mirror of
https://github.com/netbirdio/advisory-database.git
synced 2026-05-22 18:04:22 -07:00
Advisory Database Sync
This commit is contained in:
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-m8wx-w8wv-8q47",
|
||||
"modified": "2024-09-23T15:30:58Z",
|
||||
"modified": "2024-09-25T12:30:39Z",
|
||||
"published": "2022-09-15T00:00:16Z",
|
||||
"aliases": [
|
||||
"CVE-2022-2277"
|
||||
@@ -21,6 +21,10 @@
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-2277"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://publisher.hitachienergy.com/preview?DocumentID=8DBD000106&LanguageCode=en&DocumentPartId=&Action=Launch"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://publisher.hitachienergy.com/preview?DocumentId=8DBD000106&languageCode=en&Preview=true"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-25h8-g2f4-5mwj",
|
||||
"modified": "2024-04-04T08:54:03Z",
|
||||
"modified": "2024-09-25T12:30:39Z",
|
||||
"published": "2023-10-25T18:32:20Z",
|
||||
"aliases": [
|
||||
"CVE-2023-26575"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-4869-ghp2-7x5q",
|
||||
"modified": "2024-04-04T08:53:59Z",
|
||||
"modified": "2024-09-25T12:30:39Z",
|
||||
"published": "2023-10-25T18:32:20Z",
|
||||
"aliases": [
|
||||
"CVE-2023-26571"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-4f7j-xf8r-8572",
|
||||
"modified": "2024-04-04T08:54:09Z",
|
||||
"modified": "2024-09-25T12:30:40Z",
|
||||
"published": "2023-10-25T18:32:21Z",
|
||||
"aliases": [
|
||||
"CVE-2023-26576"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-4r9r-cpgw-cf98",
|
||||
"modified": "2024-04-04T08:54:06Z",
|
||||
"modified": "2024-09-25T12:30:39Z",
|
||||
"published": "2023-10-25T18:32:20Z",
|
||||
"aliases": [
|
||||
"CVE-2023-26574"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-52hf-8hgx-m78v",
|
||||
"modified": "2024-04-04T08:54:00Z",
|
||||
"modified": "2024-09-25T12:30:39Z",
|
||||
"published": "2023-10-25T18:32:20Z",
|
||||
"aliases": [
|
||||
"CVE-2023-26570"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-63rp-vfr8-4qw7",
|
||||
"modified": "2024-04-04T08:54:32Z",
|
||||
"modified": "2024-09-25T12:30:40Z",
|
||||
"published": "2023-10-25T18:32:21Z",
|
||||
"aliases": [
|
||||
"CVE-2023-27375"
|
||||
|
||||
@@ -28,6 +28,7 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-116",
|
||||
"CWE-20",
|
||||
"CWE-74"
|
||||
],
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-h87j-f78f-m3fm",
|
||||
"modified": "2024-04-04T08:54:04Z",
|
||||
"modified": "2024-09-25T12:30:39Z",
|
||||
"published": "2023-10-25T18:32:20Z",
|
||||
"aliases": [
|
||||
"CVE-2023-26573"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-j8rr-p259-7wpm",
|
||||
"modified": "2024-04-04T08:54:24Z",
|
||||
"modified": "2024-09-25T12:30:40Z",
|
||||
"published": "2023-10-25T18:32:21Z",
|
||||
"aliases": [
|
||||
"CVE-2023-27259"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-jv9m-jp3m-8vjq",
|
||||
"modified": "2024-04-04T08:54:31Z",
|
||||
"modified": "2024-09-25T12:30:40Z",
|
||||
"published": "2023-10-25T18:32:21Z",
|
||||
"aliases": [
|
||||
"CVE-2023-27261"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-p492-rhv2-844c",
|
||||
"modified": "2024-04-04T08:54:23Z",
|
||||
"modified": "2024-09-25T12:30:40Z",
|
||||
"published": "2023-10-25T18:32:21Z",
|
||||
"aliases": [
|
||||
"CVE-2023-27258"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-pfv4-p727-hwgq",
|
||||
"modified": "2024-04-04T08:54:21Z",
|
||||
"modified": "2024-09-25T12:30:40Z",
|
||||
"published": "2023-10-25T18:32:21Z",
|
||||
"aliases": [
|
||||
"CVE-2023-27256"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-q2mj-6ff7-3gvh",
|
||||
"modified": "2024-04-04T08:54:38Z",
|
||||
"modified": "2024-09-25T12:30:40Z",
|
||||
"published": "2023-10-25T18:32:21Z",
|
||||
"aliases": [
|
||||
"CVE-2023-27257"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-w3wr-rggh-27pq",
|
||||
"modified": "2024-04-04T08:54:34Z",
|
||||
"modified": "2024-09-25T12:30:40Z",
|
||||
"published": "2023-10-25T18:32:21Z",
|
||||
"aliases": [
|
||||
"CVE-2023-27377"
|
||||
@@ -28,7 +28,8 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-287"
|
||||
"CWE-287",
|
||||
"CWE-306"
|
||||
],
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": false,
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-xgm7-5784-5cxv",
|
||||
"modified": "2024-04-04T08:54:27Z",
|
||||
"modified": "2024-09-25T12:30:40Z",
|
||||
"published": "2023-10-25T18:32:21Z",
|
||||
"aliases": [
|
||||
"CVE-2023-27376"
|
||||
|
||||
@@ -0,0 +1,35 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-38h7-7925-fvwv",
|
||||
"modified": "2024-09-25T12:30:40Z",
|
||||
"published": "2024-09-25T12:30:40Z",
|
||||
"aliases": [
|
||||
"CVE-2024-31145"
|
||||
],
|
||||
"details": "Certain PCI devices in a system might be assigned Reserved Memory\nRegions (specified via Reserved Memory Region Reporting, \"RMRR\") for\nIntel VT-d or Unity Mapping ranges for AMD-Vi. These are typically used\nfor platform tasks such as legacy USB emulation.\n\nSince the precise purpose of these regions is unknown, once a device\nassociated with such a region is active, the mappings of these regions\nneed to remain continuouly accessible by the device. In the logic\nestablishing these mappings, error handling was flawed, resulting in\nsuch mappings to potentially remain in place when they should have been\nremoved again. Respective guests would then gain access to memory\nregions which they aren't supposed to have access to.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31145"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://xenbits.xenproject.org/xsa/advisory-460.html"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-09-25T11:15:12Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,38 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-4h99-x2cv-q42q",
|
||||
"modified": "2024-09-25T12:30:40Z",
|
||||
"published": "2024-09-25T12:30:40Z",
|
||||
"aliases": [
|
||||
"CVE-2024-6594"
|
||||
],
|
||||
"details": "Improper Handling of Exceptional Conditions vulnerability in the WatchGuard Single Sign-On Client on Windows causes the client to crash while handling malformed commands. An attacker with network access to the client could create a denial of service condition for the Single Sign-On service by repeatedly issuing malformed commands.\n\nThis issue affects Single Sign-On Client: through 12.7.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6594"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2024-00016"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-755"
|
||||
],
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-09-25T12:15:05Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,38 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-4p9j-m37v-x8j7",
|
||||
"modified": "2024-09-25T12:30:40Z",
|
||||
"published": "2024-09-25T12:30:40Z",
|
||||
"aliases": [
|
||||
"CVE-2024-7481"
|
||||
],
|
||||
"details": "Improper verification of cryptographic signature during installation of a Printer driver via the TeamViewer_service.exe component of TeamViewer Remote Clients prior version 15.58.4 for Windows allows an attacker with local unprivileged access on a Windows system to elevate their privileges and install drivers.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7481"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.teamviewer.com/en/resources/trust-center/security-bulletins/tv-2024-1006"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-347"
|
||||
],
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-09-25T11:15:12Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,50 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-8rv3-6f2r-fh68",
|
||||
"modified": "2024-09-25T12:30:40Z",
|
||||
"published": "2024-09-25T12:30:40Z",
|
||||
"aliases": [
|
||||
"CVE-2024-8858"
|
||||
],
|
||||
"details": "The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘piechart_settings’ parameter in all versions up to, and including, 8.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8858"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://plugins.trac.wordpress.org/browser/addons-for-elementor/trunk/templates/addons/piecharts/loop.php#L21"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://plugins.trac.wordpress.org/changeset/3153346"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://wordpress.org/plugins/addons-for-elementor/#developers"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/d3c2e5fe-cc02-479e-9f33-e1a783088596?source=cve"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-79"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-09-25T11:15:12Z"
|
||||
}
|
||||
}
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user