From 02706b3014dd901fbc58dc2c5263ef88d8701163 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 25 Sep 2024 12:32:12 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-m8wx-w8wv-8q47.json | 6 ++- .../GHSA-25h8-g2f4-5mwj.json | 2 +- .../GHSA-4869-ghp2-7x5q.json | 2 +- .../GHSA-4f7j-xf8r-8572.json | 2 +- .../GHSA-4r9r-cpgw-cf98.json | 2 +- .../GHSA-52hf-8hgx-m78v.json | 2 +- .../GHSA-63rp-vfr8-4qw7.json | 2 +- .../GHSA-67p3-vgwg-jfjf.json | 1 + .../GHSA-h87j-f78f-m3fm.json | 2 +- .../GHSA-j8rr-p259-7wpm.json | 2 +- .../GHSA-jv9m-jp3m-8vjq.json | 2 +- .../GHSA-p492-rhv2-844c.json | 2 +- .../GHSA-pfv4-p727-hwgq.json | 2 +- .../GHSA-q2mj-6ff7-3gvh.json | 2 +- .../GHSA-w3wr-rggh-27pq.json | 5 +- .../GHSA-xgm7-5784-5cxv.json | 2 +- .../GHSA-38h7-7925-fvwv.json | 35 +++++++++++++ .../GHSA-4h99-x2cv-q42q.json | 38 ++++++++++++++ .../GHSA-4p9j-m37v-x8j7.json | 38 ++++++++++++++ .../GHSA-8rv3-6f2r-fh68.json | 50 +++++++++++++++++++ .../GHSA-fgxf-657w-ggqj.json | 38 ++++++++++++++ .../GHSA-hrw6-9556-27w2.json | 35 +++++++++++++ .../GHSA-p25c-r659-95hm.json | 38 ++++++++++++++ .../GHSA-r59w-m542-r252.json | 38 ++++++++++++++ .../GHSA-x9f9-xjf3-f3v6.json | 35 +++++++++++++ 25 files changed, 367 insertions(+), 16 deletions(-) create mode 100644 advisories/unreviewed/2024/09/GHSA-38h7-7925-fvwv/GHSA-38h7-7925-fvwv.json create mode 100644 advisories/unreviewed/2024/09/GHSA-4h99-x2cv-q42q/GHSA-4h99-x2cv-q42q.json create mode 100644 advisories/unreviewed/2024/09/GHSA-4p9j-m37v-x8j7/GHSA-4p9j-m37v-x8j7.json create mode 100644 advisories/unreviewed/2024/09/GHSA-8rv3-6f2r-fh68/GHSA-8rv3-6f2r-fh68.json create mode 100644 advisories/unreviewed/2024/09/GHSA-fgxf-657w-ggqj/GHSA-fgxf-657w-ggqj.json create mode 100644 advisories/unreviewed/2024/09/GHSA-hrw6-9556-27w2/GHSA-hrw6-9556-27w2.json create mode 100644 advisories/unreviewed/2024/09/GHSA-p25c-r659-95hm/GHSA-p25c-r659-95hm.json create mode 100644 advisories/unreviewed/2024/09/GHSA-r59w-m542-r252/GHSA-r59w-m542-r252.json create mode 100644 advisories/unreviewed/2024/09/GHSA-x9f9-xjf3-f3v6/GHSA-x9f9-xjf3-f3v6.json diff --git a/advisories/unreviewed/2022/09/GHSA-m8wx-w8wv-8q47/GHSA-m8wx-w8wv-8q47.json b/advisories/unreviewed/2022/09/GHSA-m8wx-w8wv-8q47/GHSA-m8wx-w8wv-8q47.json index 9057a0cce48..fff97df43d7 100644 --- a/advisories/unreviewed/2022/09/GHSA-m8wx-w8wv-8q47/GHSA-m8wx-w8wv-8q47.json +++ b/advisories/unreviewed/2022/09/GHSA-m8wx-w8wv-8q47/GHSA-m8wx-w8wv-8q47.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m8wx-w8wv-8q47", - "modified": "2024-09-23T15:30:58Z", + "modified": "2024-09-25T12:30:39Z", "published": "2022-09-15T00:00:16Z", "aliases": [ "CVE-2022-2277" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-2277" }, + { + "type": "WEB", + "url": "https://publisher.hitachienergy.com/preview?DocumentID=8DBD000106&LanguageCode=en&DocumentPartId=&Action=Launch" + }, { "type": "WEB", "url": "https://publisher.hitachienergy.com/preview?DocumentId=8DBD000106&languageCode=en&Preview=true" diff --git a/advisories/unreviewed/2023/10/GHSA-25h8-g2f4-5mwj/GHSA-25h8-g2f4-5mwj.json b/advisories/unreviewed/2023/10/GHSA-25h8-g2f4-5mwj/GHSA-25h8-g2f4-5mwj.json index 8ce023cb192..660a816d7ae 100644 --- a/advisories/unreviewed/2023/10/GHSA-25h8-g2f4-5mwj/GHSA-25h8-g2f4-5mwj.json +++ b/advisories/unreviewed/2023/10/GHSA-25h8-g2f4-5mwj/GHSA-25h8-g2f4-5mwj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-25h8-g2f4-5mwj", - "modified": "2024-04-04T08:54:03Z", + "modified": "2024-09-25T12:30:39Z", "published": "2023-10-25T18:32:20Z", "aliases": [ "CVE-2023-26575" diff --git a/advisories/unreviewed/2023/10/GHSA-4869-ghp2-7x5q/GHSA-4869-ghp2-7x5q.json b/advisories/unreviewed/2023/10/GHSA-4869-ghp2-7x5q/GHSA-4869-ghp2-7x5q.json index a56ab0ed409..b5b42c0243a 100644 --- a/advisories/unreviewed/2023/10/GHSA-4869-ghp2-7x5q/GHSA-4869-ghp2-7x5q.json +++ b/advisories/unreviewed/2023/10/GHSA-4869-ghp2-7x5q/GHSA-4869-ghp2-7x5q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4869-ghp2-7x5q", - "modified": "2024-04-04T08:53:59Z", + "modified": "2024-09-25T12:30:39Z", "published": "2023-10-25T18:32:20Z", "aliases": [ "CVE-2023-26571" diff --git a/advisories/unreviewed/2023/10/GHSA-4f7j-xf8r-8572/GHSA-4f7j-xf8r-8572.json b/advisories/unreviewed/2023/10/GHSA-4f7j-xf8r-8572/GHSA-4f7j-xf8r-8572.json index 6feee5e228b..612b2bb4859 100644 --- a/advisories/unreviewed/2023/10/GHSA-4f7j-xf8r-8572/GHSA-4f7j-xf8r-8572.json +++ b/advisories/unreviewed/2023/10/GHSA-4f7j-xf8r-8572/GHSA-4f7j-xf8r-8572.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4f7j-xf8r-8572", - "modified": "2024-04-04T08:54:09Z", + "modified": "2024-09-25T12:30:40Z", "published": "2023-10-25T18:32:21Z", "aliases": [ "CVE-2023-26576" diff --git a/advisories/unreviewed/2023/10/GHSA-4r9r-cpgw-cf98/GHSA-4r9r-cpgw-cf98.json b/advisories/unreviewed/2023/10/GHSA-4r9r-cpgw-cf98/GHSA-4r9r-cpgw-cf98.json index b4a78e52222..3119345539b 100644 --- a/advisories/unreviewed/2023/10/GHSA-4r9r-cpgw-cf98/GHSA-4r9r-cpgw-cf98.json +++ b/advisories/unreviewed/2023/10/GHSA-4r9r-cpgw-cf98/GHSA-4r9r-cpgw-cf98.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4r9r-cpgw-cf98", - "modified": "2024-04-04T08:54:06Z", + "modified": "2024-09-25T12:30:39Z", "published": "2023-10-25T18:32:20Z", "aliases": [ "CVE-2023-26574" diff --git a/advisories/unreviewed/2023/10/GHSA-52hf-8hgx-m78v/GHSA-52hf-8hgx-m78v.json b/advisories/unreviewed/2023/10/GHSA-52hf-8hgx-m78v/GHSA-52hf-8hgx-m78v.json index e7f4e043678..fcb94c09732 100644 --- a/advisories/unreviewed/2023/10/GHSA-52hf-8hgx-m78v/GHSA-52hf-8hgx-m78v.json +++ b/advisories/unreviewed/2023/10/GHSA-52hf-8hgx-m78v/GHSA-52hf-8hgx-m78v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-52hf-8hgx-m78v", - "modified": "2024-04-04T08:54:00Z", + "modified": "2024-09-25T12:30:39Z", "published": "2023-10-25T18:32:20Z", "aliases": [ "CVE-2023-26570" diff --git a/advisories/unreviewed/2023/10/GHSA-63rp-vfr8-4qw7/GHSA-63rp-vfr8-4qw7.json b/advisories/unreviewed/2023/10/GHSA-63rp-vfr8-4qw7/GHSA-63rp-vfr8-4qw7.json index f2c003e17e7..8b2a3dbf1dd 100644 --- a/advisories/unreviewed/2023/10/GHSA-63rp-vfr8-4qw7/GHSA-63rp-vfr8-4qw7.json +++ b/advisories/unreviewed/2023/10/GHSA-63rp-vfr8-4qw7/GHSA-63rp-vfr8-4qw7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-63rp-vfr8-4qw7", - "modified": "2024-04-04T08:54:32Z", + "modified": "2024-09-25T12:30:40Z", "published": "2023-10-25T18:32:21Z", "aliases": [ "CVE-2023-27375" diff --git a/advisories/unreviewed/2023/10/GHSA-67p3-vgwg-jfjf/GHSA-67p3-vgwg-jfjf.json b/advisories/unreviewed/2023/10/GHSA-67p3-vgwg-jfjf/GHSA-67p3-vgwg-jfjf.json index a034630fdad..214a2f5f756 100644 --- a/advisories/unreviewed/2023/10/GHSA-67p3-vgwg-jfjf/GHSA-67p3-vgwg-jfjf.json +++ b/advisories/unreviewed/2023/10/GHSA-67p3-vgwg-jfjf/GHSA-67p3-vgwg-jfjf.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-116", "CWE-20", "CWE-74" ], diff --git a/advisories/unreviewed/2023/10/GHSA-h87j-f78f-m3fm/GHSA-h87j-f78f-m3fm.json b/advisories/unreviewed/2023/10/GHSA-h87j-f78f-m3fm/GHSA-h87j-f78f-m3fm.json index 10b312145d6..b63122050c9 100644 --- a/advisories/unreviewed/2023/10/GHSA-h87j-f78f-m3fm/GHSA-h87j-f78f-m3fm.json +++ b/advisories/unreviewed/2023/10/GHSA-h87j-f78f-m3fm/GHSA-h87j-f78f-m3fm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h87j-f78f-m3fm", - "modified": "2024-04-04T08:54:04Z", + "modified": "2024-09-25T12:30:39Z", "published": "2023-10-25T18:32:20Z", "aliases": [ "CVE-2023-26573" diff --git a/advisories/unreviewed/2023/10/GHSA-j8rr-p259-7wpm/GHSA-j8rr-p259-7wpm.json b/advisories/unreviewed/2023/10/GHSA-j8rr-p259-7wpm/GHSA-j8rr-p259-7wpm.json index da50a6cb7d6..16bbadd839a 100644 --- a/advisories/unreviewed/2023/10/GHSA-j8rr-p259-7wpm/GHSA-j8rr-p259-7wpm.json +++ b/advisories/unreviewed/2023/10/GHSA-j8rr-p259-7wpm/GHSA-j8rr-p259-7wpm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j8rr-p259-7wpm", - "modified": "2024-04-04T08:54:24Z", + "modified": "2024-09-25T12:30:40Z", "published": "2023-10-25T18:32:21Z", "aliases": [ "CVE-2023-27259" diff --git a/advisories/unreviewed/2023/10/GHSA-jv9m-jp3m-8vjq/GHSA-jv9m-jp3m-8vjq.json b/advisories/unreviewed/2023/10/GHSA-jv9m-jp3m-8vjq/GHSA-jv9m-jp3m-8vjq.json index 8167cc4beec..2bf68791e53 100644 --- a/advisories/unreviewed/2023/10/GHSA-jv9m-jp3m-8vjq/GHSA-jv9m-jp3m-8vjq.json +++ b/advisories/unreviewed/2023/10/GHSA-jv9m-jp3m-8vjq/GHSA-jv9m-jp3m-8vjq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jv9m-jp3m-8vjq", - "modified": "2024-04-04T08:54:31Z", + "modified": "2024-09-25T12:30:40Z", "published": "2023-10-25T18:32:21Z", "aliases": [ "CVE-2023-27261" diff --git a/advisories/unreviewed/2023/10/GHSA-p492-rhv2-844c/GHSA-p492-rhv2-844c.json b/advisories/unreviewed/2023/10/GHSA-p492-rhv2-844c/GHSA-p492-rhv2-844c.json index 6ee93eb9b01..f99c44ac3fa 100644 --- a/advisories/unreviewed/2023/10/GHSA-p492-rhv2-844c/GHSA-p492-rhv2-844c.json +++ b/advisories/unreviewed/2023/10/GHSA-p492-rhv2-844c/GHSA-p492-rhv2-844c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p492-rhv2-844c", - "modified": "2024-04-04T08:54:23Z", + "modified": "2024-09-25T12:30:40Z", "published": "2023-10-25T18:32:21Z", "aliases": [ "CVE-2023-27258" diff --git a/advisories/unreviewed/2023/10/GHSA-pfv4-p727-hwgq/GHSA-pfv4-p727-hwgq.json b/advisories/unreviewed/2023/10/GHSA-pfv4-p727-hwgq/GHSA-pfv4-p727-hwgq.json index b572e84f260..6d6615ec553 100644 --- a/advisories/unreviewed/2023/10/GHSA-pfv4-p727-hwgq/GHSA-pfv4-p727-hwgq.json +++ b/advisories/unreviewed/2023/10/GHSA-pfv4-p727-hwgq/GHSA-pfv4-p727-hwgq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pfv4-p727-hwgq", - "modified": "2024-04-04T08:54:21Z", + "modified": "2024-09-25T12:30:40Z", "published": "2023-10-25T18:32:21Z", "aliases": [ "CVE-2023-27256" diff --git a/advisories/unreviewed/2023/10/GHSA-q2mj-6ff7-3gvh/GHSA-q2mj-6ff7-3gvh.json b/advisories/unreviewed/2023/10/GHSA-q2mj-6ff7-3gvh/GHSA-q2mj-6ff7-3gvh.json index 0ccb844c0dd..3e1390c6ab6 100644 --- a/advisories/unreviewed/2023/10/GHSA-q2mj-6ff7-3gvh/GHSA-q2mj-6ff7-3gvh.json +++ b/advisories/unreviewed/2023/10/GHSA-q2mj-6ff7-3gvh/GHSA-q2mj-6ff7-3gvh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q2mj-6ff7-3gvh", - "modified": "2024-04-04T08:54:38Z", + "modified": "2024-09-25T12:30:40Z", "published": "2023-10-25T18:32:21Z", "aliases": [ "CVE-2023-27257" diff --git a/advisories/unreviewed/2023/10/GHSA-w3wr-rggh-27pq/GHSA-w3wr-rggh-27pq.json b/advisories/unreviewed/2023/10/GHSA-w3wr-rggh-27pq/GHSA-w3wr-rggh-27pq.json index 4a01ac0dc84..b776cf1cbd2 100644 --- a/advisories/unreviewed/2023/10/GHSA-w3wr-rggh-27pq/GHSA-w3wr-rggh-27pq.json +++ b/advisories/unreviewed/2023/10/GHSA-w3wr-rggh-27pq/GHSA-w3wr-rggh-27pq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w3wr-rggh-27pq", - "modified": "2024-04-04T08:54:34Z", + "modified": "2024-09-25T12:30:40Z", "published": "2023-10-25T18:32:21Z", "aliases": [ "CVE-2023-27377" @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-287" + "CWE-287", + "CWE-306" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-xgm7-5784-5cxv/GHSA-xgm7-5784-5cxv.json b/advisories/unreviewed/2023/10/GHSA-xgm7-5784-5cxv/GHSA-xgm7-5784-5cxv.json index fe4c197503c..175d2930fec 100644 --- a/advisories/unreviewed/2023/10/GHSA-xgm7-5784-5cxv/GHSA-xgm7-5784-5cxv.json +++ b/advisories/unreviewed/2023/10/GHSA-xgm7-5784-5cxv/GHSA-xgm7-5784-5cxv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xgm7-5784-5cxv", - "modified": "2024-04-04T08:54:27Z", + "modified": "2024-09-25T12:30:40Z", "published": "2023-10-25T18:32:21Z", "aliases": [ "CVE-2023-27376" diff --git a/advisories/unreviewed/2024/09/GHSA-38h7-7925-fvwv/GHSA-38h7-7925-fvwv.json b/advisories/unreviewed/2024/09/GHSA-38h7-7925-fvwv/GHSA-38h7-7925-fvwv.json new file mode 100644 index 00000000000..f60059e103c --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-38h7-7925-fvwv/GHSA-38h7-7925-fvwv.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-38h7-7925-fvwv", + "modified": "2024-09-25T12:30:40Z", + "published": "2024-09-25T12:30:40Z", + "aliases": [ + "CVE-2024-31145" + ], + "details": "Certain PCI devices in a system might be assigned Reserved Memory\nRegions (specified via Reserved Memory Region Reporting, \"RMRR\") for\nIntel VT-d or Unity Mapping ranges for AMD-Vi. These are typically used\nfor platform tasks such as legacy USB emulation.\n\nSince the precise purpose of these regions is unknown, once a device\nassociated with such a region is active, the mappings of these regions\nneed to remain continuouly accessible by the device. In the logic\nestablishing these mappings, error handling was flawed, resulting in\nsuch mappings to potentially remain in place when they should have been\nremoved again. Respective guests would then gain access to memory\nregions which they aren't supposed to have access to.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31145" + }, + { + "type": "WEB", + "url": "https://xenbits.xenproject.org/xsa/advisory-460.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T11:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-4h99-x2cv-q42q/GHSA-4h99-x2cv-q42q.json b/advisories/unreviewed/2024/09/GHSA-4h99-x2cv-q42q/GHSA-4h99-x2cv-q42q.json new file mode 100644 index 00000000000..f60dbfaa133 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-4h99-x2cv-q42q/GHSA-4h99-x2cv-q42q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4h99-x2cv-q42q", + "modified": "2024-09-25T12:30:40Z", + "published": "2024-09-25T12:30:40Z", + "aliases": [ + "CVE-2024-6594" + ], + "details": "Improper Handling of Exceptional Conditions vulnerability in the WatchGuard Single Sign-On Client on Windows causes the client to crash while handling malformed commands. An attacker with network access to the client could create a denial of service condition for the Single Sign-On service by repeatedly issuing malformed commands.\n\nThis issue affects Single Sign-On Client: through 12.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6594" + }, + { + "type": "WEB", + "url": "https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2024-00016" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-755" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T12:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-4p9j-m37v-x8j7/GHSA-4p9j-m37v-x8j7.json b/advisories/unreviewed/2024/09/GHSA-4p9j-m37v-x8j7/GHSA-4p9j-m37v-x8j7.json new file mode 100644 index 00000000000..7f11b0cc270 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-4p9j-m37v-x8j7/GHSA-4p9j-m37v-x8j7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4p9j-m37v-x8j7", + "modified": "2024-09-25T12:30:40Z", + "published": "2024-09-25T12:30:40Z", + "aliases": [ + "CVE-2024-7481" + ], + "details": "Improper verification of cryptographic signature during installation of a Printer driver via the TeamViewer_service.exe component of TeamViewer Remote Clients prior version 15.58.4 for Windows allows an attacker with local unprivileged access on a Windows system to elevate their privileges and install drivers.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7481" + }, + { + "type": "WEB", + "url": "https://www.teamviewer.com/en/resources/trust-center/security-bulletins/tv-2024-1006" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-347" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T11:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-8rv3-6f2r-fh68/GHSA-8rv3-6f2r-fh68.json b/advisories/unreviewed/2024/09/GHSA-8rv3-6f2r-fh68/GHSA-8rv3-6f2r-fh68.json new file mode 100644 index 00000000000..6d1020c1544 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-8rv3-6f2r-fh68/GHSA-8rv3-6f2r-fh68.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8rv3-6f2r-fh68", + "modified": "2024-09-25T12:30:40Z", + "published": "2024-09-25T12:30:40Z", + "aliases": [ + "CVE-2024-8858" + ], + "details": "The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘piechart_settings’ parameter in all versions up to, and including, 8.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8858" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/addons-for-elementor/trunk/templates/addons/piecharts/loop.php#L21" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3153346" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/addons-for-elementor/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/d3c2e5fe-cc02-479e-9f33-e1a783088596?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T11:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-fgxf-657w-ggqj/GHSA-fgxf-657w-ggqj.json b/advisories/unreviewed/2024/09/GHSA-fgxf-657w-ggqj/GHSA-fgxf-657w-ggqj.json new file mode 100644 index 00000000000..4cfcee683b1 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-fgxf-657w-ggqj/GHSA-fgxf-657w-ggqj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fgxf-657w-ggqj", + "modified": "2024-09-25T12:30:40Z", + "published": "2024-09-25T12:30:40Z", + "aliases": [ + "CVE-2024-6592" + ], + "details": "Incorrect Authorization vulnerability in the protocol communication between the WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows and the WatchGuard Single Sign-On Client on Windows and MacOS allows Authentication Bypass.This issue affects the Authentication Gateway: through 12.10.2; Windows Single Sign-On Client: through 12.7; MacOS Single Sign-On Client: through 12.5.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6592" + }, + { + "type": "WEB", + "url": "https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2024-00014" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T12:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-hrw6-9556-27w2/GHSA-hrw6-9556-27w2.json b/advisories/unreviewed/2024/09/GHSA-hrw6-9556-27w2/GHSA-hrw6-9556-27w2.json new file mode 100644 index 00000000000..ce665b035cb --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-hrw6-9556-27w2/GHSA-hrw6-9556-27w2.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hrw6-9556-27w2", + "modified": "2024-09-25T12:30:40Z", + "published": "2024-09-25T12:30:40Z", + "aliases": [ + "CVE-2024-31146" + ], + "details": "When multiple devices share resources and one of them is to be passed\nthrough to a guest, security of the entire system and of respective\nguests individually cannot really be guaranteed without knowing\ninternals of any of the involved guests. Therefore such a configuration\ncannot really be security-supported, yet making that explicit was so far\nmissing.\n\nResources the sharing of which is known to be problematic include, but\nare not limited to\n- - PCI Base Address Registers (BARs) of multiple devices mapping to the\n same page (4k on x86),\n- - INTx lines.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31146" + }, + { + "type": "WEB", + "url": "https://xenbits.xenproject.org/xsa/advisory-461.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T11:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-p25c-r659-95hm/GHSA-p25c-r659-95hm.json b/advisories/unreviewed/2024/09/GHSA-p25c-r659-95hm/GHSA-p25c-r659-95hm.json new file mode 100644 index 00000000000..dfb7b887efd --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-p25c-r659-95hm/GHSA-p25c-r659-95hm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p25c-r659-95hm", + "modified": "2024-09-25T12:30:40Z", + "published": "2024-09-25T12:30:40Z", + "aliases": [ + "CVE-2024-7479" + ], + "details": "Improper verification of cryptographic signature during installation of a VPN driver via the TeamViewer_service.exe component of TeamViewer Remote Clients prior version 15.58.4 for Windows allows an attacker with local unprivileged access on a Windows system to elevate their privileges and install drivers.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7479" + }, + { + "type": "WEB", + "url": "https://www.teamviewer.com/en/resources/trust-center/security-bulletins/tv-2024-1006" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-347" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T11:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-r59w-m542-r252/GHSA-r59w-m542-r252.json b/advisories/unreviewed/2024/09/GHSA-r59w-m542-r252/GHSA-r59w-m542-r252.json new file mode 100644 index 00000000000..9df163dc5aa --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-r59w-m542-r252/GHSA-r59w-m542-r252.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r59w-m542-r252", + "modified": "2024-09-25T12:30:40Z", + "published": "2024-09-25T12:30:40Z", + "aliases": [ + "CVE-2024-6593" + ], + "details": "Incorrect Authorization vulnerability in WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows allows an attacker with network access to execute restricted management commands.\nThis issue affects Authentication Gateway: through 12.10.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6593" + }, + { + "type": "WEB", + "url": "https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2024-00015" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T12:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-x9f9-xjf3-f3v6/GHSA-x9f9-xjf3-f3v6.json b/advisories/unreviewed/2024/09/GHSA-x9f9-xjf3-f3v6/GHSA-x9f9-xjf3-f3v6.json new file mode 100644 index 00000000000..2a9c6dcb20d --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-x9f9-xjf3-f3v6/GHSA-x9f9-xjf3-f3v6.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x9f9-xjf3-f3v6", + "modified": "2024-09-25T12:30:40Z", + "published": "2024-09-25T12:30:40Z", + "aliases": [ + "CVE-2024-45817" + ], + "details": "In x86's APIC (Advanced Programmable Interrupt Controller) architecture,\nerror conditions are reported in a status register. Furthermore, the OS\ncan opt to receive an interrupt when a new error occurs.\n\nIt is possible to configure the error interrupt with an illegal vector,\nwhich generates an error when an error interrupt is raised.\n\nThis case causes Xen to recurse through vlapic_error(). The recursion\nitself is bounded; errors accumulate in the the status register and only\ngenerate an interrupt when a new status bit becomes set.\n\nHowever, the lock protecting this state in Xen will try to be taken\nrecursively, and deadlock.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45817" + }, + { + "type": "WEB", + "url": "https://xenbits.xenproject.org/xsa/advisory-462.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T11:15:12Z" + } +} \ No newline at end of file