diff --git a/advisories/unreviewed/2024/09/GHSA-34w3-rhpm-qv77/GHSA-34w3-rhpm-qv77.json b/advisories/unreviewed/2024/09/GHSA-34w3-rhpm-qv77/GHSA-34w3-rhpm-qv77.json index 77b59210912..70c05bdae99 100644 --- a/advisories/unreviewed/2024/09/GHSA-34w3-rhpm-qv77/GHSA-34w3-rhpm-qv77.json +++ b/advisories/unreviewed/2024/09/GHSA-34w3-rhpm-qv77/GHSA-34w3-rhpm-qv77.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-34w3-rhpm-qv77", - "modified": "2024-09-26T09:31:42Z", + "modified": "2024-10-01T15:32:03Z", "published": "2024-09-26T09:31:42Z", "aliases": [ "CVE-2024-8861" diff --git a/advisories/unreviewed/2024/09/GHSA-3784-5wfh-hvvw/GHSA-3784-5wfh-hvvw.json b/advisories/unreviewed/2024/09/GHSA-3784-5wfh-hvvw/GHSA-3784-5wfh-hvvw.json index d1f2ea56525..a78d84cd212 100644 --- a/advisories/unreviewed/2024/09/GHSA-3784-5wfh-hvvw/GHSA-3784-5wfh-hvvw.json +++ b/advisories/unreviewed/2024/09/GHSA-3784-5wfh-hvvw/GHSA-3784-5wfh-hvvw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3784-5wfh-hvvw", - "modified": "2024-09-30T06:33:37Z", + "modified": "2024-10-01T15:32:05Z", "published": "2024-09-30T06:33:37Z", "aliases": [ "CVE-2024-8283" ], "details": "The Slider by 10Web WordPress plugin before 1.2.59 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-30T06:15:14Z" diff --git a/advisories/unreviewed/2024/09/GHSA-97x9-7h6v-3jx9/GHSA-97x9-7h6v-3jx9.json b/advisories/unreviewed/2024/09/GHSA-97x9-7h6v-3jx9/GHSA-97x9-7h6v-3jx9.json index 61749068bc2..c85cc3f080c 100644 --- a/advisories/unreviewed/2024/09/GHSA-97x9-7h6v-3jx9/GHSA-97x9-7h6v-3jx9.json +++ b/advisories/unreviewed/2024/09/GHSA-97x9-7h6v-3jx9/GHSA-97x9-7h6v-3jx9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-97x9-7h6v-3jx9", - "modified": "2024-09-17T21:30:32Z", + "modified": "2024-10-01T15:32:03Z", "published": "2024-09-17T21:30:32Z", "aliases": [ "CVE-2024-8900" ], "details": "An attacker could write data to the user's clipboard, bypassing the user prompt, during a certain sequence of navigational events. This vulnerability affects Firefox < 129.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T19:15:29Z" diff --git a/advisories/unreviewed/2024/09/GHSA-9hpf-pfx9-rfv9/GHSA-9hpf-pfx9-rfv9.json b/advisories/unreviewed/2024/09/GHSA-9hpf-pfx9-rfv9/GHSA-9hpf-pfx9-rfv9.json index bea199a3ecb..8482a3b2faa 100644 --- a/advisories/unreviewed/2024/09/GHSA-9hpf-pfx9-rfv9/GHSA-9hpf-pfx9-rfv9.json +++ b/advisories/unreviewed/2024/09/GHSA-9hpf-pfx9-rfv9/GHSA-9hpf-pfx9-rfv9.json @@ -48,7 +48,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-285" + "CWE-285", + "CWE-862" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-f25r-g5v8-v6qj/GHSA-f25r-g5v8-v6qj.json b/advisories/unreviewed/2024/09/GHSA-f25r-g5v8-v6qj/GHSA-f25r-g5v8-v6qj.json index ad61e939104..6bde2ce1726 100644 --- a/advisories/unreviewed/2024/09/GHSA-f25r-g5v8-v6qj/GHSA-f25r-g5v8-v6qj.json +++ b/advisories/unreviewed/2024/09/GHSA-f25r-g5v8-v6qj/GHSA-f25r-g5v8-v6qj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f25r-g5v8-v6qj", - "modified": "2024-09-30T06:33:37Z", + "modified": "2024-10-01T15:32:05Z", "published": "2024-09-30T06:33:36Z", "aliases": [ "CVE-2024-8239" ], "details": "The Starbox WordPress plugin before 3.5.3 does not properly render social media profiles URLs in certain contexts, like the malicious user's profile or pages where the starbox shortcode is used, which may be abused by users with at least the contributor role to conduct Stored XSS attacks.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-30T06:15:14Z" diff --git a/advisories/unreviewed/2024/09/GHSA-f5cq-8c4f-j2qr/GHSA-f5cq-8c4f-j2qr.json b/advisories/unreviewed/2024/09/GHSA-f5cq-8c4f-j2qr/GHSA-f5cq-8c4f-j2qr.json index acc33e5268b..9ed3df74466 100644 --- a/advisories/unreviewed/2024/09/GHSA-f5cq-8c4f-j2qr/GHSA-f5cq-8c4f-j2qr.json +++ b/advisories/unreviewed/2024/09/GHSA-f5cq-8c4f-j2qr/GHSA-f5cq-8c4f-j2qr.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-130" + "CWE-130", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-jj5c-5q6m-fv25/GHSA-jj5c-5q6m-fv25.json b/advisories/unreviewed/2024/09/GHSA-jj5c-5q6m-fv25/GHSA-jj5c-5q6m-fv25.json index edf8f3d43c6..7df5d5b9798 100644 --- a/advisories/unreviewed/2024/09/GHSA-jj5c-5q6m-fv25/GHSA-jj5c-5q6m-fv25.json +++ b/advisories/unreviewed/2024/09/GHSA-jj5c-5q6m-fv25/GHSA-jj5c-5q6m-fv25.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jj5c-5q6m-fv25", - "modified": "2024-09-26T12:32:02Z", + "modified": "2024-10-01T15:32:03Z", "published": "2024-09-26T12:32:02Z", "aliases": [ "CVE-2024-8633" diff --git a/advisories/unreviewed/2024/09/GHSA-mjww-f2pv-rp7w/GHSA-mjww-f2pv-rp7w.json b/advisories/unreviewed/2024/09/GHSA-mjww-f2pv-rp7w/GHSA-mjww-f2pv-rp7w.json index 04d8674d576..3c38d524a4f 100644 --- a/advisories/unreviewed/2024/09/GHSA-mjww-f2pv-rp7w/GHSA-mjww-f2pv-rp7w.json +++ b/advisories/unreviewed/2024/09/GHSA-mjww-f2pv-rp7w/GHSA-mjww-f2pv-rp7w.json @@ -36,6 +36,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-79", "CWE-80" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/09/GHSA-p9fh-v6cv-cj9f/GHSA-p9fh-v6cv-cj9f.json b/advisories/unreviewed/2024/09/GHSA-p9fh-v6cv-cj9f/GHSA-p9fh-v6cv-cj9f.json index 7a29ebe8c1d..866fa22ca88 100644 --- a/advisories/unreviewed/2024/09/GHSA-p9fh-v6cv-cj9f/GHSA-p9fh-v6cv-cj9f.json +++ b/advisories/unreviewed/2024/09/GHSA-p9fh-v6cv-cj9f/GHSA-p9fh-v6cv-cj9f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p9fh-v6cv-cj9f", - "modified": "2024-09-26T12:32:02Z", + "modified": "2024-10-01T15:32:03Z", "published": "2024-09-26T12:32:02Z", "aliases": [ "CVE-2024-8704" diff --git a/advisories/unreviewed/2024/09/GHSA-q948-g7j9-xjx3/GHSA-q948-g7j9-xjx3.json b/advisories/unreviewed/2024/09/GHSA-q948-g7j9-xjx3/GHSA-q948-g7j9-xjx3.json index 8de7cb37c70..b1fd79e88f6 100644 --- a/advisories/unreviewed/2024/09/GHSA-q948-g7j9-xjx3/GHSA-q948-g7j9-xjx3.json +++ b/advisories/unreviewed/2024/09/GHSA-q948-g7j9-xjx3/GHSA-q948-g7j9-xjx3.json @@ -48,7 +48,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-284" + "CWE-284", + "CWE-639" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-vpc6-qr46-3mw7/GHSA-vpc6-qr46-3mw7.json b/advisories/unreviewed/2024/09/GHSA-vpc6-qr46-3mw7/GHSA-vpc6-qr46-3mw7.json index b4ac195f8db..43cff038c58 100644 --- a/advisories/unreviewed/2024/09/GHSA-vpc6-qr46-3mw7/GHSA-vpc6-qr46-3mw7.json +++ b/advisories/unreviewed/2024/09/GHSA-vpc6-qr46-3mw7/GHSA-vpc6-qr46-3mw7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vpc6-qr46-3mw7", - "modified": "2024-09-28T03:30:43Z", + "modified": "2024-10-01T15:32:04Z", "published": "2024-09-28T03:30:43Z", "aliases": [ "CVE-2024-8353" diff --git a/advisories/unreviewed/2024/09/GHSA-vpxh-qgmv-7643/GHSA-vpxh-qgmv-7643.json b/advisories/unreviewed/2024/09/GHSA-vpxh-qgmv-7643/GHSA-vpxh-qgmv-7643.json index 4fcd1471a7c..ff29139d8fd 100644 --- a/advisories/unreviewed/2024/09/GHSA-vpxh-qgmv-7643/GHSA-vpxh-qgmv-7643.json +++ b/advisories/unreviewed/2024/09/GHSA-vpxh-qgmv-7643/GHSA-vpxh-qgmv-7643.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vpxh-qgmv-7643", - "modified": "2024-09-26T09:31:42Z", + "modified": "2024-10-01T15:32:03Z", "published": "2024-09-26T09:31:42Z", "aliases": [ "CVE-2024-9025" diff --git a/advisories/unreviewed/2024/09/GHSA-wj25-rxgg-p3g9/GHSA-wj25-rxgg-p3g9.json b/advisories/unreviewed/2024/09/GHSA-wj25-rxgg-p3g9/GHSA-wj25-rxgg-p3g9.json index 338d821b574..31dd8175b65 100644 --- a/advisories/unreviewed/2024/09/GHSA-wj25-rxgg-p3g9/GHSA-wj25-rxgg-p3g9.json +++ b/advisories/unreviewed/2024/09/GHSA-wj25-rxgg-p3g9/GHSA-wj25-rxgg-p3g9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wj25-rxgg-p3g9", - "modified": "2024-09-26T12:32:02Z", + "modified": "2024-10-01T15:32:03Z", "published": "2024-09-26T12:32:02Z", "aliases": [ "CVE-2024-9127" diff --git a/advisories/unreviewed/2024/10/GHSA-22q9-m8j5-x7xg/GHSA-22q9-m8j5-x7xg.json b/advisories/unreviewed/2024/10/GHSA-22q9-m8j5-x7xg/GHSA-22q9-m8j5-x7xg.json new file mode 100644 index 00000000000..1f92417e05c --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-22q9-m8j5-x7xg/GHSA-22q9-m8j5-x7xg.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-22q9-m8j5-x7xg", + "modified": "2024-10-01T15:32:06Z", + "published": "2024-10-01T15:32:06Z", + "aliases": [ + "CVE-2024-46261" + ], + "details": "cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_make32() function at cute_png.h.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46261" + }, + { + "type": "WEB", + "url": "https://github.com/Helson-S/FuzzyTesting/blob/master/cute_headers/cute_png/heapof-r1-cp_make32-cute_png-948c10" + }, + { + "type": "WEB", + "url": "https://github.com/Helson-S/FuzzyTesting/blob/master/cute_headers/cute_png/heapof-r1-cp_make32-cute_png-948c10/poc" + }, + { + "type": "WEB", + "url": "https://github.com/Helson-S/FuzzyTesting/blob/master/cute_headers/cute_png/heapof-r1-cp_make32-cute_png-948c10/poc/sample4.png" + }, + { + "type": "WEB", + "url": "https://github.com/Helson-S/FuzzyTesting/blob/master/cute_headers/cute_png/heapof-r1-cp_make32-cute_png-948c10/vulDescription.assets/image-20240527232015967.png" + }, + { + "type": "WEB", + "url": "https://github.com/Helson-S/FuzzyTesting/blob/master/cute_headers/cute_png/heapof-r1-cp_make32-cute_png-948c10/vulDescription.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-01T14:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-2mw5-5xxw-vv7j/GHSA-2mw5-5xxw-vv7j.json b/advisories/unreviewed/2024/10/GHSA-2mw5-5xxw-vv7j/GHSA-2mw5-5xxw-vv7j.json new file mode 100644 index 00000000000..81cf45304fe --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-2mw5-5xxw-vv7j/GHSA-2mw5-5xxw-vv7j.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2mw5-5xxw-vv7j", + "modified": "2024-10-01T15:32:06Z", + "published": "2024-10-01T15:32:06Z", + "aliases": [ + "CVE-2024-46258" + ], + "details": "cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_load_png_mem() function at cute_png.h.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46258" + }, + { + "type": "WEB", + "url": "https://github.com/Helson-S/FuzzyTesting/blob/master/cute_headers/cute_png/heapof-r1-cp_load_png_mem-cute_png-1105c15" + }, + { + "type": "WEB", + "url": "https://github.com/Helson-S/FuzzyTesting/blob/master/cute_headers/cute_png/heapof-r1-cp_load_png_mem-cute_png-1105c15/poc" + }, + { + "type": "WEB", + "url": "https://github.com/Helson-S/FuzzyTesting/blob/master/cute_headers/cute_png/heapof-r1-cp_load_png_mem-cute_png-1105c15/poc/sample2.png" + }, + { + "type": "WEB", + "url": "https://github.com/Helson-S/FuzzyTesting/blob/master/cute_headers/cute_png/heapof-r1-cp_load_png_mem-cute_png-1105c15/vulDescription.assets/image-20240527231514578.png" + }, + { + "type": "WEB", + "url": "https://github.com/Helson-S/FuzzyTesting/blob/master/cute_headers/cute_png/heapof-r1-cp_load_png_mem-cute_png-1105c15/vulDescription.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-01T14:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-5grv-4qg8-xxfq/GHSA-5grv-4qg8-xxfq.json b/advisories/unreviewed/2024/10/GHSA-5grv-4qg8-xxfq/GHSA-5grv-4qg8-xxfq.json index e89fa23cdd2..8112f18b0e6 100644 --- a/advisories/unreviewed/2024/10/GHSA-5grv-4qg8-xxfq/GHSA-5grv-4qg8-xxfq.json +++ b/advisories/unreviewed/2024/10/GHSA-5grv-4qg8-xxfq/GHSA-5grv-4qg8-xxfq.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5grv-4qg8-xxfq", - "modified": "2024-10-01T09:30:49Z", + "modified": "2024-10-01T15:32:05Z", "published": "2024-10-01T09:30:49Z", "aliases": [ "CVE-2024-9145" ], "details": "Wiz Code Visual Studio Code extension in versions 1.0.0 up to 1.5.3 and Wiz (legacy) Visual Studio Code extension in versions 0.13.0 up to 0.17.8 are vulnerable to local command injection if the user opens a maliciously crafted Dockerfile located in a path that has been marked as a \"trusted folder\" within Visual Studio Code, and initiates a manual scan of the file.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/10/GHSA-899q-56q2-qx8p/GHSA-899q-56q2-qx8p.json b/advisories/unreviewed/2024/10/GHSA-899q-56q2-qx8p/GHSA-899q-56q2-qx8p.json new file mode 100644 index 00000000000..941b9e69cc6 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-899q-56q2-qx8p/GHSA-899q-56q2-qx8p.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-899q-56q2-qx8p", + "modified": "2024-10-01T15:32:08Z", + "published": "2024-10-01T15:32:08Z", + "aliases": [ + "CVE-2024-46274" + ], + "details": "cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_stored() function at cute_png.h.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46274" + }, + { + "type": "WEB", + "url": "https://github.com/Helson-S/FuzzyTesting/blob/master/cute_headers/cute_png/heapof-r65280-cp_stored-cute_png-543c2" + }, + { + "type": "WEB", + "url": "https://github.com/Helson-S/FuzzyTesting/blob/master/cute_headers/cute_png/heapof-r65280-cp_stored-cute_png-543c2/poc" + }, + { + "type": "WEB", + "url": "https://github.com/Helson-S/FuzzyTesting/blob/master/cute_headers/cute_png/heapof-r65280-cp_stored-cute_png-543c2/poc/sample10.png" + }, + { + "type": "WEB", + "url": "https://github.com/Helson-S/FuzzyTesting/blob/master/cute_headers/cute_png/heapof-r65280-cp_stored-cute_png-543c2/vulDescription.assets/image-20240527233813133.png" + }, + { + "type": "WEB", + "url": "https://github.com/Helson-S/FuzzyTesting/blob/master/cute_headers/cute_png/heapof-r65280-cp_stored-cute_png-543c2/vulDescription.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-01T14:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-8mvm-82qc-mpjj/GHSA-8mvm-82qc-mpjj.json b/advisories/unreviewed/2024/10/GHSA-8mvm-82qc-mpjj/GHSA-8mvm-82qc-mpjj.json new file mode 100644 index 00000000000..cc015a95f10 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-8mvm-82qc-mpjj/GHSA-8mvm-82qc-mpjj.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8mvm-82qc-mpjj", + "modified": "2024-10-01T15:32:07Z", + "published": "2024-10-01T15:32:07Z", + "aliases": [ + "CVE-2024-46264" + ], + "details": "cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_find() function at cute_png.h.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46264" + }, + { + "type": "WEB", + "url": "https://github.com/Helson-S/FuzzyTesting/blob/master/cute_headers/cute_png/heapof-r4-cp_find-cute_png-979c8" + }, + { + "type": "WEB", + "url": "https://github.com/Helson-S/FuzzyTesting/blob/master/cute_headers/cute_png/heapof-r4-cp_find-cute_png-979c8/poc" + }, + { + "type": "WEB", + "url": "https://github.com/Helson-S/FuzzyTesting/blob/master/cute_headers/cute_png/heapof-r4-cp_find-cute_png-979c8/poc/sample8.png" + }, + { + "type": "WEB", + "url": "https://github.com/Helson-S/FuzzyTesting/blob/master/cute_headers/cute_png/heapof-r4-cp_find-cute_png-979c8/vulDescription.assets/image-20240527233234147.png" + }, + { + "type": "WEB", + "url": "https://github.com/Helson-S/FuzzyTesting/blob/master/cute_headers/cute_png/heapof-r4-cp_find-cute_png-979c8/vulDescription.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-01T14:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-f7h9-hrg7-94fg/GHSA-f7h9-hrg7-94fg.json b/advisories/unreviewed/2024/10/GHSA-f7h9-hrg7-94fg/GHSA-f7h9-hrg7-94fg.json new file mode 100644 index 00000000000..18d5a6b0138 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-f7h9-hrg7-94fg/GHSA-f7h9-hrg7-94fg.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f7h9-hrg7-94fg", + "modified": "2024-10-01T15:32:08Z", + "published": "2024-10-01T15:32:08Z", + "aliases": [ + "CVE-2021-37577" + ], + "details": "Bluetooth LE and BR/EDR Secure Connections pairing and Secure Simple Pairing using the Passkey entry protocol in Bluetooth Core Specifications 2.1 through 5.3 may permit an unauthenticated man-in-the-middle attacker to identify the Passkey used during pairing by reflection of a crafted public key with the same X coordinate as the offered public key and by reflection of the authentication evidence of the initiating device, potentially permitting this attacker to complete authenticated pairing with the responding device using the correct Passkey for the pairing session. This is a related issue to CVE-2020-26558.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-37577" + }, + { + "type": "WEB", + "url": "https://bluetooth.com" + }, + { + "type": "WEB", + "url": "https://www.bluetooth.com/learn-about-bluetooth/key-attributes/bluetooth-security/passkey-impersonation" + }, + { + "type": "WEB", + "url": "https://www.bluetooth.com/learn-about-bluetooth/key-attributes/bluetooth-security/reporting-security" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-01T15:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-fr2v-4w3g-v7vf/GHSA-fr2v-4w3g-v7vf.json b/advisories/unreviewed/2024/10/GHSA-fr2v-4w3g-v7vf/GHSA-fr2v-4w3g-v7vf.json new file mode 100644 index 00000000000..ec2a6b25b24 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-fr2v-4w3g-v7vf/GHSA-fr2v-4w3g-v7vf.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fr2v-4w3g-v7vf", + "modified": "2024-10-01T15:32:06Z", + "published": "2024-10-01T15:32:06Z", + "aliases": [ + "CVE-2024-46259" + ], + "details": "cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_unfilter() function at cute_png.h.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46259" + }, + { + "type": "WEB", + "url": "https://github.com/Helson-S/FuzzyTesting/blob/master/cute_headers/cute_png/heapof-r1-cp_unfilter-cute_png-1019c11" + }, + { + "type": "WEB", + "url": "https://github.com/Helson-S/FuzzyTesting/blob/master/cute_headers/cute_png/heapof-r1-cp_unfilter-cute_png-1019c11/poc" + }, + { + "type": "WEB", + "url": "https://github.com/Helson-S/FuzzyTesting/blob/master/cute_headers/cute_png/heapof-r1-cp_unfilter-cute_png-1019c11/poc/sample6.png" + }, + { + "type": "WEB", + "url": "https://github.com/Helson-S/FuzzyTesting/blob/master/cute_headers/cute_png/heapof-r1-cp_unfilter-cute_png-1019c11/vulDescription.assets/image-20240527232602298.png" + }, + { + "type": "WEB", + "url": "https://github.com/Helson-S/FuzzyTesting/blob/master/cute_headers/cute_png/heapof-r1-cp_unfilter-cute_png-1019c11/vulDescription.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-01T14:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-gxrc-fm43-25gv/GHSA-gxrc-fm43-25gv.json b/advisories/unreviewed/2024/10/GHSA-gxrc-fm43-25gv/GHSA-gxrc-fm43-25gv.json new file mode 100644 index 00000000000..4cd0634628b --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-gxrc-fm43-25gv/GHSA-gxrc-fm43-25gv.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gxrc-fm43-25gv", + "modified": "2024-10-01T15:32:05Z", + "published": "2024-10-01T15:32:05Z", + "aliases": [ + "CVE-2024-44744" + ], + "details": "An issue in Malwarebytes Premium Security v5.0.0.883 allows attackers to execute arbitrary code via placing crafted binaries into unspecified directories.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44744" + }, + { + "type": "WEB", + "url": "https://googleprojectzero.blogspot.com/2016/02/the-definitive-guide-on-win32-to-nt.html" + }, + { + "type": "WEB", + "url": "https://medium.com/%40danielshaulov01/malwarebytes-premium-security-av-bypass-cve-2024-44744-97bb6192ed4a" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-01T14:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-hcq3-45wr-fr6m/GHSA-hcq3-45wr-fr6m.json b/advisories/unreviewed/2024/10/GHSA-hcq3-45wr-fr6m/GHSA-hcq3-45wr-fr6m.json new file mode 100644 index 00000000000..37f032153ad --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-hcq3-45wr-fr6m/GHSA-hcq3-45wr-fr6m.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hcq3-45wr-fr6m", + "modified": "2024-10-01T15:32:07Z", + "published": "2024-10-01T15:32:07Z", + "aliases": [ + "CVE-2024-46263" + ], + "details": "cute_png v1.05 was discovered to contain a stack overflow via the cp_dynamic() function at cute_png.h.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46263" + }, + { + "type": "WEB", + "url": "https://github.com/Helson-S/FuzzyTesting/blob/master/cute_headers/cute_png/stkof-w1-cp_dynamic-cute_png-601c71" + }, + { + "type": "WEB", + "url": "https://github.com/Helson-S/FuzzyTesting/blob/master/cute_headers/cute_png/stkof-w1-cp_dynamic-cute_png-601c71/poc" + }, + { + "type": "WEB", + "url": "https://github.com/Helson-S/FuzzyTesting/blob/master/cute_headers/cute_png/stkof-w1-cp_dynamic-cute_png-601c71/poc/sample15.png" + }, + { + "type": "WEB", + "url": "https://github.com/Helson-S/FuzzyTesting/blob/master/cute_headers/cute_png/stkof-w1-cp_dynamic-cute_png-601c71/vulDescription.assets/image-20240527235936692.png" + }, + { + "type": "WEB", + "url": "https://github.com/Helson-S/FuzzyTesting/blob/master/cute_headers/cute_png/stkof-w1-cp_dynamic-cute_png-601c71/vulDescription.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-01T14:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-j3fg-crmh-9vqp/GHSA-j3fg-crmh-9vqp.json b/advisories/unreviewed/2024/10/GHSA-j3fg-crmh-9vqp/GHSA-j3fg-crmh-9vqp.json new file mode 100644 index 00000000000..7d57159f116 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-j3fg-crmh-9vqp/GHSA-j3fg-crmh-9vqp.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j3fg-crmh-9vqp", + "modified": "2024-10-01T15:32:08Z", + "published": "2024-10-01T15:32:08Z", + "aliases": [ + "CVE-2024-46276" + ], + "details": "cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_chunk() function at cute_png.h.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46276" + }, + { + "type": "WEB", + "url": "https://github.com/Helson-S/FuzzyTesting/blob/master/cute_headers/cute_png/heapof-r4-cp_chunk-cute_png-956c7" + }, + { + "type": "WEB", + "url": "https://github.com/Helson-S/FuzzyTesting/blob/master/cute_headers/cute_png/heapof-r4-cp_chunk-cute_png-956c7/poc" + }, + { + "type": "WEB", + "url": "https://github.com/Helson-S/FuzzyTesting/blob/master/cute_headers/cute_png/heapof-r4-cp_chunk-cute_png-956c7/poc/sample7.png" + }, + { + "type": "WEB", + "url": "https://github.com/Helson-S/FuzzyTesting/blob/master/cute_headers/cute_png/heapof-r4-cp_chunk-cute_png-956c7/vulDescription.assets/image-20240527232923330.png" + }, + { + "type": "WEB", + "url": "https://github.com/Helson-S/FuzzyTesting/blob/master/cute_headers/cute_png/heapof-r4-cp_chunk-cute_png-956c7/vulDescription.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-01T14:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-jmcc-268g-jp5g/GHSA-jmcc-268g-jp5g.json b/advisories/unreviewed/2024/10/GHSA-jmcc-268g-jp5g/GHSA-jmcc-268g-jp5g.json new file mode 100644 index 00000000000..f3a28e795bb --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-jmcc-268g-jp5g/GHSA-jmcc-268g-jp5g.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jmcc-268g-jp5g", + "modified": "2024-10-01T15:32:05Z", + "published": "2024-10-01T15:32:05Z", + "aliases": [ + "CVE-2023-7273" + ], + "details": "Cross site request forgery in Kiteworks OwnCloud allows an unauthenticated attacker to forge requests.\nIf a request has no Authorization header, it is created with an empty string as value by a rewrite rule. The CSRF check is done by comparing the header value to null, meaning that the existing CSRF check is bypassed in this case. An attacker can, for example, create a new administrator account if the request is executed in the browser of an authenticated victim.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-7273" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2041007" + }, + { + "type": "WEB", + "url": "https://cirosec.de/sa/sa-2023-012" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-01T13:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-m4rx-3qxq-mgjf/GHSA-m4rx-3qxq-mgjf.json b/advisories/unreviewed/2024/10/GHSA-m4rx-3qxq-mgjf/GHSA-m4rx-3qxq-mgjf.json new file mode 100644 index 00000000000..90850116649 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-m4rx-3qxq-mgjf/GHSA-m4rx-3qxq-mgjf.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m4rx-3qxq-mgjf", + "modified": "2024-10-01T15:32:09Z", + "published": "2024-10-01T15:32:09Z", + "aliases": [ + "CVE-2024-44610" + ], + "details": "PCAN-Ethernet Gateway FD before 1.3.0 and PCAN-Ethernet Gateway before 2.11.0 are vulnerable to Command injection.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44610" + }, + { + "type": "WEB", + "url": "https://cve.mahi.be/peak_pcan_dr" + }, + { + "type": "WEB", + "url": "https://github.com/BertoldVdb/PcanExploit" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-01T15:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-m823-2m6m-p9f2/GHSA-m823-2m6m-p9f2.json b/advisories/unreviewed/2024/10/GHSA-m823-2m6m-p9f2/GHSA-m823-2m6m-p9f2.json new file mode 100644 index 00000000000..6688da0d828 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-m823-2m6m-p9f2/GHSA-m823-2m6m-p9f2.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m823-2m6m-p9f2", + "modified": "2024-10-01T15:32:07Z", + "published": "2024-10-01T15:32:07Z", + "aliases": [ + "CVE-2024-46267" + ], + "details": "cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_block() function at cute_png.h.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46267" + }, + { + "type": "WEB", + "url": "https://github.com/Helson-S/FuzzyTesting/blob/master/cute_headers/cute_png/heapof-w98-cp_block-5c0-cute_png-642c5" + }, + { + "type": "WEB", + "url": "https://github.com/Helson-S/FuzzyTesting/blob/master/cute_headers/cute_png/heapof-w98-cp_block-5c0-cute_png-642c5/poc" + }, + { + "type": "WEB", + "url": "https://github.com/Helson-S/FuzzyTesting/blob/master/cute_headers/cute_png/heapof-w98-cp_block-5c0-cute_png-642c5/poc/sample13.png" + }, + { + "type": "WEB", + "url": "https://github.com/Helson-S/FuzzyTesting/blob/master/cute_headers/cute_png/heapof-w98-cp_block-5c0-cute_png-642c5/vulDescription.assets/image-20240527234842953.png" + }, + { + "type": "WEB", + "url": "https://github.com/Helson-S/FuzzyTesting/blob/master/cute_headers/cute_png/heapof-w98-cp_block-5c0-cute_png-642c5/vulDescription.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-01T14:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-mv5p-xvr5-f5qg/GHSA-mv5p-xvr5-f5qg.json b/advisories/unreviewed/2024/10/GHSA-mv5p-xvr5-f5qg/GHSA-mv5p-xvr5-f5qg.json new file mode 100644 index 00000000000..b1a064fbad1 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-mv5p-xvr5-f5qg/GHSA-mv5p-xvr5-f5qg.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mv5p-xvr5-f5qg", + "modified": "2024-10-01T15:32:08Z", + "published": "2024-10-01T15:32:08Z", + "aliases": [ + "CVE-2024-25658" + ], + "details": "Cleartext storage of passwords in Infinera TNMS (Transcend Network Management System) Server 19.10.3 allows attackers (with access to the database or exported configuration files) to obtain SNMP users' usernames and passwords in cleartext.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25658" + }, + { + "type": "WEB", + "url": "https://www.cvcn.gov.it/cvcn/cve/CVE-2024-25658" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-01T15:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-wh5g-cw5m-22mw/GHSA-wh5g-cw5m-22mw.json b/advisories/unreviewed/2024/10/GHSA-wh5g-cw5m-22mw/GHSA-wh5g-cw5m-22mw.json new file mode 100644 index 00000000000..be8ae2ae24a --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-wh5g-cw5m-22mw/GHSA-wh5g-cw5m-22mw.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wh5g-cw5m-22mw", + "modified": "2024-10-01T15:32:08Z", + "published": "2024-10-01T15:32:08Z", + "aliases": [ + "CVE-2024-25661" + ], + "details": "In Infinera TNMS (Transcend Network Management System) 19.10.3, cleartext storage of sensitive information in memory of the desktop application TNMS Client allows guest OS administrators to obtain various users' passwords by reading memory dumps of the desktop application.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25661" + }, + { + "type": "WEB", + "url": "https://www.cvcn.gov.it/cvcn/cve/CVE-2024-25661" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-01T15:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-www5-6jrx-9mwq/GHSA-www5-6jrx-9mwq.json b/advisories/unreviewed/2024/10/GHSA-www5-6jrx-9mwq/GHSA-www5-6jrx-9mwq.json new file mode 100644 index 00000000000..ec039fde6e6 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-www5-6jrx-9mwq/GHSA-www5-6jrx-9mwq.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-www5-6jrx-9mwq", + "modified": "2024-10-01T15:32:05Z", + "published": "2024-10-01T15:32:05Z", + "aliases": [ + "CVE-2024-41276" + ], + "details": "A vulnerability in Kaiten version 57.131.12 and earlier allows attackers to bypass the PIN code authentication mechanism. The application requires users to input a 6-digit PIN code sent to their email for authorization after entering their login credentials. However, the request limiting mechanism can be easily bypassed, enabling attackers to perform a brute force attack to guess the correct PIN and gain unauthorized access to the application.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41276" + }, + { + "type": "WEB", + "url": "https://github.com/artemy-ccrsky/CVE-2024-41276" + }, + { + "type": "WEB", + "url": "https://kaiten.ru" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-01T14:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-xw32-6422-frqm/GHSA-xw32-6422-frqm.json b/advisories/unreviewed/2024/10/GHSA-xw32-6422-frqm/GHSA-xw32-6422-frqm.json new file mode 100644 index 00000000000..29521131b4d --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-xw32-6422-frqm/GHSA-xw32-6422-frqm.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xw32-6422-frqm", + "modified": "2024-10-01T15:32:09Z", + "published": "2024-10-01T15:32:09Z", + "aliases": [ + "CVE-2024-45967" + ], + "details": "Pagekit 1.0.18 is vulnerable to Cross Site Scripting (XSS) in index.php/admin/site/widget.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45967" + }, + { + "type": "WEB", + "url": "https://github.com/yingning620/test123/blob/main/Pagekit%20CMS/Pagekit%20CMS%20v1.0.18%20%E5%AD%98%E5%82%A8%E5%9E%8BXSS.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-01T15:15:08Z" + } +} \ No newline at end of file