --- a/advisories/unreviewed/2021/12/GHSA-8qrv-qg3h-g8m6/GHSA-8qrv-qg3h-g8m6.json +++ b/advisories/unreviewed/2021/12/GHSA-8qrv-qg3h-g8m6/GHSA-8qrv-qg3h-g8m6.json @@ -7,12 +7,8 @@ "CVE-2021-26340" ], "details": "A malicious hypervisor in conjunction with an unprivileged attacker process inside an SEV/SEV-ES guest VM may fail to flush the Translation Lookaside Buffer (TLB) resulting in unexpected behavior inside the virtual machine (VM).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2021/12/GHSA-8w7p-v3p3-2mrj/GHSA-8w7p-v3p3-2mrj.json b/advisories/unreviewed/2021/12/GHSA-8w7p-v3p3-2mrj/GHSA-8w7p-v3p3-2mrj.json index 7c1e790807c..fffdb2ad656 100644 --- a/advisories/unreviewed/2021/12/GHSA-8w7p-v3p3-2mrj/GHSA-8w7p-v3p3-2mrj.json +++ b/advisories/unreviewed/2021/12/GHSA-8w7p-v3p3-2mrj/GHSA-8w7p-v3p3-2mrj.json @@ -7,12 +7,8 @@ "CVE-2021-32024" ], "details": "A remote code execution vulnerability in the BMP image codec of BlackBerry QNX SDP version(s) 6.4 to 7.1 could allow an attacker to potentially execute code in the context of the affected process.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2021/12/GHSA-8xmf-g2gr-jr5w/GHSA-8xmf-g2gr-jr5w.json b/advisories/unreviewed/2021/12/GHSA-8xmf-g2gr-jr5w/GHSA-8xmf-g2gr-jr5w.json index 91db71c09f4..18209c83889 100644 --- a/advisories/unreviewed/2021/12/GHSA-8xmf-g2gr-jr5w/GHSA-8xmf-g2gr-jr5w.json +++ b/advisories/unreviewed/2021/12/GHSA-8xmf-g2gr-jr5w/GHSA-8xmf-g2gr-jr5w.json @@ -7,12 +7,8 @@ "CVE-2021-39054" ], "details": "IBM Spectrum Copy Data Management 2.2.13 and earlier could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 214525.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-93p6-c827-87mm/GHSA-93p6-c827-87mm.json b/advisories/unreviewed/2021/12/GHSA-93p6-c827-87mm/GHSA-93p6-c827-87mm.json index 1c6ac75197e..6a212059583 100644 --- a/advisories/unreviewed/2021/12/GHSA-93p6-c827-87mm/GHSA-93p6-c827-87mm.json +++ b/advisories/unreviewed/2021/12/GHSA-93p6-c827-87mm/GHSA-93p6-c827-87mm.json @@ -7,12 +7,8 @@ "CVE-2021-37934" ], "details": "Due to insufficient server-side login-attempt limit enforcement, a vulnerability in /account/login in Huntflow Enterprise before 3.10.14 could allow an unauthenticated, remote user to perform multiple login attempts for brute-force password guessing.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-94p6-v23w-67wg/GHSA-94p6-v23w-67wg.json b/advisories/unreviewed/2021/12/GHSA-94p6-v23w-67wg/GHSA-94p6-v23w-67wg.json index 0fc03ce14c9..bc0f2447b58 100644 --- a/advisories/unreviewed/2021/12/GHSA-94p6-v23w-67wg/GHSA-94p6-v23w-67wg.json +++ b/advisories/unreviewed/2021/12/GHSA-94p6-v23w-67wg/GHSA-94p6-v23w-67wg.json @@ -7,12 +7,8 @@ "CVE-2021-42760" ], "details": "A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWLM version 8.6.1 and below allows attacker to disclose sensitive information from DB tables via crafted requests.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-96xv-6m77-v224/GHSA-96xv-6m77-v224.json b/advisories/unreviewed/2021/12/GHSA-96xv-6m77-v224/GHSA-96xv-6m77-v224.json index 7efb4fa45b0..94a9e16b37c 100644 --- a/advisories/unreviewed/2021/12/GHSA-96xv-6m77-v224/GHSA-96xv-6m77-v224.json +++ b/advisories/unreviewed/2021/12/GHSA-96xv-6m77-v224/GHSA-96xv-6m77-v224.json @@ -7,12 +7,8 @@ "CVE-2021-44153" ], "details": "An issue was discovered in Reprise RLM 14.2. When editing the license file, it is possible for an admin user to enable an option to run arbitrary executables, as demonstrated by an ISV demo \"C:\\Windows\\System32\\calc.exe\" entry. An attacker can exploit this to run a malicious binary on startup, or when triggering the Reread/Restart Servers function on the webserver. (Exploitation does not require CVE-2018-15573, because the license file is meant to be changed in the application.)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2021/12/GHSA-9c2c-v6c7-rjgv/GHSA-9c2c-v6c7-rjgv.json b/advisories/unreviewed/2021/12/GHSA-9c2c-v6c7-rjgv/GHSA-9c2c-v6c7-rjgv.json index 6360c46a66f..8c0bfdbe3eb 100644 --- a/advisories/unreviewed/2021/12/GHSA-9c2c-v6c7-rjgv/GHSA-9c2c-v6c7-rjgv.json +++ b/advisories/unreviewed/2021/12/GHSA-9c2c-v6c7-rjgv/GHSA-9c2c-v6c7-rjgv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-9h5m-38gw-j896/GHSA-9h5m-38gw-j896.json b/advisories/unreviewed/2021/12/GHSA-9h5m-38gw-j896/GHSA-9h5m-38gw-j896.json index 8f64cd41eae..0385e2b50cb 100644 --- a/advisories/unreviewed/2021/12/GHSA-9h5m-38gw-j896/GHSA-9h5m-38gw-j896.json +++ b/advisories/unreviewed/2021/12/GHSA-9h5m-38gw-j896/GHSA-9h5m-38gw-j896.json @@ -7,12 +7,8 @@ "CVE-2021-26109" ], "details": "An integer overflow or wraparound vulnerability in the memory allocator of SSLVPN in FortiOS before 7.0.1 may allow an unauthenticated attacker to corrupt control data on the heap via specifically crafted requests to SSLVPN, resulting in potentially arbitrary code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-9h7c-fm35-pjfg/GHSA-9h7c-fm35-pjfg.json b/advisories/unreviewed/2021/12/GHSA-9h7c-fm35-pjfg/GHSA-9h7c-fm35-pjfg.json index 78e20535500..5e7c3fc6066 100644 --- a/advisories/unreviewed/2021/12/GHSA-9h7c-fm35-pjfg/GHSA-9h7c-fm35-pjfg.json +++ b/advisories/unreviewed/2021/12/GHSA-9h7c-fm35-pjfg/GHSA-9h7c-fm35-pjfg.json @@ -7,12 +7,8 @@ "CVE-2021-41065" ], "details": "An issue was discovered in Listary through 6. An attacker can create a \\\\.\\pipe\\Listary.listaryService named pipe and wait for a privileged user to open a session on the Listary installed host. Listary will automatically access the named pipe and the attacker will be able to duplicate the victim's token to impersonate him. This exploit is valid in certain Windows versions (Microsoft has patched the issue in later Windows 10 builds).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-9jvc-93xj-9mfg/GHSA-9jvc-93xj-9mfg.json b/advisories/unreviewed/2021/12/GHSA-9jvc-93xj-9mfg/GHSA-9jvc-93xj-9mfg.json index 81727275fcd..aec109beb89 100644 --- a/advisories/unreviewed/2021/12/GHSA-9jvc-93xj-9mfg/GHSA-9jvc-93xj-9mfg.json +++ b/advisories/unreviewed/2021/12/GHSA-9jvc-93xj-9mfg/GHSA-9jvc-93xj-9mfg.json @@ -7,12 +7,8 @@ "CVE-2021-39939" ], "details": "An uncontrolled resource consumption vulnerability in GitLab Runner affecting all versions starting from 13.7 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker triggering a job with a specially crafted docker image to exhaust resources on runner manager", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-9mhg-328h-2hfr/GHSA-9mhg-328h-2hfr.json b/advisories/unreviewed/2021/12/GHSA-9mhg-328h-2hfr/GHSA-9mhg-328h-2hfr.json index 0624aa1b19a..fcb60ac1585 100644 --- a/advisories/unreviewed/2021/12/GHSA-9mhg-328h-2hfr/GHSA-9mhg-328h-2hfr.json +++ b/advisories/unreviewed/2021/12/GHSA-9mhg-328h-2hfr/GHSA-9mhg-328h-2hfr.json @@ -7,12 +7,8 @@ "CVE-2021-39918" ], "details": "Incorrect Authorization in GitLab EE affecting all versions starting from 11.1 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows a user to add comments to a vulnerability which cannot be accessed.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-9p7p-4ghr-x9cx/GHSA-9p7p-4ghr-x9cx.json b/advisories/unreviewed/2021/12/GHSA-9p7p-4ghr-x9cx/GHSA-9p7p-4ghr-x9cx.json index bece20e644d..574eebe5b68 100644 --- a/advisories/unreviewed/2021/12/GHSA-9p7p-4ghr-x9cx/GHSA-9p7p-4ghr-x9cx.json +++ b/advisories/unreviewed/2021/12/GHSA-9p7p-4ghr-x9cx/GHSA-9p7p-4ghr-x9cx.json @@ -7,12 +7,8 @@ "CVE-2021-24747" ], "details": "The SEO Booster WordPress plugin through 3.7 allows for authenticated SQL injection via the \"fn_my_ajaxified_dataloader_ajax\" AJAX request as the $_REQUEST['order'][0]['dir'] parameter is not properly escaped leading to blind and error-based SQL injections.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-9qcg-w23p-8gwc/GHSA-9qcg-w23p-8gwc.json b/advisories/unreviewed/2021/12/GHSA-9qcg-w23p-8gwc/GHSA-9qcg-w23p-8gwc.json index 5bdf2b68818..f71b31692e4 100644 --- a/advisories/unreviewed/2021/12/GHSA-9qcg-w23p-8gwc/GHSA-9qcg-w23p-8gwc.json +++ b/advisories/unreviewed/2021/12/GHSA-9qcg-w23p-8gwc/GHSA-9qcg-w23p-8gwc.json @@ -7,12 +7,8 @@ "CVE-2021-44043" ], "details": "An issue was discovered in UiPath App Studio 21.4.4. There is a persistent XSS vulnerability in the file-upload functionality for uploading icons when attempting to create new Apps. An attacker with minimal privileges in the application can build their own App and upload a malicious file containing an XSS payload, by uploading an arbitrary file and modifying the MIME type in a subsequent HTTP request. This then allows the file to be stored and retrieved from the server by other users in the same organization.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-9w6r-rp23-g8hv/GHSA-9w6r-rp23-g8hv.json b/advisories/unreviewed/2021/12/GHSA-9w6r-rp23-g8hv/GHSA-9w6r-rp23-g8hv.json index e7140b41d2f..d5bfc1421a5 100644 --- a/advisories/unreviewed/2021/12/GHSA-9w6r-rp23-g8hv/GHSA-9w6r-rp23-g8hv.json +++ b/advisories/unreviewed/2021/12/GHSA-9w6r-rp23-g8hv/GHSA-9w6r-rp23-g8hv.json @@ -7,12 +7,8 @@ "CVE-2021-40858" ], "details": "Auerswald COMpact 5500R devices before 8.2B allow Arbitrary File Disclosure. A sub-admin can read the cleartext Admin password via the fileName=../../etc/passwd substring.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-9xfx-427g-vgqq/GHSA-9xfx-427g-vgqq.json b/advisories/unreviewed/2021/12/GHSA-9xfx-427g-vgqq/GHSA-9xfx-427g-vgqq.json index 8697d566c25..094fdf67a5a 100644 --- a/advisories/unreviewed/2021/12/GHSA-9xfx-427g-vgqq/GHSA-9xfx-427g-vgqq.json +++ b/advisories/unreviewed/2021/12/GHSA-9xfx-427g-vgqq/GHSA-9xfx-427g-vgqq.json @@ -7,12 +7,8 @@ "CVE-2021-24932" ], "details": "The Auto Featured Image (Auto Post Thumbnail) WordPress plugin before 3.9.3 does not sanitise and escape the post_id parameter before outputting back in an admin page within a JS block, leading to a Reflected Cross-Site Scripting issue.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-9xv2-8g99-6925/GHSA-9xv2-8g99-6925.json b/advisories/unreviewed/2021/12/GHSA-9xv2-8g99-6925/GHSA-9xv2-8g99-6925.json index f4e97b69d1d..78c43c48244 100644 --- a/advisories/unreviewed/2021/12/GHSA-9xv2-8g99-6925/GHSA-9xv2-8g99-6925.json +++ b/advisories/unreviewed/2021/12/GHSA-9xv2-8g99-6925/GHSA-9xv2-8g99-6925.json @@ -7,12 +7,8 @@ "CVE-2021-39941" ], "details": "An information disclosure vulnerability in GitLab CE/EE versions 12.0 to 14.3.6, 14.4 to 14.4.4, and 14.5 to 14.5.2 allowed non-project members to see the default branch name for projects that restrict access to the repository to project members", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-c59j-qqg4-j885/GHSA-c59j-qqg4-j885.json b/advisories/unreviewed/2021/12/GHSA-c59j-qqg4-j885/GHSA-c59j-qqg4-j885.json index 51b65b01d94..042678bd715 100644 --- a/advisories/unreviewed/2021/12/GHSA-c59j-qqg4-j885/GHSA-c59j-qqg4-j885.json +++ b/advisories/unreviewed/2021/12/GHSA-c59j-qqg4-j885/GHSA-c59j-qqg4-j885.json @@ -7,12 +7,8 @@ "CVE-2021-40883" ], "details": "A Remote Code Execution (RCE) vulnerability exists in emlog 5.3.1 via content/plugins.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-c9jx-56c3-85wf/GHSA-c9jx-56c3-85wf.json b/advisories/unreviewed/2021/12/GHSA-c9jx-56c3-85wf/GHSA-c9jx-56c3-85wf.json index 48d5d4126dc..abd41f350eb 100644 --- a/advisories/unreviewed/2021/12/GHSA-c9jx-56c3-85wf/GHSA-c9jx-56c3-85wf.json +++ b/advisories/unreviewed/2021/12/GHSA-c9jx-56c3-85wf/GHSA-c9jx-56c3-85wf.json @@ -7,12 +7,8 @@ "CVE-2021-44833" ], "details": "The CLI 1.0.0 for Amazon AWS OpenSearch has weak permissions for the configuration file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-c9pf-3r6r-m8r5/GHSA-c9pf-3r6r-m8r5.json b/advisories/unreviewed/2021/12/GHSA-c9pf-3r6r-m8r5/GHSA-c9pf-3r6r-m8r5.json index 587f86c03b9..d238cbbd665 100644 --- a/advisories/unreviewed/2021/12/GHSA-c9pf-3r6r-m8r5/GHSA-c9pf-3r6r-m8r5.json +++ b/advisories/unreviewed/2021/12/GHSA-c9pf-3r6r-m8r5/GHSA-c9pf-3r6r-m8r5.json @@ -7,12 +7,8 @@ "CVE-2021-24970" ], "details": "The All-in-One Video Gallery WordPress plugin before 2.5.0 does not sanitise and validate the tab parameter before using it in a require statement in the admin dashboard, leading to a Local File Inclusion issue", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-c9xv-q798-33wg/GHSA-c9xv-q798-33wg.json b/advisories/unreviewed/2021/12/GHSA-c9xv-q798-33wg/GHSA-c9xv-q798-33wg.json index 357421076b5..bff1cc5a837 100644 --- a/advisories/unreviewed/2021/12/GHSA-c9xv-q798-33wg/GHSA-c9xv-q798-33wg.json +++ b/advisories/unreviewed/2021/12/GHSA-c9xv-q798-33wg/GHSA-c9xv-q798-33wg.json @@ -7,12 +7,8 @@ "CVE-2021-24951" ], "details": "The LearnPress WordPress plugin before 4.1.4 does not sanitise, validate and escape the id parameter before using it in SQL statements when duplicating course/lesson/quiz/question, leading to SQL Injections issues", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-cc75-w727-3jqw/GHSA-cc75-w727-3jqw.json b/advisories/unreviewed/2021/12/GHSA-cc75-w727-3jqw/GHSA-cc75-w727-3jqw.json index e3596ce2f04..84321a62f77 100644 --- a/advisories/unreviewed/2021/12/GHSA-cc75-w727-3jqw/GHSA-cc75-w727-3jqw.json +++ b/advisories/unreviewed/2021/12/GHSA-cc75-w727-3jqw/GHSA-cc75-w727-3jqw.json @@ -7,12 +7,8 @@ "CVE-2021-39944" ], "details": "An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. A permissions validation flaw allowed group members with a developer role to elevate their privilege to a maintainer on projects they import", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-cc82-9xq4-fr7x/GHSA-cc82-9xq4-fr7x.json b/advisories/unreviewed/2021/12/GHSA-cc82-9xq4-fr7x/GHSA-cc82-9xq4-fr7x.json index 902cf33c989..6997345d791 100644 --- a/advisories/unreviewed/2021/12/GHSA-cc82-9xq4-fr7x/GHSA-cc82-9xq4-fr7x.json +++ b/advisories/unreviewed/2021/12/GHSA-cc82-9xq4-fr7x/GHSA-cc82-9xq4-fr7x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-ccc8-q55j-mm8v/GHSA-ccc8-q55j-mm8v.json b/advisories/unreviewed/2021/12/GHSA-ccc8-q55j-mm8v/GHSA-ccc8-q55j-mm8v.json index a4d0fc8dbc5..3d8c3ccada1 100644 --- a/advisories/unreviewed/2021/12/GHSA-ccc8-q55j-mm8v/GHSA-ccc8-q55j-mm8v.json +++ b/advisories/unreviewed/2021/12/GHSA-ccc8-q55j-mm8v/GHSA-ccc8-q55j-mm8v.json @@ -7,12 +7,8 @@ "CVE-2021-38931" ], "details": "IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1, and 11.5 is vulnerable to an information disclosure as a result of a connected user having indirect read access to a table where they are not authorized to select from. IBM X-Force ID: 210418.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-cq92-gcq7-fwfg/GHSA-cq92-gcq7-fwfg.json b/advisories/unreviewed/2021/12/GHSA-cq92-gcq7-fwfg/GHSA-cq92-gcq7-fwfg.json index 2d6440abaf1..929490312e6 100644 --- a/advisories/unreviewed/2021/12/GHSA-cq92-gcq7-fwfg/GHSA-cq92-gcq7-fwfg.json +++ b/advisories/unreviewed/2021/12/GHSA-cq92-gcq7-fwfg/GHSA-cq92-gcq7-fwfg.json @@ -7,12 +7,8 @@ "CVE-2021-25523" ], "details": "Insecure storage of device information in Samsung Dialer prior to version 12.7.05.24 allows attacker to get Samsung Account ID.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-crxx-35wq-w63c/GHSA-crxx-35wq-w63c.json b/advisories/unreviewed/2021/12/GHSA-crxx-35wq-w63c/GHSA-crxx-35wq-w63c.json index 7b578172778..f8a399ed028 100644 --- a/advisories/unreviewed/2021/12/GHSA-crxx-35wq-w63c/GHSA-crxx-35wq-w63c.json +++ b/advisories/unreviewed/2021/12/GHSA-crxx-35wq-w63c/GHSA-crxx-35wq-w63c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-cv28-8pqv-x45p/GHSA-cv28-8pqv-x45p.json b/advisories/unreviewed/2021/12/GHSA-cv28-8pqv-x45p/GHSA-cv28-8pqv-x45p.json index ec65c01f141..d3d27300b03 100644 --- a/advisories/unreviewed/2021/12/GHSA-cv28-8pqv-x45p/GHSA-cv28-8pqv-x45p.json +++ b/advisories/unreviewed/2021/12/GHSA-cv28-8pqv-x45p/GHSA-cv28-8pqv-x45p.json @@ -7,12 +7,8 @@ "CVE-2021-20867" ], "details": "Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing authorization vulnerability in moving the field group which may allow a user to move the unauthorized field group via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-cx3c-jf2w-95p5/GHSA-cx3c-jf2w-95p5.json b/advisories/unreviewed/2021/12/GHSA-cx3c-jf2w-95p5/GHSA-cx3c-jf2w-95p5.json index c9a8b6de34e..1e2a6706a31 100644 --- a/advisories/unreviewed/2021/12/GHSA-cx3c-jf2w-95p5/GHSA-cx3c-jf2w-95p5.json +++ b/advisories/unreviewed/2021/12/GHSA-cx3c-jf2w-95p5/GHSA-cx3c-jf2w-95p5.json @@ -7,12 +7,8 @@ "CVE-2021-43982" ], "details": "Delta Electronics CNCSoft Versions 1.01.30 and prior are vulnerable to a stack-based buffer overflow, which may allow an attacker to execute arbitrary code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-f2fc-p952-6xf6/GHSA-f2fc-p952-6xf6.json b/advisories/unreviewed/2021/12/GHSA-f2fc-p952-6xf6/GHSA-f2fc-p952-6xf6.json index 5736cf110dd..304615a3d36 100644 --- a/advisories/unreviewed/2021/12/GHSA-f2fc-p952-6xf6/GHSA-f2fc-p952-6xf6.json +++ b/advisories/unreviewed/2021/12/GHSA-f2fc-p952-6xf6/GHSA-f2fc-p952-6xf6.json @@ -7,12 +7,8 @@ "CVE-2021-20865" ], "details": "Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing authorization vulnerability in browsing database which may allow a user to browse unauthorized data via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-f8vh-ph3q-qhmc/GHSA-f8vh-ph3q-qhmc.json b/advisories/unreviewed/2021/12/GHSA-f8vh-ph3q-qhmc/GHSA-f8vh-ph3q-qhmc.json index 35e6106862a..d4b4ce7497e 100644 --- a/advisories/unreviewed/2021/12/GHSA-f8vh-ph3q-qhmc/GHSA-f8vh-ph3q-qhmc.json +++ b/advisories/unreviewed/2021/12/GHSA-f8vh-ph3q-qhmc/GHSA-f8vh-ph3q-qhmc.json @@ -7,12 +7,8 @@ "CVE-2021-20040" ], "details": "A relative path traversal vulnerability in the SMA100 upload funtion allows a remote unauthenticated attacker to upload crafted web pages or files as a 'nobody' user. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-f9ww-7rv4-vqfq/GHSA-f9ww-7rv4-vqfq.json b/advisories/unreviewed/2021/12/GHSA-f9ww-7rv4-vqfq/GHSA-f9ww-7rv4-vqfq.json index 86eda8706c2..6d156f364cd 100644 --- a/advisories/unreviewed/2021/12/GHSA-f9ww-7rv4-vqfq/GHSA-f9ww-7rv4-vqfq.json +++ b/advisories/unreviewed/2021/12/GHSA-f9ww-7rv4-vqfq/GHSA-f9ww-7rv4-vqfq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-ff2w-m935-v55x/GHSA-ff2w-m935-v55x.json b/advisories/unreviewed/2021/12/GHSA-ff2w-m935-v55x/GHSA-ff2w-m935-v55x.json index 52252cbb088..4ae58a19eee 100644 --- a/advisories/unreviewed/2021/12/GHSA-ff2w-m935-v55x/GHSA-ff2w-m935-v55x.json +++ b/advisories/unreviewed/2021/12/GHSA-ff2w-m935-v55x/GHSA-ff2w-m935-v55x.json @@ -7,12 +7,8 @@ "CVE-2021-41024" ], "details": "A relative path traversal [CWE-23] vulnerabiltiy in FortiOS versions 7.0.0 and 7.0.1 and FortiProxy verison 7.0.0 may allow an unauthenticated, unauthorized attacker to inject path traversal character sequences to disclose sensitive information of the server via the GET request of the login page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-fh7r-crx5-gjvh/GHSA-fh7r-crx5-gjvh.json b/advisories/unreviewed/2021/12/GHSA-fh7r-crx5-gjvh/GHSA-fh7r-crx5-gjvh.json index b38abcb7511..9c496ab2640 100644 --- a/advisories/unreviewed/2021/12/GHSA-fh7r-crx5-gjvh/GHSA-fh7r-crx5-gjvh.json +++ b/advisories/unreviewed/2021/12/GHSA-fh7r-crx5-gjvh/GHSA-fh7r-crx5-gjvh.json @@ -7,12 +7,8 @@ "CVE-2021-3829" ], "details": "openwhyd is vulnerable to URL Redirection to Untrusted Site", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-fhm6-4vjw-5xgx/GHSA-fhm6-4vjw-5xgx.json b/advisories/unreviewed/2021/12/GHSA-fhm6-4vjw-5xgx/GHSA-fhm6-4vjw-5xgx.json index b0b5d035989..a65a03afb4c 100644 --- a/advisories/unreviewed/2021/12/GHSA-fhm6-4vjw-5xgx/GHSA-fhm6-4vjw-5xgx.json +++ b/advisories/unreviewed/2021/12/GHSA-fhm6-4vjw-5xgx/GHSA-fhm6-4vjw-5xgx.json @@ -7,12 +7,8 @@ "CVE-2021-20044" ], "details": "A post-authentication remote command injection vulnerability in SonicWall SMA100 allows a remote authenticated attacker to execute OS system commands in the appliance. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-fjf7-cx66-jx8m/GHSA-fjf7-cx66-jx8m.json b/advisories/unreviewed/2021/12/GHSA-fjf7-cx66-jx8m/GHSA-fjf7-cx66-jx8m.json index 1378ce31e01..034fe9b4bbe 100644 --- a/advisories/unreviewed/2021/12/GHSA-fjf7-cx66-jx8m/GHSA-fjf7-cx66-jx8m.json +++ b/advisories/unreviewed/2021/12/GHSA-fjf7-cx66-jx8m/GHSA-fjf7-cx66-jx8m.json @@ -7,12 +7,8 @@ "CVE-2021-36188" ], "details": "A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows attacker to execute unauthorized code or commands via crafted GET parameters in requests to login and error handlers", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-fp4x-73jw-phj9/GHSA-fp4x-73jw-phj9.json b/advisories/unreviewed/2021/12/GHSA-fp4x-73jw-phj9/GHSA-fp4x-73jw-phj9.json index 47959a73bd9..4ab1de69b0c 100644 --- a/advisories/unreviewed/2021/12/GHSA-fp4x-73jw-phj9/GHSA-fp4x-73jw-phj9.json +++ b/advisories/unreviewed/2021/12/GHSA-fp4x-73jw-phj9/GHSA-fp4x-73jw-phj9.json @@ -7,12 +7,8 @@ "CVE-2021-24782" ], "details": "The Flex Local Fonts WordPress plugin through 1.0.0 does not escape the Class Name field when adding a font, which could allow hight privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-fpgv-9v95-hrgv/GHSA-fpgv-9v95-hrgv.json b/advisories/unreviewed/2021/12/GHSA-fpgv-9v95-hrgv/GHSA-fpgv-9v95-hrgv.json index d9d2321b0cc..ee600dda9a0 100644 --- a/advisories/unreviewed/2021/12/GHSA-fpgv-9v95-hrgv/GHSA-fpgv-9v95-hrgv.json +++ b/advisories/unreviewed/2021/12/GHSA-fpgv-9v95-hrgv/GHSA-fpgv-9v95-hrgv.json @@ -7,12 +7,8 @@ "CVE-2021-36191" ], "details": "A url redirection to untrusted site ('open redirect') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows attacker to use the device as proxy via crafted GET parameters in requests to error handlers", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-fqqh-g3vm-m5g2/GHSA-fqqh-g3vm-m5g2.json b/advisories/unreviewed/2021/12/GHSA-fqqh-g3vm-m5g2/GHSA-fqqh-g3vm-m5g2.json index cf215faeea6..372b53f032a 100644 --- a/advisories/unreviewed/2021/12/GHSA-fqqh-g3vm-m5g2/GHSA-fqqh-g3vm-m5g2.json +++ b/advisories/unreviewed/2021/12/GHSA-fqqh-g3vm-m5g2/GHSA-fqqh-g3vm-m5g2.json @@ -7,12 +7,8 @@ "CVE-2021-43204" ], "details": "A improper control of a resource through its lifetime in Fortinet FortiClientWindows version 6.4.1 and 6.4.0, version 6.2.9 and below, version 6.0.10 and below allows attacker to cause a complete denial of service of its components via changes of directory access permissions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2021/12/GHSA-frfh-3v2w-565j/GHSA-frfh-3v2w-565j.json b/advisories/unreviewed/2021/12/GHSA-frfh-3v2w-565j/GHSA-frfh-3v2w-565j.json index 2fe6e0da1d0..698dcea3f97 100644 --- a/advisories/unreviewed/2021/12/GHSA-frfh-3v2w-565j/GHSA-frfh-3v2w-565j.json +++ b/advisories/unreviewed/2021/12/GHSA-frfh-3v2w-565j/GHSA-frfh-3v2w-565j.json @@ -7,12 +7,8 @@ "CVE-2021-39049" ], "details": "IBM i2 Analyst's Notebook 9.2.0, 9.2.1, and 9.2.2 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local attacker could overflow a buffer and gain lower level privileges. IBM X-Force ID: 214439.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-fvw8-6hqj-qw58/GHSA-fvw8-6hqj-qw58.json b/advisories/unreviewed/2021/12/GHSA-fvw8-6hqj-qw58/GHSA-fvw8-6hqj-qw58.json index 17557ab3222..9ef387db764 100644 --- a/advisories/unreviewed/2021/12/GHSA-fvw8-6hqj-qw58/GHSA-fvw8-6hqj-qw58.json +++ b/advisories/unreviewed/2021/12/GHSA-fvw8-6hqj-qw58/GHSA-fvw8-6hqj-qw58.json @@ -7,12 +7,8 @@ "CVE-2021-44154" ], "details": "An issue was discovered in Reprise RLM 14.2. By using an admin account, an attacker can write a payload to /goform/edit_opt, which will then be triggered when running the diagnostics (via /goform/diagnostics_doit), resulting in a buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-fw34-2587-pprf/GHSA-fw34-2587-pprf.json b/advisories/unreviewed/2021/12/GHSA-fw34-2587-pprf/GHSA-fw34-2587-pprf.json index f3a99faf005..8dc5bbeb4b4 100644 --- a/advisories/unreviewed/2021/12/GHSA-fw34-2587-pprf/GHSA-fw34-2587-pprf.json +++ b/advisories/unreviewed/2021/12/GHSA-fw34-2587-pprf/GHSA-fw34-2587-pprf.json @@ -7,12 +7,8 @@ "CVE-2021-38505" ], "details": "Microsoft introduced a new feature in Windows 10 known as Cloud Clipboard which, if enabled, will record data copied to the clipboard to the cloud, and make it available on other computers in certain scenarios. Applications that wish to prevent copied data from being recorded in Cloud History must use specific clipboard formats; and Firefox before versions 94 and ESR 91.3 did not implement them. This could have caused sensitive data to be recorded to a user's Microsoft account. *This bug only affects Firefox for Windows 10+ with Cloud Clipboard enabled. Other operating systems are unaffected.*. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-g3q6-jxj3-44v3/GHSA-g3q6-jxj3-44v3.json b/advisories/unreviewed/2021/12/GHSA-g3q6-jxj3-44v3/GHSA-g3q6-jxj3-44v3.json index a2afa77a8ce..06492a6091d 100644 --- a/advisories/unreviewed/2021/12/GHSA-g3q6-jxj3-44v3/GHSA-g3q6-jxj3-44v3.json +++ b/advisories/unreviewed/2021/12/GHSA-g3q6-jxj3-44v3/GHSA-g3q6-jxj3-44v3.json @@ -7,12 +7,8 @@ "CVE-2021-41030" ], "details": "An authentication bypass by capture-replay vulnerability [CWE-294] in FortiClient EMS versions 7.0.1 and below and 6.4.4 and below may allow an unauthenticated attacker to impersonate an existing user by intercepting and re-using valid SAML authentication messages.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-g47m-f7f9-9p9x/GHSA-g47m-f7f9-9p9x.json b/advisories/unreviewed/2021/12/GHSA-g47m-f7f9-9p9x/GHSA-g47m-f7f9-9p9x.json index cf1565e1f65..21095b3e6d1 100644 --- a/advisories/unreviewed/2021/12/GHSA-g47m-f7f9-9p9x/GHSA-g47m-f7f9-9p9x.json +++ b/advisories/unreviewed/2021/12/GHSA-g47m-f7f9-9p9x/GHSA-g47m-f7f9-9p9x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-g8j3-2rcp-jrhm/GHSA-g8j3-2rcp-jrhm.json b/advisories/unreviewed/2021/12/GHSA-g8j3-2rcp-jrhm/GHSA-g8j3-2rcp-jrhm.json index 4e822da6aa5..61716864a2f 100644 --- a/advisories/unreviewed/2021/12/GHSA-g8j3-2rcp-jrhm/GHSA-g8j3-2rcp-jrhm.json +++ b/advisories/unreviewed/2021/12/GHSA-g8j3-2rcp-jrhm/GHSA-g8j3-2rcp-jrhm.json @@ -7,12 +7,8 @@ "CVE-2021-39938" ], "details": "A vulnerable regular expression pattern in GitLab CE/EE since version 8.15 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker to cause uncontrolled resource consumption leading to Denial of Service via specially crafted deploy Slash commands", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-gcpg-c569-xfr4/GHSA-gcpg-c569-xfr4.json b/advisories/unreviewed/2021/12/GHSA-gcpg-c569-xfr4/GHSA-gcpg-c569-xfr4.json index 4b90e3c230f..ea2d57e68b8 100644 --- a/advisories/unreviewed/2021/12/GHSA-gcpg-c569-xfr4/GHSA-gcpg-c569-xfr4.json +++ b/advisories/unreviewed/2021/12/GHSA-gcpg-c569-xfr4/GHSA-gcpg-c569-xfr4.json @@ -7,12 +7,8 @@ "CVE-2021-20866" ], "details": "Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing authorization vulnerability in obtaining the user list which may allow a user to obtain the unauthorized information via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-gfwx-7f38-2397/GHSA-gfwx-7f38-2397.json b/advisories/unreviewed/2021/12/GHSA-gfwx-7f38-2397/GHSA-gfwx-7f38-2397.json index 35fd9116e7e..b2ed87a7451 100644 --- a/advisories/unreviewed/2021/12/GHSA-gfwx-7f38-2397/GHSA-gfwx-7f38-2397.json +++ b/advisories/unreviewed/2021/12/GHSA-gfwx-7f38-2397/GHSA-gfwx-7f38-2397.json @@ -7,12 +7,8 @@ "CVE-2021-39930" ], "details": "Missing authorization in GitLab EE versions between 12.4 and 14.3.6, between 14.4.0 and 14.4.4, and between 14.5.0 and 14.5.2 allowed an attacker to access a user's custom project and group templates", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-gp35-882c-rhqq/GHSA-gp35-882c-rhqq.json b/advisories/unreviewed/2021/12/GHSA-gp35-882c-rhqq/GHSA-gp35-882c-rhqq.json index 6b0ebb64dbf..ff929c3a35b 100644 --- a/advisories/unreviewed/2021/12/GHSA-gp35-882c-rhqq/GHSA-gp35-882c-rhqq.json +++ b/advisories/unreviewed/2021/12/GHSA-gp35-882c-rhqq/GHSA-gp35-882c-rhqq.json @@ -7,12 +7,8 @@ "CVE-2021-24896" ], "details": "The Caldera Forms WordPress plugin before 1.9.5 does not sanitise and escape the Form Name before outputting it in attributes, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-h4m4-4f78-3cq7/GHSA-h4m4-4f78-3cq7.json b/advisories/unreviewed/2021/12/GHSA-h4m4-4f78-3cq7/GHSA-h4m4-4f78-3cq7.json index 4a0022d43bd..1849043665a 100644 --- a/advisories/unreviewed/2021/12/GHSA-h4m4-4f78-3cq7/GHSA-h4m4-4f78-3cq7.json +++ b/advisories/unreviewed/2021/12/GHSA-h4m4-4f78-3cq7/GHSA-h4m4-4f78-3cq7.json @@ -7,12 +7,8 @@ "CVE-2021-41449" ], "details": "A path traversal attack in web interfaces of Netgear RAX35, RAX38, and RAX40 routers before v1.0.4.102, allows a remote unauthenticated attacker to gain access to sensitive restricted information, such as forbidden files of the web application, via sending a specially crafted HTTP packet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-h72j-pmww-phww/GHSA-h72j-pmww-phww.json b/advisories/unreviewed/2021/12/GHSA-h72j-pmww-phww/GHSA-h72j-pmww-phww.json index 086f5680dc0..e9ce00ac090 100644 --- a/advisories/unreviewed/2021/12/GHSA-h72j-pmww-phww/GHSA-h72j-pmww-phww.json +++ b/advisories/unreviewed/2021/12/GHSA-h72j-pmww-phww/GHSA-h72j-pmww-phww.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2021/12/GHSA-h7pc-9m8f-584g/GHSA-h7pc-9m8f-584g.json b/advisories/unreviewed/2021/12/GHSA-h7pc-9m8f-584g/GHSA-h7pc-9m8f-584g.json index 327663cb6c6..a27539972ef 100644 --- a/advisories/unreviewed/2021/12/GHSA-h7pc-9m8f-584g/GHSA-h7pc-9m8f-584g.json +++ b/advisories/unreviewed/2021/12/GHSA-h7pc-9m8f-584g/GHSA-h7pc-9m8f-584g.json @@ -7,12 +7,8 @@ "CVE-2021-44557" ], "details": "National Library of the Netherlands multiNER <= c0440948057afc6e3d6b4903a7c05e666b94a3bc is affected by an XML External Entity (XXE) vulnerability in multiNER/ner.py. Since XML parsing resolves external entities, a malicious XML stream could leak internal files and/or cause a DoS.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-h876-4pvm-cp76/GHSA-h876-4pvm-cp76.json b/advisories/unreviewed/2021/12/GHSA-h876-4pvm-cp76/GHSA-h876-4pvm-cp76.json index 2996f52930d..3e784058167 100644 --- a/advisories/unreviewed/2021/12/GHSA-h876-4pvm-cp76/GHSA-h876-4pvm-cp76.json +++ b/advisories/unreviewed/2021/12/GHSA-h876-4pvm-cp76/GHSA-h876-4pvm-cp76.json @@ -7,12 +7,8 @@ "CVE-2021-40279" ], "details": "An SQL Injection vulnerability exists in zzcms 8.2, 8.3, 2020, and 2021 via the id parameter in admin/bad.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-h9rw-2gc4-4x9v/GHSA-h9rw-2gc4-4x9v.json b/advisories/unreviewed/2021/12/GHSA-h9rw-2gc4-4x9v/GHSA-h9rw-2gc4-4x9v.json index 04b87274d47..bca1c19f1f7 100644 --- a/advisories/unreviewed/2021/12/GHSA-h9rw-2gc4-4x9v/GHSA-h9rw-2gc4-4x9v.json +++ b/advisories/unreviewed/2021/12/GHSA-h9rw-2gc4-4x9v/GHSA-h9rw-2gc4-4x9v.json @@ -7,12 +7,8 @@ "CVE-2021-42759" ], "details": "A violation of secure design principles in Fortinet Meru AP version 8.6.1 and below, version 8.5.5 and below allows attacker to execute unauthorized code or commands via crafted cli commands.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-hcmw-22rw-4v9j/GHSA-hcmw-22rw-4v9j.json b/advisories/unreviewed/2021/12/GHSA-hcmw-22rw-4v9j/GHSA-hcmw-22rw-4v9j.json index be5fedae71e..f98d5471a92 100644 --- a/advisories/unreviewed/2021/12/GHSA-hcmw-22rw-4v9j/GHSA-hcmw-22rw-4v9j.json +++ b/advisories/unreviewed/2021/12/GHSA-hcmw-22rw-4v9j/GHSA-hcmw-22rw-4v9j.json @@ -7,12 +7,8 @@ "CVE-2021-41067" ], "details": "An issue was discovered in Listary through 6. Improper implementation of the update process leads to the download of software updates with a /check-update HTTP-based connection. This can be exploited with MITM techniques. Together with the lack of package validation, it can lead to manipulation of update packages that can cause an installation of malicious content.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-hfgv-8383-5fm8/GHSA-hfgv-8383-5fm8.json b/advisories/unreviewed/2021/12/GHSA-hfgv-8383-5fm8/GHSA-hfgv-8383-5fm8.json index 59f971b53f6..7899ca5b016 100644 --- a/advisories/unreviewed/2021/12/GHSA-hfgv-8383-5fm8/GHSA-hfgv-8383-5fm8.json +++ b/advisories/unreviewed/2021/12/GHSA-hfgv-8383-5fm8/GHSA-hfgv-8383-5fm8.json @@ -7,12 +7,8 @@ "CVE-2021-24818" ], "details": "The WP Limits WordPress plugin through 1.0 does not have CSRF check when saving its settings, allowing attacker to make a logged in admin change them, which could make the blog unstable by setting low values", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-hfgw-xgjr-v384/GHSA-hfgw-xgjr-v384.json b/advisories/unreviewed/2021/12/GHSA-hfgw-xgjr-v384/GHSA-hfgw-xgjr-v384.json index 4ffa00a07af..3e3a1eaea12 100644 --- a/advisories/unreviewed/2021/12/GHSA-hfgw-xgjr-v384/GHSA-hfgw-xgjr-v384.json +++ b/advisories/unreviewed/2021/12/GHSA-hfgw-xgjr-v384/GHSA-hfgw-xgjr-v384.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-hhg7-mpgg-68qf/GHSA-hhg7-mpgg-68qf.json b/advisories/unreviewed/2021/12/GHSA-hhg7-mpgg-68qf/GHSA-hhg7-mpgg-68qf.json index 308f5be44b8..eb7d65d2177 100644 --- a/advisories/unreviewed/2021/12/GHSA-hhg7-mpgg-68qf/GHSA-hhg7-mpgg-68qf.json +++ b/advisories/unreviewed/2021/12/GHSA-hhg7-mpgg-68qf/GHSA-hhg7-mpgg-68qf.json @@ -7,12 +7,8 @@ "CVE-2021-44513" ], "details": "Insecure creation of temporary directories in tmate-ssh-server 2.3.0 allows a local attacker to compromise the integrity of session handling.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-hvhx-qhmq-cpjp/GHSA-hvhx-qhmq-cpjp.json b/advisories/unreviewed/2021/12/GHSA-hvhx-qhmq-cpjp/GHSA-hvhx-qhmq-cpjp.json index 0bfed729c8e..a091604b1c7 100644 --- a/advisories/unreviewed/2021/12/GHSA-hvhx-qhmq-cpjp/GHSA-hvhx-qhmq-cpjp.json +++ b/advisories/unreviewed/2021/12/GHSA-hvhx-qhmq-cpjp/GHSA-hvhx-qhmq-cpjp.json @@ -7,12 +7,8 @@ "CVE-2021-36719" ], "details": "PineApp - Mail Secure - The attacker must be logged in as a user to the Pineapp system. The attacker exploits the vulnerable nicUpload.php file to upload a malicious file,Thus taking over the server and running remote code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-hvvh-wh5g-3ppr/GHSA-hvvh-wh5g-3ppr.json b/advisories/unreviewed/2021/12/GHSA-hvvh-wh5g-3ppr/GHSA-hvvh-wh5g-3ppr.json index 7b412a5a441..19fb5feb697 100644 --- a/advisories/unreviewed/2021/12/GHSA-hvvh-wh5g-3ppr/GHSA-hvvh-wh5g-3ppr.json +++ b/advisories/unreviewed/2021/12/GHSA-hvvh-wh5g-3ppr/GHSA-hvvh-wh5g-3ppr.json @@ -7,12 +7,8 @@ "CVE-2021-37861" ], "details": "Mattermost 6.0.2 and earlier fails to sufficiently sanitize user's password in audit logs when user creation fails.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-hwh5-9mfv-g2m5/GHSA-hwh5-9mfv-g2m5.json b/advisories/unreviewed/2021/12/GHSA-hwh5-9mfv-g2m5/GHSA-hwh5-9mfv-g2m5.json index bdab3069496..e5c13114827 100644 --- a/advisories/unreviewed/2021/12/GHSA-hwh5-9mfv-g2m5/GHSA-hwh5-9mfv-g2m5.json +++ b/advisories/unreviewed/2021/12/GHSA-hwh5-9mfv-g2m5/GHSA-hwh5-9mfv-g2m5.json @@ -7,12 +7,8 @@ "CVE-2021-25521" ], "details": "Insecure caller check in sharevia deeplink logic prior to Samsung Internet 16.0.2 allows unstrusted applications to get current tab URL in Samsung Internet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-j77p-xp62-rqm6/GHSA-j77p-xp62-rqm6.json b/advisories/unreviewed/2021/12/GHSA-j77p-xp62-rqm6/GHSA-j77p-xp62-rqm6.json index f3774c23251..eeccafd3a98 100644 --- a/advisories/unreviewed/2021/12/GHSA-j77p-xp62-rqm6/GHSA-j77p-xp62-rqm6.json +++ b/advisories/unreviewed/2021/12/GHSA-j77p-xp62-rqm6/GHSA-j77p-xp62-rqm6.json @@ -7,12 +7,8 @@ "CVE-2021-40860" ], "details": "A SQL Injection in the custom filter query component in Genesys intelligent Workload Distribution (IWD) before 9.0.013.11 allows an attacker to execute arbitrary SQL queries via the ql_expression parameter, with which all data in the database can be extracted and OS command execution is possible depending on the permissions and/or database engine.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-j8g6-7jj6-7w7v/GHSA-j8g6-7jj6-7w7v.json b/advisories/unreviewed/2021/12/GHSA-j8g6-7jj6-7w7v/GHSA-j8g6-7jj6-7w7v.json index fc6750396af..00caf23d7c6 100644 --- a/advisories/unreviewed/2021/12/GHSA-j8g6-7jj6-7w7v/GHSA-j8g6-7jj6-7w7v.json +++ b/advisories/unreviewed/2021/12/GHSA-j8g6-7jj6-7w7v/GHSA-j8g6-7jj6-7w7v.json @@ -7,12 +7,8 @@ "CVE-2021-37187" ], "details": "An issue was discovered on Digi TransPort devices through 2021-07-21. An authenticated attacker may read a password file (with reversible passwords) from the device, which allows decoding of other users' passwords.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-j8rh-gjh8-236w/GHSA-j8rh-gjh8-236w.json b/advisories/unreviewed/2021/12/GHSA-j8rh-gjh8-236w/GHSA-j8rh-gjh8-236w.json index 4cb25f94200..40e87a038ca 100644 --- a/advisories/unreviewed/2021/12/GHSA-j8rh-gjh8-236w/GHSA-j8rh-gjh8-236w.json +++ b/advisories/unreviewed/2021/12/GHSA-j8rh-gjh8-236w/GHSA-j8rh-gjh8-236w.json @@ -7,12 +7,8 @@ "CVE-2021-20047" ], "details": "SonicWall Global VPN client version 4.10.6 (32-bit and 64-bit) and earlier have a DLL Search Order Hijacking vulnerability. Successful exploitation via a local attacker could result in remote code execution in the target system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-jcvw-97r9-7cg7/GHSA-jcvw-97r9-7cg7.json b/advisories/unreviewed/2021/12/GHSA-jcvw-97r9-7cg7/GHSA-jcvw-97r9-7cg7.json index 6c3f753f8a7..48d7a0068a1 100644 --- a/advisories/unreviewed/2021/12/GHSA-jcvw-97r9-7cg7/GHSA-jcvw-97r9-7cg7.json +++ b/advisories/unreviewed/2021/12/GHSA-jcvw-97r9-7cg7/GHSA-jcvw-97r9-7cg7.json @@ -7,12 +7,8 @@ "CVE-2021-24925" ], "details": "The Modern Events Calendar Lite WordPress plugin before 6.1.5 does not sanitise and escape the current_month_divider parameter of its mec_list_load_more AJAX call (available to both unauthenticated and authenticated users) before outputting it back in the response, leading to a Reflected Cross-Site Scripting issue", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-jg5p-7m49-jgfj/GHSA-jg5p-7m49-jgfj.json b/advisories/unreviewed/2021/12/GHSA-jg5p-7m49-jgfj/GHSA-jg5p-7m49-jgfj.json index dc668979d60..cdd01b244b9 100644 --- a/advisories/unreviewed/2021/12/GHSA-jg5p-7m49-jgfj/GHSA-jg5p-7m49-jgfj.json +++ b/advisories/unreviewed/2021/12/GHSA-jg5p-7m49-jgfj/GHSA-jg5p-7m49-jgfj.json @@ -7,12 +7,8 @@ "CVE-2021-36195" ], "details": "Multiple command injection vulnerabilities in the command line interpreter of FortiWeb versions 6.4.1, 6.4.0, 6.3.0 through 6.3.15, 6.2.0 through 6.2.6, and 6.1.0 through 6.1.2 may allow an authenticated attacker to execute arbitrary commands on the underlying system shell via specially crafted command arguments.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-jgm2-2f8q-fj63/GHSA-jgm2-2f8q-fj63.json b/advisories/unreviewed/2021/12/GHSA-jgm2-2f8q-fj63/GHSA-jgm2-2f8q-fj63.json index 475e5638d90..8cbfece6798 100644 --- a/advisories/unreviewed/2021/12/GHSA-jgm2-2f8q-fj63/GHSA-jgm2-2f8q-fj63.json +++ b/advisories/unreviewed/2021/12/GHSA-jgm2-2f8q-fj63/GHSA-jgm2-2f8q-fj63.json @@ -7,12 +7,8 @@ "CVE-2021-41027" ], "details": "A stack-based buffer overflow in Fortinet FortiWeb version 6.4.1 and 6.4.0, allows an authenticated attacker to execute unauthorized code or commands via crafted certificates loaded into the device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-jjwg-7f28-x45q/GHSA-jjwg-7f28-x45q.json b/advisories/unreviewed/2021/12/GHSA-jjwg-7f28-x45q/GHSA-jjwg-7f28-x45q.json index d6dfc60d973..f571dc87961 100644 --- a/advisories/unreviewed/2021/12/GHSA-jjwg-7f28-x45q/GHSA-jjwg-7f28-x45q.json +++ b/advisories/unreviewed/2021/12/GHSA-jjwg-7f28-x45q/GHSA-jjwg-7f28-x45q.json @@ -7,12 +7,8 @@ "CVE-2021-42752" ], "details": "A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWLM version 8.6.1 and below allows attacker to execute malicious javascript code on victim's host via crafted HTTP requests", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-jmhc-vxg9-h2g4/GHSA-jmhc-vxg9-h2g4.json b/advisories/unreviewed/2021/12/GHSA-jmhc-vxg9-h2g4/GHSA-jmhc-vxg9-h2g4.json index 2e569b362d5..2cfc2838ba7 100644 --- a/advisories/unreviewed/2021/12/GHSA-jmhc-vxg9-h2g4/GHSA-jmhc-vxg9-h2g4.json +++ b/advisories/unreviewed/2021/12/GHSA-jmhc-vxg9-h2g4/GHSA-jmhc-vxg9-h2g4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-jrj8-w63v-jf8f/GHSA-jrj8-w63v-jf8f.json b/advisories/unreviewed/2021/12/GHSA-jrj8-w63v-jf8f/GHSA-jrj8-w63v-jf8f.json index 82c387be7e2..d6755d919f9 100644 --- a/advisories/unreviewed/2021/12/GHSA-jrj8-w63v-jf8f/GHSA-jrj8-w63v-jf8f.json +++ b/advisories/unreviewed/2021/12/GHSA-jrj8-w63v-jf8f/GHSA-jrj8-w63v-jf8f.json @@ -7,12 +7,8 @@ "CVE-2021-38917" ], "details": "IBM PowerVM Hypervisor FW860, FW940, and FW950 could allow an attacker that gains service access to the FSP can read and write arbitrary host system memory through a series of carefully crafted service procedures. IBM X-Force ID: 210018.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2021/12/GHSA-jw75-49hr-wcmr/GHSA-jw75-49hr-wcmr.json b/advisories/unreviewed/2021/12/GHSA-jw75-49hr-wcmr/GHSA-jw75-49hr-wcmr.json index 56758259d58..9867ef2f393 100644 --- a/advisories/unreviewed/2021/12/GHSA-jw75-49hr-wcmr/GHSA-jw75-49hr-wcmr.json +++ b/advisories/unreviewed/2021/12/GHSA-jw75-49hr-wcmr/GHSA-jw75-49hr-wcmr.json @@ -7,12 +7,8 @@ "CVE-2021-37054" ], "details": "There is an Identity spoofing and authentication bypass vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service confidentiality.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-jwp4-cwh4-pg3c/GHSA-jwp4-cwh4-pg3c.json b/advisories/unreviewed/2021/12/GHSA-jwp4-cwh4-pg3c/GHSA-jwp4-cwh4-pg3c.json index 9ac327a8f91..6d424823fd7 100644 --- a/advisories/unreviewed/2021/12/GHSA-jwp4-cwh4-pg3c/GHSA-jwp4-cwh4-pg3c.json +++ b/advisories/unreviewed/2021/12/GHSA-jwp4-cwh4-pg3c/GHSA-jwp4-cwh4-pg3c.json @@ -7,12 +7,8 @@ "CVE-2021-37037" ], "details": "There is an Invalid address access vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause the device to restart.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2021/12/GHSA-jx3f-hj4m-h7p9/GHSA-jx3f-hj4m-h7p9.json b/advisories/unreviewed/2021/12/GHSA-jx3f-hj4m-h7p9/GHSA-jx3f-hj4m-h7p9.json index b7643f1ccb2..204fe0c47b9 100644 --- a/advisories/unreviewed/2021/12/GHSA-jx3f-hj4m-h7p9/GHSA-jx3f-hj4m-h7p9.json +++ b/advisories/unreviewed/2021/12/GHSA-jx3f-hj4m-h7p9/GHSA-jx3f-hj4m-h7p9.json @@ -7,12 +7,8 @@ "CVE-2021-42110" ], "details": "An issue was discovered in Allegro Windows (formerly Popsy Windows) before 3.3.4156.1. A standard user can escalate privileges to SYSTEM if the FTP module is installed, because of DLL hijacking.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2021/12/GHSA-m65r-7jgg-xwhp/GHSA-m65r-7jgg-xwhp.json b/advisories/unreviewed/2021/12/GHSA-m65r-7jgg-xwhp/GHSA-m65r-7jgg-xwhp.json index ac52679c419..abaa0b56dc5 100644 --- a/advisories/unreviewed/2021/12/GHSA-m65r-7jgg-xwhp/GHSA-m65r-7jgg-xwhp.json +++ b/advisories/unreviewed/2021/12/GHSA-m65r-7jgg-xwhp/GHSA-m65r-7jgg-xwhp.json @@ -7,12 +7,8 @@ "CVE-2021-24792" ], "details": "The Shiny Buttons WordPress plugin through 1.1.0 does not have any authorisation and CSRF in place when saving a template (wpbtn_save_template function hooked to the init action), nor sanitise and escape them before outputting them in the admin dashboard, which allow unauthenticated users to add a malicious template and lead to Stored Cross-Site Scripting issues.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-m6m7-mf2p-99p5/GHSA-m6m7-mf2p-99p5.json b/advisories/unreviewed/2021/12/GHSA-m6m7-mf2p-99p5/GHSA-m6m7-mf2p-99p5.json index 3b9fdeea4a7..1927003417a 100644 --- a/advisories/unreviewed/2021/12/GHSA-m6m7-mf2p-99p5/GHSA-m6m7-mf2p-99p5.json +++ b/advisories/unreviewed/2021/12/GHSA-m6m7-mf2p-99p5/GHSA-m6m7-mf2p-99p5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-m6q6-5v8h-vp6v/GHSA-m6q6-5v8h-vp6v.json b/advisories/unreviewed/2021/12/GHSA-m6q6-5v8h-vp6v/GHSA-m6q6-5v8h-vp6v.json index 289990aca07..7a575a36481 100644 --- a/advisories/unreviewed/2021/12/GHSA-m6q6-5v8h-vp6v/GHSA-m6q6-5v8h-vp6v.json +++ b/advisories/unreviewed/2021/12/GHSA-m6q6-5v8h-vp6v/GHSA-m6q6-5v8h-vp6v.json @@ -7,12 +7,8 @@ "CVE-2021-27983" ], "details": "Remote Code Execution (RCE) vulnerability exists in MaxSite CMS v107.5 via the Documents page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2021/12/GHSA-m96c-8jmv-4r54/GHSA-m96c-8jmv-4r54.json b/advisories/unreviewed/2021/12/GHSA-m96c-8jmv-4r54/GHSA-m96c-8jmv-4r54.json index 0318e54e276..c85e7b90071 100644 --- a/advisories/unreviewed/2021/12/GHSA-m96c-8jmv-4r54/GHSA-m96c-8jmv-4r54.json +++ b/advisories/unreviewed/2021/12/GHSA-m96c-8jmv-4r54/GHSA-m96c-8jmv-4r54.json @@ -7,12 +7,8 @@ "CVE-2021-24859" ], "details": "The User Meta Shortcodes WordPress plugin through 0.5 registers a shortcode that allows any user with a role as low as contributor to access other users metadata by specifying the user login as a parameter. This makes the WP instance vulnerable to data extrafiltration, including password hashes", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-mch5-89c5-9g6p/GHSA-mch5-89c5-9g6p.json b/advisories/unreviewed/2021/12/GHSA-mch5-89c5-9g6p/GHSA-mch5-89c5-9g6p.json index 38550542c8d..28ba741f5b6 100644 --- a/advisories/unreviewed/2021/12/GHSA-mch5-89c5-9g6p/GHSA-mch5-89c5-9g6p.json +++ b/advisories/unreviewed/2021/12/GHSA-mch5-89c5-9g6p/GHSA-mch5-89c5-9g6p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-mg7h-r8f5-67xj/GHSA-mg7h-r8f5-67xj.json b/advisories/unreviewed/2021/12/GHSA-mg7h-r8f5-67xj/GHSA-mg7h-r8f5-67xj.json index 1616e7ca17d..692bfb84197 100644 --- a/advisories/unreviewed/2021/12/GHSA-mg7h-r8f5-67xj/GHSA-mg7h-r8f5-67xj.json +++ b/advisories/unreviewed/2021/12/GHSA-mg7h-r8f5-67xj/GHSA-mg7h-r8f5-67xj.json @@ -7,12 +7,8 @@ "CVE-2021-24955" ], "details": "The User Registration, Login Form, User Profile & Membership WordPress plugin before 3.2.3 does not escape the data parameter of the pp_get_forms_by_builder_type AJAX action before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-mgfp-hcp6-39f4/GHSA-mgfp-hcp6-39f4.json b/advisories/unreviewed/2021/12/GHSA-mgfp-hcp6-39f4/GHSA-mgfp-hcp6-39f4.json index 5e5c6015d07..0b60caa0f0c 100644 --- a/advisories/unreviewed/2021/12/GHSA-mgfp-hcp6-39f4/GHSA-mgfp-hcp6-39f4.json +++ b/advisories/unreviewed/2021/12/GHSA-mgfp-hcp6-39f4/GHSA-mgfp-hcp6-39f4.json @@ -7,12 +7,8 @@ "CVE-2021-43530" ], "details": "A Universal XSS vulnerability was present in Firefox for Android resulting from improper sanitization when processing a URL scanned from a QR code. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 94.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-mgrc-fpr7-mq3c/GHSA-mgrc-fpr7-mq3c.json b/advisories/unreviewed/2021/12/GHSA-mgrc-fpr7-mq3c/GHSA-mgrc-fpr7-mq3c.json index 8a259e78adb..8e58514813d 100644 --- a/advisories/unreviewed/2021/12/GHSA-mgrc-fpr7-mq3c/GHSA-mgrc-fpr7-mq3c.json +++ b/advisories/unreviewed/2021/12/GHSA-mgrc-fpr7-mq3c/GHSA-mgrc-fpr7-mq3c.json @@ -7,12 +7,8 @@ "CVE-2021-20145" ], "details": "Gryphon Tower routers contain an unprotected openvpn configuration file which can grant attackers access to the Gryphon homebound VPN network which exposes the LAN interfaces of other users' devices connected to the same service. An attacker could leverage this to make configuration changes to, or otherwise attack victims' devices as though they were on an adjacent network.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-mjx8-7r29-w8cq/GHSA-mjx8-7r29-w8cq.json b/advisories/unreviewed/2021/12/GHSA-mjx8-7r29-w8cq/GHSA-mjx8-7r29-w8cq.json index c7c060dd932..fb4a98d8867 100644 --- a/advisories/unreviewed/2021/12/GHSA-mjx8-7r29-w8cq/GHSA-mjx8-7r29-w8cq.json +++ b/advisories/unreviewed/2021/12/GHSA-mjx8-7r29-w8cq/GHSA-mjx8-7r29-w8cq.json @@ -7,12 +7,8 @@ "CVE-2021-3817" ], "details": "wbce_cms is vulnerable to Improper Neutralization of Special Elements used in an SQL Command", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-mpgw-pwqr-q9jp/GHSA-mpgw-pwqr-q9jp.json b/advisories/unreviewed/2021/12/GHSA-mpgw-pwqr-q9jp/GHSA-mpgw-pwqr-q9jp.json index cdc9e068b3f..4e9de710f31 100644 --- a/advisories/unreviewed/2021/12/GHSA-mpgw-pwqr-q9jp/GHSA-mpgw-pwqr-q9jp.json +++ b/advisories/unreviewed/2021/12/GHSA-mpgw-pwqr-q9jp/GHSA-mpgw-pwqr-q9jp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-mqgv-jjjv-xw48/GHSA-mqgv-jjjv-xw48.json b/advisories/unreviewed/2021/12/GHSA-mqgv-jjjv-xw48/GHSA-mqgv-jjjv-xw48.json index 01f002efebb..e13cdbe33a6 100644 --- a/advisories/unreviewed/2021/12/GHSA-mqgv-jjjv-xw48/GHSA-mqgv-jjjv-xw48.json +++ b/advisories/unreviewed/2021/12/GHSA-mqgv-jjjv-xw48/GHSA-mqgv-jjjv-xw48.json @@ -7,12 +7,8 @@ "CVE-2021-24771" ], "details": "The Inspirational Quote Rotator WordPress plugin through 1.0.0 does not sanitize and escape some of its quote fields when adding/editing a quote as admin, leading to Stored Cross-Site scripting issues when the quote is output in the \"Quotes list\" even when the unfiltered_html capability is disallowed", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-mx9v-6qg3-92rp/GHSA-mx9v-6qg3-92rp.json b/advisories/unreviewed/2021/12/GHSA-mx9v-6qg3-92rp/GHSA-mx9v-6qg3-92rp.json index 51ab10af9a6..0d4a9b500ad 100644 --- a/advisories/unreviewed/2021/12/GHSA-mx9v-6qg3-92rp/GHSA-mx9v-6qg3-92rp.json +++ b/advisories/unreviewed/2021/12/GHSA-mx9v-6qg3-92rp/GHSA-mx9v-6qg3-92rp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-mxxq-jqh7-gv6g/GHSA-mxxq-jqh7-gv6g.json b/advisories/unreviewed/2021/12/GHSA-mxxq-jqh7-gv6g/GHSA-mxxq-jqh7-gv6g.json index d4e02d92c38..a2418f5fb08 100644 --- a/advisories/unreviewed/2021/12/GHSA-mxxq-jqh7-gv6g/GHSA-mxxq-jqh7-gv6g.json +++ b/advisories/unreviewed/2021/12/GHSA-mxxq-jqh7-gv6g/GHSA-mxxq-jqh7-gv6g.json @@ -7,12 +7,8 @@ "CVE-2021-20139" ], "details": "An unauthenticated command injection vulnerability exists in the parameters of operation 3 in the controller_server service on Gryphon Tower routers. An unauthenticated remote attacker on the same network can execute commands as root on the device by sending a specially crafted malicious packet to the controller_server service on port 9999.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-p2qj-5m9h-ffxq/GHSA-p2qj-5m9h-ffxq.json b/advisories/unreviewed/2021/12/GHSA-p2qj-5m9h-ffxq/GHSA-p2qj-5m9h-ffxq.json index 9256f833724..8699667e75b 100644 --- a/advisories/unreviewed/2021/12/GHSA-p2qj-5m9h-ffxq/GHSA-p2qj-5m9h-ffxq.json +++ b/advisories/unreviewed/2021/12/GHSA-p2qj-5m9h-ffxq/GHSA-p2qj-5m9h-ffxq.json @@ -7,12 +7,8 @@ "CVE-2021-37044" ], "details": "There is a Permission control vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service availability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-p3p2-9rqf-r8j8/GHSA-p3p2-9rqf-r8j8.json b/advisories/unreviewed/2021/12/GHSA-p3p2-9rqf-r8j8/GHSA-p3p2-9rqf-r8j8.json index ed5e3cc4d5a..17e4a609f2f 100644 --- a/advisories/unreviewed/2021/12/GHSA-p3p2-9rqf-r8j8/GHSA-p3p2-9rqf-r8j8.json +++ b/advisories/unreviewed/2021/12/GHSA-p3p2-9rqf-r8j8/GHSA-p3p2-9rqf-r8j8.json @@ -7,12 +7,8 @@ "CVE-2018-25021" ], "details": "The TCP Server module in toxcore before 0.2.8 doesn't free the TCP priority queue under certain conditions, which allows a remote attacker to exhaust the system's memory, causing a denial of service (DoS).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-p475-9mm9-rp5x/GHSA-p475-9mm9-rp5x.json b/advisories/unreviewed/2021/12/GHSA-p475-9mm9-rp5x/GHSA-p475-9mm9-rp5x.json index 06e052a2729..725e16d9212 100644 --- a/advisories/unreviewed/2021/12/GHSA-p475-9mm9-rp5x/GHSA-p475-9mm9-rp5x.json +++ b/advisories/unreviewed/2021/12/GHSA-p475-9mm9-rp5x/GHSA-p475-9mm9-rp5x.json @@ -7,12 +7,8 @@ "CVE-2021-37074" ], "details": "There is a Race Condition vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to the user root privilege escalation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-p4m7-49xq-h85c/GHSA-p4m7-49xq-h85c.json b/advisories/unreviewed/2021/12/GHSA-p4m7-49xq-h85c/GHSA-p4m7-49xq-h85c.json index 5a5270e1090..7a48d95a0f4 100644 --- a/advisories/unreviewed/2021/12/GHSA-p4m7-49xq-h85c/GHSA-p4m7-49xq-h85c.json +++ b/advisories/unreviewed/2021/12/GHSA-p4m7-49xq-h85c/GHSA-p4m7-49xq-h85c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-p5ch-7hc9-cv48/GHSA-p5ch-7hc9-cv48.json b/advisories/unreviewed/2021/12/GHSA-p5ch-7hc9-cv48/GHSA-p5ch-7hc9-cv48.json index daf7b3355b0..77071f19125 100644 --- a/advisories/unreviewed/2021/12/GHSA-p5ch-7hc9-cv48/GHSA-p5ch-7hc9-cv48.json +++ b/advisories/unreviewed/2021/12/GHSA-p5ch-7hc9-cv48/GHSA-p5ch-7hc9-cv48.json @@ -7,12 +7,8 @@ "CVE-2021-42066" ], "details": "SAP Business One - version 10.0, allows an admin user to view DB password in plain text over the network, which should otherwise be encrypted. For an attacker to discover vulnerable function in-depth application knowledge is required, but once exploited the attacker may be able to completely compromise confidentiality, integrity, and availability of the application.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-p5m6-c47j-fg8m/GHSA-p5m6-c47j-fg8m.json b/advisories/unreviewed/2021/12/GHSA-p5m6-c47j-fg8m/GHSA-p5m6-c47j-fg8m.json index df8ce654549..e29284fbddf 100644 --- a/advisories/unreviewed/2021/12/GHSA-p5m6-c47j-fg8m/GHSA-p5m6-c47j-fg8m.json +++ b/advisories/unreviewed/2021/12/GHSA-p5m6-c47j-fg8m/GHSA-p5m6-c47j-fg8m.json @@ -7,12 +7,8 @@ "CVE-2021-36173" ], "details": "A heap-based buffer overflow in the firmware signature verification function of FortiOS versions 7.0.1, 7.0.0, 6.4.0 through 6.4.6, 6.2.0 through 6.2.9, and 6.0.0 through 6.0.13 may allow an attacker to execute arbitrary code via specially crafted installation images.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-p6pm-7qxv-f8f3/GHSA-p6pm-7qxv-f8f3.json b/advisories/unreviewed/2021/12/GHSA-p6pm-7qxv-f8f3/GHSA-p6pm-7qxv-f8f3.json index f434f61e7c7..0612a062e83 100644 --- a/advisories/unreviewed/2021/12/GHSA-p6pm-7qxv-f8f3/GHSA-p6pm-7qxv-f8f3.json +++ b/advisories/unreviewed/2021/12/GHSA-p6pm-7qxv-f8f3/GHSA-p6pm-7qxv-f8f3.json @@ -7,12 +7,8 @@ "CVE-2021-39936" ], "details": "Improper access control in GitLab CE/EE affecting all versions starting from 10.7 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker in possession of a deploy token to access a project's disabled wiki.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-p7cc-j2xj-7xp5/GHSA-p7cc-j2xj-7xp5.json b/advisories/unreviewed/2021/12/GHSA-p7cc-j2xj-7xp5/GHSA-p7cc-j2xj-7xp5.json index 3d65918625a..1f337113a22 100644 --- a/advisories/unreviewed/2021/12/GHSA-p7cc-j2xj-7xp5/GHSA-p7cc-j2xj-7xp5.json +++ b/advisories/unreviewed/2021/12/GHSA-p7cc-j2xj-7xp5/GHSA-p7cc-j2xj-7xp5.json @@ -7,12 +7,8 @@ "CVE-2021-37092" ], "details": "There is a Incomplete Cleanup vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to availability affected.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-p8r7-m476-v2m9/GHSA-p8r7-m476-v2m9.json b/advisories/unreviewed/2021/12/GHSA-p8r7-m476-v2m9/GHSA-p8r7-m476-v2m9.json index 6784836a468..0b594b69b76 100644 --- a/advisories/unreviewed/2021/12/GHSA-p8r7-m476-v2m9/GHSA-p8r7-m476-v2m9.json +++ b/advisories/unreviewed/2021/12/GHSA-p8r7-m476-v2m9/GHSA-p8r7-m476-v2m9.json @@ -7,12 +7,8 @@ "CVE-2021-37097" ], "details": "There is a Code Injection vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to system restart.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-p9wr-7hwx-rwm9/GHSA-p9wr-7hwx-rwm9.json b/advisories/unreviewed/2021/12/GHSA-p9wr-7hwx-rwm9/GHSA-p9wr-7hwx-rwm9.json index bfccf143c9a..3da34d8ccfc 100644 --- a/advisories/unreviewed/2021/12/GHSA-p9wr-7hwx-rwm9/GHSA-p9wr-7hwx-rwm9.json +++ b/advisories/unreviewed/2021/12/GHSA-p9wr-7hwx-rwm9/GHSA-p9wr-7hwx-rwm9.json @@ -7,12 +7,8 @@ "CVE-2021-37050" ], "details": "There is a Missing sensitive data encryption vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service confidentiality.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-pm9p-228m-rc94/GHSA-pm9p-228m-rc94.json b/advisories/unreviewed/2021/12/GHSA-pm9p-228m-rc94/GHSA-pm9p-228m-rc94.json index 0247d936abf..7d2a49a5c40 100644 --- a/advisories/unreviewed/2021/12/GHSA-pm9p-228m-rc94/GHSA-pm9p-228m-rc94.json +++ b/advisories/unreviewed/2021/12/GHSA-pm9p-228m-rc94/GHSA-pm9p-228m-rc94.json @@ -7,12 +7,8 @@ "CVE-2021-42546" ], "details": "Insufficient Input Validation in the search functionality of Wordpress plugin Use-Your-Drive prior to 1.18.3 allows unauthenticated user to craft a reflected Cross-Site Scripting attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-prm5-542j-m494/GHSA-prm5-542j-m494.json b/advisories/unreviewed/2021/12/GHSA-prm5-542j-m494/GHSA-prm5-542j-m494.json index b12e49e6dbd..1ab6ee98918 100644 --- a/advisories/unreviewed/2021/12/GHSA-prm5-542j-m494/GHSA-prm5-542j-m494.json +++ b/advisories/unreviewed/2021/12/GHSA-prm5-542j-m494/GHSA-prm5-542j-m494.json @@ -7,12 +7,8 @@ "CVE-2021-31745" ], "details": "Session Fixation vulnerability in login.php in Pluck-CMS Pluck 4.7.15 allows an attacker to sustain unauthorized access to the platform. Because Pluck does not invalidate prior sessions after a password change, access can be sustained even after an administrator performs regular remediation attempts such as resetting their password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-pwfh-3w8f-vww5/GHSA-pwfh-3w8f-vww5.json b/advisories/unreviewed/2021/12/GHSA-pwfh-3w8f-vww5/GHSA-pwfh-3w8f-vww5.json index a94b139333d..464e564da5f 100644 --- a/advisories/unreviewed/2021/12/GHSA-pwfh-3w8f-vww5/GHSA-pwfh-3w8f-vww5.json +++ b/advisories/unreviewed/2021/12/GHSA-pwfh-3w8f-vww5/GHSA-pwfh-3w8f-vww5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-pxph-w77w-wjcr/GHSA-pxph-w77w-wjcr.json b/advisories/unreviewed/2021/12/GHSA-pxph-w77w-wjcr/GHSA-pxph-w77w-wjcr.json index 4ed8d322a8e..9ef43d252df 100644 --- a/advisories/unreviewed/2021/12/GHSA-pxph-w77w-wjcr/GHSA-pxph-w77w-wjcr.json +++ b/advisories/unreviewed/2021/12/GHSA-pxph-w77w-wjcr/GHSA-pxph-w77w-wjcr.json @@ -7,12 +7,8 @@ "CVE-2021-43067" ], "details": "A exposure of sensitive information to an unauthorized actor in Fortinet FortiAuthenticator version 6.4.0, version 6.3.2 and below, version 6.2.1 and below, version 6.1.2 and below, version 6.0.7 to 6.0.1 allows attacker to duplicate a target LDAP user 2 factors authentication token via crafted HTTP requests.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-pxpq-hvq2-x6wx/GHSA-pxpq-hvq2-x6wx.json b/advisories/unreviewed/2021/12/GHSA-pxpq-hvq2-x6wx/GHSA-pxpq-hvq2-x6wx.json index 45de2b57c48..c2222bd348c 100644 --- a/advisories/unreviewed/2021/12/GHSA-pxpq-hvq2-x6wx/GHSA-pxpq-hvq2-x6wx.json +++ b/advisories/unreviewed/2021/12/GHSA-pxpq-hvq2-x6wx/GHSA-pxpq-hvq2-x6wx.json @@ -7,12 +7,8 @@ "CVE-2021-20146" ], "details": "An unprotected ssh private key exists on the Gryphon devices which could be used to achieve root access to a server affiliated with Gryphon's development and infrastructure. At the time of discovery, the ssh key could be used to login to the development server hosted in Amazon Web Services.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-q537-77j4-xv6x/GHSA-q537-77j4-xv6x.json b/advisories/unreviewed/2021/12/GHSA-q537-77j4-xv6x/GHSA-q537-77j4-xv6x.json index 6a547c51437..9950e476046 100644 --- a/advisories/unreviewed/2021/12/GHSA-q537-77j4-xv6x/GHSA-q537-77j4-xv6x.json +++ b/advisories/unreviewed/2021/12/GHSA-q537-77j4-xv6x/GHSA-q537-77j4-xv6x.json @@ -7,12 +7,8 @@ "CVE-2021-31747" ], "details": "Missing SSL Certificate Validation issue exists in Pluck 4.7.15 in update_applet.php, which could lead to man-in-the-middle attacks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-q54c-h3qc-6ggj/GHSA-q54c-h3qc-6ggj.json b/advisories/unreviewed/2021/12/GHSA-q54c-h3qc-6ggj/GHSA-q54c-h3qc-6ggj.json index cdbafc323b1..a2fdad4f9d9 100644 --- a/advisories/unreviewed/2021/12/GHSA-q54c-h3qc-6ggj/GHSA-q54c-h3qc-6ggj.json +++ b/advisories/unreviewed/2021/12/GHSA-q54c-h3qc-6ggj/GHSA-q54c-h3qc-6ggj.json @@ -7,12 +7,8 @@ "CVE-2020-19042" ], "details": "Cross Site Scripting (XSS) vulnerability exists in zzcms 2019 XSS via a modify action in user/adv.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-q5c4-rqq9-f524/GHSA-q5c4-rqq9-f524.json b/advisories/unreviewed/2021/12/GHSA-q5c4-rqq9-f524/GHSA-q5c4-rqq9-f524.json index e026953c390..dfd7c33e35f 100644 --- a/advisories/unreviewed/2021/12/GHSA-q5c4-rqq9-f524/GHSA-q5c4-rqq9-f524.json +++ b/advisories/unreviewed/2021/12/GHSA-q5c4-rqq9-f524/GHSA-q5c4-rqq9-f524.json @@ -7,12 +7,8 @@ "CVE-2021-24857" ], "details": "The ToTop Link WordPress plugin through 1.7.1 passes base64 encoded user input to the unserialize() PHP function, which could lead to PHP Object injection if a plugin installed on the blog has a suitable gadget chain.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-q983-m4fh-gqhm/GHSA-q983-m4fh-gqhm.json b/advisories/unreviewed/2021/12/GHSA-q983-m4fh-gqhm/GHSA-q983-m4fh-gqhm.json index 3915fc662d9..ed33398675a 100644 --- a/advisories/unreviewed/2021/12/GHSA-q983-m4fh-gqhm/GHSA-q983-m4fh-gqhm.json +++ b/advisories/unreviewed/2021/12/GHSA-q983-m4fh-gqhm/GHSA-q983-m4fh-gqhm.json @@ -7,12 +7,8 @@ "CVE-2021-38937" ], "details": "IBM PowerVM Hypervisor FW940, FW950, and FW1010 could allow an authenticated user to cause the system to crash using a specially crafted IBMi Hypervisor call. IBM X-Force ID: 210894.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2021/12/GHSA-qc9v-r7rw-wvm2/GHSA-qc9v-r7rw-wvm2.json b/advisories/unreviewed/2021/12/GHSA-qc9v-r7rw-wvm2/GHSA-qc9v-r7rw-wvm2.json index adef6169118..148a88d75a7 100644 --- a/advisories/unreviewed/2021/12/GHSA-qc9v-r7rw-wvm2/GHSA-qc9v-r7rw-wvm2.json +++ b/advisories/unreviewed/2021/12/GHSA-qc9v-r7rw-wvm2/GHSA-qc9v-r7rw-wvm2.json @@ -7,12 +7,8 @@ "CVE-2021-25524" ], "details": "Insecure storage of device information in Contacts prior to version 12.7.05.24 allows attacker to get Samsung Account ID.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-qcxw-qqmj-c5fp/GHSA-qcxw-qqmj-c5fp.json b/advisories/unreviewed/2021/12/GHSA-qcxw-qqmj-c5fp/GHSA-qcxw-qqmj-c5fp.json index f2e9422fc52..0abd08a8b57 100644 --- a/advisories/unreviewed/2021/12/GHSA-qcxw-qqmj-c5fp/GHSA-qcxw-qqmj-c5fp.json +++ b/advisories/unreviewed/2021/12/GHSA-qcxw-qqmj-c5fp/GHSA-qcxw-qqmj-c5fp.json @@ -7,12 +7,8 @@ "CVE-2021-29678" ], "details": "IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a user with DBADM authority to access other databases and read or modify files. IBM X-Force ID: 199914.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-qf83-36x6-5fv9/GHSA-qf83-36x6-5fv9.json b/advisories/unreviewed/2021/12/GHSA-qf83-36x6-5fv9/GHSA-qf83-36x6-5fv9.json index d313103e8e2..238f86d3685 100644 --- a/advisories/unreviewed/2021/12/GHSA-qf83-36x6-5fv9/GHSA-qf83-36x6-5fv9.json +++ b/advisories/unreviewed/2021/12/GHSA-qf83-36x6-5fv9/GHSA-qf83-36x6-5fv9.json @@ -7,12 +7,8 @@ "CVE-2021-38901" ], "details": "IBM Spectrum Protect Operations Center 7.1, under special configurations, could allow a local user to obtain highly sensitive information. IBM X-Force ID: 209610.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-qfq2-v5pr-268p/GHSA-qfq2-v5pr-268p.json b/advisories/unreviewed/2021/12/GHSA-qfq2-v5pr-268p/GHSA-qfq2-v5pr-268p.json index 551f2408c2a..e641244fbbf 100644 --- a/advisories/unreviewed/2021/12/GHSA-qfq2-v5pr-268p/GHSA-qfq2-v5pr-268p.json +++ b/advisories/unreviewed/2021/12/GHSA-qfq2-v5pr-268p/GHSA-qfq2-v5pr-268p.json @@ -7,12 +7,8 @@ "CVE-2021-25516" ], "details": "An improper check or handling of exceptional conditions in Exynos baseband prior to SMR Dec-2021 Release 1 allows attackers to track locations.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-qgc2-ccpf-f2fm/GHSA-qgc2-ccpf-f2fm.json b/advisories/unreviewed/2021/12/GHSA-qgc2-ccpf-f2fm/GHSA-qgc2-ccpf-f2fm.json index 94531cc42ed..6b1bee4c61a 100644 --- a/advisories/unreviewed/2021/12/GHSA-qgc2-ccpf-f2fm/GHSA-qgc2-ccpf-f2fm.json +++ b/advisories/unreviewed/2021/12/GHSA-qgc2-ccpf-f2fm/GHSA-qgc2-ccpf-f2fm.json @@ -7,12 +7,8 @@ "CVE-2021-41017" ], "details": "Multiple heap-based buffer overflow vulnerabilities in some web API controllers of FortiWeb 6.4.1, 6.4.0, and 6.3.0 through 6.3.15 may allow a remote authenticated attacker to execute arbitrary code or commands via specifically crafted HTTP requests.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-qhp6-xj37-53m2/GHSA-qhp6-xj37-53m2.json b/advisories/unreviewed/2021/12/GHSA-qhp6-xj37-53m2/GHSA-qhp6-xj37-53m2.json index 68a8bd5c32d..c9d6fdaa05a 100644 --- a/advisories/unreviewed/2021/12/GHSA-qhp6-xj37-53m2/GHSA-qhp6-xj37-53m2.json +++ b/advisories/unreviewed/2021/12/GHSA-qhp6-xj37-53m2/GHSA-qhp6-xj37-53m2.json @@ -7,12 +7,8 @@ "CVE-2021-20041" ], "details": "An unauthenticated and remote adversary can consume all of the device's CPU due to crafted HTTP requests sent to SMA100 /fileshare/sonicfiles/sonicfiles resulting in a loop with unreachable exit condition. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-qjc5-hqhg-64c3/GHSA-qjc5-hqhg-64c3.json b/advisories/unreviewed/2021/12/GHSA-qjc5-hqhg-64c3/GHSA-qjc5-hqhg-64c3.json index c34cee9a436..101c5750788 100644 --- a/advisories/unreviewed/2021/12/GHSA-qjc5-hqhg-64c3/GHSA-qjc5-hqhg-64c3.json +++ b/advisories/unreviewed/2021/12/GHSA-qjc5-hqhg-64c3/GHSA-qjc5-hqhg-64c3.json @@ -7,12 +7,8 @@ "CVE-2021-20144" ], "details": "An unauthenticated command injection vulnerability exists in the parameters of operation 49 in the controller_server service on Gryphon Tower routers. An unauthenticated remote attacker on the same network can execute commands as root on the device by sending a specially crafted malicious packet to the controller_server service on port 9999.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-qqmp-4mv9-hvqq/GHSA-qqmp-4mv9-hvqq.json b/advisories/unreviewed/2021/12/GHSA-qqmp-4mv9-hvqq/GHSA-qqmp-4mv9-hvqq.json index 7c692b14d5a..576b8db338e 100644 --- a/advisories/unreviewed/2021/12/GHSA-qqmp-4mv9-hvqq/GHSA-qqmp-4mv9-hvqq.json +++ b/advisories/unreviewed/2021/12/GHSA-qqmp-4mv9-hvqq/GHSA-qqmp-4mv9-hvqq.json @@ -7,12 +7,8 @@ "CVE-2021-37039" ], "details": "There is an Input verification vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause Bluetooth DoS.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-qrff-fqpr-45f9/GHSA-qrff-fqpr-45f9.json b/advisories/unreviewed/2021/12/GHSA-qrff-fqpr-45f9/GHSA-qrff-fqpr-45f9.json index 7877609584d..a4a5a5fdbec 100644 --- a/advisories/unreviewed/2021/12/GHSA-qrff-fqpr-45f9/GHSA-qrff-fqpr-45f9.json +++ b/advisories/unreviewed/2021/12/GHSA-qrff-fqpr-45f9/GHSA-qrff-fqpr-45f9.json @@ -7,12 +7,8 @@ "CVE-2021-44556" ], "details": "National Library of the Netherlands digger < 6697d1269d981e35e11f240725b16401b5ce3db5 is affected by a XML External Entity (XXE) vulnerability. Since XML parsing resolves external entities, a malicious XML stream could leak internal files and/or cause a DoS.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-qrvc-x2cw-mgcp/GHSA-qrvc-x2cw-mgcp.json b/advisories/unreviewed/2021/12/GHSA-qrvc-x2cw-mgcp/GHSA-qrvc-x2cw-mgcp.json index be0328b3a7b..6e8725d8869 100644 --- a/advisories/unreviewed/2021/12/GHSA-qrvc-x2cw-mgcp/GHSA-qrvc-x2cw-mgcp.json +++ b/advisories/unreviewed/2021/12/GHSA-qrvc-x2cw-mgcp/GHSA-qrvc-x2cw-mgcp.json @@ -7,12 +7,8 @@ "CVE-2021-24819" ], "details": "The Page/Post Content Shortcode WordPress plugin through 1.0 does not have proper authorisation in place, allowing users with a role as low as contributor to access draft/private/password protected/trashed posts/pages they should not be allowed to, including posts created by other users such as admins and editors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-qv52-3gx5-px5v/GHSA-qv52-3gx5-px5v.json b/advisories/unreviewed/2021/12/GHSA-qv52-3gx5-px5v/GHSA-qv52-3gx5-px5v.json index 4430d19eadc..b605917aef9 100644 --- a/advisories/unreviewed/2021/12/GHSA-qv52-3gx5-px5v/GHSA-qv52-3gx5-px5v.json +++ b/advisories/unreviewed/2021/12/GHSA-qv52-3gx5-px5v/GHSA-qv52-3gx5-px5v.json @@ -7,12 +7,8 @@ "CVE-2021-26108" ], "details": "A use of hard-coded cryptographic key vulnerability in the SSLVPN of FortiOS before 7.0.1 may allow an attacker to retrieve the key by reverse engineering.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-qv89-64x4-4p5x/GHSA-qv89-64x4-4p5x.json b/advisories/unreviewed/2021/12/GHSA-qv89-64x4-4p5x/GHSA-qv89-64x4-4p5x.json index e7bd7383b08..7e1ca57e199 100644 --- a/advisories/unreviewed/2021/12/GHSA-qv89-64x4-4p5x/GHSA-qv89-64x4-4p5x.json +++ b/advisories/unreviewed/2021/12/GHSA-qv89-64x4-4p5x/GHSA-qv89-64x4-4p5x.json @@ -7,12 +7,8 @@ "CVE-2021-40094" ], "details": "A DOM-based XSS vulnerability affects SquaredUp for SCOM 5.2.1.6654. If successfully exploited, this vulnerability may allow attackers to inject malicious code into a user's device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-qwj7-chm6-2f8f/GHSA-qwj7-chm6-2f8f.json b/advisories/unreviewed/2021/12/GHSA-qwj7-chm6-2f8f/GHSA-qwj7-chm6-2f8f.json index 359f0aa9bb9..f3e89c58d9b 100644 --- a/advisories/unreviewed/2021/12/GHSA-qwj7-chm6-2f8f/GHSA-qwj7-chm6-2f8f.json +++ b/advisories/unreviewed/2021/12/GHSA-qwj7-chm6-2f8f/GHSA-qwj7-chm6-2f8f.json @@ -7,12 +7,8 @@ "CVE-2021-40007" ], "details": "There is an information leak vulnerability in eCNS280_TD V100R005C10SPC650. The vulnerability is caused by improper log output management. An attacker with the ability to access the log file of device may lead to information disclosure.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-r26h-3pgg-jf32/GHSA-r26h-3pgg-jf32.json b/advisories/unreviewed/2021/12/GHSA-r26h-3pgg-jf32/GHSA-r26h-3pgg-jf32.json index 299d0427c49..a0b4af44402 100644 --- a/advisories/unreviewed/2021/12/GHSA-r26h-3pgg-jf32/GHSA-r26h-3pgg-jf32.json +++ b/advisories/unreviewed/2021/12/GHSA-r26h-3pgg-jf32/GHSA-r26h-3pgg-jf32.json @@ -7,12 +7,8 @@ "CVE-2021-41697" ], "details": "A reflected Cross Site Scripting (XSS) vulnerability exists in Premiumdatingscript 4.2.7.7 via the aerror_description parameter in assets/sources/instagram.php script.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-r45q-p6m3-6gmv/GHSA-r45q-p6m3-6gmv.json b/advisories/unreviewed/2021/12/GHSA-r45q-p6m3-6gmv/GHSA-r45q-p6m3-6gmv.json index 321f807970b..cf17099c943 100644 --- a/advisories/unreviewed/2021/12/GHSA-r45q-p6m3-6gmv/GHSA-r45q-p6m3-6gmv.json +++ b/advisories/unreviewed/2021/12/GHSA-r45q-p6m3-6gmv/GHSA-r45q-p6m3-6gmv.json @@ -7,12 +7,8 @@ "CVE-2021-39937" ], "details": "A collision in access memoization logic in all versions of GitLab CE/EE before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, leads to potential elevated privileges in groups and projects under rare circumstances", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-r6p5-8pxg-2vcp/GHSA-r6p5-8pxg-2vcp.json b/advisories/unreviewed/2021/12/GHSA-r6p5-8pxg-2vcp/GHSA-r6p5-8pxg-2vcp.json index 60f39d092b7..32d022b4475 100644 --- a/advisories/unreviewed/2021/12/GHSA-r6p5-8pxg-2vcp/GHSA-r6p5-8pxg-2vcp.json +++ b/advisories/unreviewed/2021/12/GHSA-r6p5-8pxg-2vcp/GHSA-r6p5-8pxg-2vcp.json @@ -7,12 +7,8 @@ "CVE-2021-43531" ], "details": "When a user loaded a Web Extensions context menu, the Web Extension could access the post-redirect URL of the element clicked. If the Web Extension lacked the WebRequest permission for the hosts involved in the redirect, this would be a same-origin-violation leaking data the Web Extension should have access to. This was fixed to provide the pre-redirect URL. This is related to CVE-2021-43532 but in the context of Web Extensions. This vulnerability affects Firefox < 94.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-r92f-7624-w64m/GHSA-r92f-7624-w64m.json b/advisories/unreviewed/2021/12/GHSA-r92f-7624-w64m/GHSA-r92f-7624-w64m.json index 8140df6d1b1..ebed1806199 100644 --- a/advisories/unreviewed/2021/12/GHSA-r92f-7624-w64m/GHSA-r92f-7624-w64m.json +++ b/advisories/unreviewed/2021/12/GHSA-r92f-7624-w64m/GHSA-r92f-7624-w64m.json @@ -7,12 +7,8 @@ "CVE-2021-39053" ], "details": "IBM Spectrum Copy Data Management 2.2.13 and earlier could allow a remote attacker to obtain sensitive information, caused by the improper handling of requests for Spectrum Copy Data Management Admin Console. By sending a specially-crafted request, a remote attacker could exploit this vulnerability to obtain sensitive information. IBM X-Force ID: 214524.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2021/12/GHSA-r95c-3gx6-f23p/GHSA-r95c-3gx6-f23p.json b/advisories/unreviewed/2021/12/GHSA-r95c-3gx6-f23p/GHSA-r95c-3gx6-f23p.json index bca20fc1a28..16cbdf6f56e 100644 --- a/advisories/unreviewed/2021/12/GHSA-r95c-3gx6-f23p/GHSA-r95c-3gx6-f23p.json +++ b/advisories/unreviewed/2021/12/GHSA-r95c-3gx6-f23p/GHSA-r95c-3gx6-f23p.json @@ -7,12 +7,8 @@ "CVE-2021-39057" ], "details": "IBM Spectrum Protect Plus 10.1.0.0 through 10.1.8.x is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 214616.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-rc7g-prg9-344f/GHSA-rc7g-prg9-344f.json b/advisories/unreviewed/2021/12/GHSA-rc7g-prg9-344f/GHSA-rc7g-prg9-344f.json index b9af81bc8b9..1eafff1e957 100644 --- a/advisories/unreviewed/2021/12/GHSA-rc7g-prg9-344f/GHSA-rc7g-prg9-344f.json +++ b/advisories/unreviewed/2021/12/GHSA-rc7g-prg9-344f/GHSA-rc7g-prg9-344f.json @@ -7,12 +7,8 @@ "CVE-2021-43117" ], "details": "fastadmin v1.2.1 is affected by a file upload vulnerability which allows arbitrary code execution through shell access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-rq39-fwwc-45gh/GHSA-rq39-fwwc-45gh.json b/advisories/unreviewed/2021/12/GHSA-rq39-fwwc-45gh/GHSA-rq39-fwwc-45gh.json index 9757a83ea1c..9a5a01d6c0a 100644 --- a/advisories/unreviewed/2021/12/GHSA-rq39-fwwc-45gh/GHSA-rq39-fwwc-45gh.json +++ b/advisories/unreviewed/2021/12/GHSA-rq39-fwwc-45gh/GHSA-rq39-fwwc-45gh.json @@ -7,12 +7,8 @@ "CVE-2021-20143" ], "details": "An unauthenticated command injection vulnerability exists in the parameters of operation 48 in the controller_server service on Gryphon Tower routers. An unauthenticated remote attacker on the same network can execute commands as root on the device by sending a specially crafted malicious packet to the controller_server service on port 9999.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-rv4w-qmhg-65pf/GHSA-rv4w-qmhg-65pf.json b/advisories/unreviewed/2021/12/GHSA-rv4w-qmhg-65pf/GHSA-rv4w-qmhg-65pf.json index 30c4b52dcf1..9f92cc91d5f 100644 --- a/advisories/unreviewed/2021/12/GHSA-rv4w-qmhg-65pf/GHSA-rv4w-qmhg-65pf.json +++ b/advisories/unreviewed/2021/12/GHSA-rv4w-qmhg-65pf/GHSA-rv4w-qmhg-65pf.json @@ -7,12 +7,8 @@ "CVE-2020-19682" ], "details": "A Cross Site Request Forgery (CSRF) vulnerability exits in ZZZCMS V1.7.1 via the save_user funciton in save.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-rw6f-wgvq-rrvg/GHSA-rw6f-wgvq-rrvg.json b/advisories/unreviewed/2021/12/GHSA-rw6f-wgvq-rrvg/GHSA-rw6f-wgvq-rrvg.json index 20fa08c455c..03368da8a93 100644 --- a/advisories/unreviewed/2021/12/GHSA-rw6f-wgvq-rrvg/GHSA-rw6f-wgvq-rrvg.json +++ b/advisories/unreviewed/2021/12/GHSA-rw6f-wgvq-rrvg/GHSA-rw6f-wgvq-rrvg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-rx4w-62p5-v393/GHSA-rx4w-62p5-v393.json b/advisories/unreviewed/2021/12/GHSA-rx4w-62p5-v393/GHSA-rx4w-62p5-v393.json index 95fa9d1fa18..e1acbd8c64e 100644 --- a/advisories/unreviewed/2021/12/GHSA-rx4w-62p5-v393/GHSA-rx4w-62p5-v393.json +++ b/advisories/unreviewed/2021/12/GHSA-rx4w-62p5-v393/GHSA-rx4w-62p5-v393.json @@ -7,12 +7,8 @@ "CVE-2021-36911" ], "details": "Stored Cross-Site Scripting (XSS) vulnerability discovered in WordPress Comment Engine Pro plugin (versions <= 1.0), could be exploited by users with Editor or higher role.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-v2fg-9ph4-5293/GHSA-v2fg-9ph4-5293.json b/advisories/unreviewed/2021/12/GHSA-v2fg-9ph4-5293/GHSA-v2fg-9ph4-5293.json index b81c8d5ce84..658146f1904 100644 --- a/advisories/unreviewed/2021/12/GHSA-v2fg-9ph4-5293/GHSA-v2fg-9ph4-5293.json +++ b/advisories/unreviewed/2021/12/GHSA-v2fg-9ph4-5293/GHSA-v2fg-9ph4-5293.json @@ -7,12 +7,8 @@ "CVE-2021-43533" ], "details": "When parsing internationalized domain names, high bits of the characters in the URLs were sometimes stripped, resulting in inconsistencies that could lead to user confusion or attacks such as phishing. This vulnerability affects Firefox < 94.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2021/12/GHSA-v4qw-4358-7wh4/GHSA-v4qw-4358-7wh4.json b/advisories/unreviewed/2021/12/GHSA-v4qw-4358-7wh4/GHSA-v4qw-4358-7wh4.json index 91757230b4a..38cb1820bc6 100644 --- a/advisories/unreviewed/2021/12/GHSA-v4qw-4358-7wh4/GHSA-v4qw-4358-7wh4.json +++ b/advisories/unreviewed/2021/12/GHSA-v4qw-4358-7wh4/GHSA-v4qw-4358-7wh4.json @@ -7,12 +7,8 @@ "CVE-2021-39915" ], "details": "Improper access control in the GraphQL API in GitLab CE/EE affecting all versions starting from 13.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker to see the names of project access tokens on arbitrary projects", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-v87v-crjf-8qv4/GHSA-v87v-crjf-8qv4.json b/advisories/unreviewed/2021/12/GHSA-v87v-crjf-8qv4/GHSA-v87v-crjf-8qv4.json index 8cc79396d98..51a4071d15c 100644 --- a/advisories/unreviewed/2021/12/GHSA-v87v-crjf-8qv4/GHSA-v87v-crjf-8qv4.json +++ b/advisories/unreviewed/2021/12/GHSA-v87v-crjf-8qv4/GHSA-v87v-crjf-8qv4.json @@ -7,12 +7,8 @@ "CVE-2021-23860" ], "details": "An error in a page handler of the VRM may lead to a reflected cross site scripting (XSS) in the web-based interface. To exploit this vulnerability an attack must be able to modify the HTTP header that is sent. This issue also affects installations of the DIVAR IP and BVMS with VRM installed.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-v8wc-9v93-v894/GHSA-v8wc-9v93-v894.json b/advisories/unreviewed/2021/12/GHSA-v8wc-9v93-v894/GHSA-v8wc-9v93-v894.json index 5b4515706f0..12ccc90fb7b 100644 --- a/advisories/unreviewed/2021/12/GHSA-v8wc-9v93-v894/GHSA-v8wc-9v93-v894.json +++ b/advisories/unreviewed/2021/12/GHSA-v8wc-9v93-v894/GHSA-v8wc-9v93-v894.json @@ -7,12 +7,8 @@ "CVE-2021-40092" ], "details": "A cross-site scripting (XSS) vulnerability in Image Tile in SquaredUp for SCOM 5.2.1.6654 allows remote attackers to inject arbitrary web script or HTML via an SVG file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-v99f-7jp8-w888/GHSA-v99f-7jp8-w888.json b/advisories/unreviewed/2021/12/GHSA-v99f-7jp8-w888/GHSA-v99f-7jp8-w888.json index f45b07b2a88..28faaa76eb9 100644 --- a/advisories/unreviewed/2021/12/GHSA-v99f-7jp8-w888/GHSA-v99f-7jp8-w888.json +++ b/advisories/unreviewed/2021/12/GHSA-v99f-7jp8-w888/GHSA-v99f-7jp8-w888.json @@ -7,12 +7,8 @@ "CVE-2021-36189" ], "details": "A missing encryption of sensitive data in Fortinet FortiClientEMS version 7.0.1 and below, version 6.4.4 and below allows attacker to information disclosure via inspecting browser decrypted data", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-vgg4-9pr4-xc96/GHSA-vgg4-9pr4-xc96.json b/advisories/unreviewed/2021/12/GHSA-vgg4-9pr4-xc96/GHSA-vgg4-9pr4-xc96.json index 5c34c6e6adc..9c96d1626a6 100644 --- a/advisories/unreviewed/2021/12/GHSA-vgg4-9pr4-xc96/GHSA-vgg4-9pr4-xc96.json +++ b/advisories/unreviewed/2021/12/GHSA-vgg4-9pr4-xc96/GHSA-vgg4-9pr4-xc96.json @@ -7,12 +7,8 @@ "CVE-2021-41450" ], "details": "An HTTP request smuggling attack in TP-Link AX10v1 before v1_211117 allows a remote unauthenticated attacker to DoS the web application via sending a specific HTTP packet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-vj37-39rq-5f3g/GHSA-vj37-39rq-5f3g.json b/advisories/unreviewed/2021/12/GHSA-vj37-39rq-5f3g/GHSA-vj37-39rq-5f3g.json index a36c7640baf..7818e862728 100644 --- a/advisories/unreviewed/2021/12/GHSA-vj37-39rq-5f3g/GHSA-vj37-39rq-5f3g.json +++ b/advisories/unreviewed/2021/12/GHSA-vj37-39rq-5f3g/GHSA-vj37-39rq-5f3g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-vq57-688w-8qm4/GHSA-vq57-688w-8qm4.json b/advisories/unreviewed/2021/12/GHSA-vq57-688w-8qm4/GHSA-vq57-688w-8qm4.json index 74e4d6bafc2..d129eba5902 100644 --- a/advisories/unreviewed/2021/12/GHSA-vq57-688w-8qm4/GHSA-vq57-688w-8qm4.json +++ b/advisories/unreviewed/2021/12/GHSA-vq57-688w-8qm4/GHSA-vq57-688w-8qm4.json @@ -7,12 +7,8 @@ "CVE-2021-39063" ], "details": "IBM Spectrum Protect Plus 10.1.0.0 through 10.1.8.x uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information due to a misconfiguration in access control headers. IBM X-Force ID: 214956.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-vqm9-53v7-p2g4/GHSA-vqm9-53v7-p2g4.json b/advisories/unreviewed/2021/12/GHSA-vqm9-53v7-p2g4/GHSA-vqm9-53v7-p2g4.json index 4f1ff170ae3..378160d8ef2 100644 --- a/advisories/unreviewed/2021/12/GHSA-vqm9-53v7-p2g4/GHSA-vqm9-53v7-p2g4.json +++ b/advisories/unreviewed/2021/12/GHSA-vqm9-53v7-p2g4/GHSA-vqm9-53v7-p2g4.json @@ -7,12 +7,8 @@ "CVE-2021-25522" ], "details": "Insecure storage of sensitive information vulnerability in Smart Capture prior to version 4.8.02.10 allows attacker to access victim's captured images without permission.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-vrmc-c625-vvf7/GHSA-vrmc-c625-vvf7.json b/advisories/unreviewed/2021/12/GHSA-vrmc-c625-vvf7/GHSA-vrmc-c625-vvf7.json index 6485953b69c..af605733aff 100644 --- a/advisories/unreviewed/2021/12/GHSA-vrmc-c625-vvf7/GHSA-vrmc-c625-vvf7.json +++ b/advisories/unreviewed/2021/12/GHSA-vrmc-c625-vvf7/GHSA-vrmc-c625-vvf7.json @@ -7,12 +7,8 @@ "CVE-2021-38947" ], "details": "IBM Spectrum Copy Data Management 2.2.13 and earlier uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 211242.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-vrp3-rwcp-4q77/GHSA-vrp3-rwcp-4q77.json b/advisories/unreviewed/2021/12/GHSA-vrp3-rwcp-4q77/GHSA-vrp3-rwcp-4q77.json index 1c524444c7c..720c7bc78e6 100644 --- a/advisories/unreviewed/2021/12/GHSA-vrp3-rwcp-4q77/GHSA-vrp3-rwcp-4q77.json +++ b/advisories/unreviewed/2021/12/GHSA-vrp3-rwcp-4q77/GHSA-vrp3-rwcp-4q77.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-vvwh-jqqq-8v6c/GHSA-vvwh-jqqq-8v6c.json b/advisories/unreviewed/2021/12/GHSA-vvwh-jqqq-8v6c/GHSA-vvwh-jqqq-8v6c.json index 876e9e479d0..1a1631f5d1b 100644 --- a/advisories/unreviewed/2021/12/GHSA-vvwh-jqqq-8v6c/GHSA-vvwh-jqqq-8v6c.json +++ b/advisories/unreviewed/2021/12/GHSA-vvwh-jqqq-8v6c/GHSA-vvwh-jqqq-8v6c.json @@ -7,12 +7,8 @@ "CVE-2021-42549" ], "details": "Insufficient Input Validation in the search functionality of Wordpress plugin Lets-Box prior to 1.15.3 allows unauthenticated user to craft a reflected Cross-Site Scripting attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-w27q-xjw8-g94c/GHSA-w27q-xjw8-g94c.json b/advisories/unreviewed/2021/12/GHSA-w27q-xjw8-g94c/GHSA-w27q-xjw8-g94c.json index af2ad26c612..52a5c38f4e8 100644 --- a/advisories/unreviewed/2021/12/GHSA-w27q-xjw8-g94c/GHSA-w27q-xjw8-g94c.json +++ b/advisories/unreviewed/2021/12/GHSA-w27q-xjw8-g94c/GHSA-w27q-xjw8-g94c.json @@ -7,12 +7,8 @@ "CVE-2020-22421" ], "details": "74CMS v6.0.4 was discovered to contain a cross-site scripting (XSS) vulnerability via /index.php?m=&c=help&a=help_list&key.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-w37j-mvh3-43m8/GHSA-w37j-mvh3-43m8.json b/advisories/unreviewed/2021/12/GHSA-w37j-mvh3-43m8/GHSA-w37j-mvh3-43m8.json index 6f0ebf53793..0b7f1781fd4 100644 --- a/advisories/unreviewed/2021/12/GHSA-w37j-mvh3-43m8/GHSA-w37j-mvh3-43m8.json +++ b/advisories/unreviewed/2021/12/GHSA-w37j-mvh3-43m8/GHSA-w37j-mvh3-43m8.json @@ -7,12 +7,8 @@ "CVE-2021-31746" ], "details": "Zip Slip vulnerability in Pluck-CMS Pluck 4.7.15 allows an attacker to upload specially crafted zip files, resulting in directory traversal and potentially arbitrary code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-w54r-gmxf-p69m/GHSA-w54r-gmxf-p69m.json b/advisories/unreviewed/2021/12/GHSA-w54r-gmxf-p69m/GHSA-w54r-gmxf-p69m.json index 2c4610c34dc..616879c8827 100644 --- a/advisories/unreviewed/2021/12/GHSA-w54r-gmxf-p69m/GHSA-w54r-gmxf-p69m.json +++ b/advisories/unreviewed/2021/12/GHSA-w54r-gmxf-p69m/GHSA-w54r-gmxf-p69m.json @@ -7,12 +7,8 @@ "CVE-2021-44514" ], "details": "ManageEngine's OpUtils 12.5.556 and prior allow access to a few audit directories without authentication.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-w8xx-5j5x-h7v6/GHSA-w8xx-5j5x-h7v6.json b/advisories/unreviewed/2021/12/GHSA-w8xx-5j5x-h7v6/GHSA-w8xx-5j5x-h7v6.json index 03e449c190d..5ddc5a6409c 100644 --- a/advisories/unreviewed/2021/12/GHSA-w8xx-5j5x-h7v6/GHSA-w8xx-5j5x-h7v6.json +++ b/advisories/unreviewed/2021/12/GHSA-w8xx-5j5x-h7v6/GHSA-w8xx-5j5x-h7v6.json @@ -7,12 +7,8 @@ "CVE-2021-40861" ], "details": "A SQL Injection in the custom filter query component in Genesys intelligent Workload Distribution (IWD) 9.0.017.07 allows an attacker to execute arbitrary SQL queries via the value attribute, with which all data in the database can be extracted and OS command execution is possible depending on the permissions and/or database engine.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-w9fc-5fg9-fgph/GHSA-w9fc-5fg9-fgph.json b/advisories/unreviewed/2021/12/GHSA-w9fc-5fg9-fgph/GHSA-w9fc-5fg9-fgph.json index b15166e47f1..28c16e4d5d1 100644 --- a/advisories/unreviewed/2021/12/GHSA-w9fc-5fg9-fgph/GHSA-w9fc-5fg9-fgph.json +++ b/advisories/unreviewed/2021/12/GHSA-w9fc-5fg9-fgph/GHSA-w9fc-5fg9-fgph.json @@ -7,12 +7,8 @@ "CVE-2021-23859" ], "details": "An unauthenticated attacker is able to send a special HTTP request, that causes a service to crash. In case of a standalone VRM or BVMS with VRM installation this crash also opens the possibility to send further unauthenticated commands to the service. On some products the interface is only local accessible lowering the CVSS base score. For a list of modified CVSS scores, please see the official Bosch Advisory Appendix chapter Modified CVSS Scores for CVE-2021-23859", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-wgf2-cvhg-c384/GHSA-wgf2-cvhg-c384.json b/advisories/unreviewed/2021/12/GHSA-wgf2-cvhg-c384/GHSA-wgf2-cvhg-c384.json index 3538e43966d..4a0baf49237 100644 --- a/advisories/unreviewed/2021/12/GHSA-wgf2-cvhg-c384/GHSA-wgf2-cvhg-c384.json +++ b/advisories/unreviewed/2021/12/GHSA-wgf2-cvhg-c384/GHSA-wgf2-cvhg-c384.json @@ -7,12 +7,8 @@ "CVE-2021-4048" ], "details": "An out-of-bounds read flaw was found in the CLARRV, DLARRV, SLARRV, and ZLARRV functions in lapack through version 3.10.0, as also used in OpenBLAS before version 0.3.18. Specially crafted inputs passed to these functions could cause an application using lapack to crash or possibly disclose portions of its memory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-wp8f-r7rg-qrpg/GHSA-wp8f-r7rg-qrpg.json b/advisories/unreviewed/2021/12/GHSA-wp8f-r7rg-qrpg/GHSA-wp8f-r7rg-qrpg.json index f71d1cb5d47..eb53a4429cf 100644 --- a/advisories/unreviewed/2021/12/GHSA-wp8f-r7rg-qrpg/GHSA-wp8f-r7rg-qrpg.json +++ b/advisories/unreviewed/2021/12/GHSA-wp8f-r7rg-qrpg/GHSA-wp8f-r7rg-qrpg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-wp9j-fhh7-35qv/GHSA-wp9j-fhh7-35qv.json b/advisories/unreviewed/2021/12/GHSA-wp9j-fhh7-35qv/GHSA-wp9j-fhh7-35qv.json index fde3b0004a8..a72e30bccfe 100644 --- a/advisories/unreviewed/2021/12/GHSA-wp9j-fhh7-35qv/GHSA-wp9j-fhh7-35qv.json +++ b/advisories/unreviewed/2021/12/GHSA-wp9j-fhh7-35qv/GHSA-wp9j-fhh7-35qv.json @@ -7,12 +7,8 @@ "CVE-2021-26103" ], "details": "An insufficient verification of data authenticity vulnerability (CWE-345) in the user interface of FortiProxy verison 2.0.3 and below, 1.2.11 and below and FortiGate verison 7.0.0, 6.4.6 and below, 6.2.9 and below of SSL VPN portal may allow a remote, unauthenticated attacker to conduct a cross-site request forgery (CSRF) attack . Only SSL VPN in web mode or full mode are impacted by this vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-x28v-v72r-w8fj/GHSA-x28v-v72r-w8fj.json b/advisories/unreviewed/2021/12/GHSA-x28v-v72r-w8fj/GHSA-x28v-v72r-w8fj.json index 9bdeb4db3c3..564a45b2786 100644 --- a/advisories/unreviewed/2021/12/GHSA-x28v-v72r-w8fj/GHSA-x28v-v72r-w8fj.json +++ b/advisories/unreviewed/2021/12/GHSA-x28v-v72r-w8fj/GHSA-x28v-v72r-w8fj.json @@ -7,12 +7,8 @@ "CVE-2021-27984" ], "details": "In Pluck-4.7.15 admin background a remote command execution vulnerability exists when uploading files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-x4wq-ph23-36hw/GHSA-x4wq-ph23-36hw.json b/advisories/unreviewed/2021/12/GHSA-x4wq-ph23-36hw/GHSA-x4wq-ph23-36hw.json index 25ec83d2106..ac94e6cd3fb 100644 --- a/advisories/unreviewed/2021/12/GHSA-x4wq-ph23-36hw/GHSA-x4wq-ph23-36hw.json +++ b/advisories/unreviewed/2021/12/GHSA-x4wq-ph23-36hw/GHSA-x4wq-ph23-36hw.json @@ -7,12 +7,8 @@ "CVE-2021-36194" ], "details": "Multiple stack-based buffer overflows in the API controllers of FortiWeb 6.4.1, 6.4.0, and 6.3.0 through 6.3.15 may allow an authenticated attacker to achieve arbitrary code execution via specially crafted requests.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-x547-6pg3-h56r/GHSA-x547-6pg3-h56r.json b/advisories/unreviewed/2021/12/GHSA-x547-6pg3-h56r/GHSA-x547-6pg3-h56r.json index 9c80caa0f6f..89cee39a68b 100644 --- a/advisories/unreviewed/2021/12/GHSA-x547-6pg3-h56r/GHSA-x547-6pg3-h56r.json +++ b/advisories/unreviewed/2021/12/GHSA-x547-6pg3-h56r/GHSA-x547-6pg3-h56r.json @@ -7,12 +7,8 @@ "CVE-2021-24756" ], "details": "The WP System Log WordPress plugin before 1.0.21 does not sanitise, validate and escape the IP address retrieved from login requests before outputting them in the admin dashboard, which could allow unauthenticated attacker to perform Cross-Site Scripting attacks against admins viewing the logs.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-x5xq-hf4g-4cgq/GHSA-x5xq-hf4g-4cgq.json b/advisories/unreviewed/2021/12/GHSA-x5xq-hf4g-4cgq/GHSA-x5xq-hf4g-4cgq.json index 9ad129749cf..aafd013cc02 100644 --- a/advisories/unreviewed/2021/12/GHSA-x5xq-hf4g-4cgq/GHSA-x5xq-hf4g-4cgq.json +++ b/advisories/unreviewed/2021/12/GHSA-x5xq-hf4g-4cgq/GHSA-x5xq-hf4g-4cgq.json @@ -7,12 +7,8 @@ "CVE-2021-43532" ], "details": "The 'Copy Image Link' context menu action would copy the final image URL after redirects. By embedding an image that triggered authentication flows - in conjunction with a Content Security Policy that stopped a redirection chain in the middle - the final image URL could be one that contained an authentication token used to takeover a user account. If a website tricked a user into copy and pasting the image link back to the page, the page would be able to steal the authentication tokens. This was fixed by making the action return the original URL, before any redirects. This vulnerability affects Firefox < 94.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-x8r9-m3mh-g58r/GHSA-x8r9-m3mh-g58r.json b/advisories/unreviewed/2021/12/GHSA-x8r9-m3mh-g58r/GHSA-x8r9-m3mh-g58r.json index 5d442b34319..0b8dbca2f4a 100644 --- a/advisories/unreviewed/2021/12/GHSA-x8r9-m3mh-g58r/GHSA-x8r9-m3mh-g58r.json +++ b/advisories/unreviewed/2021/12/GHSA-x8r9-m3mh-g58r/GHSA-x8r9-m3mh-g58r.json @@ -7,12 +7,8 @@ "CVE-2021-43978" ], "details": "Allegro WIndows 3.3.4152.0, embeds software administrator database credentials into its binary files, which allows users to access and modify data using the same credentials.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-xcm8-pjqh-87pg/GHSA-xcm8-pjqh-87pg.json b/advisories/unreviewed/2021/12/GHSA-xcm8-pjqh-87pg/GHSA-xcm8-pjqh-87pg.json index 6c9056e39ff..f7e4b2e60a4 100644 --- a/advisories/unreviewed/2021/12/GHSA-xcm8-pjqh-87pg/GHSA-xcm8-pjqh-87pg.json +++ b/advisories/unreviewed/2021/12/GHSA-xcm8-pjqh-87pg/GHSA-xcm8-pjqh-87pg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-xh8q-q4r3-6x29/GHSA-xh8q-q4r3-6x29.json b/advisories/unreviewed/2021/12/GHSA-xh8q-q4r3-6x29/GHSA-xh8q-q4r3-6x29.json index 98ffb728e30..c61386dcbc5 100644 --- a/advisories/unreviewed/2021/12/GHSA-xh8q-q4r3-6x29/GHSA-xh8q-q4r3-6x29.json +++ b/advisories/unreviewed/2021/12/GHSA-xh8q-q4r3-6x29/GHSA-xh8q-q4r3-6x29.json @@ -7,12 +7,8 @@ "CVE-2021-39919" ], "details": "In all versions of GitLab CE/EE starting version 14.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, the reset password token and new user email token are accidentally logged which may lead to information disclosure.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-xhc5-mpp2-4rmp/GHSA-xhc5-mpp2-4rmp.json b/advisories/unreviewed/2021/12/GHSA-xhc5-mpp2-4rmp/GHSA-xhc5-mpp2-4rmp.json index d5a0a88a89c..c3fb227cdff 100644 --- a/advisories/unreviewed/2021/12/GHSA-xhc5-mpp2-4rmp/GHSA-xhc5-mpp2-4rmp.json +++ b/advisories/unreviewed/2021/12/GHSA-xhc5-mpp2-4rmp/GHSA-xhc5-mpp2-4rmp.json @@ -7,12 +7,8 @@ "CVE-2021-24954" ], "details": "The User Registration, Login Form, User Profile & Membership WordPress plugin before 3.2.3 does not sanitise and escape the ppress_cc_data parameter before outputting it back in an attribute of an admin dashboard page, leading to a Reflected Cross-Site Scripting issue", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-xhx3-2rfr-6x58/GHSA-xhx3-2rfr-6x58.json b/advisories/unreviewed/2021/12/GHSA-xhx3-2rfr-6x58/GHSA-xhx3-2rfr-6x58.json index 97a11a0d4a1..b02814ae6c4 100644 --- a/advisories/unreviewed/2021/12/GHSA-xhx3-2rfr-6x58/GHSA-xhx3-2rfr-6x58.json +++ b/advisories/unreviewed/2021/12/GHSA-xhx3-2rfr-6x58/GHSA-xhx3-2rfr-6x58.json @@ -7,12 +7,8 @@ "CVE-2021-20141" ], "details": "An unauthenticated command injection vulnerability exists in the parameters of operation 32 in the controller_server service on Gryphon Tower routers. An unauthenticated remote attacker on the same network can execute commands as root on the device by sending a specially crafted malicious packet to the controller_server service on port 9999.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-xp4c-cgxh-h77w/GHSA-xp4c-cgxh-h77w.json b/advisories/unreviewed/2021/12/GHSA-xp4c-cgxh-h77w/GHSA-xp4c-cgxh-h77w.json index 5aa553bec95..8775123f773 100644 --- a/advisories/unreviewed/2021/12/GHSA-xp4c-cgxh-h77w/GHSA-xp4c-cgxh-h77w.json +++ b/advisories/unreviewed/2021/12/GHSA-xp4c-cgxh-h77w/GHSA-xp4c-cgxh-h77w.json @@ -7,12 +7,8 @@ "CVE-2021-40093" ], "details": "A cross-site scripting (XSS) vulnerability in integration configuration in SquaredUp for SCOM 5.2.1.6654 allows remote attackers to inject arbitrary web script or HTML via dashboard actions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-xphm-wf5f-fcxm/GHSA-xphm-wf5f-fcxm.json b/advisories/unreviewed/2021/12/GHSA-xphm-wf5f-fcxm/GHSA-xphm-wf5f-fcxm.json index c06dadb971e..fb026e68e6c 100644 --- a/advisories/unreviewed/2021/12/GHSA-xphm-wf5f-fcxm/GHSA-xphm-wf5f-fcxm.json +++ b/advisories/unreviewed/2021/12/GHSA-xphm-wf5f-fcxm/GHSA-xphm-wf5f-fcxm.json @@ -7,12 +7,8 @@ "CVE-2021-41696" ], "details": "An authentication bypass (account takeover) vulnerability exists in Premiumdatingscript 4.2.7.7 due to a weak password reset mechanism in requests\\user.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-xqqh-6x8q-wqhc/GHSA-xqqh-6x8q-wqhc.json b/advisories/unreviewed/2021/12/GHSA-xqqh-6x8q-wqhc/GHSA-xqqh-6x8q-wqhc.json index a60b056e712..c6435baf8b4 100644 --- a/advisories/unreviewed/2021/12/GHSA-xqqh-6x8q-wqhc/GHSA-xqqh-6x8q-wqhc.json +++ b/advisories/unreviewed/2021/12/GHSA-xqqh-6x8q-wqhc/GHSA-xqqh-6x8q-wqhc.json @@ -7,12 +7,8 @@ "CVE-2021-24861" ], "details": "The Quotes Collection WordPress plugin through 2.5.2 does not validate and escape the bulkcheck parameter before using it in a SQL statement, leading to a SQL injection", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-xv2h-mwv5-j9r3/GHSA-xv2h-mwv5-j9r3.json b/advisories/unreviewed/2021/12/GHSA-xv2h-mwv5-j9r3/GHSA-xv2h-mwv5-j9r3.json index ae51fdbb13b..b1dee702803 100644 --- a/advisories/unreviewed/2021/12/GHSA-xv2h-mwv5-j9r3/GHSA-xv2h-mwv5-j9r3.json +++ b/advisories/unreviewed/2021/12/GHSA-xv2h-mwv5-j9r3/GHSA-xv2h-mwv5-j9r3.json @@ -7,12 +7,8 @@ "CVE-2021-44233" ], "details": "SAP GRC Access Control - versions V1100_700, V1100_731, V1200_750, does not perform necessary authorization checks for an authenticated user, which could lead to escalation of privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-xv5r-jf97-8xjm/GHSA-xv5r-jf97-8xjm.json b/advisories/unreviewed/2021/12/GHSA-xv5r-jf97-8xjm/GHSA-xv5r-jf97-8xjm.json index 7e2aa0574cc..3805dd22876 100644 --- a/advisories/unreviewed/2021/12/GHSA-xv5r-jf97-8xjm/GHSA-xv5r-jf97-8xjm.json +++ b/advisories/unreviewed/2021/12/GHSA-xv5r-jf97-8xjm/GHSA-xv5r-jf97-8xjm.json @@ -7,12 +7,8 @@ "CVE-2021-37935" ], "details": "An information disclosure vulnerability in the login page of Huntflow Enterprise before 3.10.4 could allow an unauthenticated, remote user to get information about the domain name of the configured LDAP server. An attacker could exploit this vulnerability by requesting the login page and searching for the \"isLdap\" JavaScript parameter in the HTML source code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-xvr9-h38m-rc5q/GHSA-xvr9-h38m-rc5q.json b/advisories/unreviewed/2021/12/GHSA-xvr9-h38m-rc5q/GHSA-xvr9-h38m-rc5q.json index b23d2071628..2f34cde68f9 100644 --- a/advisories/unreviewed/2021/12/GHSA-xvr9-h38m-rc5q/GHSA-xvr9-h38m-rc5q.json +++ b/advisories/unreviewed/2021/12/GHSA-xvr9-h38m-rc5q/GHSA-xvr9-h38m-rc5q.json @@ -7,12 +7,8 @@ "CVE-2021-24871" ], "details": "The Get Custom Field Values WordPress plugin before 4.0.1 does not escape custom fields before outputting them in the page, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-xwhx-6g69-79wc/GHSA-xwhx-6g69-79wc.json b/advisories/unreviewed/2021/12/GHSA-xwhx-6g69-79wc/GHSA-xwhx-6g69-79wc.json index 1da4d6c3e20..a17441c1aef 100644 --- a/advisories/unreviewed/2021/12/GHSA-xwhx-6g69-79wc/GHSA-xwhx-6g69-79wc.json +++ b/advisories/unreviewed/2021/12/GHSA-xwhx-6g69-79wc/GHSA-xwhx-6g69-79wc.json @@ -7,12 +7,8 @@ "CVE-2020-4496" ], "details": "The IBM Spectrum Protect Plus 10.1.0.0 through 10.1.8.x server connection to an IBM Spectrum Protect Plus workload agent is subject to a man-in-the-middle attack due to improper certificate validation. IBM X-Force ID: 182046.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-226c-wpq4-r9cj/GHSA-226c-wpq4-r9cj.json b/advisories/unreviewed/2022/05/GHSA-226c-wpq4-r9cj/GHSA-226c-wpq4-r9cj.json index 3878dd3f11e..cfd0b7bb638 100644 --- a/advisories/unreviewed/2022/05/GHSA-226c-wpq4-r9cj/GHSA-226c-wpq4-r9cj.json +++ b/advisories/unreviewed/2022/05/GHSA-226c-wpq4-r9cj/GHSA-226c-wpq4-r9cj.json @@ -7,12 +7,8 @@ "CVE-2009-2590" ], "details": "SQL injection vulnerability in showcategory.php in Hutscripts PHP Website Script allows remote attackers to execute arbitrary SQL commands via the cid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-24fj-8422-2v9w/GHSA-24fj-8422-2v9w.json b/advisories/unreviewed/2022/05/GHSA-24fj-8422-2v9w/GHSA-24fj-8422-2v9w.json index 9031bee6dd8..9800807e756 100644 --- a/advisories/unreviewed/2022/05/GHSA-24fj-8422-2v9w/GHSA-24fj-8422-2v9w.json +++ b/advisories/unreviewed/2022/05/GHSA-24fj-8422-2v9w/GHSA-24fj-8422-2v9w.json @@ -7,12 +7,8 @@ "CVE-2009-2516" ], "details": "The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold and SP1, and Server 2008 Gold does not properly validate data sent from user mode, which allows local users to gain privileges via a crafted PE .exe file that triggers a NULL pointer dereference during chain traversal, aka \"Windows Kernel NULL Pointer Dereference Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-24p4-658w-mxw6/GHSA-24p4-658w-mxw6.json b/advisories/unreviewed/2022/05/GHSA-24p4-658w-mxw6/GHSA-24p4-658w-mxw6.json index cc4bbd4d600..071c8b471d9 100644 --- a/advisories/unreviewed/2022/05/GHSA-24p4-658w-mxw6/GHSA-24p4-658w-mxw6.json +++ b/advisories/unreviewed/2022/05/GHSA-24p4-658w-mxw6/GHSA-24p4-658w-mxw6.json @@ -7,12 +7,8 @@ "CVE-2009-2924" ], "details": "Multiple SQL injection vulnerabilities in Videos Broadcast Yourself 2 allow remote attackers to execute arbitrary SQL commands via the (1) UploadID parameter to videoint.php, and possibly the (2) cat_id parameter to catvideo.php and (3) uid parameter to cviewchannels.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2589-6chq-5gj4/GHSA-2589-6chq-5gj4.json b/advisories/unreviewed/2022/05/GHSA-2589-6chq-5gj4/GHSA-2589-6chq-5gj4.json index ef1ad091f26..e53cb731559 100644 --- a/advisories/unreviewed/2022/05/GHSA-2589-6chq-5gj4/GHSA-2589-6chq-5gj4.json +++ b/advisories/unreviewed/2022/05/GHSA-2589-6chq-5gj4/GHSA-2589-6chq-5gj4.json @@ -7,12 +7,8 @@ "CVE-2009-2848" ], "details": "The execve function in the Linux kernel, possibly 2.6.30-rc6 and earlier, does not properly clear the current->clear_child_tid pointer, which allows local users to cause a denial of service (memory corruption) or possibly gain privileges via a clone system call with CLONE_CHILD_SETTID or CLONE_CHILD_CLEARTID enabled, which is not properly handled during thread creation and exit.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-25q8-wqrc-rrrr/GHSA-25q8-wqrc-rrrr.json b/advisories/unreviewed/2022/05/GHSA-25q8-wqrc-rrrr/GHSA-25q8-wqrc-rrrr.json index 767e450b59c..c3b042dbe0a 100644 --- a/advisories/unreviewed/2022/05/GHSA-25q8-wqrc-rrrr/GHSA-25q8-wqrc-rrrr.json +++ b/advisories/unreviewed/2022/05/GHSA-25q8-wqrc-rrrr/GHSA-25q8-wqrc-rrrr.json @@ -7,12 +7,8 @@ "CVE-2009-2579" ], "details": "SQL injection vulnerability in reward_points.post.php in the Reward points addon in CS-Cart before 2.0.6 allows remote authenticated users to execute arbitrary SQL commands via the sort_order parameter in a reward_points.userlog action to index.php, a different vulnerability than CVE-2005-4429.2.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-26gg-4hm3-4xgm/GHSA-26gg-4hm3-4xgm.json b/advisories/unreviewed/2022/05/GHSA-26gg-4hm3-4xgm/GHSA-26gg-4hm3-4xgm.json index 7bcaae0ea59..a3d3826030a 100644 --- a/advisories/unreviewed/2022/05/GHSA-26gg-4hm3-4xgm/GHSA-26gg-4hm3-4xgm.json +++ b/advisories/unreviewed/2022/05/GHSA-26gg-4hm3-4xgm/GHSA-26gg-4hm3-4xgm.json @@ -7,12 +7,8 @@ "CVE-2009-3164" ], "details": "Unspecified vulnerability in the IPv6 networking stack in Sun Solaris 10, and OpenSolaris snv_01 through snv_82 and snv_111 through snv_122, when a Cassini GigaSwift Ethernet Adapter (aka CE) interface is used, allows remote attackers to cause a denial of service (panic) via vectors involving jumbo frames. NOTE: this issue exists because of an incomplete fix for CVE-2009-2136.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-274m-66j7-crv4/GHSA-274m-66j7-crv4.json b/advisories/unreviewed/2022/05/GHSA-274m-66j7-crv4/GHSA-274m-66j7-crv4.json index f51aaa74476..2c89735a250 100644 --- a/advisories/unreviewed/2022/05/GHSA-274m-66j7-crv4/GHSA-274m-66j7-crv4.json +++ b/advisories/unreviewed/2022/05/GHSA-274m-66j7-crv4/GHSA-274m-66j7-crv4.json @@ -7,12 +7,8 @@ "CVE-2009-2691" ], "details": "The mm_for_maps function in fs/proc/base.c in the Linux kernel 2.6.30.4 and earlier allows local users to read (1) maps and (2) smaps files under proc/ via vectors related to ELF loading, a setuid process, and a race condition.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-284f-r3f8-mcp6/GHSA-284f-r3f8-mcp6.json b/advisories/unreviewed/2022/05/GHSA-284f-r3f8-mcp6/GHSA-284f-r3f8-mcp6.json index 69633581248..ea38c8d73f5 100644 --- a/advisories/unreviewed/2022/05/GHSA-284f-r3f8-mcp6/GHSA-284f-r3f8-mcp6.json +++ b/advisories/unreviewed/2022/05/GHSA-284f-r3f8-mcp6/GHSA-284f-r3f8-mcp6.json @@ -7,12 +7,8 @@ "CVE-2009-2634" ], "details": "PHP remote file inclusion vulnerability in toolbar_ext.php in the MediaLibrary (com_media_library) component 1.5.3 Basic for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-28gm-vh7p-5c7v/GHSA-28gm-vh7p-5c7v.json b/advisories/unreviewed/2022/05/GHSA-28gm-vh7p-5c7v/GHSA-28gm-vh7p-5c7v.json index c8c7723ab05..976bdb645ff 100644 --- a/advisories/unreviewed/2022/05/GHSA-28gm-vh7p-5c7v/GHSA-28gm-vh7p-5c7v.json +++ b/advisories/unreviewed/2022/05/GHSA-28gm-vh7p-5c7v/GHSA-28gm-vh7p-5c7v.json @@ -7,12 +7,8 @@ "CVE-2009-3060" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Joker Board (aka JBoard) 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the notice parameter to editform.php, (2) the edit_user_message parameter to core/edit_user_message.php, or (3) the user_title parameter to inc/head.inc.php, reachable through any PHP script.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2c4v-vhcv-h8xg/GHSA-2c4v-vhcv-h8xg.json b/advisories/unreviewed/2022/05/GHSA-2c4v-vhcv-h8xg/GHSA-2c4v-vhcv-h8xg.json index 12996247090..f4404d598cc 100644 --- a/advisories/unreviewed/2022/05/GHSA-2c4v-vhcv-h8xg/GHSA-2c4v-vhcv-h8xg.json +++ b/advisories/unreviewed/2022/05/GHSA-2c4v-vhcv-h8xg/GHSA-2c4v-vhcv-h8xg.json @@ -7,12 +7,8 @@ "CVE-2009-2973" ], "details": "Google Chrome before 2.0.172.43 does not prevent SSL connections to a site with an X.509 certificate signed with the (1) MD2 or (2) MD4 algorithm, which makes it easier for man-in-the-middle attackers to spoof arbitrary HTTPS servers via a crafted certificate, a related issue to CVE-2009-2409.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2c59-mm9r-vwwg/GHSA-2c59-mm9r-vwwg.json b/advisories/unreviewed/2022/05/GHSA-2c59-mm9r-vwwg/GHSA-2c59-mm9r-vwwg.json index 87feca0c6e9..286b851c831 100644 --- a/advisories/unreviewed/2022/05/GHSA-2c59-mm9r-vwwg/GHSA-2c59-mm9r-vwwg.json +++ b/advisories/unreviewed/2022/05/GHSA-2c59-mm9r-vwwg/GHSA-2c59-mm9r-vwwg.json @@ -7,12 +7,8 @@ "CVE-2009-3035" ], "details": "The web console in Symantec Altiris Notification Server 6.0.x before 6.0 SP3 R12 uses a hardcoded key that can decrypt SQL Server credentials and certain discovery credentials, and stores this key on the Notification Server machine, which allows local users to obtain sensitive information and possibly execute arbitrary code by decrypting and using these credentials.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2c6f-jjmq-4hv4/GHSA-2c6f-jjmq-4hv4.json b/advisories/unreviewed/2022/05/GHSA-2c6f-jjmq-4hv4/GHSA-2c6f-jjmq-4hv4.json index 9c7e316c069..bc6842d9088 100644 --- a/advisories/unreviewed/2022/05/GHSA-2c6f-jjmq-4hv4/GHSA-2c6f-jjmq-4hv4.json +++ b/advisories/unreviewed/2022/05/GHSA-2c6f-jjmq-4hv4/GHSA-2c6f-jjmq-4hv4.json @@ -7,12 +7,8 @@ "CVE-2009-2640" ], "details": "Multiple SQL injection vulnerabilities in cgi/admin.cgi in Interlogy Profile Manager Basic allow remote attackers to execute arbitrary SQL commands via a pmadm cookie in (1) an edittemp action or (2) a users action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2f6q-9673-2g62/GHSA-2f6q-9673-2g62.json b/advisories/unreviewed/2022/05/GHSA-2f6q-9673-2g62/GHSA-2f6q-9673-2g62.json index 9bf0c77c2fa..f8bd51b57ca 100644 --- a/advisories/unreviewed/2022/05/GHSA-2f6q-9673-2g62/GHSA-2f6q-9673-2g62.json +++ b/advisories/unreviewed/2022/05/GHSA-2f6q-9673-2g62/GHSA-2f6q-9673-2g62.json @@ -7,12 +7,8 @@ "CVE-2009-2834" ], "details": "IOKit in Apple Mac OS X before 10.6.2 allows local users to modify the firmware of a (1) USB or (2) Bluetooth keyboard via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2gq8-v73v-2x6j/GHSA-2gq8-v73v-2x6j.json b/advisories/unreviewed/2022/05/GHSA-2gq8-v73v-2x6j/GHSA-2gq8-v73v-2x6j.json index 0fcdd2405ab..70d5d972cac 100644 --- a/advisories/unreviewed/2022/05/GHSA-2gq8-v73v-2x6j/GHSA-2gq8-v73v-2x6j.json +++ b/advisories/unreviewed/2022/05/GHSA-2gq8-v73v-2x6j/GHSA-2gq8-v73v-2x6j.json @@ -7,12 +7,8 @@ "CVE-2009-2994" ], "details": "Buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 might allow attackers to execute arbitrary code via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2gxr-wcww-qxm9/GHSA-2gxr-wcww-qxm9.json b/advisories/unreviewed/2022/05/GHSA-2gxr-wcww-qxm9/GHSA-2gxr-wcww-qxm9.json index 1509b0e649c..1f1279c900b 100644 --- a/advisories/unreviewed/2022/05/GHSA-2gxr-wcww-qxm9/GHSA-2gxr-wcww-qxm9.json +++ b/advisories/unreviewed/2022/05/GHSA-2gxr-wcww-qxm9/GHSA-2gxr-wcww-qxm9.json @@ -7,12 +7,8 @@ "CVE-2009-2916" ], "details": "Format string vulnerability in the CNS_AddTxt function in logs.dll in 2K Games Vietcong 2 1.10 and earlier might allow remote attackers to execute arbitrary code via format string specifiers in the nickname.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2mfh-952f-g7hg/GHSA-2mfh-952f-g7hg.json b/advisories/unreviewed/2022/05/GHSA-2mfh-952f-g7hg/GHSA-2mfh-952f-g7hg.json index 6a97af14d44..0ee92f840d2 100644 --- a/advisories/unreviewed/2022/05/GHSA-2mfh-952f-g7hg/GHSA-2mfh-952f-g7hg.json +++ b/advisories/unreviewed/2022/05/GHSA-2mfh-952f-g7hg/GHSA-2mfh-952f-g7hg.json @@ -7,12 +7,8 @@ "CVE-2009-2678" ], "details": "Unspecified vulnerability in Open System Services (OSS) Name Server on HP NonStop G06.27, G06.28, G06.29, G06.30, H06.06, H06.07, H06.08, and J06.03 allows remote attackers to obtain sensitive information via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2mwr-5rv2-5mxh/GHSA-2mwr-5rv2-5mxh.json b/advisories/unreviewed/2022/05/GHSA-2mwr-5rv2-5mxh/GHSA-2mwr-5rv2-5mxh.json index a11015a09ea..fd21c9af543 100644 --- a/advisories/unreviewed/2022/05/GHSA-2mwr-5rv2-5mxh/GHSA-2mwr-5rv2-5mxh.json +++ b/advisories/unreviewed/2022/05/GHSA-2mwr-5rv2-5mxh/GHSA-2mwr-5rv2-5mxh.json @@ -7,12 +7,8 @@ "CVE-2009-2952" ], "details": "Unspecified vulnerability in the pollwakeup function in Sun Solaris 10, and OpenSolaris before snv_51, allows local users to cause a denial of service (panic) via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2p9w-qq57-w5jv/GHSA-2p9w-qq57-w5jv.json b/advisories/unreviewed/2022/05/GHSA-2p9w-qq57-w5jv/GHSA-2p9w-qq57-w5jv.json index ccab78c2ba2..01956286084 100644 --- a/advisories/unreviewed/2022/05/GHSA-2p9w-qq57-w5jv/GHSA-2p9w-qq57-w5jv.json +++ b/advisories/unreviewed/2022/05/GHSA-2p9w-qq57-w5jv/GHSA-2p9w-qq57-w5jv.json @@ -7,12 +7,8 @@ "CVE-2009-2803" ], "details": "CarbonCore in Apple Mac OS X 10.4.11 and 10.5.8 allows attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a file with a crafted resource fork.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2pjq-rfqm-7x97/GHSA-2pjq-rfqm-7x97.json b/advisories/unreviewed/2022/05/GHSA-2pjq-rfqm-7x97/GHSA-2pjq-rfqm-7x97.json index cfef1922ac2..be558c8744a 100644 --- a/advisories/unreviewed/2022/05/GHSA-2pjq-rfqm-7x97/GHSA-2pjq-rfqm-7x97.json +++ b/advisories/unreviewed/2022/05/GHSA-2pjq-rfqm-7x97/GHSA-2pjq-rfqm-7x97.json @@ -7,12 +7,8 @@ "CVE-2009-3065" ], "details": "PHP remote file inclusion vulnerability in editor/edit_htmlarea.php in Ve-EDIT 0.1.4 allows remote attackers to execute arbitrary PHP code via a URL in the highlighter parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2rjp-vrf3-8qx8/GHSA-2rjp-vrf3-8qx8.json b/advisories/unreviewed/2022/05/GHSA-2rjp-vrf3-8qx8/GHSA-2rjp-vrf3-8qx8.json index b71b9150b9b..bc26ff97fa1 100644 --- a/advisories/unreviewed/2022/05/GHSA-2rjp-vrf3-8qx8/GHSA-2rjp-vrf3-8qx8.json +++ b/advisories/unreviewed/2022/05/GHSA-2rjp-vrf3-8qx8/GHSA-2rjp-vrf3-8qx8.json @@ -7,12 +7,8 @@ "CVE-2009-2656" ], "details": "Unspecified vulnerability in the com.android.phone process in Android 1.0, 1.1, and 1.5 allows remote attackers to cause a denial of service (network disconnection) via a crafted SMS message, as demonstrated by Collin Mulliner and Charlie Miller at Black Hat USA 2009.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2rq6-m3fr-ffm2/GHSA-2rq6-m3fr-ffm2.json b/advisories/unreviewed/2022/05/GHSA-2rq6-m3fr-ffm2/GHSA-2rq6-m3fr-ffm2.json index 5931a30c378..27e7bb18a0b 100644 --- a/advisories/unreviewed/2022/05/GHSA-2rq6-m3fr-ffm2/GHSA-2rq6-m3fr-ffm2.json +++ b/advisories/unreviewed/2022/05/GHSA-2rq6-m3fr-ffm2/GHSA-2rq6-m3fr-ffm2.json @@ -7,12 +7,8 @@ "CVE-2009-3033" ], "details": "Buffer overflow in the RunCmd method in the Altiris eXpress NS Console Utilities ActiveX control in AeXNSConsoleUtilities.dll in the web console in Symantec Altiris Deployment Solution 6.9.x, Altiris Notification Server 6.0.x, and Management Platform 7.0.x allows remote attackers to execute arbitrary code via a long string in the second argument.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2wm6-3pg4-h6hp/GHSA-2wm6-3pg4-h6hp.json b/advisories/unreviewed/2022/05/GHSA-2wm6-3pg4-h6hp/GHSA-2wm6-3pg4-h6hp.json index bf4352b3ce5..9464cd5df82 100644 --- a/advisories/unreviewed/2022/05/GHSA-2wm6-3pg4-h6hp/GHSA-2wm6-3pg4-h6hp.json +++ b/advisories/unreviewed/2022/05/GHSA-2wm6-3pg4-h6hp/GHSA-2wm6-3pg4-h6hp.json @@ -7,12 +7,8 @@ "CVE-2009-3174" ], "details": "PHP remote file inclusion vulnerability in fonctions_racine.php in OBOphiX 2.7.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the chemin_lib parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2wv4-x82r-pj66/GHSA-2wv4-x82r-pj66.json b/advisories/unreviewed/2022/05/GHSA-2wv4-x82r-pj66/GHSA-2wv4-x82r-pj66.json index 8a516ea078f..a9ef60f50f0 100644 --- a/advisories/unreviewed/2022/05/GHSA-2wv4-x82r-pj66/GHSA-2wv4-x82r-pj66.json +++ b/advisories/unreviewed/2022/05/GHSA-2wv4-x82r-pj66/GHSA-2wv4-x82r-pj66.json @@ -7,12 +7,8 @@ "CVE-2009-2889" ], "details": "Cross-site scripting (XSS) vulnerability in index.php in PHP Scripts Now Hangman allows remote attackers to inject arbitrary web script or HTML via the letters parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2wxv-94xf-vqv2/GHSA-2wxv-94xf-vqv2.json b/advisories/unreviewed/2022/05/GHSA-2wxv-94xf-vqv2/GHSA-2wxv-94xf-vqv2.json index ab78c18a0e2..d35878de2b2 100644 --- a/advisories/unreviewed/2022/05/GHSA-2wxv-94xf-vqv2/GHSA-2wxv-94xf-vqv2.json +++ b/advisories/unreviewed/2022/05/GHSA-2wxv-94xf-vqv2/GHSA-2wxv-94xf-vqv2.json @@ -7,12 +7,8 @@ "CVE-2009-2816" ], "details": "The implementation of Cross-Origin Resource Sharing (CORS) in WebKit, as used in Apple Safari before 4.0.4 and Google Chrome before 3.0.195.33, includes certain custom HTTP headers in the OPTIONS request during cross-origin operations with preflight, which makes it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks via a crafted web page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2xr8-cfj3-j3g6/GHSA-2xr8-cfj3-j3g6.json b/advisories/unreviewed/2022/05/GHSA-2xr8-cfj3-j3g6/GHSA-2xr8-cfj3-j3g6.json index 196e85b2120..9d83ddcbc13 100644 --- a/advisories/unreviewed/2022/05/GHSA-2xr8-cfj3-j3g6/GHSA-2xr8-cfj3-j3g6.json +++ b/advisories/unreviewed/2022/05/GHSA-2xr8-cfj3-j3g6/GHSA-2xr8-cfj3-j3g6.json @@ -7,12 +7,8 @@ "CVE-2009-2597" ], "details": "The Sun Java System (SJS) Access Manager Policy Agent module 2.2 for SJS Web Proxy Server 4.0 allows remote attackers to cause a denial of service (daemon crash) via a GET request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3237-mfpp-3f69/GHSA-3237-mfpp-3f69.json b/advisories/unreviewed/2022/05/GHSA-3237-mfpp-3f69/GHSA-3237-mfpp-3f69.json index 460dfcbf64d..af3282a5703 100644 --- a/advisories/unreviewed/2022/05/GHSA-3237-mfpp-3f69/GHSA-3237-mfpp-3f69.json +++ b/advisories/unreviewed/2022/05/GHSA-3237-mfpp-3f69/GHSA-3237-mfpp-3f69.json @@ -7,12 +7,8 @@ "CVE-2009-3184" ], "details": "Multiple SQL injection vulnerabilities in index.php in Pirates of The Caribbean in the E-Gold Game Series allow remote attackers to execute arbitrary SQL commands via the (1) x and (2) y parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-32ch-hx5j-xxhq/GHSA-32ch-hx5j-xxhq.json b/advisories/unreviewed/2022/05/GHSA-32ch-hx5j-xxhq/GHSA-32ch-hx5j-xxhq.json index 3b5e7aadf06..062f0183c58 100644 --- a/advisories/unreviewed/2022/05/GHSA-32ch-hx5j-xxhq/GHSA-32ch-hx5j-xxhq.json +++ b/advisories/unreviewed/2022/05/GHSA-32ch-hx5j-xxhq/GHSA-32ch-hx5j-xxhq.json @@ -7,12 +7,8 @@ "CVE-2009-2972" ], "details": "in.lpd in the print service in Sun Solaris 8 and 9 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors that trigger a \"fork()/exec() bomb.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-337w-hr8c-gg4f/GHSA-337w-hr8c-gg4f.json b/advisories/unreviewed/2022/05/GHSA-337w-hr8c-gg4f/GHSA-337w-hr8c-gg4f.json index eecee3953b5..0d00f019791 100644 --- a/advisories/unreviewed/2022/05/GHSA-337w-hr8c-gg4f/GHSA-337w-hr8c-gg4f.json +++ b/advisories/unreviewed/2022/05/GHSA-337w-hr8c-gg4f/GHSA-337w-hr8c-gg4f.json @@ -7,12 +7,8 @@ "CVE-2009-2643" ], "details": "Multiple unspecified vulnerabilities in the PDF distiller in the Attachment Service component in Research In Motion (RIM) BlackBerry Enterprise Server (BES) software 4.1.3 through 5.0 and BlackBerry Professional Software 4.1.4 allow user-assisted remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted .pdf file attachment, a different vulnerability than CVE-2008-3246 and CVE-2009-0219.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-338r-39f8-6rqm/GHSA-338r-39f8-6rqm.json b/advisories/unreviewed/2022/05/GHSA-338r-39f8-6rqm/GHSA-338r-39f8-6rqm.json index 9587a217da6..b0094e1ecb6 100644 --- a/advisories/unreviewed/2022/05/GHSA-338r-39f8-6rqm/GHSA-338r-39f8-6rqm.json +++ b/advisories/unreviewed/2022/05/GHSA-338r-39f8-6rqm/GHSA-338r-39f8-6rqm.json @@ -7,12 +7,8 @@ "CVE-2009-2648" ], "details": "FlashDen Guestbook allows remote attackers to obtain configuration information via a direct request to amfphp/phpinfo.php, which calls the phpinfo function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3564-89gh-mmc9/GHSA-3564-89gh-mmc9.json b/advisories/unreviewed/2022/05/GHSA-3564-89gh-mmc9/GHSA-3564-89gh-mmc9.json index 054ebf09785..adaf1a3e2de 100644 --- a/advisories/unreviewed/2022/05/GHSA-3564-89gh-mmc9/GHSA-3564-89gh-mmc9.json +++ b/advisories/unreviewed/2022/05/GHSA-3564-89gh-mmc9/GHSA-3564-89gh-mmc9.json @@ -7,12 +7,8 @@ "CVE-2009-3150" ], "details": "SQL injection vulnerability in index.php in Multi Website 1.5 allows remote attackers to execute arbitrary SQL commands via the Browse parameter in a vote action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-35r5-pw6j-5f37/GHSA-35r5-pw6j-5f37.json b/advisories/unreviewed/2022/05/GHSA-35r5-pw6j-5f37/GHSA-35r5-pw6j-5f37.json index d4a0c137c18..af7935eeae2 100644 --- a/advisories/unreviewed/2022/05/GHSA-35r5-pw6j-5f37/GHSA-35r5-pw6j-5f37.json +++ b/advisories/unreviewed/2022/05/GHSA-35r5-pw6j-5f37/GHSA-35r5-pw6j-5f37.json @@ -7,12 +7,8 @@ "CVE-2009-2868" ], "details": "Unspecified vulnerability in Cisco IOS 12.2 through 12.4, when certificate-based authentication is enabled for IKE, allows remote attackers to cause a denial of service (Phase 1 SA exhaustion) via crafted requests, aka Bug IDs CSCsy07555 and CSCee72997.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-36cj-jv5c-963p/GHSA-36cj-jv5c-963p.json b/advisories/unreviewed/2022/05/GHSA-36cj-jv5c-963p/GHSA-36cj-jv5c-963p.json index add71b6ed7e..8ebd6277dd0 100644 --- a/advisories/unreviewed/2022/05/GHSA-36cj-jv5c-963p/GHSA-36cj-jv5c-963p.json +++ b/advisories/unreviewed/2022/05/GHSA-36cj-jv5c-963p/GHSA-36cj-jv5c-963p.json @@ -7,12 +7,8 @@ "CVE-2009-2592" ], "details": "SQL injection vulnerability in guestbook.php in PHPJunkYard GBook 1.6 allows remote attackers to execute arbitrary SQL commands via the mes_id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-36j8-893c-jhgw/GHSA-36j8-893c-jhgw.json b/advisories/unreviewed/2022/05/GHSA-36j8-893c-jhgw/GHSA-36j8-893c-jhgw.json index 20b750b4b14..bad3a0e59db 100644 --- a/advisories/unreviewed/2022/05/GHSA-36j8-893c-jhgw/GHSA-36j8-893c-jhgw.json +++ b/advisories/unreviewed/2022/05/GHSA-36j8-893c-jhgw/GHSA-36j8-893c-jhgw.json @@ -7,12 +7,8 @@ "CVE-2009-2824" ], "details": "Multiple buffer overflows in Apple Type Services (ATS) in Apple Mac OS X 10.5.8 allow remote attackers to execute arbitrary code via a crafted embedded font in a document.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-38gh-v47f-3r7c/GHSA-38gh-v47f-3r7c.json b/advisories/unreviewed/2022/05/GHSA-38gh-v47f-3r7c/GHSA-38gh-v47f-3r7c.json index b7ed13170b5..af41e29cd43 100644 --- a/advisories/unreviewed/2022/05/GHSA-38gh-v47f-3r7c/GHSA-38gh-v47f-3r7c.json +++ b/advisories/unreviewed/2022/05/GHSA-38gh-v47f-3r7c/GHSA-38gh-v47f-3r7c.json @@ -7,12 +7,8 @@ "CVE-2009-2896" ], "details": "Buffer overflow in KMplayer 2.9.4.1433 and earlier allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a long string in a subtitle (.srt) playlist file. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-38m7-p48j-3jpx/GHSA-38m7-p48j-3jpx.json b/advisories/unreviewed/2022/05/GHSA-38m7-p48j-3jpx/GHSA-38m7-p48j-3jpx.json index 86f2b864816..213e5aaa2c5 100644 --- a/advisories/unreviewed/2022/05/GHSA-38m7-p48j-3jpx/GHSA-38m7-p48j-3jpx.json +++ b/advisories/unreviewed/2022/05/GHSA-38m7-p48j-3jpx/GHSA-38m7-p48j-3jpx.json @@ -7,12 +7,8 @@ "CVE-2009-2869" ], "details": "Unspecified vulnerability in Cisco IOS 12.2XNA, 12.2XNB, 12.2XNC, 12.2XND, 12.4MD, 12.4T, 12.4XZ, and 12.4YA allows remote attackers to cause a denial of service (device reload) via a crafted NTPv4 packet, aka Bug IDs CSCsu24505 and CSCsv75948.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-38w6-8hf5-r299/GHSA-38w6-8hf5-r299.json b/advisories/unreviewed/2022/05/GHSA-38w6-8hf5-r299/GHSA-38w6-8hf5-r299.json index 957dd57b717..a08efb1187e 100644 --- a/advisories/unreviewed/2022/05/GHSA-38w6-8hf5-r299/GHSA-38w6-8hf5-r299.json +++ b/advisories/unreviewed/2022/05/GHSA-38w6-8hf5-r299/GHSA-38w6-8hf5-r299.json @@ -7,12 +7,8 @@ "CVE-2009-3076" ], "details": "Mozilla Firefox before 3.0.14 does not properly implement certain dialogs associated with the (1) pkcs11.addmodule and (2) pkcs11.deletemodule operations, which makes it easier for remote attackers to trick a user into installing or removing an arbitrary PKCS11 module.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -100,9 +96,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-39jq-h4cx-9j2q/GHSA-39jq-h4cx-9j2q.json b/advisories/unreviewed/2022/05/GHSA-39jq-h4cx-9j2q/GHSA-39jq-h4cx-9j2q.json index 8b88c146322..648272f06c2 100644 --- a/advisories/unreviewed/2022/05/GHSA-39jq-h4cx-9j2q/GHSA-39jq-h4cx-9j2q.json +++ b/advisories/unreviewed/2022/05/GHSA-39jq-h4cx-9j2q/GHSA-39jq-h4cx-9j2q.json @@ -7,12 +7,8 @@ "CVE-2009-3162" ], "details": "Cross-site scripting (XSS) vulnerability in Multi Website 1.5 allows remote attackers to inject arbitrary web script or HTML via the search parameter in a search action to the default URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-39qg-c7hm-9wwf/GHSA-39qg-c7hm-9wwf.json b/advisories/unreviewed/2022/05/GHSA-39qg-c7hm-9wwf/GHSA-39qg-c7hm-9wwf.json index d42ea329537..6933295a586 100644 --- a/advisories/unreviewed/2022/05/GHSA-39qg-c7hm-9wwf/GHSA-39qg-c7hm-9wwf.json +++ b/advisories/unreviewed/2022/05/GHSA-39qg-c7hm-9wwf/GHSA-39qg-c7hm-9wwf.json @@ -7,12 +7,8 @@ "CVE-2009-3026" ], "details": "protocols/jabber/auth.c in libpurple in Pidgin 2.6.0, and possibly other versions, does not follow the \"require TLS/SSL\" preference when connecting to older Jabber servers that do not follow the XMPP specification, which causes libpurple to connect to the server without the expected encryption and allows remote attackers to sniff sessions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3c23-3vh8-88jr/GHSA-3c23-3vh8-88jr.json b/advisories/unreviewed/2022/05/GHSA-3c23-3vh8-88jr/GHSA-3c23-3vh8-88jr.json index ca66698aa99..94bd806cc43 100644 --- a/advisories/unreviewed/2022/05/GHSA-3c23-3vh8-88jr/GHSA-3c23-3vh8-88jr.json +++ b/advisories/unreviewed/2022/05/GHSA-3c23-3vh8-88jr/GHSA-3c23-3vh8-88jr.json @@ -7,12 +7,8 @@ "CVE-2009-2499" ], "details": "Microsoft Windows Media Format Runtime 9.0, 9.5, and 11; and Microsoft Media Foundation on Windows Vista Gold, SP1, and SP2 and Server 2008; allows remote attackers to execute arbitrary code via an MP3 file with crafted metadata that triggers memory corruption, aka \"Windows Media Playback Memory Corruption Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3c54-7fm7-g696/GHSA-3c54-7fm7-g696.json b/advisories/unreviewed/2022/05/GHSA-3c54-7fm7-g696/GHSA-3c54-7fm7-g696.json index 20101342ce0..2cf001cc9dc 100644 --- a/advisories/unreviewed/2022/05/GHSA-3c54-7fm7-g696/GHSA-3c54-7fm7-g696.json +++ b/advisories/unreviewed/2022/05/GHSA-3c54-7fm7-g696/GHSA-3c54-7fm7-g696.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3cm9-r84w-4v7c/GHSA-3cm9-r84w-4v7c.json b/advisories/unreviewed/2022/05/GHSA-3cm9-r84w-4v7c/GHSA-3cm9-r84w-4v7c.json index edbae794fb1..f3dc4238de4 100644 --- a/advisories/unreviewed/2022/05/GHSA-3cm9-r84w-4v7c/GHSA-3cm9-r84w-4v7c.json +++ b/advisories/unreviewed/2022/05/GHSA-3cm9-r84w-4v7c/GHSA-3cm9-r84w-4v7c.json @@ -7,12 +7,8 @@ "CVE-2009-2738" ], "details": "Cross-site request forgery (CSRF) vulnerability in the WebGUI in FreeNAS before 0.7RC1 allows remote attackers to hijack the authentication of users for unspecified requests via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3fh4-76x3-9pjc/GHSA-3fh4-76x3-9pjc.json b/advisories/unreviewed/2022/05/GHSA-3fh4-76x3-9pjc/GHSA-3fh4-76x3-9pjc.json index 9afbb202753..d1953bcb291 100644 --- a/advisories/unreviewed/2022/05/GHSA-3fh4-76x3-9pjc/GHSA-3fh4-76x3-9pjc.json +++ b/advisories/unreviewed/2022/05/GHSA-3fh4-76x3-9pjc/GHSA-3fh4-76x3-9pjc.json @@ -7,12 +7,8 @@ "CVE-2009-2674" ], "details": "Integer overflow in javaws.exe in Sun Java Web Start in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 allows context-dependent attackers to execute arbitrary code via a crafted JPEG image that is not properly handled during display to a splash screen, which triggers a heap-based buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -124,9 +120,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3gcj-hw9g-gmm2/GHSA-3gcj-hw9g-gmm2.json b/advisories/unreviewed/2022/05/GHSA-3gcj-hw9g-gmm2/GHSA-3gcj-hw9g-gmm2.json index ef66fe3e967..629c46c5b63 100644 --- a/advisories/unreviewed/2022/05/GHSA-3gcj-hw9g-gmm2/GHSA-3gcj-hw9g-gmm2.json +++ b/advisories/unreviewed/2022/05/GHSA-3gcj-hw9g-gmm2/GHSA-3gcj-hw9g-gmm2.json @@ -7,12 +7,8 @@ "CVE-2009-3025" ], "details": "Unspecified vulnerability in Pidgin 2.6.0 allows remote attackers to cause a denial of service (crash) via a link in a Yahoo IM.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3gh7-cv65-5fg2/GHSA-3gh7-cv65-5fg2.json b/advisories/unreviewed/2022/05/GHSA-3gh7-cv65-5fg2/GHSA-3gh7-cv65-5fg2.json index 3392f991ccd..2a91da72c35 100644 --- a/advisories/unreviewed/2022/05/GHSA-3gh7-cv65-5fg2/GHSA-3gh7-cv65-5fg2.json +++ b/advisories/unreviewed/2022/05/GHSA-3gh7-cv65-5fg2/GHSA-3gh7-cv65-5fg2.json @@ -7,12 +7,8 @@ "CVE-2009-2633" ], "details": "PHP remote file inclusion vulnerability in toolbar_ext.php in the VehicleManager (com_vehiclemanager) component 1.0 Basic for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3gwf-437g-7hgf/GHSA-3gwf-437g-7hgf.json b/advisories/unreviewed/2022/05/GHSA-3gwf-437g-7hgf/GHSA-3gwf-437g-7hgf.json index e3e39bb2fe0..377b286debd 100644 --- a/advisories/unreviewed/2022/05/GHSA-3gwf-437g-7hgf/GHSA-3gwf-437g-7hgf.json +++ b/advisories/unreviewed/2022/05/GHSA-3gwf-437g-7hgf/GHSA-3gwf-437g-7hgf.json @@ -7,12 +7,8 @@ "CVE-2009-2805" ], "details": "Integer overflow in CoreGraphics in Apple Mac OS X 10.4.11 and 10.5.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JBIG2 stream in a PDF file, leading to a heap-based buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3jjj-2fhq-8hwq/GHSA-3jjj-2fhq-8hwq.json b/advisories/unreviewed/2022/05/GHSA-3jjj-2fhq-8hwq/GHSA-3jjj-2fhq-8hwq.json index fe1a84764fa..99634c0916f 100644 --- a/advisories/unreviewed/2022/05/GHSA-3jjj-2fhq-8hwq/GHSA-3jjj-2fhq-8hwq.json +++ b/advisories/unreviewed/2022/05/GHSA-3jjj-2fhq-8hwq/GHSA-3jjj-2fhq-8hwq.json @@ -7,12 +7,8 @@ "CVE-2009-3021" ], "details": "Cross-site scripting (XSS) vulnerability in Site Calendar 'mycaljp' plugin 2.0.0 through 2.0.6, as used in the Japanese extended package of Geeklog 1.5.0 through 1.5.2 and when distributed 20090629 or earlier, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3jw8-9rgf-396w/GHSA-3jw8-9rgf-396w.json b/advisories/unreviewed/2022/05/GHSA-3jw8-9rgf-396w/GHSA-3jw8-9rgf-396w.json index c6494b43550..26258c7ac5b 100644 --- a/advisories/unreviewed/2022/05/GHSA-3jw8-9rgf-396w/GHSA-3jw8-9rgf-396w.json +++ b/advisories/unreviewed/2022/05/GHSA-3jw8-9rgf-396w/GHSA-3jw8-9rgf-396w.json @@ -7,12 +7,8 @@ "CVE-2009-2510" ], "details": "The CryptoAPI component in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, as used by Internet Explorer and other applications, does not properly handle a '\\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, aka \"Null Truncation in X.509 Common Name Vulnerability,\" a related issue to CVE-2009-2408.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3m8m-gfg5-5q83/GHSA-3m8m-gfg5-5q83.json b/advisories/unreviewed/2022/05/GHSA-3m8m-gfg5-5q83/GHSA-3m8m-gfg5-5q83.json index 9d97d1d34e7..7750d170717 100644 --- a/advisories/unreviewed/2022/05/GHSA-3m8m-gfg5-5q83/GHSA-3m8m-gfg5-5q83.json +++ b/advisories/unreviewed/2022/05/GHSA-3m8m-gfg5-5q83/GHSA-3m8m-gfg5-5q83.json @@ -7,12 +7,8 @@ "CVE-2009-3247" ], "details": "Cross-site scripting (XSS) vulnerability in the Activities module in vtiger CRM 5.0.4 allows remote attackers to inject arbitrary web script or HTML via the action parameter to phprint.php. NOTE: the query_string vector is already covered by CVE-2008-3101.3.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3mp6-x287-jf43/GHSA-3mp6-x287-jf43.json b/advisories/unreviewed/2022/05/GHSA-3mp6-x287-jf43/GHSA-3mp6-x287-jf43.json index bdd665e7a4c..67e3a3b654d 100644 --- a/advisories/unreviewed/2022/05/GHSA-3mp6-x287-jf43/GHSA-3mp6-x287-jf43.json +++ b/advisories/unreviewed/2022/05/GHSA-3mp6-x287-jf43/GHSA-3mp6-x287-jf43.json @@ -7,12 +7,8 @@ "CVE-2009-2898" ], "details": "Cross-site scripting (XSS) vulnerability in the Alerts list feature in the web interface in SpringSource Hyperic HQ 3.2.x before 3.2.6.1, 4.0.x before 4.0.3.1, 4.1.x before 4.1.2.1, and 4.2-beta1; Application Management Suite (AMS) 2.0.0.SR3; and tc Server 6.0.20.B allows remote authenticated users to inject arbitrary web script or HTML via the Description field. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3mv4-77hr-gc5g/GHSA-3mv4-77hr-gc5g.json b/advisories/unreviewed/2022/05/GHSA-3mv4-77hr-gc5g/GHSA-3mv4-77hr-gc5g.json index d95c2cae1bb..f571dcac23d 100644 --- a/advisories/unreviewed/2022/05/GHSA-3mv4-77hr-gc5g/GHSA-3mv4-77hr-gc5g.json +++ b/advisories/unreviewed/2022/05/GHSA-3mv4-77hr-gc5g/GHSA-3mv4-77hr-gc5g.json @@ -7,12 +7,8 @@ "CVE-2009-2812" ], "details": "Launch Services in Apple Mac OS X 10.5.8 does not properly recognize an unsafe Uniform Type Identifier (UTI) in an exported document type in a downloaded application, which allows remote attackers to trigger the automatic opening of a file, and execute arbitrary code, via a crafted web site.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3pm5-9xjq-m3q6/GHSA-3pm5-9xjq-m3q6.json b/advisories/unreviewed/2022/05/GHSA-3pm5-9xjq-m3q6/GHSA-3pm5-9xjq-m3q6.json index 8968f450242..b53f244b419 100644 --- a/advisories/unreviewed/2022/05/GHSA-3pm5-9xjq-m3q6/GHSA-3pm5-9xjq-m3q6.json +++ b/advisories/unreviewed/2022/05/GHSA-3pm5-9xjq-m3q6/GHSA-3pm5-9xjq-m3q6.json @@ -7,12 +7,8 @@ "CVE-2009-2753" ], "details": "Multiple buffer overflows in the authentication functionality in librpc.dll in the Informix Storage Manager (ISM) Portmapper service (aka portmap.exe), as used in IBM Informix Dynamic Server (IDS) 10.x before 10.00.TC9 and 11.x before 11.10.TC3, allow remote attackers to execute arbitrary code via a crafted parameter size.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3qmw-6w2g-9g2c/GHSA-3qmw-6w2g-9g2c.json b/advisories/unreviewed/2022/05/GHSA-3qmw-6w2g-9g2c/GHSA-3qmw-6w2g-9g2c.json index df6f413b7cc..f974c659a6d 100644 --- a/advisories/unreviewed/2022/05/GHSA-3qmw-6w2g-9g2c/GHSA-3qmw-6w2g-9g2c.json +++ b/advisories/unreviewed/2022/05/GHSA-3qmw-6w2g-9g2c/GHSA-3qmw-6w2g-9g2c.json @@ -7,12 +7,8 @@ "CVE-2009-3170" ], "details": "Stack-based buffer overflow in AIMP2 Audio Converter 2.53 (build 330) and earlier allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long File1 argument in a (1) .pls or (2) .m3u playlist file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3qxm-qv9f-98xq/GHSA-3qxm-qv9f-98xq.json b/advisories/unreviewed/2022/05/GHSA-3qxm-qv9f-98xq/GHSA-3qxm-qv9f-98xq.json index ff4ee97e330..445547b5dc9 100644 --- a/advisories/unreviewed/2022/05/GHSA-3qxm-qv9f-98xq/GHSA-3qxm-qv9f-98xq.json +++ b/advisories/unreviewed/2022/05/GHSA-3qxm-qv9f-98xq/GHSA-3qxm-qv9f-98xq.json @@ -7,12 +7,8 @@ "CVE-2009-3082" ], "details": "SQL injection vulnerability in wcategory.php in Snow Hall Silurus System 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3qxw-7f8c-wvj7/GHSA-3qxw-7f8c-wvj7.json b/advisories/unreviewed/2022/05/GHSA-3qxw-7f8c-wvj7/GHSA-3qxw-7f8c-wvj7.json index 5626303f838..9ba8d046516 100644 --- a/advisories/unreviewed/2022/05/GHSA-3qxw-7f8c-wvj7/GHSA-3qxw-7f8c-wvj7.json +++ b/advisories/unreviewed/2022/05/GHSA-3qxw-7f8c-wvj7/GHSA-3qxw-7f8c-wvj7.json @@ -7,12 +7,8 @@ "CVE-2009-2999" ], "details": "The com.android.phone process in Android 1.5 CRBxx allows remote attackers to cause a denial of service (application restart and network disconnection) via an SMS message containing a malformed WAP Push message that triggers an ArrayIndexOutOfBoundsException exception, possibly a related issue to CVE-2009-2656.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3r8g-564w-2jq8/GHSA-3r8g-564w-2jq8.json b/advisories/unreviewed/2022/05/GHSA-3r8g-564w-2jq8/GHSA-3r8g-564w-2jq8.json index 9b6f036f3cf..b80e1706720 100644 --- a/advisories/unreviewed/2022/05/GHSA-3r8g-564w-2jq8/GHSA-3r8g-564w-2jq8.json +++ b/advisories/unreviewed/2022/05/GHSA-3r8g-564w-2jq8/GHSA-3r8g-564w-2jq8.json @@ -7,12 +7,8 @@ "CVE-2009-3056" ], "details": "PHP remote file inclusion vulnerability in include/engine/content/elements/menu.php in KingCMS 0.6.0 allows remote attackers to execute arbitrary PHP code via a URL in the CONFIG[AdminPath] parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3rgv-v89r-wjff/GHSA-3rgv-v89r-wjff.json b/advisories/unreviewed/2022/05/GHSA-3rgv-v89r-wjff/GHSA-3rgv-v89r-wjff.json index 0985503bafd..ee7fc6fceb5 100644 --- a/advisories/unreviewed/2022/05/GHSA-3rgv-v89r-wjff/GHSA-3rgv-v89r-wjff.json +++ b/advisories/unreviewed/2022/05/GHSA-3rgv-v89r-wjff/GHSA-3rgv-v89r-wjff.json @@ -7,12 +7,8 @@ "CVE-2009-3299" ], "details": "Cross-site scripting (XSS) vulnerability in the resume blocktype in Mahara before 1.0.13, and 1.1.x before 1.1.7, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3rph-v6j3-hfch/GHSA-3rph-v6j3-hfch.json b/advisories/unreviewed/2022/05/GHSA-3rph-v6j3-hfch/GHSA-3rph-v6j3-hfch.json index 9d1f475eaf5..b665fac692a 100644 --- a/advisories/unreviewed/2022/05/GHSA-3rph-v6j3-hfch/GHSA-3rph-v6j3-hfch.json +++ b/advisories/unreviewed/2022/05/GHSA-3rph-v6j3-hfch/GHSA-3rph-v6j3-hfch.json @@ -7,12 +7,8 @@ "CVE-2009-2764" ], "details": "Microsoft Internet Explorer 8.0.7100.0 on Windows 7 RC on the x64 platform allows remote attackers to cause a denial of service (application crash) via a certain DIV element in conjunction with SCRIPT elements that have empty contents and no reference to a valid external script location.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3v4w-v493-36w7/GHSA-3v4w-v493-36w7.json b/advisories/unreviewed/2022/05/GHSA-3v4w-v493-36w7/GHSA-3v4w-v493-36w7.json index 7c2490c224f..67f80b3d4ed 100644 --- a/advisories/unreviewed/2022/05/GHSA-3v4w-v493-36w7/GHSA-3v4w-v493-36w7.json +++ b/advisories/unreviewed/2022/05/GHSA-3v4w-v493-36w7/GHSA-3v4w-v493-36w7.json @@ -7,12 +7,8 @@ "CVE-2009-2509" ], "details": "Active Directory Federation Services (ADFS) in Microsoft Windows Server 2003 SP2 and Server 2008 Gold and SP2 does not properly validate headers in HTTP requests, which allows remote authenticated users to execute arbitrary code via a crafted request to an IIS web server, aka \"Remote Code Execution in ADFS Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3vqg-cv53-whw6/GHSA-3vqg-cv53-whw6.json b/advisories/unreviewed/2022/05/GHSA-3vqg-cv53-whw6/GHSA-3vqg-cv53-whw6.json index 54400e7ca30..133fe25a27a 100644 --- a/advisories/unreviewed/2022/05/GHSA-3vqg-cv53-whw6/GHSA-3vqg-cv53-whw6.json +++ b/advisories/unreviewed/2022/05/GHSA-3vqg-cv53-whw6/GHSA-3vqg-cv53-whw6.json @@ -7,12 +7,8 @@ "CVE-2009-2505" ], "details": "The Internet Authentication Service (IAS) in Microsoft Windows Vista SP2 and Server 2008 SP2 does not properly validate MS-CHAP v2 Protected Extensible Authentication Protocol (PEAP) authentication requests, which allows remote attackers to execute arbitrary code via crafted structures in a malformed request, aka \"Internet Authentication Service Memory Corruption Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3wh4-9fpj-4gx2/GHSA-3wh4-9fpj-4gx2.json b/advisories/unreviewed/2022/05/GHSA-3wh4-9fpj-4gx2/GHSA-3wh4-9fpj-4gx2.json index 7f22766607f..1eaca5d8e35 100644 --- a/advisories/unreviewed/2022/05/GHSA-3wh4-9fpj-4gx2/GHSA-3wh4-9fpj-4gx2.json +++ b/advisories/unreviewed/2022/05/GHSA-3wh4-9fpj-4gx2/GHSA-3wh4-9fpj-4gx2.json @@ -7,12 +7,8 @@ "CVE-2009-2931" ], "details": "Directory traversal vulnerability in p.php in SlideShowPro Director 1.1 through 1.3.8 allows remote attackers to read arbitrary files via directory traversal sequences in the a parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3wh5-4rmj-5jxh/GHSA-3wh5-4rmj-5jxh.json b/advisories/unreviewed/2022/05/GHSA-3wh5-4rmj-5jxh/GHSA-3wh5-4rmj-5jxh.json index cfbfdc5e32e..4dd1435946a 100644 --- a/advisories/unreviewed/2022/05/GHSA-3wh5-4rmj-5jxh/GHSA-3wh5-4rmj-5jxh.json +++ b/advisories/unreviewed/2022/05/GHSA-3wh5-4rmj-5jxh/GHSA-3wh5-4rmj-5jxh.json @@ -7,12 +7,8 @@ "CVE-2009-2602" ], "details": "R2 Newsletter Lite, Pro, and Stats stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for admin.mdb.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3wmj-6h74-prmg/GHSA-3wmj-6h74-prmg.json b/advisories/unreviewed/2022/05/GHSA-3wmj-6h74-prmg/GHSA-3wmj-6h74-prmg.json index d55bdfeadd1..b2b307ad934 100644 --- a/advisories/unreviewed/2022/05/GHSA-3wmj-6h74-prmg/GHSA-3wmj-6h74-prmg.json +++ b/advisories/unreviewed/2022/05/GHSA-3wmj-6h74-prmg/GHSA-3wmj-6h74-prmg.json @@ -7,12 +7,8 @@ "CVE-2009-3155" ], "details": "Cross-site scripting (XSS) vulnerability in gmap.php in the Almond Classifieds (com_aclassf) component 7.5 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the addr parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3wv8-c9pw-2c36/GHSA-3wv8-c9pw-2c36.json b/advisories/unreviewed/2022/05/GHSA-3wv8-c9pw-2c36/GHSA-3wv8-c9pw-2c36.json index 76860a9328e..e36ee91a001 100644 --- a/advisories/unreviewed/2022/05/GHSA-3wv8-c9pw-2c36/GHSA-3wv8-c9pw-2c36.json +++ b/advisories/unreviewed/2022/05/GHSA-3wv8-c9pw-2c36/GHSA-3wv8-c9pw-2c36.json @@ -7,12 +7,8 @@ "CVE-2009-2957" ], "details": "Heap-based buffer overflow in the tftp_request function in tftp.c in dnsmasq before 2.50, when --enable-tftp is used, might allow remote attackers to execute arbitrary code via a long filename in a TFTP packet, as demonstrated by a read (aka RRQ) request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-432m-fhgv-3568/GHSA-432m-fhgv-3568.json b/advisories/unreviewed/2022/05/GHSA-432m-fhgv-3568/GHSA-432m-fhgv-3568.json index abf22d322fb..d89ce8a2346 100644 --- a/advisories/unreviewed/2022/05/GHSA-432m-fhgv-3568/GHSA-432m-fhgv-3568.json +++ b/advisories/unreviewed/2022/05/GHSA-432m-fhgv-3568/GHSA-432m-fhgv-3568.json @@ -7,12 +7,8 @@ "CVE-2009-2791" ], "details": "PHP remote file inclusion vulnerability in pda_projects.php in WebDynamite ProjectButler 1.5.0 allows remote attackers to execute arbitrary PHP code via a URL in the offset parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-44gq-3r46-fprm/GHSA-44gq-3r46-fprm.json b/advisories/unreviewed/2022/05/GHSA-44gq-3r46-fprm/GHSA-44gq-3r46-fprm.json index 6109969165d..5896f62c4d5 100644 --- a/advisories/unreviewed/2022/05/GHSA-44gq-3r46-fprm/GHSA-44gq-3r46-fprm.json +++ b/advisories/unreviewed/2022/05/GHSA-44gq-3r46-fprm/GHSA-44gq-3r46-fprm.json @@ -7,12 +7,8 @@ "CVE-2009-3242" ], "details": "Unspecified vulnerability in packet.c in the GSM A RR dissector in Wireshark 1.2.0 and 1.2.1 allows remote attackers to cause a denial of service (application crash) via unknown vectors related to \"an uninitialized dissector handle,\" which triggers an assertion failure.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-44vw-5m8p-p6fc/GHSA-44vw-5m8p-p6fc.json b/advisories/unreviewed/2022/05/GHSA-44vw-5m8p-p6fc/GHSA-44vw-5m8p-p6fc.json index 338a68fff13..12e99e8f027 100644 --- a/advisories/unreviewed/2022/05/GHSA-44vw-5m8p-p6fc/GHSA-44vw-5m8p-p6fc.json +++ b/advisories/unreviewed/2022/05/GHSA-44vw-5m8p-p6fc/GHSA-44vw-5m8p-p6fc.json @@ -7,12 +7,8 @@ "CVE-2009-2595" ], "details": "Cross-site scripting (XSS) vulnerability in productSearch.html in Censura 2.0.4 and 2.1.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter in a ProductSearch action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-462q-5367-hv76/GHSA-462q-5367-hv76.json b/advisories/unreviewed/2022/05/GHSA-462q-5367-hv76/GHSA-462q-5367-hv76.json index 0cdf06e03f4..8d64ef42054 100644 --- a/advisories/unreviewed/2022/05/GHSA-462q-5367-hv76/GHSA-462q-5367-hv76.json +++ b/advisories/unreviewed/2022/05/GHSA-462q-5367-hv76/GHSA-462q-5367-hv76.json @@ -7,12 +7,8 @@ "CVE-2009-2686" ], "details": "Unspecified vulnerability in HP NonStop G06.12.00 through G06.32.00, H06.08.00 through H06.18.01, and J06.04.00 through J06.07.01 allows local users to gain privileges, cause a denial of service, or obtain \"access to data\" via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-46cp-3g9x-pvj9/GHSA-46cp-3g9x-pvj9.json b/advisories/unreviewed/2022/05/GHSA-46cp-3g9x-pvj9/GHSA-46cp-3g9x-pvj9.json index c053c7fb032..c5726fb01c6 100644 --- a/advisories/unreviewed/2022/05/GHSA-46cp-3g9x-pvj9/GHSA-46cp-3g9x-pvj9.json +++ b/advisories/unreviewed/2022/05/GHSA-46cp-3g9x-pvj9/GHSA-46cp-3g9x-pvj9.json @@ -7,12 +7,8 @@ "CVE-2009-2894" ], "details": "Multiple SQL injection vulnerabilities in Ebay Clone 2009 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to product_desc.php, and the cid parameter to (2) showcategory.php and (3) gallery.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-46qm-6m33-4283/GHSA-46qm-6m33-4283.json b/advisories/unreviewed/2022/05/GHSA-46qm-6m33-4283/GHSA-46qm-6m33-4283.json index 214d0acb1dd..0388817c80b 100644 --- a/advisories/unreviewed/2022/05/GHSA-46qm-6m33-4283/GHSA-46qm-6m33-4283.json +++ b/advisories/unreviewed/2022/05/GHSA-46qm-6m33-4283/GHSA-46qm-6m33-4283.json @@ -7,12 +7,8 @@ "CVE-2009-2861" ], "details": "The Over-the-Air Provisioning (OTAP) functionality on Cisco Aironet Lightweight Access Point 1100 and 1200 devices does not properly implement access-point association, which allows remote attackers to spoof a controller and cause a denial of service (service outage) via crafted remote radio management (RRM) packets, aka \"SkyJack\" or Bug ID CSCtb56664.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-47c7-xq7g-3v46/GHSA-47c7-xq7g-3v46.json b/advisories/unreviewed/2022/05/GHSA-47c7-xq7g-3v46/GHSA-47c7-xq7g-3v46.json index d7e3d84e57b..6029c8af5f8 100644 --- a/advisories/unreviewed/2022/05/GHSA-47c7-xq7g-3v46/GHSA-47c7-xq7g-3v46.json +++ b/advisories/unreviewed/2022/05/GHSA-47c7-xq7g-3v46/GHSA-47c7-xq7g-3v46.json @@ -7,12 +7,8 @@ "CVE-2009-2830" ], "details": "Multiple buffer overflows in Christos Zoulas file before 5.03 in Apple Mac OS X 10.6.x before 10.6.2 allow user-assisted remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Common Document Format (CDF) file. NOTE: this might overlap CVE-2009-1515.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4c9p-fq6h-4839/GHSA-4c9p-fq6h-4839.json b/advisories/unreviewed/2022/05/GHSA-4c9p-fq6h-4839/GHSA-4c9p-fq6h-4839.json index d0477642afb..9a3272df137 100644 --- a/advisories/unreviewed/2022/05/GHSA-4c9p-fq6h-4839/GHSA-4c9p-fq6h-4839.json +++ b/advisories/unreviewed/2022/05/GHSA-4c9p-fq6h-4839/GHSA-4c9p-fq6h-4839.json @@ -7,12 +7,8 @@ "CVE-2009-3252" ], "details": "Multiple SQL injection vulnerabilities in news.php in Rock Band CMS 0.10 allow remote attackers to execute arbitrary SQL commands via the (1) year and (2) id parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4crp-jh2p-xg7w/GHSA-4crp-jh2p-xg7w.json b/advisories/unreviewed/2022/05/GHSA-4crp-jh2p-xg7w/GHSA-4crp-jh2p-xg7w.json index 999ae0e808a..d264f3415ec 100644 --- a/advisories/unreviewed/2022/05/GHSA-4crp-jh2p-xg7w/GHSA-4crp-jh2p-xg7w.json +++ b/advisories/unreviewed/2022/05/GHSA-4crp-jh2p-xg7w/GHSA-4crp-jh2p-xg7w.json @@ -7,12 +7,8 @@ "CVE-2009-3163" ], "details": "Multiple format string vulnerabilities in lib/silcclient/command.c in Secure Internet Live Conferencing (SILC) Toolkit before 1.1.10, and SILC Client 1.1.8 and earlier, allow remote attackers to execute arbitrary code via format string specifiers in a channel name, related to (1) silc_client_command_topic, (2) silc_client_command_kick, (3) silc_client_command_leave, and (4) silc_client_command_users.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4fch-ghwj-4wq6/GHSA-4fch-ghwj-4wq6.json b/advisories/unreviewed/2022/05/GHSA-4fch-ghwj-4wq6/GHSA-4fch-ghwj-4wq6.json index c1a5f5b722e..ead6b462f55 100644 --- a/advisories/unreviewed/2022/05/GHSA-4fch-ghwj-4wq6/GHSA-4fch-ghwj-4wq6.json +++ b/advisories/unreviewed/2022/05/GHSA-4fch-ghwj-4wq6/GHSA-4fch-ghwj-4wq6.json @@ -7,12 +7,8 @@ "CVE-2009-3258" ], "details": "vtiger CRM before 5.1.0 allows remote authenticated users, with certain View privileges, to delete (1) attachments, (2) reports, (3) filters, (4) views, and (5) tickets; insert (6) attachments, (7) reports, (8) filters, (9) views, and (10) tickets; and edit (11) reports, (12) filters, (13) views, and (14) tickets via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4fhc-2vjg-rx26/GHSA-4fhc-2vjg-rx26.json b/advisories/unreviewed/2022/05/GHSA-4fhc-2vjg-rx26/GHSA-4fhc-2vjg-rx26.json index d0e1d95dd17..b94173c6140 100644 --- a/advisories/unreviewed/2022/05/GHSA-4fhc-2vjg-rx26/GHSA-4fhc-2vjg-rx26.json +++ b/advisories/unreviewed/2022/05/GHSA-4fhc-2vjg-rx26/GHSA-4fhc-2vjg-rx26.json @@ -7,12 +7,8 @@ "CVE-2009-3040" ], "details": "Multiple SQL injection vulnerabilities in Open Computer and Software (OCS) Inventory NG 1.02 for Unix allow remote attackers to execute arbitrary SQL commands via the (1) N, (2) DL, (3) O and (4) V parameters to download.php and the (5) SYSTEMID parameter to group_show.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4frw-vv4p-5hrq/GHSA-4frw-vv4p-5hrq.json b/advisories/unreviewed/2022/05/GHSA-4frw-vv4p-5hrq/GHSA-4frw-vv4p-5hrq.json index 22135c89160..083364f158a 100644 --- a/advisories/unreviewed/2022/05/GHSA-4frw-vv4p-5hrq/GHSA-4frw-vv4p-5hrq.json +++ b/advisories/unreviewed/2022/05/GHSA-4frw-vv4p-5hrq/GHSA-4frw-vv4p-5hrq.json @@ -7,12 +7,8 @@ "CVE-2009-2992" ], "details": "An unspecified ActiveX control in Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 does not properly validate input, which allows attackers to cause a denial of service via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4h5h-76c6-8744/GHSA-4h5h-76c6-8744.json b/advisories/unreviewed/2022/05/GHSA-4h5h-76c6-8744/GHSA-4h5h-76c6-8744.json index dbce2a73f28..4ffeef8f729 100644 --- a/advisories/unreviewed/2022/05/GHSA-4h5h-76c6-8744/GHSA-4h5h-76c6-8744.json +++ b/advisories/unreviewed/2022/05/GHSA-4h5h-76c6-8744/GHSA-4h5h-76c6-8744.json @@ -7,12 +7,8 @@ "CVE-2009-2654" ], "details": "Mozilla Firefox before 3.0.13, and 3.5.x before 3.5.2, allows remote attackers to spoof the address bar, and possibly conduct phishing attacks, via a crafted web page that calls window.open with an invalid character in the URL, makes document.write calls to the resulting object, and then calls the stop method during the loading of the error page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4jq6-q6h2-8qqx/GHSA-4jq6-q6h2-8qqx.json b/advisories/unreviewed/2022/05/GHSA-4jq6-q6h2-8qqx/GHSA-4jq6-q6h2-8qqx.json index 59cc17b87eb..4796284f29c 100644 --- a/advisories/unreviewed/2022/05/GHSA-4jq6-q6h2-8qqx/GHSA-4jq6-q6h2-8qqx.json +++ b/advisories/unreviewed/2022/05/GHSA-4jq6-q6h2-8qqx/GHSA-4jq6-q6h2-8qqx.json @@ -7,12 +7,8 @@ "CVE-2009-3006" ], "details": "Maxthon Browser 2.5.3.80 UNICODE allows remote attackers to spoof the address bar, via window.open with a relative URI, to show an arbitrary URL on the web site visited by the victim, as demonstrated by a visit to an attacker-controlled web page, which triggers a spoofed login form for the site containing that page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4px9-25hv-vh6p/GHSA-4px9-25hv-vh6p.json b/advisories/unreviewed/2022/05/GHSA-4px9-25hv-vh6p/GHSA-4px9-25hv-vh6p.json index f78c532c0d7..803383a2bb1 100644 --- a/advisories/unreviewed/2022/05/GHSA-4px9-25hv-vh6p/GHSA-4px9-25hv-vh6p.json +++ b/advisories/unreviewed/2022/05/GHSA-4px9-25hv-vh6p/GHSA-4px9-25hv-vh6p.json @@ -7,12 +7,8 @@ "CVE-2009-2500" ], "details": "Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a crafted WMF image file, aka \"GDI+ WMF Integer Overflow Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4qq2-3gjp-fjvr/GHSA-4qq2-3gjp-fjvr.json b/advisories/unreviewed/2022/05/GHSA-4qq2-3gjp-fjvr/GHSA-4qq2-3gjp-fjvr.json index e0717332b8e..d036a4d6ba8 100644 --- a/advisories/unreviewed/2022/05/GHSA-4qq2-3gjp-fjvr/GHSA-4qq2-3gjp-fjvr.json +++ b/advisories/unreviewed/2022/05/GHSA-4qq2-3gjp-fjvr/GHSA-4qq2-3gjp-fjvr.json @@ -7,12 +7,8 @@ "CVE-2009-3159" ], "details": "Unspecified vulnerability in the rriDecompress function in IBM WebSphere MQ 7.0.0.0, 7.0.0.1, and 7.0.0.2 allows remote attackers to cause a denial of service via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4r65-cmrj-vf2r/GHSA-4r65-cmrj-vf2r.json b/advisories/unreviewed/2022/05/GHSA-4r65-cmrj-vf2r/GHSA-4r65-cmrj-vf2r.json index 43ac3a8da08..b42b4f54d0d 100644 --- a/advisories/unreviewed/2022/05/GHSA-4r65-cmrj-vf2r/GHSA-4r65-cmrj-vf2r.json +++ b/advisories/unreviewed/2022/05/GHSA-4r65-cmrj-vf2r/GHSA-4r65-cmrj-vf2r.json @@ -7,12 +7,8 @@ "CVE-2009-2589" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Hutscripts PHP Website Script allow remote attackers to inject arbitrary web script or HTML via the msg parameter to (1) feedback.php, (2) index.php, and (3) lostpassword.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4rcc-2rmf-f973/GHSA-4rcc-2rmf-f973.json b/advisories/unreviewed/2022/05/GHSA-4rcc-2rmf-f973/GHSA-4rcc-2rmf-f973.json index ea5307548aa..2129d67484d 100644 --- a/advisories/unreviewed/2022/05/GHSA-4rcc-2rmf-f973/GHSA-4rcc-2rmf-f973.json +++ b/advisories/unreviewed/2022/05/GHSA-4rcc-2rmf-f973/GHSA-4rcc-2rmf-f973.json @@ -7,12 +7,8 @@ "CVE-2009-2846" ], "details": "The eisa_eeprom_read function in the parisc isa-eeprom component (drivers/parisc/eisa_eeprom.c) in the Linux kernel before 2.6.31-rc6 allows local users to access restricted memory via a negative ppos argument, which bypasses a check that assumes that ppos is positive and causes an out-of-bounds read in the readb function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4rjf-p9gv-749h/GHSA-4rjf-p9gv-749h.json b/advisories/unreviewed/2022/05/GHSA-4rjf-p9gv-749h/GHSA-4rjf-p9gv-749h.json index 47428967366..c4b0b4e037b 100644 --- a/advisories/unreviewed/2022/05/GHSA-4rjf-p9gv-749h/GHSA-4rjf-p9gv-749h.json +++ b/advisories/unreviewed/2022/05/GHSA-4rjf-p9gv-749h/GHSA-4rjf-p9gv-749h.json @@ -7,12 +7,8 @@ "CVE-2009-2673" ], "details": "The proxy mechanism implementation in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, allows remote attackers to bypass intended access restrictions and connect to arbitrary sites via unspecified vectors, related to a declaration that lacks the final keyword.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -164,9 +160,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4v69-5j48-v73q/GHSA-4v69-5j48-v73q.json b/advisories/unreviewed/2022/05/GHSA-4v69-5j48-v73q/GHSA-4v69-5j48-v73q.json index 3c1f0fdc988..4c49b6906cf 100644 --- a/advisories/unreviewed/2022/05/GHSA-4v69-5j48-v73q/GHSA-4v69-5j48-v73q.json +++ b/advisories/unreviewed/2022/05/GHSA-4v69-5j48-v73q/GHSA-4v69-5j48-v73q.json @@ -7,12 +7,8 @@ "CVE-2009-3149" ], "details": "Directory traversal vulnerability in _css/js.php in Elgg 1.5, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the js parameter. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4w46-vcfx-xvfg/GHSA-4w46-vcfx-xvfg.json b/advisories/unreviewed/2022/05/GHSA-4w46-vcfx-xvfg/GHSA-4w46-vcfx-xvfg.json index 9a58aa26b67..ade1f7908c0 100644 --- a/advisories/unreviewed/2022/05/GHSA-4w46-vcfx-xvfg/GHSA-4w46-vcfx-xvfg.json +++ b/advisories/unreviewed/2022/05/GHSA-4w46-vcfx-xvfg/GHSA-4w46-vcfx-xvfg.json @@ -7,12 +7,8 @@ "CVE-2009-2793" ], "details": "The kernel in NetBSD, probably 5.0.1 and earlier, on x86 platforms does not properly handle a pre-commit failure of the iret instruction, which might allow local users to gain privileges via vectors related to a tempEIP pseudocode variable that is outside of the code-segment limits.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4w89-mmpq-2xw4/GHSA-4w89-mmpq-2xw4.json b/advisories/unreviewed/2022/05/GHSA-4w89-mmpq-2xw4/GHSA-4w89-mmpq-2xw4.json index a9a36e9b727..036b301f774 100644 --- a/advisories/unreviewed/2022/05/GHSA-4w89-mmpq-2xw4/GHSA-4w89-mmpq-2xw4.json +++ b/advisories/unreviewed/2022/05/GHSA-4w89-mmpq-2xw4/GHSA-4w89-mmpq-2xw4.json @@ -7,12 +7,8 @@ "CVE-2009-2804" ], "details": "Integer overflow in ColorSync in Apple Mac OS X 10.4.11 and 10.5.8, and Safari before 4.0.4 on Windows, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted ColorSync profile embedded in an image, leading to a heap-based buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4wx8-8w53-w4xf/GHSA-4wx8-8w53-w4xf.json b/advisories/unreviewed/2022/05/GHSA-4wx8-8w53-w4xf/GHSA-4wx8-8w53-w4xf.json index 61d9fa8af74..5e9bef73dcf 100644 --- a/advisories/unreviewed/2022/05/GHSA-4wx8-8w53-w4xf/GHSA-4wx8-8w53-w4xf.json +++ b/advisories/unreviewed/2022/05/GHSA-4wx8-8w53-w4xf/GHSA-4wx8-8w53-w4xf.json @@ -7,12 +7,8 @@ "CVE-2009-2486" ], "details": "Unspecified vulnerability in the SCTP implementation in Sun Solaris 10, and OpenSolaris before snv_120, allows remote attackers to cause a denial of service (panic) via unspecified packets.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4xwv-9c83-q58w/GHSA-4xwv-9c83-q58w.json b/advisories/unreviewed/2022/05/GHSA-4xwv-9c83-q58w/GHSA-4xwv-9c83-q58w.json index aa6b890ad2b..49823e0b72c 100644 --- a/advisories/unreviewed/2022/05/GHSA-4xwv-9c83-q58w/GHSA-4xwv-9c83-q58w.json +++ b/advisories/unreviewed/2022/05/GHSA-4xwv-9c83-q58w/GHSA-4xwv-9c83-q58w.json @@ -7,12 +7,8 @@ "CVE-2009-3047" ], "details": "Opera before 10.00, when a collapsed address bar is used, does not properly update the domain name from the previously visited site to the currently visited site, which might allow remote attackers to spoof URLs.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4xx5-2cr7-4qrq/GHSA-4xx5-2cr7-4qrq.json b/advisories/unreviewed/2022/05/GHSA-4xx5-2cr7-4qrq/GHSA-4xx5-2cr7-4qrq.json index 76a8231baf8..b891a05c812 100644 --- a/advisories/unreviewed/2022/05/GHSA-4xx5-2cr7-4qrq/GHSA-4xx5-2cr7-4qrq.json +++ b/advisories/unreviewed/2022/05/GHSA-4xx5-2cr7-4qrq/GHSA-4xx5-2cr7-4qrq.json @@ -7,12 +7,8 @@ "CVE-2009-2671" ], "details": "The SOCKS proxy implementation in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, allows remote attackers to discover the username of the account that invoked an untrusted (1) applet or (2) Java Web Start application via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -160,9 +156,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-52qh-2cwx-r4gf/GHSA-52qh-2cwx-r4gf.json b/advisories/unreviewed/2022/05/GHSA-52qh-2cwx-r4gf/GHSA-52qh-2cwx-r4gf.json index e61d20963c5..52c3ae9b9fa 100644 --- a/advisories/unreviewed/2022/05/GHSA-52qh-2cwx-r4gf/GHSA-52qh-2cwx-r4gf.json +++ b/advisories/unreviewed/2022/05/GHSA-52qh-2cwx-r4gf/GHSA-52qh-2cwx-r4gf.json @@ -7,12 +7,8 @@ "CVE-2009-2652" ], "details": "Unspecified vulnerability in Solaris Trusted Extensions in Sun Solaris 10, and OpenSolaris snv_37 through snv_120, allows remote attackers to cause a denial of service (panic) via vectors involving the parsing of labeled packets.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-53hx-f3mf-p54c/GHSA-53hx-f3mf-p54c.json b/advisories/unreviewed/2022/05/GHSA-53hx-f3mf-p54c/GHSA-53hx-f3mf-p54c.json index 3f2b1b873d4..57fdad55702 100644 --- a/advisories/unreviewed/2022/05/GHSA-53hx-f3mf-p54c/GHSA-53hx-f3mf-p54c.json +++ b/advisories/unreviewed/2022/05/GHSA-53hx-f3mf-p54c/GHSA-53hx-f3mf-p54c.json @@ -7,12 +7,8 @@ "CVE-2009-3228" ], "details": "The tc_fill_tclass function in net/sched/sch_api.c in the tc subsystem in the Linux kernel 2.4.x before 2.4.37.6 and 2.6.x before 2.6.31-rc9 does not initialize certain (1) tcm__pad1 and (2) tcm__pad2 structure members, which might allow local users to obtain sensitive information from kernel memory via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-57vp-79gr-9j72/GHSA-57vp-79gr-9j72.json b/advisories/unreviewed/2022/05/GHSA-57vp-79gr-9j72/GHSA-57vp-79gr-9j72.json index 087b1ec60c3..83ba6ffa1a6 100644 --- a/advisories/unreviewed/2022/05/GHSA-57vp-79gr-9j72/GHSA-57vp-79gr-9j72.json +++ b/advisories/unreviewed/2022/05/GHSA-57vp-79gr-9j72/GHSA-57vp-79gr-9j72.json @@ -7,12 +7,8 @@ "CVE-2009-2942" ], "details": "The mysql-ocaml bindings 1.0.4 for MySQL do not properly support the mysql_real_escape_string function, which might allow remote attackers to leverage escaping issues involving multibyte character encodings.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5c54-wvq7-976j/GHSA-5c54-wvq7-976j.json b/advisories/unreviewed/2022/05/GHSA-5c54-wvq7-976j/GHSA-5c54-wvq7-976j.json index 7cfc7cbd55c..a6a76fbe65f 100644 --- a/advisories/unreviewed/2022/05/GHSA-5c54-wvq7-976j/GHSA-5c54-wvq7-976j.json +++ b/advisories/unreviewed/2022/05/GHSA-5c54-wvq7-976j/GHSA-5c54-wvq7-976j.json @@ -7,12 +7,8 @@ "CVE-2009-2626" ], "details": "The zend_restore_ini_entry_cb function in zend_ini.c in PHP 5.3.0, 5.2.10, and earlier versions allows context-specific attackers to obtain sensitive information (memory contents) and cause a PHP crash by using the ini_set function to declare a variable, then using the ini_restore function to restore the variable.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5cc8-559g-qhg4/GHSA-5cc8-559g-qhg4.json b/advisories/unreviewed/2022/05/GHSA-5cc8-559g-qhg4/GHSA-5cc8-559g-qhg4.json index 8a8be65311f..f4e3592455a 100644 --- a/advisories/unreviewed/2022/05/GHSA-5cc8-559g-qhg4/GHSA-5cc8-559g-qhg4.json +++ b/advisories/unreviewed/2022/05/GHSA-5cc8-559g-qhg4/GHSA-5cc8-559g-qhg4.json @@ -7,12 +7,8 @@ "CVE-2009-2583" ], "details": "Multiple session fixation vulnerabilities in IBM Tivoli Identity Manager (ITIM) 5.0.0.6 allow remote attackers to hijack web sessions via unspecified vectors involving the (1) console and (2) self service interfaces.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5f46-9784-q9xr/GHSA-5f46-9784-q9xr.json b/advisories/unreviewed/2022/05/GHSA-5f46-9784-q9xr/GHSA-5f46-9784-q9xr.json index 3788a934f7e..f9eea54f7ab 100644 --- a/advisories/unreviewed/2022/05/GHSA-5f46-9784-q9xr/GHSA-5f46-9784-q9xr.json +++ b/advisories/unreviewed/2022/05/GHSA-5f46-9784-q9xr/GHSA-5f46-9784-q9xr.json @@ -7,12 +7,8 @@ "CVE-2009-2723" ], "details": "Unspecified vulnerability in deserialization in the Provider class in Sun Java SE 5.0 before Update 20 has unknown impact and attack vectors, aka BugId 6444262.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5gvg-42jf-22j8/GHSA-5gvg-42jf-22j8.json b/advisories/unreviewed/2022/05/GHSA-5gvg-42jf-22j8/GHSA-5gvg-42jf-22j8.json index a21b83bad45..a5620ad47c7 100644 --- a/advisories/unreviewed/2022/05/GHSA-5gvg-42jf-22j8/GHSA-5gvg-42jf-22j8.json +++ b/advisories/unreviewed/2022/05/GHSA-5gvg-42jf-22j8/GHSA-5gvg-42jf-22j8.json @@ -7,12 +7,8 @@ "CVE-2009-2799" ], "details": "Heap-based buffer overflow in Apple QuickTime before 7.6.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted H.264 movie file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5h56-hp83-f22q/GHSA-5h56-hp83-f22q.json b/advisories/unreviewed/2022/05/GHSA-5h56-hp83-f22q/GHSA-5h56-hp83-f22q.json index 1980fb63193..1f1bf9193fd 100644 --- a/advisories/unreviewed/2022/05/GHSA-5h56-hp83-f22q/GHSA-5h56-hp83-f22q.json +++ b/advisories/unreviewed/2022/05/GHSA-5h56-hp83-f22q/GHSA-5h56-hp83-f22q.json @@ -7,12 +7,8 @@ "CVE-2009-3017" ], "details": "Orca Browser 1.2 build 5 does not properly block data: URIs in Refresh and Location headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header that contains JavaScript sequences in a data:text/html URI, (2) entering a data:text/html URI with JavaScript sequences when specifying the content of a Refresh header, (3) injecting a Location header that contains JavaScript sequences in a data:text/html URI, or (4) entering a data:text/html URI with JavaScript sequences when specifying the content of a Location header; and does not properly handle javascript: URIs in HTML links within 302 error documents sent from web servers, which allows user-assisted remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (5) injecting a Location HTTP response header or (6) specifying the content of a Location HTTP response header.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5jpc-f6pq-gmw6/GHSA-5jpc-f6pq-gmw6.json b/advisories/unreviewed/2022/05/GHSA-5jpc-f6pq-gmw6/GHSA-5jpc-f6pq-gmw6.json index ab930e3a351..2cda927d317 100644 --- a/advisories/unreviewed/2022/05/GHSA-5jpc-f6pq-gmw6/GHSA-5jpc-f6pq-gmw6.json +++ b/advisories/unreviewed/2022/05/GHSA-5jpc-f6pq-gmw6/GHSA-5jpc-f6pq-gmw6.json @@ -7,12 +7,8 @@ "CVE-2009-2524" ], "details": "Integer underflow in the NTLM authentication feature in the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows remote attackers to cause a denial of service (reboot) via a malformed packet, aka \"Local Security Authority Subsystem Service Integer Overflow Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5mgg-m9j7-h63w/GHSA-5mgg-m9j7-h63w.json b/advisories/unreviewed/2022/05/GHSA-5mgg-m9j7-h63w/GHSA-5mgg-m9j7-h63w.json index e36c157c572..953fd32618e 100644 --- a/advisories/unreviewed/2022/05/GHSA-5mgg-m9j7-h63w/GHSA-5mgg-m9j7-h63w.json +++ b/advisories/unreviewed/2022/05/GHSA-5mgg-m9j7-h63w/GHSA-5mgg-m9j7-h63w.json @@ -7,12 +7,8 @@ "CVE-2009-3020" ], "details": "win32k.sys in Microsoft Windows Server 2003 SP2 allows remote attackers to cause a denial of service (system crash) by referencing a crafted .eot file in the src descriptor of an @font-face Cascading Style Sheets (CSS) rule in an HTML document, possibly related to the Embedded OpenType (EOT) Font Engine, a different vulnerability than CVE-2006-0010, CVE-2009-0231, and CVE-2009-0232. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5p9h-x8mc-2cx4/GHSA-5p9h-x8mc-2cx4.json b/advisories/unreviewed/2022/05/GHSA-5p9h-x8mc-2cx4/GHSA-5p9h-x8mc-2cx4.json index e1b5223faca..7d4d48bd05b 100644 --- a/advisories/unreviewed/2022/05/GHSA-5p9h-x8mc-2cx4/GHSA-5p9h-x8mc-2cx4.json +++ b/advisories/unreviewed/2022/05/GHSA-5p9h-x8mc-2cx4/GHSA-5p9h-x8mc-2cx4.json @@ -7,12 +7,8 @@ "CVE-2009-3075" ], "details": "Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox before 3.0.14 and 3.5.x before 3.5.2, Thunderbird before 2.0.0.24, and SeaMonkey before 1.1.19 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to use of mutable strings in the js_StringReplaceHelper function in js/src/jsstr.cpp, and unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -124,9 +120,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5pcq-rhwq-4w2j/GHSA-5pcq-rhwq-4w2j.json b/advisories/unreviewed/2022/05/GHSA-5pcq-rhwq-4w2j/GHSA-5pcq-rhwq-4w2j.json index ceaecdee52d..3a9ffa2e6bc 100644 --- a/advisories/unreviewed/2022/05/GHSA-5pcq-rhwq-4w2j/GHSA-5pcq-rhwq-4w2j.json +++ b/advisories/unreviewed/2022/05/GHSA-5pcq-rhwq-4w2j/GHSA-5pcq-rhwq-4w2j.json @@ -7,12 +7,8 @@ "CVE-2009-3001" ], "details": "The llc_ui_getname function in net/llc/af_llc.c in the Linux kernel 2.6.31-rc7 and earlier does not initialize a certain data structure, which allows local users to read the contents of some kernel memory locations by calling getsockname on an AF_LLC socket.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5pjj-cvfp-x5m8/GHSA-5pjj-cvfp-x5m8.json b/advisories/unreviewed/2022/05/GHSA-5pjj-cvfp-x5m8/GHSA-5pjj-cvfp-x5m8.json index 59d903352b7..add32c6aee8 100644 --- a/advisories/unreviewed/2022/05/GHSA-5pjj-cvfp-x5m8/GHSA-5pjj-cvfp-x5m8.json +++ b/advisories/unreviewed/2022/05/GHSA-5pjj-cvfp-x5m8/GHSA-5pjj-cvfp-x5m8.json @@ -7,12 +7,8 @@ "CVE-2009-3248" ], "details": "Cross-site request forgery (CSRF) vulnerability in the RSS module in vtiger CRM 5.0.4 allows remote attackers to hijack the authentication of Admin users for requests that modify the news feed system via the rssurl parameter in a Save action to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5q52-45hp-63pf/GHSA-5q52-45hp-63pf.json b/advisories/unreviewed/2022/05/GHSA-5q52-45hp-63pf/GHSA-5q52-45hp-63pf.json index 909001c9b45..7a3eb37bc58 100644 --- a/advisories/unreviewed/2022/05/GHSA-5q52-45hp-63pf/GHSA-5q52-45hp-63pf.json +++ b/advisories/unreviewed/2022/05/GHSA-5q52-45hp-63pf/GHSA-5q52-45hp-63pf.json @@ -7,12 +7,8 @@ "CVE-2009-2501" ], "details": "Heap-based buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a crafted PNG image file, aka \"GDI+ PNG Heap Overflow Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5q6h-pq4j-vpx7/GHSA-5q6h-pq4j-vpx7.json b/advisories/unreviewed/2022/05/GHSA-5q6h-pq4j-vpx7/GHSA-5q6h-pq4j-vpx7.json index 04c762f17fb..e61447d6557 100644 --- a/advisories/unreviewed/2022/05/GHSA-5q6h-pq4j-vpx7/GHSA-5q6h-pq4j-vpx7.json +++ b/advisories/unreviewed/2022/05/GHSA-5q6h-pq4j-vpx7/GHSA-5q6h-pq4j-vpx7.json @@ -7,12 +7,8 @@ "CVE-2009-2890" ], "details": "Cross-site scripting (XSS) vulnerability in results.php in PHP Scripts Now Riddles allows remote attackers to inject arbitrary web script or HTML via the searchquery parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5qcf-9mhg-gcxv/GHSA-5qcf-9mhg-gcxv.json b/advisories/unreviewed/2022/05/GHSA-5qcf-9mhg-gcxv/GHSA-5qcf-9mhg-gcxv.json index 02bbea7c139..384ee6ee20d 100644 --- a/advisories/unreviewed/2022/05/GHSA-5qcf-9mhg-gcxv/GHSA-5qcf-9mhg-gcxv.json +++ b/advisories/unreviewed/2022/05/GHSA-5qcf-9mhg-gcxv/GHSA-5qcf-9mhg-gcxv.json @@ -7,12 +7,8 @@ "CVE-2009-2927" ], "details": "SQL injection vulnerability in DetailFile.php in DigitalSpinners DS CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the nFileId parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5qg3-vgqv-c669/GHSA-5qg3-vgqv-c669.json b/advisories/unreviewed/2022/05/GHSA-5qg3-vgqv-c669/GHSA-5qg3-vgqv-c669.json index 4e7b26f9b83..f28f94d9ec5 100644 --- a/advisories/unreviewed/2022/05/GHSA-5qg3-vgqv-c669/GHSA-5qg3-vgqv-c669.json +++ b/advisories/unreviewed/2022/05/GHSA-5qg3-vgqv-c669/GHSA-5qg3-vgqv-c669.json @@ -7,12 +7,8 @@ "CVE-2009-3005" ], "details": "Lunascape 5.1.3 and 5.1.4 allows remote attackers to spoof the address bar, via window.open with a relative URI, to show an arbitrary URL on the web site visited by the victim, as demonstrated by a visit to an attacker-controlled web page, which triggers a spoofed login form for the site containing that page. NOTE: a related attack was reported in which an arbitrary file: URL is shown.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5qhm-mrwg-x22r/GHSA-5qhm-mrwg-x22r.json b/advisories/unreviewed/2022/05/GHSA-5qhm-mrwg-x22r/GHSA-5qhm-mrwg-x22r.json index 8ef0cec18b2..a1cbd080939 100644 --- a/advisories/unreviewed/2022/05/GHSA-5qhm-mrwg-x22r/GHSA-5qhm-mrwg-x22r.json +++ b/advisories/unreviewed/2022/05/GHSA-5qhm-mrwg-x22r/GHSA-5qhm-mrwg-x22r.json @@ -7,12 +7,8 @@ "CVE-2009-2989" ], "details": "Integer overflow in Adobe Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 might allow attackers to execute arbitrary code via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5v53-7q2j-vjr2/GHSA-5v53-7q2j-vjr2.json b/advisories/unreviewed/2022/05/GHSA-5v53-7q2j-vjr2/GHSA-5v53-7q2j-vjr2.json index 881bd746fd8..5aa3f611695 100644 --- a/advisories/unreviewed/2022/05/GHSA-5v53-7q2j-vjr2/GHSA-5v53-7q2j-vjr2.json +++ b/advisories/unreviewed/2022/05/GHSA-5v53-7q2j-vjr2/GHSA-5v53-7q2j-vjr2.json @@ -7,12 +7,8 @@ "CVE-2009-3024" ], "details": "The verify_hostname_of_cert function in the certificate checking feature in IO-Socket-SSL (IO::Socket::SSL) 1.14 through 1.25 only matches the prefix of a hostname when no wildcard is used, which allows remote attackers to bypass the hostname check for a certificate.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5v9w-r7h8-v3f2/GHSA-5v9w-r7h8-v3f2.json b/advisories/unreviewed/2022/05/GHSA-5v9w-r7h8-v3f2/GHSA-5v9w-r7h8-v3f2.json index deaa2ece75e..374e8bae8f1 100644 --- a/advisories/unreviewed/2022/05/GHSA-5v9w-r7h8-v3f2/GHSA-5v9w-r7h8-v3f2.json +++ b/advisories/unreviewed/2022/05/GHSA-5v9w-r7h8-v3f2/GHSA-5v9w-r7h8-v3f2.json @@ -7,12 +7,8 @@ "CVE-2009-2879" ], "details": "Heap-based buffer overflow in atas32.dll in the Cisco WebEx WRF Player 26.x before 26.49.32 (aka T26SP49EP32) for Windows, 27.x before 27.10.x (aka T27SP10) for Windows, 26.x before 26.49.35 for Mac OS X and Linux, and 27.x before 27.11.8 for Mac OS X and Linux allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a crafted WebEx Recording Format (WRF) file, a different vulnerability than CVE-2009-2876 and CVE-2009-2878.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5whj-vff8-jw8g/GHSA-5whj-vff8-jw8g.json b/advisories/unreviewed/2022/05/GHSA-5whj-vff8-jw8g/GHSA-5whj-vff8-jw8g.json index 3f5385dbd74..7a9b4cf32ee 100644 --- a/advisories/unreviewed/2022/05/GHSA-5whj-vff8-jw8g/GHSA-5whj-vff8-jw8g.json +++ b/advisories/unreviewed/2022/05/GHSA-5whj-vff8-jw8g/GHSA-5whj-vff8-jw8g.json @@ -7,12 +7,8 @@ "CVE-2009-2928" ], "details": "Cross-site scripting (XSS) vulnerability in login.php in TGS Content Management 0.x allows remote attackers to inject arbitrary web script or HTML via the previous_page parameter, a different vector than CVE-2008-6839.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5xjj-gmfx-xvf4/GHSA-5xjj-gmfx-xvf4.json b/advisories/unreviewed/2022/05/GHSA-5xjj-gmfx-xvf4/GHSA-5xjj-gmfx-xvf4.json index 68ec2de33e7..70549484cd5 100644 --- a/advisories/unreviewed/2022/05/GHSA-5xjj-gmfx-xvf4/GHSA-5xjj-gmfx-xvf4.json +++ b/advisories/unreviewed/2022/05/GHSA-5xjj-gmfx-xvf4/GHSA-5xjj-gmfx-xvf4.json @@ -7,12 +7,8 @@ "CVE-2009-2593" ], "details": "SQL injection vulnerability in censura.php in Censura 1.16.04 allows remote attackers to execute arbitrary SQL commands via the itemid parameter in a details action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-62jg-wqh5-h6g8/GHSA-62jg-wqh5-h6g8.json b/advisories/unreviewed/2022/05/GHSA-62jg-wqh5-h6g8/GHSA-62jg-wqh5-h6g8.json index 6f2a28fd6a9..7b7ebce72d6 100644 --- a/advisories/unreviewed/2022/05/GHSA-62jg-wqh5-h6g8/GHSA-62jg-wqh5-h6g8.json +++ b/advisories/unreviewed/2022/05/GHSA-62jg-wqh5-h6g8/GHSA-62jg-wqh5-h6g8.json @@ -7,12 +7,8 @@ "CVE-2009-3233" ], "details": "changetrack 4.3 allows local users to execute arbitrary commands via CRLF sequences and shell metacharacters in a filename in a directory that is checked by changetrack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-63x4-39mf-5c4v/GHSA-63x4-39mf-5c4v.json b/advisories/unreviewed/2022/05/GHSA-63x4-39mf-5c4v/GHSA-63x4-39mf-5c4v.json index 1a6bb597485..d3ea88275e2 100644 --- a/advisories/unreviewed/2022/05/GHSA-63x4-39mf-5c4v/GHSA-63x4-39mf-5c4v.json +++ b/advisories/unreviewed/2022/05/GHSA-63x4-39mf-5c4v/GHSA-63x4-39mf-5c4v.json @@ -7,12 +7,8 @@ "CVE-2009-3044" ], "details": "Opera before 10.00 does not properly handle a (1) '\\0' character or (2) invalid wildcard character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-65q5-4r9q-gp26/GHSA-65q5-4r9q-gp26.json b/advisories/unreviewed/2022/05/GHSA-65q5-4r9q-gp26/GHSA-65q5-4r9q-gp26.json index a5420352a91..13473d872b6 100644 --- a/advisories/unreviewed/2022/05/GHSA-65q5-4r9q-gp26/GHSA-65q5-4r9q-gp26.json +++ b/advisories/unreviewed/2022/05/GHSA-65q5-4r9q-gp26/GHSA-65q5-4r9q-gp26.json @@ -7,12 +7,8 @@ "CVE-2009-2702" ], "details": "KDE KSSL in kdelibs 3.5.4, 4.2.4, and 4.3 does not properly handle a '\\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-65qh-vmj5-8hx8/GHSA-65qh-vmj5-8hx8.json b/advisories/unreviewed/2022/05/GHSA-65qh-vmj5-8hx8/GHSA-65qh-vmj5-8hx8.json index abf3788560f..a6f853bdf8e 100644 --- a/advisories/unreviewed/2022/05/GHSA-65qh-vmj5-8hx8/GHSA-65qh-vmj5-8hx8.json +++ b/advisories/unreviewed/2022/05/GHSA-65qh-vmj5-8hx8/GHSA-65qh-vmj5-8hx8.json @@ -7,12 +7,8 @@ "CVE-2009-2968" ], "details": "Directory traversal vulnerability in a support component in the web interface in VMware Studio 2.0 public beta before build 1017-185256 allows remote attackers to upload files to arbitrary locations via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-66q4-848x-vrfc/GHSA-66q4-848x-vrfc.json b/advisories/unreviewed/2022/05/GHSA-66q4-848x-vrfc/GHSA-66q4-848x-vrfc.json index ca67ef935d6..e5e48f655a5 100644 --- a/advisories/unreviewed/2022/05/GHSA-66q4-848x-vrfc/GHSA-66q4-848x-vrfc.json +++ b/advisories/unreviewed/2022/05/GHSA-66q4-848x-vrfc/GHSA-66q4-848x-vrfc.json @@ -7,12 +7,8 @@ "CVE-2009-2815" ], "details": "The Telephony component in Apple iPhone OS before 3.1 does not properly handle SMS arrival notifications, which allows remote attackers to cause a denial of service (NULL pointer dereference and service interruption) via a crafted SMS message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-678r-9fw4-2w76/GHSA-678r-9fw4-2w76.json b/advisories/unreviewed/2022/05/GHSA-678r-9fw4-2w76/GHSA-678r-9fw4-2w76.json index 2accf051cb6..903d6bd41a2 100644 --- a/advisories/unreviewed/2022/05/GHSA-678r-9fw4-2w76/GHSA-678r-9fw4-2w76.json +++ b/advisories/unreviewed/2022/05/GHSA-678r-9fw4-2w76/GHSA-678r-9fw4-2w76.json @@ -7,12 +7,8 @@ "CVE-2009-2628" ], "details": "The VMnc media codec in vmnc.dll in VMware Movie Decoder before 6.5.3 build 185404, VMware Workstation 6.5.x before 6.5.3 build 185404, VMware Player 2.5.x before 2.5.3 build 185404, and VMware ACE 2.5.x before 2.5.3 build 185404 on Windows does not properly handle certain small heights in video content, which might allow remote attackers to execute arbitrary code via a crafted AVI file that triggers heap memory corruption.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-678w-jw48-h26c/GHSA-678w-jw48-h26c.json b/advisories/unreviewed/2022/05/GHSA-678w-jw48-h26c/GHSA-678w-jw48-h26c.json index 89348db970b..1cb1e082416 100644 --- a/advisories/unreviewed/2022/05/GHSA-678w-jw48-h26c/GHSA-678w-jw48-h26c.json +++ b/advisories/unreviewed/2022/05/GHSA-678w-jw48-h26c/GHSA-678w-jw48-h26c.json @@ -7,12 +7,8 @@ "CVE-2009-2795" ], "details": "Heap-based buffer overflow in the Recovery Mode component in Apple iPhone OS before 3.1, and iPhone OS before 3.1.1 for iPod touch, allows local users to bypass the passcode requirement and access arbitrary data via vectors related to \"command parsing.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-67fc-qg8q-p5jx/GHSA-67fc-qg8q-p5jx.json b/advisories/unreviewed/2022/05/GHSA-67fc-qg8q-p5jx/GHSA-67fc-qg8q-p5jx.json index f82bd556a01..8a98daa7bd2 100644 --- a/advisories/unreviewed/2022/05/GHSA-67fc-qg8q-p5jx/GHSA-67fc-qg8q-p5jx.json +++ b/advisories/unreviewed/2022/05/GHSA-67fc-qg8q-p5jx/GHSA-67fc-qg8q-p5jx.json @@ -7,12 +7,8 @@ "CVE-2009-3089" ], "details": "IBM Tivoli Directory Server (TDS) 6.0 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via unspecified vectors, related to (1) the ibmslapd.exe daemon on Windows and (2) the ibmdiradm daemon in the administration server on Linux, as demonstrated by certain modules in VulnDisco Pack Professional 8.11, a different vulnerability than CVE-2006-0717. NOTE: as of 20090903, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-69jj-5437-wm23/GHSA-69jj-5437-wm23.json b/advisories/unreviewed/2022/05/GHSA-69jj-5437-wm23/GHSA-69jj-5437-wm23.json index 62592bd11c1..cee62dc6b33 100644 --- a/advisories/unreviewed/2022/05/GHSA-69jj-5437-wm23/GHSA-69jj-5437-wm23.json +++ b/advisories/unreviewed/2022/05/GHSA-69jj-5437-wm23/GHSA-69jj-5437-wm23.json @@ -7,12 +7,8 @@ "CVE-2009-3003" ], "details": "Microsoft Internet Explorer 6 through 8 allows remote attackers to spoof the address bar, via window.open with a relative URI, to show an arbitrary URL on the web site visited by the victim, as demonstrated by a visit to an attacker-controlled web page, which triggers a spoofed login form for the site containing that page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-69rh-9hxh-3h4x/GHSA-69rh-9hxh-3h4x.json b/advisories/unreviewed/2022/05/GHSA-69rh-9hxh-3h4x/GHSA-69rh-9hxh-3h4x.json index dc18fd2b2f3..5a7d9ad18e1 100644 --- a/advisories/unreviewed/2022/05/GHSA-69rh-9hxh-3h4x/GHSA-69rh-9hxh-3h4x.json +++ b/advisories/unreviewed/2022/05/GHSA-69rh-9hxh-3h4x/GHSA-69rh-9hxh-3h4x.json @@ -7,12 +7,8 @@ "CVE-2009-2668" ], "details": "Microsoft Internet Explorer 6 through 6.0.2900.2180 and 7 through 7.0.6000.16473 allows remote attackers to cause a denial of service (CPU consumption) via an XML document composed of a long series of start-tags with no corresponding end-tags, a related issue to CVE-2009-1232.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6cf2-g5cm-mr2w/GHSA-6cf2-g5cm-mr2w.json b/advisories/unreviewed/2022/05/GHSA-6cf2-g5cm-mr2w/GHSA-6cf2-g5cm-mr2w.json index 964a45672a1..9fc32f26c71 100644 --- a/advisories/unreviewed/2022/05/GHSA-6cf2-g5cm-mr2w/GHSA-6cf2-g5cm-mr2w.json +++ b/advisories/unreviewed/2022/05/GHSA-6cf2-g5cm-mr2w/GHSA-6cf2-g5cm-mr2w.json @@ -7,12 +7,8 @@ "CVE-2009-2526" ], "details": "Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 do not properly validate fields in SMBv2 packets, which allows remote attackers to cause a denial of service (infinite loop and system hang) via a crafted packet to the Server service, aka \"SMBv2 Infinite Loop Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6cgm-f8fj-9wc2/GHSA-6cgm-f8fj-9wc2.json b/advisories/unreviewed/2022/05/GHSA-6cgm-f8fj-9wc2/GHSA-6cgm-f8fj-9wc2.json index 25ae496b56a..0f7ef250413 100644 --- a/advisories/unreviewed/2022/05/GHSA-6cgm-f8fj-9wc2/GHSA-6cgm-f8fj-9wc2.json +++ b/advisories/unreviewed/2022/05/GHSA-6cgm-f8fj-9wc2/GHSA-6cgm-f8fj-9wc2.json @@ -7,12 +7,8 @@ "CVE-2009-2923" ], "details": "Multiple directory traversal vulnerabilities in BitmixSoft PHP-Lance 1.52 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) language parameter to show.php and (2) in parameter to advanced_search.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6fhg-rjcp-rf8f/GHSA-6fhg-rjcp-rf8f.json b/advisories/unreviewed/2022/05/GHSA-6fhg-rjcp-rf8f/GHSA-6fhg-rjcp-rf8f.json index a70f1172152..dcc807c2762 100644 --- a/advisories/unreviewed/2022/05/GHSA-6fhg-rjcp-rf8f/GHSA-6fhg-rjcp-rf8f.json +++ b/advisories/unreviewed/2022/05/GHSA-6fhg-rjcp-rf8f/GHSA-6fhg-rjcp-rf8f.json @@ -7,12 +7,8 @@ "CVE-2009-3236" ], "details": "The form library in Horde Application Framework 3.2 before 3.2.5 and 3.3 before 3.3.5; Groupware 1.1 before 1.1.6 and 1.2 before 1.2.4; and Groupware Webmail Edition 1.1 before 1.1.6 and 1.2 before 1.2.4; reuses temporary filenames during the upload process which allows remote attackers, with privileges to write to the address book, to overwrite arbitrary files and execute PHP code via crafted Horde_Form_Type_image form field elements.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6fp8-mc4g-xqxw/GHSA-6fp8-mc4g-xqxw.json b/advisories/unreviewed/2022/05/GHSA-6fp8-mc4g-xqxw/GHSA-6fp8-mc4g-xqxw.json index fee332c9124..e2923481f3f 100644 --- a/advisories/unreviewed/2022/05/GHSA-6fp8-mc4g-xqxw/GHSA-6fp8-mc4g-xqxw.json +++ b/advisories/unreviewed/2022/05/GHSA-6fp8-mc4g-xqxw/GHSA-6fp8-mc4g-xqxw.json @@ -7,12 +7,8 @@ "CVE-2009-2867" ], "details": "Unspecified vulnerability in Cisco IOS 12.2XNA, 12.2XNB, 12.2XNC, 12.2XND, 12.4T, 12.4XZ, and 12.4YA, when Zone-Based Policy Firewall SIP Inspection is enabled, allows remote attackers to cause a denial of service (device reload) via a crafted SIP transit packet, aka Bug ID CSCsr18691.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6gg3-vvc7-gvjq/GHSA-6gg3-vvc7-gvjq.json b/advisories/unreviewed/2022/05/GHSA-6gg3-vvc7-gvjq/GHSA-6gg3-vvc7-gvjq.json index 190c9edd330..a66e485b265 100644 --- a/advisories/unreviewed/2022/05/GHSA-6gg3-vvc7-gvjq/GHSA-6gg3-vvc7-gvjq.json +++ b/advisories/unreviewed/2022/05/GHSA-6gg3-vvc7-gvjq/GHSA-6gg3-vvc7-gvjq.json @@ -7,12 +7,8 @@ "CVE-2009-2665" ], "details": "The nsDocument::SetScriptGlobalObject function in content/base/src/nsDocument.cpp in Mozilla Firefox 3.5.x before 3.5.2, when certain add-ons are enabled, does not properly handle a Link HTTP header, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via a crafted web page, related to an incorrect security wrapper.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6jqw-6g89-r7rg/GHSA-6jqw-6g89-r7rg.json b/advisories/unreviewed/2022/05/GHSA-6jqw-6g89-r7rg/GHSA-6jqw-6g89-r7rg.json index 514f27c9201..6d22a7a92d5 100644 --- a/advisories/unreviewed/2022/05/GHSA-6jqw-6g89-r7rg/GHSA-6jqw-6g89-r7rg.json +++ b/advisories/unreviewed/2022/05/GHSA-6jqw-6g89-r7rg/GHSA-6jqw-6g89-r7rg.json @@ -7,12 +7,8 @@ "CVE-2009-2670" ], "details": "The audio system in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, does not prevent access to java.lang.System properties by (1) untrusted applets and (2) Java Web Start applications, which allows context-dependent attackers to obtain sensitive information by reading these properties.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -164,9 +160,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6q93-7ff8-58mr/GHSA-6q93-7ff8-58mr.json b/advisories/unreviewed/2022/05/GHSA-6q93-7ff8-58mr/GHSA-6q93-7ff8-58mr.json index 9e881152c96..930a4c179cc 100644 --- a/advisories/unreviewed/2022/05/GHSA-6q93-7ff8-58mr/GHSA-6q93-7ff8-58mr.json +++ b/advisories/unreviewed/2022/05/GHSA-6q93-7ff8-58mr/GHSA-6q93-7ff8-58mr.json @@ -7,12 +7,8 @@ "CVE-2009-2481" ], "details": "mt-wizard.cgi in Six Apart Movable Type before 4.261, when global templates are not initialized, allows remote attackers to bypass access restrictions and (1) send e-mail to arbitrary addresses or (2) obtain sensitive information via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6r7p-fppp-wg95/GHSA-6r7p-fppp-wg95.json b/advisories/unreviewed/2022/05/GHSA-6r7p-fppp-wg95/GHSA-6r7p-fppp-wg95.json index e69af04401d..1cd4ec048ac 100644 --- a/advisories/unreviewed/2022/05/GHSA-6r7p-fppp-wg95/GHSA-6r7p-fppp-wg95.json +++ b/advisories/unreviewed/2022/05/GHSA-6r7p-fppp-wg95/GHSA-6r7p-fppp-wg95.json @@ -7,12 +7,8 @@ "CVE-2009-3126" ], "details": "Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a crafted PNG image file, aka \"GDI+ PNG Integer Overflow Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6v76-rxh6-qjw4/GHSA-6v76-rxh6-qjw4.json b/advisories/unreviewed/2022/05/GHSA-6v76-rxh6-qjw4/GHSA-6v76-rxh6-qjw4.json index 815b4767787..ce4a85d6ee4 100644 --- a/advisories/unreviewed/2022/05/GHSA-6v76-rxh6-qjw4/GHSA-6v76-rxh6-qjw4.json +++ b/advisories/unreviewed/2022/05/GHSA-6v76-rxh6-qjw4/GHSA-6v76-rxh6-qjw4.json @@ -7,12 +7,8 @@ "CVE-2009-2783" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 2.3.3 allow remote attackers to inject arbitrary web script or HTML via the (1) op parameter to modules/pm/viewpmsg.php and (2) query string to modules/profile/user.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6v8v-wc26-56rj/GHSA-6v8v-wc26-56rj.json b/advisories/unreviewed/2022/05/GHSA-6v8v-wc26-56rj/GHSA-6v8v-wc26-56rj.json index ce78cf22f3d..9168c1ac5f9 100644 --- a/advisories/unreviewed/2022/05/GHSA-6v8v-wc26-56rj/GHSA-6v8v-wc26-56rj.json +++ b/advisories/unreviewed/2022/05/GHSA-6v8v-wc26-56rj/GHSA-6v8v-wc26-56rj.json @@ -7,12 +7,8 @@ "CVE-2009-3002" ], "details": "The Linux kernel before 2.6.31-rc7 does not initialize certain data structures within getname functions, which allows local users to read the contents of some kernel memory locations by calling getsockname on (1) an AF_APPLETALK socket, related to the atalk_getname function in net/appletalk/ddp.c; (2) an AF_IRDA socket, related to the irda_getname function in net/irda/af_irda.c; (3) an AF_ECONET socket, related to the econet_getname function in net/econet/af_econet.c; (4) an AF_NETROM socket, related to the nr_getname function in net/netrom/af_netrom.c; (5) an AF_ROSE socket, related to the rose_getname function in net/rose/af_rose.c; or (6) a raw CAN socket, related to the raw_getname function in net/can/raw.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6wjh-6xpp-x5j3/GHSA-6wjh-6xpp-x5j3.json b/advisories/unreviewed/2022/05/GHSA-6wjh-6xpp-x5j3/GHSA-6wjh-6xpp-x5j3.json index f937f5b1a6a..cd8cb4ff428 100644 --- a/advisories/unreviewed/2022/05/GHSA-6wjh-6xpp-x5j3/GHSA-6wjh-6xpp-x5j3.json +++ b/advisories/unreviewed/2022/05/GHSA-6wjh-6xpp-x5j3/GHSA-6wjh-6xpp-x5j3.json @@ -7,12 +7,8 @@ "CVE-2009-3019" ], "details": "Microsoft Internet Explorer 6 on Windows XP SP2 and SP3, and Internet Explorer 7 on Vista, allows remote attackers to cause a denial of service (application crash) via JavaScript code that calls createElement to create an instance of the LI element, and then calls setAttribute to set the value attribute.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6x4g-r338-843v/GHSA-6x4g-r338-843v.json b/advisories/unreviewed/2022/05/GHSA-6x4g-r338-843v/GHSA-6x4g-r338-843v.json index bb6372d5f27..b132333baf8 100644 --- a/advisories/unreviewed/2022/05/GHSA-6x4g-r338-843v/GHSA-6x4g-r338-843v.json +++ b/advisories/unreviewed/2022/05/GHSA-6x4g-r338-843v/GHSA-6x4g-r338-843v.json @@ -7,12 +7,8 @@ "CVE-2009-2882" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in PG MatchMaking allow remote attackers to inject arbitrary web script or HTML via the show parameter to (1) browse_ladies.php and (2) browse_men.php, the (3) gender parameter to search.php, and the (4) id parameter to services.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-73m8-jfrm-fr4j/GHSA-73m8-jfrm-fr4j.json b/advisories/unreviewed/2022/05/GHSA-73m8-jfrm-fr4j/GHSA-73m8-jfrm-fr4j.json index 55ef2311ed7..4d81cf5e989 100644 --- a/advisories/unreviewed/2022/05/GHSA-73m8-jfrm-fr4j/GHSA-73m8-jfrm-fr4j.json +++ b/advisories/unreviewed/2022/05/GHSA-73m8-jfrm-fr4j/GHSA-73m8-jfrm-fr4j.json @@ -7,12 +7,8 @@ "CVE-2009-2904" ], "details": "A certain Red Hat modification to the ChrootDirectory feature in OpenSSH 4.8, as used in sshd in OpenSSH 4.3 in Red Hat Enterprise Linux (RHEL) 5.4 and Fedora 11, allows local users to gain privileges via hard links to setuid programs that use configuration files within the chroot directory, related to requirements for directory ownership.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-73qv-xhr2-28jm/GHSA-73qv-xhr2-28jm.json b/advisories/unreviewed/2022/05/GHSA-73qv-xhr2-28jm/GHSA-73qv-xhr2-28jm.json index 0ba94c05e98..396dbf51d8c 100644 --- a/advisories/unreviewed/2022/05/GHSA-73qv-xhr2-28jm/GHSA-73qv-xhr2-28jm.json +++ b/advisories/unreviewed/2022/05/GHSA-73qv-xhr2-28jm/GHSA-73qv-xhr2-28jm.json @@ -7,12 +7,8 @@ "CVE-2009-2947" ], "details": "Cross-site scripting (XSS) vulnerability in Xapian Omega before 1.0.16 allows remote attackers to inject arbitrary web script or HTML via unspecified CGI parameter values, which are sometimes included in exception messages.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-745f-p38x-qh76/GHSA-745f-p38x-qh76.json b/advisories/unreviewed/2022/05/GHSA-745f-p38x-qh76/GHSA-745f-p38x-qh76.json index d2cb31df072..3567a7d3b5d 100644 --- a/advisories/unreviewed/2022/05/GHSA-745f-p38x-qh76/GHSA-745f-p38x-qh76.json +++ b/advisories/unreviewed/2022/05/GHSA-745f-p38x-qh76/GHSA-745f-p38x-qh76.json @@ -7,12 +7,8 @@ "CVE-2009-2998" ], "details": "Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 do not properly validate input, which might allow attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2009-3458.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-75pw-vg89-wmq9/GHSA-75pw-vg89-wmq9.json b/advisories/unreviewed/2022/05/GHSA-75pw-vg89-wmq9/GHSA-75pw-vg89-wmq9.json index a8aa7d5be0d..85f2bcd7474 100644 --- a/advisories/unreviewed/2022/05/GHSA-75pw-vg89-wmq9/GHSA-75pw-vg89-wmq9.json +++ b/advisories/unreviewed/2022/05/GHSA-75pw-vg89-wmq9/GHSA-75pw-vg89-wmq9.json @@ -7,12 +7,8 @@ "CVE-2009-2956" ], "details": "The (1) Net.Commerce and (2) Net.Data components in IBM WebSphere Commerce Suite store sensitive information under the web root with insufficient access control, which allows remote attackers to discover passwords, and database and filesystem details, via direct requests for configuration files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-768p-jf5g-qpf8/GHSA-768p-jf5g-qpf8.json b/advisories/unreviewed/2022/05/GHSA-768p-jf5g-qpf8/GHSA-768p-jf5g-qpf8.json index 485a2940b6a..e33b3790a65 100644 --- a/advisories/unreviewed/2022/05/GHSA-768p-jf5g-qpf8/GHSA-768p-jf5g-qpf8.json +++ b/advisories/unreviewed/2022/05/GHSA-768p-jf5g-qpf8/GHSA-768p-jf5g-qpf8.json @@ -7,12 +7,8 @@ "CVE-2009-2604" ], "details": "Multiple SQL injection vulnerabilities in adminlogin.asp in Zen Help Desk 2.1 allow remote attackers to execute arbitrary SQL commands via the (1) userid (aka username) and (2) PassWord parameters to admin.asp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-78h8-6hmr-4752/GHSA-78h8-6hmr-4752.json b/advisories/unreviewed/2022/05/GHSA-78h8-6hmr-4752/GHSA-78h8-6hmr-4752.json index 679bb152bd6..7b30d7c838a 100644 --- a/advisories/unreviewed/2022/05/GHSA-78h8-6hmr-4752/GHSA-78h8-6hmr-4752.json +++ b/advisories/unreviewed/2022/05/GHSA-78h8-6hmr-4752/GHSA-78h8-6hmr-4752.json @@ -7,12 +7,8 @@ "CVE-2009-2920" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Elvin 1.2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) component and (2) priority parameters to buglist.php; and the (3) Username (4) E-mail, (5) Pass, and (6) Confirm pass fields to createaccount.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-78pq-pvr6-4q37/GHSA-78pq-pvr6-4q37.json b/advisories/unreviewed/2022/05/GHSA-78pq-pvr6-4q37/GHSA-78pq-pvr6-4q37.json index 6d8aef41ad4..646c4075885 100644 --- a/advisories/unreviewed/2022/05/GHSA-78pq-pvr6-4q37/GHSA-78pq-pvr6-4q37.json +++ b/advisories/unreviewed/2022/05/GHSA-78pq-pvr6-4q37/GHSA-78pq-pvr6-4q37.json @@ -7,12 +7,8 @@ "CVE-2009-2613" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in DataCheck Solutions LinkPal 1.x allow remote attackers to inject arbitrary web script or HTML via the page parameter to (1) z_loginfailed.asp, (2) z_admin_login.asp, (3) z_forgot.asp, and possibly unspecified other components. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7994-g46v-pm8q/GHSA-7994-g46v-pm8q.json b/advisories/unreviewed/2022/05/GHSA-7994-g46v-pm8q/GHSA-7994-g46v-pm8q.json index 132c3f0b967..eb8cf109602 100644 --- a/advisories/unreviewed/2022/05/GHSA-7994-g46v-pm8q/GHSA-7994-g46v-pm8q.json +++ b/advisories/unreviewed/2022/05/GHSA-7994-g46v-pm8q/GHSA-7994-g46v-pm8q.json @@ -7,12 +7,8 @@ "CVE-2009-2680" ], "details": "Unspecified vulnerability in the Remote Management Interface (RMI) for MSL Tape Libraries and 1/8 G2 Tape Autoloaders in HP StorageWorks 1/8 G2 Tape Autoloader firmware 2.30 and earlier, MSL2024 Tape Library firmware 4.20 and earlier, MSL4048 Tape Library firmware 6.50 and earlier, and MSL8096 Tape Library firmware 8.90 and earlier allows remote attackers to cause a denial of service via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-79wj-8p7q-rfq7/GHSA-79wj-8p7q-rfq7.json b/advisories/unreviewed/2022/05/GHSA-79wj-8p7q-rfq7/GHSA-79wj-8p7q-rfq7.json index 49388a38197..8a0d7721ec7 100644 --- a/advisories/unreviewed/2022/05/GHSA-79wj-8p7q-rfq7/GHSA-79wj-8p7q-rfq7.json +++ b/advisories/unreviewed/2022/05/GHSA-79wj-8p7q-rfq7/GHSA-79wj-8p7q-rfq7.json @@ -7,12 +7,8 @@ "CVE-2009-2817" ], "details": "Buffer overflow in Apple iTunes before 9.0.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted .pls file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7c4m-hg3m-wrpf/GHSA-7c4m-hg3m-wrpf.json b/advisories/unreviewed/2022/05/GHSA-7c4m-hg3m-wrpf/GHSA-7c4m-hg3m-wrpf.json index 4d03883e3af..b79caa1f021 100644 --- a/advisories/unreviewed/2022/05/GHSA-7c4m-hg3m-wrpf/GHSA-7c4m-hg3m-wrpf.json +++ b/advisories/unreviewed/2022/05/GHSA-7c4m-hg3m-wrpf/GHSA-7c4m-hg3m-wrpf.json @@ -7,12 +7,8 @@ "CVE-2009-3059" ], "details": "Multiple SQL injection vulnerabilities in Joker Board (aka JBoard) 2.0 and earlier allow remote attackers to execute arbitrary SQL commands via (1) core/select.php or (2) the city parameter to top_add.inc.php, reachable through sboard.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7c58-65v4-hw6h/GHSA-7c58-65v4-hw6h.json b/advisories/unreviewed/2022/05/GHSA-7c58-65v4-hw6h/GHSA-7c58-65v4-hw6h.json index 5c6c465dfe6..af50ec6dd33 100644 --- a/advisories/unreviewed/2022/05/GHSA-7c58-65v4-hw6h/GHSA-7c58-65v4-hw6h.json +++ b/advisories/unreviewed/2022/05/GHSA-7c58-65v4-hw6h/GHSA-7c58-65v4-hw6h.json @@ -7,12 +7,8 @@ "CVE-2009-2644" ], "details": "Race condition in the Solaris Auditing subsystem in Sun Solaris 9 and 10 and OpenSolaris before snv_121, when extended file attributes are used, allows local users to cause a denial of service (panic) via vectors related to \"pathnames for invalid fds.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7fm6-w28r-mgch/GHSA-7fm6-w28r-mgch.json b/advisories/unreviewed/2022/05/GHSA-7fm6-w28r-mgch/GHSA-7fm6-w28r-mgch.json index 55812f9e6ab..f63905f8b63 100644 --- a/advisories/unreviewed/2022/05/GHSA-7fm6-w28r-mgch/GHSA-7fm6-w28r-mgch.json +++ b/advisories/unreviewed/2022/05/GHSA-7fm6-w28r-mgch/GHSA-7fm6-w28r-mgch.json @@ -7,12 +7,8 @@ "CVE-2009-3177" ], "details": "Unspecified vulnerability in Kaspersky Online Scanner 7.0 has unknown impact and attack vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.8, (1) \"Kaspersky Online Antivirus Scanner 7.0 exploit (Linux)\" and (2) \"Kaspersky Online Antivirus Scanner 7.0 exploit (Windows).\" NOTE: as of 20090909, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7g5w-rf2f-26r6/GHSA-7g5w-rf2f-26r6.json b/advisories/unreviewed/2022/05/GHSA-7g5w-rf2f-26r6/GHSA-7g5w-rf2f-26r6.json index 6841b460db8..49d59ec56f6 100644 --- a/advisories/unreviewed/2022/05/GHSA-7g5w-rf2f-26r6/GHSA-7g5w-rf2f-26r6.json +++ b/advisories/unreviewed/2022/05/GHSA-7g5w-rf2f-26r6/GHSA-7g5w-rf2f-26r6.json @@ -7,12 +7,8 @@ "CVE-2009-2739" ], "details": "Cross-site scripting (XSS) vulnerability in FreeNAS before 0.69.2 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7g9x-xhfc-88x2/GHSA-7g9x-xhfc-88x2.json b/advisories/unreviewed/2022/05/GHSA-7g9x-xhfc-88x2/GHSA-7g9x-xhfc-88x2.json index 5bfbc034447..ba010b7e6aa 100644 --- a/advisories/unreviewed/2022/05/GHSA-7g9x-xhfc-88x2/GHSA-7g9x-xhfc-88x2.json +++ b/advisories/unreviewed/2022/05/GHSA-7g9x-xhfc-88x2/GHSA-7g9x-xhfc-88x2.json @@ -7,12 +7,8 @@ "CVE-2009-3256" ], "details": "Cross-site scripting (XSS) vulnerability in include/ajax/blogInfo.php in LiveStreet 0.2 allows remote attackers to inject arbitrary web script or HTML via the URI, as demonstrated by a SCRIPT element in an arbitrary parameter such as the asd parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7h6h-gqjm-2r96/GHSA-7h6h-gqjm-2r96.json b/advisories/unreviewed/2022/05/GHSA-7h6h-gqjm-2r96/GHSA-7h6h-gqjm-2r96.json index c935dea0588..a1a24eb24b3 100644 --- a/advisories/unreviewed/2022/05/GHSA-7h6h-gqjm-2r96/GHSA-7h6h-gqjm-2r96.json +++ b/advisories/unreviewed/2022/05/GHSA-7h6h-gqjm-2r96/GHSA-7h6h-gqjm-2r96.json @@ -7,12 +7,8 @@ "CVE-2009-2649" ], "details": "The IATA (ata) driver in FreeBSD 6.0 and 8.0, when read access to /dev is available, allows local users to cause a denial of service (kernel panic) via a certain IOCTL request with a large count, which triggers a malloc call with a large value.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7hf8-pr4q-94mp/GHSA-7hf8-pr4q-94mp.json b/advisories/unreviewed/2022/05/GHSA-7hf8-pr4q-94mp/GHSA-7hf8-pr4q-94mp.json index e9529577f1b..72a56f5c7e6 100644 --- a/advisories/unreviewed/2022/05/GHSA-7hf8-pr4q-94mp/GHSA-7hf8-pr4q-94mp.json +++ b/advisories/unreviewed/2022/05/GHSA-7hf8-pr4q-94mp/GHSA-7hf8-pr4q-94mp.json @@ -7,12 +7,8 @@ "CVE-2009-3029" ], "details": "Cross-site scripting (XSS) vulnerability in the console in Symantec SecurityExpressions Audit and Compliance Server 4.1.1, 4.1, and earlier allows remote authenticated users to inject arbitrary web script or HTML via \"external client input\" that triggers crafted error messages.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7hrp-6jq3-pm4q/GHSA-7hrp-6jq3-pm4q.json b/advisories/unreviewed/2022/05/GHSA-7hrp-6jq3-pm4q/GHSA-7hrp-6jq3-pm4q.json index c8eaf0a3b23..95d0642e147 100644 --- a/advisories/unreviewed/2022/05/GHSA-7hrp-6jq3-pm4q/GHSA-7hrp-6jq3-pm4q.json +++ b/advisories/unreviewed/2022/05/GHSA-7hrp-6jq3-pm4q/GHSA-7hrp-6jq3-pm4q.json @@ -7,12 +7,8 @@ "CVE-2009-2855" ], "details": "The strListGetItem function in src/HttpHeaderTools.c in Squid 2.7 allows remote attackers to cause a denial of service via a crafted auth header with certain comma delimiters that trigger an infinite loop of calls to the strcspn function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7j3p-ffqc-xjpg/GHSA-7j3p-ffqc-xjpg.json b/advisories/unreviewed/2022/05/GHSA-7j3p-ffqc-xjpg/GHSA-7j3p-ffqc-xjpg.json index b829dc5014b..aced71cb313 100644 --- a/advisories/unreviewed/2022/05/GHSA-7j3p-ffqc-xjpg/GHSA-7j3p-ffqc-xjpg.json +++ b/advisories/unreviewed/2022/05/GHSA-7j3p-ffqc-xjpg/GHSA-7j3p-ffqc-xjpg.json @@ -7,12 +7,8 @@ "CVE-2009-2661" ], "details": "The asn1_length function in strongSwan 2.8 before 2.8.11, 4.2 before 4.2.17, and 4.3 before 4.3.3 does not properly handle X.509 certificates with crafted Relative Distinguished Names (RDNs), which allows remote attackers to cause a denial of service (pluto IKE daemon crash) via malformed ASN.1 data. NOTE: this is due to an incomplete fix for CVE-2009-2185.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7mf2-2xwm-399x/GHSA-7mf2-2xwm-399x.json b/advisories/unreviewed/2022/05/GHSA-7mf2-2xwm-399x/GHSA-7mf2-2xwm-399x.json index 5bc3989fc42..6f9370f8e82 100644 --- a/advisories/unreviewed/2022/05/GHSA-7mf2-2xwm-399x/GHSA-7mf2-2xwm-399x.json +++ b/advisories/unreviewed/2022/05/GHSA-7mf2-2xwm-399x/GHSA-7mf2-2xwm-399x.json @@ -7,12 +7,8 @@ "CVE-2009-2955" ], "details": "Google Chrome 1.0.154.48 and earlier allows remote attackers to cause a denial of service (CPU consumption and application hang) via JavaScript code with a long string value for the hash property (aka location.hash), a related issue to CVE-2008-5715.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7mgv-jg63-hvqh/GHSA-7mgv-jg63-hvqh.json b/advisories/unreviewed/2022/05/GHSA-7mgv-jg63-hvqh/GHSA-7mgv-jg63-hvqh.json index 9e565cf51c1..fbb2601d510 100644 --- a/advisories/unreviewed/2022/05/GHSA-7mgv-jg63-hvqh/GHSA-7mgv-jg63-hvqh.json +++ b/advisories/unreviewed/2022/05/GHSA-7mgv-jg63-hvqh/GHSA-7mgv-jg63-hvqh.json @@ -7,12 +7,8 @@ "CVE-2009-2479" ], "details": "Mozilla Firefox 3.0.x, 3.5, and 3.5.1 on Windows allows remote attackers to cause a denial of service (uncaught exception and application crash) via a long Unicode string argument to the write method. NOTE: this was originally reported as a stack-based buffer overflow. NOTE: on Linux and Mac OS X, a crash resulting from this long string reportedly occurs in an operating-system library, not in Firefox.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7p94-p9c2-37vj/GHSA-7p94-p9c2-37vj.json b/advisories/unreviewed/2022/05/GHSA-7p94-p9c2-37vj/GHSA-7p94-p9c2-37vj.json index bb57f11b413..8a36130ed20 100644 --- a/advisories/unreviewed/2022/05/GHSA-7p94-p9c2-37vj/GHSA-7p94-p9c2-37vj.json +++ b/advisories/unreviewed/2022/05/GHSA-7p94-p9c2-37vj/GHSA-7p94-p9c2-37vj.json @@ -7,12 +7,8 @@ "CVE-2009-2808" ], "details": "Help Viewer in Apple Mac OS X before 10.6.2 does not use an HTTPS connection to retrieve Apple Help content from a web site, which allows man-in-the-middle attackers to send a crafted help:runscript link, and thereby execute arbitrary code, via a spoofed response.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7pmp-xp53-4j98/GHSA-7pmp-xp53-4j98.json b/advisories/unreviewed/2022/05/GHSA-7pmp-xp53-4j98/GHSA-7pmp-xp53-4j98.json index fa8e295b722..fff059f6faf 100644 --- a/advisories/unreviewed/2022/05/GHSA-7pmp-xp53-4j98/GHSA-7pmp-xp53-4j98.json +++ b/advisories/unreviewed/2022/05/GHSA-7pmp-xp53-4j98/GHSA-7pmp-xp53-4j98.json @@ -7,12 +7,8 @@ "CVE-2009-3084" ], "details": "The msn_slp_process_msg function in libpurple/protocols/msn/slpcall.c in the MSN protocol plugin in libpurple 2.6.0 and 2.6.1, as used in Pidgin before 2.6.2, allows remote attackers to cause a denial of service (application crash) via a handwritten (aka Ink) message, related to an uninitialized variable and the incorrect \"UTF16-LE\" charset name.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7ppr-2cvm-q8gq/GHSA-7ppr-2cvm-q8gq.json b/advisories/unreviewed/2022/05/GHSA-7ppr-2cvm-q8gq/GHSA-7ppr-2cvm-q8gq.json index 447d87b8ad9..d378a858f4d 100644 --- a/advisories/unreviewed/2022/05/GHSA-7ppr-2cvm-q8gq/GHSA-7ppr-2cvm-q8gq.json +++ b/advisories/unreviewed/2022/05/GHSA-7ppr-2cvm-q8gq/GHSA-7ppr-2cvm-q8gq.json @@ -7,12 +7,8 @@ "CVE-2009-3243" ], "details": "Unspecified vulnerability in the TLS dissector in Wireshark 1.2.0 and 1.2.1, when running on Windows, allows remote attackers to cause a denial of service (application crash) via unknown vectors related to TLS 1.2 conversations.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7v9h-h65m-ff8g/GHSA-7v9h-h65m-ff8g.json b/advisories/unreviewed/2022/05/GHSA-7v9h-h65m-ff8g/GHSA-7v9h-h65m-ff8g.json index bd66d926364..547c3af8ae8 100644 --- a/advisories/unreviewed/2022/05/GHSA-7v9h-h65m-ff8g/GHSA-7v9h-h65m-ff8g.json +++ b/advisories/unreviewed/2022/05/GHSA-7v9h-h65m-ff8g/GHSA-7v9h-h65m-ff8g.json @@ -7,12 +7,8 @@ "CVE-2009-2647" ], "details": "Unspecified vulnerability in Kaspersky Anti-Virus 2010 and Kaspersky Internet Security 2010 before Critical Fix 9.0.0.463 allows remote attackers to disable the Kaspersky application via unknown attack vectors unrelated to \"an external script.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7vv7-w5vq-v4pm/GHSA-7vv7-w5vq-v4pm.json b/advisories/unreviewed/2022/05/GHSA-7vv7-w5vq-v4pm/GHSA-7vv7-w5vq-v4pm.json index d323637ee34..de7a42c666d 100644 --- a/advisories/unreviewed/2022/05/GHSA-7vv7-w5vq-v4pm/GHSA-7vv7-w5vq-v4pm.json +++ b/advisories/unreviewed/2022/05/GHSA-7vv7-w5vq-v4pm/GHSA-7vv7-w5vq-v4pm.json @@ -7,12 +7,8 @@ "CVE-2009-2775" ], "details": "SQL injection vulnerability in linkout.php in PHPArcadeScript (PHP Arcade Script) 4.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7w7r-692f-6f39/GHSA-7w7r-692f-6f39.json b/advisories/unreviewed/2022/05/GHSA-7w7r-692f-6f39/GHSA-7w7r-692f-6f39.json index fb3e890cfde..fb3a77e1f5c 100644 --- a/advisories/unreviewed/2022/05/GHSA-7w7r-692f-6f39/GHSA-7w7r-692f-6f39.json +++ b/advisories/unreviewed/2022/05/GHSA-7w7r-692f-6f39/GHSA-7w7r-692f-6f39.json @@ -7,12 +7,8 @@ "CVE-2009-2880" ], "details": "Buffer overflow in atrpui.dll in the Cisco WebEx WRF Player 26.x before 26.49.32 for Windows, 27.x before 27.10.x for Windows, 26.x before 26.49.35 for Mac OS X and Linux, and 27.x before 27.11.8 for Mac OS X and Linux allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted WebEx Recording Format (WRF) file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7wrp-3pc5-gg9v/GHSA-7wrp-3pc5-gg9v.json b/advisories/unreviewed/2022/05/GHSA-7wrp-3pc5-gg9v/GHSA-7wrp-3pc5-gg9v.json index 1d12effe55e..0bfa95f168d 100644 --- a/advisories/unreviewed/2022/05/GHSA-7wrp-3pc5-gg9v/GHSA-7wrp-3pc5-gg9v.json +++ b/advisories/unreviewed/2022/05/GHSA-7wrp-3pc5-gg9v/GHSA-7wrp-3pc5-gg9v.json @@ -7,12 +7,8 @@ "CVE-2009-2953" ], "details": "Mozilla Firefox 3.0.6 through 3.0.13, and 3.5.x, allows remote attackers to cause a denial of service (CPU consumption) via JavaScript code with a long string value for the hash property (aka location.hash), a related issue to CVE-2008-5715.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7xf9-399c-v97r/GHSA-7xf9-399c-v97r.json b/advisories/unreviewed/2022/05/GHSA-7xf9-399c-v97r/GHSA-7xf9-399c-v97r.json index 9d6940a32b2..c1940b73fdd 100644 --- a/advisories/unreviewed/2022/05/GHSA-7xf9-399c-v97r/GHSA-7xf9-399c-v97r.json +++ b/advisories/unreviewed/2022/05/GHSA-7xf9-399c-v97r/GHSA-7xf9-399c-v97r.json @@ -7,12 +7,8 @@ "CVE-2009-2681" ], "details": "Unspecified vulnerability in HP ProCurve Identity Driven Manager (IDM) A.02.x through A.02.03 and A.03.x through A.03.00, on Windows Server 2003 with IAS and Windows Server 2008 with NPS, allows local users to gain privileges via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-83qm-4jqf-qgx7/GHSA-83qm-4jqf-qgx7.json b/advisories/unreviewed/2022/05/GHSA-83qm-4jqf-qgx7/GHSA-83qm-4jqf-qgx7.json index 801de8ebf31..a2a6bba54e0 100644 --- a/advisories/unreviewed/2022/05/GHSA-83qm-4jqf-qgx7/GHSA-83qm-4jqf-qgx7.json +++ b/advisories/unreviewed/2022/05/GHSA-83qm-4jqf-qgx7/GHSA-83qm-4jqf-qgx7.json @@ -7,12 +7,8 @@ "CVE-2009-3250" ], "details": "The saveForwardAttachments procedure in the Compose Mail functionality in vtiger CRM 5.0.4 allows remote authenticated users to execute arbitrary code by composing an e-mail message with an attachment filename ending in (1) .php in installations based on certain Apache HTTP Server configurations, (2) .php. on Windows, or (3) .php/ on Linux, and then making a direct request to a certain pathname under storage/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8422-mgg8-93rh/GHSA-8422-mgg8-93rh.json b/advisories/unreviewed/2022/05/GHSA-8422-mgg8-93rh/GHSA-8422-mgg8-93rh.json index cae972a1aa8..464a94b243f 100644 --- a/advisories/unreviewed/2022/05/GHSA-8422-mgg8-93rh/GHSA-8422-mgg8-93rh.json +++ b/advisories/unreviewed/2022/05/GHSA-8422-mgg8-93rh/GHSA-8422-mgg8-93rh.json @@ -7,12 +7,8 @@ "CVE-2009-2638" ], "details": "SQL injection vulnerability in the AkoBook (com_akobook) component 2.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the gbid parameter in a reply action to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-858w-r7fm-3rfx/GHSA-858w-r7fm-3rfx.json b/advisories/unreviewed/2022/05/GHSA-858w-r7fm-3rfx/GHSA-858w-r7fm-3rfx.json index 4ad602e8fed..27014c16b11 100644 --- a/advisories/unreviewed/2022/05/GHSA-858w-r7fm-3rfx/GHSA-858w-r7fm-3rfx.json +++ b/advisories/unreviewed/2022/05/GHSA-858w-r7fm-3rfx/GHSA-858w-r7fm-3rfx.json @@ -7,12 +7,8 @@ "CVE-2009-2770" ], "details": "PowerUpload 2.4 allows remote attackers to bypass authentication and gain administrative access via a MIME encoded value of admin for the myadminname cookie.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-86qj-p6wv-2c9q/GHSA-86qj-p6wv-2c9q.json b/advisories/unreviewed/2022/05/GHSA-86qj-p6wv-2c9q/GHSA-86qj-p6wv-2c9q.json index 017bedd68a7..53eb5e35f6b 100644 --- a/advisories/unreviewed/2022/05/GHSA-86qj-p6wv-2c9q/GHSA-86qj-p6wv-2c9q.json +++ b/advisories/unreviewed/2022/05/GHSA-86qj-p6wv-2c9q/GHSA-86qj-p6wv-2c9q.json @@ -7,12 +7,8 @@ "CVE-2009-2572" ], "details": "Cross-site request forgery (CSRF) vulnerability in the Fivestar module 5.x-1.x before 5.x-1.14 and 6.x-1.x before 6.x-1.14, a module for Drupal, allows remote attackers to hijack the authentication of arbitrary users for requests that cast votes.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8738-58qp-rj68/GHSA-8738-58qp-rj68.json b/advisories/unreviewed/2022/05/GHSA-8738-58qp-rj68/GHSA-8738-58qp-rj68.json index dfcac610a3e..335be44cd4a 100644 --- a/advisories/unreviewed/2022/05/GHSA-8738-58qp-rj68/GHSA-8738-58qp-rj68.json +++ b/advisories/unreviewed/2022/05/GHSA-8738-58qp-rj68/GHSA-8738-58qp-rj68.json @@ -7,12 +7,8 @@ "CVE-2009-2480" ], "details": "Cross-site scripting (XSS) vulnerability in mt-wizard.cgi in Six Apart Movable Type 4.24, and 4.25 when global templates are not initialized, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-87wh-4mv4-q723/GHSA-87wh-4mv4-q723.json b/advisories/unreviewed/2022/05/GHSA-87wh-4mv4-q723/GHSA-87wh-4mv4-q723.json index 0988110bc71..2c3c3eb7f6c 100644 --- a/advisories/unreviewed/2022/05/GHSA-87wh-4mv4-q723/GHSA-87wh-4mv4-q723.json +++ b/advisories/unreviewed/2022/05/GHSA-87wh-4mv4-q723/GHSA-87wh-4mv4-q723.json @@ -7,12 +7,8 @@ "CVE-2009-2842" ], "details": "Apple Safari before 4.0.4 does not properly implement certain (1) Open Image and (2) Open Link menu options, which allows remote attackers to read local HTML files via a crafted web site.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-88w6-q5j8-vrrr/GHSA-88w6-q5j8-vrrr.json b/advisories/unreviewed/2022/05/GHSA-88w6-q5j8-vrrr/GHSA-88w6-q5j8-vrrr.json index e167506950a..0b97e58ff30 100644 --- a/advisories/unreviewed/2022/05/GHSA-88w6-q5j8-vrrr/GHSA-88w6-q5j8-vrrr.json +++ b/advisories/unreviewed/2022/05/GHSA-88w6-q5j8-vrrr/GHSA-88w6-q5j8-vrrr.json @@ -7,12 +7,8 @@ "CVE-2009-3301" ], "details": "Integer underflow in filter/ww8/ww8par2.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted sprmTDefTable table property modifier in a Word document.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-89f6-w32j-rm5x/GHSA-89f6-w32j-rm5x.json b/advisories/unreviewed/2022/05/GHSA-89f6-w32j-rm5x/GHSA-89f6-w32j-rm5x.json index c4a23824388..f7308051f51 100644 --- a/advisories/unreviewed/2022/05/GHSA-89f6-w32j-rm5x/GHSA-89f6-w32j-rm5x.json +++ b/advisories/unreviewed/2022/05/GHSA-89f6-w32j-rm5x/GHSA-89f6-w32j-rm5x.json @@ -7,12 +7,8 @@ "CVE-2009-3296" ], "details": "Multiple integer overflows in tiffread.c in CamlImages 2.2 might allow remote attackers to execute arbitrary code via TIFF images containing large width and height values that trigger heap-based buffer overflows.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-89w9-2j44-v823/GHSA-89w9-2j44-v823.json b/advisories/unreviewed/2022/05/GHSA-89w9-2j44-v823/GHSA-89w9-2j44-v823.json index 94e6481d9d5..02df35aedd2 100644 --- a/advisories/unreviewed/2022/05/GHSA-89w9-2j44-v823/GHSA-89w9-2j44-v823.json +++ b/advisories/unreviewed/2022/05/GHSA-89w9-2j44-v823/GHSA-89w9-2j44-v823.json @@ -7,12 +7,8 @@ "CVE-2009-2664" ], "details": "The js_watch_set function in js/src/jsdbgapi.cpp in the JavaScript engine in Mozilla Firefox before 3.0.12 allows remote attackers to cause a denial of service (assertion failure and application exit) or possibly execute arbitrary code via a crafted .js file, related to a \"memory safety bug.\" NOTE: this was originally reported as affecting versions before 3.0.13.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8cxh-33q5-hvj6/GHSA-8cxh-33q5-hvj6.json b/advisories/unreviewed/2022/05/GHSA-8cxh-33q5-hvj6/GHSA-8cxh-33q5-hvj6.json index bc22e5d4965..f63581d7d39 100644 --- a/advisories/unreviewed/2022/05/GHSA-8cxh-33q5-hvj6/GHSA-8cxh-33q5-hvj6.json +++ b/advisories/unreviewed/2022/05/GHSA-8cxh-33q5-hvj6/GHSA-8cxh-33q5-hvj6.json @@ -7,12 +7,8 @@ "CVE-2009-3072" ], "details": "Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.14 and 3.5.x before 3.5.3, Thunderbird before 2.0.0.24, and SeaMonkey before 1.1.19 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the BinHex decoder in netwerk/streamconv/converters/nsBinHexDecoder.cpp, and unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -124,9 +120,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8fc7-mgr4-r5h3/GHSA-8fc7-mgr4-r5h3.json b/advisories/unreviewed/2022/05/GHSA-8fc7-mgr4-r5h3/GHSA-8fc7-mgr4-r5h3.json index ffff1acee9d..f3820c34dfc 100644 --- a/advisories/unreviewed/2022/05/GHSA-8fc7-mgr4-r5h3/GHSA-8fc7-mgr4-r5h3.json +++ b/advisories/unreviewed/2022/05/GHSA-8fc7-mgr4-r5h3/GHSA-8fc7-mgr4-r5h3.json @@ -7,12 +7,8 @@ "CVE-2009-2966" ], "details": "avp.exe in Kaspersky Internet Security 9.0.0.459 and Anti-Virus 9.0.0.463 allows remote attackers to cause a denial of service (CPU consumption and network connectivity loss) via an HTTP URL request that contains a large number of dot \".\" characters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8g49-cpfw-2gpm/GHSA-8g49-cpfw-2gpm.json b/advisories/unreviewed/2022/05/GHSA-8g49-cpfw-2gpm/GHSA-8g49-cpfw-2gpm.json index 3c203e4fef6..e8f2e7d4f2b 100644 --- a/advisories/unreviewed/2022/05/GHSA-8g49-cpfw-2gpm/GHSA-8g49-cpfw-2gpm.json +++ b/advisories/unreviewed/2022/05/GHSA-8g49-cpfw-2gpm/GHSA-8g49-cpfw-2gpm.json @@ -7,12 +7,8 @@ "CVE-2009-2586" ], "details": "Cross-site scripting (XSS) vulnerability in articles.php in EDGEPHP EZArticles allows remote attackers to inject arbitrary web script or HTML via the title parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8g7m-922w-m36f/GHSA-8g7m-922w-m36f.json b/advisories/unreviewed/2022/05/GHSA-8g7m-922w-m36f/GHSA-8g7m-922w-m36f.json index a479cf1eda1..da611431a18 100644 --- a/advisories/unreviewed/2022/05/GHSA-8g7m-922w-m36f/GHSA-8g7m-922w-m36f.json +++ b/advisories/unreviewed/2022/05/GHSA-8g7m-922w-m36f/GHSA-8g7m-922w-m36f.json @@ -7,12 +7,8 @@ "CVE-2009-2774" ], "details": "SQL injection vulnerability in paidbanner.php in PHP Paid 4 Mail Script allows remote attackers to execute arbitrary SQL commands via the ID parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8gqw-gxjh-q85g/GHSA-8gqw-gxjh-q85g.json b/advisories/unreviewed/2022/05/GHSA-8gqw-gxjh-q85g/GHSA-8gqw-gxjh-q85g.json index f17ed0106c8..7f6f581feaa 100644 --- a/advisories/unreviewed/2022/05/GHSA-8gqw-gxjh-q85g/GHSA-8gqw-gxjh-q85g.json +++ b/advisories/unreviewed/2022/05/GHSA-8gqw-gxjh-q85g/GHSA-8gqw-gxjh-q85g.json @@ -7,12 +7,8 @@ "CVE-2009-2600" ], "details": "Multiple directory traversal vulnerabilities in view.php in Webboard 2.90 beta and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in the topic parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8j5g-48x9-r6p7/GHSA-8j5g-48x9-r6p7.json b/advisories/unreviewed/2022/05/GHSA-8j5g-48x9-r6p7/GHSA-8j5g-48x9-r6p7.json index 7666a6b4029..3c4b6d9632d 100644 --- a/advisories/unreviewed/2022/05/GHSA-8j5g-48x9-r6p7/GHSA-8j5g-48x9-r6p7.json +++ b/advisories/unreviewed/2022/05/GHSA-8j5g-48x9-r6p7/GHSA-8j5g-48x9-r6p7.json @@ -7,12 +7,8 @@ "CVE-2009-2705" ], "details": "CA SiteMinder allows remote attackers to bypass cross-site scripting (XSS) protections for J2EE applications via a request containing non-canonical, \"overlong Unicode\" in place of blacklisted characters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8mrf-rr57-82qp/GHSA-8mrf-rr57-82qp.json b/advisories/unreviewed/2022/05/GHSA-8mrf-rr57-82qp/GHSA-8mrf-rr57-82qp.json index 8a26fc9d5d8..eae69235cef 100644 --- a/advisories/unreviewed/2022/05/GHSA-8mrf-rr57-82qp/GHSA-8mrf-rr57-82qp.json +++ b/advisories/unreviewed/2022/05/GHSA-8mrf-rr57-82qp/GHSA-8mrf-rr57-82qp.json @@ -7,12 +7,8 @@ "CVE-2009-3135" ], "details": "Stack-based buffer overflow in Microsoft Office Word 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, Open XML File Format Converter for Mac, Office Word Viewer 2003 SP3, and Office Word Viewer allow remote attackers to execute arbitrary code via a Word document with a malformed File Information Block (FIB) structure, aka \"Microsoft Office Word File Information Memory Corruption Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8q7j-85mf-jv76/GHSA-8q7j-85mf-jv76.json b/advisories/unreviewed/2022/05/GHSA-8q7j-85mf-jv76/GHSA-8q7j-85mf-jv76.json index ea3ae16a249..87e424c7ce7 100644 --- a/advisories/unreviewed/2022/05/GHSA-8q7j-85mf-jv76/GHSA-8q7j-85mf-jv76.json +++ b/advisories/unreviewed/2022/05/GHSA-8q7j-85mf-jv76/GHSA-8q7j-85mf-jv76.json @@ -7,12 +7,8 @@ "CVE-2009-2828" ], "details": "The server in DirectoryService in Apple Mac OS X 10.5.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8q8h-9fx4-hc7h/GHSA-8q8h-9fx4-hc7h.json b/advisories/unreviewed/2022/05/GHSA-8q8h-9fx4-hc7h/GHSA-8q8h-9fx4-hc7h.json index 96b22ad207b..74446f4d0a0 100644 --- a/advisories/unreviewed/2022/05/GHSA-8q8h-9fx4-hc7h/GHSA-8q8h-9fx4-hc7h.json +++ b/advisories/unreviewed/2022/05/GHSA-8q8h-9fx4-hc7h/GHSA-8q8h-9fx4-hc7h.json @@ -7,12 +7,8 @@ "CVE-2009-2682" ], "details": "Unspecified vulnerability in Role-Based Access Control (RBAC) in HP HP-UX B.11.23 and B.11.31 allows local users to bypass intended access restrictions via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8qv8-2hmc-98qf/GHSA-8qv8-2hmc-98qf.json b/advisories/unreviewed/2022/05/GHSA-8qv8-2hmc-98qf/GHSA-8qv8-2hmc-98qf.json index 5720b46e933..275dc24af44 100644 --- a/advisories/unreviewed/2022/05/GHSA-8qv8-2hmc-98qf/GHSA-8qv8-2hmc-98qf.json +++ b/advisories/unreviewed/2022/05/GHSA-8qv8-2hmc-98qf/GHSA-8qv8-2hmc-98qf.json @@ -7,12 +7,8 @@ "CVE-2009-2771" ], "details": "Cross-site scripting (XSS) vulnerability in Free Arcade Script 1.3 allows remote attackers to inject arbitrary web script or HTML via the keyword parameter to the default URI under search/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8qvm-3v5h-74qx/GHSA-8qvm-3v5h-74qx.json b/advisories/unreviewed/2022/05/GHSA-8qvm-3v5h-74qx/GHSA-8qvm-3v5h-74qx.json index 90f4c5d989c..f48488c17fa 100644 --- a/advisories/unreviewed/2022/05/GHSA-8qvm-3v5h-74qx/GHSA-8qvm-3v5h-74qx.json +++ b/advisories/unreviewed/2022/05/GHSA-8qvm-3v5h-74qx/GHSA-8qvm-3v5h-74qx.json @@ -7,12 +7,8 @@ "CVE-2009-3294" ], "details": "The popen API function in TSRM/tsrm_win32.c in PHP before 5.2.11 and 5.3.x before 5.3.1, when running on certain Windows operating systems, allows context-dependent attackers to cause a denial of service (crash) via a crafted (1) \"e\" or (2) \"er\" string in the second argument (aka mode), possibly related to the _fdopen function in the Microsoft C runtime library. NOTE: this might not cross privilege boundaries except in rare cases in which the mode argument is accessible to an attacker outside of an application that uses the popen function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8rmw-827g-63jm/GHSA-8rmw-827g-63jm.json b/advisories/unreviewed/2022/05/GHSA-8rmw-827g-63jm/GHSA-8rmw-827g-63jm.json index 41bf4e9f038..309bb484a75 100644 --- a/advisories/unreviewed/2022/05/GHSA-8rmw-827g-63jm/GHSA-8rmw-827g-63jm.json +++ b/advisories/unreviewed/2022/05/GHSA-8rmw-827g-63jm/GHSA-8rmw-827g-63jm.json @@ -7,12 +7,8 @@ "CVE-2009-2724" ], "details": "Race condition in the java.lang package in Sun Java SE 5.0 before Update 20 has unknown impact and attack vectors, related to a \"3Y Race condition in reflection checks.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8vq2-fxxp-56hm/GHSA-8vq2-fxxp-56hm.json b/advisories/unreviewed/2022/05/GHSA-8vq2-fxxp-56hm/GHSA-8vq2-fxxp-56hm.json index 67d05e93a2d..261c6b4d41d 100644 --- a/advisories/unreviewed/2022/05/GHSA-8vq2-fxxp-56hm/GHSA-8vq2-fxxp-56hm.json +++ b/advisories/unreviewed/2022/05/GHSA-8vq2-fxxp-56hm/GHSA-8vq2-fxxp-56hm.json @@ -7,12 +7,8 @@ "CVE-2009-2512" ], "details": "The Web Services on Devices API (WSDAPI) in Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 does not properly process the headers of WSD messages, which allows remote attackers to execute arbitrary code via a crafted (1) message or (2) response, aka \"Web Services on Devices API Memory Corruption Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8vxj-gwfr-p4jf/GHSA-8vxj-gwfr-p4jf.json b/advisories/unreviewed/2022/05/GHSA-8vxj-gwfr-p4jf/GHSA-8vxj-gwfr-p4jf.json index 4e718bfea00..7334813ed73 100644 --- a/advisories/unreviewed/2022/05/GHSA-8vxj-gwfr-p4jf/GHSA-8vxj-gwfr-p4jf.json +++ b/advisories/unreviewed/2022/05/GHSA-8vxj-gwfr-p4jf/GHSA-8vxj-gwfr-p4jf.json @@ -7,12 +7,8 @@ "CVE-2009-2646" ], "details": "Multiple unspecified vulnerabilities in the PDF distiller in the Attachment Service component in Research In Motion (RIM) BlackBerry Enterprise Server (BES) software 4.1.3 through 4.1.6 and BlackBerry Professional Software 4.1.4 allow user-assisted remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted .pdf file attachment, a different vulnerability than CVE-2008-3246 and CVE-2009-0219.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8w34-5f4j-6qgx/GHSA-8w34-5f4j-6qgx.json b/advisories/unreviewed/2022/05/GHSA-8w34-5f4j-6qgx/GHSA-8w34-5f4j-6qgx.json index fd8b4851b1d..bbf5c492eef 100644 --- a/advisories/unreviewed/2022/05/GHSA-8w34-5f4j-6qgx/GHSA-8w34-5f4j-6qgx.json +++ b/advisories/unreviewed/2022/05/GHSA-8w34-5f4j-6qgx/GHSA-8w34-5f4j-6qgx.json @@ -7,12 +7,8 @@ "CVE-2009-2921" ], "details": "Multiple SQL injection vulnerabilities in login.php in MOC Designs PHP News 1.1 allow remote attackers to execute arbitrary SQL commands via the (1) newsuser parameter (User field) and (2) newspassword parameter (Password field).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8x6c-86hp-5fvc/GHSA-8x6c-86hp-5fvc.json b/advisories/unreviewed/2022/05/GHSA-8x6c-86hp-5fvc/GHSA-8x6c-86hp-5fvc.json index ef0ed241b58..a535af28402 100644 --- a/advisories/unreviewed/2022/05/GHSA-8x6c-86hp-5fvc/GHSA-8x6c-86hp-5fvc.json +++ b/advisories/unreviewed/2022/05/GHSA-8x6c-86hp-5fvc/GHSA-8x6c-86hp-5fvc.json @@ -7,12 +7,8 @@ "CVE-2009-2627" ], "details": "Insecure method vulnerability in the Acer LunchApp (aka AcerCtrls.APlunch) ActiveX control in acerctrl.ocx allows remote attackers to execute arbitrary commands via the Run method, a different vulnerability than CVE-2006-6121.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8xjp-4c57-jp66/GHSA-8xjp-4c57-jp66.json b/advisories/unreviewed/2022/05/GHSA-8xjp-4c57-jp66/GHSA-8xjp-4c57-jp66.json index f548cc25cc4..188ce789dda 100644 --- a/advisories/unreviewed/2022/05/GHSA-8xjp-4c57-jp66/GHSA-8xjp-4c57-jp66.json +++ b/advisories/unreviewed/2022/05/GHSA-8xjp-4c57-jp66/GHSA-8xjp-4c57-jp66.json @@ -7,12 +7,8 @@ "CVE-2009-2991" ], "details": "Unspecified vulnerability in the Mozilla plug-in in Adobe Reader and Acrobat 8.x before 8.1.7, and possibly 7.x before 7.1.4 and 9.x before 9.2, might allow remote attackers to execute arbitrary code via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8xw7-76qp-6wrc/GHSA-8xw7-76qp-6wrc.json b/advisories/unreviewed/2022/05/GHSA-8xw7-76qp-6wrc/GHSA-8xw7-76qp-6wrc.json index 4bb7a035ac5..7079f9d58d1 100644 --- a/advisories/unreviewed/2022/05/GHSA-8xw7-76qp-6wrc/GHSA-8xw7-76qp-6wrc.json +++ b/advisories/unreviewed/2022/05/GHSA-8xw7-76qp-6wrc/GHSA-8xw7-76qp-6wrc.json @@ -7,12 +7,8 @@ "CVE-2009-2599" ], "details": "SQL injection vulnerability in index.php in RadCLASSIFIEDS Gold 2.0 allows remote attackers to execute arbitrary SQL commands via the seller parameter in a search action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-925m-6mfx-32g2/GHSA-925m-6mfx-32g2.json b/advisories/unreviewed/2022/05/GHSA-925m-6mfx-32g2/GHSA-925m-6mfx-32g2.json index 1af9dc1ad19..6e086861907 100644 --- a/advisories/unreviewed/2022/05/GHSA-925m-6mfx-32g2/GHSA-925m-6mfx-32g2.json +++ b/advisories/unreviewed/2022/05/GHSA-925m-6mfx-32g2/GHSA-925m-6mfx-32g2.json @@ -7,12 +7,8 @@ "CVE-2009-2881" ], "details": "Multiple SQL injection vulnerabilities in Basilic 1.5.13 allow remote attackers to execute arbitrary SQL commands via the idAuthor parameter to (1) index.php and possibly (2) allpubs.php in publications/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9284-5mwp-2g62/GHSA-9284-5mwp-2g62.json b/advisories/unreviewed/2022/05/GHSA-9284-5mwp-2g62/GHSA-9284-5mwp-2g62.json index bf18970d571..50acfc9c614 100644 --- a/advisories/unreviewed/2022/05/GHSA-9284-5mwp-2g62/GHSA-9284-5mwp-2g62.json +++ b/advisories/unreviewed/2022/05/GHSA-9284-5mwp-2g62/GHSA-9284-5mwp-2g62.json @@ -7,12 +7,8 @@ "CVE-2009-2605" ], "details": "Multiple SQL injection vulnerabilities in adminquery.php in Traidnt Up 2.0 allow remote attackers to execute arbitrary SQL commands via (1) trupuser and (2) truppassword cookies to uploadcp/index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-94w4-5268-h2hr/GHSA-94w4-5268-h2hr.json b/advisories/unreviewed/2022/05/GHSA-94w4-5268-h2hr/GHSA-94w4-5268-h2hr.json index 0aa79696431..88bf356ceaa 100644 --- a/advisories/unreviewed/2022/05/GHSA-94w4-5268-h2hr/GHSA-94w4-5268-h2hr.json +++ b/advisories/unreviewed/2022/05/GHSA-94w4-5268-h2hr/GHSA-94w4-5268-h2hr.json @@ -7,12 +7,8 @@ "CVE-2009-2733" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Achievo before 1.4.0 allow remote attackers to inject arbitrary web script or HTML via (1) the scheduler title in the scheduler module, and the (2) atksearch[contractnumber], (3) atksearch_AE_customer[customer], (4) atksearchmode[contracttype], and possibly (5) atksearch[contractname] parameters to the Organization Contracts administration page, reachable through dispatch.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-963v-cpjr-8g28/GHSA-963v-cpjr-8g28.json b/advisories/unreviewed/2022/05/GHSA-963v-cpjr-8g28/GHSA-963v-cpjr-8g28.json index b474565c0c4..370187eda66 100644 --- a/advisories/unreviewed/2022/05/GHSA-963v-cpjr-8g28/GHSA-963v-cpjr-8g28.json +++ b/advisories/unreviewed/2022/05/GHSA-963v-cpjr-8g28/GHSA-963v-cpjr-8g28.json @@ -7,12 +7,8 @@ "CVE-2009-2641" ], "details": "PHP remote file inclusion vulnerability in app_and_readme/navigator/index.php in School Data Navigator allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. NOTE: this can also be leveraged to include and execute arbitrary local files via .. (dot dot) sequences.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-96fh-38m4-95mm/GHSA-96fh-38m4-95mm.json b/advisories/unreviewed/2022/05/GHSA-96fh-38m4-95mm/GHSA-96fh-38m4-95mm.json index fff43dc80ec..84499976c12 100644 --- a/advisories/unreviewed/2022/05/GHSA-96fh-38m4-95mm/GHSA-96fh-38m4-95mm.json +++ b/advisories/unreviewed/2022/05/GHSA-96fh-38m4-95mm/GHSA-96fh-38m4-95mm.json @@ -7,12 +7,8 @@ "CVE-2009-3071" ], "details": "Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.14, and 3.5.x before 3.5.2, allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -80,9 +76,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-96hx-x89p-576c/GHSA-96hx-x89p-576c.json b/advisories/unreviewed/2022/05/GHSA-96hx-x89p-576c/GHSA-96hx-x89p-576c.json index 78880e21b0b..dd35a4bd0e4 100644 --- a/advisories/unreviewed/2022/05/GHSA-96hx-x89p-576c/GHSA-96hx-x89p-576c.json +++ b/advisories/unreviewed/2022/05/GHSA-96hx-x89p-576c/GHSA-96hx-x89p-576c.json @@ -7,12 +7,8 @@ "CVE-2009-3148" ], "details": "Multiple SQL injection vulnerabilities in PortalXP Teacher Edition 1.2 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) calendar.php, (2) news.php, and (3) links.php; and the (4) assignment_id parameter to assignments.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-96x2-2v9f-7j4q/GHSA-96x2-2v9f-7j4q.json b/advisories/unreviewed/2022/05/GHSA-96x2-2v9f-7j4q/GHSA-96x2-2v9f-7j4q.json index 0a516831c83..fe723c93fdd 100644 --- a/advisories/unreviewed/2022/05/GHSA-96x2-2v9f-7j4q/GHSA-96x2-2v9f-7j4q.json +++ b/advisories/unreviewed/2022/05/GHSA-96x2-2v9f-7j4q/GHSA-96x2-2v9f-7j4q.json @@ -7,12 +7,8 @@ "CVE-2009-2934" ], "details": "Multiple stack-based buffer overflows in xaudio.dll in Programmed Integration PIPL 2.5.0 and 2.5.0D allow remote attackers to execute arbitrary code via a long string in a (1) .pls or (2) .pl playlist file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-97qx-33fc-6rj2/GHSA-97qx-33fc-6rj2.json b/advisories/unreviewed/2022/05/GHSA-97qx-33fc-6rj2/GHSA-97qx-33fc-6rj2.json index 7d5d798e85e..e5d14a69f9e 100644 --- a/advisories/unreviewed/2022/05/GHSA-97qx-33fc-6rj2/GHSA-97qx-33fc-6rj2.json +++ b/advisories/unreviewed/2022/05/GHSA-97qx-33fc-6rj2/GHSA-97qx-33fc-6rj2.json @@ -7,12 +7,8 @@ "CVE-2009-2835" ], "details": "The kernel in Apple Mac OS X before 10.6.2 does not properly handle task state segments, which allows local users to gain privileges, cause a denial of service (system crash), or obtain sensitive information via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-97rh-hvhj-xf5r/GHSA-97rh-hvhj-xf5r.json b/advisories/unreviewed/2022/05/GHSA-97rh-hvhj-xf5r/GHSA-97rh-hvhj-xf5r.json index 3d91b08f7ad..1d97d18f1b0 100644 --- a/advisories/unreviewed/2022/05/GHSA-97rh-hvhj-xf5r/GHSA-97rh-hvhj-xf5r.json +++ b/advisories/unreviewed/2022/05/GHSA-97rh-hvhj-xf5r/GHSA-97rh-hvhj-xf5r.json @@ -7,12 +7,8 @@ "CVE-2009-3098" ], "details": "Unspecified vulnerability in the Portal in HP Operations Dashboard 2.1 on Windows Server 2003 SP2 allows remote attackers to have an unknown impact, related to a \"Remote exploit,\" as demonstrated by a certain module in VulnDisco Pack Professional 8.11. NOTE: as of 20090903, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-982f-g4wh-9m46/GHSA-982f-g4wh-9m46.json b/advisories/unreviewed/2022/05/GHSA-982f-g4wh-9m46/GHSA-982f-g4wh-9m46.json index af7b1259f93..d1a4a7ba75c 100644 --- a/advisories/unreviewed/2022/05/GHSA-982f-g4wh-9m46/GHSA-982f-g4wh-9m46.json +++ b/advisories/unreviewed/2022/05/GHSA-982f-g4wh-9m46/GHSA-982f-g4wh-9m46.json @@ -7,12 +7,8 @@ "CVE-2009-2490" ], "details": "Unspecified vulnerability in the utaudiod daemon in Sun Ray Server Software (SRSS) 4.0, when Solaris Trusted Extensions is enabled, allows local users to cause a denial of service (audio outage) or possibly gain privileges via unknown vectors related to \"resource leaks.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-993g-7wv3-q8cj/GHSA-993g-7wv3-q8cj.json b/advisories/unreviewed/2022/05/GHSA-993g-7wv3-q8cj/GHSA-993g-7wv3-q8cj.json index 3488ea83df0..73401b20d95 100644 --- a/advisories/unreviewed/2022/05/GHSA-993g-7wv3-q8cj/GHSA-993g-7wv3-q8cj.json +++ b/advisories/unreviewed/2022/05/GHSA-993g-7wv3-q8cj/GHSA-993g-7wv3-q8cj.json @@ -7,12 +7,8 @@ "CVE-2009-2833" ], "details": "Buffer overflow in the UCCompareTextDefault API in International Components for Unicode in Apple Mac OS X 10.5.8 allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-99cg-v7m7-v6v7/GHSA-99cg-v7m7-v6v7.json b/advisories/unreviewed/2022/05/GHSA-99cg-v7m7-v6v7/GHSA-99cg-v7m7-v6v7.json index d719467d024..8de66ad0ee6 100644 --- a/advisories/unreviewed/2022/05/GHSA-99cg-v7m7-v6v7/GHSA-99cg-v7m7-v6v7.json +++ b/advisories/unreviewed/2022/05/GHSA-99cg-v7m7-v6v7/GHSA-99cg-v7m7-v6v7.json @@ -7,12 +7,8 @@ "CVE-2009-2884" ], "details": "Cross-site scripting (XSS) vulnerability in bios.php in PHP Scripts Now World's Tallest Buildings allows remote attackers to inject arbitrary web script or HTML via the rank parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-99wr-w25w-rhrf/GHSA-99wr-w25w-rhrf.json b/advisories/unreviewed/2022/05/GHSA-99wr-w25w-rhrf/GHSA-99wr-w25w-rhrf.json index 09a2ff4a6fe..165f727467b 100644 --- a/advisories/unreviewed/2022/05/GHSA-99wr-w25w-rhrf/GHSA-99wr-w25w-rhrf.json +++ b/advisories/unreviewed/2022/05/GHSA-99wr-w25w-rhrf/GHSA-99wr-w25w-rhrf.json @@ -7,12 +7,8 @@ "CVE-2009-2786" ], "details": "SQL injection vulnerability in reputation.php in the Reputation plugin 2.2.4, 2.2.3, 2.0.4, and earlier for PunBB allows remote attackers to execute arbitrary SQL commands via the poster parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9crh-cc7m-2263/GHSA-9crh-cc7m-2263.json b/advisories/unreviewed/2022/05/GHSA-9crh-cc7m-2263/GHSA-9crh-cc7m-2263.json index ee5a9466c9a..fb70bb691f1 100644 --- a/advisories/unreviewed/2022/05/GHSA-9crh-cc7m-2263/GHSA-9crh-cc7m-2263.json +++ b/advisories/unreviewed/2022/05/GHSA-9crh-cc7m-2263/GHSA-9crh-cc7m-2263.json @@ -7,12 +7,8 @@ "CVE-2009-3015" ], "details": "QtWeb 3.0 Builds 001 and 003 does not properly block javascript: and data: URIs in Refresh and Location headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header that contains a javascript: URI, (2) entering a javascript: URI when specifying the content of a Refresh header, (3) injecting a Refresh header that contains JavaScript sequences in a data:text/html URI, (4) entering a data:text/html URI with JavaScript sequences when specifying the content of a Refresh header, (5) injecting a Location header that contains JavaScript sequences in a data:text/html URI, or (6) entering a data:text/html URI with JavaScript sequences when specifying the content of a Location header.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9cx7-5w9f-75jq/GHSA-9cx7-5w9f-75jq.json b/advisories/unreviewed/2022/05/GHSA-9cx7-5w9f-75jq/GHSA-9cx7-5w9f-75jq.json index 3afdd5b656b..1b19b4d07a7 100644 --- a/advisories/unreviewed/2022/05/GHSA-9cx7-5w9f-75jq/GHSA-9cx7-5w9f-75jq.json +++ b/advisories/unreviewed/2022/05/GHSA-9cx7-5w9f-75jq/GHSA-9cx7-5w9f-75jq.json @@ -7,12 +7,8 @@ "CVE-2009-2594" ], "details": "Cross-site scripting (XSS) vulnerability in censura.php in Censura 1.16.04 allows remote attackers to inject arbitrary web script or HTML via the itemid parameter in a details action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9fcw-h273-v9r3/GHSA-9fcw-h273-v9r3.json b/advisories/unreviewed/2022/05/GHSA-9fcw-h273-v9r3/GHSA-9fcw-h273-v9r3.json index 0fe3a836335..f58f05241bb 100644 --- a/advisories/unreviewed/2022/05/GHSA-9fcw-h273-v9r3/GHSA-9fcw-h273-v9r3.json +++ b/advisories/unreviewed/2022/05/GHSA-9fcw-h273-v9r3/GHSA-9fcw-h273-v9r3.json @@ -7,12 +7,8 @@ "CVE-2009-2525" ], "details": "Microsoft Windows Media Runtime, as used in DirectShow WMA Voice Codec, Windows Media Audio Voice Decoder, and Audio Compression Manager (ACM), does not properly initialize unspecified functions within compressed audio files, which allows remote attackers to execute arbitrary code via (1) a crafted media file or (2) crafted streaming content, aka \"Windows Media Runtime Heap Corruption Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9gf3-j9w5-g3hm/GHSA-9gf3-j9w5-g3hm.json b/advisories/unreviewed/2022/05/GHSA-9gf3-j9w5-g3hm/GHSA-9gf3-j9w5-g3hm.json index 8ce5efec886..7aa3e05709f 100644 --- a/advisories/unreviewed/2022/05/GHSA-9gf3-j9w5-g3hm/GHSA-9gf3-j9w5-g3hm.json +++ b/advisories/unreviewed/2022/05/GHSA-9gf3-j9w5-g3hm/GHSA-9gf3-j9w5-g3hm.json @@ -7,12 +7,8 @@ "CVE-2009-2946" ], "details": "Eval injection vulnerability in scripts/uscan.pl before Rev 1984 in devscripts allows remote attackers to execute arbitrary Perl code via crafted pathnames on distribution servers for upstream source code used in Debian GNU/Linux packages.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9gvv-96c5-f9vx/GHSA-9gvv-96c5-f9vx.json b/advisories/unreviewed/2022/05/GHSA-9gvv-96c5-f9vx/GHSA-9gvv-96c5-f9vx.json index b7c2befa9c3..a57043999c6 100644 --- a/advisories/unreviewed/2022/05/GHSA-9gvv-96c5-f9vx/GHSA-9gvv-96c5-f9vx.json +++ b/advisories/unreviewed/2022/05/GHSA-9gvv-96c5-f9vx/GHSA-9gvv-96c5-f9vx.json @@ -7,12 +7,8 @@ "CVE-2009-3237" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Horde Application Framework 3.2 before 3.2.5 and 3.3 before 3.3.5; Groupware 1.1 before 1.1.6 and 1.2 before 1.2.4; and Groupware Webmail Edition 1.1 before 1.1.6 and 1.2 before 1.2.4; allow remote attackers to inject arbitrary web script or HTML via the (1) crafted number preferences that are not properly handled in the preference system (services/prefs.php), as demonstrated by the sidebar_width parameter; or (2) crafted unknown MIME \"text parts\" that are not properly handled in the MIME viewer library (config/mime_drivers.php).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9hgg-vhrm-7vx2/GHSA-9hgg-vhrm-7vx2.json b/advisories/unreviewed/2022/05/GHSA-9hgg-vhrm-7vx2/GHSA-9hgg-vhrm-7vx2.json index bda1709b7be..798397c713b 100644 --- a/advisories/unreviewed/2022/05/GHSA-9hgg-vhrm-7vx2/GHSA-9hgg-vhrm-7vx2.json +++ b/advisories/unreviewed/2022/05/GHSA-9hgg-vhrm-7vx2/GHSA-9hgg-vhrm-7vx2.json @@ -7,12 +7,8 @@ "CVE-2009-3048" ], "details": "Opera before 10.00 on Linux, Solaris, and FreeBSD does not properly implement the \"INPUT TYPE=file\" functionality, which allows remote attackers to trick a user into uploading an unintended file via vectors involving a \"dropped file.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9jg3-ffw3-vq2f/GHSA-9jg3-ffw3-vq2f.json b/advisories/unreviewed/2022/05/GHSA-9jg3-ffw3-vq2f/GHSA-9jg3-ffw3-vq2f.json index fbfa38e0f9a..9ea5025d0d1 100644 --- a/advisories/unreviewed/2022/05/GHSA-9jg3-ffw3-vq2f/GHSA-9jg3-ffw3-vq2f.json +++ b/advisories/unreviewed/2022/05/GHSA-9jg3-ffw3-vq2f/GHSA-9jg3-ffw3-vq2f.json @@ -7,12 +7,8 @@ "CVE-2009-2639" ], "details": "SQL injection vulnerability in admin.php in MRCGIGUY The Ticket System 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a viewticket action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9jw6-f2rj-4m2g/GHSA-9jw6-f2rj-4m2g.json b/advisories/unreviewed/2022/05/GHSA-9jw6-f2rj-4m2g/GHSA-9jw6-f2rj-4m2g.json index 35b1731b626..99d676bcca2 100644 --- a/advisories/unreviewed/2022/05/GHSA-9jw6-f2rj-4m2g/GHSA-9jw6-f2rj-4m2g.json +++ b/advisories/unreviewed/2022/05/GHSA-9jw6-f2rj-4m2g/GHSA-9jw6-f2rj-4m2g.json @@ -7,12 +7,8 @@ "CVE-2009-2798" ], "details": "Heap-based buffer overflow in Apple QuickTime before 7.6.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted FlashPix file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9m84-hc5j-m7wj/GHSA-9m84-hc5j-m7wj.json b/advisories/unreviewed/2022/05/GHSA-9m84-hc5j-m7wj/GHSA-9m84-hc5j-m7wj.json index d947f745135..558fc29fc74 100644 --- a/advisories/unreviewed/2022/05/GHSA-9m84-hc5j-m7wj/GHSA-9m84-hc5j-m7wj.json +++ b/advisories/unreviewed/2022/05/GHSA-9m84-hc5j-m7wj/GHSA-9m84-hc5j-m7wj.json @@ -7,12 +7,8 @@ "CVE-2009-2779" ], "details": "SQL injection vulnerability in index.php in AJ Matrix DNA allows remote attackers to execute arbitrary SQL commands via the id parameter in a productdetail action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9mcg-gf2h-6xxx/GHSA-9mcg-gf2h-6xxx.json b/advisories/unreviewed/2022/05/GHSA-9mcg-gf2h-6xxx/GHSA-9mcg-gf2h-6xxx.json index 6ebe499b823..985fccbd428 100644 --- a/advisories/unreviewed/2022/05/GHSA-9mcg-gf2h-6xxx/GHSA-9mcg-gf2h-6xxx.json +++ b/advisories/unreviewed/2022/05/GHSA-9mcg-gf2h-6xxx/GHSA-9mcg-gf2h-6xxx.json @@ -7,12 +7,8 @@ "CVE-2009-2754" ], "details": "Integer signedness error in the authentication functionality in librpc.dll in the Informix Storage Manager (ISM) Portmapper service (aka portmap.exe), as used in IBM Informix Dynamic Server (IDS) 10.x before 10.00.TC9 and 11.x before 11.10.TC3 and EMC Legato NetWorker, allows remote attackers to execute arbitrary code via a crafted parameter size that triggers a stack-based buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9q3x-8xjm-8642/GHSA-9q3x-8xjm-8642.json b/advisories/unreviewed/2022/05/GHSA-9q3x-8xjm-8642/GHSA-9q3x-8xjm-8642.json index 5e3243b8529..828e1878779 100644 --- a/advisories/unreviewed/2022/05/GHSA-9q3x-8xjm-8642/GHSA-9q3x-8xjm-8642.json +++ b/advisories/unreviewed/2022/05/GHSA-9q3x-8xjm-8642/GHSA-9q3x-8xjm-8642.json @@ -7,12 +7,8 @@ "CVE-2009-2851" ], "details": "Cross-site scripting (XSS) vulnerability in the administrator interface in WordPress before 2.8.2 allows remote attackers to inject arbitrary web script or HTML via a comment author URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9q9v-fv5g-fj8r/GHSA-9q9v-fv5g-fj8r.json b/advisories/unreviewed/2022/05/GHSA-9q9v-fv5g-fj8r/GHSA-9q9v-fv5g-fj8r.json index 7e5ac699b57..087d0259b64 100644 --- a/advisories/unreviewed/2022/05/GHSA-9q9v-fv5g-fj8r/GHSA-9q9v-fv5g-fj8r.json +++ b/advisories/unreviewed/2022/05/GHSA-9q9v-fv5g-fj8r/GHSA-9q9v-fv5g-fj8r.json @@ -7,12 +7,8 @@ "CVE-2009-2576" ], "details": "Microsoft Internet Explorer 6.0.2900.2180 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via a long Unicode string argument to the write method, a related issue to CVE-2009-2479. NOTE: it was later reported that 7.0.6000.16473 and earlier are also affected.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9qj6-5wm9-wp55/GHSA-9qj6-5wm9-wp55.json b/advisories/unreviewed/2022/05/GHSA-9qj6-5wm9-wp55/GHSA-9qj6-5wm9-wp55.json index 50e4f1b2482..69d2f6c765b 100644 --- a/advisories/unreviewed/2022/05/GHSA-9qj6-5wm9-wp55/GHSA-9qj6-5wm9-wp55.json +++ b/advisories/unreviewed/2022/05/GHSA-9qj6-5wm9-wp55/GHSA-9qj6-5wm9-wp55.json @@ -7,12 +7,8 @@ "CVE-2009-3042" ], "details": "SQL injection vulnerability in machine.php in Open Computer and Software (OCS) Inventory NG 1.02.1 allows remote attackers to execute arbitrary SQL commands via the systemid parameter, a different vector than CVE-2009-3040.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9r85-jqv2-rmpv/GHSA-9r85-jqv2-rmpv.json b/advisories/unreviewed/2022/05/GHSA-9r85-jqv2-rmpv/GHSA-9r85-jqv2-rmpv.json index 97e4e492ab9..d3c32c16f4b 100644 --- a/advisories/unreviewed/2022/05/GHSA-9r85-jqv2-rmpv/GHSA-9r85-jqv2-rmpv.json +++ b/advisories/unreviewed/2022/05/GHSA-9r85-jqv2-rmpv/GHSA-9r85-jqv2-rmpv.json @@ -7,12 +7,8 @@ "CVE-2009-3180" ], "details": "Anantasoft Gazelle CMS 1.0 allows remote attackers to conduct a password reset for other users via a modified user parameter to renew.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9r9h-639m-hg32/GHSA-9r9h-639m-hg32.json b/advisories/unreviewed/2022/05/GHSA-9r9h-639m-hg32/GHSA-9r9h-639m-hg32.json index 477d8e0320c..d3b769e94e5 100644 --- a/advisories/unreviewed/2022/05/GHSA-9r9h-639m-hg32/GHSA-9r9h-639m-hg32.json +++ b/advisories/unreviewed/2022/05/GHSA-9r9h-639m-hg32/GHSA-9r9h-639m-hg32.json @@ -7,12 +7,8 @@ "CVE-2009-2792" ], "details": "Directory traversal vulnerability in plugings/pagecontent.php in Really Simple CMS (RSCMS) 0.3a allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the PT parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9rcr-489q-q8xm/GHSA-9rcr-489q-q8xm.json b/advisories/unreviewed/2022/05/GHSA-9rcr-489q-q8xm/GHSA-9rcr-489q-q8xm.json index fe30793cc53..cd6541f1938 100644 --- a/advisories/unreviewed/2022/05/GHSA-9rcr-489q-q8xm/GHSA-9rcr-489q-q8xm.json +++ b/advisories/unreviewed/2022/05/GHSA-9rcr-489q-q8xm/GHSA-9rcr-489q-q8xm.json @@ -7,12 +7,8 @@ "CVE-2009-3158" ], "details": "admin/files.php in simplePHPWeb 0.2 does not require authentication, which allows remote attackers to perform unspecified administrative actions via unknown vectors. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9rq4-g25h-r3w7/GHSA-9rq4-g25h-r3w7.json b/advisories/unreviewed/2022/05/GHSA-9rq4-g25h-r3w7/GHSA-9rq4-g25h-r3w7.json index dfe12ab9146..276168b6d2e 100644 --- a/advisories/unreviewed/2022/05/GHSA-9rq4-g25h-r3w7/GHSA-9rq4-g25h-r3w7.json +++ b/advisories/unreviewed/2022/05/GHSA-9rq4-g25h-r3w7/GHSA-9rq4-g25h-r3w7.json @@ -7,12 +7,8 @@ "CVE-2009-3182" ], "details": "Unrestricted file upload vulnerability in admin/editor/filemanager/browser.html in Anantasoft Gazelle CMS 1.0 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in user/File/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9rrc-79p2-q54h/GHSA-9rrc-79p2-q54h.json b/advisories/unreviewed/2022/05/GHSA-9rrc-79p2-q54h/GHSA-9rrc-79p2-q54h.json index cbb740cb00f..836a1684dcc 100644 --- a/advisories/unreviewed/2022/05/GHSA-9rrc-79p2-q54h/GHSA-9rrc-79p2-q54h.json +++ b/advisories/unreviewed/2022/05/GHSA-9rrc-79p2-q54h/GHSA-9rrc-79p2-q54h.json @@ -7,12 +7,8 @@ "CVE-2009-3000" ], "details": "The sockfs module in the kernel in Sun Solaris 10 and OpenSolaris snv_41 through snv_122, when Network Cache Accelerator (NCA) logging is enabled, allows remote attackers to cause a denial of service (panic) via unspecified web-server traffic that triggers a NULL pointer dereference in the nl7c_http_log function, related to \"improper http response handling.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9v5v-cghp-7hhr/GHSA-9v5v-cghp-7hhr.json b/advisories/unreviewed/2022/05/GHSA-9v5v-cghp-7hhr/GHSA-9v5v-cghp-7hhr.json index fd57dcccccc..4b7024baab4 100644 --- a/advisories/unreviewed/2022/05/GHSA-9v5v-cghp-7hhr/GHSA-9v5v-cghp-7hhr.json +++ b/advisories/unreviewed/2022/05/GHSA-9v5v-cghp-7hhr/GHSA-9v5v-cghp-7hhr.json @@ -7,12 +7,8 @@ "CVE-2009-2789" ], "details": "SQL injection vulnerability in the Permis (com_groups) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a list action to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9vjx-w5p4-4vg6/GHSA-9vjx-w5p4-4vg6.json b/advisories/unreviewed/2022/05/GHSA-9vjx-w5p4-4vg6/GHSA-9vjx-w5p4-4vg6.json index c067fa0a66d..43cee9726aa 100644 --- a/advisories/unreviewed/2022/05/GHSA-9vjx-w5p4-4vg6/GHSA-9vjx-w5p4-4vg6.json +++ b/advisories/unreviewed/2022/05/GHSA-9vjx-w5p4-4vg6/GHSA-9vjx-w5p4-4vg6.json @@ -7,12 +7,8 @@ "CVE-2009-2807" ], "details": "Heap-based buffer overflow in the USB backend in CUPS in Apple Mac OS X 10.5.8 allows local users to gain privileges via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9w44-9hpj-hxw8/GHSA-9w44-9hpj-hxw8.json b/advisories/unreviewed/2022/05/GHSA-9w44-9hpj-hxw8/GHSA-9w44-9hpj-hxw8.json index dabd180e703..57cee807be6 100644 --- a/advisories/unreviewed/2022/05/GHSA-9w44-9hpj-hxw8/GHSA-9w44-9hpj-hxw8.json +++ b/advisories/unreviewed/2022/05/GHSA-9w44-9hpj-hxw8/GHSA-9w44-9hpj-hxw8.json @@ -7,12 +7,8 @@ "CVE-2009-2636" ], "details": "Cross-site scripting (XSS) vulnerability in the Integration page in the WebMail component in Kerio MailServer 6.6.0, 6.6.1, 6.6.2, and 6.7.0 allows remote attackers to inject arbitrary web script or HTML via an e-mail message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9wv5-pprm-9xw9/GHSA-9wv5-pprm-9xw9.json b/advisories/unreviewed/2022/05/GHSA-9wv5-pprm-9xw9/GHSA-9wv5-pprm-9xw9.json index 4f15e494e2b..7c21405c5ce 100644 --- a/advisories/unreviewed/2022/05/GHSA-9wv5-pprm-9xw9/GHSA-9wv5-pprm-9xw9.json +++ b/advisories/unreviewed/2022/05/GHSA-9wv5-pprm-9xw9/GHSA-9wv5-pprm-9xw9.json @@ -7,12 +7,8 @@ "CVE-2009-2978" ], "details": "SQL injection vulnerability in SugarCRM 4.5.1o and earlier, 5.0.0k and earlier, and 5.2.0g and earlier, allows remote attackers to execute arbitrary SQL commands via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9xfg-6whq-qvgm/GHSA-9xfg-6whq-qvgm.json b/advisories/unreviewed/2022/05/GHSA-9xfg-6whq-qvgm/GHSA-9xfg-6whq-qvgm.json index 5bb27244f16..52eea672abc 100644 --- a/advisories/unreviewed/2022/05/GHSA-9xfg-6whq-qvgm/GHSA-9xfg-6whq-qvgm.json +++ b/advisories/unreviewed/2022/05/GHSA-9xfg-6whq-qvgm/GHSA-9xfg-6whq-qvgm.json @@ -7,12 +7,8 @@ "CVE-2009-3156" ], "details": "Cross-site scripting (XSS) vulnerability in the Date Tools sub-module in the Date module 6.x before 6.x-2.3 for Drupal allows remote authenticated users, with \"use date tools\" or \"administer content types\" privileges, to inject arbitrary web script or HTML via a \"Content type label\" field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9xgx-r24h-w85c/GHSA-9xgx-r24h-w85c.json b/advisories/unreviewed/2022/05/GHSA-9xgx-r24h-w85c/GHSA-9xgx-r24h-w85c.json index e366b264531..726e540efb3 100644 --- a/advisories/unreviewed/2022/05/GHSA-9xgx-r24h-w85c/GHSA-9xgx-r24h-w85c.json +++ b/advisories/unreviewed/2022/05/GHSA-9xgx-r24h-w85c/GHSA-9xgx-r24h-w85c.json @@ -7,12 +7,8 @@ "CVE-2009-2988" ], "details": "Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 do not properly validate input, which allows attackers to cause a denial of service via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c2j5-3wjw-c48g/GHSA-c2j5-3wjw-c48g.json b/advisories/unreviewed/2022/05/GHSA-c2j5-3wjw-c48g/GHSA-c2j5-3wjw-c48g.json index a7cbb00f517..26617aa80ec 100644 --- a/advisories/unreviewed/2022/05/GHSA-c2j5-3wjw-c48g/GHSA-c2j5-3wjw-c48g.json +++ b/advisories/unreviewed/2022/05/GHSA-c2j5-3wjw-c48g/GHSA-c2j5-3wjw-c48g.json @@ -7,12 +7,8 @@ "CVE-2009-2982" ], "details": "An unspecified certificate in Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 might allow remote attackers to conduct a \"social engineering attack\" via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c2mw-mjjw-7p85/GHSA-c2mw-mjjw-7p85.json b/advisories/unreviewed/2022/05/GHSA-c2mw-mjjw-7p85/GHSA-c2mw-mjjw-7p85.json index 497ec1c6fec..3dc537a8382 100644 --- a/advisories/unreviewed/2022/05/GHSA-c2mw-mjjw-7p85/GHSA-c2mw-mjjw-7p85.json +++ b/advisories/unreviewed/2022/05/GHSA-c2mw-mjjw-7p85/GHSA-c2mw-mjjw-7p85.json @@ -7,12 +7,8 @@ "CVE-2009-2945" ], "details": "weblogin/login.fcgi (aka the WebLogin login script) in Stanford University WebAuth 3.5.5, 3.6.0, and 3.6.1 places passwords in URLs in certain circumstances involving conversion of a POST request to a GET request, which allows context-dependent attackers to discover passwords by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c2rh-3265-vp8c/GHSA-c2rh-3265-vp8c.json b/advisories/unreviewed/2022/05/GHSA-c2rh-3265-vp8c/GHSA-c2rh-3265-vp8c.json index 63e56da6051..a716f350a67 100644 --- a/advisories/unreviewed/2022/05/GHSA-c2rh-3265-vp8c/GHSA-c2rh-3265-vp8c.json +++ b/advisories/unreviewed/2022/05/GHSA-c2rh-3265-vp8c/GHSA-c2rh-3265-vp8c.json @@ -7,12 +7,8 @@ "CVE-2009-3181" ], "details": "Directory traversal vulnerability in Anantasoft Gazelle CMS 1.0 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in the customizetemplate parameter in a direct request to admin/settemplate.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c3j9-9fc9-p66x/GHSA-c3j9-9fc9-p66x.json b/advisories/unreviewed/2022/05/GHSA-c3j9-9fc9-p66x/GHSA-c3j9-9fc9-p66x.json index d111e728797..74a9b9e95ff 100644 --- a/advisories/unreviewed/2022/05/GHSA-c3j9-9fc9-p66x/GHSA-c3j9-9fc9-p66x.json +++ b/advisories/unreviewed/2022/05/GHSA-c3j9-9fc9-p66x/GHSA-c3j9-9fc9-p66x.json @@ -7,12 +7,8 @@ "CVE-2009-3028" ], "details": "The Altiris eXpress NS SC Download ActiveX control in AeXNSPkgDLLib.dll, as used in Symantec Altiris Deployment Solution 6.9.x, Notification Server 6.0.x, and Symantec Management Platform 7.0.x exposes an unsafe method, which allows remote attackers to force the download of arbitrary files and possibly execute arbitrary code via the DownloadAndInstall method.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c3qm-g6p7-rfr3/GHSA-c3qm-g6p7-rfr3.json b/advisories/unreviewed/2022/05/GHSA-c3qm-g6p7-rfr3/GHSA-c3qm-g6p7-rfr3.json index 052748bec59..34a7f21334d 100644 --- a/advisories/unreviewed/2022/05/GHSA-c3qm-g6p7-rfr3/GHSA-c3qm-g6p7-rfr3.json +++ b/advisories/unreviewed/2022/05/GHSA-c3qm-g6p7-rfr3/GHSA-c3qm-g6p7-rfr3.json @@ -7,12 +7,8 @@ "CVE-2009-2617" ], "details": "Stack-based buffer overflow in medialib.dll in BaoFeng Storm 3.9.62 allows remote attackers to execute arbitrary code via a long pathname in the source attribute of an item element in a .smpl playlist file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c4r8-9pm5-5275/GHSA-c4r8-9pm5-5275.json b/advisories/unreviewed/2022/05/GHSA-c4r8-9pm5-5275/GHSA-c4r8-9pm5-5275.json index c3b648981f6..6cc267981c6 100644 --- a/advisories/unreviewed/2022/05/GHSA-c4r8-9pm5-5275/GHSA-c4r8-9pm5-5275.json +++ b/advisories/unreviewed/2022/05/GHSA-c4r8-9pm5-5275/GHSA-c4r8-9pm5-5275.json @@ -7,12 +7,8 @@ "CVE-2009-2912" ], "details": "The (1) sendfile and (2) sendfilev functions in Sun Solaris 8 through 10, and OpenSolaris before snv_110, allow local users to cause a denial of service (panic) via vectors related to vnode function calls.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c5g5-37rh-vqmp/GHSA-c5g5-37rh-vqmp.json b/advisories/unreviewed/2022/05/GHSA-c5g5-37rh-vqmp/GHSA-c5g5-37rh-vqmp.json index d5e33672220..67a14fe5a62 100644 --- a/advisories/unreviewed/2022/05/GHSA-c5g5-37rh-vqmp/GHSA-c5g5-37rh-vqmp.json +++ b/advisories/unreviewed/2022/05/GHSA-c5g5-37rh-vqmp/GHSA-c5g5-37rh-vqmp.json @@ -7,12 +7,8 @@ "CVE-2009-3265" ], "details": "Cross-site scripting (XSS) vulnerability in Opera 9 and 10 allows remote attackers to inject arbitrary web script or HTML via a (1) RSS or (2) Atom feed, related to the rendering of the application/rss+xml content type as \"scripted content.\" NOTE: the vendor reportedly considers this behavior a \"design feature,\" not a vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c5qh-p8w9-vjq7/GHSA-c5qh-p8w9-vjq7.json b/advisories/unreviewed/2022/05/GHSA-c5qh-p8w9-vjq7/GHSA-c5qh-p8w9-vjq7.json index 0a5c1528e05..90c7e95d3d3 100644 --- a/advisories/unreviewed/2022/05/GHSA-c5qh-p8w9-vjq7/GHSA-c5qh-p8w9-vjq7.json +++ b/advisories/unreviewed/2022/05/GHSA-c5qh-p8w9-vjq7/GHSA-c5qh-p8w9-vjq7.json @@ -7,12 +7,8 @@ "CVE-2009-3245" ], "details": "OpenSSL before 0.9.8m does not check for a NULL return value from bn_wexpand function calls in (1) crypto/bn/bn_div.c, (2) crypto/bn/bn_gf2m.c, (3) crypto/ec/ec2_smpl.c, and (4) engines/e_ubsec.c, which has unspecified impact and context-dependent attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c7j3-xxqh-xjh7/GHSA-c7j3-xxqh-xjh7.json b/advisories/unreviewed/2022/05/GHSA-c7j3-xxqh-xjh7/GHSA-c7j3-xxqh-xjh7.json index dbef1cc692a..42d20743b29 100644 --- a/advisories/unreviewed/2022/05/GHSA-c7j3-xxqh-xjh7/GHSA-c7j3-xxqh-xjh7.json +++ b/advisories/unreviewed/2022/05/GHSA-c7j3-xxqh-xjh7/GHSA-c7j3-xxqh-xjh7.json @@ -7,12 +7,8 @@ "CVE-2009-2933" ], "details": "SQL injection vulnerability in comments.php in Piwigo before 2.0.3 allows remote attackers to execute arbitrary SQL commands via the items_number parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c846-hjc5-6vmf/GHSA-c846-hjc5-6vmf.json b/advisories/unreviewed/2022/05/GHSA-c846-hjc5-6vmf/GHSA-c846-hjc5-6vmf.json index 920612d1bd2..5013f51eca9 100644 --- a/advisories/unreviewed/2022/05/GHSA-c846-hjc5-6vmf/GHSA-c846-hjc5-6vmf.json +++ b/advisories/unreviewed/2022/05/GHSA-c846-hjc5-6vmf/GHSA-c846-hjc5-6vmf.json @@ -7,12 +7,8 @@ "CVE-2009-2883" ], "details": "SQL injection vulnerability in admin/login.php in SaphpLesson 4.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the cp_username parameter, related to an error in the CleanVar function in includes/functions.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c85v-8h9f-3jwr/GHSA-c85v-8h9f-3jwr.json b/advisories/unreviewed/2022/05/GHSA-c85v-8h9f-3jwr/GHSA-c85v-8h9f-3jwr.json index 4782162a844..7984c24bb11 100644 --- a/advisories/unreviewed/2022/05/GHSA-c85v-8h9f-3jwr/GHSA-c85v-8h9f-3jwr.json +++ b/advisories/unreviewed/2022/05/GHSA-c85v-8h9f-3jwr/GHSA-c85v-8h9f-3jwr.json @@ -7,12 +7,8 @@ "CVE-2009-2847" ], "details": "The do_sigaltstack function in kernel/signal.c in Linux kernel 2.4 through 2.4.37 and 2.6 before 2.6.31-rc5, when running on 64-bit systems, does not clear certain padding bytes from a structure, which allows local users to obtain sensitive information from the kernel stack via the sigaltstack function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -104,9 +100,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c9r9-vvw2-676q/GHSA-c9r9-vvw2-676q.json b/advisories/unreviewed/2022/05/GHSA-c9r9-vvw2-676q/GHSA-c9r9-vvw2-676q.json index 61afb19ab1c..6a43c9ee8b6 100644 --- a/advisories/unreviewed/2022/05/GHSA-c9r9-vvw2-676q/GHSA-c9r9-vvw2-676q.json +++ b/advisories/unreviewed/2022/05/GHSA-c9r9-vvw2-676q/GHSA-c9r9-vvw2-676q.json @@ -7,12 +7,8 @@ "CVE-2009-2777" ], "details": "SQL injection vulnerability in visitor/view.php in GarageSales Script allows remote attackers to execute arbitrary SQL commands via the key parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cc7j-f64f-pf58/GHSA-cc7j-f64f-pf58.json b/advisories/unreviewed/2022/05/GHSA-cc7j-f64f-pf58/GHSA-cc7j-f64f-pf58.json index a422c1f2cdf..5b5a28cbf26 100644 --- a/advisories/unreviewed/2022/05/GHSA-cc7j-f64f-pf58/GHSA-cc7j-f64f-pf58.json +++ b/advisories/unreviewed/2022/05/GHSA-cc7j-f64f-pf58/GHSA-cc7j-f64f-pf58.json @@ -7,12 +7,8 @@ "CVE-2009-3153" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in x10 MP3 Search engine 1.6.5 allow remote attackers to inject arbitrary web script or HTML via the (1) pic_id parameter to includes/video_ad.php, (2) category parameter to linkvideos_listing.php, id parameter to (3) templates/header1.php and (4) mp3/lyrics.php, key parameter to (5) video_listing.php and (6) adult/video_listing.php, and name parameter to (7) mp3/embed.php and (8) mp3/info.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cfgp-6px9-h8qc/GHSA-cfgp-6px9-h8qc.json b/advisories/unreviewed/2022/05/GHSA-cfgp-6px9-h8qc/GHSA-cfgp-6px9-h8qc.json index 74739e69fb9..e524a9a5143 100644 --- a/advisories/unreviewed/2022/05/GHSA-cfgp-6px9-h8qc/GHSA-cfgp-6px9-h8qc.json +++ b/advisories/unreviewed/2022/05/GHSA-cfgp-6px9-h8qc/GHSA-cfgp-6px9-h8qc.json @@ -7,12 +7,8 @@ "CVE-2009-2503" ], "details": "GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Windows Server 2003 SP2, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 does not properly allocate an unspecified buffer, which allows remote attackers to execute arbitrary code via a crafted TIFF image file that triggers memory corruption, aka \"GDI+ TIFF Memory Corruption Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cfvh-jfgx-3rc7/GHSA-cfvh-jfgx-3rc7.json b/advisories/unreviewed/2022/05/GHSA-cfvh-jfgx-3rc7/GHSA-cfvh-jfgx-3rc7.json index b5382b47c36..bba6afc6d70 100644 --- a/advisories/unreviewed/2022/05/GHSA-cfvh-jfgx-3rc7/GHSA-cfvh-jfgx-3rc7.json +++ b/advisories/unreviewed/2022/05/GHSA-cfvh-jfgx-3rc7/GHSA-cfvh-jfgx-3rc7.json @@ -7,12 +7,8 @@ "CVE-2009-3161" ], "details": "The server in IBM WebSphere MQ 7.0.0.1, 7.0.0.2, and 7.0.1.0 allows attackers to cause a denial of service (trap) or possibly have unspecified other impact via malformed data.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cgg7-545q-m5mf/GHSA-cgg7-545q-m5mf.json b/advisories/unreviewed/2022/05/GHSA-cgg7-545q-m5mf/GHSA-cgg7-545q-m5mf.json index 28acab661e1..0b2e6ffc6eb 100644 --- a/advisories/unreviewed/2022/05/GHSA-cgg7-545q-m5mf/GHSA-cgg7-545q-m5mf.json +++ b/advisories/unreviewed/2022/05/GHSA-cgg7-545q-m5mf/GHSA-cgg7-545q-m5mf.json @@ -7,12 +7,8 @@ "CVE-2009-3273" ], "details": "iPhone Mail in Apple iPhone OS, and iPhone OS for iPod touch, does not validate X.509 certificates, which allows man-in-the-middle attackers to spoof arbitrary SSL e-mail servers via a crafted certificate.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-ch49-j2xq-99mr/GHSA-ch49-j2xq-99mr.json b/advisories/unreviewed/2022/05/GHSA-ch49-j2xq-99mr/GHSA-ch49-j2xq-99mr.json index 5ed12818e9b..28b24ca18d4 100644 --- a/advisories/unreviewed/2022/05/GHSA-ch49-j2xq-99mr/GHSA-ch49-j2xq-99mr.json +++ b/advisories/unreviewed/2022/05/GHSA-ch49-j2xq-99mr/GHSA-ch49-j2xq-99mr.json @@ -7,12 +7,8 @@ "CVE-2009-3049" ], "details": "Opera before 10.00 does not properly display all characters in Internationalized Domain Names (IDN) in the address bar, which allows remote attackers to spoof URLs and conduct phishing attacks, related to Unicode and Punycode.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cjf3-jm6v-3h96/GHSA-cjf3-jm6v-3h96.json b/advisories/unreviewed/2022/05/GHSA-cjf3-jm6v-3h96/GHSA-cjf3-jm6v-3h96.json index ce208ba9b1f..709f7900d4c 100644 --- a/advisories/unreviewed/2022/05/GHSA-cjf3-jm6v-3h96/GHSA-cjf3-jm6v-3h96.json +++ b/advisories/unreviewed/2022/05/GHSA-cjf3-jm6v-3h96/GHSA-cjf3-jm6v-3h96.json @@ -7,12 +7,8 @@ "CVE-2009-3230" ], "details": "The core server component in PostgreSQL 8.4 before 8.4.1, 8.3 before 8.3.8, 8.2 before 8.2.14, 8.1 before 8.1.18, 8.0 before 8.0.22, and 7.4 before 7.4.26 does not use the appropriate privileges for the (1) RESET ROLE and (2) RESET SESSION AUTHORIZATION operations, which allows remote authenticated users to gain privileges. NOTE: this is due to an incomplete fix for CVE-2007-6600.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -108,9 +104,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cm35-rm5w-66gj/GHSA-cm35-rm5w-66gj.json b/advisories/unreviewed/2022/05/GHSA-cm35-rm5w-66gj/GHSA-cm35-rm5w-66gj.json index 14f9d778e44..c108bcd5ae8 100644 --- a/advisories/unreviewed/2022/05/GHSA-cm35-rm5w-66gj/GHSA-cm35-rm5w-66gj.json +++ b/advisories/unreviewed/2022/05/GHSA-cm35-rm5w-66gj/GHSA-cm35-rm5w-66gj.json @@ -7,12 +7,8 @@ "CVE-2009-2926" ], "details": "Multiple SQL injection vulnerabilities in PHP Competition System BETA 0.84 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) day parameter to show_matchs.php and (2) pageno parameter to persons.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cm69-ppm8-q566/GHSA-cm69-ppm8-q566.json b/advisories/unreviewed/2022/05/GHSA-cm69-ppm8-q566/GHSA-cm69-ppm8-q566.json index 22e26329d65..c7f7715dfa0 100644 --- a/advisories/unreviewed/2022/05/GHSA-cm69-ppm8-q566/GHSA-cm69-ppm8-q566.json +++ b/advisories/unreviewed/2022/05/GHSA-cm69-ppm8-q566/GHSA-cm69-ppm8-q566.json @@ -7,12 +7,8 @@ "CVE-2009-2508" ], "details": "The single sign-on implementation in Active Directory Federation Services (ADFS) in Microsoft Windows Server 2003 SP2 and Server 2008 Gold and SP2 does not properly remove credentials at the end of a network session, which allows physically proximate attackers to obtain the credentials of a previous user of the same web browser by using data from the browser's cache, aka \"Single Sign On Spoofing in ADFS Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cmrv-4pg3-2v25/GHSA-cmrv-4pg3-2v25.json b/advisories/unreviewed/2022/05/GHSA-cmrv-4pg3-2v25/GHSA-cmrv-4pg3-2v25.json index 16bf64d370c..fc294aad847 100644 --- a/advisories/unreviewed/2022/05/GHSA-cmrv-4pg3-2v25/GHSA-cmrv-4pg3-2v25.json +++ b/advisories/unreviewed/2022/05/GHSA-cmrv-4pg3-2v25/GHSA-cmrv-4pg3-2v25.json @@ -7,12 +7,8 @@ "CVE-2009-3166" ], "details": "token.cgi in Bugzilla 3.4rc1 through 3.4.1 places a password in a URL at the beginning of a login session that occurs immediately after a password reset, which allows context-dependent attackers to discover passwords by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cp6v-68qx-j42x/GHSA-cp6v-68qx-j42x.json b/advisories/unreviewed/2022/05/GHSA-cp6v-68qx-j42x/GHSA-cp6v-68qx-j42x.json index 5f061c0c355..f5957fa3799 100644 --- a/advisories/unreviewed/2022/05/GHSA-cp6v-68qx-j42x/GHSA-cp6v-68qx-j42x.json +++ b/advisories/unreviewed/2022/05/GHSA-cp6v-68qx-j42x/GHSA-cp6v-68qx-j42x.json @@ -7,12 +7,8 @@ "CVE-2009-3244" ], "details": "Heap-based buffer overflow in the SwDir.dll ActiveX control in Adobe Shockwave Player 11.5.1.601 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long PlayerVersion property value.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cp92-4h8q-cwwj/GHSA-cp92-4h8q-cwwj.json b/advisories/unreviewed/2022/05/GHSA-cp92-4h8q-cwwj/GHSA-cp92-4h8q-cwwj.json index 186027df9dc..3ea0d945a84 100644 --- a/advisories/unreviewed/2022/05/GHSA-cp92-4h8q-cwwj/GHSA-cp92-4h8q-cwwj.json +++ b/advisories/unreviewed/2022/05/GHSA-cp92-4h8q-cwwj/GHSA-cp92-4h8q-cwwj.json @@ -7,12 +7,8 @@ "CVE-2009-2856" ], "details": "Sun Virtual Desktop Infrastructure (VDI) 3.0, when anonymous binding is enabled, does not properly handle a client's attempt to establish an authenticated and encrypted connection, which might allow remote attackers to read cleartext VDI configuration-data requests by sniffing LDAP sessions on the network.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cr7h-x682-5qj5/GHSA-cr7h-x682-5qj5.json b/advisories/unreviewed/2022/05/GHSA-cr7h-x682-5qj5/GHSA-cr7h-x682-5qj5.json index c149579a9c3..eb2422fdb0b 100644 --- a/advisories/unreviewed/2022/05/GHSA-cr7h-x682-5qj5/GHSA-cr7h-x682-5qj5.json +++ b/advisories/unreviewed/2022/05/GHSA-cr7h-x682-5qj5/GHSA-cr7h-x682-5qj5.json @@ -7,12 +7,8 @@ "CVE-2009-2603" ], "details": "Multiple SQL injection vulnerabilities in index.php in Escon SupportPortal Pro 3.0 allow remote attackers to execute arbitrary SQL commands via the (1) cat and (2) tid parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cr8h-fpgg-m55q/GHSA-cr8h-fpgg-m55q.json b/advisories/unreviewed/2022/05/GHSA-cr8h-fpgg-m55q/GHSA-cr8h-fpgg-m55q.json index 5142cfabbf6..c4ed09b866b 100644 --- a/advisories/unreviewed/2022/05/GHSA-cr8h-fpgg-m55q/GHSA-cr8h-fpgg-m55q.json +++ b/advisories/unreviewed/2022/05/GHSA-cr8h-fpgg-m55q/GHSA-cr8h-fpgg-m55q.json @@ -7,12 +7,8 @@ "CVE-2009-2876" ], "details": "Heap-based buffer overflow in atas32.dll in the Cisco WebEx WRF Player 26.x before 26.49.32 (aka T26SP49EP32) for Windows, 27.x before 27.10.x (aka T27SP10) for Windows, 26.x before 26.49.35 for Mac OS X and Linux, and 27.x before 27.11.8 for Mac OS X and Linux allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a crafted WebEx Recording Format (WRF) file, a different vulnerability than CVE-2009-2878 and CVE-2009-2879.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cvj4-9f98-hhj7/GHSA-cvj4-9f98-hhj7.json b/advisories/unreviewed/2022/05/GHSA-cvj4-9f98-hhj7/GHSA-cvj4-9f98-hhj7.json index 7af913f7a62..6cd8ddbca05 100644 --- a/advisories/unreviewed/2022/05/GHSA-cvj4-9f98-hhj7/GHSA-cvj4-9f98-hhj7.json +++ b/advisories/unreviewed/2022/05/GHSA-cvj4-9f98-hhj7/GHSA-cvj4-9f98-hhj7.json @@ -7,12 +7,8 @@ "CVE-2009-2492" ], "details": "Cross-site scripting (XSS) vulnerability in mt-wizard.cgi in Six Apart Movable Type before 4.261 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2009-2480.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cx78-j9qw-j4q7/GHSA-cx78-j9qw-j4q7.json b/advisories/unreviewed/2022/05/GHSA-cx78-j9qw-j4q7/GHSA-cx78-j9qw-j4q7.json index 2e2eb90ddf5..a95a86244fb 100644 --- a/advisories/unreviewed/2022/05/GHSA-cx78-j9qw-j4q7/GHSA-cx78-j9qw-j4q7.json +++ b/advisories/unreviewed/2022/05/GHSA-cx78-j9qw-j4q7/GHSA-cx78-j9qw-j4q7.json @@ -7,12 +7,8 @@ "CVE-2009-2769" ], "details": "PHP remote file inclusion vulnerability in include/timesheet.php in Ultrize TimeSheet 1.2.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the config[include_dir] parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cxw5-vw86-jmmw/GHSA-cxw5-vw86-jmmw.json b/advisories/unreviewed/2022/05/GHSA-cxw5-vw86-jmmw/GHSA-cxw5-vw86-jmmw.json index e0136a8606f..f8e10d4c6c0 100644 --- a/advisories/unreviewed/2022/05/GHSA-cxw5-vw86-jmmw/GHSA-cxw5-vw86-jmmw.json +++ b/advisories/unreviewed/2022/05/GHSA-cxw5-vw86-jmmw/GHSA-cxw5-vw86-jmmw.json @@ -7,12 +7,8 @@ "CVE-2009-2488" ], "details": "Unspecified vulnerability in the NFSv4 module in the kernel in Sun Solaris 10, and OpenSolaris snv_102 through snv_119, allows local users to cause a denial of service (client panic) via vectors involving \"file operations.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f2wm-qqmc-637h/GHSA-f2wm-qqmc-637h.json b/advisories/unreviewed/2022/05/GHSA-f2wm-qqmc-637h/GHSA-f2wm-qqmc-637h.json index 665ffe9f789..b44471122e3 100644 --- a/advisories/unreviewed/2022/05/GHSA-f2wm-qqmc-637h/GHSA-f2wm-qqmc-637h.json +++ b/advisories/unreviewed/2022/05/GHSA-f2wm-qqmc-637h/GHSA-f2wm-qqmc-637h.json @@ -7,12 +7,8 @@ "CVE-2009-2574" ], "details": "index.php in MiniTwitter 0.2 beta allows remote authenticated users to modify certain options of arbitrary accounts via an opt action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f36r-j88j-6j27/GHSA-f36r-j88j-6j27.json b/advisories/unreviewed/2022/05/GHSA-f36r-j88j-6j27/GHSA-f36r-j88j-6j27.json index 35d7a3fee21..d5302fd1390 100644 --- a/advisories/unreviewed/2022/05/GHSA-f36r-j88j-6j27/GHSA-f36r-j88j-6j27.json +++ b/advisories/unreviewed/2022/05/GHSA-f36r-j88j-6j27/GHSA-f36r-j88j-6j27.json @@ -7,12 +7,8 @@ "CVE-2009-2629" ], "details": "Buffer underflow in src/http/ngx_http_parse.c in nginx 0.1.0 through 0.5.37, 0.6.x before 0.6.39, 0.7.x before 0.7.62, and 0.8.x before 0.8.15 allows remote attackers to execute arbitrary code via crafted HTTP requests.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f3mh-84r7-6579/GHSA-f3mh-84r7-6579.json b/advisories/unreviewed/2022/05/GHSA-f3mh-84r7-6579/GHSA-f3mh-84r7-6579.json index bb6b369f5db..b151f7c57cd 100644 --- a/advisories/unreviewed/2022/05/GHSA-f3mh-84r7-6579/GHSA-f3mh-84r7-6579.json +++ b/advisories/unreviewed/2022/05/GHSA-f3mh-84r7-6579/GHSA-f3mh-84r7-6579.json @@ -7,12 +7,8 @@ "CVE-2009-2476" ], "details": "The Java Management Extensions (JMX) implementation in Sun Java SE 6 before Update 15, and OpenJDK, does not properly enforce OpenType checks, which allows context-dependent attackers to bypass intended access restrictions by leveraging finalizer resurrection to obtain a reference to a privileged object.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -88,9 +84,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f4c6-vp9v-vmq4/GHSA-f4c6-vp9v-vmq4.json b/advisories/unreviewed/2022/05/GHSA-f4c6-vp9v-vmq4/GHSA-f4c6-vp9v-vmq4.json index 07a57f8898b..c2ed9ffae04 100644 --- a/advisories/unreviewed/2022/05/GHSA-f4c6-vp9v-vmq4/GHSA-f4c6-vp9v-vmq4.json +++ b/advisories/unreviewed/2022/05/GHSA-f4c6-vp9v-vmq4/GHSA-f4c6-vp9v-vmq4.json @@ -7,12 +7,8 @@ "CVE-2009-2796" ], "details": "The UIKit component in Apple iPhone OS 3.0, and iPhone OS 3.0.1 for iPod touch, allows physically proximate attackers to discover a password by watching a user undo deletions of characters in the password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f5g6-55mc-jx72/GHSA-f5g6-55mc-jx72.json b/advisories/unreviewed/2022/05/GHSA-f5g6-55mc-jx72/GHSA-f5g6-55mc-jx72.json index 6c198905f08..bd85f9f1fb2 100644 --- a/advisories/unreviewed/2022/05/GHSA-f5g6-55mc-jx72/GHSA-f5g6-55mc-jx72.json +++ b/advisories/unreviewed/2022/05/GHSA-f5g6-55mc-jx72/GHSA-f5g6-55mc-jx72.json @@ -7,12 +7,8 @@ "CVE-2009-2666" ], "details": "socket.c in fetchmail before 6.3.11 does not properly handle a '\\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -88,9 +84,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f672-qjcm-xx2f/GHSA-f672-qjcm-xx2f.json b/advisories/unreviewed/2022/05/GHSA-f672-qjcm-xx2f/GHSA-f672-qjcm-xx2f.json index 51e9d6058d5..6ccb394727c 100644 --- a/advisories/unreviewed/2022/05/GHSA-f672-qjcm-xx2f/GHSA-f672-qjcm-xx2f.json +++ b/advisories/unreviewed/2022/05/GHSA-f672-qjcm-xx2f/GHSA-f672-qjcm-xx2f.json @@ -7,12 +7,8 @@ "CVE-2009-2784" ], "details": "Multiple directory traversal vulnerabilities in dit.cms 1.3, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the path parameter to index.php in (1) install/, (2) menus/left_rightslideopen/, (3) menus/side_pullout/, (4) menus/side_slideopen/, (5) menus/simple/, (6) menus/top_dropdown/, and (7) menus/topside/; the sitemap parameter to index.php in (8) menus/left_rightslideopen/, (9) menus/side_pullout/, (10) menus/side_slideopen/, (11) menus/top_dropdown/, and (12) menus/topside/; and the (13) relPath parameter to index/index.php. NOTE: PHP remote file inclusion vulnerabilities reportedly also exist for some of these vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f6w4-jpgx-q8w2/GHSA-f6w4-jpgx-q8w2.json b/advisories/unreviewed/2022/05/GHSA-f6w4-jpgx-q8w2/GHSA-f6w4-jpgx-q8w2.json index 809a3bf2938..601ac9fbecb 100644 --- a/advisories/unreviewed/2022/05/GHSA-f6w4-jpgx-q8w2/GHSA-f6w4-jpgx-q8w2.json +++ b/advisories/unreviewed/2022/05/GHSA-f6w4-jpgx-q8w2/GHSA-f6w4-jpgx-q8w2.json @@ -7,12 +7,8 @@ "CVE-2009-2782" ], "details": "SQL injection vulnerability in the JFusion (com_jfusion) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f75p-9w69-p43r/GHSA-f75p-9w69-p43r.json b/advisories/unreviewed/2022/05/GHSA-f75p-9w69-p43r/GHSA-f75p-9w69-p43r.json index a0a2fbcdd44..480369c7991 100644 --- a/advisories/unreviewed/2022/05/GHSA-f75p-9w69-p43r/GHSA-f75p-9w69-p43r.json +++ b/advisories/unreviewed/2022/05/GHSA-f75p-9w69-p43r/GHSA-f75p-9w69-p43r.json @@ -7,12 +7,8 @@ "CVE-2009-2719" ], "details": "The Java Web Start implementation in Sun Java SE 6 before Update 15 allows context-dependent attackers to cause a denial of service (NullPointerException) via a crafted .jnlp file, as demonstrated by the jnlp_file/appletDesc/index.html#misc test in the Technology Compatibility Kit (TCK) for the Java Network Launching Protocol (JNLP).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f787-v5g2-7c4p/GHSA-f787-v5g2-7c4p.json b/advisories/unreviewed/2022/05/GHSA-f787-v5g2-7c4p/GHSA-f787-v5g2-7c4p.json index dd4e4a41508..d68a5acfe14 100644 --- a/advisories/unreviewed/2022/05/GHSA-f787-v5g2-7c4p/GHSA-f787-v5g2-7c4p.json +++ b/advisories/unreviewed/2022/05/GHSA-f787-v5g2-7c4p/GHSA-f787-v5g2-7c4p.json @@ -7,12 +7,8 @@ "CVE-2009-3004" ], "details": "Avant Browser 11.7 Builds 35 and 36 allows remote attackers to spoof the address bar, via window.open with a relative URI, to show an arbitrary URL on the web site visited by the victim, as demonstrated by a visit to an attacker-controlled web page, which triggers a spoofed login form for the site containing that page. NOTE: a related attack was reported in which an arbitrary file: URL is shown.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f78f-8m3f-69xh/GHSA-f78f-8m3f-69xh.json b/advisories/unreviewed/2022/05/GHSA-f78f-8m3f-69xh/GHSA-f78f-8m3f-69xh.json index b3d771edde6..fc7478cbf6a 100644 --- a/advisories/unreviewed/2022/05/GHSA-f78f-8m3f-69xh/GHSA-f78f-8m3f-69xh.json +++ b/advisories/unreviewed/2022/05/GHSA-f78f-8m3f-69xh/GHSA-f78f-8m3f-69xh.json @@ -7,12 +7,8 @@ "CVE-2009-2519" ], "details": "The DHTML Editing Component ActiveX control in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not properly format HTML markup, which allows remote attackers to execute arbitrary code via a crafted web site that triggers \"system state\" corruption, aka \"DHTML Editing Component ActiveX Control Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f78m-3xxg-82w8/GHSA-f78m-3xxg-82w8.json b/advisories/unreviewed/2022/05/GHSA-f78m-3xxg-82w8/GHSA-f78m-3xxg-82w8.json index 760985b30e2..298c0276455 100644 --- a/advisories/unreviewed/2022/05/GHSA-f78m-3xxg-82w8/GHSA-f78m-3xxg-82w8.json +++ b/advisories/unreviewed/2022/05/GHSA-f78m-3xxg-82w8/GHSA-f78m-3xxg-82w8.json @@ -7,12 +7,8 @@ "CVE-2009-2632" ], "details": "Buffer overflow in the SIEVE script component (sieve/script.c), as used in cyrus-imapd in Cyrus IMAP Server 2.2.13 and 2.3.14, and Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, allows local users to execute arbitrary code and read or modify arbitrary messages via a crafted SIEVE script, related to the incorrect use of the sizeof operator for determining buffer length, combined with an integer signedness error.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f7wx-r9cj-c65j/GHSA-f7wx-r9cj-c65j.json b/advisories/unreviewed/2022/05/GHSA-f7wx-r9cj-c65j/GHSA-f7wx-r9cj-c65j.json index 8cd507c107e..4ccf5286e3d 100644 --- a/advisories/unreviewed/2022/05/GHSA-f7wx-r9cj-c65j/GHSA-f7wx-r9cj-c65j.json +++ b/advisories/unreviewed/2022/05/GHSA-f7wx-r9cj-c65j/GHSA-f7wx-r9cj-c65j.json @@ -7,12 +7,8 @@ "CVE-2009-3175" ], "details": "Multiple SQL injection vulnerabilities in Model Agency Manager PRO (formerly Modeling Agency Content Management Script) allow remote attackers to execute arbitrary SQL commands via the user_id parameter to (1) view.php, (2) photos.php, and (3) motm.php; and the (4) id parameter to forum_message.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f8c8-v22w-8vv8/GHSA-f8c8-v22w-8vv8.json b/advisories/unreviewed/2022/05/GHSA-f8c8-v22w-8vv8/GHSA-f8c8-v22w-8vv8.json index b1a0e3d1319..78cca3b0233 100644 --- a/advisories/unreviewed/2022/05/GHSA-f8c8-v22w-8vv8/GHSA-f8c8-v22w-8vv8.json +++ b/advisories/unreviewed/2022/05/GHSA-f8c8-v22w-8vv8/GHSA-f8c8-v22w-8vv8.json @@ -7,12 +7,8 @@ "CVE-2009-2511" ], "details": "Integer overflow in the CryptoAPI component in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows man-in-the-middle attackers to spoof arbitrary SSL servers and other entities via an X.509 certificate that has a malformed ASN.1 Object Identifier (OID) and was issued by a legitimate Certification Authority, aka \"Integer Overflow in X.509 Object Identifiers Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fc7c-pw72-423g/GHSA-fc7c-pw72-423g.json b/advisories/unreviewed/2022/05/GHSA-fc7c-pw72-423g/GHSA-fc7c-pw72-423g.json index 74eb477b0ed..492538ec413 100644 --- a/advisories/unreviewed/2022/05/GHSA-fc7c-pw72-423g/GHSA-fc7c-pw72-423g.json +++ b/advisories/unreviewed/2022/05/GHSA-fc7c-pw72-423g/GHSA-fc7c-pw72-423g.json @@ -7,12 +7,8 @@ "CVE-2009-2974" ], "details": "Google Chrome 1.0.154.65, 1.0.154.48, and earlier allows remote attackers to (1) cause a denial of service (application hang) via vectors involving a chromehtml: URI value for the document.location property or (2) cause a denial of service (application hang and CPU consumption) via vectors involving a series of function calls that set a chromehtml: URI value for the document.location property.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fcvp-2grf-8j6r/GHSA-fcvp-2grf-8j6r.json b/advisories/unreviewed/2022/05/GHSA-fcvp-2grf-8j6r/GHSA-fcvp-2grf-8j6r.json index 1588c614e0c..8199ba7c1de 100644 --- a/advisories/unreviewed/2022/05/GHSA-fcvp-2grf-8j6r/GHSA-fcvp-2grf-8j6r.json +++ b/advisories/unreviewed/2022/05/GHSA-fcvp-2grf-8j6r/GHSA-fcvp-2grf-8j6r.json @@ -7,12 +7,8 @@ "CVE-2009-3069" ], "details": "Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.3 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-ff43-6vf9-7633/GHSA-ff43-6vf9-7633.json b/advisories/unreviewed/2022/05/GHSA-ff43-6vf9-7633/GHSA-ff43-6vf9-7633.json index f3f5850004c..4594b0f44ad 100644 --- a/advisories/unreviewed/2022/05/GHSA-ff43-6vf9-7633/GHSA-ff43-6vf9-7633.json +++ b/advisories/unreviewed/2022/05/GHSA-ff43-6vf9-7633/GHSA-ff43-6vf9-7633.json @@ -7,12 +7,8 @@ "CVE-2009-3068" ], "details": "Unrestricted file upload vulnerability in the RoboHelpServer Servlet (robohelp/server) in Adobe RoboHelp Server 8 allows remote attackers to execute arbitrary code by uploading a Java Archive (.jsp) file during a PUBLISH action, then accessing it via a direct request to the file in the robohelp/robo/reserved/web directory under its sessionid subdirectory, as demonstrated by the vd_adobe module in VulnDisco Pack Professional 8.7 through 8.11.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-ff8g-m3gr-6cff/GHSA-ff8g-m3gr-6cff.json b/advisories/unreviewed/2022/05/GHSA-ff8g-m3gr-6cff/GHSA-ff8g-m3gr-6cff.json index a6943139466..a5035a48e81 100644 --- a/advisories/unreviewed/2022/05/GHSA-ff8g-m3gr-6cff/GHSA-ff8g-m3gr-6cff.json +++ b/advisories/unreviewed/2022/05/GHSA-ff8g-m3gr-6cff/GHSA-ff8g-m3gr-6cff.json @@ -7,12 +7,8 @@ "CVE-2009-2965" ], "details": "Cross-site scripting (XSS) vulnerability in entry/index.jsp in Radvision Scopia 5.7, and possibly other versions before SD 7.0.100, allows remote attackers to inject arbitrary web script or HTML via the page parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ffp3-gcjc-rmv9/GHSA-ffp3-gcjc-rmv9.json b/advisories/unreviewed/2022/05/GHSA-ffp3-gcjc-rmv9/GHSA-ffp3-gcjc-rmv9.json index 2eca0d1c94a..e8660c77473 100644 --- a/advisories/unreviewed/2022/05/GHSA-ffp3-gcjc-rmv9/GHSA-ffp3-gcjc-rmv9.json +++ b/advisories/unreviewed/2022/05/GHSA-ffp3-gcjc-rmv9/GHSA-ffp3-gcjc-rmv9.json @@ -7,12 +7,8 @@ "CVE-2009-2712" ], "details": "Sun Java System Access Manager 6.3 2005Q1, 7.0 2005Q4, and 7.1; and OpenSSO Enterprise 8.0; when AMConfig.properties enables the debug flag, allows local users to discover cleartext passwords by reading debug files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fgx4-56q6-xxw8/GHSA-fgx4-56q6-xxw8.json b/advisories/unreviewed/2022/05/GHSA-fgx4-56q6-xxw8/GHSA-fgx4-56q6-xxw8.json index 8af2b5d59f5..ee60928c596 100644 --- a/advisories/unreviewed/2022/05/GHSA-fgx4-56q6-xxw8/GHSA-fgx4-56q6-xxw8.json +++ b/advisories/unreviewed/2022/05/GHSA-fgx4-56q6-xxw8/GHSA-fgx4-56q6-xxw8.json @@ -7,12 +7,8 @@ "CVE-2009-2905" ], "details": "Heap-based buffer overflow in textbox.c in newt 0.51.5, 0.51.6, and 0.52.2 allows local users to cause a denial of service (application crash) or possibly execute arbitrary code via a request to display a crafted text dialog box.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fj22-5g9h-44w5/GHSA-fj22-5g9h-44w5.json b/advisories/unreviewed/2022/05/GHSA-fj22-5g9h-44w5/GHSA-fj22-5g9h-44w5.json index 435a7cc1e6e..4059389a303 100644 --- a/advisories/unreviewed/2022/05/GHSA-fj22-5g9h-44w5/GHSA-fj22-5g9h-44w5.json +++ b/advisories/unreviewed/2022/05/GHSA-fj22-5g9h-44w5/GHSA-fj22-5g9h-44w5.json @@ -7,12 +7,8 @@ "CVE-2009-2672" ], "details": "The proxy mechanism implementation in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, does not prevent access to browser cookies by untrusted (1) applets and (2) Java Web Start applications, which allows remote attackers to hijack web sessions via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -144,9 +140,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fppw-cm5c-3hfp/GHSA-fppw-cm5c-3hfp.json b/advisories/unreviewed/2022/05/GHSA-fppw-cm5c-3hfp/GHSA-fppw-cm5c-3hfp.json index 06ae4946b43..4cf4a5ab470 100644 --- a/advisories/unreviewed/2022/05/GHSA-fppw-cm5c-3hfp/GHSA-fppw-cm5c-3hfp.json +++ b/advisories/unreviewed/2022/05/GHSA-fppw-cm5c-3hfp/GHSA-fppw-cm5c-3hfp.json @@ -7,12 +7,8 @@ "CVE-2009-2794" ], "details": "The Exchange Support component in Apple iPhone OS before 3.1, and iPhone OS before 3.1.1 for iPod touch, does not properly implement the \"Maximum inactivity time lock\" functionality, which allows local users to bypass intended Microsoft Exchange restrictions by choosing a large Require Passcode time value.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fq36-f3jg-qjrw/GHSA-fq36-f3jg-qjrw.json b/advisories/unreviewed/2022/05/GHSA-fq36-f3jg-qjrw/GHSA-fq36-f3jg-qjrw.json index 1b786965884..facb1dff9d8 100644 --- a/advisories/unreviewed/2022/05/GHSA-fq36-f3jg-qjrw/GHSA-fq36-f3jg-qjrw.json +++ b/advisories/unreviewed/2022/05/GHSA-fq36-f3jg-qjrw/GHSA-fq36-f3jg-qjrw.json @@ -7,12 +7,8 @@ "CVE-2009-3298" ], "details": "Mahara before 1.0.13, and 1.1.x before 1.1.7, allows remote authenticated institution administrators to reset a site administrator password via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fq54-rqwh-5q9h/GHSA-fq54-rqwh-5q9h.json b/advisories/unreviewed/2022/05/GHSA-fq54-rqwh-5q9h/GHSA-fq54-rqwh-5q9h.json index 2dd88855b25..dd4af5601f7 100644 --- a/advisories/unreviewed/2022/05/GHSA-fq54-rqwh-5q9h/GHSA-fq54-rqwh-5q9h.json +++ b/advisories/unreviewed/2022/05/GHSA-fq54-rqwh-5q9h/GHSA-fq54-rqwh-5q9h.json @@ -7,12 +7,8 @@ "CVE-2009-3031" ], "details": "Stack-based buffer overflow in the BrowseAndSaveFile method in the Altiris eXpress NS ConsoleUtilities ActiveX control 6.0.0.1846 in AeXNSConsoleUtilities.dll in Symantec Altiris Notification Server (NS) 6.0 before R12, Deployment Server 6.8 and 6.9 in Symantec Altiris Deployment Solution 6.9 SP3, and Symantec Management Platform (SMP) 7.0 before SP3 allows remote attackers to execute arbitrary code via a long string in the second argument.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fq5r-xr7f-93pp/GHSA-fq5r-xr7f-93pp.json b/advisories/unreviewed/2022/05/GHSA-fq5r-xr7f-93pp/GHSA-fq5r-xr7f-93pp.json index 023c21513f0..3feaab738e7 100644 --- a/advisories/unreviewed/2022/05/GHSA-fq5r-xr7f-93pp/GHSA-fq5r-xr7f-93pp.json +++ b/advisories/unreviewed/2022/05/GHSA-fq5r-xr7f-93pp/GHSA-fq5r-xr7f-93pp.json @@ -7,12 +7,8 @@ "CVE-2009-3260" ], "details": "Cross-site scripting (XSS) vulnerability in LiveStreet 0.2 allows remote attackers to inject arbitrary web script or HTML via the header of the topic in a comment.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-frq7-c9fm-p56v/GHSA-frq7-c9fm-p56v.json b/advisories/unreviewed/2022/05/GHSA-frq7-c9fm-p56v/GHSA-frq7-c9fm-p56v.json index 00d83abfa2e..362d350bdc0 100644 --- a/advisories/unreviewed/2022/05/GHSA-frq7-c9fm-p56v/GHSA-frq7-c9fm-p56v.json +++ b/advisories/unreviewed/2022/05/GHSA-frq7-c9fm-p56v/GHSA-frq7-c9fm-p56v.json @@ -7,12 +7,8 @@ "CVE-2009-2598" ], "details": "Multiple SQL injection vulnerabilities in Online Grades & Attendance 3.2.6 and earlier allow (1) remote attackers to execute arbitrary SQL commands via the key parameter in a resetpass action to index.php and (2) remote authenticated users to execute arbitrary SQL commands via the ADD parameter in a mailto action to parents/parents.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-frw8-crh2-gr2h/GHSA-frw8-crh2-gr2h.json b/advisories/unreviewed/2022/05/GHSA-frw8-crh2-gr2h/GHSA-frw8-crh2-gr2h.json index ea41b948c34..a2aa7db6b34 100644 --- a/advisories/unreviewed/2022/05/GHSA-frw8-crh2-gr2h/GHSA-frw8-crh2-gr2h.json +++ b/advisories/unreviewed/2022/05/GHSA-frw8-crh2-gr2h/GHSA-frw8-crh2-gr2h.json @@ -7,12 +7,8 @@ "CVE-2009-2840" ], "details": "Spotlight in Apple Mac OS X 10.5.8 does not properly handle temporary files, which allows local users to overwrite arbitrary files in the context of a different user's privileges via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-frx8-mqfc-pcm6/GHSA-frx8-mqfc-pcm6.json b/advisories/unreviewed/2022/05/GHSA-frx8-mqfc-pcm6/GHSA-frx8-mqfc-pcm6.json index ca3d60faa04..c8268b2cba9 100644 --- a/advisories/unreviewed/2022/05/GHSA-frx8-mqfc-pcm6/GHSA-frx8-mqfc-pcm6.json +++ b/advisories/unreviewed/2022/05/GHSA-frx8-mqfc-pcm6/GHSA-frx8-mqfc-pcm6.json @@ -7,12 +7,8 @@ "CVE-2009-3011" ], "details": "Google Chrome 1.0.154.48 and earlier, 2.0.172.28, 2.0.172.37, and 3.0.193.2 Beta does not properly block data: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header that contains JavaScript sequences in a data:text/html URI or (2) entering a data:text/html URI with JavaScript sequences when specifying the content of a Refresh header. NOTE: the JavaScript executes outside of the context of the HTTP site.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fx63-8q93-pfr5/GHSA-fx63-8q93-pfr5.json b/advisories/unreviewed/2022/05/GHSA-fx63-8q93-pfr5/GHSA-fx63-8q93-pfr5.json index a9a6fcb10af..42dd97b3572 100644 --- a/advisories/unreviewed/2022/05/GHSA-fx63-8q93-pfr5/GHSA-fx63-8q93-pfr5.json +++ b/advisories/unreviewed/2022/05/GHSA-fx63-8q93-pfr5/GHSA-fx63-8q93-pfr5.json @@ -7,12 +7,8 @@ "CVE-2009-2624" ], "details": "The huft_build function in inflate.c in gzip before 1.3.13 creates a hufts (aka huffman) table that is too small, which allows remote attackers to cause a denial of service (application crash or infinite loop) or possibly execute arbitrary code via a crafted archive. NOTE: this issue is caused by a CVE-2006-4334 regression.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fxc7-cgfx-xfrw/GHSA-fxc7-cgfx-xfrw.json b/advisories/unreviewed/2022/05/GHSA-fxc7-cgfx-xfrw/GHSA-fxc7-cgfx-xfrw.json index 16183a9bed4..15e4b5a489a 100644 --- a/advisories/unreviewed/2022/05/GHSA-fxc7-cgfx-xfrw/GHSA-fxc7-cgfx-xfrw.json +++ b/advisories/unreviewed/2022/05/GHSA-fxc7-cgfx-xfrw/GHSA-fxc7-cgfx-xfrw.json @@ -7,12 +7,8 @@ "CVE-2009-3054" ], "details": "SQL injection vulnerability in the Artetics.com Art Portal (com_artportal) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the portalid parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fxvj-wr6f-vvf9/GHSA-fxvj-wr6f-vvf9.json b/advisories/unreviewed/2022/05/GHSA-fxvj-wr6f-vvf9/GHSA-fxvj-wr6f-vvf9.json index 2805b4c30be..f43c260fecb 100644 --- a/advisories/unreviewed/2022/05/GHSA-fxvj-wr6f-vvf9/GHSA-fxvj-wr6f-vvf9.json +++ b/advisories/unreviewed/2022/05/GHSA-fxvj-wr6f-vvf9/GHSA-fxvj-wr6f-vvf9.json @@ -7,12 +7,8 @@ "CVE-2009-3008" ], "details": "K-Meleon 1.5.3 allows context-dependent attackers to spoof the address bar, via window.open with a relative URI, to show an arbitrary file: URL after a victim has visited any file: URL, as demonstrated by a visit to a file: document written by the attacker.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g3mg-m63j-55xf/GHSA-g3mg-m63j-55xf.json b/advisories/unreviewed/2022/05/GHSA-g3mg-m63j-55xf/GHSA-g3mg-m63j-55xf.json index be67327b21a..5a943a438a7 100644 --- a/advisories/unreviewed/2022/05/GHSA-g3mg-m63j-55xf/GHSA-g3mg-m63j-55xf.json +++ b/advisories/unreviewed/2022/05/GHSA-g3mg-m63j-55xf/GHSA-g3mg-m63j-55xf.json @@ -7,12 +7,8 @@ "CVE-2009-2621" ], "details": "Squid 3.0 through 3.0.STABLE16 and 3.1 through 3.1.0.11 does not properly enforce \"buffer limits and related bound checks,\" which allows remote attackers to cause a denial of service via (1) an incomplete request or (2) a request with a large header size, related to (a) HttpMsg.cc and (b) client_side.cc.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g463-6wfq-2jp4/GHSA-g463-6wfq-2jp4.json b/advisories/unreviewed/2022/05/GHSA-g463-6wfq-2jp4/GHSA-g463-6wfq-2jp4.json index 675e9dc7075..0976272ccaf 100644 --- a/advisories/unreviewed/2022/05/GHSA-g463-6wfq-2jp4/GHSA-g463-6wfq-2jp4.json +++ b/advisories/unreviewed/2022/05/GHSA-g463-6wfq-2jp4/GHSA-g463-6wfq-2jp4.json @@ -7,12 +7,8 @@ "CVE-2009-2727" ], "details": "Stack-based buffer overflow in the _tt_internal_realpath function in the ToolTalk library (libtt.a) in IBM AIX 5.2.0, 5.3.0, 5.3.7 through 5.3.10, and 6.1.0 through 6.1.3, when the rpc.ttdbserver daemon is enabled in /etc/inetd.conf, allows remote attackers to execute arbitrary code via a long XDR-encoded ASCII string to remote procedure 15.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g64q-cp29-92g8/GHSA-g64q-cp29-92g8.json b/advisories/unreviewed/2022/05/GHSA-g64q-cp29-92g8/GHSA-g64q-cp29-92g8.json index 887544854a2..bdc58a2a5da 100644 --- a/advisories/unreviewed/2022/05/GHSA-g64q-cp29-92g8/GHSA-g64q-cp29-92g8.json +++ b/advisories/unreviewed/2022/05/GHSA-g64q-cp29-92g8/GHSA-g64q-cp29-92g8.json @@ -7,12 +7,8 @@ "CVE-2009-2895" ], "details": "SQL injection vulnerability in rss.php in Ultimate Regnow Affiliate (URA) 3.0 allows remote attackers to execute arbitrary SQL commands via the cat parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g6cx-7h34-gvx4/GHSA-g6cx-7h34-gvx4.json b/advisories/unreviewed/2022/05/GHSA-g6cx-7h34-gvx4/GHSA-g6cx-7h34-gvx4.json index 076dfdf9c59..3ad76451ae3 100644 --- a/advisories/unreviewed/2022/05/GHSA-g6cx-7h34-gvx4/GHSA-g6cx-7h34-gvx4.json +++ b/advisories/unreviewed/2022/05/GHSA-g6cx-7h34-gvx4/GHSA-g6cx-7h34-gvx4.json @@ -7,12 +7,8 @@ "CVE-2009-2487" ], "details": "Use-after-free vulnerability in the frpr_icmp function in the ipfilter (aka IP Filter) subsystem in Sun Solaris 10, and OpenSolaris snv_45 through snv_110, allows remote attackers to cause a denial of service (panic) via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g93w-x36g-q7gg/GHSA-g93w-x36g-q7gg.json b/advisories/unreviewed/2022/05/GHSA-g93w-x36g-q7gg/GHSA-g93w-x36g-q7gg.json index 7b031c3358a..b0069a48bf7 100644 --- a/advisories/unreviewed/2022/05/GHSA-g93w-x36g-q7gg/GHSA-g93w-x36g-q7gg.json +++ b/advisories/unreviewed/2022/05/GHSA-g93w-x36g-q7gg/GHSA-g93w-x36g-q7gg.json @@ -7,12 +7,8 @@ "CVE-2009-2975" ], "details": "Mozilla Firefox 3.5.2 on Windows XP, in some situations possibly involving an incompletely configured protocol handler, does not properly implement setting the document.location property to a value specifying a protocol associated with an external application, which allows remote attackers to cause a denial of service (memory consumption) via vectors involving a series of function calls that set this property, as demonstrated by (1) the chromehtml: protocol and (2) the aim: protocol.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gchf-737v-546c/GHSA-gchf-737v-546c.json b/advisories/unreviewed/2022/05/GHSA-gchf-737v-546c/GHSA-gchf-737v-546c.json index 875e0ba2dc3..70a5c786fd3 100644 --- a/advisories/unreviewed/2022/05/GHSA-gchf-737v-546c/GHSA-gchf-737v-546c.json +++ b/advisories/unreviewed/2022/05/GHSA-gchf-737v-546c/GHSA-gchf-737v-546c.json @@ -7,12 +7,8 @@ "CVE-2009-3045" ], "details": "Opera before 10.00 trusts root X.509 certificates signed with the MD2 algorithm, which makes it easier for man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted server certificate.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gcq7-fw5c-5h74/GHSA-gcq7-fw5c-5h74.json b/advisories/unreviewed/2022/05/GHSA-gcq7-fw5c-5h74/GHSA-gcq7-fw5c-5h74.json index 5253d3aec89..69c159c9056 100644 --- a/advisories/unreviewed/2022/05/GHSA-gcq7-fw5c-5h74/GHSA-gcq7-fw5c-5h74.json +++ b/advisories/unreviewed/2022/05/GHSA-gcq7-fw5c-5h74/GHSA-gcq7-fw5c-5h74.json @@ -7,12 +7,8 @@ "CVE-2009-2961" ], "details": "Stack-based buffer overflow in Thaddy de Konng KOL Player 1.0 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long URL in a .MP3 playlist file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gcv4-v78m-cc85/GHSA-gcv4-v78m-cc85.json b/advisories/unreviewed/2022/05/GHSA-gcv4-v78m-cc85/GHSA-gcv4-v78m-cc85.json index 5add6b2efeb..ddfe4469405 100644 --- a/advisories/unreviewed/2022/05/GHSA-gcv4-v78m-cc85/GHSA-gcv4-v78m-cc85.json +++ b/advisories/unreviewed/2022/05/GHSA-gcv4-v78m-cc85/GHSA-gcv4-v78m-cc85.json @@ -7,12 +7,8 @@ "CVE-2009-3261" ], "details": "update/update_0.1.2_to_0.2.php in LiveStreet 0.2 does not require administrative authentication, which allows remote attackers to perform DROP TABLE operations via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gf4j-rqc4-f9q2/GHSA-gf4j-rqc4-f9q2.json b/advisories/unreviewed/2022/05/GHSA-gf4j-rqc4-f9q2/GHSA-gf4j-rqc4-f9q2.json index 2d20c339b96..3a3ea62a31c 100644 --- a/advisories/unreviewed/2022/05/GHSA-gf4j-rqc4-f9q2/GHSA-gf4j-rqc4-f9q2.json +++ b/advisories/unreviewed/2022/05/GHSA-gf4j-rqc4-f9q2/GHSA-gf4j-rqc4-f9q2.json @@ -7,12 +7,8 @@ "CVE-2009-2932" ], "details": "Cross-site scripting (XSS) vulnerability in uddiclient/process in the UDDI client in SAP NetWeaver Application Server (Java) 7.0 allows remote attackers to inject arbitrary web script or HTML via the TModel Key field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gfmg-656w-qp45/GHSA-gfmg-656w-qp45.json b/advisories/unreviewed/2022/05/GHSA-gfmg-656w-qp45/GHSA-gfmg-656w-qp45.json index 613d4dd84d6..45a2de52adc 100644 --- a/advisories/unreviewed/2022/05/GHSA-gfmg-656w-qp45/GHSA-gfmg-656w-qp45.json +++ b/advisories/unreviewed/2022/05/GHSA-gfmg-656w-qp45/GHSA-gfmg-656w-qp45.json @@ -7,12 +7,8 @@ "CVE-2009-2513" ], "details": "The Graphics Device Interface (GDI) in win32k.sys in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka \"Win32k Insufficient Data Validation Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gg6v-c4q4-582f/GHSA-gg6v-c4q4-582f.json b/advisories/unreviewed/2022/05/GHSA-gg6v-c4q4-582f/GHSA-gg6v-c4q4-582f.json index e08402d772f..d9d3c124f02 100644 --- a/advisories/unreviewed/2022/05/GHSA-gg6v-c4q4-582f/GHSA-gg6v-c4q4-582f.json +++ b/advisories/unreviewed/2022/05/GHSA-gg6v-c4q4-582f/GHSA-gg6v-c4q4-582f.json @@ -7,12 +7,8 @@ "CVE-2009-2694" ], "details": "The msn_slplink_process_msg function in libpurple/protocols/msn/slplink.c in libpurple, as used in Pidgin (formerly Gaim) before 2.5.9 and Adium 1.3.5 and earlier, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) by sending multiple crafted SLP (aka MSNSLP) messages to trigger an overwrite of an arbitrary memory location. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2009-1376.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -96,9 +92,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-ghm7-4qj5-mxj2/GHSA-ghm7-4qj5-mxj2.json b/advisories/unreviewed/2022/05/GHSA-ghm7-4qj5-mxj2/GHSA-ghm7-4qj5-mxj2.json index 03b5e4b553d..e2808e5dfae 100644 --- a/advisories/unreviewed/2022/05/GHSA-ghm7-4qj5-mxj2/GHSA-ghm7-4qj5-mxj2.json +++ b/advisories/unreviewed/2022/05/GHSA-ghm7-4qj5-mxj2/GHSA-ghm7-4qj5-mxj2.json @@ -7,12 +7,8 @@ "CVE-2009-2752" ], "details": "IBM WebSphere Commerce 7.0 does not properly encrypt data in a database, which makes it easier for local users to obtain sensitive information by defeating cryptographic protection mechanisms.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gjvv-qp9c-jcr8/GHSA-gjvv-qp9c-jcr8.json b/advisories/unreviewed/2022/05/GHSA-gjvv-qp9c-jcr8/GHSA-gjvv-qp9c-jcr8.json index 49c2893b275..6813d09136c 100644 --- a/advisories/unreviewed/2022/05/GHSA-gjvv-qp9c-jcr8/GHSA-gjvv-qp9c-jcr8.json +++ b/advisories/unreviewed/2022/05/GHSA-gjvv-qp9c-jcr8/GHSA-gjvv-qp9c-jcr8.json @@ -7,12 +7,8 @@ "CVE-2009-2687" ], "details": "The exif_read_data function in the Exif module in PHP before 5.2.10 allows remote attackers to cause a denial of service (crash) via a malformed JPEG image with invalid offset fields, a different issue than CVE-2005-3353.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gjw4-r34c-p2g9/GHSA-gjw4-r34c-p2g9.json b/advisories/unreviewed/2022/05/GHSA-gjw4-r34c-p2g9/GHSA-gjw4-r34c-p2g9.json index b05e464922b..0fea5a00deb 100644 --- a/advisories/unreviewed/2022/05/GHSA-gjw4-r34c-p2g9/GHSA-gjw4-r34c-p2g9.json +++ b/advisories/unreviewed/2022/05/GHSA-gjw4-r34c-p2g9/GHSA-gjw4-r34c-p2g9.json @@ -7,12 +7,8 @@ "CVE-2009-3053" ], "details": "Directory traversal vulnerability in the Agora (com_agora) component 3.0.0b for Joomla! allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the action parameter to the avatars page, reachable through index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gm6v-mq6p-p5fx/GHSA-gm6v-mq6p-p5fx.json b/advisories/unreviewed/2022/05/GHSA-gm6v-mq6p-p5fx/GHSA-gm6v-mq6p-p5fx.json index 717e404ce59..8fef851e7d2 100644 --- a/advisories/unreviewed/2022/05/GHSA-gm6v-mq6p-p5fx/GHSA-gm6v-mq6p-p5fx.json +++ b/advisories/unreviewed/2022/05/GHSA-gm6v-mq6p-p5fx/GHSA-gm6v-mq6p-p5fx.json @@ -7,12 +7,8 @@ "CVE-2009-2619" ], "details": "SQL injection vulnerability in login.asp in DataCheck Solutions V-SpacePal allows remote attackers to execute arbitrary SQL commands via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gp2v-rg23-2v69/GHSA-gp2v-rg23-2v69.json b/advisories/unreviewed/2022/05/GHSA-gp2v-rg23-2v69/GHSA-gp2v-rg23-2v69.json index a1de4f5f57e..bb6060e4786 100644 --- a/advisories/unreviewed/2022/05/GHSA-gp2v-rg23-2v69/GHSA-gp2v-rg23-2v69.json +++ b/advisories/unreviewed/2022/05/GHSA-gp2v-rg23-2v69/GHSA-gp2v-rg23-2v69.json @@ -7,12 +7,8 @@ "CVE-2009-3067" ], "details": "Cross-site scripting (XSS) vulnerability in index.php in Reservation Manager allows remote attackers to inject arbitrary web script or HTML via the resman_startdate parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gpxx-3842-mjw3/GHSA-gpxx-3842-mjw3.json b/advisories/unreviewed/2022/05/GHSA-gpxx-3842-mjw3/GHSA-gpxx-3842-mjw3.json index 8f5a02805d1..cf948e0c0a2 100644 --- a/advisories/unreviewed/2022/05/GHSA-gpxx-3842-mjw3/GHSA-gpxx-3842-mjw3.json +++ b/advisories/unreviewed/2022/05/GHSA-gpxx-3842-mjw3/GHSA-gpxx-3842-mjw3.json @@ -7,12 +7,8 @@ "CVE-2009-2853" ], "details": "Wordpress before 2.8.3 allows remote attackers to gain privileges via a direct request to (1) admin-footer.php, (2) edit-category-form.php, (3) edit-form-advanced.php, (4) edit-form-comment.php, (5) edit-link-category-form.php, (6) edit-link-form.php, (7) edit-page-form.php, and (8) edit-tag-form.php in wp-admin/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gq5x-hvxj-cp4r/GHSA-gq5x-hvxj-cp4r.json b/advisories/unreviewed/2022/05/GHSA-gq5x-hvxj-cp4r/GHSA-gq5x-hvxj-cp4r.json index b7a7ea19d0e..bf6dad98a2c 100644 --- a/advisories/unreviewed/2022/05/GHSA-gq5x-hvxj-cp4r/GHSA-gq5x-hvxj-cp4r.json +++ b/advisories/unreviewed/2022/05/GHSA-gq5x-hvxj-cp4r/GHSA-gq5x-hvxj-cp4r.json @@ -7,12 +7,8 @@ "CVE-2009-3238" ], "details": "The get_random_int function in drivers/char/random.c in the Linux kernel before 2.6.30 produces insufficiently random numbers, which allows attackers to predict the return value, and possibly defeat protection mechanisms based on randomization, via vectors that leverage the function's tendency to \"return the same value over and over again for long stretches of time.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -72,9 +68,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-grh9-678v-4762/GHSA-grh9-678v-4762.json b/advisories/unreviewed/2022/05/GHSA-grh9-678v-4762/GHSA-grh9-678v-4762.json index bc810bdb1ca..5dee58e1020 100644 --- a/advisories/unreviewed/2022/05/GHSA-grh9-678v-4762/GHSA-grh9-678v-4762.json +++ b/advisories/unreviewed/2022/05/GHSA-grh9-678v-4762/GHSA-grh9-678v-4762.json @@ -7,12 +7,8 @@ "CVE-2009-3241" ], "details": "Unspecified vulnerability in the OpcUa (OPC UA) dissector in Wireshark 0.99.6 through 1.0.8 and 1.2.0 through 1.2.1 allows remote attackers to cause a denial of service (memory and CPU consumption) via malformed OPCUA Service CallRequest packets.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gvm3-v4j9-4r52/GHSA-gvm3-v4j9-4r52.json b/advisories/unreviewed/2022/05/GHSA-gvm3-v4j9-4r52/GHSA-gvm3-v4j9-4r52.json index 9a7a8944f77..3cd1a7bff27 100644 --- a/advisories/unreviewed/2022/05/GHSA-gvm3-v4j9-4r52/GHSA-gvm3-v4j9-4r52.json +++ b/advisories/unreviewed/2022/05/GHSA-gvm3-v4j9-4r52/GHSA-gvm3-v4j9-4r52.json @@ -7,12 +7,8 @@ "CVE-2009-3058" ], "details": "Stack-based buffer overflow in akPlayer 1.9.0 allows remote attackers to execute arbitrary code via a long string in a .plt playlist file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gvqg-72g2-c5mx/GHSA-gvqg-72g2-c5mx.json b/advisories/unreviewed/2022/05/GHSA-gvqg-72g2-c5mx/GHSA-gvqg-72g2-c5mx.json index 2027d1bfcff..1efd4f0682e 100644 --- a/advisories/unreviewed/2022/05/GHSA-gvqg-72g2-c5mx/GHSA-gvqg-72g2-c5mx.json +++ b/advisories/unreviewed/2022/05/GHSA-gvqg-72g2-c5mx/GHSA-gvqg-72g2-c5mx.json @@ -7,12 +7,8 @@ "CVE-2009-2637" ], "details": "PHP remote file inclusion vulnerability in toolbar_ext.php in the BookLibrary (com_booklibrary) component 1.5.2.4 Basic for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gvqg-h6mh-r9j7/GHSA-gvqg-h6mh-r9j7.json b/advisories/unreviewed/2022/05/GHSA-gvqg-h6mh-r9j7/GHSA-gvqg-h6mh-r9j7.json index 5531c95f231..e85613dccb1 100644 --- a/advisories/unreviewed/2022/05/GHSA-gvqg-h6mh-r9j7/GHSA-gvqg-h6mh-r9j7.json +++ b/advisories/unreviewed/2022/05/GHSA-gvqg-h6mh-r9j7/GHSA-gvqg-h6mh-r9j7.json @@ -7,12 +7,8 @@ "CVE-2009-2930" ], "details": "Cross-site scripting (XSS) vulnerability in the Search feature in elka CMS (aka Elkapax) allows remote attackers to inject arbitrary web script or HTML via the q parameter to the default URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gwgv-rcrg-qfjm/GHSA-gwgv-rcrg-qfjm.json b/advisories/unreviewed/2022/05/GHSA-gwgv-rcrg-qfjm/GHSA-gwgv-rcrg-qfjm.json index 3a938d8efd6..fae56f7cc6d 100644 --- a/advisories/unreviewed/2022/05/GHSA-gwgv-rcrg-qfjm/GHSA-gwgv-rcrg-qfjm.json +++ b/advisories/unreviewed/2022/05/GHSA-gwgv-rcrg-qfjm/GHSA-gwgv-rcrg-qfjm.json @@ -7,12 +7,8 @@ "CVE-2009-2735" ], "details": "SQL injection vulnerability in admin.php in sun-jester OpenNews 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gx42-wp82-42x7/GHSA-gx42-wp82-42x7.json b/advisories/unreviewed/2022/05/GHSA-gx42-wp82-42x7/GHSA-gx42-wp82-42x7.json index cc393d01038..ce59794bbae 100644 --- a/advisories/unreviewed/2022/05/GHSA-gx42-wp82-42x7/GHSA-gx42-wp82-42x7.json +++ b/advisories/unreviewed/2022/05/GHSA-gx42-wp82-42x7/GHSA-gx42-wp82-42x7.json @@ -7,12 +7,8 @@ "CVE-2009-3231" ], "details": "The core server component in PostgreSQL 8.3 before 8.3.8 and 8.2 before 8.2.14, when using LDAP authentication with anonymous binds, allows remote attackers to bypass authentication via an empty password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gxcf-x722-p7ch/GHSA-gxcf-x722-p7ch.json b/advisories/unreviewed/2022/05/GHSA-gxcf-x722-p7ch/GHSA-gxcf-x722-p7ch.json index 10ed67e9fa4..0c24b96cc6d 100644 --- a/advisories/unreviewed/2022/05/GHSA-gxcf-x722-p7ch/GHSA-gxcf-x722-p7ch.json +++ b/advisories/unreviewed/2022/05/GHSA-gxcf-x722-p7ch/GHSA-gxcf-x722-p7ch.json @@ -7,12 +7,8 @@ "CVE-2009-2781" ], "details": "SQL injection vulnerability in forum.php in Arab Portal 2.x, when magic_quotes_gpc is disabled, allows remote authenticated users to execute arbitrary SQL commands via the qc parameter in an addcomment action, a different vector than CVE-2006-1666.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gxf5-wh5r-8mfp/GHSA-gxf5-wh5r-8mfp.json b/advisories/unreviewed/2022/05/GHSA-gxf5-wh5r-8mfp/GHSA-gxf5-wh5r-8mfp.json index 1a9393b48c2..cb124d5f696 100644 --- a/advisories/unreviewed/2022/05/GHSA-gxf5-wh5r-8mfp/GHSA-gxf5-wh5r-8mfp.json +++ b/advisories/unreviewed/2022/05/GHSA-gxf5-wh5r-8mfp/GHSA-gxf5-wh5r-8mfp.json @@ -7,12 +7,8 @@ "CVE-2009-3176" ], "details": "Buffer overflow in the ActiveX control in Novell iPrint Client 4.38 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown attack vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.1, \"Novell iPrint Client 4.38 ActiveX exploit.\" NOTE: as of 20090909, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gxpr-j99r-h2rq/GHSA-gxpr-j99r-h2rq.json b/advisories/unreviewed/2022/05/GHSA-gxpr-j99r-h2rq/GHSA-gxpr-j99r-h2rq.json index aa1118b24b2..98a94ca72db 100644 --- a/advisories/unreviewed/2022/05/GHSA-gxpr-j99r-h2rq/GHSA-gxpr-j99r-h2rq.json +++ b/advisories/unreviewed/2022/05/GHSA-gxpr-j99r-h2rq/GHSA-gxpr-j99r-h2rq.json @@ -7,12 +7,8 @@ "CVE-2009-2788" ], "details": "Multiple SQL injection vulnerabilities in Mobilelib GOLD 3 allow remote attackers to execute arbitrary SQL commands via the (1) adminName parameter to cp/auth.php, (2) cid parameter to artcat.php, and (3) catid parameter to show.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h2f6-3wpm-87wp/GHSA-h2f6-3wpm-87wp.json b/advisories/unreviewed/2022/05/GHSA-h2f6-3wpm-87wp/GHSA-h2f6-3wpm-87wp.json index 1d4730e5946..fd1b9d7e514 100644 --- a/advisories/unreviewed/2022/05/GHSA-h2f6-3wpm-87wp/GHSA-h2f6-3wpm-87wp.json +++ b/advisories/unreviewed/2022/05/GHSA-h2f6-3wpm-87wp/GHSA-h2f6-3wpm-87wp.json @@ -7,12 +7,8 @@ "CVE-2009-2677" ], "details": "Cross-site request forgery (CSRF) vulnerability in HP Insight Control Suite For Linux (aka ICE-LX) before 2.11 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h3h4-v8x5-4h4j/GHSA-h3h4-v8x5-4h4j.json b/advisories/unreviewed/2022/05/GHSA-h3h4-v8x5-4h4j/GHSA-h3h4-v8x5-4h4j.json index 13357ba695d..4f70c283601 100644 --- a/advisories/unreviewed/2022/05/GHSA-h3h4-v8x5-4h4j/GHSA-h3h4-v8x5-4h4j.json +++ b/advisories/unreviewed/2022/05/GHSA-h3h4-v8x5-4h4j/GHSA-h3h4-v8x5-4h4j.json @@ -7,12 +7,8 @@ "CVE-2009-2732" ], "details": "The checkHTTPpassword function in http.c in ntop 3.3.10 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an Authorization HTTP header that lacks a : (colon) character in the base64-decoded string.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h44c-f6p3-hp74/GHSA-h44c-f6p3-hp74.json b/advisories/unreviewed/2022/05/GHSA-h44c-f6p3-hp74/GHSA-h44c-f6p3-hp74.json index 3d90c896384..43af245e45f 100644 --- a/advisories/unreviewed/2022/05/GHSA-h44c-f6p3-hp74/GHSA-h44c-f6p3-hp74.json +++ b/advisories/unreviewed/2022/05/GHSA-h44c-f6p3-hp74/GHSA-h44c-f6p3-hp74.json @@ -7,12 +7,8 @@ "CVE-2009-2601" ], "details": "SQL injection vulnerability in the Joomlaequipment (aka JUser or com_juser) component 2.0.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a show_profile action to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h4gg-hxcg-84h7/GHSA-h4gg-hxcg-84h7.json b/advisories/unreviewed/2022/05/GHSA-h4gg-hxcg-84h7/GHSA-h4gg-hxcg-84h7.json index c164cc3bc42..455906f3e9b 100644 --- a/advisories/unreviewed/2022/05/GHSA-h4gg-hxcg-84h7/GHSA-h4gg-hxcg-84h7.json +++ b/advisories/unreviewed/2022/05/GHSA-h4gg-hxcg-84h7/GHSA-h4gg-hxcg-84h7.json @@ -7,12 +7,8 @@ "CVE-2009-2918" ], "details": "The tgbvpn.sys driver in TheGreenBow IPSec VPN Client 4.61.003 allows local users to cause a denial of service (NULL pointer dereference and system crash) via a crafted request to the 0x80000034 IOCTL, probably involving an input or output buffer size of 0.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h6cm-xhvp-x8jm/GHSA-h6cm-xhvp-x8jm.json b/advisories/unreviewed/2022/05/GHSA-h6cm-xhvp-x8jm/GHSA-h6cm-xhvp-x8jm.json index b69abfeaa5b..3011f95b40f 100644 --- a/advisories/unreviewed/2022/05/GHSA-h6cm-xhvp-x8jm/GHSA-h6cm-xhvp-x8jm.json +++ b/advisories/unreviewed/2022/05/GHSA-h6cm-xhvp-x8jm/GHSA-h6cm-xhvp-x8jm.json @@ -7,12 +7,8 @@ "CVE-2009-2844" ], "details": "cfg80211 in net/wireless/scan.c in the Linux kernel 2.6.30-rc1 and other versions before 2.6.31-rc6 allows remote attackers to cause a denial of service (crash) via a sequence of beacon frames in which one frame omits an SSID Information Element (IE) and the subsequent frame contains an SSID IE, which triggers a NULL pointer dereference in the cmp_ies function. NOTE: a potential weakness in the is_mesh function was also addressed, but the relevant condition did not exist in the code, so it is not a vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h7qr-2r4v-9236/GHSA-h7qr-2r4v-9236.json b/advisories/unreviewed/2022/05/GHSA-h7qr-2r4v-9236/GHSA-h7qr-2r4v-9236.json index 790a3eddf15..280fcf4a1f8 100644 --- a/advisories/unreviewed/2022/05/GHSA-h7qr-2r4v-9236/GHSA-h7qr-2r4v-9236.json +++ b/advisories/unreviewed/2022/05/GHSA-h7qr-2r4v-9236/GHSA-h7qr-2r4v-9236.json @@ -7,12 +7,8 @@ "CVE-2009-2954" ], "details": "Microsoft Internet Explorer 6.0.2900.2180 and earlier allows remote attackers to cause a denial of service (CPU consumption and application hang) via JavaScript code with a long string value for the hash property (aka location.hash), a related issue to CVE-2008-5715.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hc23-8qcx-6f4p/GHSA-hc23-8qcx-6f4p.json b/advisories/unreviewed/2022/05/GHSA-hc23-8qcx-6f4p/GHSA-hc23-8qcx-6f4p.json index 8e167a80148..acb838de1d1 100644 --- a/advisories/unreviewed/2022/05/GHSA-hc23-8qcx-6f4p/GHSA-hc23-8qcx-6f4p.json +++ b/advisories/unreviewed/2022/05/GHSA-hc23-8qcx-6f4p/GHSA-hc23-8qcx-6f4p.json @@ -7,12 +7,8 @@ "CVE-2009-2587" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in DragDropCart allow remote attackers to inject arbitrary web script or HTML via the (1) sid parameter to assets/js/ddcart.php, the (2) prefix parameter to includes/ajax/getstate.php, the search parameter to (3) index.php and (4) search.php, the (5) redirect parameter to login.php, and the (6) product parameter to productdetail.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hcc5-4c4w-p9qg/GHSA-hcc5-4c4w-p9qg.json b/advisories/unreviewed/2022/05/GHSA-hcc5-4c4w-p9qg/GHSA-hcc5-4c4w-p9qg.json index ce4e2fe23f5..16a3f7816ee 100644 --- a/advisories/unreviewed/2022/05/GHSA-hcc5-4c4w-p9qg/GHSA-hcc5-4c4w-p9qg.json +++ b/advisories/unreviewed/2022/05/GHSA-hcc5-4c4w-p9qg/GHSA-hcc5-4c4w-p9qg.json @@ -7,12 +7,8 @@ "CVE-2009-2658" ], "details": "Directory traversal vulnerability in ZNC before 0.072 allows remote attackers to overwrite arbitrary files via a crafted DCC SEND request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hcmh-25x8-w958/GHSA-hcmh-25x8-w958.json b/advisories/unreviewed/2022/05/GHSA-hcmh-25x8-w958/GHSA-hcmh-25x8-w958.json index e282fb6ad1d..0aa2d6076c2 100644 --- a/advisories/unreviewed/2022/05/GHSA-hcmh-25x8-w958/GHSA-hcmh-25x8-w958.json +++ b/advisories/unreviewed/2022/05/GHSA-hcmh-25x8-w958/GHSA-hcmh-25x8-w958.json @@ -7,12 +7,8 @@ "CVE-2009-2537" ], "details": "KDE Konqueror allows remote attackers to cause a denial of service (memory consumption) via a large integer value for the length property of a Select object, a related issue to CVE-2009-1692.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -76,9 +72,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hcx3-pcj4-c39m/GHSA-hcx3-pcj4-c39m.json b/advisories/unreviewed/2022/05/GHSA-hcx3-pcj4-c39m/GHSA-hcx3-pcj4-c39m.json index 0a4c339cca9..6f05a232f02 100644 --- a/advisories/unreviewed/2022/05/GHSA-hcx3-pcj4-c39m/GHSA-hcx3-pcj4-c39m.json +++ b/advisories/unreviewed/2022/05/GHSA-hcx3-pcj4-c39m/GHSA-hcx3-pcj4-c39m.json @@ -7,12 +7,8 @@ "CVE-2009-2615" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in DataCheck Solutions SitePal 1.x allow remote attackers to inject arbitrary web script or HTML via the page parameter to (1) z_admin_login.asp, (2) z_forgot.asp, and possibly unspecified other components. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hf63-h777-fqg6/GHSA-hf63-h777-fqg6.json b/advisories/unreviewed/2022/05/GHSA-hf63-h777-fqg6/GHSA-hf63-h777-fqg6.json index 7c131c207da..d0bd726d2f5 100644 --- a/advisories/unreviewed/2022/05/GHSA-hf63-h777-fqg6/GHSA-hf63-h777-fqg6.json +++ b/advisories/unreviewed/2022/05/GHSA-hf63-h777-fqg6/GHSA-hf63-h777-fqg6.json @@ -7,12 +7,8 @@ "CVE-2009-2873" ], "details": "Cisco IOS 12.0 through 12.4, when IP-based tunnels and the Cisco Express Forwarding feature are enabled, allows remote attackers to cause a denial of service (device reload) via malformed packets, aka Bug ID CSCsx70889.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hhvf-c3gg-qc9m/GHSA-hhvf-c3gg-qc9m.json b/advisories/unreviewed/2022/05/GHSA-hhvf-c3gg-qc9m/GHSA-hhvf-c3gg-qc9m.json index 63b9300fd80..ad1dce0cd62 100644 --- a/advisories/unreviewed/2022/05/GHSA-hhvf-c3gg-qc9m/GHSA-hhvf-c3gg-qc9m.json +++ b/advisories/unreviewed/2022/05/GHSA-hhvf-c3gg-qc9m/GHSA-hhvf-c3gg-qc9m.json @@ -7,12 +7,8 @@ "CVE-2009-3061" ], "details": "SQL injection vulnerability in lesson.php in Alqatari Q R Script 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hjmg-8jw6-qj7r/GHSA-hjmg-8jw6-qj7r.json b/advisories/unreviewed/2022/05/GHSA-hjmg-8jw6-qj7r/GHSA-hjmg-8jw6-qj7r.json index 45d0f86f375..0c8b4799c03 100644 --- a/advisories/unreviewed/2022/05/GHSA-hjmg-8jw6-qj7r/GHSA-hjmg-8jw6-qj7r.json +++ b/advisories/unreviewed/2022/05/GHSA-hjmg-8jw6-qj7r/GHSA-hjmg-8jw6-qj7r.json @@ -7,12 +7,8 @@ "CVE-2009-3157" ], "details": "Cross-site scripting (XSS) vulnerability in the Calendar module 6.x before 6.x-2.2 for Drupal allows remote authenticated users, with \"create new content types\" privileges, to inject arbitrary web script or HTML via the title of a content type.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hjq4-8wh4-grxv/GHSA-hjq4-8wh4-grxv.json b/advisories/unreviewed/2022/05/GHSA-hjq4-8wh4-grxv/GHSA-hjq4-8wh4-grxv.json index 2fc2a07c94e..8ecd610c117 100644 --- a/advisories/unreviewed/2022/05/GHSA-hjq4-8wh4-grxv/GHSA-hjq4-8wh4-grxv.json +++ b/advisories/unreviewed/2022/05/GHSA-hjq4-8wh4-grxv/GHSA-hjq4-8wh4-grxv.json @@ -7,12 +7,8 @@ "CVE-2009-2650" ], "details": "Heap-based buffer overflow in Sorcerer Software MultiMedia Jukebox 4.0 Build 020124 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted (1) .m3u or possibly (2) .pst file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hpjc-pfpw-w77x/GHSA-hpjc-pfpw-w77x.json b/advisories/unreviewed/2022/05/GHSA-hpjc-pfpw-w77x/GHSA-hpjc-pfpw-w77x.json index 91db0ab2259..4e5e09574d6 100644 --- a/advisories/unreviewed/2022/05/GHSA-hpjc-pfpw-w77x/GHSA-hpjc-pfpw-w77x.json +++ b/advisories/unreviewed/2022/05/GHSA-hpjc-pfpw-w77x/GHSA-hpjc-pfpw-w77x.json @@ -7,12 +7,8 @@ "CVE-2009-3090" ], "details": "Unspecified vulnerability in IBM Tivoli Directory Server (TDS) 6.0 on Linux allows remote attackers to cause a denial of service via unknown vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.11. NOTE: as of 20090903, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hqqf-rvh9-623q/GHSA-hqqf-rvh9-623q.json b/advisories/unreviewed/2022/05/GHSA-hqqf-rvh9-623q/GHSA-hqqf-rvh9-623q.json index 053fce90306..212dc1b37da 100644 --- a/advisories/unreviewed/2022/05/GHSA-hqqf-rvh9-623q/GHSA-hqqf-rvh9-623q.json +++ b/advisories/unreviewed/2022/05/GHSA-hqqf-rvh9-623q/GHSA-hqqf-rvh9-623q.json @@ -7,12 +7,8 @@ "CVE-2009-3057" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in AOM Software Beex 3 allow remote attackers to inject arbitrary web script or HTML via the navaction parameter to (1) news.php and (2) partneralle.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hr3q-997w-pw4x/GHSA-hr3q-997w-pw4x.json b/advisories/unreviewed/2022/05/GHSA-hr3q-997w-pw4x/GHSA-hr3q-997w-pw4x.json index f8827cfb023..ad6ef9083f6 100644 --- a/advisories/unreviewed/2022/05/GHSA-hr3q-997w-pw4x/GHSA-hr3q-997w-pw4x.json +++ b/advisories/unreviewed/2022/05/GHSA-hr3q-997w-pw4x/GHSA-hr3q-997w-pw4x.json @@ -7,12 +7,8 @@ "CVE-2009-3013" ], "details": "Opera 9.52 and earlier, and 10.00 Beta 3 Build 1699, does not properly block data: URIs in Location headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Location header that contains JavaScript sequences in a data:text/html URI or (2) entering a data:text/html URI with JavaScript sequences when specifying the content of a Location header. NOTE: the JavaScript executes outside of the context of the HTTP site.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hvm6-88j5-7vcm/GHSA-hvm6-88j5-7vcm.json b/advisories/unreviewed/2022/05/GHSA-hvm6-88j5-7vcm/GHSA-hvm6-88j5-7vcm.json index 2d59dff91de..56d5cb01633 100644 --- a/advisories/unreviewed/2022/05/GHSA-hvm6-88j5-7vcm/GHSA-hvm6-88j5-7vcm.json +++ b/advisories/unreviewed/2022/05/GHSA-hvm6-88j5-7vcm/GHSA-hvm6-88j5-7vcm.json @@ -7,12 +7,8 @@ "CVE-2009-2584" ], "details": "Off-by-one error in the options_write function in drivers/misc/sgi-gru/gruprocfs.c in the SGI GRU driver in the Linux kernel 2.6.30.2 and earlier on ia64 and x86 platforms might allow local users to overwrite arbitrary memory locations and gain privileges via a crafted count argument, which triggers a stack-based buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hx9x-3jpr-5g63/GHSA-hx9x-3jpr-5g63.json b/advisories/unreviewed/2022/05/GHSA-hx9x-3jpr-5g63/GHSA-hx9x-3jpr-5g63.json index 78d6610ba28..c6cfed0d1f0 100644 --- a/advisories/unreviewed/2022/05/GHSA-hx9x-3jpr-5g63/GHSA-hx9x-3jpr-5g63.json +++ b/advisories/unreviewed/2022/05/GHSA-hx9x-3jpr-5g63/GHSA-hx9x-3jpr-5g63.json @@ -7,12 +7,8 @@ "CVE-2009-3070" ], "details": "Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.14 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -76,9 +72,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j22q-m838-5xhc/GHSA-j22q-m838-5xhc.json b/advisories/unreviewed/2022/05/GHSA-j22q-m838-5xhc/GHSA-j22q-m838-5xhc.json index 4845e63c14d..99a1fafbdc9 100644 --- a/advisories/unreviewed/2022/05/GHSA-j22q-m838-5xhc/GHSA-j22q-m838-5xhc.json +++ b/advisories/unreviewed/2022/05/GHSA-j22q-m838-5xhc/GHSA-j22q-m838-5xhc.json @@ -7,12 +7,8 @@ "CVE-2009-2797" ], "details": "The WebKit component in Safari in Apple iPhone OS before 3.1, and iPhone OS before 3.1.1 for iPod touch, does not remove usernames and passwords from URLs sent in Referer headers, which allows remote attackers to obtain sensitive information by reading Referer logs on a web server.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j278-j9c7-cwvf/GHSA-j278-j9c7-cwvf.json b/advisories/unreviewed/2022/05/GHSA-j278-j9c7-cwvf/GHSA-j278-j9c7-cwvf.json index f67212046b1..26f7eda60cd 100644 --- a/advisories/unreviewed/2022/05/GHSA-j278-j9c7-cwvf/GHSA-j278-j9c7-cwvf.json +++ b/advisories/unreviewed/2022/05/GHSA-j278-j9c7-cwvf/GHSA-j278-j9c7-cwvf.json @@ -7,12 +7,8 @@ "CVE-2009-3088" ], "details": "Heap-based buffer overflow in ibmdiradm in IBM Tivoli Directory Server (TDS) 6.0 on Linux allows remote attackers to have an unspecified impact via unknown vectors that trigger heap corruption, as demonstrated by a certain module in VulnDisco Pack Professional 8.11. NOTE: as of 20090903, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j2jw-vxpm-g78j/GHSA-j2jw-vxpm-g78j.json b/advisories/unreviewed/2022/05/GHSA-j2jw-vxpm-g78j/GHSA-j2jw-vxpm-g78j.json index 8f4cef0b7ad..47764a17f45 100644 --- a/advisories/unreviewed/2022/05/GHSA-j2jw-vxpm-g78j/GHSA-j2jw-vxpm-g78j.json +++ b/advisories/unreviewed/2022/05/GHSA-j2jw-vxpm-g78j/GHSA-j2jw-vxpm-g78j.json @@ -7,12 +7,8 @@ "CVE-2009-2518" ], "details": "Integer overflow in GDI+ in Microsoft Office XP SP3 allows remote attackers to execute arbitrary code via an Office document with a bitmap (aka BMP) image that triggers memory corruption, aka \"Office BMP Integer Overflow Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j36j-5rq8-vg5c/GHSA-j36j-5rq8-vg5c.json b/advisories/unreviewed/2022/05/GHSA-j36j-5rq8-vg5c/GHSA-j36j-5rq8-vg5c.json index f0bc7047b42..54a02dce6eb 100644 --- a/advisories/unreviewed/2022/05/GHSA-j36j-5rq8-vg5c/GHSA-j36j-5rq8-vg5c.json +++ b/advisories/unreviewed/2022/05/GHSA-j36j-5rq8-vg5c/GHSA-j36j-5rq8-vg5c.json @@ -7,12 +7,8 @@ "CVE-2009-3308" ], "details": "SQL injection vulnerability in show-cat.php in FanUpdate 2.2.1 allows remote attackers to execute arbitrary SQL commands via the listingid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j484-x726-7wg8/GHSA-j484-x726-7wg8.json b/advisories/unreviewed/2022/05/GHSA-j484-x726-7wg8/GHSA-j484-x726-7wg8.json index 2f648b073e1..a331d8b9649 100644 --- a/advisories/unreviewed/2022/05/GHSA-j484-x726-7wg8/GHSA-j484-x726-7wg8.json +++ b/advisories/unreviewed/2022/05/GHSA-j484-x726-7wg8/GHSA-j484-x726-7wg8.json @@ -7,12 +7,8 @@ "CVE-2009-2801" ], "details": "The Application Firewall in Apple Mac OS X 10.5.8 drops unspecified firewall rules after a reboot, which might allow remote attackers to bypass intended access restrictions via packet data, related to a \"timing issue.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j4wg-r9jw-hw3j/GHSA-j4wg-r9jw-hw3j.json b/advisories/unreviewed/2022/05/GHSA-j4wg-r9jw-hw3j/GHSA-j4wg-r9jw-hw3j.json index b28fecbac29..20b5d428f56 100644 --- a/advisories/unreviewed/2022/05/GHSA-j4wg-r9jw-hw3j/GHSA-j4wg-r9jw-hw3j.json +++ b/advisories/unreviewed/2022/05/GHSA-j4wg-r9jw-hw3j/GHSA-j4wg-r9jw-hw3j.json @@ -7,12 +7,8 @@ "CVE-2009-2642" ], "details": "index.php in Desi Short URL Script 1.0 allows remote attackers to bypass authentication by setting the logged cookie to 1 and the uid cookie to an integer value, as demonstrated by a value of 13.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j5mh-66x5-7vpc/GHSA-j5mh-66x5-7vpc.json b/advisories/unreviewed/2022/05/GHSA-j5mh-66x5-7vpc/GHSA-j5mh-66x5-7vpc.json index dd33293adef..00a748ae575 100644 --- a/advisories/unreviewed/2022/05/GHSA-j5mh-66x5-7vpc/GHSA-j5mh-66x5-7vpc.json +++ b/advisories/unreviewed/2022/05/GHSA-j5mh-66x5-7vpc/GHSA-j5mh-66x5-7vpc.json @@ -7,12 +7,8 @@ "CVE-2009-2886" ], "details": "SQL injection vulnerability in bios.php in PHP Scripts Now President Bios allows remote attackers to execute arbitrary SQL commands via the rank parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j5v5-fpm8-w528/GHSA-j5v5-fpm8-w528.json b/advisories/unreviewed/2022/05/GHSA-j5v5-fpm8-w528/GHSA-j5v5-fpm8-w528.json index b6d688236e7..ab5942e0a91 100644 --- a/advisories/unreviewed/2022/05/GHSA-j5v5-fpm8-w528/GHSA-j5v5-fpm8-w528.json +++ b/advisories/unreviewed/2022/05/GHSA-j5v5-fpm8-w528/GHSA-j5v5-fpm8-w528.json @@ -7,12 +7,8 @@ "CVE-2009-2878" ], "details": "Heap-based buffer overflow in atas32.dll in the Cisco WebEx WRF Player 26.x before 26.49.32 (aka T26SP49EP32) for Windows, 27.x before 27.10.x (aka T27SP10) for Windows, 26.x before 26.49.35 for Mac OS X and Linux, and 27.x before 27.11.8 for Mac OS X and Linux allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a crafted WebEx Recording Format (WRF) file, a different vulnerability than CVE-2009-2876 and CVE-2009-2879.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j64g-84vg-pq34/GHSA-j64g-84vg-pq34.json b/advisories/unreviewed/2022/05/GHSA-j64g-84vg-pq34/GHSA-j64g-84vg-pq34.json index ffd3573813a..05a56b7e41e 100644 --- a/advisories/unreviewed/2022/05/GHSA-j64g-84vg-pq34/GHSA-j64g-84vg-pq34.json +++ b/advisories/unreviewed/2022/05/GHSA-j64g-84vg-pq34/GHSA-j64g-84vg-pq34.json @@ -7,12 +7,8 @@ "CVE-2009-2829" ], "details": "Event Monitor in Apple Mac OS X 10.5.8 does not properly handle crafted authentication data sent to an SSH daemon, which allows remote attackers to cause a denial of service via vectors involving processing of XML log documents by other services, related to a \"log injection\" issue.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j6rr-99wm-q9wm/GHSA-j6rr-99wm-q9wm.json b/advisories/unreviewed/2022/05/GHSA-j6rr-99wm-q9wm/GHSA-j6rr-99wm-q9wm.json index 7386c3495ab..9d44d8301ef 100644 --- a/advisories/unreviewed/2022/05/GHSA-j6rr-99wm-q9wm/GHSA-j6rr-99wm-q9wm.json +++ b/advisories/unreviewed/2022/05/GHSA-j6rr-99wm-q9wm/GHSA-j6rr-99wm-q9wm.json @@ -7,12 +7,8 @@ "CVE-2009-3043" ], "details": "The tty_ldisc_hangup function in drivers/char/tty_ldisc.c in the Linux kernel 2.6.31-rc before 2.6.31-rc8 allows local users to cause a denial of service (system crash, sometimes preceded by a NULL pointer dereference) or possibly gain privileges via certain pseudo-terminal I/O activity, as demonstrated by KernelTtyTest.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j73r-w9hq-h7h7/GHSA-j73r-w9hq-h7h7.json b/advisories/unreviewed/2022/05/GHSA-j73r-w9hq-h7h7/GHSA-j73r-w9hq-h7h7.json index 52934aa769e..14aa5b31009 100644 --- a/advisories/unreviewed/2022/05/GHSA-j73r-w9hq-h7h7/GHSA-j73r-w9hq-h7h7.json +++ b/advisories/unreviewed/2022/05/GHSA-j73r-w9hq-h7h7/GHSA-j73r-w9hq-h7h7.json @@ -7,12 +7,8 @@ "CVE-2009-2981" ], "details": "Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 do not properly validate input, which might allow attackers to bypass intended Trust Manager restrictions via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j7ff-hmc8-4xc8/GHSA-j7ff-hmc8-4xc8.json b/advisories/unreviewed/2022/05/GHSA-j7ff-hmc8-4xc8/GHSA-j7ff-hmc8-4xc8.json index 9ac23e15c68..2dc5664b1e5 100644 --- a/advisories/unreviewed/2022/05/GHSA-j7ff-hmc8-4xc8/GHSA-j7ff-hmc8-4xc8.json +++ b/advisories/unreviewed/2022/05/GHSA-j7ff-hmc8-4xc8/GHSA-j7ff-hmc8-4xc8.json @@ -7,12 +7,8 @@ "CVE-2009-2767" ], "details": "The init_posix_timers function in kernel/posix-timers.c in the Linux kernel before 2.6.31-rc6 allows local users to cause a denial of service (OOPS) or possibly gain privileges via a CLOCK_MONOTONIC_RAW clock_nanosleep call that triggers a NULL pointer dereference.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j7rw-94xq-mrc3/GHSA-j7rw-94xq-mrc3.json b/advisories/unreviewed/2022/05/GHSA-j7rw-94xq-mrc3/GHSA-j7rw-94xq-mrc3.json index 0832f9f467f..67d328bb863 100644 --- a/advisories/unreviewed/2022/05/GHSA-j7rw-94xq-mrc3/GHSA-j7rw-94xq-mrc3.json +++ b/advisories/unreviewed/2022/05/GHSA-j7rw-94xq-mrc3/GHSA-j7rw-94xq-mrc3.json @@ -7,12 +7,8 @@ "CVE-2009-2979" ], "details": "Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 do not properly perform XMP-XML entity expansion, which allows remote attackers to cause a denial of service via a crafted document.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j8v8-w66x-xw2w/GHSA-j8v8-w66x-xw2w.json b/advisories/unreviewed/2022/05/GHSA-j8v8-w66x-xw2w/GHSA-j8v8-w66x-xw2w.json index 35560bcfa40..78007ab025f 100644 --- a/advisories/unreviewed/2022/05/GHSA-j8v8-w66x-xw2w/GHSA-j8v8-w66x-xw2w.json +++ b/advisories/unreviewed/2022/05/GHSA-j8v8-w66x-xw2w/GHSA-j8v8-w66x-xw2w.json @@ -7,12 +7,8 @@ "CVE-2009-3229" ], "details": "The core server component in PostgreSQL 8.4 before 8.4.1, 8.3 before 8.3.8, and 8.2 before 8.2.14 allows remote authenticated users to cause a denial of service (backend shutdown) by \"re-LOAD-ing\" libraries from a certain plugins directory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -92,9 +88,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j964-5hxf-3v7r/GHSA-j964-5hxf-3v7r.json b/advisories/unreviewed/2022/05/GHSA-j964-5hxf-3v7r/GHSA-j964-5hxf-3v7r.json index 800500566e3..d86e8ff4d6b 100644 --- a/advisories/unreviewed/2022/05/GHSA-j964-5hxf-3v7r/GHSA-j964-5hxf-3v7r.json +++ b/advisories/unreviewed/2022/05/GHSA-j964-5hxf-3v7r/GHSA-j964-5hxf-3v7r.json @@ -7,12 +7,8 @@ "CVE-2009-2810" ], "details": "Launch Services in Apple Mac OS X 10.6.x before 10.6.2 recursively clears quarantine information upon opening a quarantined folder, which allows user-assisted remote attackers to execute arbitrary code via a quarantined application that does not trigger a \"potentially unsafe\" warning message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jc49-c4w8-g43h/GHSA-jc49-c4w8-g43h.json b/advisories/unreviewed/2022/05/GHSA-jc49-c4w8-g43h/GHSA-jc49-c4w8-g43h.json index 3c00112591e..1b02beac476 100644 --- a/advisories/unreviewed/2022/05/GHSA-jc49-c4w8-g43h/GHSA-jc49-c4w8-g43h.json +++ b/advisories/unreviewed/2022/05/GHSA-jc49-c4w8-g43h/GHSA-jc49-c4w8-g43h.json @@ -7,12 +7,8 @@ "CVE-2009-2766" ], "details": "httpd.c in httpd in the management GUI in DD-WRT 24 sp1 does not require administrative authentication for programs under cgi-bin/, which allows remote attackers to change settings via HTTP requests.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jc5p-6484-2396/GHSA-jc5p-6484-2396.json b/advisories/unreviewed/2022/05/GHSA-jc5p-6484-2396/GHSA-jc5p-6484-2396.json index f26f5313614..3321313a38d 100644 --- a/advisories/unreviewed/2022/05/GHSA-jc5p-6484-2396/GHSA-jc5p-6484-2396.json +++ b/advisories/unreviewed/2022/05/GHSA-jc5p-6484-2396/GHSA-jc5p-6484-2396.json @@ -7,12 +7,8 @@ "CVE-2009-2950" ], "details": "Heap-based buffer overflow in the GIFLZWDecompressor::GIFLZWDecompressor function in filter.vcl/lgif/decode.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted GIF file, related to LZW decompression.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jfc5-x82h-wvpp/GHSA-jfc5-x82h-wvpp.json b/advisories/unreviewed/2022/05/GHSA-jfc5-x82h-wvpp/GHSA-jfc5-x82h-wvpp.json index f39bd06d38b..b881927bd6b 100644 --- a/advisories/unreviewed/2022/05/GHSA-jfc5-x82h-wvpp/GHSA-jfc5-x82h-wvpp.json +++ b/advisories/unreviewed/2022/05/GHSA-jfc5-x82h-wvpp/GHSA-jfc5-x82h-wvpp.json @@ -7,12 +7,8 @@ "CVE-2009-3016" ], "details": "Apple Safari 4.0.3 does not properly block javascript: and data: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header that contains a javascript: URI, (2) entering a javascript: URI when specifying the content of a Refresh header, (3) injecting a Refresh header that contains JavaScript sequences in a data:text/html URI, or (4) entering a data:text/html URI with JavaScript sequences when specifying the content of a Refresh header.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jh8r-4ff3-92j9/GHSA-jh8r-4ff3-92j9.json b/advisories/unreviewed/2022/05/GHSA-jh8r-4ff3-92j9/GHSA-jh8r-4ff3-92j9.json index 68543421e39..8050c4f4ca6 100644 --- a/advisories/unreviewed/2022/05/GHSA-jh8r-4ff3-92j9/GHSA-jh8r-4ff3-92j9.json +++ b/advisories/unreviewed/2022/05/GHSA-jh8r-4ff3-92j9/GHSA-jh8r-4ff3-92j9.json @@ -7,12 +7,8 @@ "CVE-2009-2695" ], "details": "The Linux kernel before 2.6.31-rc7 does not properly prevent mmap operations that target page zero and other low memory addresses, which allows local users to gain privileges by exploiting NULL pointer dereference vulnerabilities, related to (1) the default configuration of the allow_unconfined_mmap_low boolean in SELinux on Red Hat Enterprise Linux (RHEL) 5, (2) an error that causes allow_unconfined_mmap_low to be ignored in the unconfined_t domain, (3) lack of a requirement for the CAP_SYS_RAWIO capability for these mmap operations, and (4) interaction between the mmap_min_addr protection mechanism and certain application programs.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jj6p-27w9-hh6m/GHSA-jj6p-27w9-hh6m.json b/advisories/unreviewed/2022/05/GHSA-jj6p-27w9-hh6m/GHSA-jj6p-27w9-hh6m.json index ceb27cef786..a9f7a63afea 100644 --- a/advisories/unreviewed/2022/05/GHSA-jj6p-27w9-hh6m/GHSA-jj6p-27w9-hh6m.json +++ b/advisories/unreviewed/2022/05/GHSA-jj6p-27w9-hh6m/GHSA-jj6p-27w9-hh6m.json @@ -7,12 +7,8 @@ "CVE-2009-2964" ], "details": "Multiple cross-site request forgery (CSRF) vulnerabilities in SquirrelMail 1.4.19 and earlier, and NaSMail before 1.7, allow remote attackers to hijack the authentication of unspecified victims via features such as send message and change preferences, related to (1) functions/mailbox_display.php, (2) src/addrbook_search_html.php, (3) src/addressbook.php, (4) src/compose.php, (5) src/folders.php, (6) src/folders_create.php, (7) src/folders_delete.php, (8) src/folders_rename_do.php, (9) src/folders_rename_getname.php, (10) src/folders_subscribe.php, (11) src/move_messages.php, (12) src/options.php, (13) src/options_highlight.php, (14) src/options_identities.php, (15) src/options_order.php, (16) src/search.php, and (17) src/vcard.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jjfc-23rr-g872/GHSA-jjfc-23rr-g872.json b/advisories/unreviewed/2022/05/GHSA-jjfc-23rr-g872/GHSA-jjfc-23rr-g872.json index 76304439847..8c341259b1d 100644 --- a/advisories/unreviewed/2022/05/GHSA-jjfc-23rr-g872/GHSA-jjfc-23rr-g872.json +++ b/advisories/unreviewed/2022/05/GHSA-jjfc-23rr-g872/GHSA-jjfc-23rr-g872.json @@ -7,12 +7,8 @@ "CVE-2009-3041" ], "details": "SPIP 1.9 before 1.9.2i and 2.0.x through 2.0.8 does not use proper access control for (1) ecrire/exec/install.php and (2) ecrire/index.php, which allows remote attackers to conduct unauthorized activities related to installation and backups, as exploited in the wild in August 2009.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jm2r-hj8x-f5qq/GHSA-jm2r-hj8x-f5qq.json b/advisories/unreviewed/2022/05/GHSA-jm2r-hj8x-f5qq/GHSA-jm2r-hj8x-f5qq.json index 0699a82fbdb..803baa497b2 100644 --- a/advisories/unreviewed/2022/05/GHSA-jm2r-hj8x-f5qq/GHSA-jm2r-hj8x-f5qq.json +++ b/advisories/unreviewed/2022/05/GHSA-jm2r-hj8x-f5qq/GHSA-jm2r-hj8x-f5qq.json @@ -7,12 +7,8 @@ "CVE-2009-3063" ], "details": "SQL injection vulnerability in the Game Server (com_gameserver) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a gamepanel action to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jqc4-44qp-7w9w/GHSA-jqc4-44qp-7w9w.json b/advisories/unreviewed/2022/05/GHSA-jqc4-44qp-7w9w/GHSA-jqc4-44qp-7w9w.json index 497b6e424c2..e7e0a976735 100644 --- a/advisories/unreviewed/2022/05/GHSA-jqc4-44qp-7w9w/GHSA-jqc4-44qp-7w9w.json +++ b/advisories/unreviewed/2022/05/GHSA-jqc4-44qp-7w9w/GHSA-jqc4-44qp-7w9w.json @@ -7,12 +7,8 @@ "CVE-2009-2651" ], "details": "main/rtp.c in Asterisk Open Source 1.6.1 before 1.6.1.2 allows remote attackers to cause a denial of service (crash) via an RTP text frame without a certain delimiter, which triggers a NULL pointer dereference and the subsequent calculation of an invalid pointer.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jqmj-qqmc-wfgw/GHSA-jqmj-qqmc-wfgw.json b/advisories/unreviewed/2022/05/GHSA-jqmj-qqmc-wfgw/GHSA-jqmj-qqmc-wfgw.json index db01368697b..345b555fbac 100644 --- a/advisories/unreviewed/2022/05/GHSA-jqmj-qqmc-wfgw/GHSA-jqmj-qqmc-wfgw.json +++ b/advisories/unreviewed/2022/05/GHSA-jqmj-qqmc-wfgw/GHSA-jqmj-qqmc-wfgw.json @@ -7,12 +7,8 @@ "CVE-2009-3173" ], "details": "Unrestricted file upload vulnerability in admin/add_album.php in The Rat CMS Alpha 2 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in images/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jv67-6q9j-gjmg/GHSA-jv67-6q9j-gjmg.json b/advisories/unreviewed/2022/05/GHSA-jv67-6q9j-gjmg/GHSA-jv67-6q9j-gjmg.json index f6ea6963d43..59dd0fd039a 100644 --- a/advisories/unreviewed/2022/05/GHSA-jv67-6q9j-gjmg/GHSA-jv67-6q9j-gjmg.json +++ b/advisories/unreviewed/2022/05/GHSA-jv67-6q9j-gjmg/GHSA-jv67-6q9j-gjmg.json @@ -7,12 +7,8 @@ "CVE-2009-2862" ], "details": "The Object Groups for Access Control Lists (ACLs) feature in Cisco IOS 12.2XNB, 12.2XNC, 12.2XND, 12.4MD, 12.4T, 12.4XZ, and 12.4YA allows remote attackers to bypass intended access restrictions via crafted requests, aka Bug IDs CSCsx07114, CSCsu70214, CSCsw47076, CSCsv48603, CSCsy54122, and CSCsu50252.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jv6f-9247-pc9g/GHSA-jv6f-9247-pc9g.json b/advisories/unreviewed/2022/05/GHSA-jv6f-9247-pc9g/GHSA-jv6f-9247-pc9g.json index 68247571621..1a74211f8a3 100644 --- a/advisories/unreviewed/2022/05/GHSA-jv6f-9247-pc9g/GHSA-jv6f-9247-pc9g.json +++ b/advisories/unreviewed/2022/05/GHSA-jv6f-9247-pc9g/GHSA-jv6f-9247-pc9g.json @@ -7,12 +7,8 @@ "CVE-2009-2717" ], "details": "The Abstract Window Toolkit (AWT) implementation in Sun Java SE 6 before Update 15 on Windows 2000 Professional does not provide a Security Warning Icon, which makes it easier for context-dependent attackers to trick a user into interacting unsafely with an untrusted applet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jv6v-hc3c-59cq/GHSA-jv6v-hc3c-59cq.json b/advisories/unreviewed/2022/05/GHSA-jv6v-hc3c-59cq/GHSA-jv6v-hc3c-59cq.json index 4f5881901f5..3cce5c9f46a 100644 --- a/advisories/unreviewed/2022/05/GHSA-jv6v-hc3c-59cq/GHSA-jv6v-hc3c-59cq.json +++ b/advisories/unreviewed/2022/05/GHSA-jv6v-hc3c-59cq/GHSA-jv6v-hc3c-59cq.json @@ -7,12 +7,8 @@ "CVE-2009-1528" ], "details": "Microsoft Internet Explorer 6 and 7 for Windows XP SP2 and SP3; 6 and 7 for Server 2003 SP2; 7 for Vista Gold, SP1, and SP2; and 7 for Server 2008 SP2 does not properly synchronize AJAX requests, which allows allows remote attackers to execute arbitrary code via a large number of concurrent, asynchronous XMLHttpRequest calls, aka \"HTML Object Memory Corruption Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jv8p-9p3v-3h2p/GHSA-jv8p-9p3v-3h2p.json b/advisories/unreviewed/2022/05/GHSA-jv8p-9p3v-3h2p/GHSA-jv8p-9p3v-3h2p.json index 08cac7b64f4..6228cbe15b1 100644 --- a/advisories/unreviewed/2022/05/GHSA-jv8p-9p3v-3h2p/GHSA-jv8p-9p3v-3h2p.json +++ b/advisories/unreviewed/2022/05/GHSA-jv8p-9p3v-3h2p/GHSA-jv8p-9p3v-3h2p.json @@ -7,12 +7,8 @@ "CVE-2009-2676" ], "details": "Unspecified vulnerability in JNLPAppletlauncher in Sun Java SE, and SE for Business, in JDK and JRE 6 Update 14 and earlier and JDK and JRE 5.0 Update 19 and earlier; and Java SE for Business in SDK and JRE 1.4.2_21 and earlier; allows remote attackers to create or modify arbitrary files via vectors involving an untrusted Java applet that accesses an old version of JNLPAppletLauncher.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -112,9 +108,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jv96-g6m6-p7xw/GHSA-jv96-g6m6-p7xw.json b/advisories/unreviewed/2022/05/GHSA-jv96-g6m6-p7xw/GHSA-jv96-g6m6-p7xw.json index 720447ed8de..a86f5a6b216 100644 --- a/advisories/unreviewed/2022/05/GHSA-jv96-g6m6-p7xw/GHSA-jv96-g6m6-p7xw.json +++ b/advisories/unreviewed/2022/05/GHSA-jv96-g6m6-p7xw/GHSA-jv96-g6m6-p7xw.json @@ -7,12 +7,8 @@ "CVE-2009-2491" ], "details": "The utaudiod daemon in Sun Ray Server Software (SRSS) 4.0, when Solaris Trusted Extensions is enabled, allows local users to access the sessions of arbitrary users via unknown vectors related to \"resource leaks.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jvhf-p5j4-xwrc/GHSA-jvhf-p5j4-xwrc.json b/advisories/unreviewed/2022/05/GHSA-jvhf-p5j4-xwrc/GHSA-jvhf-p5j4-xwrc.json index 4da35a9ed71..a4467da0991 100644 --- a/advisories/unreviewed/2022/05/GHSA-jvhf-p5j4-xwrc/GHSA-jvhf-p5j4-xwrc.json +++ b/advisories/unreviewed/2022/05/GHSA-jvhf-p5j4-xwrc/GHSA-jvhf-p5j4-xwrc.json @@ -7,12 +7,8 @@ "CVE-2009-2865" ], "details": "Buffer overflow in the login implementation in the Extension Mobility feature in the Unified Communications Manager Express (CME) component in Cisco IOS 12.4XW, 12.4XY, 12.4XZ, and 12.4YA allows remote attackers to execute arbitrary code or cause a denial of service via crafted HTTP requests, aka Bug ID CSCsq58779.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jvhh-4rp5-cfmm/GHSA-jvhh-4rp5-cfmm.json b/advisories/unreviewed/2022/05/GHSA-jvhh-4rp5-cfmm/GHSA-jvhh-4rp5-cfmm.json index c5021a8108c..11ecdfcbb93 100644 --- a/advisories/unreviewed/2022/05/GHSA-jvhh-4rp5-cfmm/GHSA-jvhh-4rp5-cfmm.json +++ b/advisories/unreviewed/2022/05/GHSA-jvhh-4rp5-cfmm/GHSA-jvhh-4rp5-cfmm.json @@ -7,12 +7,8 @@ "CVE-2009-2631" ], "details": "Multiple clientless SSL VPN products that run in web browsers, including Stonesoft StoneGate; Cisco ASA; SonicWALL E-Class SSL VPN and SonicWALL SSL VPN; SafeNet SecureWire Access Gateway; Juniper Networks Secure Access; Nortel CallPilot; Citrix Access Gateway; and other products, when running in configurations that do not restrict access to the same domain as the VPN, retrieve the content of remote URLs from one domain and rewrite them so they originate from the VPN's domain, which violates the same origin policy and allows remote attackers to conduct cross-site scripting attacks, read cookies that originated from other domains, access the Web VPN session to gain access to internal resources, perform key logging, and conduct other attacks. NOTE: it could be argued that this is a fundamental design problem in any clientless VPN solution, as opposed to a commonly-introduced error that can be fixed in separate implementations. Therefore a single CVE has been assigned for all products that have this design.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -112,9 +108,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jvqf-xjc3-2chj/GHSA-jvqf-xjc3-2chj.json b/advisories/unreviewed/2022/05/GHSA-jvqf-xjc3-2chj/GHSA-jvqf-xjc3-2chj.json index 2ff9944b8aa..003f045bf86 100644 --- a/advisories/unreviewed/2022/05/GHSA-jvqf-xjc3-2chj/GHSA-jvqf-xjc3-2chj.json +++ b/advisories/unreviewed/2022/05/GHSA-jvqf-xjc3-2chj/GHSA-jvqf-xjc3-2chj.json @@ -7,12 +7,8 @@ "CVE-2009-2875" ], "details": "Buffer overflow in atas32.dll in the Cisco WebEx WRF Player 26.x before 26.49.32 for Windows, 27.x before 27.10.x for Windows, 26.x before 26.49.35 for Mac OS X and Linux, and 27.x before 27.11.8 for Mac OS X and Linux allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted WebEx Recording Format (WRF) file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jvwc-xf39-g9w4/GHSA-jvwc-xf39-g9w4.json b/advisories/unreviewed/2022/05/GHSA-jvwc-xf39-g9w4/GHSA-jvwc-xf39-g9w4.json index 588e7d47a9f..ce4df0de780 100644 --- a/advisories/unreviewed/2022/05/GHSA-jvwc-xf39-g9w4/GHSA-jvwc-xf39-g9w4.json +++ b/advisories/unreviewed/2022/05/GHSA-jvwc-xf39-g9w4/GHSA-jvwc-xf39-g9w4.json @@ -7,12 +7,8 @@ "CVE-2009-2688" ], "details": "Multiple integer overflows in glyphs-eimage.c in XEmacs 21.4.22, when running on Windows, allow remote attackers to cause a denial of service (crash) or execute arbitrary code via (1) the tiff_instantiate function processing a crafted TIFF file, (2) the png_instantiate function processing a crafted PNG file, and (3) the jpeg_instantiate function processing a crafted JPEG file, all which trigger a heap-based buffer overflow. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jw96-m7hf-43gx/GHSA-jw96-m7hf-43gx.json b/advisories/unreviewed/2022/05/GHSA-jw96-m7hf-43gx/GHSA-jw96-m7hf-43gx.json index eecd9bc5909..d57a5721f60 100644 --- a/advisories/unreviewed/2022/05/GHSA-jw96-m7hf-43gx/GHSA-jw96-m7hf-43gx.json +++ b/advisories/unreviewed/2022/05/GHSA-jw96-m7hf-43gx/GHSA-jw96-m7hf-43gx.json @@ -7,12 +7,8 @@ "CVE-2009-2720" ], "details": "Unspecified vulnerability in the javax.swing.plaf.synth.SynthContext.isSubregion method in the Swing implementation in Sun Java SE 6 before Update 15 allows context-dependent attackers to cause a denial of service (NullPointerException in the Jemmy library) via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jwgc-gq99-q68c/GHSA-jwgc-gq99-q68c.json b/advisories/unreviewed/2022/05/GHSA-jwgc-gq99-q68c/GHSA-jwgc-gq99-q68c.json index ace3c394e2b..7541fcedefc 100644 --- a/advisories/unreviewed/2022/05/GHSA-jwgc-gq99-q68c/GHSA-jwgc-gq99-q68c.json +++ b/advisories/unreviewed/2022/05/GHSA-jwgc-gq99-q68c/GHSA-jwgc-gq99-q68c.json @@ -7,12 +7,8 @@ "CVE-2009-2831" ], "details": "Dictionary in Apple Mac OS X 10.5.8 allows remote attackers to create arbitrary files with any contents, and thereby execute arbitrary code, via crafted JavaScript, related to a \"design issue.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jwpx-7cc6-qwj2/GHSA-jwpx-7cc6-qwj2.json b/advisories/unreviewed/2022/05/GHSA-jwpx-7cc6-qwj2/GHSA-jwpx-7cc6-qwj2.json index 6c178b7c71c..563dfeacb4d 100644 --- a/advisories/unreviewed/2022/05/GHSA-jwpx-7cc6-qwj2/GHSA-jwpx-7cc6-qwj2.json +++ b/advisories/unreviewed/2022/05/GHSA-jwpx-7cc6-qwj2/GHSA-jwpx-7cc6-qwj2.json @@ -7,12 +7,8 @@ "CVE-2009-2591" ], "details": "SQL injection vulnerability in the MyAnnonces module for E-Xoopport 3.1 allows remote attackers to execute arbitrary SQL commands via the lid parameter in a viewannonces action to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m22j-h75j-625m/GHSA-m22j-h75j-625m.json b/advisories/unreviewed/2022/05/GHSA-m22j-h75j-625m/GHSA-m22j-h75j-625m.json index f9840c70803..444522675b7 100644 --- a/advisories/unreviewed/2022/05/GHSA-m22j-h75j-625m/GHSA-m22j-h75j-625m.json +++ b/advisories/unreviewed/2022/05/GHSA-m22j-h75j-625m/GHSA-m22j-h75j-625m.json @@ -7,12 +7,8 @@ "CVE-2009-3073" ], "details": "Unspecified vulnerability in the JavaScript engine in Mozilla Firefox 3.5.x before 3.5.3 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m2fq-xfx5-q6pg/GHSA-m2fq-xfx5-q6pg.json b/advisories/unreviewed/2022/05/GHSA-m2fq-xfx5-q6pg/GHSA-m2fq-xfx5-q6pg.json index 598e9a1d5a5..5e81d3bea53 100644 --- a/advisories/unreviewed/2022/05/GHSA-m2fq-xfx5-q6pg/GHSA-m2fq-xfx5-q6pg.json +++ b/advisories/unreviewed/2022/05/GHSA-m2fq-xfx5-q6pg/GHSA-m2fq-xfx5-q6pg.json @@ -7,12 +7,8 @@ "CVE-2009-2573" ], "details": "Multiple SQL injection vulnerabilities in MiniTwitter 0.2 beta, when magic_quotes_gpc is disabled, allow remote authenticated users to execute arbitrary SQL commands via the (1) user parameter to (a) index.php and (b) rss.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m324-m3w8-rqmj/GHSA-m324-m3w8-rqmj.json b/advisories/unreviewed/2022/05/GHSA-m324-m3w8-rqmj/GHSA-m324-m3w8-rqmj.json index 07914dc95c4..2fd16b8704a 100644 --- a/advisories/unreviewed/2022/05/GHSA-m324-m3w8-rqmj/GHSA-m324-m3w8-rqmj.json +++ b/advisories/unreviewed/2022/05/GHSA-m324-m3w8-rqmj/GHSA-m324-m3w8-rqmj.json @@ -7,12 +7,8 @@ "CVE-2009-2985" ], "details": "Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allow attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2009-2996.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m4qp-3gf5-73rm/GHSA-m4qp-3gf5-73rm.json b/advisories/unreviewed/2022/05/GHSA-m4qp-3gf5-73rm/GHSA-m4qp-3gf5-73rm.json index 069b82bab9f..5b50a7a17c0 100644 --- a/advisories/unreviewed/2022/05/GHSA-m4qp-3gf5-73rm/GHSA-m4qp-3gf5-73rm.json +++ b/advisories/unreviewed/2022/05/GHSA-m4qp-3gf5-73rm/GHSA-m4qp-3gf5-73rm.json @@ -7,12 +7,8 @@ "CVE-2009-2958" ], "details": "The tftp_request function in tftp.c in dnsmasq before 2.50, when --enable-tftp is used, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a TFTP read (aka RRQ) request with a malformed blksize option.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m565-4qwf-5j4g/GHSA-m565-4qwf-5j4g.json b/advisories/unreviewed/2022/05/GHSA-m565-4qwf-5j4g/GHSA-m565-4qwf-5j4g.json index a91e4292549..749a2aafcd2 100644 --- a/advisories/unreviewed/2022/05/GHSA-m565-4qwf-5j4g/GHSA-m565-4qwf-5j4g.json +++ b/advisories/unreviewed/2022/05/GHSA-m565-4qwf-5j4g/GHSA-m565-4qwf-5j4g.json @@ -7,12 +7,8 @@ "CVE-2009-3030" ], "details": "Cross-site scripting (XSS) vulnerability in Symantec SecurityExpressions Audit and Compliance Server 4.1.1, 4.1, and earlier allows remote attackers to inject arbitrary web script or HTML via vectors that trigger an error message in a response, related to an \"HTML Injection issue.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m645-386w-2j36/GHSA-m645-386w-2j36.json b/advisories/unreviewed/2022/05/GHSA-m645-386w-2j36/GHSA-m645-386w-2j36.json index b2c75926a5f..1ae8b9c4c09 100644 --- a/advisories/unreviewed/2022/05/GHSA-m645-386w-2j36/GHSA-m645-386w-2j36.json +++ b/advisories/unreviewed/2022/05/GHSA-m645-386w-2j36/GHSA-m645-386w-2j36.json @@ -7,12 +7,8 @@ "CVE-2009-2790" ], "details": "SQL injection vulnerability in cat_products.php in SoftBiz Dating Script allows remote attackers to execute arbitrary SQL commands via the cid parameter. NOTE: this might overlap CVE-2006-3271.4.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m794-79rf-h8x7/GHSA-m794-79rf-h8x7.json b/advisories/unreviewed/2022/05/GHSA-m794-79rf-h8x7/GHSA-m794-79rf-h8x7.json index df4c3a6f1dc..7b5c67a2544 100644 --- a/advisories/unreviewed/2022/05/GHSA-m794-79rf-h8x7/GHSA-m794-79rf-h8x7.json +++ b/advisories/unreviewed/2022/05/GHSA-m794-79rf-h8x7/GHSA-m794-79rf-h8x7.json @@ -7,12 +7,8 @@ "CVE-2009-2679" ], "details": "Unspecified vulnerability in bootpd in HP HP-UX B.11.11, B.11.23, and B.11.31 allows remote attackers to cause a denial of service via unknown attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m7pr-wwvp-92ph/GHSA-m7pr-wwvp-92ph.json b/advisories/unreviewed/2022/05/GHSA-m7pr-wwvp-92ph/GHSA-m7pr-wwvp-92ph.json index 08622d383ae..b91456463e3 100644 --- a/advisories/unreviewed/2022/05/GHSA-m7pr-wwvp-92ph/GHSA-m7pr-wwvp-92ph.json +++ b/advisories/unreviewed/2022/05/GHSA-m7pr-wwvp-92ph/GHSA-m7pr-wwvp-92ph.json @@ -7,12 +7,8 @@ "CVE-2009-2837" ], "details": "Heap-based buffer overflow in QuickDraw Manager in Apple Mac OS X before 10.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PICT image.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m7qq-ch2w-w47w/GHSA-m7qq-ch2w-w47w.json b/advisories/unreviewed/2022/05/GHSA-m7qq-ch2w-w47w/GHSA-m7qq-ch2w-w47w.json index fb26abd6fde..10c44863708 100644 --- a/advisories/unreviewed/2022/05/GHSA-m7qq-ch2w-w47w/GHSA-m7qq-ch2w-w47w.json +++ b/advisories/unreviewed/2022/05/GHSA-m7qq-ch2w-w47w/GHSA-m7qq-ch2w-w47w.json @@ -7,12 +7,8 @@ "CVE-2009-2963" ], "details": "Unspecified vulnerability in the update feature in Toolbar Uninstaller 1.0.2 allows remote attackers to force the download and execution of arbitrary files via attack vectors related to a \"malformed update url and a malformed update website.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m89c-gc36-4jv9/GHSA-m89c-gc36-4jv9.json b/advisories/unreviewed/2022/05/GHSA-m89c-gc36-4jv9/GHSA-m89c-gc36-4jv9.json index 80b7611d3d0..55ba5a4b4ca 100644 --- a/advisories/unreviewed/2022/05/GHSA-m89c-gc36-4jv9/GHSA-m89c-gc36-4jv9.json +++ b/advisories/unreviewed/2022/05/GHSA-m89c-gc36-4jv9/GHSA-m89c-gc36-4jv9.json @@ -7,12 +7,8 @@ "CVE-2009-2614" ], "details": "SQL injection vulnerability in z_admin_login.asp in DataCheck Solutions LinkPal 1.x allows remote attackers to execute arbitrary SQL commands via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m9qw-8j6w-4vww/GHSA-m9qw-8j6w-4vww.json b/advisories/unreviewed/2022/05/GHSA-m9qw-8j6w-4vww/GHSA-m9qw-8j6w-4vww.json index 8c11b8d5407..76adb991169 100644 --- a/advisories/unreviewed/2022/05/GHSA-m9qw-8j6w-4vww/GHSA-m9qw-8j6w-4vww.json +++ b/advisories/unreviewed/2022/05/GHSA-m9qw-8j6w-4vww/GHSA-m9qw-8j6w-4vww.json @@ -7,12 +7,8 @@ "CVE-2009-2504" ], "details": "Multiple integer overflows in unspecified APIs in GDI+ in Microsoft .NET Framework 1.1 SP1, .NET Framework 2.0 SP1 and SP2, Windows XP SP2 and SP3, Windows Server 2003 SP2, Vista Gold and SP1, Server 2008 Gold, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 allow remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka \"GDI+ .NET API Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mc48-q63q-2mqm/GHSA-mc48-q63q-2mqm.json b/advisories/unreviewed/2022/05/GHSA-mc48-q63q-2mqm/GHSA-mc48-q63q-2mqm.json index 091a7641c0c..0c54fb98ff0 100644 --- a/advisories/unreviewed/2022/05/GHSA-mc48-q63q-2mqm/GHSA-mc48-q63q-2mqm.json +++ b/advisories/unreviewed/2022/05/GHSA-mc48-q63q-2mqm/GHSA-mc48-q63q-2mqm.json @@ -7,12 +7,8 @@ "CVE-2009-3147" ], "details": "Cross-site scripting (XSS) vulnerability in showproduct.php in ReviewPost Pro vB3 allows remote attackers to inject arbitrary web script or HTML via the date parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mcgx-gc58-pqxx/GHSA-mcgx-gc58-pqxx.json b/advisories/unreviewed/2022/05/GHSA-mcgx-gc58-pqxx/GHSA-mcgx-gc58-pqxx.json index 0dc916dacc6..a5fbbb3a052 100644 --- a/advisories/unreviewed/2022/05/GHSA-mcgx-gc58-pqxx/GHSA-mcgx-gc58-pqxx.json +++ b/advisories/unreviewed/2022/05/GHSA-mcgx-gc58-pqxx/GHSA-mcgx-gc58-pqxx.json @@ -7,12 +7,8 @@ "CVE-2009-2780" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in 68 Classifieds 4.1 allow remote attackers to inject arbitrary web script or HTML via the (1) cat parameter to category.php, view parameter to (2) login.php and (3) viewlisting.php, page parameter to (4) searchresults.php and (5) toplistings.php, and (6) member parameter to viewmember.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mf87-67ch-56pf/GHSA-mf87-67ch-56pf.json b/advisories/unreviewed/2022/05/GHSA-mf87-67ch-56pf/GHSA-mf87-67ch-56pf.json index d1046079599..33198ddbaea 100644 --- a/advisories/unreviewed/2022/05/GHSA-mf87-67ch-56pf/GHSA-mf87-67ch-56pf.json +++ b/advisories/unreviewed/2022/05/GHSA-mf87-67ch-56pf/GHSA-mf87-67ch-56pf.json @@ -7,12 +7,8 @@ "CVE-2009-3251" ], "details": "include/utils/ListViewUtils.php in vtiger CRM before 5.1.0 allows remote authenticated users to bypass intended access restrictions and read the (1) visibility, (2) location, and (3) recurrence fields of a calendar via a custom view.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mf92-5j9q-wjfr/GHSA-mf92-5j9q-wjfr.json b/advisories/unreviewed/2022/05/GHSA-mf92-5j9q-wjfr/GHSA-mf92-5j9q-wjfr.json index 0213c35e66d..32967e44bd1 100644 --- a/advisories/unreviewed/2022/05/GHSA-mf92-5j9q-wjfr/GHSA-mf92-5j9q-wjfr.json +++ b/advisories/unreviewed/2022/05/GHSA-mf92-5j9q-wjfr/GHSA-mf92-5j9q-wjfr.json @@ -7,12 +7,8 @@ "CVE-2009-2864" ], "details": "Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 5.x before 5.1(3g), 6.x before 6.1(4), 7.0.x before 7.0(2a)su1, and 7.1.x before 7.1(2) allows remote attackers to cause a denial of service (service restart) via malformed SIP messages, aka Bug ID CSCsz95423.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mfmc-fxm6-3cgf/GHSA-mfmc-fxm6-3cgf.json b/advisories/unreviewed/2022/05/GHSA-mfmc-fxm6-3cgf/GHSA-mfmc-fxm6-3cgf.json index a373974490c..556bdb78d5c 100644 --- a/advisories/unreviewed/2022/05/GHSA-mfmc-fxm6-3cgf/GHSA-mfmc-fxm6-3cgf.json +++ b/advisories/unreviewed/2022/05/GHSA-mfmc-fxm6-3cgf/GHSA-mfmc-fxm6-3cgf.json @@ -7,12 +7,8 @@ "CVE-2009-3131" ], "details": "Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer 2003 SP3; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allow remote attackers to execute arbitrary code via a spreadsheet with a crafted formula embedded in a cell, aka \"Excel Formula Parsing Memory Corruption Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mfvj-29wx-4v2c/GHSA-mfvj-29wx-4v2c.json b/advisories/unreviewed/2022/05/GHSA-mfvj-29wx-4v2c/GHSA-mfvj-29wx-4v2c.json index 6b7cf1cb84d..af9e08f6ead 100644 --- a/advisories/unreviewed/2022/05/GHSA-mfvj-29wx-4v2c/GHSA-mfvj-29wx-4v2c.json +++ b/advisories/unreviewed/2022/05/GHSA-mfvj-29wx-4v2c/GHSA-mfvj-29wx-4v2c.json @@ -7,12 +7,8 @@ "CVE-2009-2662" ], "details": "The browser engine in Mozilla Firefox 3.5.x before 3.5.2 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the TraceRecorder::snapshot function in js/src/jstracer.cpp, and unspecified other vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mfxg-gv98-v84v/GHSA-mfxg-gv98-v84v.json b/advisories/unreviewed/2022/05/GHSA-mfxg-gv98-v84v/GHSA-mfxg-gv98-v84v.json index c547209356f..abe512bbee2 100644 --- a/advisories/unreviewed/2022/05/GHSA-mfxg-gv98-v84v/GHSA-mfxg-gv98-v84v.json +++ b/advisories/unreviewed/2022/05/GHSA-mfxg-gv98-v84v/GHSA-mfxg-gv98-v84v.json @@ -7,12 +7,8 @@ "CVE-2009-2960" ], "details": "CuteFlow 2.10.3 and 2.11.0_c does not properly restrict access to pages/edituser.php, which allows remote attackers to modify usernames and passwords via a direct request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mgm3-5x33-7mw3/GHSA-mgm3-5x33-7mw3.json b/advisories/unreviewed/2022/05/GHSA-mgm3-5x33-7mw3/GHSA-mgm3-5x33-7mw3.json index 165d988ec76..aea05d4556c 100644 --- a/advisories/unreviewed/2022/05/GHSA-mgm3-5x33-7mw3/GHSA-mgm3-5x33-7mw3.json +++ b/advisories/unreviewed/2022/05/GHSA-mgm3-5x33-7mw3/GHSA-mgm3-5x33-7mw3.json @@ -7,12 +7,8 @@ "CVE-2009-2581" ], "details": "Cross-site scripting (XSS) vulnerability in modifier.php in EditeurScripts EsNews 1.2 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mgvr-5qfh-f7r5/GHSA-mgvr-5qfh-f7r5.json b/advisories/unreviewed/2022/05/GHSA-mgvr-5qfh-f7r5/GHSA-mgvr-5qfh-f7r5.json index 17bf66ac5e5..9d3c997f7b9 100644 --- a/advisories/unreviewed/2022/05/GHSA-mgvr-5qfh-f7r5/GHSA-mgvr-5qfh-f7r5.json +++ b/advisories/unreviewed/2022/05/GHSA-mgvr-5qfh-f7r5/GHSA-mgvr-5qfh-f7r5.json @@ -7,12 +7,8 @@ "CVE-2009-2772" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in PG Roommate Finder Solution allow remote attackers to inject arbitrary web script or HTML via the part parameter to (1) quick_search.php and (2) viewprofile.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mh8p-xcfm-pqrq/GHSA-mh8p-xcfm-pqrq.json b/advisories/unreviewed/2022/05/GHSA-mh8p-xcfm-pqrq/GHSA-mh8p-xcfm-pqrq.json index 31e96363629..3293e09f344 100644 --- a/advisories/unreviewed/2022/05/GHSA-mh8p-xcfm-pqrq/GHSA-mh8p-xcfm-pqrq.json +++ b/advisories/unreviewed/2022/05/GHSA-mh8p-xcfm-pqrq/GHSA-mh8p-xcfm-pqrq.json @@ -7,12 +7,8 @@ "CVE-2009-2776" ], "details": "SQL injection vulnerability in showresult.asp in Smart ASP Survey allows remote attackers to execute arbitrary SQL commands via the catid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mh95-8g9g-vqf9/GHSA-mh95-8g9g-vqf9.json b/advisories/unreviewed/2022/05/GHSA-mh95-8g9g-vqf9/GHSA-mh95-8g9g-vqf9.json index 0c918dbc197..5d1717a596f 100644 --- a/advisories/unreviewed/2022/05/GHSA-mh95-8g9g-vqf9/GHSA-mh95-8g9g-vqf9.json +++ b/advisories/unreviewed/2022/05/GHSA-mh95-8g9g-vqf9/GHSA-mh95-8g9g-vqf9.json @@ -7,12 +7,8 @@ "CVE-2009-2913" ], "details": "Cross-site scripting (XSS) vulnerability in index.php in XZero Community Classifieds 4.97.8 allows remote attackers to inject arbitrary web script or HTML via the URI. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mh9m-75gc-gjxq/GHSA-mh9m-75gc-gjxq.json b/advisories/unreviewed/2022/05/GHSA-mh9m-75gc-gjxq/GHSA-mh9m-75gc-gjxq.json index 6a9e9a8851f..e2db22c0b68 100644 --- a/advisories/unreviewed/2022/05/GHSA-mh9m-75gc-gjxq/GHSA-mh9m-75gc-gjxq.json +++ b/advisories/unreviewed/2022/05/GHSA-mh9m-75gc-gjxq/GHSA-mh9m-75gc-gjxq.json @@ -7,12 +7,8 @@ "CVE-2009-2872" ], "details": "Cisco IOS 12.0 through 12.4, when IP-based tunnels and the Cisco Express Forwarding feature are enabled, allows remote attackers to cause a denial of service (device reload) via a malformed packet that is not properly handled during switching from one tunnel to a second tunnel, aka Bug IDs CSCsh97579 and CSCsq31776.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mhgr-f9r9-gf56/GHSA-mhgr-f9r9-gf56.json b/advisories/unreviewed/2022/05/GHSA-mhgr-f9r9-gf56/GHSA-mhgr-f9r9-gf56.json index 33a0891e7c4..dff4bfed88d 100644 --- a/advisories/unreviewed/2022/05/GHSA-mhgr-f9r9-gf56/GHSA-mhgr-f9r9-gf56.json +++ b/advisories/unreviewed/2022/05/GHSA-mhgr-f9r9-gf56/GHSA-mhgr-f9r9-gf56.json @@ -7,12 +7,8 @@ "CVE-2009-3178" ], "details": "Unspecified vulnerability in mm.exe in Symantec Altiris Deployment Solution 6.9 allows remote attackers to cause a denial of service via unknown attack vectors, as demonstrated by a certain module in VulnDisco Pack Professional 7.18, \"Symantec Altiris Deployment Solution 6.9 DoS.\" NOTE: as of 20090909, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mmg7-q8j9-f8wj/GHSA-mmg7-q8j9-f8wj.json b/advisories/unreviewed/2022/05/GHSA-mmg7-q8j9-f8wj/GHSA-mmg7-q8j9-f8wj.json index cf7c4bab93f..6eae63e809a 100644 --- a/advisories/unreviewed/2022/05/GHSA-mmg7-q8j9-f8wj/GHSA-mmg7-q8j9-f8wj.json +++ b/advisories/unreviewed/2022/05/GHSA-mmg7-q8j9-f8wj/GHSA-mmg7-q8j9-f8wj.json @@ -7,12 +7,8 @@ "CVE-2009-2582" ], "details": "Stack-based buffer overflow in manager.exe in Akamai Download Manager (aka DLM or dlmanager) before 2.2.4.8 allows remote web servers to execute arbitrary code via a malformed HTTP response during a Redswoosh download, a different vulnerability than CVE-2007-1891 and CVE-2007-1892.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mpq2-pcrq-r69f/GHSA-mpq2-pcrq-r69f.json b/advisories/unreviewed/2022/05/GHSA-mpq2-pcrq-r69f/GHSA-mpq2-pcrq-r69f.json index 7307f02ebf9..e28e6dd6c54 100644 --- a/advisories/unreviewed/2022/05/GHSA-mpq2-pcrq-r69f/GHSA-mpq2-pcrq-r69f.json +++ b/advisories/unreviewed/2022/05/GHSA-mpq2-pcrq-r69f/GHSA-mpq2-pcrq-r69f.json @@ -7,12 +7,8 @@ "CVE-2009-3012" ], "details": "Mozilla Firefox 3.0.13 and earlier, 3.5, 3.6 a1 pre, and 3.7 a1 pre does not properly block data: URIs in Location headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Location header that contains JavaScript sequences in a data:text/html URI or (2) entering a data:text/html URI with JavaScript sequences when specifying the content of a Location header. NOTE: the JavaScript executes outside of the context of the HTTP site.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mqc9-c5v8-8hw8/GHSA-mqc9-c5v8-8hw8.json b/advisories/unreviewed/2022/05/GHSA-mqc9-c5v8-8hw8/GHSA-mqc9-c5v8-8hw8.json index 5167efa6226..95eeff48bc3 100644 --- a/advisories/unreviewed/2022/05/GHSA-mqc9-c5v8-8hw8/GHSA-mqc9-c5v8-8hw8.json +++ b/advisories/unreviewed/2022/05/GHSA-mqc9-c5v8-8hw8/GHSA-mqc9-c5v8-8hw8.json @@ -7,12 +7,8 @@ "CVE-2009-3167" ], "details": "Directory traversal vulnerability in index.php in Anantasoft Gazelle CMS 1.0, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the template parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mrg5-xx7w-3qcp/GHSA-mrg5-xx7w-3qcp.json b/advisories/unreviewed/2022/05/GHSA-mrg5-xx7w-3qcp/GHSA-mrg5-xx7w-3qcp.json index 7007fb7e7dd..e60a05c01ab 100644 --- a/advisories/unreviewed/2022/05/GHSA-mrg5-xx7w-3qcp/GHSA-mrg5-xx7w-3qcp.json +++ b/advisories/unreviewed/2022/05/GHSA-mrg5-xx7w-3qcp/GHSA-mrg5-xx7w-3qcp.json @@ -7,12 +7,8 @@ "CVE-2009-2818" ], "details": "Adaptive Firewall in Apple Mac OS X before 10.6.2 does not properly handle invalid usernames in SSH login attempts, which makes it easier for remote attackers to obtain login access via a brute-force attack (aka dictionary attack).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mrwv-m2pr-m6wf/GHSA-mrwv-m2pr-m6wf.json b/advisories/unreviewed/2022/05/GHSA-mrwv-m2pr-m6wf/GHSA-mrwv-m2pr-m6wf.json index 5478b168e11..be0dbc5c87b 100644 --- a/advisories/unreviewed/2022/05/GHSA-mrwv-m2pr-m6wf/GHSA-mrwv-m2pr-m6wf.json +++ b/advisories/unreviewed/2022/05/GHSA-mrwv-m2pr-m6wf/GHSA-mrwv-m2pr-m6wf.json @@ -7,12 +7,8 @@ "CVE-2009-2514" ], "details": "win32k.sys in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not correctly parse font code during construction of a directory-entry table, which allows remote attackers to execute arbitrary code via a crafted Embedded OpenType (EOT) font, aka \"Win32k EOT Parsing Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mv28-cc94-6wvh/GHSA-mv28-cc94-6wvh.json b/advisories/unreviewed/2022/05/GHSA-mv28-cc94-6wvh/GHSA-mv28-cc94-6wvh.json index 4b0b884df30..72c57a6dbfa 100644 --- a/advisories/unreviewed/2022/05/GHSA-mv28-cc94-6wvh/GHSA-mv28-cc94-6wvh.json +++ b/advisories/unreviewed/2022/05/GHSA-mv28-cc94-6wvh/GHSA-mv28-cc94-6wvh.json @@ -7,12 +7,8 @@ "CVE-2009-2484" ], "details": "Stack-based buffer overflow in the Win32AddConnection function in modules/access/smb.c in VideoLAN VLC media player 0.9.9, when running on Microsoft Windows, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long smb URI in a playlist file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mv6q-6xwq-rrw9/GHSA-mv6q-6xwq-rrw9.json b/advisories/unreviewed/2022/05/GHSA-mv6q-6xwq-rrw9/GHSA-mv6q-6xwq-rrw9.json index c9ece23f5d5..f5b0a920a5d 100644 --- a/advisories/unreviewed/2022/05/GHSA-mv6q-6xwq-rrw9/GHSA-mv6q-6xwq-rrw9.json +++ b/advisories/unreviewed/2022/05/GHSA-mv6q-6xwq-rrw9/GHSA-mv6q-6xwq-rrw9.json @@ -7,12 +7,8 @@ "CVE-2009-3010" ], "details": "Mozilla Firefox 3.0.13 and earlier, 3.5, 3.6 a1 pre, and 3.7 a1 pre; SeaMonkey 1.1.17; and Mozilla 1.7.x and earlier do not properly block data: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header that contains JavaScript sequences in a data:text/html URI or (2) entering a data:text/html URI with JavaScript sequences when specifying the content of a Refresh header. NOTE: in some product versions, the JavaScript executes outside of the context of the HTTP site.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mvcm-4jxr-w697/GHSA-mvcm-4jxr-w697.json b/advisories/unreviewed/2022/05/GHSA-mvcm-4jxr-w697/GHSA-mvcm-4jxr-w697.json index 969bcecb8c9..247a299813d 100644 --- a/advisories/unreviewed/2022/05/GHSA-mvcm-4jxr-w697/GHSA-mvcm-4jxr-w697.json +++ b/advisories/unreviewed/2022/05/GHSA-mvcm-4jxr-w697/GHSA-mvcm-4jxr-w697.json @@ -7,12 +7,8 @@ "CVE-2009-3127" ], "details": "Microsoft Office Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, Open XML File Format Converter for Mac, and Office Excel Viewer 2003 SP3 do not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka \"Excel Cache Memory Corruption Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mvjv-f233-94jq/GHSA-mvjv-f233-94jq.json b/advisories/unreviewed/2022/05/GHSA-mvjv-f233-94jq/GHSA-mvjv-f233-94jq.json index 2e7a439c57e..fe9d0abd44c 100644 --- a/advisories/unreviewed/2022/05/GHSA-mvjv-f233-94jq/GHSA-mvjv-f233-94jq.json +++ b/advisories/unreviewed/2022/05/GHSA-mvjv-f233-94jq/GHSA-mvjv-f233-94jq.json @@ -7,12 +7,8 @@ "CVE-2009-2532" ], "details": "Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold and SP2, and Windows 7 RC do not properly process the command value in an SMB Multi-Protocol Negotiate Request packet, which allows remote attackers to execute arbitrary code via a crafted SMBv2 packet to the Server service, aka \"SMBv2 Command Value Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mwf2-x6q4-2rwj/GHSA-mwf2-x6q4-2rwj.json b/advisories/unreviewed/2022/05/GHSA-mwf2-x6q4-2rwj/GHSA-mwf2-x6q4-2rwj.json index 7c14d1aaa9b..14677f76bbc 100644 --- a/advisories/unreviewed/2022/05/GHSA-mwf2-x6q4-2rwj/GHSA-mwf2-x6q4-2rwj.json +++ b/advisories/unreviewed/2022/05/GHSA-mwf2-x6q4-2rwj/GHSA-mwf2-x6q4-2rwj.json @@ -7,12 +7,8 @@ "CVE-2009-2606" ], "details": "ASP Football Pool 2.3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for NFL.mdb.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p2gg-4552-32w2/GHSA-p2gg-4552-32w2.json b/advisories/unreviewed/2022/05/GHSA-p2gg-4552-32w2/GHSA-p2gg-4552-32w2.json index 90a9273afd9..448204a1745 100644 --- a/advisories/unreviewed/2022/05/GHSA-p2gg-4552-32w2/GHSA-p2gg-4552-32w2.json +++ b/advisories/unreviewed/2022/05/GHSA-p2gg-4552-32w2/GHSA-p2gg-4552-32w2.json @@ -7,12 +7,8 @@ "CVE-2009-2987" ], "details": "Unspecified vulnerability in an ActiveX control in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 on Windows allows remote attackers to cause a denial of service via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p375-prpx-3ph3/GHSA-p375-prpx-3ph3.json b/advisories/unreviewed/2022/05/GHSA-p375-prpx-3ph3/GHSA-p375-prpx-3ph3.json index e524a4857e3..cfc4aac6341 100644 --- a/advisories/unreviewed/2022/05/GHSA-p375-prpx-3ph3/GHSA-p375-prpx-3ph3.json +++ b/advisories/unreviewed/2022/05/GHSA-p375-prpx-3ph3/GHSA-p375-prpx-3ph3.json @@ -7,12 +7,8 @@ "CVE-2009-3165" ], "details": "SQL injection vulnerability in the Bug.create WebService function in Bugzilla 2.23.4 through 3.0.8, 3.1.1 through 3.2.4, and 3.3.1 through 3.4.1 allows remote attackers to execute arbitrary SQL commands via unspecified parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p3mw-2r4j-49c2/GHSA-p3mw-2r4j-49c2.json b/advisories/unreviewed/2022/05/GHSA-p3mw-2r4j-49c2/GHSA-p3mw-2r4j-49c2.json index 3a1fff0231b..4606181c659 100644 --- a/advisories/unreviewed/2022/05/GHSA-p3mw-2r4j-49c2/GHSA-p3mw-2r4j-49c2.json +++ b/advisories/unreviewed/2022/05/GHSA-p3mw-2r4j-49c2/GHSA-p3mw-2r4j-49c2.json @@ -7,12 +7,8 @@ "CVE-2009-2577" ], "details": "Opera 9.52 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption, and application hang) via a long Unicode string argument to the write method, a related issue to CVE-2009-2479.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p3rr-cvjw-cgxr/GHSA-p3rr-cvjw-cgxr.json b/advisories/unreviewed/2022/05/GHSA-p3rr-cvjw-cgxr/GHSA-p3rr-cvjw-cgxr.json index 591aadbe0b0..5a32cb2f9db 100644 --- a/advisories/unreviewed/2022/05/GHSA-p3rr-cvjw-cgxr/GHSA-p3rr-cvjw-cgxr.json +++ b/advisories/unreviewed/2022/05/GHSA-p3rr-cvjw-cgxr/GHSA-p3rr-cvjw-cgxr.json @@ -7,12 +7,8 @@ "CVE-2009-2765" ], "details": "httpd.c in httpd in the management GUI in DD-WRT 24 sp1, and other versions before build 12533, allows remote attackers to execute arbitrary commands via shell metacharacters in a request to a cgi-bin/ URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p3w4-7hc7-833g/GHSA-p3w4-7hc7-833g.json b/advisories/unreviewed/2022/05/GHSA-p3w4-7hc7-833g/GHSA-p3w4-7hc7-833g.json index e224b2002d0..2309d1543fc 100644 --- a/advisories/unreviewed/2022/05/GHSA-p3w4-7hc7-833g/GHSA-p3w4-7hc7-833g.json +++ b/advisories/unreviewed/2022/05/GHSA-p3w4-7hc7-833g/GHSA-p3w4-7hc7-833g.json @@ -7,12 +7,8 @@ "CVE-2009-2721" ], "details": "Multiple unspecified vulnerabilities in the Provider class in Sun Java SE 5.0 before Update 20 have unknown impact and attack vectors, aka BugId 6406003.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p457-r5cx-pcgv/GHSA-p457-r5cx-pcgv.json b/advisories/unreviewed/2022/05/GHSA-p457-r5cx-pcgv/GHSA-p457-r5cx-pcgv.json index b744fdd7744..9080004c404 100644 --- a/advisories/unreviewed/2022/05/GHSA-p457-r5cx-pcgv/GHSA-p457-r5cx-pcgv.json +++ b/advisories/unreviewed/2022/05/GHSA-p457-r5cx-pcgv/GHSA-p457-r5cx-pcgv.json @@ -7,12 +7,8 @@ "CVE-2009-2814" ], "details": "Cross-site scripting (XSS) vulnerability in the Wiki Server in Apple Mac OS X 10.5.8 allows remote attackers to inject arbitrary web script or HTML via a search request containing data that does not use UTF-8 encoding.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p56p-c4j5-395j/GHSA-p56p-c4j5-395j.json b/advisories/unreviewed/2022/05/GHSA-p56p-c4j5-395j/GHSA-p56p-c4j5-395j.json index 7087650371f..22d74c85864 100644 --- a/advisories/unreviewed/2022/05/GHSA-p56p-c4j5-395j/GHSA-p56p-c4j5-395j.json +++ b/advisories/unreviewed/2022/05/GHSA-p56p-c4j5-395j/GHSA-p56p-c4j5-395j.json @@ -7,12 +7,8 @@ "CVE-2009-3066" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in PropertyWatchScript.com Property Watch 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) videoid parameter to tools/email.php and (2) redirect parameter to tools/login.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p5fj-7pgr-xv7v/GHSA-p5fj-7pgr-xv7v.json b/advisories/unreviewed/2022/05/GHSA-p5fj-7pgr-xv7v/GHSA-p5fj-7pgr-xv7v.json index 3eeed97cb1b..8a6e8bee5c3 100644 --- a/advisories/unreviewed/2022/05/GHSA-p5fj-7pgr-xv7v/GHSA-p5fj-7pgr-xv7v.json +++ b/advisories/unreviewed/2022/05/GHSA-p5fj-7pgr-xv7v/GHSA-p5fj-7pgr-xv7v.json @@ -7,12 +7,8 @@ "CVE-2009-2477" ], "details": "js/src/jstracer.cpp in the Just-in-time (JIT) JavaScript compiler (aka TraceMonkey) in Mozilla Firefox 3.5 before 3.5.1 allows remote attackers to execute arbitrary code via certain use of the escape function that triggers access to uninitialized memory locations, as originally demonstrated by a document containing P and FONT elements.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p5vp-96h6-xqrg/GHSA-p5vp-96h6-xqrg.json b/advisories/unreviewed/2022/05/GHSA-p5vp-96h6-xqrg/GHSA-p5vp-96h6-xqrg.json index 414624655ae..ccd30dd0085 100644 --- a/advisories/unreviewed/2022/05/GHSA-p5vp-96h6-xqrg/GHSA-p5vp-96h6-xqrg.json +++ b/advisories/unreviewed/2022/05/GHSA-p5vp-96h6-xqrg/GHSA-p5vp-96h6-xqrg.json @@ -7,12 +7,8 @@ "CVE-2009-3302" ], "details": "filter/ww8/ww8par2.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted sprmTSetBrc table property modifier in a Word document, related to a \"boundary error flaw.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p62h-hghf-j328/GHSA-p62h-hghf-j328.json b/advisories/unreviewed/2022/05/GHSA-p62h-hghf-j328/GHSA-p62h-hghf-j328.json index dc4d164b294..3f67082d6f3 100644 --- a/advisories/unreviewed/2022/05/GHSA-p62h-hghf-j328/GHSA-p62h-hghf-j328.json +++ b/advisories/unreviewed/2022/05/GHSA-p62h-hghf-j328/GHSA-p62h-hghf-j328.json @@ -7,12 +7,8 @@ "CVE-2009-2907" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in SpringSource tc Server 6.0.20.B and earlier, Application Management Suite (AMS) before 2.0.0.SR4, Hyperic HQ Open Source before 4.2.x, Hyperic HQ 4.0 Enterprise before 4.0.3.2, and Hyperic HQ 4.1 Enterprise before 4.1.2.1 allow remote attackers to inject arbitrary web script or HTML via the description field and unspecified \"input fields.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p7fh-hvqc-m963/GHSA-p7fh-hvqc-m963.json b/advisories/unreviewed/2022/05/GHSA-p7fh-hvqc-m963/GHSA-p7fh-hvqc-m963.json index 987a868b75e..45abe91a42c 100644 --- a/advisories/unreviewed/2022/05/GHSA-p7fh-hvqc-m963/GHSA-p7fh-hvqc-m963.json +++ b/advisories/unreviewed/2022/05/GHSA-p7fh-hvqc-m963/GHSA-p7fh-hvqc-m963.json @@ -7,12 +7,8 @@ "CVE-2009-3007" ], "details": "Mozilla Firefox 3.5.1 and SeaMonkey 1.1.17, and Flock 2.5.1, allow context-dependent attackers to spoof the address bar, via window.open with a relative URI, to show an arbitrary file: URL after a victim has visited any file: URL, as demonstrated by a visit to a file: document written by the attacker.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p988-h6pg-9xrg/GHSA-p988-h6pg-9xrg.json b/advisories/unreviewed/2022/05/GHSA-p988-h6pg-9xrg/GHSA-p988-h6pg-9xrg.json index 9936b1cd8a2..cf69edcf9cf 100644 --- a/advisories/unreviewed/2022/05/GHSA-p988-h6pg-9xrg/GHSA-p988-h6pg-9xrg.json +++ b/advisories/unreviewed/2022/05/GHSA-p988-h6pg-9xrg/GHSA-p988-h6pg-9xrg.json @@ -7,12 +7,8 @@ "CVE-2009-2925" ], "details": "Directory traversal vulnerability in DJcalendar.cgi in DJCalendar allows remote attackers to read arbitrary files via a .. (dot dot) in the TEMPLATE parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pc3h-f2j5-gmm4/GHSA-pc3h-f2j5-gmm4.json b/advisories/unreviewed/2022/05/GHSA-pc3h-f2j5-gmm4/GHSA-pc3h-f2j5-gmm4.json index 8134b27c46a..22ddbea109d 100644 --- a/advisories/unreviewed/2022/05/GHSA-pc3h-f2j5-gmm4/GHSA-pc3h-f2j5-gmm4.json +++ b/advisories/unreviewed/2022/05/GHSA-pc3h-f2j5-gmm4/GHSA-pc3h-f2j5-gmm4.json @@ -7,12 +7,8 @@ "CVE-2009-2655" ], "details": "mshtml.dll in Microsoft Internet Explorer 7 and 8 on Windows XP SP3 allows remote attackers to cause a denial of service (application crash) by calling the JavaScript findText method with a crafted Unicode string in the first argument, and only one additional argument, as demonstrated by a second argument of -1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pcmf-mvr6-mrr7/GHSA-pcmf-mvr6-mrr7.json b/advisories/unreviewed/2022/05/GHSA-pcmf-mvr6-mrr7/GHSA-pcmf-mvr6-mrr7.json index 2e42c8bdb12..01a29832012 100644 --- a/advisories/unreviewed/2022/05/GHSA-pcmf-mvr6-mrr7/GHSA-pcmf-mvr6-mrr7.json +++ b/advisories/unreviewed/2022/05/GHSA-pcmf-mvr6-mrr7/GHSA-pcmf-mvr6-mrr7.json @@ -7,12 +7,8 @@ "CVE-2009-3081" ], "details": "SQL injection vulnerability in index.php in Uiga Church Portal allows remote attackers to execute arbitrary SQL commands via the month parameter in a calendar action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pgc6-mrqp-hqww/GHSA-pgc6-mrqp-hqww.json b/advisories/unreviewed/2022/05/GHSA-pgc6-mrqp-hqww/GHSA-pgc6-mrqp-hqww.json index 319643df53b..97789cea125 100644 --- a/advisories/unreviewed/2022/05/GHSA-pgc6-mrqp-hqww/GHSA-pgc6-mrqp-hqww.json +++ b/advisories/unreviewed/2022/05/GHSA-pgc6-mrqp-hqww/GHSA-pgc6-mrqp-hqww.json @@ -7,12 +7,8 @@ "CVE-2009-3255" ], "details": "SQL injection vulnerability in RASH Quote Management System (RQMS) 1.2.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the user parameter in an admin action to the default URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pgvx-j63m-jjgr/GHSA-pgvx-j63m-jjgr.json b/advisories/unreviewed/2022/05/GHSA-pgvx-j63m-jjgr/GHSA-pgvx-j63m-jjgr.json index 2c1e3286267..1353925a7fb 100644 --- a/advisories/unreviewed/2022/05/GHSA-pgvx-j63m-jjgr/GHSA-pgvx-j63m-jjgr.json +++ b/advisories/unreviewed/2022/05/GHSA-pgvx-j63m-jjgr/GHSA-pgvx-j63m-jjgr.json @@ -7,12 +7,8 @@ "CVE-2009-3079" ], "details": "Unspecified vulnerability in Mozilla Firefox before 3.0.14, and 3.5.x before 3.5.3, allows remote attackers to execute arbitrary JavaScript with chrome privileges via vectors involving an object, the FeedWriter, and the BrowserFeedWriter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-phgx-679x-jm97/GHSA-phgx-679x-jm97.json b/advisories/unreviewed/2022/05/GHSA-phgx-679x-jm97/GHSA-phgx-679x-jm97.json index 9420066f0f3..49d42762baf 100644 --- a/advisories/unreviewed/2022/05/GHSA-phgx-679x-jm97/GHSA-phgx-679x-jm97.json +++ b/advisories/unreviewed/2022/05/GHSA-phgx-679x-jm97/GHSA-phgx-679x-jm97.json @@ -7,12 +7,8 @@ "CVE-2009-3087" ], "details": "Unspecified vulnerability in nserver.exe in the server in IBM Lotus Domino 8.0 on Windows Server 2003 allows remote attackers to cause a denial of service (daemon crash) via unknown vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.11. NOTE: as of 20090903, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-phm7-3gvw-rm4v/GHSA-phm7-3gvw-rm4v.json b/advisories/unreviewed/2022/05/GHSA-phm7-3gvw-rm4v/GHSA-phm7-3gvw-rm4v.json index 35181d051c2..c0ef3ea252f 100644 --- a/advisories/unreviewed/2022/05/GHSA-phm7-3gvw-rm4v/GHSA-phm7-3gvw-rm4v.json +++ b/advisories/unreviewed/2022/05/GHSA-phm7-3gvw-rm4v/GHSA-phm7-3gvw-rm4v.json @@ -7,12 +7,8 @@ "CVE-2009-2667" ], "details": "Unspecified vulnerability in IBM Tivoli Key Lifecycle Manager (TKLM) 1.0 has unknown impact and attack vectors, related to a \"password security vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-phqm-4q46-2r6c/GHSA-phqm-4q46-2r6c.json b/advisories/unreviewed/2022/05/GHSA-phqm-4q46-2r6c/GHSA-phqm-4q46-2r6c.json index 312ae95e6bf..0a698337d7c 100644 --- a/advisories/unreviewed/2022/05/GHSA-phqm-4q46-2r6c/GHSA-phqm-4q46-2r6c.json +++ b/advisories/unreviewed/2022/05/GHSA-phqm-4q46-2r6c/GHSA-phqm-4q46-2r6c.json @@ -7,12 +7,8 @@ "CVE-2009-2874" ], "details": "The TimesTenD process in Cisco Unified Presence 1.x, 6.x before 6.0(6), and 7.x before 7.0(4) allows remote attackers to cause a denial of service (process crash) via a large number of TCP connections to ports 16200 and 22794, aka Bug ID CSCsy17662.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-phwj-5f67-567g/GHSA-phwj-5f67-567g.json b/advisories/unreviewed/2022/05/GHSA-phwj-5f67-567g/GHSA-phwj-5f67-567g.json index 255f6980d4d..99ef1e89109 100644 --- a/advisories/unreviewed/2022/05/GHSA-phwj-5f67-567g/GHSA-phwj-5f67-567g.json +++ b/advisories/unreviewed/2022/05/GHSA-phwj-5f67-567g/GHSA-phwj-5f67-567g.json @@ -7,12 +7,8 @@ "CVE-2009-2887" ], "details": "Cross-site scripting (XSS) vulnerability in bios.php in PHP Scripts Now President Bios allows remote attackers to inject arbitrary web script or HTML via the rank parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-phxv-vc8h-3g23/GHSA-phxv-vc8h-3g23.json b/advisories/unreviewed/2022/05/GHSA-phxv-vc8h-3g23/GHSA-phxv-vc8h-3g23.json index 50aa873c610..681035bb7c3 100644 --- a/advisories/unreviewed/2022/05/GHSA-phxv-vc8h-3g23/GHSA-phxv-vc8h-3g23.json +++ b/advisories/unreviewed/2022/05/GHSA-phxv-vc8h-3g23/GHSA-phxv-vc8h-3g23.json @@ -7,12 +7,8 @@ "CVE-2009-2970" ], "details": "Stack-based buffer overflow in the GetUiDllVersion function in an ActiveX control in UiCheck.dll before 1.0.0.7 in UiTV UiPlayer, as used in BaiduX and other products, allows remote attackers to execute arbitrary code via the filename parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pj4h-cpcx-vrg8/GHSA-pj4h-cpcx-vrg8.json b/advisories/unreviewed/2022/05/GHSA-pj4h-cpcx-vrg8/GHSA-pj4h-cpcx-vrg8.json index b5253e6ffae..2dfad440468 100644 --- a/advisories/unreviewed/2022/05/GHSA-pj4h-cpcx-vrg8/GHSA-pj4h-cpcx-vrg8.json +++ b/advisories/unreviewed/2022/05/GHSA-pj4h-cpcx-vrg8/GHSA-pj4h-cpcx-vrg8.json @@ -7,12 +7,8 @@ "CVE-2009-2915" ], "details": "SQL injection vulnerability in 2fly_gift.php in 2FLY Gift Delivery System 6.0 allows remote attackers to execute arbitrary SQL commands via the gameid parameter in a content action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ppjc-pm9w-w6q7/GHSA-ppjc-pm9w-w6q7.json b/advisories/unreviewed/2022/05/GHSA-ppjc-pm9w-w6q7/GHSA-ppjc-pm9w-w6q7.json index eb5e621713e..1336dd1e351 100644 --- a/advisories/unreviewed/2022/05/GHSA-ppjc-pm9w-w6q7/GHSA-ppjc-pm9w-w6q7.json +++ b/advisories/unreviewed/2022/05/GHSA-ppjc-pm9w-w6q7/GHSA-ppjc-pm9w-w6q7.json @@ -7,12 +7,8 @@ "CVE-2009-2899" ], "details": "The monitor perl script in the Sybase database plug-in in SpringSource Hyperic HQ before 4.3 allows local users to obtain the database password by listing the process and its arguments.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pq5x-qrx9-87q4/GHSA-pq5x-qrx9-87q4.json b/advisories/unreviewed/2022/05/GHSA-pq5x-qrx9-87q4/GHSA-pq5x-qrx9-87q4.json index 4cd6c5f01cb..fd613635de1 100644 --- a/advisories/unreviewed/2022/05/GHSA-pq5x-qrx9-87q4/GHSA-pq5x-qrx9-87q4.json +++ b/advisories/unreviewed/2022/05/GHSA-pq5x-qrx9-87q4/GHSA-pq5x-qrx9-87q4.json @@ -7,12 +7,8 @@ "CVE-2009-2911" ], "details": "SystemTap 1.0, when the --unprivileged option is used, does not properly restrict certain data sizes, which allows local users to (1) cause a denial of service or gain privileges via a print operation with a large number of arguments that trigger a kernel stack overflow, (2) cause a denial of service via crafted DWARF expressions that trigger a kernel stack frame overflow, or (3) cause a denial of service (infinite loop) via vectors that trigger creation of large unwind tables, related to Common Information Entry (CIE) and Call Frame Instruction (CFI) records.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pqhg-j5hh-cx9v/GHSA-pqhg-j5hh-cx9v.json b/advisories/unreviewed/2022/05/GHSA-pqhg-j5hh-cx9v/GHSA-pqhg-j5hh-cx9v.json index 6594939d22f..c69b5105ca1 100644 --- a/advisories/unreviewed/2022/05/GHSA-pqhg-j5hh-cx9v/GHSA-pqhg-j5hh-cx9v.json +++ b/advisories/unreviewed/2022/05/GHSA-pqhg-j5hh-cx9v/GHSA-pqhg-j5hh-cx9v.json @@ -7,12 +7,8 @@ "CVE-2009-3085" ], "details": "The XMPP protocol plugin in libpurple in Pidgin before 2.6.2 does not properly handle an error IQ stanza during an attempted fetch of a custom smiley, which allows remote attackers to cause a denial of service (application crash) via XHTML-IM content with cid: images.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-prgp-qwrq-6qh6/GHSA-prgp-qwrq-6qh6.json b/advisories/unreviewed/2022/05/GHSA-prgp-qwrq-6qh6/GHSA-prgp-qwrq-6qh6.json index 47663959f9f..ce290afc35d 100644 --- a/advisories/unreviewed/2022/05/GHSA-prgp-qwrq-6qh6/GHSA-prgp-qwrq-6qh6.json +++ b/advisories/unreviewed/2022/05/GHSA-prgp-qwrq-6qh6/GHSA-prgp-qwrq-6qh6.json @@ -7,12 +7,8 @@ "CVE-2009-2734" ], "details": "SQL injection vulnerability in the get_employee function in classweekreport.inc in Achievo before 1.4.0 allows remote attackers to execute arbitrary SQL commands via the userid parameter (aka user_id variable) to dispatch.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pvm6-r47j-qphc/GHSA-pvm6-r47j-qphc.json b/advisories/unreviewed/2022/05/GHSA-pvm6-r47j-qphc/GHSA-pvm6-r47j-qphc.json index bbc86b47642..cf2bb0e96e1 100644 --- a/advisories/unreviewed/2022/05/GHSA-pvm6-r47j-qphc/GHSA-pvm6-r47j-qphc.json +++ b/advisories/unreviewed/2022/05/GHSA-pvm6-r47j-qphc/GHSA-pvm6-r47j-qphc.json @@ -7,12 +7,8 @@ "CVE-2009-2657" ], "details": "nilfs-utils before 2.0.14 installs multiple programs with unnecessary setuid privileges, which allows local users to execute arbitrary commands via the device string in a -c command line option to mkfs.nilfs2.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pw85-c3xj-rm6m/GHSA-pw85-c3xj-rm6m.json b/advisories/unreviewed/2022/05/GHSA-pw85-c3xj-rm6m/GHSA-pw85-c3xj-rm6m.json index 70331c8bcfc..bc4b2cc3059 100644 --- a/advisories/unreviewed/2022/05/GHSA-pw85-c3xj-rm6m/GHSA-pw85-c3xj-rm6m.json +++ b/advisories/unreviewed/2022/05/GHSA-pw85-c3xj-rm6m/GHSA-pw85-c3xj-rm6m.json @@ -7,12 +7,8 @@ "CVE-2009-3077" ], "details": "Mozilla Firefox before 3.0.14, and 3.5.x before 3.5.3, does not properly manage pointers for the columns (aka TreeColumns) of a XUL tree element, which allows remote attackers to execute arbitrary code via a crafted HTML document, related to a \"dangling pointer vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pwqm-w24q-7cf8/GHSA-pwqm-w24q-7cf8.json b/advisories/unreviewed/2022/05/GHSA-pwqm-w24q-7cf8/GHSA-pwqm-w24q-7cf8.json index 6982badb440..c281c679ab7 100644 --- a/advisories/unreviewed/2022/05/GHSA-pwqm-w24q-7cf8/GHSA-pwqm-w24q-7cf8.json +++ b/advisories/unreviewed/2022/05/GHSA-pwqm-w24q-7cf8/GHSA-pwqm-w24q-7cf8.json @@ -7,12 +7,8 @@ "CVE-2009-2800" ], "details": "Buffer overflow in Alias Manager in Apple Mac OS X 10.4.11 and 10.5.8 allows attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted alias file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pwr9-gcmc-c33f/GHSA-pwr9-gcmc-c33f.json b/advisories/unreviewed/2022/05/GHSA-pwr9-gcmc-c33f/GHSA-pwr9-gcmc-c33f.json index 5646f734dc5..d9c0465d42d 100644 --- a/advisories/unreviewed/2022/05/GHSA-pwr9-gcmc-c33f/GHSA-pwr9-gcmc-c33f.json +++ b/advisories/unreviewed/2022/05/GHSA-pwr9-gcmc-c33f/GHSA-pwr9-gcmc-c33f.json @@ -7,12 +7,8 @@ "CVE-2009-3262" ], "details": "Cross-site scripting (XSS) vulnerability in the Self Service UI (SSUI) in IBM Tivoli Identity Manager (ITIM) 5.0.0.5 allows remote authenticated users to inject arbitrary web script or HTML via the last name field in a profile.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q26v-7829-m2f4/GHSA-q26v-7829-m2f4.json b/advisories/unreviewed/2022/05/GHSA-q26v-7829-m2f4/GHSA-q26v-7829-m2f4.json index bbd5768dc76..aafb335471a 100644 --- a/advisories/unreviewed/2022/05/GHSA-q26v-7829-m2f4/GHSA-q26v-7829-m2f4.json +++ b/advisories/unreviewed/2022/05/GHSA-q26v-7829-m2f4/GHSA-q26v-7829-m2f4.json @@ -7,12 +7,8 @@ "CVE-2009-3064" ], "details": "Directory traversal vulnerability in debugger/debug_php.php in Ve-EDIT 0.1.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the _GET[filename] parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q2wx-p2m8-jggp/GHSA-q2wx-p2m8-jggp.json b/advisories/unreviewed/2022/05/GHSA-q2wx-p2m8-jggp/GHSA-q2wx-p2m8-jggp.json index 2bad5305779..411ce3dd03d 100644 --- a/advisories/unreviewed/2022/05/GHSA-q2wx-p2m8-jggp/GHSA-q2wx-p2m8-jggp.json +++ b/advisories/unreviewed/2022/05/GHSA-q2wx-p2m8-jggp/GHSA-q2wx-p2m8-jggp.json @@ -7,12 +7,8 @@ "CVE-2009-3254" ], "details": "Multiple stack-based buffer overflows in Ultimate Player 1.56 beta allow remote attackers to execute arbitrary code via a long string in a (1) .m3u or (2) .upl playlist file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q4h5-29hc-m9pq/GHSA-q4h5-29hc-m9pq.json b/advisories/unreviewed/2022/05/GHSA-q4h5-29hc-m9pq/GHSA-q4h5-29hc-m9pq.json index 591c551e559..2a20220b980 100644 --- a/advisories/unreviewed/2022/05/GHSA-q4h5-29hc-m9pq/GHSA-q4h5-29hc-m9pq.json +++ b/advisories/unreviewed/2022/05/GHSA-q4h5-29hc-m9pq/GHSA-q4h5-29hc-m9pq.json @@ -7,12 +7,8 @@ "CVE-2009-2707" ], "details": "Unspecified vulnerability in ia32el (aka the IA 32 emulation functionality) before 7042_7022-0.4.2 in SUSE Linux Enterprise (SLE) 10 SP2 on Itanium IA64 machines allows local users to cause a denial of service (system crash) via a 32-bit x86 application.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q553-8j64-v3r6/GHSA-q553-8j64-v3r6.json b/advisories/unreviewed/2022/05/GHSA-q553-8j64-v3r6/GHSA-q553-8j64-v3r6.json index 6aa24630556..b37375f0561 100644 --- a/advisories/unreviewed/2022/05/GHSA-q553-8j64-v3r6/GHSA-q553-8j64-v3r6.json +++ b/advisories/unreviewed/2022/05/GHSA-q553-8j64-v3r6/GHSA-q553-8j64-v3r6.json @@ -7,12 +7,8 @@ "CVE-2009-3151" ], "details": "Directory traversal vulnerability in actions/downloadFile.php in Ultrize TimeSheet 1.2.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the fileName parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q74v-986x-wjxj/GHSA-q74v-986x-wjxj.json b/advisories/unreviewed/2022/05/GHSA-q74v-986x-wjxj/GHSA-q74v-986x-wjxj.json index b1b9744202a..9c7a1878ade 100644 --- a/advisories/unreviewed/2022/05/GHSA-q74v-986x-wjxj/GHSA-q74v-986x-wjxj.json +++ b/advisories/unreviewed/2022/05/GHSA-q74v-986x-wjxj/GHSA-q74v-986x-wjxj.json @@ -7,12 +7,8 @@ "CVE-2009-2787" ], "details": "Directory traversal vulnerability in include/reputation/rep_profile.php in the Reputation plugin 2.2.4, 2.2.3, 2.0.4, and earlier for PunBB, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the pun_user[language] parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q7ch-w2vf-4xmf/GHSA-q7ch-w2vf-4xmf.json b/advisories/unreviewed/2022/05/GHSA-q7ch-w2vf-4xmf/GHSA-q7ch-w2vf-4xmf.json index 74482f4da38..75934f6630d 100644 --- a/advisories/unreviewed/2022/05/GHSA-q7ch-w2vf-4xmf/GHSA-q7ch-w2vf-4xmf.json +++ b/advisories/unreviewed/2022/05/GHSA-q7ch-w2vf-4xmf/GHSA-q7ch-w2vf-4xmf.json @@ -7,12 +7,8 @@ "CVE-2009-2585" ], "details": "SQL injection vulnerability in index.php in Mlffat 2.2 allows remote attackers to execute arbitrary SQL commands via a member cookie in an account editprofile action, a different vector than CVE-2009-1731.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q7cx-49xq-m8xh/GHSA-q7cx-49xq-m8xh.json b/advisories/unreviewed/2022/05/GHSA-q7cx-49xq-m8xh/GHSA-q7cx-49xq-m8xh.json index def5b6ac93a..b3588e82e2c 100644 --- a/advisories/unreviewed/2022/05/GHSA-q7cx-49xq-m8xh/GHSA-q7cx-49xq-m8xh.json +++ b/advisories/unreviewed/2022/05/GHSA-q7cx-49xq-m8xh/GHSA-q7cx-49xq-m8xh.json @@ -7,12 +7,8 @@ "CVE-2009-2995" ], "details": "Integer overflow in Adobe Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows attackers to cause a denial of service via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q7rj-qq3v-v59x/GHSA-q7rj-qq3v-v59x.json b/advisories/unreviewed/2022/05/GHSA-q7rj-qq3v-v59x/GHSA-q7rj-qq3v-v59x.json index 7a2bc4ab749..934b6da6aca 100644 --- a/advisories/unreviewed/2022/05/GHSA-q7rj-qq3v-v59x/GHSA-q7rj-qq3v-v59x.json +++ b/advisories/unreviewed/2022/05/GHSA-q7rj-qq3v-v59x/GHSA-q7rj-qq3v-v59x.json @@ -7,12 +7,8 @@ "CVE-2009-2778" ], "details": "Cross-site scripting (XSS) vulnerability in visitor/view.php in GarageSales Script allows remote attackers to inject arbitrary web script or HTML via the key parameter. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q8g2-q8qr-hf32/GHSA-q8g2-q8qr-hf32.json b/advisories/unreviewed/2022/05/GHSA-q8g2-q8qr-hf32/GHSA-q8g2-q8qr-hf32.json index 3e95c35da03..5fbb8c6de5d 100644 --- a/advisories/unreviewed/2022/05/GHSA-q8g2-q8qr-hf32/GHSA-q8g2-q8qr-hf32.json +++ b/advisories/unreviewed/2022/05/GHSA-q8g2-q8qr-hf32/GHSA-q8g2-q8qr-hf32.json @@ -7,12 +7,8 @@ "CVE-2009-2610" ], "details": "Cross-site scripting (XSS) vulnerability in the Links Related module in the Links Package 5.x before 5.x-1.13 and 6.x before 6.x-1.2, a module for Drupal, allows remote authenticated users to inject arbitrary web script or HTML via the title field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q8w8-xvc3-7pvh/GHSA-q8w8-xvc3-7pvh.json b/advisories/unreviewed/2022/05/GHSA-q8w8-xvc3-7pvh/GHSA-q8w8-xvc3-7pvh.json index 283dadb2a2f..be2ab2caac8 100644 --- a/advisories/unreviewed/2022/05/GHSA-q8w8-xvc3-7pvh/GHSA-q8w8-xvc3-7pvh.json +++ b/advisories/unreviewed/2022/05/GHSA-q8w8-xvc3-7pvh/GHSA-q8w8-xvc3-7pvh.json @@ -7,12 +7,8 @@ "CVE-2009-2839" ], "details": "Screen Sharing in Apple Mac OS X 10.5.8 allows remote VNC servers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q948-rp96-c8w7/GHSA-q948-rp96-c8w7.json b/advisories/unreviewed/2022/05/GHSA-q948-rp96-c8w7/GHSA-q948-rp96-c8w7.json index b21e957f99e..a661a04c66f 100644 --- a/advisories/unreviewed/2022/05/GHSA-q948-rp96-c8w7/GHSA-q948-rp96-c8w7.json +++ b/advisories/unreviewed/2022/05/GHSA-q948-rp96-c8w7/GHSA-q948-rp96-c8w7.json @@ -7,12 +7,8 @@ "CVE-2009-3078" ], "details": "Visual truncation vulnerability in Mozilla Firefox before 3.0.14, and 3.5.x before 3.5.3, allows remote attackers to trigger a vertical scroll and spoof URLs via unspecified Unicode characters with a tall line-height property.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q9x2-fv97-cmpm/GHSA-q9x2-fv97-cmpm.json b/advisories/unreviewed/2022/05/GHSA-q9x2-fv97-cmpm/GHSA-q9x2-fv97-cmpm.json index ddb0a1fca31..2fc2ca8bce4 100644 --- a/advisories/unreviewed/2022/05/GHSA-q9x2-fv97-cmpm/GHSA-q9x2-fv97-cmpm.json +++ b/advisories/unreviewed/2022/05/GHSA-q9x2-fv97-cmpm/GHSA-q9x2-fv97-cmpm.json @@ -7,12 +7,8 @@ "CVE-2009-2993" ], "details": "The JavaScript for Acrobat API in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 does not properly implement the (1) Privileged Context and (2) Safe Path restrictions for unspecified JavaScript methods, which allows remote attackers to create arbitrary files, and possibly execute arbitrary code, via the cPath parameter in a crafted PDF file. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qc9x-m86v-m5v2/GHSA-qc9x-m86v-m5v2.json b/advisories/unreviewed/2022/05/GHSA-qc9x-m86v-m5v2/GHSA-qc9x-m86v-m5v2.json index 2e86a56da86..5d23cfb7531 100644 --- a/advisories/unreviewed/2022/05/GHSA-qc9x-m86v-m5v2/GHSA-qc9x-m86v-m5v2.json +++ b/advisories/unreviewed/2022/05/GHSA-qc9x-m86v-m5v2/GHSA-qc9x-m86v-m5v2.json @@ -7,12 +7,8 @@ "CVE-2009-2722" ], "details": "Multiple unspecified vulnerabilities in the Provider class in Sun Java SE 5.0 before Update 20 have unknown impact and attack vectors, aka BugId 6429594. NOTE: this issue exists because of an incorrect fix for BugId 6406003.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qfrh-wqfx-qwvj/GHSA-qfrh-wqfx-qwvj.json b/advisories/unreviewed/2022/05/GHSA-qfrh-wqfx-qwvj/GHSA-qfrh-wqfx-qwvj.json index d2a2bd714e2..611b63aae1c 100644 --- a/advisories/unreviewed/2022/05/GHSA-qfrh-wqfx-qwvj/GHSA-qfrh-wqfx-qwvj.json +++ b/advisories/unreviewed/2022/05/GHSA-qfrh-wqfx-qwvj/GHSA-qfrh-wqfx-qwvj.json @@ -7,12 +7,8 @@ "CVE-2009-2575" ], "details": "The Research In Motion (RIM) BlackBerry 8800 allows remote attackers to cause a denial of service (memory consumption and browser crash) via a large integer value for the length property of a Select object, a related issue to CVE-2009-1692.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qg5v-qf7r-mg3f/GHSA-qg5v-qf7r-mg3f.json b/advisories/unreviewed/2022/05/GHSA-qg5v-qf7r-mg3f/GHSA-qg5v-qf7r-mg3f.json index e00876e9406..318c2d1feba 100644 --- a/advisories/unreviewed/2022/05/GHSA-qg5v-qf7r-mg3f/GHSA-qg5v-qf7r-mg3f.json +++ b/advisories/unreviewed/2022/05/GHSA-qg5v-qf7r-mg3f/GHSA-qg5v-qf7r-mg3f.json @@ -7,12 +7,8 @@ "CVE-2009-2485" ], "details": "Stack-based buffer overflow in HT-MP3Player 1.0 allows remote attackers to execute arbitrary code via a long string in a .ht3 file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qg85-6mh9-hwpg/GHSA-qg85-6mh9-hwpg.json b/advisories/unreviewed/2022/05/GHSA-qg85-6mh9-hwpg/GHSA-qg85-6mh9-hwpg.json index c9826ea6631..7d8d04e57ec 100644 --- a/advisories/unreviewed/2022/05/GHSA-qg85-6mh9-hwpg/GHSA-qg85-6mh9-hwpg.json +++ b/advisories/unreviewed/2022/05/GHSA-qg85-6mh9-hwpg/GHSA-qg85-6mh9-hwpg.json @@ -7,12 +7,8 @@ "CVE-2009-2986" ], "details": "Multiple heap-based buffer overflows in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 might allow attackers to execute arbitrary code via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qm5r-9c54-3rgj/GHSA-qm5r-9c54-3rgj.json b/advisories/unreviewed/2022/05/GHSA-qm5r-9c54-3rgj/GHSA-qm5r-9c54-3rgj.json index 6afee0b9874..e982cf1c44e 100644 --- a/advisories/unreviewed/2022/05/GHSA-qm5r-9c54-3rgj/GHSA-qm5r-9c54-3rgj.json +++ b/advisories/unreviewed/2022/05/GHSA-qm5r-9c54-3rgj/GHSA-qm5r-9c54-3rgj.json @@ -7,12 +7,8 @@ "CVE-2009-3263" ], "details": "Cross-site scripting (XSS) vulnerability in Google Chrome 2.x and 3.x before 3.0.195.21 allows remote attackers to inject arbitrary web script or HTML via a (1) RSS or (2) Atom feed, related to the rendering of the application/rss+xml content type as XML \"active content.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qmc2-x7wp-66p7/GHSA-qmc2-x7wp-66p7.json b/advisories/unreviewed/2022/05/GHSA-qmc2-x7wp-66p7/GHSA-qmc2-x7wp-66p7.json index f3cb5c21e22..a0fbe7f3c4a 100644 --- a/advisories/unreviewed/2022/05/GHSA-qmc2-x7wp-66p7/GHSA-qmc2-x7wp-66p7.json +++ b/advisories/unreviewed/2022/05/GHSA-qmc2-x7wp-66p7/GHSA-qmc2-x7wp-66p7.json @@ -7,12 +7,8 @@ "CVE-2009-3050" ], "details": "Buffer overflow in the set_page_size function in util.cxx in HTMLDOC 1.8.27 and earlier allows context-dependent attackers to execute arbitrary code via a long MEDIA SIZE comment. NOTE: it was later reported that there were additional vectors in htmllib.cxx and ps-pdf.cxx using an AFM font file with a long glyph name, but these vectors do not cross privilege boundaries.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qq8p-5v5h-rxf8/GHSA-qq8p-5v5h-rxf8.json b/advisories/unreviewed/2022/05/GHSA-qq8p-5v5h-rxf8/GHSA-qq8p-5v5h-rxf8.json index 5c8a683d26f..7d23ecce452 100644 --- a/advisories/unreviewed/2022/05/GHSA-qq8p-5v5h-rxf8/GHSA-qq8p-5v5h-rxf8.json +++ b/advisories/unreviewed/2022/05/GHSA-qq8p-5v5h-rxf8/GHSA-qq8p-5v5h-rxf8.json @@ -7,12 +7,8 @@ "CVE-2009-2528" ], "details": "GDI+ in Microsoft Office XP SP3 does not properly handle malformed objects in Office Art Property Tables, which allows remote attackers to execute arbitrary code via a crafted Office document that triggers memory corruption, aka \"Memory Corruption Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qr4p-ppj7-4xcx/GHSA-qr4p-ppj7-4xcx.json b/advisories/unreviewed/2022/05/GHSA-qr4p-ppj7-4xcx/GHSA-qr4p-ppj7-4xcx.json index 39b4637be9f..3a30157a42c 100644 --- a/advisories/unreviewed/2022/05/GHSA-qr4p-ppj7-4xcx/GHSA-qr4p-ppj7-4xcx.json +++ b/advisories/unreviewed/2022/05/GHSA-qr4p-ppj7-4xcx/GHSA-qr4p-ppj7-4xcx.json @@ -7,12 +7,8 @@ "CVE-2009-3074" ], "details": "Unspecified vulnerability in the JavaScript engine in Mozilla Firefox before 3.0.14 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -72,9 +68,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qvfh-5q7j-hwg7/GHSA-qvfh-5q7j-hwg7.json b/advisories/unreviewed/2022/05/GHSA-qvfh-5q7j-hwg7/GHSA-qvfh-5q7j-hwg7.json index 9c3ec6fa6ec..d53919a30c8 100644 --- a/advisories/unreviewed/2022/05/GHSA-qvfh-5q7j-hwg7/GHSA-qvfh-5q7j-hwg7.json +++ b/advisories/unreviewed/2022/05/GHSA-qvfh-5q7j-hwg7/GHSA-qvfh-5q7j-hwg7.json @@ -7,12 +7,8 @@ "CVE-2009-2618" ], "details": "SQL injection vulnerability in the Surveys (aka NS-Polls) module in MDPro (MD-Pro) 1.083.x allows remote attackers to execute arbitrary SQL commands via the pollID parameter in a results action to modules.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qw75-fm4f-23pq/GHSA-qw75-fm4f-23pq.json b/advisories/unreviewed/2022/05/GHSA-qw75-fm4f-23pq/GHSA-qw75-fm4f-23pq.json index a648cd9da2c..954e19a951e 100644 --- a/advisories/unreviewed/2022/05/GHSA-qw75-fm4f-23pq/GHSA-qw75-fm4f-23pq.json +++ b/advisories/unreviewed/2022/05/GHSA-qw75-fm4f-23pq/GHSA-qw75-fm4f-23pq.json @@ -7,12 +7,8 @@ "CVE-2009-2852" ], "details": "WP-Syntax plugin 0.9.1 and earlier for Wordpress, with register_globals enabled, allows remote attackers to execute arbitrary PHP code via the test_filter[wp_head] array parameter to test/index.php, which is used in a call to the call_user_func_array function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qw9r-fv4r-3v2q/GHSA-qw9r-fv4r-3v2q.json b/advisories/unreviewed/2022/05/GHSA-qw9r-fv4r-3v2q/GHSA-qw9r-fv4r-3v2q.json index 2dec55f0210..132f353cfbd 100644 --- a/advisories/unreviewed/2022/05/GHSA-qw9r-fv4r-3v2q/GHSA-qw9r-fv4r-3v2q.json +++ b/advisories/unreviewed/2022/05/GHSA-qw9r-fv4r-3v2q/GHSA-qw9r-fv4r-3v2q.json @@ -7,12 +7,8 @@ "CVE-2009-2609" ], "details": "SQL injection vulnerability in the amoCourse (com_amocourse) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a category action to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r225-cxcj-p2r4/GHSA-r225-cxcj-p2r4.json b/advisories/unreviewed/2022/05/GHSA-r225-cxcj-p2r4/GHSA-r225-cxcj-p2r4.json index d48524e8a12..dcb32359011 100644 --- a/advisories/unreviewed/2022/05/GHSA-r225-cxcj-p2r4/GHSA-r225-cxcj-p2r4.json +++ b/advisories/unreviewed/2022/05/GHSA-r225-cxcj-p2r4/GHSA-r225-cxcj-p2r4.json @@ -7,12 +7,8 @@ "CVE-2009-2607" ], "details": "SQL injection vulnerability in the com_pinboard component for Joomla! allows remote attackers to execute arbitrary SQL commands via the task parameter in a showpic action to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r255-8m9g-49h6/GHSA-r255-8m9g-49h6.json b/advisories/unreviewed/2022/05/GHSA-r255-8m9g-49h6/GHSA-r255-8m9g-49h6.json index 90e347fc16b..6692d96a3bd 100644 --- a/advisories/unreviewed/2022/05/GHSA-r255-8m9g-49h6/GHSA-r255-8m9g-49h6.json +++ b/advisories/unreviewed/2022/05/GHSA-r255-8m9g-49h6/GHSA-r255-8m9g-49h6.json @@ -7,12 +7,8 @@ "CVE-2009-2612" ], "details": "SQL injection vulnerability in login.aspx in ProSMDR allows remote attackers to execute arbitrary SQL commands via the txtUser parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r2mm-qr53-2j54/GHSA-r2mm-qr53-2j54.json b/advisories/unreviewed/2022/05/GHSA-r2mm-qr53-2j54/GHSA-r2mm-qr53-2j54.json index 41faf2e55bc..2e8477c02f2 100644 --- a/advisories/unreviewed/2022/05/GHSA-r2mm-qr53-2j54/GHSA-r2mm-qr53-2j54.json +++ b/advisories/unreviewed/2022/05/GHSA-r2mm-qr53-2j54/GHSA-r2mm-qr53-2j54.json @@ -7,12 +7,8 @@ "CVE-2009-2863" ], "details": "Race condition in the Firewall Authentication Proxy feature in Cisco IOS 12.0 through 12.4 allows remote attackers to bypass authentication, or bypass the consent web page, via a crafted request, aka Bug ID CSCsy15227.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r342-j66c-57vp/GHSA-r342-j66c-57vp.json b/advisories/unreviewed/2022/05/GHSA-r342-j66c-57vp/GHSA-r342-j66c-57vp.json index a4db8944967..c9fa3881974 100644 --- a/advisories/unreviewed/2022/05/GHSA-r342-j66c-57vp/GHSA-r342-j66c-57vp.json +++ b/advisories/unreviewed/2022/05/GHSA-r342-j66c-57vp/GHSA-r342-j66c-57vp.json @@ -7,12 +7,8 @@ "CVE-2009-2997" ], "details": "Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 might allow attackers to execute arbitrary code via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r52r-p4hh-9m3j/GHSA-r52r-p4hh-9m3j.json b/advisories/unreviewed/2022/05/GHSA-r52r-p4hh-9m3j/GHSA-r52r-p4hh-9m3j.json index 36bad45527e..42d1eed6070 100644 --- a/advisories/unreviewed/2022/05/GHSA-r52r-p4hh-9m3j/GHSA-r52r-p4hh-9m3j.json +++ b/advisories/unreviewed/2022/05/GHSA-r52r-p4hh-9m3j/GHSA-r52r-p4hh-9m3j.json @@ -7,12 +7,8 @@ "CVE-2009-2663" ], "details": "libvorbis before r16182, as used in Mozilla Firefox 3.5.x before 3.5.2 and other products, allows context-dependent attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted .ogg file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -96,9 +92,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r55x-r82c-hmq3/GHSA-r55x-r82c-hmq3.json b/advisories/unreviewed/2022/05/GHSA-r55x-r82c-hmq3/GHSA-r55x-r82c-hmq3.json index 350480fc951..70bc98e854e 100644 --- a/advisories/unreviewed/2022/05/GHSA-r55x-r82c-hmq3/GHSA-r55x-r82c-hmq3.json +++ b/advisories/unreviewed/2022/05/GHSA-r55x-r82c-hmq3/GHSA-r55x-r82c-hmq3.json @@ -7,12 +7,8 @@ "CVE-2009-2715" ], "details": "Sun VirtualBox 2.2 through 3.0.2 r49928 allows guest OS users to cause a denial of service (Linux host OS reboot) via a sysenter instruction.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r57q-vf22-h8mx/GHSA-r57q-vf22-h8mx.json b/advisories/unreviewed/2022/05/GHSA-r57q-vf22-h8mx/GHSA-r57q-vf22-h8mx.json index 51da097ac82..3156ce053f7 100644 --- a/advisories/unreviewed/2022/05/GHSA-r57q-vf22-h8mx/GHSA-r57q-vf22-h8mx.json +++ b/advisories/unreviewed/2022/05/GHSA-r57q-vf22-h8mx/GHSA-r57q-vf22-h8mx.json @@ -7,12 +7,8 @@ "CVE-2009-2917" ], "details": "Stack-based buffer overflow in ImTOO MPEG Encoder 3.1.53 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted string in a (1) .cue or (2) .m3u playlist file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r6xq-p57g-7q8p/GHSA-r6xq-p57g-7q8p.json b/advisories/unreviewed/2022/05/GHSA-r6xq-p57g-7q8p/GHSA-r6xq-p57g-7q8p.json index 6e4c2317b8b..86d4876268c 100644 --- a/advisories/unreviewed/2022/05/GHSA-r6xq-p57g-7q8p/GHSA-r6xq-p57g-7q8p.json +++ b/advisories/unreviewed/2022/05/GHSA-r6xq-p57g-7q8p/GHSA-r6xq-p57g-7q8p.json @@ -7,12 +7,8 @@ "CVE-2009-2736" ], "details": "Static code injection vulnerability in admin.php in sun-jester OpenNews 1.0 allows remote authenticated administrators to inject arbitrary PHP code into config.php via the \"Overall Width\" field in a setconfig action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r78g-mr95-6qvw/GHSA-r78g-mr95-6qvw.json b/advisories/unreviewed/2022/05/GHSA-r78g-mr95-6qvw/GHSA-r78g-mr95-6qvw.json index d75151beafe..4c5e04bf79a 100644 --- a/advisories/unreviewed/2022/05/GHSA-r78g-mr95-6qvw/GHSA-r78g-mr95-6qvw.json +++ b/advisories/unreviewed/2022/05/GHSA-r78g-mr95-6qvw/GHSA-r78g-mr95-6qvw.json @@ -7,12 +7,8 @@ "CVE-2009-2870" ], "details": "Unspecified vulnerability in Cisco IOS 12.2 through 12.4, when the Cisco Unified Border Element feature is enabled, allows remote attackers to cause a denial of service (device reload) via crafted SIP messages, aka Bug ID CSCsx25880.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rfjx-v478-qccr/GHSA-rfjx-v478-qccr.json b/advisories/unreviewed/2022/05/GHSA-rfjx-v478-qccr/GHSA-rfjx-v478-qccr.json index a3b0aa33a61..f575ee206ad 100644 --- a/advisories/unreviewed/2022/05/GHSA-rfjx-v478-qccr/GHSA-rfjx-v478-qccr.json +++ b/advisories/unreviewed/2022/05/GHSA-rfjx-v478-qccr/GHSA-rfjx-v478-qccr.json @@ -7,12 +7,8 @@ "CVE-2009-2827" ], "details": "Heap-based buffer overflow in Disk Images in Apple Mac OS X 10.5.8 allows user-assisted remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted FAT filesystem on a disk image.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rfmf-5g8q-mw3m/GHSA-rfmf-5g8q-mw3m.json b/advisories/unreviewed/2022/05/GHSA-rfmf-5g8q-mw3m/GHSA-rfmf-5g8q-mw3m.json index 69239b02935..7c56276d922 100644 --- a/advisories/unreviewed/2022/05/GHSA-rfmf-5g8q-mw3m/GHSA-rfmf-5g8q-mw3m.json +++ b/advisories/unreviewed/2022/05/GHSA-rfmf-5g8q-mw3m/GHSA-rfmf-5g8q-mw3m.json @@ -7,12 +7,8 @@ "CVE-2009-1530" ], "details": "Use-after-free vulnerability in Microsoft Internet Explorer 7 for Windows XP SP2 and SP3; 7 for Server 2003 SP2; 7 for Vista Gold, SP1, and SP2; and 7 for Server 2008 SP2 allows remote attackers to execute arbitrary code by repeatedly adding HTML document nodes and calling event handlers, which triggers an access of an object that (1) was not properly initialized or (2) is deleted, aka \"HTML Objects Memory Corruption Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rfx5-q6vf-4479/GHSA-rfx5-q6vf-4479.json b/advisories/unreviewed/2022/05/GHSA-rfx5-q6vf-4479/GHSA-rfx5-q6vf-4479.json index 22fe31f103c..5f7a05fba2a 100644 --- a/advisories/unreviewed/2022/05/GHSA-rfx5-q6vf-4479/GHSA-rfx5-q6vf-4479.json +++ b/advisories/unreviewed/2022/05/GHSA-rfx5-q6vf-4479/GHSA-rfx5-q6vf-4479.json @@ -7,12 +7,8 @@ "CVE-2009-2713" ], "details": "The CDCServlet component in Sun Java System Access Manager 7.0 2005Q4 and 7.1, when Cross Domain Single Sign On (CDSSO) is enabled, does not ensure that \"policy advice\" is presented to the correct client, which allows remote attackers to obtain sensitive information via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rj7f-q6x3-vwg7/GHSA-rj7f-q6x3-vwg7.json b/advisories/unreviewed/2022/05/GHSA-rj7f-q6x3-vwg7/GHSA-rj7f-q6x3-vwg7.json index b9861c5f897..875a048a061 100644 --- a/advisories/unreviewed/2022/05/GHSA-rj7f-q6x3-vwg7/GHSA-rj7f-q6x3-vwg7.json +++ b/advisories/unreviewed/2022/05/GHSA-rj7f-q6x3-vwg7/GHSA-rj7f-q6x3-vwg7.json @@ -7,12 +7,8 @@ "CVE-2009-2683" ], "details": "Unspecified vulnerability in the Sender module in HP Remote Graphics Software (RGS) 5.1.3 through 5.2.6 allows remote authenticated users to execute arbitrary code via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rm8m-2mmh-c8h3/GHSA-rm8m-2mmh-c8h3.json b/advisories/unreviewed/2022/05/GHSA-rm8m-2mmh-c8h3/GHSA-rm8m-2mmh-c8h3.json index f30986f3b65..ec9485a4e7e 100644 --- a/advisories/unreviewed/2022/05/GHSA-rm8m-2mmh-c8h3/GHSA-rm8m-2mmh-c8h3.json +++ b/advisories/unreviewed/2022/05/GHSA-rm8m-2mmh-c8h3/GHSA-rm8m-2mmh-c8h3.json @@ -7,12 +7,8 @@ "CVE-2009-2893" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in index.php in XZero Community Classifieds 4.97.8 allow remote attackers to inject arbitrary web script or HTML via (1) the postevent parameter in a post action or (2) the _xzcal_y parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rmc4-f8mw-xvqf/GHSA-rmc4-f8mw-xvqf.json b/advisories/unreviewed/2022/05/GHSA-rmc4-f8mw-xvqf/GHSA-rmc4-f8mw-xvqf.json index 3cd85475455..f7e3da2d7e8 100644 --- a/advisories/unreviewed/2022/05/GHSA-rmc4-f8mw-xvqf/GHSA-rmc4-f8mw-xvqf.json +++ b/advisories/unreviewed/2022/05/GHSA-rmc4-f8mw-xvqf/GHSA-rmc4-f8mw-xvqf.json @@ -7,12 +7,8 @@ "CVE-2009-3093" ], "details": "Unspecified vulnerability on the ASUS WL-500W wireless router has unknown impact and remote attack vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.11. NOTE: as of 20090903, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rmfm-r95f-f779/GHSA-rmfm-r95f-f779.json b/advisories/unreviewed/2022/05/GHSA-rmfm-r95f-f779/GHSA-rmfm-r95f-f779.json index 3181f07faea..b8151d7b32b 100644 --- a/advisories/unreviewed/2022/05/GHSA-rmfm-r95f-f779/GHSA-rmfm-r95f-f779.json +++ b/advisories/unreviewed/2022/05/GHSA-rmfm-r95f-f779/GHSA-rmfm-r95f-f779.json @@ -7,12 +7,8 @@ "CVE-2009-3240" ], "details": "Cross-site scripting (XSS) vulnerability in the Happy Linux XF-Section module 1.12a for XOOPS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rmg4-9v3x-2qvv/GHSA-rmg4-9v3x-2qvv.json b/advisories/unreviewed/2022/05/GHSA-rmg4-9v3x-2qvv/GHSA-rmg4-9v3x-2qvv.json index a1fb57cd099..96d1134fac0 100644 --- a/advisories/unreviewed/2022/05/GHSA-rmg4-9v3x-2qvv/GHSA-rmg4-9v3x-2qvv.json +++ b/advisories/unreviewed/2022/05/GHSA-rmg4-9v3x-2qvv/GHSA-rmg4-9v3x-2qvv.json @@ -7,12 +7,8 @@ "CVE-2009-2690" ], "details": "The encoder in Sun Java SE 6 before Update 15, and OpenJDK, grants read access to private variables with unspecified names, which allows context-dependent attackers to obtain sensitive information via an untrusted (1) applet or (2) application.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -88,9 +84,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rmwh-hpr4-xw72/GHSA-rmwh-hpr4-xw72.json b/advisories/unreviewed/2022/05/GHSA-rmwh-hpr4-xw72/GHSA-rmwh-hpr4-xw72.json index 7101800a8c2..5435642df36 100644 --- a/advisories/unreviewed/2022/05/GHSA-rmwh-hpr4-xw72/GHSA-rmwh-hpr4-xw72.json +++ b/advisories/unreviewed/2022/05/GHSA-rmwh-hpr4-xw72/GHSA-rmwh-hpr4-xw72.json @@ -7,12 +7,8 @@ "CVE-2009-2596" ], "details": "Unspecified vulnerability in the Solaris Auditing subsystem in Sun Solaris 9 and 10 and OpenSolaris before snv_121, when extended file attributes are used, allows local users to cause a denial of service (panic) via vectors related to fad_aupath structure members.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rp94-92gp-7q47/GHSA-rp94-92gp-7q47.json b/advisories/unreviewed/2022/05/GHSA-rp94-92gp-7q47/GHSA-rp94-92gp-7q47.json index 6f28c90254d..7d3aad24ca7 100644 --- a/advisories/unreviewed/2022/05/GHSA-rp94-92gp-7q47/GHSA-rp94-92gp-7q47.json +++ b/advisories/unreviewed/2022/05/GHSA-rp94-92gp-7q47/GHSA-rp94-92gp-7q47.json @@ -7,12 +7,8 @@ "CVE-2009-2620" ], "details": "src/remote/server.cpp in fbserver.exe in Firebird SQL 1.5 before 1.5.6, 2.0 before 2.0.6, 2.1 before 2.1.3, and 2.5 before 2.5 Beta 2 allows remote attackers to cause a denial of service (daemon crash) via a malformed op_connect_request message that triggers an infinite loop or NULL pointer dereference.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rpqw-5g6j-x944/GHSA-rpqw-5g6j-x944.json b/advisories/unreviewed/2022/05/GHSA-rpqw-5g6j-x944/GHSA-rpqw-5g6j-x944.json index 8342f5ac9c1..f1827a342eb 100644 --- a/advisories/unreviewed/2022/05/GHSA-rpqw-5g6j-x944/GHSA-rpqw-5g6j-x944.json +++ b/advisories/unreviewed/2022/05/GHSA-rpqw-5g6j-x944/GHSA-rpqw-5g6j-x944.json @@ -7,12 +7,8 @@ "CVE-2009-2939" ], "details": "The postfix.postinst script in the Debian GNU/Linux and Ubuntu postfix 2.5.5 package grants the postfix user write access to /var/spool/postfix/pid, which might allow local users to conduct symlink attacks that overwrite arbitrary files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rqh9-p568-89pc/GHSA-rqh9-p568-89pc.json b/advisories/unreviewed/2022/05/GHSA-rqh9-p568-89pc/GHSA-rqh9-p568-89pc.json index 4496308693a..26ef22a5c9a 100644 --- a/advisories/unreviewed/2022/05/GHSA-rqh9-p568-89pc/GHSA-rqh9-p568-89pc.json +++ b/advisories/unreviewed/2022/05/GHSA-rqh9-p568-89pc/GHSA-rqh9-p568-89pc.json @@ -7,12 +7,8 @@ "CVE-2009-2990" ], "details": "Array index error in Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 might allow attackers to execute arbitrary code via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rqj4-c3wm-wm5p/GHSA-rqj4-c3wm-wm5p.json b/advisories/unreviewed/2022/05/GHSA-rqj4-c3wm-wm5p/GHSA-rqj4-c3wm-wm5p.json index 71afe58db8c..148761a5f90 100644 --- a/advisories/unreviewed/2022/05/GHSA-rqj4-c3wm-wm5p/GHSA-rqj4-c3wm-wm5p.json +++ b/advisories/unreviewed/2022/05/GHSA-rqj4-c3wm-wm5p/GHSA-rqj4-c3wm-wm5p.json @@ -7,12 +7,8 @@ "CVE-2009-2892" ], "details": "Multiple SQL injection vulnerabilities in header.php in Scripteen Free Image Hosting Script 2.3 allow remote attackers to execute arbitrary SQL commands via a (1) cookid or (2) cookgid cookie.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rr84-5976-78qm/GHSA-rr84-5976-78qm.json b/advisories/unreviewed/2022/05/GHSA-rr84-5976-78qm/GHSA-rr84-5976-78qm.json index c52ab7d13fc..378a039c1b2 100644 --- a/advisories/unreviewed/2022/05/GHSA-rr84-5976-78qm/GHSA-rr84-5976-78qm.json +++ b/advisories/unreviewed/2022/05/GHSA-rr84-5976-78qm/GHSA-rr84-5976-78qm.json @@ -7,12 +7,8 @@ "CVE-2009-2578" ], "details": "Google Chrome 2.x through 2.0.172 allows remote attackers to cause a denial of service (application crash) via a long Unicode string argument to the write method, a related issue to CVE-2009-2479.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rrgw-j47c-56cm/GHSA-rrgw-j47c-56cm.json b/advisories/unreviewed/2022/05/GHSA-rrgw-j47c-56cm/GHSA-rrgw-j47c-56cm.json index a742e32c4bd..e317ded0b8b 100644 --- a/advisories/unreviewed/2022/05/GHSA-rrgw-j47c-56cm/GHSA-rrgw-j47c-56cm.json +++ b/advisories/unreviewed/2022/05/GHSA-rrgw-j47c-56cm/GHSA-rrgw-j47c-56cm.json @@ -7,12 +7,8 @@ "CVE-2009-2826" ], "details": "Multiple integer overflows in CoreGraphics in Apple Mac OS X 10.5.8 allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document that triggers a heap-based buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rrp5-fpqr-wrqg/GHSA-rrp5-fpqr-wrqg.json b/advisories/unreviewed/2022/05/GHSA-rrp5-fpqr-wrqg/GHSA-rrp5-fpqr-wrqg.json index 2d4ac245f6a..48aeb8009b4 100644 --- a/advisories/unreviewed/2022/05/GHSA-rrp5-fpqr-wrqg/GHSA-rrp5-fpqr-wrqg.json +++ b/advisories/unreviewed/2022/05/GHSA-rrp5-fpqr-wrqg/GHSA-rrp5-fpqr-wrqg.json @@ -7,12 +7,8 @@ "CVE-2009-2841" ], "details": "The HTMLMediaElement::loadResource function in html/HTMLMediaElement.cpp in WebCore in WebKit before r49480, as used in Apple Safari before 4.0.4 on Mac OS X, does not perform the expected callbacks for HTML 5 media elements that have external URLs for media resources, which allows remote attackers to trigger sub-resource requests to arbitrary web sites via a crafted HTML document, as demonstrated by an HTML e-mail message that uses a media element for X-Confirm-Reading-To functionality, aka rdar problem 7271202.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -120,9 +116,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rvj3-q4fm-jvxg/GHSA-rvj3-q4fm-jvxg.json b/advisories/unreviewed/2022/05/GHSA-rvj3-q4fm-jvxg/GHSA-rvj3-q4fm-jvxg.json index 4fd9a833887..4c61cb44392 100644 --- a/advisories/unreviewed/2022/05/GHSA-rvj3-q4fm-jvxg/GHSA-rvj3-q4fm-jvxg.json +++ b/advisories/unreviewed/2022/05/GHSA-rvj3-q4fm-jvxg/GHSA-rvj3-q4fm-jvxg.json @@ -7,12 +7,8 @@ "CVE-2009-2809" ], "details": "ImageIO in Apple Mac OS X 10.4.11 and 10.5.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PixarFilm encoded TIFF image, related to \"multiple memory corruption issues.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rw8c-5h56-67gx/GHSA-rw8c-5h56-67gx.json b/advisories/unreviewed/2022/05/GHSA-rw8c-5h56-67gx/GHSA-rw8c-5h56-67gx.json index 45430e36dc7..cbc94129344 100644 --- a/advisories/unreviewed/2022/05/GHSA-rw8c-5h56-67gx/GHSA-rw8c-5h56-67gx.json +++ b/advisories/unreviewed/2022/05/GHSA-rw8c-5h56-67gx/GHSA-rw8c-5h56-67gx.json @@ -7,12 +7,8 @@ "CVE-2009-2527" ], "details": "Heap-based buffer overflow in Microsoft Windows Media Player 6.4 allows remote attackers to execute arbitrary code via (1) a crafted ASF file or (2) crafted streaming content, aka \"WMP Heap Overflow Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rwhr-7jwv-p44r/GHSA-rwhr-7jwv-p44r.json b/advisories/unreviewed/2022/05/GHSA-rwhr-7jwv-p44r/GHSA-rwhr-7jwv-p44r.json index 550aa9bd6fb..97d2bfb8dbc 100644 --- a/advisories/unreviewed/2022/05/GHSA-rwhr-7jwv-p44r/GHSA-rwhr-7jwv-p44r.json +++ b/advisories/unreviewed/2022/05/GHSA-rwhr-7jwv-p44r/GHSA-rwhr-7jwv-p44r.json @@ -7,12 +7,8 @@ "CVE-2009-2684" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Jetdirect and the Embedded Web Server (EWS) on certain HP LaserJet and Color LaserJet printers, and HP Digital Senders, allow remote attackers to inject arbitrary web script or HTML via the (1) Product_URL or (2) Tech_URL parameter in an Apply action to the support_param.html/config script.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rwv5-x4xj-5577/GHSA-rwv5-x4xj-5577.json b/advisories/unreviewed/2022/05/GHSA-rwv5-x4xj-5577/GHSA-rwv5-x4xj-5577.json index 680dc244694..2c0bd8d4285 100644 --- a/advisories/unreviewed/2022/05/GHSA-rwv5-x4xj-5577/GHSA-rwv5-x4xj-5577.json +++ b/advisories/unreviewed/2022/05/GHSA-rwv5-x4xj-5577/GHSA-rwv5-x4xj-5577.json @@ -7,12 +7,8 @@ "CVE-2009-2811" ], "details": "Incomplete blacklist vulnerability in Launch Services in Apple Mac OS X 10.5.8 allows user-assisted remote attackers to execute arbitrary code via a .fileloc file, which does not trigger a \"potentially unsafe\" warning message in the Quarantine feature.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rx5h-whxq-fw7x/GHSA-rx5h-whxq-fw7x.json b/advisories/unreviewed/2022/05/GHSA-rx5h-whxq-fw7x/GHSA-rx5h-whxq-fw7x.json index c79cd311775..ba59f3f5892 100644 --- a/advisories/unreviewed/2022/05/GHSA-rx5h-whxq-fw7x/GHSA-rx5h-whxq-fw7x.json +++ b/advisories/unreviewed/2022/05/GHSA-rx5h-whxq-fw7x/GHSA-rx5h-whxq-fw7x.json @@ -7,12 +7,8 @@ "CVE-2009-2937" ], "details": "Cross-site scripting (XSS) vulnerability in Planet 2.0 and Planet Venus allows remote attackers to inject arbitrary web script or HTML via the SRC attribute of an IMG element in a feed.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rxg7-q89w-fj88/GHSA-rxg7-q89w-fj88.json b/advisories/unreviewed/2022/05/GHSA-rxg7-q89w-fj88/GHSA-rxg7-q89w-fj88.json index 27864e8cdf2..8340891810b 100644 --- a/advisories/unreviewed/2022/05/GHSA-rxg7-q89w-fj88/GHSA-rxg7-q89w-fj88.json +++ b/advisories/unreviewed/2022/05/GHSA-rxg7-q89w-fj88/GHSA-rxg7-q89w-fj88.json @@ -7,12 +7,8 @@ "CVE-2009-2507" ], "details": "A certain ActiveX control in the Indexing Service in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not properly process URLs, which allows remote attackers to execute arbitrary programs via unspecified vectors that cause a \"vulnerable binary\" to load and run, aka \"Memory Corruption in Indexing Service Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v23q-c79q-8w79/GHSA-v23q-c79q-8w79.json b/advisories/unreviewed/2022/05/GHSA-v23q-c79q-8w79/GHSA-v23q-c79q-8w79.json index 9b693a751f1..1e38a8cda9f 100644 --- a/advisories/unreviewed/2022/05/GHSA-v23q-c79q-8w79/GHSA-v23q-c79q-8w79.json +++ b/advisories/unreviewed/2022/05/GHSA-v23q-c79q-8w79/GHSA-v23q-c79q-8w79.json @@ -7,12 +7,8 @@ "CVE-2009-2773" ], "details": "PHP remote file inclusion vulnerability in home.php in PHP Paid 4 Mail Script allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v26c-6f8f-q8r8/GHSA-v26c-6f8f-q8r8.json b/advisories/unreviewed/2022/05/GHSA-v26c-6f8f-q8r8/GHSA-v26c-6f8f-q8r8.json index 2ea3029b200..1c74f0d7a69 100644 --- a/advisories/unreviewed/2022/05/GHSA-v26c-6f8f-q8r8/GHSA-v26c-6f8f-q8r8.json +++ b/advisories/unreviewed/2022/05/GHSA-v26c-6f8f-q8r8/GHSA-v26c-6f8f-q8r8.json @@ -7,12 +7,8 @@ "CVE-2009-2704" ], "details": "CA SiteMinder allows remote attackers to bypass cross-site scripting (XSS) protections for J2EE applications via a request containing a %00 (encoded null byte).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v3g3-537w-5x73/GHSA-v3g3-537w-5x73.json b/advisories/unreviewed/2022/05/GHSA-v3g3-537w-5x73/GHSA-v3g3-537w-5x73.json index c5d5d615d6d..ddb4f21d333 100644 --- a/advisories/unreviewed/2022/05/GHSA-v3g3-537w-5x73/GHSA-v3g3-537w-5x73.json +++ b/advisories/unreviewed/2022/05/GHSA-v3g3-537w-5x73/GHSA-v3g3-537w-5x73.json @@ -7,12 +7,8 @@ "CVE-2009-3052" ], "details": "SQL injection vulnerability in root/includes/prime_quick_style.php in the Prime Quick Style addon before 1.2.3 for phpBB 3 allows remote authenticated users to execute arbitrary SQL commands via the prime_quick_style parameter to ucp.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v47c-w69f-367c/GHSA-v47c-w69f-367c.json b/advisories/unreviewed/2022/05/GHSA-v47c-w69f-367c/GHSA-v47c-w69f-367c.json index b1cbc07fb39..08fc1868799 100644 --- a/advisories/unreviewed/2022/05/GHSA-v47c-w69f-367c/GHSA-v47c-w69f-367c.json +++ b/advisories/unreviewed/2022/05/GHSA-v47c-w69f-367c/GHSA-v47c-w69f-367c.json @@ -7,12 +7,8 @@ "CVE-2009-2703" ], "details": "libpurple/protocols/irc/msgs.c in the IRC protocol plugin in libpurple in Pidgin before 2.6.2 allows remote IRC servers to cause a denial of service (NULL pointer dereference and application crash) via a TOPIC message that lacks a topic string.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v4f3-hhwx-g6v9/GHSA-v4f3-hhwx-g6v9.json b/advisories/unreviewed/2022/05/GHSA-v4f3-hhwx-g6v9/GHSA-v4f3-hhwx-g6v9.json index 9f9a569f732..345ae79d3a7 100644 --- a/advisories/unreviewed/2022/05/GHSA-v4f3-hhwx-g6v9/GHSA-v4f3-hhwx-g6v9.json +++ b/advisories/unreviewed/2022/05/GHSA-v4f3-hhwx-g6v9/GHSA-v4f3-hhwx-g6v9.json @@ -7,12 +7,8 @@ "CVE-2009-3096" ], "details": "Multiple unspecified vulnerabilities in HP Performance Insight 5.3 allow remote attackers to have an unknown impact, related to (1) a \"Remote exploit\" on Windows platforms, and (2) a \"Remote preauthentication exploit\" on the Windows Server 2003 SP2 platform, as demonstrated by certain modules in VulnDisco Pack Professional 8.11. NOTE: as of 20090903, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v57f-xgqq-m484/GHSA-v57f-xgqq-m484.json b/advisories/unreviewed/2022/05/GHSA-v57f-xgqq-m484/GHSA-v57f-xgqq-m484.json index b2e2d77f517..d3f34373a41 100644 --- a/advisories/unreviewed/2022/05/GHSA-v57f-xgqq-m484/GHSA-v57f-xgqq-m484.json +++ b/advisories/unreviewed/2022/05/GHSA-v57f-xgqq-m484/GHSA-v57f-xgqq-m484.json @@ -7,12 +7,8 @@ "CVE-2009-3062" ], "details": "SQL injection vulnerability in message_box.php in OSI Codes PHP Live! 3.3 allows remote attackers to execute arbitrary SQL commands via the deptid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v58x-whgv-c2w3/GHSA-v58x-whgv-c2w3.json b/advisories/unreviewed/2022/05/GHSA-v58x-whgv-c2w3/GHSA-v58x-whgv-c2w3.json index c685f20339a..a1bdfe54abf 100644 --- a/advisories/unreviewed/2022/05/GHSA-v58x-whgv-c2w3/GHSA-v58x-whgv-c2w3.json +++ b/advisories/unreviewed/2022/05/GHSA-v58x-whgv-c2w3/GHSA-v58x-whgv-c2w3.json @@ -7,12 +7,8 @@ "CVE-2009-2976" ], "details": "Cisco Aironet Lightweight Access Point (AP) devices send the contents of certain multicast data frames in cleartext, which allows remote attackers to discover Wireless LAN Controller MAC addresses and IP addresses, and AP configuration details, by sniffing the wireless network.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v5qv-p4x6-222f/GHSA-v5qv-p4x6-222f.json b/advisories/unreviewed/2022/05/GHSA-v5qv-p4x6-222f/GHSA-v5qv-p4x6-222f.json index 85d8ba86054..4238538dddd 100644 --- a/advisories/unreviewed/2022/05/GHSA-v5qv-p4x6-222f/GHSA-v5qv-p4x6-222f.json +++ b/advisories/unreviewed/2022/05/GHSA-v5qv-p4x6-222f/GHSA-v5qv-p4x6-222f.json @@ -7,12 +7,8 @@ "CVE-2009-2497" ], "details": "The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0, 2.0 SP1, 2.0 SP2, 3.5, and 3.5 SP1, and Silverlight 2, does not properly handle interfaces, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP), (2) a crafted Silverlight application, (3) a crafted ASP.NET application, or (4) a crafted .NET Framework application, aka \"Microsoft Silverlight and Microsoft .NET Framework CLR Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v78g-r5jj-c2v7/GHSA-v78g-r5jj-c2v7.json b/advisories/unreviewed/2022/05/GHSA-v78g-r5jj-c2v7/GHSA-v78g-r5jj-c2v7.json index 240b34e9707..4da8462ed1e 100644 --- a/advisories/unreviewed/2022/05/GHSA-v78g-r5jj-c2v7/GHSA-v78g-r5jj-c2v7.json +++ b/advisories/unreviewed/2022/05/GHSA-v78g-r5jj-c2v7/GHSA-v78g-r5jj-c2v7.json @@ -7,12 +7,8 @@ "CVE-2009-3018" ], "details": "Maxthon Browser 3.0.0.145 Alpha with Ultramode does not properly block javascript: and data: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header that contains a javascript: URI, (2) entering a javascript: URI when specifying the content of a Refresh header, (3) injecting a Refresh header that contains JavaScript sequences in a data:text/html URI, or (4) entering a data:text/html URI with JavaScript sequences when specifying the content of a Refresh header; does not properly block data: URIs in Location headers in HTTP responses, which allows user-assisted remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (5) injecting a Location header that contains JavaScript sequences in a data:text/html URI or (6) entering a data:text/html URI with JavaScript sequences when specifying the content of a Location header; and does not properly handle javascript: URIs in HTML links within (a) 301 and (b) 302 error documents sent from web servers, which allows user-assisted remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (7) injecting a Location HTTP response header or (8) specifying the content of a Location HTTP response header.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v894-3cgg-cmcx/GHSA-v894-3cgg-cmcx.json b/advisories/unreviewed/2022/05/GHSA-v894-3cgg-cmcx/GHSA-v894-3cgg-cmcx.json index 784abb8ab3c..0243b86080c 100644 --- a/advisories/unreviewed/2022/05/GHSA-v894-3cgg-cmcx/GHSA-v894-3cgg-cmcx.json +++ b/advisories/unreviewed/2022/05/GHSA-v894-3cgg-cmcx/GHSA-v894-3cgg-cmcx.json @@ -7,12 +7,8 @@ "CVE-2009-3257" ], "details": "vtiger CRM before 5.1.0 allows remote authenticated users to bypass the permissions on the (1) Account Billing Address and (2) Shipping Address fields in a profile by creating a Sales Order (SO) associated with that profile.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v9wf-6v95-96rm/GHSA-v9wf-6v95-96rm.json b/advisories/unreviewed/2022/05/GHSA-v9wf-6v95-96rm/GHSA-v9wf-6v95-96rm.json index 5f4f3b41eb0..68371cca927 100644 --- a/advisories/unreviewed/2022/05/GHSA-v9wf-6v95-96rm/GHSA-v9wf-6v95-96rm.json +++ b/advisories/unreviewed/2022/05/GHSA-v9wf-6v95-96rm/GHSA-v9wf-6v95-96rm.json @@ -7,12 +7,8 @@ "CVE-2009-3051" ], "details": "Multiple format string vulnerabilities in lib/silcclient/client_entry.c in Secure Internet Live Conferencing (SILC) Toolkit before 1.1.10, and SILC Client before 1.1.8, allow remote attackers to execute arbitrary code via format string specifiers in a nickname field, related to the (1) silc_client_add_client, (2) silc_client_update_client, and (3) silc_client_nickname_format functions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vf98-38qc-3w28/GHSA-vf98-38qc-3w28.json b/advisories/unreviewed/2022/05/GHSA-vf98-38qc-3w28/GHSA-vf98-38qc-3w28.json index 1fdb818fec1..2d5e59315d9 100644 --- a/advisories/unreviewed/2022/05/GHSA-vf98-38qc-3w28/GHSA-vf98-38qc-3w28.json +++ b/advisories/unreviewed/2022/05/GHSA-vf98-38qc-3w28/GHSA-vf98-38qc-3w28.json @@ -7,12 +7,8 @@ "CVE-2009-2697" ], "details": "The Red Hat build script for the GNOME Display Manager (GDM) before 2.16.0-56 on Red Hat Enterprise Linux (RHEL) 5 omits TCP Wrapper support, which might allow remote attackers to bypass intended access restrictions via XDMCP connections, a different vulnerability than CVE-2007-5079.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vfhc-m4v6-8pw2/GHSA-vfhc-m4v6-8pw2.json b/advisories/unreviewed/2022/05/GHSA-vfhc-m4v6-8pw2/GHSA-vfhc-m4v6-8pw2.json index 1221374512a..8909ccc424d 100644 --- a/advisories/unreviewed/2022/05/GHSA-vfhc-m4v6-8pw2/GHSA-vfhc-m4v6-8pw2.json +++ b/advisories/unreviewed/2022/05/GHSA-vfhc-m4v6-8pw2/GHSA-vfhc-m4v6-8pw2.json @@ -7,12 +7,8 @@ "CVE-2009-3152" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in becommunity/community/index.php in NTSOFT BBS E-Market Professional allow remote attackers to inject arbitrary web script or HTML via the (1) page, (2) bt_code, and (3) b_no parameters in a board view action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vfx7-qr69-2qc6/GHSA-vfx7-qr69-2qc6.json b/advisories/unreviewed/2022/05/GHSA-vfx7-qr69-2qc6/GHSA-vfx7-qr69-2qc6.json index 66999dafaf4..cd4fe6f23ba 100644 --- a/advisories/unreviewed/2022/05/GHSA-vfx7-qr69-2qc6/GHSA-vfx7-qr69-2qc6.json +++ b/advisories/unreviewed/2022/05/GHSA-vfx7-qr69-2qc6/GHSA-vfx7-qr69-2qc6.json @@ -7,12 +7,8 @@ "CVE-2009-2489" ], "details": "Unspecified vulnerability in the utdmsession program in Sun Ray Server Software (SRSS) 4.0 allows local users to access the sessions of arbitrary users via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vgcq-wc9x-jmjv/GHSA-vgcq-wc9x-jmjv.json b/advisories/unreviewed/2022/05/GHSA-vgcq-wc9x-jmjv/GHSA-vgcq-wc9x-jmjv.json index 7e14a963b94..53e13c26d2c 100644 --- a/advisories/unreviewed/2022/05/GHSA-vgcq-wc9x-jmjv/GHSA-vgcq-wc9x-jmjv.json +++ b/advisories/unreviewed/2022/05/GHSA-vgcq-wc9x-jmjv/GHSA-vgcq-wc9x-jmjv.json @@ -7,12 +7,8 @@ "CVE-2009-3160" ], "details": "IBM WebSphere MQ 6.x through 6.0.2.7, 7.0.0.0, 7.0.0.1, 7.0.0.2, and 7.0.1.0, when read ahead or asynchronous message consumption is enabled, allows attackers to have an unspecified impact via unknown vectors, related to a \"memory overwrite\" issue.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vh9w-973v-hmhv/GHSA-vh9w-973v-hmhv.json b/advisories/unreviewed/2022/05/GHSA-vh9w-973v-hmhv/GHSA-vh9w-973v-hmhv.json index 6a30cdb65fc..299b7f9717d 100644 --- a/advisories/unreviewed/2022/05/GHSA-vh9w-973v-hmhv/GHSA-vh9w-973v-hmhv.json +++ b/advisories/unreviewed/2022/05/GHSA-vh9w-973v-hmhv/GHSA-vh9w-973v-hmhv.json @@ -7,12 +7,8 @@ "CVE-2009-2825" ], "details": "Certificate Assistant in Apple Mac OS X before 10.6.2 does not properly handle a '\\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which might allow man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vj5r-5fwr-9h24/GHSA-vj5r-5fwr-9h24.json b/advisories/unreviewed/2022/05/GHSA-vj5r-5fwr-9h24/GHSA-vj5r-5fwr-9h24.json index 31fc985d8a0..6d722c7596f 100644 --- a/advisories/unreviewed/2022/05/GHSA-vj5r-5fwr-9h24/GHSA-vj5r-5fwr-9h24.json +++ b/advisories/unreviewed/2022/05/GHSA-vj5r-5fwr-9h24/GHSA-vj5r-5fwr-9h24.json @@ -7,12 +7,8 @@ "CVE-2009-2977" ], "details": "The Cisco Security Monitoring, Analysis and Response System (CS-MARS) 6.0.4 and earlier stores cleartext passwords in log/sysbacktrace.## files within error-logs.tar.gz archives, which allows context-dependent attackers to obtain sensitive information by reading these files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vm68-jqgc-q7j6/GHSA-vm68-jqgc-q7j6.json b/advisories/unreviewed/2022/05/GHSA-vm68-jqgc-q7j6/GHSA-vm68-jqgc-q7j6.json index 82aa4d779b3..b1ea6b71523 100644 --- a/advisories/unreviewed/2022/05/GHSA-vm68-jqgc-q7j6/GHSA-vm68-jqgc-q7j6.json +++ b/advisories/unreviewed/2022/05/GHSA-vm68-jqgc-q7j6/GHSA-vm68-jqgc-q7j6.json @@ -7,12 +7,8 @@ "CVE-2009-2496" ], "details": "Heap-based buffer overflow in the Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2003 SP3, Office XP Web Components SP3, Office 2003 Web Components SP3, Office 2003 Web Components SP1 for the 2007 Microsoft Office System, Internet Security and Acceleration (ISA) Server 2004 SP3 and 2006 SP1, and Office Small Business Accounting 2006 allows remote attackers to execute arbitrary code via unspecified parameters to unknown methods, aka \"Office Web Components Heap Corruption Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vm7h-xxvx-g2fw/GHSA-vm7h-xxvx-g2fw.json b/advisories/unreviewed/2022/05/GHSA-vm7h-xxvx-g2fw/GHSA-vm7h-xxvx-g2fw.json index e57aa3e7e30..f09f9ba83dc 100644 --- a/advisories/unreviewed/2022/05/GHSA-vm7h-xxvx-g2fw/GHSA-vm7h-xxvx-g2fw.json +++ b/advisories/unreviewed/2022/05/GHSA-vm7h-xxvx-g2fw/GHSA-vm7h-xxvx-g2fw.json @@ -7,12 +7,8 @@ "CVE-2009-3235" ], "details": "Multiple stack-based buffer overflows in the Sieve plugin in Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, as derived from Cyrus libsieve, allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted SIEVE script, as demonstrated by forwarding an e-mail message to a large number of recipients, a different vulnerability than CVE-2009-2632.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vmrg-crrh-jrmg/GHSA-vmrg-crrh-jrmg.json b/advisories/unreviewed/2022/05/GHSA-vmrg-crrh-jrmg/GHSA-vmrg-crrh-jrmg.json index 64273cd5198..a95f0c2f64d 100644 --- a/advisories/unreviewed/2022/05/GHSA-vmrg-crrh-jrmg/GHSA-vmrg-crrh-jrmg.json +++ b/advisories/unreviewed/2022/05/GHSA-vmrg-crrh-jrmg/GHSA-vmrg-crrh-jrmg.json @@ -7,12 +7,8 @@ "CVE-2009-2832" ], "details": "Buffer overflow in FTP Server in Apple Mac OS X before 10.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a CWD command specifying a pathname in a deeply nested hierarchy of directories, related to a \"CWD command line tool.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vr94-84mg-gxfp/GHSA-vr94-84mg-gxfp.json b/advisories/unreviewed/2022/05/GHSA-vr94-84mg-gxfp/GHSA-vr94-84mg-gxfp.json index d1ec94ae221..bcbc40e1863 100644 --- a/advisories/unreviewed/2022/05/GHSA-vr94-84mg-gxfp/GHSA-vr94-84mg-gxfp.json +++ b/advisories/unreviewed/2022/05/GHSA-vr94-84mg-gxfp/GHSA-vr94-84mg-gxfp.json @@ -7,12 +7,8 @@ "CVE-2009-2854" ], "details": "Wordpress before 2.8.3 does not check capabilities for certain actions, which allows remote attackers to make unauthorized edits or additions via a direct request to (1) edit-comments.php, (2) edit-pages.php, (3) edit.php, (4) edit-category-form.php, (5) edit-link-category-form.php, (6) edit-tag-form.php, (7) export.php, (8) import.php, or (9) link-add.php in wp-admin/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vrjm-hxm2-f263/GHSA-vrjm-hxm2-f263.json b/advisories/unreviewed/2022/05/GHSA-vrjm-hxm2-f263/GHSA-vrjm-hxm2-f263.json index ef7e9972d4e..001f7c81b2b 100644 --- a/advisories/unreviewed/2022/05/GHSA-vrjm-hxm2-f263/GHSA-vrjm-hxm2-f263.json +++ b/advisories/unreviewed/2022/05/GHSA-vrjm-hxm2-f263/GHSA-vrjm-hxm2-f263.json @@ -7,12 +7,8 @@ "CVE-2009-2877" ], "details": "Stack-based buffer overflow in ataudio.dll in the Cisco WebEx WRF Player 26.x before 26.49.32 for Windows, 27.x before 27.10.x (aka T27SP10) for Windows, 26.x before 26.49.35 for Mac OS X and Linux, and 27.x before 27.11.8 for Mac OS X and Linux allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a crafted WebEx Recording Format (WRF) file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vrr7-72hm-vrmm/GHSA-vrr7-72hm-vrmm.json b/advisories/unreviewed/2022/05/GHSA-vrr7-72hm-vrmm/GHSA-vrr7-72hm-vrmm.json index 00b3785b0d3..25aead04810 100644 --- a/advisories/unreviewed/2022/05/GHSA-vrr7-72hm-vrmm/GHSA-vrr7-72hm-vrmm.json +++ b/advisories/unreviewed/2022/05/GHSA-vrr7-72hm-vrmm/GHSA-vrr7-72hm-vrmm.json @@ -7,12 +7,8 @@ "CVE-2009-2517" ], "details": "The kernel in Microsoft Windows Server 2003 SP2 does not properly handle unspecified exceptions when an error condition occurs, which allows local users to cause a denial of service (reboot) via a crafted application, aka \"Windows Kernel Exception Handler Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vvc2-xvcw-8qmf/GHSA-vvc2-xvcw-8qmf.json b/advisories/unreviewed/2022/05/GHSA-vvc2-xvcw-8qmf/GHSA-vvc2-xvcw-8qmf.json index 3157d5d16ae..07eb948127c 100644 --- a/advisories/unreviewed/2022/05/GHSA-vvc2-xvcw-8qmf/GHSA-vvc2-xvcw-8qmf.json +++ b/advisories/unreviewed/2022/05/GHSA-vvc2-xvcw-8qmf/GHSA-vvc2-xvcw-8qmf.json @@ -7,12 +7,8 @@ "CVE-2009-2935" ], "details": "Google V8, as used in Google Chrome before 2.0.172.43, allows remote attackers to bypass intended restrictions on reading memory, and possibly obtain sensitive information or execute arbitrary code in the Chrome sandbox, via crafted JavaScript.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vvfr-p62m-9frc/GHSA-vvfr-p62m-9frc.json b/advisories/unreviewed/2022/05/GHSA-vvfr-p62m-9frc/GHSA-vvfr-p62m-9frc.json index 3ff4637dcc5..43d1256f319 100644 --- a/advisories/unreviewed/2022/05/GHSA-vvfr-p62m-9frc/GHSA-vvfr-p62m-9frc.json +++ b/advisories/unreviewed/2022/05/GHSA-vvfr-p62m-9frc/GHSA-vvfr-p62m-9frc.json @@ -7,12 +7,8 @@ "CVE-2009-2943" ], "details": "The postgresql-ocaml bindings 1.5.4, 1.7.0, and 1.12.1 for PostgreSQL libpq do not properly support the PQescapeStringConn function, which might allow remote attackers to leverage escaping issues involving multibyte character encodings.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vvrm-5g2q-cfmr/GHSA-vvrm-5g2q-cfmr.json b/advisories/unreviewed/2022/05/GHSA-vvrm-5g2q-cfmr/GHSA-vvrm-5g2q-cfmr.json index 06596d1098f..f021c6f201e 100644 --- a/advisories/unreviewed/2022/05/GHSA-vvrm-5g2q-cfmr/GHSA-vvrm-5g2q-cfmr.json +++ b/advisories/unreviewed/2022/05/GHSA-vvrm-5g2q-cfmr/GHSA-vvrm-5g2q-cfmr.json @@ -7,12 +7,8 @@ "CVE-2009-2689" ], "details": "JDK13Services.getProviders in Sun Java SE 5.0 before Update 20 and 6 before Update 15, and OpenJDK, grants full privileges to instances of unspecified object types, which allows context-dependent attackers to bypass intended access restrictions via an untrusted (1) applet or (2) application.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -96,9 +92,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vvv4-6xjg-7crg/GHSA-vvv4-6xjg-7crg.json b/advisories/unreviewed/2022/05/GHSA-vvv4-6xjg-7crg/GHSA-vvv4-6xjg-7crg.json index f00886b8457..49309166c66 100644 --- a/advisories/unreviewed/2022/05/GHSA-vvv4-6xjg-7crg/GHSA-vvv4-6xjg-7crg.json +++ b/advisories/unreviewed/2022/05/GHSA-vvv4-6xjg-7crg/GHSA-vvv4-6xjg-7crg.json @@ -7,12 +7,8 @@ "CVE-2009-2494" ], "details": "The Active Template Library (ATL) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via vectors related to erroneous free operations after reading a variant from a stream and deleting this variant, aka \"ATL Object Type Mismatch Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vw7w-hxgp-f22h/GHSA-vw7w-hxgp-f22h.json b/advisories/unreviewed/2022/05/GHSA-vw7w-hxgp-f22h/GHSA-vw7w-hxgp-f22h.json index f3bd23f02de..0ec99b85d0d 100644 --- a/advisories/unreviewed/2022/05/GHSA-vw7w-hxgp-f22h/GHSA-vw7w-hxgp-f22h.json +++ b/advisories/unreviewed/2022/05/GHSA-vw7w-hxgp-f22h/GHSA-vw7w-hxgp-f22h.json @@ -7,12 +7,8 @@ "CVE-2009-2843" ], "details": "Java for Mac OS X 10.5 before Update 6 and 10.6 before Update 1 accepts expired certificates for applets, which makes it easier for remote attackers to execute arbitrary code via an applet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vx94-4rqx-r6q8/GHSA-vx94-4rqx-r6q8.json b/advisories/unreviewed/2022/05/GHSA-vx94-4rqx-r6q8/GHSA-vx94-4rqx-r6q8.json index 7f0c97918a6..d85fe79817a 100644 --- a/advisories/unreviewed/2022/05/GHSA-vx94-4rqx-r6q8/GHSA-vx94-4rqx-r6q8.json +++ b/advisories/unreviewed/2022/05/GHSA-vx94-4rqx-r6q8/GHSA-vx94-4rqx-r6q8.json @@ -7,12 +7,8 @@ "CVE-2009-2866" ], "details": "Unspecified vulnerability in Cisco IOS 12.2 through 12.4 allows remote attackers to cause a denial of service (device reload) via a crafted H.323 packet, aka Bug ID CSCsz38104.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vxrr-hhh6-m2mm/GHSA-vxrr-hhh6-m2mm.json b/advisories/unreviewed/2022/05/GHSA-vxrr-hhh6-m2mm/GHSA-vxrr-hhh6-m2mm.json index 805507599d2..8eb55948693 100644 --- a/advisories/unreviewed/2022/05/GHSA-vxrr-hhh6-m2mm/GHSA-vxrr-hhh6-m2mm.json +++ b/advisories/unreviewed/2022/05/GHSA-vxrr-hhh6-m2mm/GHSA-vxrr-hhh6-m2mm.json @@ -7,12 +7,8 @@ "CVE-2009-2951" ], "details": "Phenotype CMS before 2.9 does not use a random salt value for password encryption, which makes it easier for context-dependent attackers to determine cleartext passwords.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w23m-j49r-4582/GHSA-w23m-j49r-4582.json b/advisories/unreviewed/2022/05/GHSA-w23m-j49r-4582/GHSA-w23m-j49r-4582.json index de72550f848..30b241c6f93 100644 --- a/advisories/unreviewed/2022/05/GHSA-w23m-j49r-4582/GHSA-w23m-j49r-4582.json +++ b/advisories/unreviewed/2022/05/GHSA-w23m-j49r-4582/GHSA-w23m-j49r-4582.json @@ -7,12 +7,8 @@ "CVE-2009-3264" ], "details": "The getSVGDocument method in Google Chrome before 3.0.195.21 omits an unspecified \"access check,\" which allows remote web servers to bypass the Same Origin Policy and conduct cross-site scripting attacks via unknown vectors, related to a user's visit to a different web server that hosts an SVG document.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w328-4vjc-f7p4/GHSA-w328-4vjc-f7p4.json b/advisories/unreviewed/2022/05/GHSA-w328-4vjc-f7p4/GHSA-w328-4vjc-f7p4.json index 219496beb1a..a77b5a5af95 100644 --- a/advisories/unreviewed/2022/05/GHSA-w328-4vjc-f7p4/GHSA-w328-4vjc-f7p4.json +++ b/advisories/unreviewed/2022/05/GHSA-w328-4vjc-f7p4/GHSA-w328-4vjc-f7p4.json @@ -7,12 +7,8 @@ "CVE-2009-2949" ], "details": "Integer overflow in the XPMReader::ReadXPM function in filter.vcl/ixpm/svt_xpmread.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to execute arbitrary code via a crafted XPM file that triggers a heap-based buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w34v-rr2h-4v99/GHSA-w34v-rr2h-4v99.json b/advisories/unreviewed/2022/05/GHSA-w34v-rr2h-4v99/GHSA-w34v-rr2h-4v99.json index 09919dbea64..23b14f04786 100644 --- a/advisories/unreviewed/2022/05/GHSA-w34v-rr2h-4v99/GHSA-w34v-rr2h-4v99.json +++ b/advisories/unreviewed/2022/05/GHSA-w34v-rr2h-4v99/GHSA-w34v-rr2h-4v99.json @@ -7,12 +7,8 @@ "CVE-2009-3234" ], "details": "Buffer overflow in the perf_copy_attr function in kernel/perf_counter.c in the Linux kernel 2.6.31-rc1 allows local users to cause a denial of service (crash) and execute arbitrary code via a \"big size data\" to the perf_counter_open system call.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w3ch-c49v-7723/GHSA-w3ch-c49v-7723.json b/advisories/unreviewed/2022/05/GHSA-w3ch-c49v-7723/GHSA-w3ch-c49v-7723.json index 2ceb72568ca..94244cb6c66 100644 --- a/advisories/unreviewed/2022/05/GHSA-w3ch-c49v-7723/GHSA-w3ch-c49v-7723.json +++ b/advisories/unreviewed/2022/05/GHSA-w3ch-c49v-7723/GHSA-w3ch-c49v-7723.json @@ -7,12 +7,8 @@ "CVE-2009-2506" ], "details": "Integer overflow in the text converters in Microsoft Office Word 2002 SP3 and 2003 SP3; Works 8.5; Office Converter Pack; and WordPad in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via a DOC file with an invalid number of property names in the DocumentSummaryInformation stream, which triggers a heap-based buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w3fx-mv24-j38q/GHSA-w3fx-mv24-j38q.json b/advisories/unreviewed/2022/05/GHSA-w3fx-mv24-j38q/GHSA-w3fx-mv24-j38q.json index 62c6f872015..b0ab5739eeb 100644 --- a/advisories/unreviewed/2022/05/GHSA-w3fx-mv24-j38q/GHSA-w3fx-mv24-j38q.json +++ b/advisories/unreviewed/2022/05/GHSA-w3fx-mv24-j38q/GHSA-w3fx-mv24-j38q.json @@ -7,12 +7,8 @@ "CVE-2009-2635" ], "details": "PHP remote file inclusion vulnerability in toolbar_ext.php in the RealEstateManager (com_realestatemanager) component 1.0 Basic for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w3gh-4v3q-r24h/GHSA-w3gh-4v3q-r24h.json b/advisories/unreviewed/2022/05/GHSA-w3gh-4v3q-r24h/GHSA-w3gh-4v3q-r24h.json index 53aa878a42b..2853b85d8f0 100644 --- a/advisories/unreviewed/2022/05/GHSA-w3gh-4v3q-r24h/GHSA-w3gh-4v3q-r24h.json +++ b/advisories/unreviewed/2022/05/GHSA-w3gh-4v3q-r24h/GHSA-w3gh-4v3q-r24h.json @@ -7,12 +7,8 @@ "CVE-2009-2914" ], "details": "Cross-site scripting (XSS) vulnerability in index.php in XZero Community Classifieds 4.97.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the name of an uploaded file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w3r6-mw8w-3782/GHSA-w3r6-mw8w-3782.json b/advisories/unreviewed/2022/05/GHSA-w3r6-mw8w-3782/GHSA-w3r6-mw8w-3782.json index 2f7b0bcfb14..59c062ccede 100644 --- a/advisories/unreviewed/2022/05/GHSA-w3r6-mw8w-3782/GHSA-w3r6-mw8w-3782.json +++ b/advisories/unreviewed/2022/05/GHSA-w3r6-mw8w-3782/GHSA-w3r6-mw8w-3782.json @@ -7,12 +7,8 @@ "CVE-2009-2685" ], "details": "Stack-based buffer overflow in the login form in the management web server in HP Power Manager allows remote attackers to execute arbitrary code via the Login variable.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w697-9m8x-pc8c/GHSA-w697-9m8x-pc8c.json b/advisories/unreviewed/2022/05/GHSA-w697-9m8x-pc8c/GHSA-w697-9m8x-pc8c.json index d8eb10a8c80..cc93be845c4 100644 --- a/advisories/unreviewed/2022/05/GHSA-w697-9m8x-pc8c/GHSA-w697-9m8x-pc8c.json +++ b/advisories/unreviewed/2022/05/GHSA-w697-9m8x-pc8c/GHSA-w697-9m8x-pc8c.json @@ -7,12 +7,8 @@ "CVE-2009-2498" ], "details": "Microsoft Windows Media Format Runtime 9.0, 9.5, and 11 and Windows Media Services 9.1 and 2008 do not properly parse malformed headers in Advanced Systems Format (ASF) files, which allows remote attackers to execute arbitrary code via a crafted (1) .asf, (2) .wmv, or (3) .wma file, aka \"Windows Media Header Parsing Invalid Free Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w6cg-32qr-cwmq/GHSA-w6cg-32qr-cwmq.json b/advisories/unreviewed/2022/05/GHSA-w6cg-32qr-cwmq/GHSA-w6cg-32qr-cwmq.json index 8e9192901a9..d1779fede44 100644 --- a/advisories/unreviewed/2022/05/GHSA-w6cg-32qr-cwmq/GHSA-w6cg-32qr-cwmq.json +++ b/advisories/unreviewed/2022/05/GHSA-w6cg-32qr-cwmq/GHSA-w6cg-32qr-cwmq.json @@ -7,12 +7,8 @@ "CVE-2009-2785" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in PHP Open Classifieds Script allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter to buy.php and the id parameter to (2) contact.php and (3) tellafriend.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w6rq-x735-2wv9/GHSA-w6rq-x735-2wv9.json b/advisories/unreviewed/2022/05/GHSA-w6rq-x735-2wv9/GHSA-w6rq-x735-2wv9.json index 1da5b6ce086..6f5660e0721 100644 --- a/advisories/unreviewed/2022/05/GHSA-w6rq-x735-2wv9/GHSA-w6rq-x735-2wv9.json +++ b/advisories/unreviewed/2022/05/GHSA-w6rq-x735-2wv9/GHSA-w6rq-x735-2wv9.json @@ -7,12 +7,8 @@ "CVE-2009-2716" ], "details": "The plugin functionality in Sun Java SE 6 before Update 15 does not properly implement version selection, which allows context-dependent attackers to leverage vulnerabilities in \"old zip and certificate handling\" and have unspecified other impact via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w73q-3j7m-724w/GHSA-w73q-3j7m-724w.json b/advisories/unreviewed/2022/05/GHSA-w73q-3j7m-724w/GHSA-w73q-3j7m-724w.json index 8d93abed53a..3c9a3cdd2aa 100644 --- a/advisories/unreviewed/2022/05/GHSA-w73q-3j7m-724w/GHSA-w73q-3j7m-724w.json +++ b/advisories/unreviewed/2022/05/GHSA-w73q-3j7m-724w/GHSA-w73q-3j7m-724w.json @@ -7,12 +7,8 @@ "CVE-2009-3038" ], "details": "A certain ActiveX control in lnresobject.dll 7.1.1.119 in the Research In Motion (RIM) Lotus Notes connector for BlackBerry Desktop Manager 5.0.0.11 allows remote attackers to cause a denial of service (Internet Explorer crash) by referencing the control's CLSID in the classid attribute of an OBJECT element.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w7jf-rxf7-qv7v/GHSA-w7jf-rxf7-qv7v.json b/advisories/unreviewed/2022/05/GHSA-w7jf-rxf7-qv7v/GHSA-w7jf-rxf7-qv7v.json index b3680fbb1f8..99489b9d34d 100644 --- a/advisories/unreviewed/2022/05/GHSA-w7jf-rxf7-qv7v/GHSA-w7jf-rxf7-qv7v.json +++ b/advisories/unreviewed/2022/05/GHSA-w7jf-rxf7-qv7v/GHSA-w7jf-rxf7-qv7v.json @@ -7,12 +7,8 @@ "CVE-2009-2718" ], "details": "The Abstract Window Toolkit (AWT) implementation in Sun Java SE 6 before Update 15 on X11 does not impose the intended constraint on distance from the window border to the Security Warning Icon, which makes it easier for context-dependent attackers to trick a user into interacting unsafely with an untrusted applet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w89j-crf7-qmgx/GHSA-w89j-crf7-qmgx.json b/advisories/unreviewed/2022/05/GHSA-w89j-crf7-qmgx/GHSA-w89j-crf7-qmgx.json index 19bd687c53f..562834315af 100644 --- a/advisories/unreviewed/2022/05/GHSA-w89j-crf7-qmgx/GHSA-w89j-crf7-qmgx.json +++ b/advisories/unreviewed/2022/05/GHSA-w89j-crf7-qmgx/GHSA-w89j-crf7-qmgx.json @@ -7,12 +7,8 @@ "CVE-2009-2983" ], "details": "Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 allow attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w8g4-h8cc-352m/GHSA-w8g4-h8cc-352m.json b/advisories/unreviewed/2022/05/GHSA-w8g4-h8cc-352m/GHSA-w8g4-h8cc-352m.json index 1ac606413a7..f3428690a92 100644 --- a/advisories/unreviewed/2022/05/GHSA-w8g4-h8cc-352m/GHSA-w8g4-h8cc-352m.json +++ b/advisories/unreviewed/2022/05/GHSA-w8g4-h8cc-352m/GHSA-w8g4-h8cc-352m.json @@ -7,12 +7,8 @@ "CVE-2009-2521" ], "details": "Stack consumption vulnerability in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 7.0 allows remote authenticated users to cause a denial of service (daemon crash) via a list (ls) -R command containing a wildcard that references a subdirectory, followed by a .. (dot dot), aka \"IIS FTP Service DoS Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w8mc-2j77-9pfm/GHSA-w8mc-2j77-9pfm.json b/advisories/unreviewed/2022/05/GHSA-w8mc-2j77-9pfm/GHSA-w8mc-2j77-9pfm.json index 6ccc766dfc8..e61d6c757c2 100644 --- a/advisories/unreviewed/2022/05/GHSA-w8mc-2j77-9pfm/GHSA-w8mc-2j77-9pfm.json +++ b/advisories/unreviewed/2022/05/GHSA-w8mc-2j77-9pfm/GHSA-w8mc-2j77-9pfm.json @@ -7,12 +7,8 @@ "CVE-2009-2871" ], "details": "Unspecified vulnerability in Cisco IOS 12.2 and 12.4, when SSLVPN sessions, SSH sessions, or IKE encrypted nonces are enabled, allows remote attackers to cause a denial of service (device reload) via a crafted encrypted packet, aka Bug ID CSCsq24002.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w98q-7wf3-vg43/GHSA-w98q-7wf3-vg43.json b/advisories/unreviewed/2022/05/GHSA-w98q-7wf3-vg43/GHSA-w98q-7wf3-vg43.json index 0e89c57f1c7..ed9c96bd22a 100644 --- a/advisories/unreviewed/2022/05/GHSA-w98q-7wf3-vg43/GHSA-w98q-7wf3-vg43.json +++ b/advisories/unreviewed/2022/05/GHSA-w98q-7wf3-vg43/GHSA-w98q-7wf3-vg43.json @@ -7,12 +7,8 @@ "CVE-2009-2495" ], "details": "The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1, and Visual C++ 2005 SP1 and 2008 Gold and SP1 does not properly enforce string termination, which allows remote attackers to obtain sensitive information via a crafted HTML document with an ATL (1) component or (2) control that triggers a buffer over-read, related to ATL headers and buffer allocation, aka \"ATL Null String Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wfhq-rjjw-5xwh/GHSA-wfhq-rjjw-5xwh.json b/advisories/unreviewed/2022/05/GHSA-wfhq-rjjw-5xwh/GHSA-wfhq-rjjw-5xwh.json index 28d50c284ab..d12efb775b8 100644 --- a/advisories/unreviewed/2022/05/GHSA-wfhq-rjjw-5xwh/GHSA-wfhq-rjjw-5xwh.json +++ b/advisories/unreviewed/2022/05/GHSA-wfhq-rjjw-5xwh/GHSA-wfhq-rjjw-5xwh.json @@ -7,12 +7,8 @@ "CVE-2009-2669" ], "details": "A certain debugging component in IBM AIX 5.3 and 6.1 does not properly handle the (1) _LIB_INIT_DBG and (2) _LIB_INIT_DBG_FILE environment variables, which allows local users to gain privileges by leveraging a setuid-root program to create an arbitrary root-owned file with world-writable permissions, related to libC.a (aka the XL C++ runtime library) in AIX 5.3 and libc.a in AIX 6.1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wfxm-x338-3x9x/GHSA-wfxm-x338-3x9x.json b/advisories/unreviewed/2022/05/GHSA-wfxm-x338-3x9x/GHSA-wfxm-x338-3x9x.json index c1232878057..ccb2ec71f4c 100644 --- a/advisories/unreviewed/2022/05/GHSA-wfxm-x338-3x9x/GHSA-wfxm-x338-3x9x.json +++ b/advisories/unreviewed/2022/05/GHSA-wfxm-x338-3x9x/GHSA-wfxm-x338-3x9x.json @@ -7,12 +7,8 @@ "CVE-2009-2996" ], "details": "Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allow attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2009-2985.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wg2p-7hvq-4gf2/GHSA-wg2p-7hvq-4gf2.json b/advisories/unreviewed/2022/05/GHSA-wg2p-7hvq-4gf2/GHSA-wg2p-7hvq-4gf2.json index 473fd222e5f..5f889db2f33 100644 --- a/advisories/unreviewed/2022/05/GHSA-wg2p-7hvq-4gf2/GHSA-wg2p-7hvq-4gf2.json +++ b/advisories/unreviewed/2022/05/GHSA-wg2p-7hvq-4gf2/GHSA-wg2p-7hvq-4gf2.json @@ -7,12 +7,8 @@ "CVE-2009-2897" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in hq/web/common/GenericError.jsp in the generic exception handler in the web interface in SpringSource Hyperic HQ 3.2.x before 3.2.6.1, 4.0.x before 4.0.3.1, 4.1.x before 4.1.2.1, and 4.2-beta1; Application Management Suite (AMS) 2.0.0.SR3; and tc Server 6.0.20.B allow remote attackers to inject arbitrary web script or HTML via invalid values for numerical parameters, as demonstrated by an uncaught java.lang.NumberFormatException exception resulting from (1) the typeId parameter to mastheadAttach.do, (2) the eid parameter to Resource.do, and (3) the u parameter in a view action to admin/user/UserAdmin.do. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wg6x-8526-fqg6/GHSA-wg6x-8526-fqg6.json b/advisories/unreviewed/2022/05/GHSA-wg6x-8526-fqg6/GHSA-wg6x-8526-fqg6.json index fb9c628dcd7..7c9885976de 100644 --- a/advisories/unreviewed/2022/05/GHSA-wg6x-8526-fqg6/GHSA-wg6x-8526-fqg6.json +++ b/advisories/unreviewed/2022/05/GHSA-wg6x-8526-fqg6/GHSA-wg6x-8526-fqg6.json @@ -7,12 +7,8 @@ "CVE-2009-2761" ], "details": "Unquoted Windows search path vulnerability in the scheduler (sched.exe) in Avira AntiVir, AntiVir Premium, Premium Security Suite, and AntiVir Professional might allow local users to gain privileges via a malicious antivir.exe file in the \"C:\\Program Files\\avira\\\" directory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wg93-p886-wx3j/GHSA-wg93-p886-wx3j.json b/advisories/unreviewed/2022/05/GHSA-wg93-p886-wx3j/GHSA-wg93-p886-wx3j.json index 43549d0b4f2..4a98e2cb7c9 100644 --- a/advisories/unreviewed/2022/05/GHSA-wg93-p886-wx3j/GHSA-wg93-p886-wx3j.json +++ b/advisories/unreviewed/2022/05/GHSA-wg93-p886-wx3j/GHSA-wg93-p886-wx3j.json @@ -7,12 +7,8 @@ "CVE-2009-2714" ], "details": "Unspecified vulnerability in Sun VirtualBox 3.0.0 and 3.0.2 allows guest OS users to cause a denial of service (host OS reboot) via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wgjj-998f-xhjv/GHSA-wgjj-998f-xhjv.json b/advisories/unreviewed/2022/05/GHSA-wgjj-998f-xhjv/GHSA-wgjj-998f-xhjv.json index e7b7c0d0171..7004b5c2ff2 100644 --- a/advisories/unreviewed/2022/05/GHSA-wgjj-998f-xhjv/GHSA-wgjj-998f-xhjv.json +++ b/advisories/unreviewed/2022/05/GHSA-wgjj-998f-xhjv/GHSA-wgjj-998f-xhjv.json @@ -7,12 +7,8 @@ "CVE-2009-3246" ], "details": "SQL injection vulnerability in spnews.php in MyBuxScript PTC-BUX allows remote attackers to execute arbitrary SQL commands via the id parameter in an spnews action to the default URI. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wh4v-6jqx-jp95/GHSA-wh4v-6jqx-jp95.json b/advisories/unreviewed/2022/05/GHSA-wh4v-6jqx-jp95/GHSA-wh4v-6jqx-jp95.json index 39c479bab4f..38e904659c3 100644 --- a/advisories/unreviewed/2022/05/GHSA-wh4v-6jqx-jp95/GHSA-wh4v-6jqx-jp95.json +++ b/advisories/unreviewed/2022/05/GHSA-wh4v-6jqx-jp95/GHSA-wh4v-6jqx-jp95.json @@ -7,12 +7,8 @@ "CVE-2009-2616" ], "details": "SQL injection vulnerability in z_admin_login.asp in DataCheck Solutions SitePal 1.x allows remote attackers to execute arbitrary SQL commands via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wm55-hw48-g8cv/GHSA-wm55-hw48-g8cv.json b/advisories/unreviewed/2022/05/GHSA-wm55-hw48-g8cv/GHSA-wm55-hw48-g8cv.json index 6444328c7fa..6f7c9bc4589 100644 --- a/advisories/unreviewed/2022/05/GHSA-wm55-hw48-g8cv/GHSA-wm55-hw48-g8cv.json +++ b/advisories/unreviewed/2022/05/GHSA-wm55-hw48-g8cv/GHSA-wm55-hw48-g8cv.json @@ -7,12 +7,8 @@ "CVE-2009-2531" ], "details": "Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka \"Uninitialized Memory Corruption Vulnerability,\" a different vulnerability than CVE-2009-2530.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wmvv-2fxc-9j89/GHSA-wmvv-2fxc-9j89.json b/advisories/unreviewed/2022/05/GHSA-wmvv-2fxc-9j89/GHSA-wmvv-2fxc-9j89.json index 9b3fd82bb70..56fa9678b8f 100644 --- a/advisories/unreviewed/2022/05/GHSA-wmvv-2fxc-9j89/GHSA-wmvv-2fxc-9j89.json +++ b/advisories/unreviewed/2022/05/GHSA-wmvv-2fxc-9j89/GHSA-wmvv-2fxc-9j89.json @@ -7,12 +7,8 @@ "CVE-2009-3171" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Anantasoft Gazelle CMS 1.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) user parameter to user.php or (2) lookup parameter to search.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wrr9-4mxw-5vxg/GHSA-wrr9-4mxw-5vxg.json b/advisories/unreviewed/2022/05/GHSA-wrr9-4mxw-5vxg/GHSA-wrr9-4mxw-5vxg.json index 6f741d0ca2b..62e83c7a390 100644 --- a/advisories/unreviewed/2022/05/GHSA-wrr9-4mxw-5vxg/GHSA-wrr9-4mxw-5vxg.json +++ b/advisories/unreviewed/2022/05/GHSA-wrr9-4mxw-5vxg/GHSA-wrr9-4mxw-5vxg.json @@ -7,12 +7,8 @@ "CVE-2009-2984" ], "details": "Unspecified vulnerability in the image decoder in Adobe Acrobat 9.x before 9.2, and possibly 7.x through 7.1.4 and 8.x through 8.1.7, allows attackers to cause a denial of service or possibly execute arbitrary code via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wrrr-43gq-gf8x/GHSA-wrrr-43gq-gf8x.json b/advisories/unreviewed/2022/05/GHSA-wrrr-43gq-gf8x/GHSA-wrrr-43gq-gf8x.json index 83fcd7150a5..a5f056f06ab 100644 --- a/advisories/unreviewed/2022/05/GHSA-wrrr-43gq-gf8x/GHSA-wrrr-43gq-gf8x.json +++ b/advisories/unreviewed/2022/05/GHSA-wrrr-43gq-gf8x/GHSA-wrrr-43gq-gf8x.json @@ -7,12 +7,8 @@ "CVE-2009-2823" ], "details": "The Apache HTTP Server in Apple Mac OS X before 10.6.2 enables the HTTP TRACE method, which allows remote attackers to conduct cross-site scripting (XSS) attacks via unspecified web client software.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wvp2-pf7p-8jjm/GHSA-wvp2-pf7p-8jjm.json b/advisories/unreviewed/2022/05/GHSA-wvp2-pf7p-8jjm/GHSA-wvp2-pf7p-8jjm.json index 307f53c4a94..b66f395032f 100644 --- a/advisories/unreviewed/2022/05/GHSA-wvp2-pf7p-8jjm/GHSA-wvp2-pf7p-8jjm.json +++ b/advisories/unreviewed/2022/05/GHSA-wvp2-pf7p-8jjm/GHSA-wvp2-pf7p-8jjm.json @@ -7,12 +7,8 @@ "CVE-2009-2980" ], "details": "Integer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows attackers to cause a denial of service or possibly execute arbitrary code via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-ww4p-6452-jmh8/GHSA-ww4p-6452-jmh8.json b/advisories/unreviewed/2022/05/GHSA-ww4p-6452-jmh8/GHSA-ww4p-6452-jmh8.json index 855fb0db222..1870f2691e9 100644 --- a/advisories/unreviewed/2022/05/GHSA-ww4p-6452-jmh8/GHSA-ww4p-6452-jmh8.json +++ b/advisories/unreviewed/2022/05/GHSA-ww4p-6452-jmh8/GHSA-ww4p-6452-jmh8.json @@ -7,12 +7,8 @@ "CVE-2009-3023" ], "details": "Buffer overflow in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 6.0 allows remote authenticated users to execute arbitrary code via a crafted NLST (NAME LIST) command that uses wildcards, leading to memory corruption, aka \"IIS FTP Service RCE and DoS Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ww59-3r9r-8fph/GHSA-ww59-3r9r-8fph.json b/advisories/unreviewed/2022/05/GHSA-ww59-3r9r-8fph/GHSA-ww59-3r9r-8fph.json index 7e6c8cea326..8c996ec9d62 100644 --- a/advisories/unreviewed/2022/05/GHSA-ww59-3r9r-8fph/GHSA-ww59-3r9r-8fph.json +++ b/advisories/unreviewed/2022/05/GHSA-ww59-3r9r-8fph/GHSA-ww59-3r9r-8fph.json @@ -7,12 +7,8 @@ "CVE-2009-2622" ], "details": "Squid 3.0 through 3.0.STABLE16 and 3.1 through 3.1.0.11 allows remote attackers to cause a denial of service via malformed requests including (1) \"missing or mismatched protocol identifier,\" (2) missing or negative status value,\" (3) \"missing version,\" or (4) \"missing or invalid status number,\" related to (a) HttpMsg.cc and (b) HttpReply.cc.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wwwc-pg6w-gw56/GHSA-wwwc-pg6w-gw56.json b/advisories/unreviewed/2022/05/GHSA-wwwc-pg6w-gw56/GHSA-wwwc-pg6w-gw56.json index e87af551a37..933b9960e08 100644 --- a/advisories/unreviewed/2022/05/GHSA-wwwc-pg6w-gw56/GHSA-wwwc-pg6w-gw56.json +++ b/advisories/unreviewed/2022/05/GHSA-wwwc-pg6w-gw56/GHSA-wwwc-pg6w-gw56.json @@ -7,12 +7,8 @@ "CVE-2009-2885" ], "details": "SQL injection vulnerability in bios.php in PHP Scripts Now World's Tallest Buildings allows remote attackers to execute arbitrary SQL commands via the rank parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wx8c-4976-gv57/GHSA-wx8c-4976-gv57.json b/advisories/unreviewed/2022/05/GHSA-wx8c-4976-gv57/GHSA-wx8c-4976-gv57.json index f11a34545d0..be16c78af88 100644 --- a/advisories/unreviewed/2022/05/GHSA-wx8c-4976-gv57/GHSA-wx8c-4976-gv57.json +++ b/advisories/unreviewed/2022/05/GHSA-wx8c-4976-gv57/GHSA-wx8c-4976-gv57.json @@ -7,12 +7,8 @@ "CVE-2009-3037" ], "details": "Buffer overflow in xlssr.dll in the Autonomy KeyView XLS viewer (aka File Viewer for Excel), as used in IBM Lotus Notes 5.x through 8.5.x, Symantec Mail Security, Symantec BrightMail Appliance, Symantec Data Loss Prevention (DLP), and other products, allows remote attackers to execute arbitrary code via a crafted .xls spreadsheet attachment.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x4jm-r7gw-5wxf/GHSA-x4jm-r7gw-5wxf.json b/advisories/unreviewed/2022/05/GHSA-x4jm-r7gw-5wxf/GHSA-x4jm-r7gw-5wxf.json index a71f737d820..bf30cf64e53 100644 --- a/advisories/unreviewed/2022/05/GHSA-x4jm-r7gw-5wxf/GHSA-x4jm-r7gw-5wxf.json +++ b/advisories/unreviewed/2022/05/GHSA-x4jm-r7gw-5wxf/GHSA-x4jm-r7gw-5wxf.json @@ -7,12 +7,8 @@ "CVE-2009-2608" ], "details": "Multiple SQL injection vulnerabilities in PHP Address Book 4.0.x allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to delete.php or (2) alphabet parameter to index.php. NOTE: the edit.php and view.php vectors are already covered by CVE-2008-2565.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x4jr-j3mp-87v9/GHSA-x4jr-j3mp-87v9.json b/advisories/unreviewed/2022/05/GHSA-x4jr-j3mp-87v9/GHSA-x4jr-j3mp-87v9.json index 4ebe886ae37..310bfed9291 100644 --- a/advisories/unreviewed/2022/05/GHSA-x4jr-j3mp-87v9/GHSA-x4jr-j3mp-87v9.json +++ b/advisories/unreviewed/2022/05/GHSA-x4jr-j3mp-87v9/GHSA-x4jr-j3mp-87v9.json @@ -7,12 +7,8 @@ "CVE-2009-3036" ], "details": "Cross-site scripting (XSS) vulnerability in the console in Symantec IM Manager 8.3 and 8.4 before 8.4.13 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x589-2c67-92qp/GHSA-x589-2c67-92qp.json b/advisories/unreviewed/2022/05/GHSA-x589-2c67-92qp/GHSA-x589-2c67-92qp.json index 88acdcc52d5..22f3d9e365f 100644 --- a/advisories/unreviewed/2022/05/GHSA-x589-2c67-92qp/GHSA-x589-2c67-92qp.json +++ b/advisories/unreviewed/2022/05/GHSA-x589-2c67-92qp/GHSA-x589-2c67-92qp.json @@ -7,12 +7,8 @@ "CVE-2009-3169" ], "details": "Multiple unspecified vulnerabilities in Hitachi JP1/File Transmission Server/FTP before 09-00 allow remote attackers to execute arbitrary code via unknown attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x5qh-hm2w-7695/GHSA-x5qh-hm2w-7695.json b/advisories/unreviewed/2022/05/GHSA-x5qh-hm2w-7695/GHSA-x5qh-hm2w-7695.json index 432845c7365..673ac7abbad 100644 --- a/advisories/unreviewed/2022/05/GHSA-x5qh-hm2w-7695/GHSA-x5qh-hm2w-7695.json +++ b/advisories/unreviewed/2022/05/GHSA-x5qh-hm2w-7695/GHSA-x5qh-hm2w-7695.json @@ -7,12 +7,8 @@ "CVE-2009-2515" ], "details": "Integer underflow in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows local users to gain privileges via a crafted application that triggers an incorrect truncation of a 64-bit integer to a 32-bit integer, aka \"Windows Kernel Integer Underflow Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x67g-9xfr-7m5f/GHSA-x67g-9xfr-7m5f.json b/advisories/unreviewed/2022/05/GHSA-x67g-9xfr-7m5f/GHSA-x67g-9xfr-7m5f.json index 0c74ff1222c..c29440f61bc 100644 --- a/advisories/unreviewed/2022/05/GHSA-x67g-9xfr-7m5f/GHSA-x67g-9xfr-7m5f.json +++ b/advisories/unreviewed/2022/05/GHSA-x67g-9xfr-7m5f/GHSA-x67g-9xfr-7m5f.json @@ -7,12 +7,8 @@ "CVE-2009-3146" ], "details": "Cross-site scripting (XSS) vulnerability in search_advance.php in ArticleFriend Script allows remote attackers to inject arbitrary web script or HTML via the SearchWd parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x6gm-v8jj-6pfw/GHSA-x6gm-v8jj-6pfw.json b/advisories/unreviewed/2022/05/GHSA-x6gm-v8jj-6pfw/GHSA-x6gm-v8jj-6pfw.json index eaadfc4d320..8f3f93947c2 100644 --- a/advisories/unreviewed/2022/05/GHSA-x6gm-v8jj-6pfw/GHSA-x6gm-v8jj-6pfw.json +++ b/advisories/unreviewed/2022/05/GHSA-x6gm-v8jj-6pfw/GHSA-x6gm-v8jj-6pfw.json @@ -7,12 +7,8 @@ "CVE-2009-2919" ], "details": "Cross-site scripting (XSS) vulnerability in Boonex Orca 2.0 and 2.0.2 allows remote authenticated users to inject arbitrary web script or HTML via the topic title field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x6gw-c9hx-x25f/GHSA-x6gw-c9hx-x25f.json b/advisories/unreviewed/2022/05/GHSA-x6gw-c9hx-x25f/GHSA-x6gw-c9hx-x25f.json index 9f4f465350d..6892dfd73f0 100644 --- a/advisories/unreviewed/2022/05/GHSA-x6gw-c9hx-x25f/GHSA-x6gw-c9hx-x25f.json +++ b/advisories/unreviewed/2022/05/GHSA-x6gw-c9hx-x25f/GHSA-x6gw-c9hx-x25f.json @@ -7,12 +7,8 @@ "CVE-2009-2730" ], "details": "libgnutls in GnuTLS before 2.8.2 does not properly handle a '\\0' character in a domain name in the subject's (1) Common Name (CN) or (2) Subject Alternative Name (SAN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -72,9 +68,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x72h-3686-9w66/GHSA-x72h-3686-9w66.json b/advisories/unreviewed/2022/05/GHSA-x72h-3686-9w66/GHSA-x72h-3686-9w66.json index 80857b40fed..381e1531ed1 100644 --- a/advisories/unreviewed/2022/05/GHSA-x72h-3686-9w66/GHSA-x72h-3686-9w66.json +++ b/advisories/unreviewed/2022/05/GHSA-x72h-3686-9w66/GHSA-x72h-3686-9w66.json @@ -7,12 +7,8 @@ "CVE-2009-3303" ], "details": "Cross-site scripting (XSS) vulnerability in www/help/tracker.php in GForge 4.5.14, 4.7 rc2, and 4.8.1 allows remote attackers to inject arbitrary web script or HTML via the helpname parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x75h-2jg7-ffxw/GHSA-x75h-2jg7-ffxw.json b/advisories/unreviewed/2022/05/GHSA-x75h-2jg7-ffxw/GHSA-x75h-2jg7-ffxw.json index 51053d03f17..0eaa908217c 100644 --- a/advisories/unreviewed/2022/05/GHSA-x75h-2jg7-ffxw/GHSA-x75h-2jg7-ffxw.json +++ b/advisories/unreviewed/2022/05/GHSA-x75h-2jg7-ffxw/GHSA-x75h-2jg7-ffxw.json @@ -7,12 +7,8 @@ "CVE-2009-2696" ], "details": "Cross-site scripting (XSS) vulnerability in jsp/cal/cal2.jsp in the calendar application in the examples web application in Apache Tomcat on Red Hat Enterprise Linux 5, Desktop Workstation 5, and Linux Desktop 5 allows remote attackers to inject arbitrary web script or HTML via the time parameter, related to \"invalid HTML.\" NOTE: this is due to a missing fix for CVE-2009-0781.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x7g4-2h3g-m2w7/GHSA-x7g4-2h3g-m2w7.json b/advisories/unreviewed/2022/05/GHSA-x7g4-2h3g-m2w7/GHSA-x7g4-2h3g-m2w7.json index 68ae8768e34..3598e6546f4 100644 --- a/advisories/unreviewed/2022/05/GHSA-x7g4-2h3g-m2w7/GHSA-x7g4-2h3g-m2w7.json +++ b/advisories/unreviewed/2022/05/GHSA-x7g4-2h3g-m2w7/GHSA-x7g4-2h3g-m2w7.json @@ -7,12 +7,8 @@ "CVE-2009-2944" ], "details": "Incomplete blacklist vulnerability in the teximg plugin in ikiwiki before 3.1415926 and 2.x before 2.53.4 allows context-dependent attackers to read arbitrary files via crafted TeX commands.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x7pq-j293-x4p5/GHSA-x7pq-j293-x4p5.json b/advisories/unreviewed/2022/05/GHSA-x7pq-j293-x4p5/GHSA-x7pq-j293-x4p5.json index a867e061858..37a2ddacaf0 100644 --- a/advisories/unreviewed/2022/05/GHSA-x7pq-j293-x4p5/GHSA-x7pq-j293-x4p5.json +++ b/advisories/unreviewed/2022/05/GHSA-x7pq-j293-x4p5/GHSA-x7pq-j293-x4p5.json @@ -7,12 +7,8 @@ "CVE-2009-2675" ], "details": "Integer overflow in the unpack200 utility in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, allows context-dependent attackers to gain privileges via unspecified length fields in the header of a Pack200-compressed JAR file, which leads to a heap-based buffer overflow during decompression.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -152,9 +148,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x8qj-q565-48rf/GHSA-x8qj-q565-48rf.json b/advisories/unreviewed/2022/05/GHSA-x8qj-q565-48rf/GHSA-x8qj-q565-48rf.json index a2d94ef1b9b..57fdafafdff 100644 --- a/advisories/unreviewed/2022/05/GHSA-x8qj-q565-48rf/GHSA-x8qj-q565-48rf.json +++ b/advisories/unreviewed/2022/05/GHSA-x8qj-q565-48rf/GHSA-x8qj-q565-48rf.json @@ -7,12 +7,8 @@ "CVE-2009-2838" ], "details": "Integer overflow in QuickLook in Apple Mac OS X 10.5.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Microsoft Office document that triggers a buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x9w7-hxvq-9xhr/GHSA-x9w7-hxvq-9xhr.json b/advisories/unreviewed/2022/05/GHSA-x9w7-hxvq-9xhr/GHSA-x9w7-hxvq-9xhr.json index 4e7af339ad4..c0368259878 100644 --- a/advisories/unreviewed/2022/05/GHSA-x9w7-hxvq-9xhr/GHSA-x9w7-hxvq-9xhr.json +++ b/advisories/unreviewed/2022/05/GHSA-x9w7-hxvq-9xhr/GHSA-x9w7-hxvq-9xhr.json @@ -7,12 +7,8 @@ "CVE-2009-2588" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Hotscripts Type PHP Clone Script allow remote attackers to inject arbitrary web script or HTML via the msg parameter to (1) feedback.php, (2) index.php, and (3) lostpassword.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x9xh-99f3-w2wr/GHSA-x9xh-99f3-w2wr.json b/advisories/unreviewed/2022/05/GHSA-x9xh-99f3-w2wr/GHSA-x9xh-99f3-w2wr.json index 7833982a7b0..d8dd03c44b7 100644 --- a/advisories/unreviewed/2022/05/GHSA-x9xh-99f3-w2wr/GHSA-x9xh-99f3-w2wr.json +++ b/advisories/unreviewed/2022/05/GHSA-x9xh-99f3-w2wr/GHSA-x9xh-99f3-w2wr.json @@ -7,12 +7,8 @@ "CVE-2009-3259" ], "details": "Multiple SQL injection vulnerabilities in RASH Quote Management System (RQMS) 1.2.2 allow remote attackers to execute arbitrary SQL commands via (1) the search parameter in a search action, (2) the quote parameter in a quote addition, or (3) a User_Name cookie in unspecified administrative actions. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xc37-2m2p-wghm/GHSA-xc37-2m2p-wghm.json b/advisories/unreviewed/2022/05/GHSA-xc37-2m2p-wghm/GHSA-xc37-2m2p-wghm.json index 3b53e9f1874..22eb0eb44c4 100644 --- a/advisories/unreviewed/2022/05/GHSA-xc37-2m2p-wghm/GHSA-xc37-2m2p-wghm.json +++ b/advisories/unreviewed/2022/05/GHSA-xc37-2m2p-wghm/GHSA-xc37-2m2p-wghm.json @@ -7,12 +7,8 @@ "CVE-2009-2849" ], "details": "The md driver (drivers/md/md.c) in the Linux kernel before 2.6.30.2 might allow local users to cause a denial of service (NULL pointer dereference) via vectors related to \"suspend_* sysfs attributes\" and the (1) suspend_lo_store or (2) suspend_hi_store functions. NOTE: this is only a vulnerability when sysfs is writable by an attacker.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -88,9 +84,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xc7p-88w7-44wr/GHSA-xc7p-88w7-44wr.json b/advisories/unreviewed/2022/05/GHSA-xc7p-88w7-44wr/GHSA-xc7p-88w7-44wr.json index 44404366a24..7ad0c21f9aa 100644 --- a/advisories/unreviewed/2022/05/GHSA-xc7p-88w7-44wr/GHSA-xc7p-88w7-44wr.json +++ b/advisories/unreviewed/2022/05/GHSA-xc7p-88w7-44wr/GHSA-xc7p-88w7-44wr.json @@ -7,12 +7,8 @@ "CVE-2009-2922" ], "details": "Absolute path traversal vulnerability in pixaria.image.php in Pixaria Gallery 2.0.0 through 2.3.5 allows remote attackers to read arbitrary files via a base64-encoded file parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xcxh-pxhq-2wrw/GHSA-xcxh-pxhq-2wrw.json b/advisories/unreviewed/2022/05/GHSA-xcxh-pxhq-2wrw/GHSA-xcxh-pxhq-2wrw.json index 6a6859ac8ae..8a89180c28a 100644 --- a/advisories/unreviewed/2022/05/GHSA-xcxh-pxhq-2wrw/GHSA-xcxh-pxhq-2wrw.json +++ b/advisories/unreviewed/2022/05/GHSA-xcxh-pxhq-2wrw/GHSA-xcxh-pxhq-2wrw.json @@ -7,12 +7,8 @@ "CVE-2009-2700" ], "details": "src/network/ssl/qsslcertificate.cpp in Nokia Trolltech Qt 4.x does not properly handle a '\\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xf95-c5hq-2g93/GHSA-xf95-c5hq-2g93.json b/advisories/unreviewed/2022/05/GHSA-xf95-c5hq-2g93/GHSA-xf95-c5hq-2g93.json index 11f1366109b..146bbb3775b 100644 --- a/advisories/unreviewed/2022/05/GHSA-xf95-c5hq-2g93/GHSA-xf95-c5hq-2g93.json +++ b/advisories/unreviewed/2022/05/GHSA-xf95-c5hq-2g93/GHSA-xf95-c5hq-2g93.json @@ -7,12 +7,8 @@ "CVE-2009-3027" ], "details": "VRTSweb.exe in VRTSweb in Symantec Backup Exec Continuous Protection Server (CPS) 11d, 12.0, and 12.5; Veritas NetBackup Operations Manager (NOM) 6.0 GA through 6.5.5; Veritas Backup Reporter (VBR) 6.0 GA through 6.6; Veritas Storage Foundation (SF) 3.5; Veritas Storage Foundation for Windows High Availability (SFWHA) 4.3MP2, 5.0, 5.0RP1a, 5.0RP2, 5.1, and 5.1AP1; Veritas Storage Foundation for High Availability (SFHA) 3.5; Veritas Storage Foundation for Oracle (SFO) 4.1, 5.0, and 5.0.1; Veritas Storage Foundation for DB2 4.1 and 5.0; Veritas Storage Foundation for Sybase 4.1 and 5.0; Veritas Storage Foundation for Oracle Real Application Cluster (SFRAC) 3.5, 4.0, 4.1, and 5.0; Veritas Storage Foundation Manager (SFM) 1.0, 1.0 MP1, 1.1, 1.1.1Ux, 1.1.1Win, and 2.0; Veritas Cluster Server (VCS) 3.5, 4.0, 4.1, and 5.0; Veritas Cluster Server One (VCSOne) 2.0, 2.0.1, and 2.0.2; Veritas Application Director (VAD) 1.1 and 1.1 Platform Expansion; Veritas Cluster Server Management Console (VCSMC) 5.1, 5.5, and 5.5.1; Veritas Storage Foundation Cluster File System (SFCFS) 3.5, 4.0, 4.1, and 5.0; Veritas Storage Foundation Cluster File System for Oracle RAC (SFCFS RAC) 5.0; Veritas Command Central Storage (CCS) 4.x, 5.0, and 5.1; Veritas Command Central Enterprise Reporter (CC-ER) 5.0 GA, 5.0 MP1, 5.0 MP1RP1, and 5.1; Veritas Command Central Storage Change Manager (CC-SCM) 5.0 and 5.1; and Veritas MicroMeasure 5.0 does not properly validate authentication requests, which allows remote attackers to trigger the unpacking of a WAR archive, and execute arbitrary code in the contained files, via crafted data to TCP port 14300.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xgqf-6h84-m649/GHSA-xgqf-6h84-m649.json b/advisories/unreviewed/2022/05/GHSA-xgqf-6h84-m649/GHSA-xgqf-6h84-m649.json index 7f69c627969..5b42de1bed4 100644 --- a/advisories/unreviewed/2022/05/GHSA-xgqf-6h84-m649/GHSA-xgqf-6h84-m649.json +++ b/advisories/unreviewed/2022/05/GHSA-xgqf-6h84-m649/GHSA-xgqf-6h84-m649.json @@ -7,12 +7,8 @@ "CVE-2009-3253" ], "details": "Stack-based buffer overflow in TriceraSoft Swift Ultralite 1.032 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long string in a .M3U playlist file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xh4v-287j-5gp7/GHSA-xh4v-287j-5gp7.json b/advisories/unreviewed/2022/05/GHSA-xh4v-287j-5gp7/GHSA-xh4v-287j-5gp7.json index 1e323f2dd88..d59f1f4e0b3 100644 --- a/advisories/unreviewed/2022/05/GHSA-xh4v-287j-5gp7/GHSA-xh4v-287j-5gp7.json +++ b/advisories/unreviewed/2022/05/GHSA-xh4v-287j-5gp7/GHSA-xh4v-287j-5gp7.json @@ -7,12 +7,8 @@ "CVE-2009-3055" ], "details": "PHP remote file inclusion vulnerability in engine/api/api.class.php in DataLife Engine (DLE) 8.2 allows remote attackers to execute arbitrary PHP code via a URL in the dle_config_api parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xh8q-gjf3-g988/GHSA-xh8q-gjf3-g988.json b/advisories/unreviewed/2022/05/GHSA-xh8q-gjf3-g988/GHSA-xh8q-gjf3-g988.json index c0a54162416..fbd6b83b542 100644 --- a/advisories/unreviewed/2022/05/GHSA-xh8q-gjf3-g988/GHSA-xh8q-gjf3-g988.json +++ b/advisories/unreviewed/2022/05/GHSA-xh8q-gjf3-g988/GHSA-xh8q-gjf3-g988.json @@ -7,12 +7,8 @@ "CVE-2009-3154" ], "details": "SQL injection vulnerability in the Almond Classifieds (com_aclassf) component 7.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the replid parameter in a manw_repl add_form action to index.php, a different vector than CVE-2009-2567.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xj3x-5wmj-qmh3/GHSA-xj3x-5wmj-qmh3.json b/advisories/unreviewed/2022/05/GHSA-xj3x-5wmj-qmh3/GHSA-xj3x-5wmj-qmh3.json index 674903a7391..014146cc3d7 100644 --- a/advisories/unreviewed/2022/05/GHSA-xj3x-5wmj-qmh3/GHSA-xj3x-5wmj-qmh3.json +++ b/advisories/unreviewed/2022/05/GHSA-xj3x-5wmj-qmh3/GHSA-xj3x-5wmj-qmh3.json @@ -7,12 +7,8 @@ "CVE-2009-2888" ], "details": "SQL injection vulnerability in index.php in PHP Scripts Now Hangman allows remote attackers to execute arbitrary SQL commands via the n parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xjwx-qg8w-3x9p/GHSA-xjwx-qg8w-3x9p.json b/advisories/unreviewed/2022/05/GHSA-xjwx-qg8w-3x9p/GHSA-xjwx-qg8w-3x9p.json index de66483550a..56fda8325b2 100644 --- a/advisories/unreviewed/2022/05/GHSA-xjwx-qg8w-3x9p/GHSA-xjwx-qg8w-3x9p.json +++ b/advisories/unreviewed/2022/05/GHSA-xjwx-qg8w-3x9p/GHSA-xjwx-qg8w-3x9p.json @@ -7,12 +7,8 @@ "CVE-2009-3249" ], "details": "Multiple directory traversal vulnerabilities in vtiger CRM 5.0.4 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the module parameter to graph.php; or the (2) module or (3) file parameter to include/Ajax/CommonAjax.php, reachable through modules/Campaigns/CampaignsAjax.php, modules/SalesOrder/SalesOrderAjax.php, modules/System/SystemAjax.php, modules/Products/ProductsAjax.php, modules/uploads/uploadsAjax.php, modules/Dashboard/DashboardAjax.php, modules/Potentials/PotentialsAjax.php, modules/Notes/NotesAjax.php, modules/Faq/FaqAjax.php, modules/Quotes/QuotesAjax.php, modules/Utilities/UtilitiesAjax.php, modules/Calendar/ActivityAjax.php, modules/Calendar/CalendarAjax.php, modules/PurchaseOrder/PurchaseOrderAjax.php, modules/HelpDesk/HelpDeskAjax.php, modules/Invoice/InvoiceAjax.php, modules/Accounts/AccountsAjax.php, modules/Reports/ReportsAjax.php, modules/Contacts/ContactsAjax.php, and modules/Portal/PortalAjax.php; and allow remote authenticated users to include and execute arbitrary local files via a .. (dot dot) in the step parameter in an Import action to the (4) Accounts, (5) Contacts, (6) HelpDesk, (7) Leads, (8) Potentials, (9) Products, or (10) Vendors module, reachable through index.php and related to modules/Import/index.php and multiple Import.php files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xjxh-vgjc-x974/GHSA-xjxh-vgjc-x974.json b/advisories/unreviewed/2022/05/GHSA-xjxh-vgjc-x974/GHSA-xjxh-vgjc-x974.json index f880a1faa04..cd4acd7e717 100644 --- a/advisories/unreviewed/2022/05/GHSA-xjxh-vgjc-x974/GHSA-xjxh-vgjc-x974.json +++ b/advisories/unreviewed/2022/05/GHSA-xjxh-vgjc-x974/GHSA-xjxh-vgjc-x974.json @@ -7,12 +7,8 @@ "CVE-2009-3172" ], "details": "Unspecified vulnerability in Hitachi Groupmax Groupware Server 07-00 through 07-50-/A, Groupmax Server Set 03-00 through 06-52, Groupware Server Set 03-00 through 06-52, and Scheduler Server Set 03-00 through 06-52 has unknown impact and attack vectors related to invalid access rights.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xjxx-h5w2-fphm/GHSA-xjxx-h5w2-fphm.json b/advisories/unreviewed/2022/05/GHSA-xjxx-h5w2-fphm/GHSA-xjxx-h5w2-fphm.json index ac022a0c364..74034802a01 100644 --- a/advisories/unreviewed/2022/05/GHSA-xjxx-h5w2-fphm/GHSA-xjxx-h5w2-fphm.json +++ b/advisories/unreviewed/2022/05/GHSA-xjxx-h5w2-fphm/GHSA-xjxx-h5w2-fphm.json @@ -7,12 +7,8 @@ "CVE-2009-3300" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in the Identity Provider (IdP) 1.3.x before 1.3.4 and 2.x before 2.1.5, and the Service Provider 1.3.x before 1.3.5 and 2.x before 2.3, in Internet2 Middleware Initiative Shibboleth allow remote attackers to inject arbitrary web script or HTML via URLs that are encountered in redirections, and appear in automatically generated forms.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xm3f-7w29-9q8h/GHSA-xm3f-7w29-9q8h.json b/advisories/unreviewed/2022/05/GHSA-xm3f-7w29-9q8h/GHSA-xm3f-7w29-9q8h.json index 3d54d2774a4..f1f3406b8c2 100644 --- a/advisories/unreviewed/2022/05/GHSA-xm3f-7w29-9q8h/GHSA-xm3f-7w29-9q8h.json +++ b/advisories/unreviewed/2022/05/GHSA-xm3f-7w29-9q8h/GHSA-xm3f-7w29-9q8h.json @@ -7,12 +7,8 @@ "CVE-2009-3083" ], "details": "The msn_slp_sip_recv function in libpurple/protocols/msn/slp.c in the MSN protocol plugin in libpurple in Pidgin before 2.6.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an SLP invite message that lacks certain required fields, as demonstrated by a malformed message from a KMess client.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xpgw-whr6-42cx/GHSA-xpgw-whr6-42cx.json b/advisories/unreviewed/2022/05/GHSA-xpgw-whr6-42cx/GHSA-xpgw-whr6-42cx.json index c5490dae357..5bc594611bf 100644 --- a/advisories/unreviewed/2022/05/GHSA-xpgw-whr6-42cx/GHSA-xpgw-whr6-42cx.json +++ b/advisories/unreviewed/2022/05/GHSA-xpgw-whr6-42cx/GHSA-xpgw-whr6-42cx.json @@ -7,12 +7,8 @@ "CVE-2009-2850" ], "details": "Multiple buffer overflows in NASA Common Data Format (CDF) allow context-dependent attackers to execute arbitrary code, as demonstrated using (1) an array index error in the ReadAEDRList64 function, and other errors in the (2) SearchForRecord_r_64, (3) LastRecord64, (4) CDFsel64, and other unspecified functions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xpw9-59vc-m8w9/GHSA-xpw9-59vc-m8w9.json b/advisories/unreviewed/2022/05/GHSA-xpw9-59vc-m8w9/GHSA-xpw9-59vc-m8w9.json index 3ee58ec31f4..d8a31b39b90 100644 --- a/advisories/unreviewed/2022/05/GHSA-xpw9-59vc-m8w9/GHSA-xpw9-59vc-m8w9.json +++ b/advisories/unreviewed/2022/05/GHSA-xpw9-59vc-m8w9/GHSA-xpw9-59vc-m8w9.json @@ -7,12 +7,8 @@ "CVE-2009-3032" ], "details": "Integer overflow in kvolefio.dll 8.5.0.8339 and 10.5.0.0 in the Autonomy KeyView Filter SDK, as used in IBM Lotus Notes 8.5, Symantec Mail Security for Microsoft Exchange 5.0.10 through 5.0.13, and other products, allows context-dependent attackers to execute arbitrary code via a crafted OLE document that triggers a heap-based buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xqh8-x69c-4q93/GHSA-xqh8-x69c-4q93.json b/advisories/unreviewed/2022/05/GHSA-xqh8-x69c-4q93/GHSA-xqh8-x69c-4q93.json index dd6f09bdf75..50173541b54 100644 --- a/advisories/unreviewed/2022/05/GHSA-xqh8-x69c-4q93/GHSA-xqh8-x69c-4q93.json +++ b/advisories/unreviewed/2022/05/GHSA-xqh8-x69c-4q93/GHSA-xqh8-x69c-4q93.json @@ -7,12 +7,8 @@ "CVE-2009-2929" ], "details": "Multiple SQL injection vulnerabilities in TGS Content Management 0.x allow remote attackers to execute arbitrary SQL commands via the (1) tgs_language_id, (2) tpl_dir, (3) referer, (4) user-agent, (5) site, (6) option, (7) db_optimization, (8) owner, (9) admin_email, (10) default_language, and (11) db_host parameters to cms/index.php; and the (12) cmd, (13) s_dir, (14) minutes, (15) s_mask, (16) test3_mp, (17) test15_file1, (18) submit, (19) brute_method, (20) ftp_server_port, (21) userfile14, (22) subj, (23) mysql_l, (24) action, and (25) userfile1 parameters to cms/frontpage_ception.php. NOTE: some of these parameters may be applicable only in nonstandard versions of the product, and cms/frontpage_ception.php may be cms/frontpage_caption.php in all released versions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xqhc-47rf-rgjc/GHSA-xqhc-47rf-rgjc.json b/advisories/unreviewed/2022/05/GHSA-xqhc-47rf-rgjc/GHSA-xqhc-47rf-rgjc.json index a610a9a39fa..d129cdd72f9 100644 --- a/advisories/unreviewed/2022/05/GHSA-xqhc-47rf-rgjc/GHSA-xqhc-47rf-rgjc.json +++ b/advisories/unreviewed/2022/05/GHSA-xqhc-47rf-rgjc/GHSA-xqhc-47rf-rgjc.json @@ -7,12 +7,8 @@ "CVE-2009-2836" ], "details": "Race condition in Login Window in Apple Mac OS X 10.6.x before 10.6.2, when at least one account has a blank password, allows attackers to bypass password authentication and obtain login access to an arbitrary account via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xrpm-74v3-f6fq/GHSA-xrpm-74v3-f6fq.json b/advisories/unreviewed/2022/05/GHSA-xrpm-74v3-f6fq/GHSA-xrpm-74v3-f6fq.json index 1044d91749e..aa7141c05db 100644 --- a/advisories/unreviewed/2022/05/GHSA-xrpm-74v3-f6fq/GHSA-xrpm-74v3-f6fq.json +++ b/advisories/unreviewed/2022/05/GHSA-xrpm-74v3-f6fq/GHSA-xrpm-74v3-f6fq.json @@ -7,12 +7,8 @@ "CVE-2009-2493" ], "details": "The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1, and Visual C++ 2005 SP1 and 2008 Gold and SP1; and Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2; does not properly restrict use of OleLoadFromStream in instantiating objects from data streams, which allows remote attackers to execute arbitrary code via a crafted HTML document with an ATL (1) component or (2) control, related to ATL headers and bypassing security policies, aka \"ATL COM Initialization Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -164,9 +160,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xv8g-4jv9-wpq8/GHSA-xv8g-4jv9-wpq8.json b/advisories/unreviewed/2022/05/GHSA-xv8g-4jv9-wpq8/GHSA-xv8g-4jv9-wpq8.json index e525fcd48e1..b412a44c3ea 100644 --- a/advisories/unreviewed/2022/05/GHSA-xv8g-4jv9-wpq8/GHSA-xv8g-4jv9-wpq8.json +++ b/advisories/unreviewed/2022/05/GHSA-xv8g-4jv9-wpq8/GHSA-xv8g-4jv9-wpq8.json @@ -7,12 +7,8 @@ "CVE-2009-2611" ], "details": "Directory traversal vulnerability in infusions/last_seen_users_panel/last_seen_users_panel.php in MyFusion (aka MyF) 6 Beta, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the settings[locale] parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xw9p-2mr3-g9mx/GHSA-xw9p-2mr3-g9mx.json b/advisories/unreviewed/2022/05/GHSA-xw9p-2mr3-g9mx/GHSA-xw9p-2mr3-g9mx.json index 04d9c695cf8..098c24a55e4 100644 --- a/advisories/unreviewed/2022/05/GHSA-xw9p-2mr3-g9mx/GHSA-xw9p-2mr3-g9mx.json +++ b/advisories/unreviewed/2022/05/GHSA-xw9p-2mr3-g9mx/GHSA-xw9p-2mr3-g9mx.json @@ -7,12 +7,8 @@ "CVE-2009-3014" ], "details": "Mozilla Firefox 3.0.13 and earlier, 3.5, 3.6 a1 pre, and 3.7 a1 pre; SeaMonkey 1.1.17; and Mozilla 1.7.x and earlier do not properly handle javascript: URIs in HTML links within 302 error documents sent from web servers, which allows user-assisted remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Location HTTP response header or (2) specifying the content of a Location HTTP response header.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xxfr-xhcv-m89f/GHSA-xxfr-xhcv-m89f.json b/advisories/unreviewed/2022/05/GHSA-xxfr-xhcv-m89f/GHSA-xxfr-xhcv-m89f.json index 5d63b3bdd0d..5ef87dea732 100644 --- a/advisories/unreviewed/2022/05/GHSA-xxfr-xhcv-m89f/GHSA-xxfr-xhcv-m89f.json +++ b/advisories/unreviewed/2022/05/GHSA-xxfr-xhcv-m89f/GHSA-xxfr-xhcv-m89f.json @@ -7,12 +7,8 @@ "CVE-2009-2711" ], "details": "XScreenSaver in Sun Solaris 9 and 10, OpenSolaris before snv_120, and X11 6.4.1 for Solaris 8, when the Xorg or Xnewt server is used, allows physically proximate attackers to obtain sensitive information by reading popup windows, which are displayed even when the screen is locked, a different vulnerability than CVE-2009-1276.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xxm5-p2jg-xh9g/GHSA-xxm5-p2jg-xh9g.json b/advisories/unreviewed/2022/05/GHSA-xxm5-p2jg-xh9g/GHSA-xxm5-p2jg-xh9g.json index 7fdfa8db21d..5f0af055368 100644 --- a/advisories/unreviewed/2022/05/GHSA-xxm5-p2jg-xh9g/GHSA-xxm5-p2jg-xh9g.json +++ b/advisories/unreviewed/2022/05/GHSA-xxm5-p2jg-xh9g/GHSA-xxm5-p2jg-xh9g.json @@ -7,12 +7,8 @@ "CVE-2009-2891" ], "details": "SQL injection vulnerability in list.php in PHP Scripts Now Riddles allows remote attackers to execute arbitrary SQL commands via the catid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-p72g-vj73-w67m/GHSA-p72g-vj73-w67m.json b/advisories/unreviewed/2022/11/GHSA-p72g-vj73-w67m/GHSA-p72g-vj73-w67m.json index 187f19e4c12..bdba01cbf02 100644 --- a/advisories/unreviewed/2022/11/GHSA-p72g-vj73-w67m/GHSA-p72g-vj73-w67m.json +++ b/advisories/unreviewed/2022/11/GHSA-p72g-vj73-w67m/GHSA-p72g-vj73-w67m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/03/GHSA-4gvm-5c8j-gw57/GHSA-4gvm-5c8j-gw57.json b/advisories/unreviewed/2023/03/GHSA-4gvm-5c8j-gw57/GHSA-4gvm-5c8j-gw57.json index cb62c29b7d8..116ea81492b 100644 --- a/advisories/unreviewed/2023/03/GHSA-4gvm-5c8j-gw57/GHSA-4gvm-5c8j-gw57.json +++ b/advisories/unreviewed/2023/03/GHSA-4gvm-5c8j-gw57/GHSA-4gvm-5c8j-gw57.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/03/GHSA-f3hr-rv72-879p/GHSA-f3hr-rv72-879p.json b/advisories/unreviewed/2023/03/GHSA-f3hr-rv72-879p/GHSA-f3hr-rv72-879p.json index 4a7146bbcbc..d05927ba2dd 100644 --- a/advisories/unreviewed/2023/03/GHSA-f3hr-rv72-879p/GHSA-f3hr-rv72-879p.json +++ b/advisories/unreviewed/2023/03/GHSA-f3hr-rv72-879p/GHSA-f3hr-rv72-879p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/03/GHSA-m2q7-9c76-qc45/GHSA-m2q7-9c76-qc45.json b/advisories/unreviewed/2023/03/GHSA-m2q7-9c76-qc45/GHSA-m2q7-9c76-qc45.json index d8d66f0c91e..438b773a226 100644 --- a/advisories/unreviewed/2023/03/GHSA-m2q7-9c76-qc45/GHSA-m2q7-9c76-qc45.json +++ b/advisories/unreviewed/2023/03/GHSA-m2q7-9c76-qc45/GHSA-m2q7-9c76-qc45.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -47,9 +45,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/03/GHSA-rpxw-v4qw-9cwh/GHSA-rpxw-v4qw-9cwh.json b/advisories/unreviewed/2023/03/GHSA-rpxw-v4qw-9cwh/GHSA-rpxw-v4qw-9cwh.json index bd49132e7b2..8d56b14391d 100644 --- a/advisories/unreviewed/2023/03/GHSA-rpxw-v4qw-9cwh/GHSA-rpxw-v4qw-9cwh.json +++ b/advisories/unreviewed/2023/03/GHSA-rpxw-v4qw-9cwh/GHSA-rpxw-v4qw-9cwh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/03/GHSA-v5g3-mw88-c3jm/GHSA-v5g3-mw88-c3jm.json b/advisories/unreviewed/2023/03/GHSA-v5g3-mw88-c3jm/GHSA-v5g3-mw88-c3jm.json index 0855cdbf722..f0864683316 100644 --- a/advisories/unreviewed/2023/03/GHSA-v5g3-mw88-c3jm/GHSA-v5g3-mw88-c3jm.json +++ b/advisories/unreviewed/2023/03/GHSA-v5g3-mw88-c3jm/GHSA-v5g3-mw88-c3jm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/03/GHSA-v82w-4932-72hf/GHSA-v82w-4932-72hf.json b/advisories/unreviewed/2023/03/GHSA-v82w-4932-72hf/GHSA-v82w-4932-72hf.json index 09ad7371bce..5fecb811432 100644 --- a/advisories/unreviewed/2023/03/GHSA-v82w-4932-72hf/GHSA-v82w-4932-72hf.json +++ b/advisories/unreviewed/2023/03/GHSA-v82w-4932-72hf/GHSA-v82w-4932-72hf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-7r95-w762-gwvp/GHSA-7r95-w762-gwvp.json b/advisories/unreviewed/2023/04/GHSA-7r95-w762-gwvp/GHSA-7r95-w762-gwvp.json index d5977826508..845f041626f 100644 --- a/advisories/unreviewed/2023/04/GHSA-7r95-w762-gwvp/GHSA-7r95-w762-gwvp.json +++ b/advisories/unreviewed/2023/04/GHSA-7r95-w762-gwvp/GHSA-7r95-w762-gwvp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/04/GHSA-8r7j-pj39-v7xh/GHSA-8r7j-pj39-v7xh.json b/advisories/unreviewed/2023/04/GHSA-8r7j-pj39-v7xh/GHSA-8r7j-pj39-v7xh.json index 4b37bf1d53b..61642da8713 100644 --- a/advisories/unreviewed/2023/04/GHSA-8r7j-pj39-v7xh/GHSA-8r7j-pj39-v7xh.json +++ b/advisories/unreviewed/2023/04/GHSA-8r7j-pj39-v7xh/GHSA-8r7j-pj39-v7xh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/06/GHSA-9pv7-q9jh-w7p4/GHSA-9pv7-q9jh-w7p4.json b/advisories/unreviewed/2023/06/GHSA-9pv7-q9jh-w7p4/GHSA-9pv7-q9jh-w7p4.json index 914571f4df6..30f8280f52d 100644 --- a/advisories/unreviewed/2023/06/GHSA-9pv7-q9jh-w7p4/GHSA-9pv7-q9jh-w7p4.json +++ b/advisories/unreviewed/2023/06/GHSA-9pv7-q9jh-w7p4/GHSA-9pv7-q9jh-w7p4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/01/GHSA-88xj-mj86-xvqx/GHSA-88xj-mj86-xvqx.json b/advisories/unreviewed/2024/01/GHSA-88xj-mj86-xvqx/GHSA-88xj-mj86-xvqx.json index f1768ef2076..d8d5c08c444 100644 --- a/advisories/unreviewed/2024/01/GHSA-88xj-mj86-xvqx/GHSA-88xj-mj86-xvqx.json +++ b/advisories/unreviewed/2024/01/GHSA-88xj-mj86-xvqx/GHSA-88xj-mj86-xvqx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/01/GHSA-c9hw-3r9q-9pc2/GHSA-c9hw-3r9q-9pc2.json b/advisories/unreviewed/2024/01/GHSA-c9hw-3r9q-9pc2/GHSA-c9hw-3r9q-9pc2.json index a60a75497a0..bbdc62c9144 100644 --- a/advisories/unreviewed/2024/01/GHSA-c9hw-3r9q-9pc2/GHSA-c9hw-3r9q-9pc2.json +++ b/advisories/unreviewed/2024/01/GHSA-c9hw-3r9q-9pc2/GHSA-c9hw-3r9q-9pc2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/01/GHSA-jr8p-mp3g-22ph/GHSA-jr8p-mp3g-22ph.json b/advisories/unreviewed/2024/01/GHSA-jr8p-mp3g-22ph/GHSA-jr8p-mp3g-22ph.json index 8b7b0d58ce7..455b4ba399f 100644 --- a/advisories/unreviewed/2024/01/GHSA-jr8p-mp3g-22ph/GHSA-jr8p-mp3g-22ph.json +++ b/advisories/unreviewed/2024/01/GHSA-jr8p-mp3g-22ph/GHSA-jr8p-mp3g-22ph.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/01/GHSA-qhv3-pfgm-69jh/GHSA-qhv3-pfgm-69jh.json b/advisories/unreviewed/2024/01/GHSA-qhv3-pfgm-69jh/GHSA-qhv3-pfgm-69jh.json index 3c8d2c31fdc..8cac7b989ed 100644 --- a/advisories/unreviewed/2024/01/GHSA-qhv3-pfgm-69jh/GHSA-qhv3-pfgm-69jh.json +++ b/advisories/unreviewed/2024/01/GHSA-qhv3-pfgm-69jh/GHSA-qhv3-pfgm-69jh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/01/GHSA-r33h-q262-63mv/GHSA-r33h-q262-63mv.json b/advisories/unreviewed/2024/01/GHSA-r33h-q262-63mv/GHSA-r33h-q262-63mv.json index bf19c901193..606cebb5012 100644 --- a/advisories/unreviewed/2024/01/GHSA-r33h-q262-63mv/GHSA-r33h-q262-63mv.json +++ b/advisories/unreviewed/2024/01/GHSA-r33h-q262-63mv/GHSA-r33h-q262-63mv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-57hj-hrjv-grpg/GHSA-57hj-hrjv-grpg.json b/advisories/unreviewed/2024/04/GHSA-57hj-hrjv-grpg/GHSA-57hj-hrjv-grpg.json index 623f1a627e8..f5e744faafa 100644 --- a/advisories/unreviewed/2024/04/GHSA-57hj-hrjv-grpg/GHSA-57hj-hrjv-grpg.json +++ b/advisories/unreviewed/2024/04/GHSA-57hj-hrjv-grpg/GHSA-57hj-hrjv-grpg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-8c6j-52q3-w3c5/GHSA-8c6j-52q3-w3c5.json b/advisories/unreviewed/2024/04/GHSA-8c6j-52q3-w3c5/GHSA-8c6j-52q3-w3c5.json index 320ea1d41d4..56aa01e7ee2 100644 --- a/advisories/unreviewed/2024/04/GHSA-8c6j-52q3-w3c5/GHSA-8c6j-52q3-w3c5.json +++ b/advisories/unreviewed/2024/04/GHSA-8c6j-52q3-w3c5/GHSA-8c6j-52q3-w3c5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-g9gh-7wv9-6wcr/GHSA-g9gh-7wv9-6wcr.json b/advisories/unreviewed/2024/04/GHSA-g9gh-7wv9-6wcr/GHSA-g9gh-7wv9-6wcr.json index affde2ffef2..8829b2abc15 100644 --- a/advisories/unreviewed/2024/04/GHSA-g9gh-7wv9-6wcr/GHSA-g9gh-7wv9-6wcr.json +++ b/advisories/unreviewed/2024/04/GHSA-g9gh-7wv9-6wcr/GHSA-g9gh-7wv9-6wcr.json @@ -7,12 +7,8 @@ "CVE-2023-52724" ], "details": "Open Networking Foundation SD-RAN onos-kpimon 0.4.7 allows out-of-bounds array access in the processIndicationFormat1 function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-wjjj-mh65-98qx/GHSA-wjjj-mh65-98qx.json b/advisories/unreviewed/2024/04/GHSA-wjjj-mh65-98qx/GHSA-wjjj-mh65-98qx.json index b84d1295059..4c965290b4e 100644 --- a/advisories/unreviewed/2024/04/GHSA-wjjj-mh65-98qx/GHSA-wjjj-mh65-98qx.json +++ b/advisories/unreviewed/2024/04/GHSA-wjjj-mh65-98qx/GHSA-wjjj-mh65-98qx.json @@ -7,12 +7,8 @@ "CVE-2023-52727" ], "details": "Open Networking Foundation SD-RAN ONOS onos-lib-go 0.10.25 allows an index out-of-range condition in parseAlignBits.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-33rp-rrfh-h9w8/GHSA-33rp-rrfh-h9w8.json b/advisories/unreviewed/2024/05/GHSA-33rp-rrfh-h9w8/GHSA-33rp-rrfh-h9w8.json index cfb30ad3b3d..209c8b3ed44 100644 --- a/advisories/unreviewed/2024/05/GHSA-33rp-rrfh-h9w8/GHSA-33rp-rrfh-h9w8.json +++ b/advisories/unreviewed/2024/05/GHSA-33rp-rrfh-h9w8/GHSA-33rp-rrfh-h9w8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-cv9w-4mcm-4cc2/GHSA-cv9w-4mcm-4cc2.json b/advisories/unreviewed/2024/05/GHSA-cv9w-4mcm-4cc2/GHSA-cv9w-4mcm-4cc2.json index 70987f831be..623d57e4aee 100644 --- a/advisories/unreviewed/2024/05/GHSA-cv9w-4mcm-4cc2/GHSA-cv9w-4mcm-4cc2.json +++ b/advisories/unreviewed/2024/05/GHSA-cv9w-4mcm-4cc2/GHSA-cv9w-4mcm-4cc2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-fmvf-fm6q-vpjg/GHSA-fmvf-fm6q-vpjg.json b/advisories/unreviewed/2024/05/GHSA-fmvf-fm6q-vpjg/GHSA-fmvf-fm6q-vpjg.json index 57e8a8cea88..df89badcab5 100644 --- a/advisories/unreviewed/2024/05/GHSA-fmvf-fm6q-vpjg/GHSA-fmvf-fm6q-vpjg.json +++ b/advisories/unreviewed/2024/05/GHSA-fmvf-fm6q-vpjg/GHSA-fmvf-fm6q-vpjg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-vv62-jfwq-693v/GHSA-vv62-jfwq-693v.json b/advisories/unreviewed/2024/05/GHSA-vv62-jfwq-693v/GHSA-vv62-jfwq-693v.json index 0f957cdeff7..503e1a6ac6e 100644 --- a/advisories/unreviewed/2024/05/GHSA-vv62-jfwq-693v/GHSA-vv62-jfwq-693v.json +++ b/advisories/unreviewed/2024/05/GHSA-vv62-jfwq-693v/GHSA-vv62-jfwq-693v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-299v-fghf-v92x/GHSA-299v-fghf-v92x.json b/advisories/unreviewed/2024/06/GHSA-299v-fghf-v92x/GHSA-299v-fghf-v92x.json index 3e0d3146211..2c77d60b7f0 100644 --- a/advisories/unreviewed/2024/06/GHSA-299v-fghf-v92x/GHSA-299v-fghf-v92x.json +++ b/advisories/unreviewed/2024/06/GHSA-299v-fghf-v92x/GHSA-299v-fghf-v92x.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-2xh4-pf7v-vh6h/GHSA-2xh4-pf7v-vh6h.json b/advisories/unreviewed/2024/06/GHSA-2xh4-pf7v-vh6h/GHSA-2xh4-pf7v-vh6h.json index c34fc2c6ff2..b39cc12ce37 100644 --- a/advisories/unreviewed/2024/06/GHSA-2xh4-pf7v-vh6h/GHSA-2xh4-pf7v-vh6h.json +++ b/advisories/unreviewed/2024/06/GHSA-2xh4-pf7v-vh6h/GHSA-2xh4-pf7v-vh6h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-3vq2-9cm2-rhrv/GHSA-3vq2-9cm2-rhrv.json b/advisories/unreviewed/2024/06/GHSA-3vq2-9cm2-rhrv/GHSA-3vq2-9cm2-rhrv.json index 5ea8399b933..bb630e96d86 100644 --- a/advisories/unreviewed/2024/06/GHSA-3vq2-9cm2-rhrv/GHSA-3vq2-9cm2-rhrv.json +++ b/advisories/unreviewed/2024/06/GHSA-3vq2-9cm2-rhrv/GHSA-3vq2-9cm2-rhrv.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-4xv7-gmf4-mjpg/GHSA-4xv7-gmf4-mjpg.json b/advisories/unreviewed/2024/06/GHSA-4xv7-gmf4-mjpg/GHSA-4xv7-gmf4-mjpg.json index c8689202d7f..942020111d1 100644 --- a/advisories/unreviewed/2024/06/GHSA-4xv7-gmf4-mjpg/GHSA-4xv7-gmf4-mjpg.json +++ b/advisories/unreviewed/2024/06/GHSA-4xv7-gmf4-mjpg/GHSA-4xv7-gmf4-mjpg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-562p-f5h4-c4cw/GHSA-562p-f5h4-c4cw.json b/advisories/unreviewed/2024/06/GHSA-562p-f5h4-c4cw/GHSA-562p-f5h4-c4cw.json index 8fb10abfaef..c7bc15cde6f 100644 --- a/advisories/unreviewed/2024/06/GHSA-562p-f5h4-c4cw/GHSA-562p-f5h4-c4cw.json +++ b/advisories/unreviewed/2024/06/GHSA-562p-f5h4-c4cw/GHSA-562p-f5h4-c4cw.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-5qjp-9vcm-q2j2/GHSA-5qjp-9vcm-q2j2.json b/advisories/unreviewed/2024/06/GHSA-5qjp-9vcm-q2j2/GHSA-5qjp-9vcm-q2j2.json index 7dec17fe9ae..6f88daf19ed 100644 --- a/advisories/unreviewed/2024/06/GHSA-5qjp-9vcm-q2j2/GHSA-5qjp-9vcm-q2j2.json +++ b/advisories/unreviewed/2024/06/GHSA-5qjp-9vcm-q2j2/GHSA-5qjp-9vcm-q2j2.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-628h-r6p2-r4vv/GHSA-628h-r6p2-r4vv.json b/advisories/unreviewed/2024/06/GHSA-628h-r6p2-r4vv/GHSA-628h-r6p2-r4vv.json index 34287064170..e63b6070f07 100644 --- a/advisories/unreviewed/2024/06/GHSA-628h-r6p2-r4vv/GHSA-628h-r6p2-r4vv.json +++ b/advisories/unreviewed/2024/06/GHSA-628h-r6p2-r4vv/GHSA-628h-r6p2-r4vv.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-674x-pqc6-c599/GHSA-674x-pqc6-c599.json b/advisories/unreviewed/2024/06/GHSA-674x-pqc6-c599/GHSA-674x-pqc6-c599.json index 0b001476d7d..297046a97f3 100644 --- a/advisories/unreviewed/2024/06/GHSA-674x-pqc6-c599/GHSA-674x-pqc6-c599.json +++ b/advisories/unreviewed/2024/06/GHSA-674x-pqc6-c599/GHSA-674x-pqc6-c599.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-6c99-7p5q-2gvx/GHSA-6c99-7p5q-2gvx.json b/advisories/unreviewed/2024/06/GHSA-6c99-7p5q-2gvx/GHSA-6c99-7p5q-2gvx.json index ad1806f422d..8c95fd9590a 100644 --- a/advisories/unreviewed/2024/06/GHSA-6c99-7p5q-2gvx/GHSA-6c99-7p5q-2gvx.json +++ b/advisories/unreviewed/2024/06/GHSA-6c99-7p5q-2gvx/GHSA-6c99-7p5q-2gvx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-6p38-mpcr-g57w/GHSA-6p38-mpcr-g57w.json b/advisories/unreviewed/2024/06/GHSA-6p38-mpcr-g57w/GHSA-6p38-mpcr-g57w.json index b495a18a660..f8243f4f693 100644 --- a/advisories/unreviewed/2024/06/GHSA-6p38-mpcr-g57w/GHSA-6p38-mpcr-g57w.json +++ b/advisories/unreviewed/2024/06/GHSA-6p38-mpcr-g57w/GHSA-6p38-mpcr-g57w.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-6v98-q8cq-9rx2/GHSA-6v98-q8cq-9rx2.json b/advisories/unreviewed/2024/06/GHSA-6v98-q8cq-9rx2/GHSA-6v98-q8cq-9rx2.json index ffec68d30ea..545e3340f0f 100644 --- a/advisories/unreviewed/2024/06/GHSA-6v98-q8cq-9rx2/GHSA-6v98-q8cq-9rx2.json +++ b/advisories/unreviewed/2024/06/GHSA-6v98-q8cq-9rx2/GHSA-6v98-q8cq-9rx2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-c3qr-8rx9-m6r2/GHSA-c3qr-8rx9-m6r2.json b/advisories/unreviewed/2024/06/GHSA-c3qr-8rx9-m6r2/GHSA-c3qr-8rx9-m6r2.json index f3e46981150..c96b6ebc2d1 100644 --- a/advisories/unreviewed/2024/06/GHSA-c3qr-8rx9-m6r2/GHSA-c3qr-8rx9-m6r2.json +++ b/advisories/unreviewed/2024/06/GHSA-c3qr-8rx9-m6r2/GHSA-c3qr-8rx9-m6r2.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-f989-r6c7-44p6/GHSA-f989-r6c7-44p6.json b/advisories/unreviewed/2024/06/GHSA-f989-r6c7-44p6/GHSA-f989-r6c7-44p6.json index 645bcff9945..40ac3739628 100644 --- a/advisories/unreviewed/2024/06/GHSA-f989-r6c7-44p6/GHSA-f989-r6c7-44p6.json +++ b/advisories/unreviewed/2024/06/GHSA-f989-r6c7-44p6/GHSA-f989-r6c7-44p6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-g868-j635-p59m/GHSA-g868-j635-p59m.json b/advisories/unreviewed/2024/06/GHSA-g868-j635-p59m/GHSA-g868-j635-p59m.json index eb014919781..651e8ad4c66 100644 --- a/advisories/unreviewed/2024/06/GHSA-g868-j635-p59m/GHSA-g868-j635-p59m.json +++ b/advisories/unreviewed/2024/06/GHSA-g868-j635-p59m/GHSA-g868-j635-p59m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-gfx2-f362-7f24/GHSA-gfx2-f362-7f24.json b/advisories/unreviewed/2024/06/GHSA-gfx2-f362-7f24/GHSA-gfx2-f362-7f24.json index 86d75ad1861..f09a5727827 100644 --- a/advisories/unreviewed/2024/06/GHSA-gfx2-f362-7f24/GHSA-gfx2-f362-7f24.json +++ b/advisories/unreviewed/2024/06/GHSA-gfx2-f362-7f24/GHSA-gfx2-f362-7f24.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-h8w4-4g94-23mh/GHSA-h8w4-4g94-23mh.json b/advisories/unreviewed/2024/06/GHSA-h8w4-4g94-23mh/GHSA-h8w4-4g94-23mh.json index 08af3d0864c..0df03d86f7c 100644 --- a/advisories/unreviewed/2024/06/GHSA-h8w4-4g94-23mh/GHSA-h8w4-4g94-23mh.json +++ b/advisories/unreviewed/2024/06/GHSA-h8w4-4g94-23mh/GHSA-h8w4-4g94-23mh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-jfv8-vg3m-73pc/GHSA-jfv8-vg3m-73pc.json b/advisories/unreviewed/2024/06/GHSA-jfv8-vg3m-73pc/GHSA-jfv8-vg3m-73pc.json index 4d91e5eb9b6..940db81c22d 100644 --- a/advisories/unreviewed/2024/06/GHSA-jfv8-vg3m-73pc/GHSA-jfv8-vg3m-73pc.json +++ b/advisories/unreviewed/2024/06/GHSA-jfv8-vg3m-73pc/GHSA-jfv8-vg3m-73pc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-jwr6-46q6-xcr4/GHSA-jwr6-46q6-xcr4.json b/advisories/unreviewed/2024/06/GHSA-jwr6-46q6-xcr4/GHSA-jwr6-46q6-xcr4.json index b80b317fd9f..ee8fce27314 100644 --- a/advisories/unreviewed/2024/06/GHSA-jwr6-46q6-xcr4/GHSA-jwr6-46q6-xcr4.json +++ b/advisories/unreviewed/2024/06/GHSA-jwr6-46q6-xcr4/GHSA-jwr6-46q6-xcr4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-m576-86pq-hpp4/GHSA-m576-86pq-hpp4.json b/advisories/unreviewed/2024/06/GHSA-m576-86pq-hpp4/GHSA-m576-86pq-hpp4.json index 0da3bf80a30..bf29f5c436c 100644 --- a/advisories/unreviewed/2024/06/GHSA-m576-86pq-hpp4/GHSA-m576-86pq-hpp4.json +++ b/advisories/unreviewed/2024/06/GHSA-m576-86pq-hpp4/GHSA-m576-86pq-hpp4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-m9w6-r7wm-g37h/GHSA-m9w6-r7wm-g37h.json b/advisories/unreviewed/2024/06/GHSA-m9w6-r7wm-g37h/GHSA-m9w6-r7wm-g37h.json index 8ffe4943098..27a84bc4125 100644 --- a/advisories/unreviewed/2024/06/GHSA-m9w6-r7wm-g37h/GHSA-m9w6-r7wm-g37h.json +++ b/advisories/unreviewed/2024/06/GHSA-m9w6-r7wm-g37h/GHSA-m9w6-r7wm-g37h.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-mf2w-j66c-qcm9/GHSA-mf2w-j66c-qcm9.json b/advisories/unreviewed/2024/06/GHSA-mf2w-j66c-qcm9/GHSA-mf2w-j66c-qcm9.json index 3e2d75b8092..3187aa1cd3b 100644 --- a/advisories/unreviewed/2024/06/GHSA-mf2w-j66c-qcm9/GHSA-mf2w-j66c-qcm9.json +++ b/advisories/unreviewed/2024/06/GHSA-mf2w-j66c-qcm9/GHSA-mf2w-j66c-qcm9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-mhgx-vc3w-x7h5/GHSA-mhgx-vc3w-x7h5.json b/advisories/unreviewed/2024/06/GHSA-mhgx-vc3w-x7h5/GHSA-mhgx-vc3w-x7h5.json index 6fd0326dff6..b45cfd54416 100644 --- a/advisories/unreviewed/2024/06/GHSA-mhgx-vc3w-x7h5/GHSA-mhgx-vc3w-x7h5.json +++ b/advisories/unreviewed/2024/06/GHSA-mhgx-vc3w-x7h5/GHSA-mhgx-vc3w-x7h5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-mv8j-pg39-6vw9/GHSA-mv8j-pg39-6vw9.json b/advisories/unreviewed/2024/06/GHSA-mv8j-pg39-6vw9/GHSA-mv8j-pg39-6vw9.json index 5853054f195..a2dcb732285 100644 --- a/advisories/unreviewed/2024/06/GHSA-mv8j-pg39-6vw9/GHSA-mv8j-pg39-6vw9.json +++ b/advisories/unreviewed/2024/06/GHSA-mv8j-pg39-6vw9/GHSA-mv8j-pg39-6vw9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-pcmr-ff73-xcj5/GHSA-pcmr-ff73-xcj5.json b/advisories/unreviewed/2024/06/GHSA-pcmr-ff73-xcj5/GHSA-pcmr-ff73-xcj5.json index d2641829746..c8caa7c86aa 100644 --- a/advisories/unreviewed/2024/06/GHSA-pcmr-ff73-xcj5/GHSA-pcmr-ff73-xcj5.json +++ b/advisories/unreviewed/2024/06/GHSA-pcmr-ff73-xcj5/GHSA-pcmr-ff73-xcj5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "WEB", diff --git a/advisories/unreviewed/2024/06/GHSA-qpvg-vp7c-mg9m/GHSA-qpvg-vp7c-mg9m.json b/advisories/unreviewed/2024/06/GHSA-qpvg-vp7c-mg9m/GHSA-qpvg-vp7c-mg9m.json index dc928a78bb1..e8fad5f3e19 100644 --- a/advisories/unreviewed/2024/06/GHSA-qpvg-vp7c-mg9m/GHSA-qpvg-vp7c-mg9m.json +++ b/advisories/unreviewed/2024/06/GHSA-qpvg-vp7c-mg9m/GHSA-qpvg-vp7c-mg9m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-rwxj-58wx-7h6x/GHSA-rwxj-58wx-7h6x.json b/advisories/unreviewed/2024/06/GHSA-rwxj-58wx-7h6x/GHSA-rwxj-58wx-7h6x.json index d812ee392ec..33e09a8238f 100644 --- a/advisories/unreviewed/2024/06/GHSA-rwxj-58wx-7h6x/GHSA-rwxj-58wx-7h6x.json +++ b/advisories/unreviewed/2024/06/GHSA-rwxj-58wx-7h6x/GHSA-rwxj-58wx-7h6x.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-wx67-x394-5q2f/GHSA-wx67-x394-5q2f.json b/advisories/unreviewed/2024/06/GHSA-wx67-x394-5q2f/GHSA-wx67-x394-5q2f.json index 1d1931e609c..8be1a1bd5e2 100644 --- a/advisories/unreviewed/2024/06/GHSA-wx67-x394-5q2f/GHSA-wx67-x394-5q2f.json +++ b/advisories/unreviewed/2024/06/GHSA-wx67-x394-5q2f/GHSA-wx67-x394-5q2f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-2wm2-45c2-f92h/GHSA-2wm2-45c2-f92h.json b/advisories/unreviewed/2024/07/GHSA-2wm2-45c2-f92h/GHSA-2wm2-45c2-f92h.json index 1ca26099762..6c355478c19 100644 --- a/advisories/unreviewed/2024/07/GHSA-2wm2-45c2-f92h/GHSA-2wm2-45c2-f92h.json +++ b/advisories/unreviewed/2024/07/GHSA-2wm2-45c2-f92h/GHSA-2wm2-45c2-f92h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-2x53-jv7f-c2x5/GHSA-2x53-jv7f-c2x5.json b/advisories/unreviewed/2024/07/GHSA-2x53-jv7f-c2x5/GHSA-2x53-jv7f-c2x5.json index c7191db11a8..00e565422e4 100644 --- a/advisories/unreviewed/2024/07/GHSA-2x53-jv7f-c2x5/GHSA-2x53-jv7f-c2x5.json +++ b/advisories/unreviewed/2024/07/GHSA-2x53-jv7f-c2x5/GHSA-2x53-jv7f-c2x5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-4w6x-hxgr-c3q5/GHSA-4w6x-hxgr-c3q5.json b/advisories/unreviewed/2024/07/GHSA-4w6x-hxgr-c3q5/GHSA-4w6x-hxgr-c3q5.json index 459c19e903d..2c178d6c541 100644 --- a/advisories/unreviewed/2024/07/GHSA-4w6x-hxgr-c3q5/GHSA-4w6x-hxgr-c3q5.json +++ b/advisories/unreviewed/2024/07/GHSA-4w6x-hxgr-c3q5/GHSA-4w6x-hxgr-c3q5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-747x-f8jr-j7m2/GHSA-747x-f8jr-j7m2.json b/advisories/unreviewed/2024/07/GHSA-747x-f8jr-j7m2/GHSA-747x-f8jr-j7m2.json index 596ee7ca82c..80131c41d07 100644 --- a/advisories/unreviewed/2024/07/GHSA-747x-f8jr-j7m2/GHSA-747x-f8jr-j7m2.json +++ b/advisories/unreviewed/2024/07/GHSA-747x-f8jr-j7m2/GHSA-747x-f8jr-j7m2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-99jj-f2xq-29qh/GHSA-99jj-f2xq-29qh.json b/advisories/unreviewed/2024/07/GHSA-99jj-f2xq-29qh/GHSA-99jj-f2xq-29qh.json index 35baa9d8b60..ded234d41c2 100644 --- a/advisories/unreviewed/2024/07/GHSA-99jj-f2xq-29qh/GHSA-99jj-f2xq-29qh.json +++ b/advisories/unreviewed/2024/07/GHSA-99jj-f2xq-29qh/GHSA-99jj-f2xq-29qh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-9f75-gjv3-f63r/GHSA-9f75-gjv3-f63r.json b/advisories/unreviewed/2024/07/GHSA-9f75-gjv3-f63r/GHSA-9f75-gjv3-f63r.json index 90bf0f80240..018be17b289 100644 --- a/advisories/unreviewed/2024/07/GHSA-9f75-gjv3-f63r/GHSA-9f75-gjv3-f63r.json +++ b/advisories/unreviewed/2024/07/GHSA-9f75-gjv3-f63r/GHSA-9f75-gjv3-f63r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-9g4r-89hx-hv6j/GHSA-9g4r-89hx-hv6j.json b/advisories/unreviewed/2024/07/GHSA-9g4r-89hx-hv6j/GHSA-9g4r-89hx-hv6j.json index 802e24aa9e8..a323c54ae19 100644 --- a/advisories/unreviewed/2024/07/GHSA-9g4r-89hx-hv6j/GHSA-9g4r-89hx-hv6j.json +++ b/advisories/unreviewed/2024/07/GHSA-9g4r-89hx-hv6j/GHSA-9g4r-89hx-hv6j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-9g8f-2366-pj88/GHSA-9g8f-2366-pj88.json b/advisories/unreviewed/2024/07/GHSA-9g8f-2366-pj88/GHSA-9g8f-2366-pj88.json index c027b7367a6..ef957e4db21 100644 --- a/advisories/unreviewed/2024/07/GHSA-9g8f-2366-pj88/GHSA-9g8f-2366-pj88.json +++ b/advisories/unreviewed/2024/07/GHSA-9g8f-2366-pj88/GHSA-9g8f-2366-pj88.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-9hx6-x24q-crmv/GHSA-9hx6-x24q-crmv.json b/advisories/unreviewed/2024/07/GHSA-9hx6-x24q-crmv/GHSA-9hx6-x24q-crmv.json index 6f71ac18d5e..ddb01907894 100644 --- a/advisories/unreviewed/2024/07/GHSA-9hx6-x24q-crmv/GHSA-9hx6-x24q-crmv.json +++ b/advisories/unreviewed/2024/07/GHSA-9hx6-x24q-crmv/GHSA-9hx6-x24q-crmv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-cfxc-ch9m-pr95/GHSA-cfxc-ch9m-pr95.json b/advisories/unreviewed/2024/07/GHSA-cfxc-ch9m-pr95/GHSA-cfxc-ch9m-pr95.json index b51ef83f39c..cd9a75ed968 100644 --- a/advisories/unreviewed/2024/07/GHSA-cfxc-ch9m-pr95/GHSA-cfxc-ch9m-pr95.json +++ b/advisories/unreviewed/2024/07/GHSA-cfxc-ch9m-pr95/GHSA-cfxc-ch9m-pr95.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-f437-v3vf-3c5h/GHSA-f437-v3vf-3c5h.json b/advisories/unreviewed/2024/07/GHSA-f437-v3vf-3c5h/GHSA-f437-v3vf-3c5h.json index 56ffbd7c741..686c778ff32 100644 --- a/advisories/unreviewed/2024/07/GHSA-f437-v3vf-3c5h/GHSA-f437-v3vf-3c5h.json +++ b/advisories/unreviewed/2024/07/GHSA-f437-v3vf-3c5h/GHSA-f437-v3vf-3c5h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-g8mv-cj5h-rwjh/GHSA-g8mv-cj5h-rwjh.json b/advisories/unreviewed/2024/07/GHSA-g8mv-cj5h-rwjh/GHSA-g8mv-cj5h-rwjh.json index 15aba166aff..79cf88199c1 100644 --- a/advisories/unreviewed/2024/07/GHSA-g8mv-cj5h-rwjh/GHSA-g8mv-cj5h-rwjh.json +++ b/advisories/unreviewed/2024/07/GHSA-g8mv-cj5h-rwjh/GHSA-g8mv-cj5h-rwjh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-gcc2-5vx5-63jr/GHSA-gcc2-5vx5-63jr.json b/advisories/unreviewed/2024/07/GHSA-gcc2-5vx5-63jr/GHSA-gcc2-5vx5-63jr.json index 3d3901d2573..4eaa3e64af1 100644 --- a/advisories/unreviewed/2024/07/GHSA-gcc2-5vx5-63jr/GHSA-gcc2-5vx5-63jr.json +++ b/advisories/unreviewed/2024/07/GHSA-gcc2-5vx5-63jr/GHSA-gcc2-5vx5-63jr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-gjx6-q229-6m6v/GHSA-gjx6-q229-6m6v.json b/advisories/unreviewed/2024/07/GHSA-gjx6-q229-6m6v/GHSA-gjx6-q229-6m6v.json index 749003d9770..b8132053bca 100644 --- a/advisories/unreviewed/2024/07/GHSA-gjx6-q229-6m6v/GHSA-gjx6-q229-6m6v.json +++ b/advisories/unreviewed/2024/07/GHSA-gjx6-q229-6m6v/GHSA-gjx6-q229-6m6v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-h654-r868-pj2q/GHSA-h654-r868-pj2q.json b/advisories/unreviewed/2024/07/GHSA-h654-r868-pj2q/GHSA-h654-r868-pj2q.json index eccb00a556f..5d5e60e4ffd 100644 --- a/advisories/unreviewed/2024/07/GHSA-h654-r868-pj2q/GHSA-h654-r868-pj2q.json +++ b/advisories/unreviewed/2024/07/GHSA-h654-r868-pj2q/GHSA-h654-r868-pj2q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-h9fq-98cf-cfj2/GHSA-h9fq-98cf-cfj2.json b/advisories/unreviewed/2024/07/GHSA-h9fq-98cf-cfj2/GHSA-h9fq-98cf-cfj2.json index ad405146235..909fad5109e 100644 --- a/advisories/unreviewed/2024/07/GHSA-h9fq-98cf-cfj2/GHSA-h9fq-98cf-cfj2.json +++ b/advisories/unreviewed/2024/07/GHSA-h9fq-98cf-cfj2/GHSA-h9fq-98cf-cfj2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-hg5v-hmf4-qqh9/GHSA-hg5v-hmf4-qqh9.json b/advisories/unreviewed/2024/07/GHSA-hg5v-hmf4-qqh9/GHSA-hg5v-hmf4-qqh9.json index 219495b2d8f..774b33ec9e5 100644 --- a/advisories/unreviewed/2024/07/GHSA-hg5v-hmf4-qqh9/GHSA-hg5v-hmf4-qqh9.json +++ b/advisories/unreviewed/2024/07/GHSA-hg5v-hmf4-qqh9/GHSA-hg5v-hmf4-qqh9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-hhwq-g35f-6pwq/GHSA-hhwq-g35f-6pwq.json b/advisories/unreviewed/2024/07/GHSA-hhwq-g35f-6pwq/GHSA-hhwq-g35f-6pwq.json index 237e0b1c61b..0682655f4b7 100644 --- a/advisories/unreviewed/2024/07/GHSA-hhwq-g35f-6pwq/GHSA-hhwq-g35f-6pwq.json +++ b/advisories/unreviewed/2024/07/GHSA-hhwq-g35f-6pwq/GHSA-hhwq-g35f-6pwq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-q935-8vhv-gg93/GHSA-q935-8vhv-gg93.json b/advisories/unreviewed/2024/07/GHSA-q935-8vhv-gg93/GHSA-q935-8vhv-gg93.json index ae0d11eedf7..03abd942a32 100644 --- a/advisories/unreviewed/2024/07/GHSA-q935-8vhv-gg93/GHSA-q935-8vhv-gg93.json +++ b/advisories/unreviewed/2024/07/GHSA-q935-8vhv-gg93/GHSA-q935-8vhv-gg93.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-qqv6-xcxx-rcc7/GHSA-qqv6-xcxx-rcc7.json b/advisories/unreviewed/2024/07/GHSA-qqv6-xcxx-rcc7/GHSA-qqv6-xcxx-rcc7.json index 18c89ff0a4f..67064844297 100644 --- a/advisories/unreviewed/2024/07/GHSA-qqv6-xcxx-rcc7/GHSA-qqv6-xcxx-rcc7.json +++ b/advisories/unreviewed/2024/07/GHSA-qqv6-xcxx-rcc7/GHSA-qqv6-xcxx-rcc7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-rfg3-3jwg-wg3c/GHSA-rfg3-3jwg-wg3c.json b/advisories/unreviewed/2024/07/GHSA-rfg3-3jwg-wg3c/GHSA-rfg3-3jwg-wg3c.json index 75f8db449a6..ebd58f1eaa1 100644 --- a/advisories/unreviewed/2024/07/GHSA-rfg3-3jwg-wg3c/GHSA-rfg3-3jwg-wg3c.json +++ b/advisories/unreviewed/2024/07/GHSA-rfg3-3jwg-wg3c/GHSA-rfg3-3jwg-wg3c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-rg6c-frmf-w953/GHSA-rg6c-frmf-w953.json b/advisories/unreviewed/2024/07/GHSA-rg6c-frmf-w953/GHSA-rg6c-frmf-w953.json index 39be123413b..9b732477d31 100644 --- a/advisories/unreviewed/2024/07/GHSA-rg6c-frmf-w953/GHSA-rg6c-frmf-w953.json +++ b/advisories/unreviewed/2024/07/GHSA-rg6c-frmf-w953/GHSA-rg6c-frmf-w953.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-v8wj-qf3f-5p7v/GHSA-v8wj-qf3f-5p7v.json b/advisories/unreviewed/2024/07/GHSA-v8wj-qf3f-5p7v/GHSA-v8wj-qf3f-5p7v.json index 9186a351001..1e76c56a51d 100644 --- a/advisories/unreviewed/2024/07/GHSA-v8wj-qf3f-5p7v/GHSA-v8wj-qf3f-5p7v.json +++ b/advisories/unreviewed/2024/07/GHSA-v8wj-qf3f-5p7v/GHSA-v8wj-qf3f-5p7v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-vwv2-7pwm-39x4/GHSA-vwv2-7pwm-39x4.json b/advisories/unreviewed/2024/07/GHSA-vwv2-7pwm-39x4/GHSA-vwv2-7pwm-39x4.json index eb01c554763..e06138c52e1 100644 --- a/advisories/unreviewed/2024/07/GHSA-vwv2-7pwm-39x4/GHSA-vwv2-7pwm-39x4.json +++ b/advisories/unreviewed/2024/07/GHSA-vwv2-7pwm-39x4/GHSA-vwv2-7pwm-39x4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-wccc-2qv8-6647/GHSA-wccc-2qv8-6647.json b/advisories/unreviewed/2024/07/GHSA-wccc-2qv8-6647/GHSA-wccc-2qv8-6647.json index e540b46ac4e..e4f2ecc30e2 100644 --- a/advisories/unreviewed/2024/07/GHSA-wccc-2qv8-6647/GHSA-wccc-2qv8-6647.json +++ b/advisories/unreviewed/2024/07/GHSA-wccc-2qv8-6647/GHSA-wccc-2qv8-6647.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-wx53-7r2h-f7w6/GHSA-wx53-7r2h-f7w6.json b/advisories/unreviewed/2024/07/GHSA-wx53-7r2h-f7w6/GHSA-wx53-7r2h-f7w6.json index 23536d65ce0..ba2440d22db 100644 --- a/advisories/unreviewed/2024/07/GHSA-wx53-7r2h-f7w6/GHSA-wx53-7r2h-f7w6.json +++ b/advisories/unreviewed/2024/07/GHSA-wx53-7r2h-f7w6/GHSA-wx53-7r2h-f7w6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-x749-289q-pg9q/GHSA-x749-289q-pg9q.json b/advisories/unreviewed/2024/07/GHSA-x749-289q-pg9q/GHSA-x749-289q-pg9q.json index 3421fcd3120..e489c78139e 100644 --- a/advisories/unreviewed/2024/07/GHSA-x749-289q-pg9q/GHSA-x749-289q-pg9q.json +++ b/advisories/unreviewed/2024/07/GHSA-x749-289q-pg9q/GHSA-x749-289q-pg9q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-24q9-34wm-r8c7/GHSA-24q9-34wm-r8c7.json b/advisories/unreviewed/2024/08/GHSA-24q9-34wm-r8c7/GHSA-24q9-34wm-r8c7.json index 20c884c90ad..270abc75fb5 100644 --- a/advisories/unreviewed/2024/08/GHSA-24q9-34wm-r8c7/GHSA-24q9-34wm-r8c7.json +++ b/advisories/unreviewed/2024/08/GHSA-24q9-34wm-r8c7/GHSA-24q9-34wm-r8c7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-2862-5xjv-8phr/GHSA-2862-5xjv-8phr.json b/advisories/unreviewed/2024/08/GHSA-2862-5xjv-8phr/GHSA-2862-5xjv-8phr.json index 9771680cd4c..48667b55f4b 100644 --- a/advisories/unreviewed/2024/08/GHSA-2862-5xjv-8phr/GHSA-2862-5xjv-8phr.json +++ b/advisories/unreviewed/2024/08/GHSA-2862-5xjv-8phr/GHSA-2862-5xjv-8phr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-28c6-pjxj-5qxg/GHSA-28c6-pjxj-5qxg.json b/advisories/unreviewed/2024/08/GHSA-28c6-pjxj-5qxg/GHSA-28c6-pjxj-5qxg.json index e546d5b2b3e..66bfefaa3fc 100644 --- a/advisories/unreviewed/2024/08/GHSA-28c6-pjxj-5qxg/GHSA-28c6-pjxj-5qxg.json +++ b/advisories/unreviewed/2024/08/GHSA-28c6-pjxj-5qxg/GHSA-28c6-pjxj-5qxg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-2xmp-f94r-wqm9/GHSA-2xmp-f94r-wqm9.json b/advisories/unreviewed/2024/08/GHSA-2xmp-f94r-wqm9/GHSA-2xmp-f94r-wqm9.json index d4ef5a5d507..dcd570cced0 100644 --- a/advisories/unreviewed/2024/08/GHSA-2xmp-f94r-wqm9/GHSA-2xmp-f94r-wqm9.json +++ b/advisories/unreviewed/2024/08/GHSA-2xmp-f94r-wqm9/GHSA-2xmp-f94r-wqm9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-36c7-h45p-9hch/GHSA-36c7-h45p-9hch.json b/advisories/unreviewed/2024/08/GHSA-36c7-h45p-9hch/GHSA-36c7-h45p-9hch.json index a5cc904caa1..9295b87701d 100644 --- a/advisories/unreviewed/2024/08/GHSA-36c7-h45p-9hch/GHSA-36c7-h45p-9hch.json +++ b/advisories/unreviewed/2024/08/GHSA-36c7-h45p-9hch/GHSA-36c7-h45p-9hch.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-38qw-v9q4-hm9j/GHSA-38qw-v9q4-hm9j.json b/advisories/unreviewed/2024/08/GHSA-38qw-v9q4-hm9j/GHSA-38qw-v9q4-hm9j.json index b681bc3a555..19575c108d4 100644 --- a/advisories/unreviewed/2024/08/GHSA-38qw-v9q4-hm9j/GHSA-38qw-v9q4-hm9j.json +++ b/advisories/unreviewed/2024/08/GHSA-38qw-v9q4-hm9j/GHSA-38qw-v9q4-hm9j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-3r8w-q925-6wvv/GHSA-3r8w-q925-6wvv.json b/advisories/unreviewed/2024/08/GHSA-3r8w-q925-6wvv/GHSA-3r8w-q925-6wvv.json index c2dae86693c..683f67ad98d 100644 --- a/advisories/unreviewed/2024/08/GHSA-3r8w-q925-6wvv/GHSA-3r8w-q925-6wvv.json +++ b/advisories/unreviewed/2024/08/GHSA-3r8w-q925-6wvv/GHSA-3r8w-q925-6wvv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-44gw-49w9-fmfr/GHSA-44gw-49w9-fmfr.json b/advisories/unreviewed/2024/08/GHSA-44gw-49w9-fmfr/GHSA-44gw-49w9-fmfr.json index 29bfddb6e70..e80348b4326 100644 --- a/advisories/unreviewed/2024/08/GHSA-44gw-49w9-fmfr/GHSA-44gw-49w9-fmfr.json +++ b/advisories/unreviewed/2024/08/GHSA-44gw-49w9-fmfr/GHSA-44gw-49w9-fmfr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-482h-w5qp-gfxw/GHSA-482h-w5qp-gfxw.json b/advisories/unreviewed/2024/08/GHSA-482h-w5qp-gfxw/GHSA-482h-w5qp-gfxw.json index f91870a8dc1..94c474ac9e8 100644 --- a/advisories/unreviewed/2024/08/GHSA-482h-w5qp-gfxw/GHSA-482h-w5qp-gfxw.json +++ b/advisories/unreviewed/2024/08/GHSA-482h-w5qp-gfxw/GHSA-482h-w5qp-gfxw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-4vr6-qr4v-xmvq/GHSA-4vr6-qr4v-xmvq.json b/advisories/unreviewed/2024/08/GHSA-4vr6-qr4v-xmvq/GHSA-4vr6-qr4v-xmvq.json index 3522b972fca..71f22d25cfa 100644 --- a/advisories/unreviewed/2024/08/GHSA-4vr6-qr4v-xmvq/GHSA-4vr6-qr4v-xmvq.json +++ b/advisories/unreviewed/2024/08/GHSA-4vr6-qr4v-xmvq/GHSA-4vr6-qr4v-xmvq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-59w3-f5g7-27hp/GHSA-59w3-f5g7-27hp.json b/advisories/unreviewed/2024/08/GHSA-59w3-f5g7-27hp/GHSA-59w3-f5g7-27hp.json index 753673738e9..f4d556d068f 100644 --- a/advisories/unreviewed/2024/08/GHSA-59w3-f5g7-27hp/GHSA-59w3-f5g7-27hp.json +++ b/advisories/unreviewed/2024/08/GHSA-59w3-f5g7-27hp/GHSA-59w3-f5g7-27hp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-5fq6-69rp-89qc/GHSA-5fq6-69rp-89qc.json b/advisories/unreviewed/2024/08/GHSA-5fq6-69rp-89qc/GHSA-5fq6-69rp-89qc.json index e958ad4d219..79ed76ef542 100644 --- a/advisories/unreviewed/2024/08/GHSA-5fq6-69rp-89qc/GHSA-5fq6-69rp-89qc.json +++ b/advisories/unreviewed/2024/08/GHSA-5fq6-69rp-89qc/GHSA-5fq6-69rp-89qc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-6523-746v-mrwg/GHSA-6523-746v-mrwg.json b/advisories/unreviewed/2024/08/GHSA-6523-746v-mrwg/GHSA-6523-746v-mrwg.json index 32656635d40..95c9d00b3e6 100644 --- a/advisories/unreviewed/2024/08/GHSA-6523-746v-mrwg/GHSA-6523-746v-mrwg.json +++ b/advisories/unreviewed/2024/08/GHSA-6523-746v-mrwg/GHSA-6523-746v-mrwg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-72q5-rjgc-hrvj/GHSA-72q5-rjgc-hrvj.json b/advisories/unreviewed/2024/08/GHSA-72q5-rjgc-hrvj/GHSA-72q5-rjgc-hrvj.json index b249bad9c14..dac74fedc9d 100644 --- a/advisories/unreviewed/2024/08/GHSA-72q5-rjgc-hrvj/GHSA-72q5-rjgc-hrvj.json +++ b/advisories/unreviewed/2024/08/GHSA-72q5-rjgc-hrvj/GHSA-72q5-rjgc-hrvj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-7fgx-pmw9-49h5/GHSA-7fgx-pmw9-49h5.json b/advisories/unreviewed/2024/08/GHSA-7fgx-pmw9-49h5/GHSA-7fgx-pmw9-49h5.json index cb28fa3626e..3d98b66a29d 100644 --- a/advisories/unreviewed/2024/08/GHSA-7fgx-pmw9-49h5/GHSA-7fgx-pmw9-49h5.json +++ b/advisories/unreviewed/2024/08/GHSA-7fgx-pmw9-49h5/GHSA-7fgx-pmw9-49h5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-7pwm-mqqh-jmmq/GHSA-7pwm-mqqh-jmmq.json b/advisories/unreviewed/2024/08/GHSA-7pwm-mqqh-jmmq/GHSA-7pwm-mqqh-jmmq.json index 4b8bf714a5d..169a331258f 100644 --- a/advisories/unreviewed/2024/08/GHSA-7pwm-mqqh-jmmq/GHSA-7pwm-mqqh-jmmq.json +++ b/advisories/unreviewed/2024/08/GHSA-7pwm-mqqh-jmmq/GHSA-7pwm-mqqh-jmmq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-7r79-ppgg-4h8m/GHSA-7r79-ppgg-4h8m.json b/advisories/unreviewed/2024/08/GHSA-7r79-ppgg-4h8m/GHSA-7r79-ppgg-4h8m.json index 12fc5fa03fb..85c03ee6f7a 100644 --- a/advisories/unreviewed/2024/08/GHSA-7r79-ppgg-4h8m/GHSA-7r79-ppgg-4h8m.json +++ b/advisories/unreviewed/2024/08/GHSA-7r79-ppgg-4h8m/GHSA-7r79-ppgg-4h8m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-85fc-rr25-p568/GHSA-85fc-rr25-p568.json b/advisories/unreviewed/2024/08/GHSA-85fc-rr25-p568/GHSA-85fc-rr25-p568.json index fe2ac6127c6..f95c06c2008 100644 --- a/advisories/unreviewed/2024/08/GHSA-85fc-rr25-p568/GHSA-85fc-rr25-p568.json +++ b/advisories/unreviewed/2024/08/GHSA-85fc-rr25-p568/GHSA-85fc-rr25-p568.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-8g6r-2qgw-fhv7/GHSA-8g6r-2qgw-fhv7.json b/advisories/unreviewed/2024/08/GHSA-8g6r-2qgw-fhv7/GHSA-8g6r-2qgw-fhv7.json index d7d39c8e5e3..d5fd5adc4d5 100644 --- a/advisories/unreviewed/2024/08/GHSA-8g6r-2qgw-fhv7/GHSA-8g6r-2qgw-fhv7.json +++ b/advisories/unreviewed/2024/08/GHSA-8g6r-2qgw-fhv7/GHSA-8g6r-2qgw-fhv7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-96g3-59vf-qvw4/GHSA-96g3-59vf-qvw4.json b/advisories/unreviewed/2024/08/GHSA-96g3-59vf-qvw4/GHSA-96g3-59vf-qvw4.json index f046c7d23a3..9d3193ec119 100644 --- a/advisories/unreviewed/2024/08/GHSA-96g3-59vf-qvw4/GHSA-96g3-59vf-qvw4.json +++ b/advisories/unreviewed/2024/08/GHSA-96g3-59vf-qvw4/GHSA-96g3-59vf-qvw4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-9c64-9pw3-wh7p/GHSA-9c64-9pw3-wh7p.json b/advisories/unreviewed/2024/08/GHSA-9c64-9pw3-wh7p/GHSA-9c64-9pw3-wh7p.json index 667bf483449..e56ecaf91f3 100644 --- a/advisories/unreviewed/2024/08/GHSA-9c64-9pw3-wh7p/GHSA-9c64-9pw3-wh7p.json +++ b/advisories/unreviewed/2024/08/GHSA-9c64-9pw3-wh7p/GHSA-9c64-9pw3-wh7p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-ccfc-25xc-jwxh/GHSA-ccfc-25xc-jwxh.json b/advisories/unreviewed/2024/08/GHSA-ccfc-25xc-jwxh/GHSA-ccfc-25xc-jwxh.json index 4645f48c238..b66ca29bbc7 100644 --- a/advisories/unreviewed/2024/08/GHSA-ccfc-25xc-jwxh/GHSA-ccfc-25xc-jwxh.json +++ b/advisories/unreviewed/2024/08/GHSA-ccfc-25xc-jwxh/GHSA-ccfc-25xc-jwxh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-cm9m-hp76-grcq/GHSA-cm9m-hp76-grcq.json b/advisories/unreviewed/2024/08/GHSA-cm9m-hp76-grcq/GHSA-cm9m-hp76-grcq.json index d8a85e2b19f..186eb4bb546 100644 --- a/advisories/unreviewed/2024/08/GHSA-cm9m-hp76-grcq/GHSA-cm9m-hp76-grcq.json +++ b/advisories/unreviewed/2024/08/GHSA-cm9m-hp76-grcq/GHSA-cm9m-hp76-grcq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-f8cm-7v7p-g823/GHSA-f8cm-7v7p-g823.json b/advisories/unreviewed/2024/08/GHSA-f8cm-7v7p-g823/GHSA-f8cm-7v7p-g823.json index 06a70118042..939e00ed004 100644 --- a/advisories/unreviewed/2024/08/GHSA-f8cm-7v7p-g823/GHSA-f8cm-7v7p-g823.json +++ b/advisories/unreviewed/2024/08/GHSA-f8cm-7v7p-g823/GHSA-f8cm-7v7p-g823.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-f8v3-3x87-4mpx/GHSA-f8v3-3x87-4mpx.json b/advisories/unreviewed/2024/08/GHSA-f8v3-3x87-4mpx/GHSA-f8v3-3x87-4mpx.json index 641675343e4..99cc2586808 100644 --- a/advisories/unreviewed/2024/08/GHSA-f8v3-3x87-4mpx/GHSA-f8v3-3x87-4mpx.json +++ b/advisories/unreviewed/2024/08/GHSA-f8v3-3x87-4mpx/GHSA-f8v3-3x87-4mpx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-fr37-hq3w-ch93/GHSA-fr37-hq3w-ch93.json b/advisories/unreviewed/2024/08/GHSA-fr37-hq3w-ch93/GHSA-fr37-hq3w-ch93.json index 8e0a235fa41..f778e1f5bc6 100644 --- a/advisories/unreviewed/2024/08/GHSA-fr37-hq3w-ch93/GHSA-fr37-hq3w-ch93.json +++ b/advisories/unreviewed/2024/08/GHSA-fr37-hq3w-ch93/GHSA-fr37-hq3w-ch93.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-g4v9-cgh3-4j6f/GHSA-g4v9-cgh3-4j6f.json b/advisories/unreviewed/2024/08/GHSA-g4v9-cgh3-4j6f/GHSA-g4v9-cgh3-4j6f.json index 796b1252bcf..57933a0506c 100644 --- a/advisories/unreviewed/2024/08/GHSA-g4v9-cgh3-4j6f/GHSA-g4v9-cgh3-4j6f.json +++ b/advisories/unreviewed/2024/08/GHSA-g4v9-cgh3-4j6f/GHSA-g4v9-cgh3-4j6f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-g72g-w36f-8rf4/GHSA-g72g-w36f-8rf4.json b/advisories/unreviewed/2024/08/GHSA-g72g-w36f-8rf4/GHSA-g72g-w36f-8rf4.json index 4a2dcf4ae4f..17d16e5023d 100644 --- a/advisories/unreviewed/2024/08/GHSA-g72g-w36f-8rf4/GHSA-g72g-w36f-8rf4.json +++ b/advisories/unreviewed/2024/08/GHSA-g72g-w36f-8rf4/GHSA-g72g-w36f-8rf4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-gc66-2jq6-66c6/GHSA-gc66-2jq6-66c6.json b/advisories/unreviewed/2024/08/GHSA-gc66-2jq6-66c6/GHSA-gc66-2jq6-66c6.json index 4ca8ce7f773..48854e9da38 100644 --- a/advisories/unreviewed/2024/08/GHSA-gc66-2jq6-66c6/GHSA-gc66-2jq6-66c6.json +++ b/advisories/unreviewed/2024/08/GHSA-gc66-2jq6-66c6/GHSA-gc66-2jq6-66c6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-ggw5-pfvx-r7j9/GHSA-ggw5-pfvx-r7j9.json b/advisories/unreviewed/2024/08/GHSA-ggw5-pfvx-r7j9/GHSA-ggw5-pfvx-r7j9.json index 79c894a5a4d..8d10f69f1cc 100644 --- a/advisories/unreviewed/2024/08/GHSA-ggw5-pfvx-r7j9/GHSA-ggw5-pfvx-r7j9.json +++ b/advisories/unreviewed/2024/08/GHSA-ggw5-pfvx-r7j9/GHSA-ggw5-pfvx-r7j9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-gqg7-4h7v-f4hf/GHSA-gqg7-4h7v-f4hf.json b/advisories/unreviewed/2024/08/GHSA-gqg7-4h7v-f4hf/GHSA-gqg7-4h7v-f4hf.json index d84403b95ac..592c042196c 100644 --- a/advisories/unreviewed/2024/08/GHSA-gqg7-4h7v-f4hf/GHSA-gqg7-4h7v-f4hf.json +++ b/advisories/unreviewed/2024/08/GHSA-gqg7-4h7v-f4hf/GHSA-gqg7-4h7v-f4hf.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-hg8r-px7r-4j3w/GHSA-hg8r-px7r-4j3w.json b/advisories/unreviewed/2024/08/GHSA-hg8r-px7r-4j3w/GHSA-hg8r-px7r-4j3w.json index e8e87defc1d..1efccb21e34 100644 --- a/advisories/unreviewed/2024/08/GHSA-hg8r-px7r-4j3w/GHSA-hg8r-px7r-4j3w.json +++ b/advisories/unreviewed/2024/08/GHSA-hg8r-px7r-4j3w/GHSA-hg8r-px7r-4j3w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-j5wm-h22f-j8qm/GHSA-j5wm-h22f-j8qm.json b/advisories/unreviewed/2024/08/GHSA-j5wm-h22f-j8qm/GHSA-j5wm-h22f-j8qm.json index 943da096271..0047810e7a2 100644 --- a/advisories/unreviewed/2024/08/GHSA-j5wm-h22f-j8qm/GHSA-j5wm-h22f-j8qm.json +++ b/advisories/unreviewed/2024/08/GHSA-j5wm-h22f-j8qm/GHSA-j5wm-h22f-j8qm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-mchm-hhh8-w57p/GHSA-mchm-hhh8-w57p.json b/advisories/unreviewed/2024/08/GHSA-mchm-hhh8-w57p/GHSA-mchm-hhh8-w57p.json index c1d67e0a751..3c3629d6018 100644 --- a/advisories/unreviewed/2024/08/GHSA-mchm-hhh8-w57p/GHSA-mchm-hhh8-w57p.json +++ b/advisories/unreviewed/2024/08/GHSA-mchm-hhh8-w57p/GHSA-mchm-hhh8-w57p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-mpg7-9mg3-3974/GHSA-mpg7-9mg3-3974.json b/advisories/unreviewed/2024/08/GHSA-mpg7-9mg3-3974/GHSA-mpg7-9mg3-3974.json index 760406fada0..4b9e115eede 100644 --- a/advisories/unreviewed/2024/08/GHSA-mpg7-9mg3-3974/GHSA-mpg7-9mg3-3974.json +++ b/advisories/unreviewed/2024/08/GHSA-mpg7-9mg3-3974/GHSA-mpg7-9mg3-3974.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-mx8m-2wh5-m3hh/GHSA-mx8m-2wh5-m3hh.json b/advisories/unreviewed/2024/08/GHSA-mx8m-2wh5-m3hh/GHSA-mx8m-2wh5-m3hh.json index d0033eacd23..c69fe70f3e7 100644 --- a/advisories/unreviewed/2024/08/GHSA-mx8m-2wh5-m3hh/GHSA-mx8m-2wh5-m3hh.json +++ b/advisories/unreviewed/2024/08/GHSA-mx8m-2wh5-m3hh/GHSA-mx8m-2wh5-m3hh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-p269-768c-9733/GHSA-p269-768c-9733.json b/advisories/unreviewed/2024/08/GHSA-p269-768c-9733/GHSA-p269-768c-9733.json index 1a30018a1d8..38ba1136eff 100644 --- a/advisories/unreviewed/2024/08/GHSA-p269-768c-9733/GHSA-p269-768c-9733.json +++ b/advisories/unreviewed/2024/08/GHSA-p269-768c-9733/GHSA-p269-768c-9733.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/08/GHSA-p34g-w82h-w82c/GHSA-p34g-w82h-w82c.json b/advisories/unreviewed/2024/08/GHSA-p34g-w82h-w82c/GHSA-p34g-w82h-w82c.json index 5efa5356dda..0f51017749a 100644 --- a/advisories/unreviewed/2024/08/GHSA-p34g-w82h-w82c/GHSA-p34g-w82h-w82c.json +++ b/advisories/unreviewed/2024/08/GHSA-p34g-w82h-w82c/GHSA-p34g-w82h-w82c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/08/GHSA-p433-57hw-rf68/GHSA-p433-57hw-rf68.json b/advisories/unreviewed/2024/08/GHSA-p433-57hw-rf68/GHSA-p433-57hw-rf68.json index 543bb7e8a7b..c85a4a88b47 100644 --- a/advisories/unreviewed/2024/08/GHSA-p433-57hw-rf68/GHSA-p433-57hw-rf68.json +++ b/advisories/unreviewed/2024/08/GHSA-p433-57hw-rf68/GHSA-p433-57hw-rf68.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-q5q5-qr9g-74ch/GHSA-q5q5-qr9g-74ch.json b/advisories/unreviewed/2024/08/GHSA-q5q5-qr9g-74ch/GHSA-q5q5-qr9g-74ch.json index b9f395fbfe2..300a3e45b8c 100644 --- a/advisories/unreviewed/2024/08/GHSA-q5q5-qr9g-74ch/GHSA-q5q5-qr9g-74ch.json +++ b/advisories/unreviewed/2024/08/GHSA-q5q5-qr9g-74ch/GHSA-q5q5-qr9g-74ch.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-qgv4-x6mv-vh78/GHSA-qgv4-x6mv-vh78.json b/advisories/unreviewed/2024/08/GHSA-qgv4-x6mv-vh78/GHSA-qgv4-x6mv-vh78.json index 3d305774a1f..5c37458371b 100644 --- a/advisories/unreviewed/2024/08/GHSA-qgv4-x6mv-vh78/GHSA-qgv4-x6mv-vh78.json +++ b/advisories/unreviewed/2024/08/GHSA-qgv4-x6mv-vh78/GHSA-qgv4-x6mv-vh78.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-rfcf-h5v4-mcfh/GHSA-rfcf-h5v4-mcfh.json b/advisories/unreviewed/2024/08/GHSA-rfcf-h5v4-mcfh/GHSA-rfcf-h5v4-mcfh.json index e55070622df..fa2008fffa7 100644 --- a/advisories/unreviewed/2024/08/GHSA-rfcf-h5v4-mcfh/GHSA-rfcf-h5v4-mcfh.json +++ b/advisories/unreviewed/2024/08/GHSA-rfcf-h5v4-mcfh/GHSA-rfcf-h5v4-mcfh.json @@ -7,12 +7,8 @@ "CVE-2022-48900" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nxen/netfront: react properly to failing gnttab_end_foreign_access_ref()\n\nWhen calling gnttab_end_foreign_access_ref() the returned value must\nbe tested and the reaction to that value should be appropriate.\n\nIn case of failure in xennet_get_responses() the reaction should not be\nto crash the system, but to disable the network device.\n\nThe calls in setup_netfront() can be replaced by calls of\ngnttab_end_foreign_access(). While at it avoid double free of ring\npages and grant references via xennet_disconnect_backend() in this case.\n\nThis is CVE-2022-23042 / part of XSA-396.\n\n---\nV2:\n- avoid double free\nV3:\n- remove pointless initializer (Jan Beulich)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/08/GHSA-v5xv-g87f-x57w/GHSA-v5xv-g87f-x57w.json b/advisories/unreviewed/2024/08/GHSA-v5xv-g87f-x57w/GHSA-v5xv-g87f-x57w.json index 0b4046d8927..fe30aca0716 100644 --- a/advisories/unreviewed/2024/08/GHSA-v5xv-g87f-x57w/GHSA-v5xv-g87f-x57w.json +++ b/advisories/unreviewed/2024/08/GHSA-v5xv-g87f-x57w/GHSA-v5xv-g87f-x57w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -39,9 +37,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/08/GHSA-vmrv-fwh7-gvm4/GHSA-vmrv-fwh7-gvm4.json b/advisories/unreviewed/2024/08/GHSA-vmrv-fwh7-gvm4/GHSA-vmrv-fwh7-gvm4.json index 6a2ce5f2fee..48fab485ec7 100644 --- a/advisories/unreviewed/2024/08/GHSA-vmrv-fwh7-gvm4/GHSA-vmrv-fwh7-gvm4.json +++ b/advisories/unreviewed/2024/08/GHSA-vmrv-fwh7-gvm4/GHSA-vmrv-fwh7-gvm4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-w4h5-9mg2-vv6r/GHSA-w4h5-9mg2-vv6r.json b/advisories/unreviewed/2024/08/GHSA-w4h5-9mg2-vv6r/GHSA-w4h5-9mg2-vv6r.json index 76b07aab571..94c4f71be06 100644 --- a/advisories/unreviewed/2024/08/GHSA-w4h5-9mg2-vv6r/GHSA-w4h5-9mg2-vv6r.json +++ b/advisories/unreviewed/2024/08/GHSA-w4h5-9mg2-vv6r/GHSA-w4h5-9mg2-vv6r.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-wcph-x6mx-4gh6/GHSA-wcph-x6mx-4gh6.json b/advisories/unreviewed/2024/08/GHSA-wcph-x6mx-4gh6/GHSA-wcph-x6mx-4gh6.json index c47056c2935..3e2d04e7c73 100644 --- a/advisories/unreviewed/2024/08/GHSA-wcph-x6mx-4gh6/GHSA-wcph-x6mx-4gh6.json +++ b/advisories/unreviewed/2024/08/GHSA-wcph-x6mx-4gh6/GHSA-wcph-x6mx-4gh6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-xx3f-44rh-4g76/GHSA-xx3f-44rh-4g76.json b/advisories/unreviewed/2024/08/GHSA-xx3f-44rh-4g76/GHSA-xx3f-44rh-4g76.json index b800006c045..16e66e90a65 100644 --- a/advisories/unreviewed/2024/08/GHSA-xx3f-44rh-4g76/GHSA-xx3f-44rh-4g76.json +++ b/advisories/unreviewed/2024/08/GHSA-xx3f-44rh-4g76/GHSA-xx3f-44rh-4g76.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY",