Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2024-08-13 15:33:03 +00:00
parent d072c1d78f
commit 0667c286bb
39 changed files with 631 additions and 80 deletions
@@ -32,6 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-116",
"CWE-644"
],
"severity": "MODERATE",
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-56wj-jfhp-fq9f",
"modified": "2024-07-31T21:32:38Z",
"modified": "2024-08-13T15:31:33Z",
"published": "2024-07-31T21:32:38Z",
"aliases": [
"CVE-2019-6198"
@@ -32,7 +32,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-1004"
"CWE-1004",
"CWE-732"
],
"severity": "LOW",
"github_reviewed": false,
@@ -28,7 +28,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-287"
"CWE-287",
"CWE-77"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -32,7 +32,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-20"
"CWE-20",
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-23v8-j48f-jm74",
"modified": "2024-08-12T15:30:48Z",
"modified": "2024-08-13T15:31:33Z",
"published": "2024-08-12T15:30:48Z",
"aliases": [
"CVE-2023-50809"
],
"details": "In certain Sonos products before S1 Release 11.12 and S2 release 15.9, the mt_7615.ko wireless driver does not properly validate an information element during negotiation of a WPA2 four-way handshake. This lack of validation leads to a stack buffer overflow. This can result in remote code execution within the kernel. This affects Amp, Arc, Arc SL, Beam, Beam Gen 2, Beam SL, and Five.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-121"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-12T13:38:11Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2mcp-f38w-p5gf",
"modified": "2024-08-12T15:30:51Z",
"modified": "2024-08-13T15:31:34Z",
"published": "2024-08-12T15:30:51Z",
"aliases": [
"CVE-2024-6760"
],
"details": "A logic bug in the code which disables kernel tracing for setuid programs meant that tracing was not disabled when it should have, allowing unprivileged users to trace and inspect the behavior of setuid programs.\n\nThe bug may be used by an unprivileged user to read the contents of files to which they would not otherwise have access, such as the local password database.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-12T13:38:40Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2qw7-j9xq-5qjq",
"modified": "2024-08-12T18:30:48Z",
"modified": "2024-08-13T15:31:34Z",
"published": "2024-08-12T18:30:48Z",
"aliases": [
"CVE-2024-42623"
],
"details": "FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/layout/delete/1",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-352"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-12T17:15:17Z"
@@ -0,0 +1,46 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3h5p-hx2f-x27c",
"modified": "2024-08-13T15:31:32Z",
"published": "2024-08-13T15:31:32Z",
"aliases": [
"CVE-2024-23787"
],
"details": "Path traversal vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to obtain an arbitrary file in the affected product.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23787"
},
{
"type": "WEB",
"url": "https://jp.sharp/support/taiyo/info/JVNVU94591337_en.pdf"
},
{
"type": "WEB",
"url": "https://jp.sharp/support/taiyo/info/JVNVU94591337_jp.pdf"
},
{
"type": "WEB",
"url": "https://jvn.jp/en/vu/JVNVU94591337"
}
],
"database_specific": {
"cwe_ids": [
"CWE-22"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-14T10:15:08Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-46r4-hcf2-8pmx",
"modified": "2024-08-06T15:30:54Z",
"modified": "2024-08-13T15:31:33Z",
"published": "2024-08-06T15:30:54Z",
"aliases": [
"CVE-2024-41913"
],
"details": "A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The firmware flaw does not properly sanitize User input.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-434"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-06T14:16:04Z"
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4wrj-qhhf-3c55",
"modified": "2024-08-13T15:31:35Z",
"published": "2024-08-13T15:31:35Z",
"aliases": [
"CVE-2024-41623"
],
"details": "An issue in D3D Security D3D IP Camera (D8801) v.V9.1.17.1.4-20180428 allows a local attacker to execute arbitrary code via a crafted payload",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41623"
},
{
"type": "WEB",
"url": "https://github.com/Anonymous120386/Anonymous"
},
{
"type": "WEB",
"url": "http://d3d.com"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-13T14:15:12Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-62mf-rw5r-h5jq",
"modified": "2024-08-12T18:30:48Z",
"modified": "2024-08-13T15:31:34Z",
"published": "2024-08-12T18:30:48Z",
"aliases": [
"CVE-2024-42632"
],
"details": "FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/page/add.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-352"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-12T16:15:17Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-644m-h87w-v6x9",
"modified": "2024-08-12T18:30:48Z",
"modified": "2024-08-13T15:31:34Z",
"published": "2024-08-12T18:30:48Z",
"aliases": [
"CVE-2024-42630"
],
"details": "FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_manager/create_file.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-352"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-12T16:15:17Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6q4q-jp73-89cq",
"modified": "2024-08-12T18:30:48Z",
"modified": "2024-08-13T15:31:34Z",
"published": "2024-08-12T18:30:48Z",
"aliases": [
"CVE-2024-42545"
],
"details": "TOTOLINK A3700R v9.1.2u.5822_B20200513 has a buffer overflow vulnerability in the ssid parameter in setWizardCfg function.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-120"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-12T18:15:12Z"
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-766h-vjvr-5rg4",
"modified": "2024-08-13T15:31:35Z",
"published": "2024-08-13T15:31:35Z",
"aliases": [
"CVE-2024-5849"
],
"details": "An unauthenticated remote attacker may use a reflected XSS vulnerability to obtain information from a user or reboot the affected device once.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5849"
},
{
"type": "WEB",
"url": "https://cert.vde.com/en/advisories/VDE-2024-033"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-13T13:15:13Z"
}
}
@@ -48,7 +48,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-122"
"CWE-122",
"CWE-787"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7xp8-p4r3-6rv8",
"modified": "2024-08-06T15:30:54Z",
"modified": "2024-08-13T15:31:33Z",
"published": "2024-08-06T15:30:54Z",
"aliases": [
"CVE-2024-41911"
],
"details": "A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The flaw does not properly neutralize input during a web page generation.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-06T14:16:04Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-82fp-rv69-j7ww",
"modified": "2024-08-12T18:30:48Z",
"modified": "2024-08-13T15:31:34Z",
"published": "2024-08-12T18:30:48Z",
"aliases": [
"CVE-2024-42543"
],
"details": "TOTOLINK A3700R v9.1.2u.5822_B20200513 has a buffer overflow vulnerability in the http_host parameter in the loginauth function.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-120"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-12T18:15:12Z"
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-83cp-ppjr-7w6j",
"modified": "2024-08-13T15:31:36Z",
"published": "2024-08-13T15:31:36Z",
"aliases": [
"CVE-2024-42738"
],
"details": "In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setDmzCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42738"
},
{
"type": "WEB",
"url": "https://github.com/HouseFuzz/reports/blob/main/totolink/x5000r/setDmzCfg/setDmzCfg.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-13T14:15:13Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-86mq-3mw2-pcch",
"modified": "2024-08-12T18:30:48Z",
"modified": "2024-08-13T15:31:34Z",
"published": "2024-08-12T18:30:48Z",
"aliases": [
"CVE-2024-42631"
],
"details": "FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/layout/edit/1.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-352"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-12T16:15:17Z"

Some files were not shown because too many files have changed in this diff Show More