From 06dcdcd0cd9485aad52e0431f1d506b9ec97ed1b Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 9 Jan 2024 18:31:45 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-gqhm-4h93-rrhg.json | 96 +++++++++++++++++++ .../GHSA-gqhm-4h93-rrhg.json | 46 --------- .../GHSA-29hx-4x6h-2q4x.json | 8 ++ .../GHSA-38xw-jx8m-w5wp.json | 8 ++ .../GHSA-53qp-xq7m-xppp.json | 12 +++ .../GHSA-g8c7-p5fx-vxh6.json | 8 ++ .../GHSA-hpp6-2prw-cvwr.json | 12 +++ .../GHSA-rfg4-wjmf-xghf.json | 12 +++ .../GHSA-rv87-xrcf-5c22.json | 12 +++ .../GHSA-xgc4-wqm7-7qrj.json | 11 ++- .../GHSA-2f47-rm5c-8fr9.json | 2 +- .../GHSA-2w87-fjj9-j39h.json | 4 + .../GHSA-34wv-gh47-86r8.json | 38 ++++++++ .../GHSA-37gw-25xx-74f7.json | 38 ++++++++ .../GHSA-3mhh-fjjv-vfrh.json | 38 ++++++++ .../GHSA-3p2x-fgmw-32pv.json | 38 ++++++++ .../GHSA-3pg3-7f5j-x2m5.json | 38 ++++++++ .../GHSA-3qxp-wv2v-jfc4.json | 38 ++++++++ .../GHSA-3vm6-qcr3-wwv3.json | 9 +- .../GHSA-4p4p-22cr-2gqw.json | 4 + .../GHSA-4x52-4p76-xv6v.json | 11 ++- .../GHSA-59h3-54m2-3jm7.json | 46 +++++++++ .../GHSA-5f2c-q448-h62x.json | 11 ++- .../GHSA-5fw3-xj86-w3c3.json | 46 +++++++++ .../GHSA-5q6v-3768-8xq7.json | 38 ++++++++ .../GHSA-5x77-x3qm-5v2f.json | 38 ++++++++ .../GHSA-62fm-r774-57v7.json | 38 ++++++++ .../GHSA-66j8-27jm-c7ff.json | 38 ++++++++ .../GHSA-6ch4-5r6m-5v7w.json | 38 ++++++++ .../GHSA-6fjx-3c25-3qrc.json | 38 ++++++++ .../GHSA-6gw8-36pw-g34w.json | 38 ++++++++ .../GHSA-6j79-xv7w-8g6f.json | 38 ++++++++ .../GHSA-7p5c-g6m3-v67r.json | 38 ++++++++ .../GHSA-7rrh-5xjg-2jmp.json | 38 ++++++++ .../GHSA-85h2-c2jq-7mg4.json | 38 ++++++++ .../GHSA-8g65-3569-fx34.json | 5 +- .../GHSA-8g6x-mrx6-77x2.json | 38 ++++++++ .../GHSA-92hj-6r7m-gqhh.json | 9 +- .../GHSA-98g6-xh36-x2p7.json | 38 ++++++++ .../GHSA-9cx9-hjrh-cgmm.json | 38 ++++++++ .../GHSA-9gfv-m6hh-94gq.json | 9 +- .../GHSA-9p7x-rvcj-9wg6.json | 38 ++++++++ .../GHSA-9rm8-w7j5-j66w.json | 4 + .../GHSA-9w5p-cfp8-w353.json | 38 ++++++++ .../GHSA-c2cf-p6qq-wxrr.json | 38 ++++++++ .../GHSA-cx5m-8m85-mm6m.json | 38 ++++++++ .../GHSA-f6jr-7pgg-f497.json | 11 ++- .../GHSA-f7xv-mwmj-x7p9.json | 38 ++++++++ .../GHSA-fh95-g988-p9j3.json | 9 +- .../GHSA-fp7j-p7cw-gqcx.json | 38 ++++++++ .../GHSA-fpg3-7wj3-x58x.json | 38 ++++++++ .../GHSA-fqmm-mm4m-5h74.json | 38 ++++++++ .../GHSA-fv65-2c76-4jh9.json | 38 ++++++++ .../GHSA-fvh6-48v9-mqh2.json | 38 ++++++++ .../GHSA-g5xc-jv8h-2232.json | 38 ++++++++ .../GHSA-ghfh-q3pc-fx3g.json | 38 ++++++++ .../GHSA-hqxc-wrhh-3x6q.json | 38 ++++++++ .../GHSA-hwrv-r72x-jcwr.json | 4 + .../GHSA-jcxm-cfv5-gp8j.json | 38 ++++++++ .../GHSA-jf4q-23f7-4mp3.json | 38 ++++++++ .../GHSA-jf62-g97c-j9x3.json | 4 +- .../GHSA-jh2h-9mjq-3gvm.json | 38 ++++++++ .../GHSA-jjvf-rww2-493v.json | 46 +++++++++ .../GHSA-jw42-5m4v-9c8g.json | 38 ++++++++ .../GHSA-jw97-qgpr-gq9q.json | 38 ++++++++ .../GHSA-m9vg-87mr-c2rx.json | 38 ++++++++ .../GHSA-mw57-gv8v-cj4r.json | 38 ++++++++ .../GHSA-pc6v-rjpx-v6rm.json | 38 ++++++++ .../GHSA-pgpx-675x-4jcv.json | 4 + .../GHSA-pjh6-2v65-x4fj.json | 11 ++- .../GHSA-q795-pwf5-9r9x.json | 9 +- .../GHSA-qpjw-c5c3-h83r.json | 38 ++++++++ .../GHSA-rh83-2fx8-8x6x.json | 38 ++++++++ .../GHSA-rhpx-9698-w5hr.json | 38 ++++++++ .../GHSA-rj8q-prqp-jwfg.json | 51 ++++++++++ .../GHSA-rm58-g3gh-gqf5.json | 4 + .../GHSA-rrrh-8rp4-pgc2.json | 38 ++++++++ .../GHSA-rx9g-96r8-m5g4.json | 38 ++++++++ .../GHSA-v2rr-hhf4-8739.json | 47 +++++++++ .../GHSA-vw59-wm86-qh74.json | 31 ++++++ .../GHSA-w3p5-6w9w-p383.json | 9 +- .../GHSA-w48w-95mf-vvc4.json | 38 ++++++++ .../GHSA-w6xv-37jv-7cjr.json | 38 ++++++++ .../GHSA-wqmr-cp8m-946m.json | 2 +- .../GHSA-wwcg-p45r-pv65.json | 38 ++++++++ .../GHSA-x5cx-qfrc-rw4r.json | 38 ++++++++ .../GHSA-x5gw-mqgf-fwh3.json | 5 +- .../GHSA-xr84-qwr9-vj33.json | 4 + 88 files changed, 2444 insertions(+), 92 deletions(-) create mode 100644 advisories/github-reviewed/2022/05/GHSA-gqhm-4h93-rrhg/GHSA-gqhm-4h93-rrhg.json delete mode 100644 advisories/unreviewed/2022/05/GHSA-gqhm-4h93-rrhg/GHSA-gqhm-4h93-rrhg.json create mode 100644 advisories/unreviewed/2024/01/GHSA-34wv-gh47-86r8/GHSA-34wv-gh47-86r8.json create mode 100644 advisories/unreviewed/2024/01/GHSA-37gw-25xx-74f7/GHSA-37gw-25xx-74f7.json create mode 100644 advisories/unreviewed/2024/01/GHSA-3mhh-fjjv-vfrh/GHSA-3mhh-fjjv-vfrh.json create mode 100644 advisories/unreviewed/2024/01/GHSA-3p2x-fgmw-32pv/GHSA-3p2x-fgmw-32pv.json create mode 100644 advisories/unreviewed/2024/01/GHSA-3pg3-7f5j-x2m5/GHSA-3pg3-7f5j-x2m5.json create mode 100644 advisories/unreviewed/2024/01/GHSA-3qxp-wv2v-jfc4/GHSA-3qxp-wv2v-jfc4.json create mode 100644 advisories/unreviewed/2024/01/GHSA-59h3-54m2-3jm7/GHSA-59h3-54m2-3jm7.json create mode 100644 advisories/unreviewed/2024/01/GHSA-5fw3-xj86-w3c3/GHSA-5fw3-xj86-w3c3.json create mode 100644 advisories/unreviewed/2024/01/GHSA-5q6v-3768-8xq7/GHSA-5q6v-3768-8xq7.json create mode 100644 advisories/unreviewed/2024/01/GHSA-5x77-x3qm-5v2f/GHSA-5x77-x3qm-5v2f.json create mode 100644 advisories/unreviewed/2024/01/GHSA-62fm-r774-57v7/GHSA-62fm-r774-57v7.json create mode 100644 advisories/unreviewed/2024/01/GHSA-66j8-27jm-c7ff/GHSA-66j8-27jm-c7ff.json create mode 100644 advisories/unreviewed/2024/01/GHSA-6ch4-5r6m-5v7w/GHSA-6ch4-5r6m-5v7w.json create mode 100644 advisories/unreviewed/2024/01/GHSA-6fjx-3c25-3qrc/GHSA-6fjx-3c25-3qrc.json create mode 100644 advisories/unreviewed/2024/01/GHSA-6gw8-36pw-g34w/GHSA-6gw8-36pw-g34w.json create mode 100644 advisories/unreviewed/2024/01/GHSA-6j79-xv7w-8g6f/GHSA-6j79-xv7w-8g6f.json create mode 100644 advisories/unreviewed/2024/01/GHSA-7p5c-g6m3-v67r/GHSA-7p5c-g6m3-v67r.json create mode 100644 advisories/unreviewed/2024/01/GHSA-7rrh-5xjg-2jmp/GHSA-7rrh-5xjg-2jmp.json create mode 100644 advisories/unreviewed/2024/01/GHSA-85h2-c2jq-7mg4/GHSA-85h2-c2jq-7mg4.json create mode 100644 advisories/unreviewed/2024/01/GHSA-8g6x-mrx6-77x2/GHSA-8g6x-mrx6-77x2.json create mode 100644 advisories/unreviewed/2024/01/GHSA-98g6-xh36-x2p7/GHSA-98g6-xh36-x2p7.json create mode 100644 advisories/unreviewed/2024/01/GHSA-9cx9-hjrh-cgmm/GHSA-9cx9-hjrh-cgmm.json create mode 100644 advisories/unreviewed/2024/01/GHSA-9p7x-rvcj-9wg6/GHSA-9p7x-rvcj-9wg6.json create mode 100644 advisories/unreviewed/2024/01/GHSA-9w5p-cfp8-w353/GHSA-9w5p-cfp8-w353.json create mode 100644 advisories/unreviewed/2024/01/GHSA-c2cf-p6qq-wxrr/GHSA-c2cf-p6qq-wxrr.json create mode 100644 advisories/unreviewed/2024/01/GHSA-cx5m-8m85-mm6m/GHSA-cx5m-8m85-mm6m.json create mode 100644 advisories/unreviewed/2024/01/GHSA-f7xv-mwmj-x7p9/GHSA-f7xv-mwmj-x7p9.json create mode 100644 advisories/unreviewed/2024/01/GHSA-fp7j-p7cw-gqcx/GHSA-fp7j-p7cw-gqcx.json create mode 100644 advisories/unreviewed/2024/01/GHSA-fpg3-7wj3-x58x/GHSA-fpg3-7wj3-x58x.json create mode 100644 advisories/unreviewed/2024/01/GHSA-fqmm-mm4m-5h74/GHSA-fqmm-mm4m-5h74.json create mode 100644 advisories/unreviewed/2024/01/GHSA-fv65-2c76-4jh9/GHSA-fv65-2c76-4jh9.json create mode 100644 advisories/unreviewed/2024/01/GHSA-fvh6-48v9-mqh2/GHSA-fvh6-48v9-mqh2.json create mode 100644 advisories/unreviewed/2024/01/GHSA-g5xc-jv8h-2232/GHSA-g5xc-jv8h-2232.json create mode 100644 advisories/unreviewed/2024/01/GHSA-ghfh-q3pc-fx3g/GHSA-ghfh-q3pc-fx3g.json create mode 100644 advisories/unreviewed/2024/01/GHSA-hqxc-wrhh-3x6q/GHSA-hqxc-wrhh-3x6q.json create mode 100644 advisories/unreviewed/2024/01/GHSA-jcxm-cfv5-gp8j/GHSA-jcxm-cfv5-gp8j.json create mode 100644 advisories/unreviewed/2024/01/GHSA-jf4q-23f7-4mp3/GHSA-jf4q-23f7-4mp3.json create mode 100644 advisories/unreviewed/2024/01/GHSA-jh2h-9mjq-3gvm/GHSA-jh2h-9mjq-3gvm.json create mode 100644 advisories/unreviewed/2024/01/GHSA-jjvf-rww2-493v/GHSA-jjvf-rww2-493v.json create mode 100644 advisories/unreviewed/2024/01/GHSA-jw42-5m4v-9c8g/GHSA-jw42-5m4v-9c8g.json create mode 100644 advisories/unreviewed/2024/01/GHSA-jw97-qgpr-gq9q/GHSA-jw97-qgpr-gq9q.json create mode 100644 advisories/unreviewed/2024/01/GHSA-m9vg-87mr-c2rx/GHSA-m9vg-87mr-c2rx.json create mode 100644 advisories/unreviewed/2024/01/GHSA-mw57-gv8v-cj4r/GHSA-mw57-gv8v-cj4r.json create mode 100644 advisories/unreviewed/2024/01/GHSA-pc6v-rjpx-v6rm/GHSA-pc6v-rjpx-v6rm.json create mode 100644 advisories/unreviewed/2024/01/GHSA-qpjw-c5c3-h83r/GHSA-qpjw-c5c3-h83r.json create mode 100644 advisories/unreviewed/2024/01/GHSA-rh83-2fx8-8x6x/GHSA-rh83-2fx8-8x6x.json create mode 100644 advisories/unreviewed/2024/01/GHSA-rhpx-9698-w5hr/GHSA-rhpx-9698-w5hr.json create mode 100644 advisories/unreviewed/2024/01/GHSA-rj8q-prqp-jwfg/GHSA-rj8q-prqp-jwfg.json create mode 100644 advisories/unreviewed/2024/01/GHSA-rrrh-8rp4-pgc2/GHSA-rrrh-8rp4-pgc2.json create mode 100644 advisories/unreviewed/2024/01/GHSA-rx9g-96r8-m5g4/GHSA-rx9g-96r8-m5g4.json create mode 100644 advisories/unreviewed/2024/01/GHSA-v2rr-hhf4-8739/GHSA-v2rr-hhf4-8739.json create mode 100644 advisories/unreviewed/2024/01/GHSA-vw59-wm86-qh74/GHSA-vw59-wm86-qh74.json create mode 100644 advisories/unreviewed/2024/01/GHSA-w48w-95mf-vvc4/GHSA-w48w-95mf-vvc4.json create mode 100644 advisories/unreviewed/2024/01/GHSA-w6xv-37jv-7cjr/GHSA-w6xv-37jv-7cjr.json create mode 100644 advisories/unreviewed/2024/01/GHSA-wwcg-p45r-pv65/GHSA-wwcg-p45r-pv65.json create mode 100644 advisories/unreviewed/2024/01/GHSA-x5cx-qfrc-rw4r/GHSA-x5cx-qfrc-rw4r.json diff --git a/advisories/github-reviewed/2022/05/GHSA-gqhm-4h93-rrhg/GHSA-gqhm-4h93-rrhg.json b/advisories/github-reviewed/2022/05/GHSA-gqhm-4h93-rrhg/GHSA-gqhm-4h93-rrhg.json new file mode 100644 index 00000000000..fb8c07e8c42 --- /dev/null +++ b/advisories/github-reviewed/2022/05/GHSA-gqhm-4h93-rrhg/GHSA-gqhm-4h93-rrhg.json @@ -0,0 +1,96 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gqhm-4h93-rrhg", + "modified": "2024-01-09T18:30:37Z", + "published": "2022-05-13T01:48:40Z", + "aliases": [ + "CVE-2018-1000866" + ], + "summary": "Jenkins Script Security and Pipeline Groovy Plugins Sandbox Bypass", + "details": "A sandbox bypass vulnerability exists in Pipeline: Groovy Plugin 2.59 and earlier in groovy-sandbox/src/main/java/org/kohsuke/groovy/sandbox/SandboxTransformer.java, groovy-cps/lib/src/main/java/com/cloudbees/groovy/cps/SandboxCpsTransformer.java that allows attackers with Job/Configure permission, or unauthorized attackers with SCM commit privileges and corresponding pipelines based on Jenkinsfiles set up in Jenkins, to execute arbitrary code on the Jenkins master JVM", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Maven", + "name": "org.jenkins-ci.plugins.workflow:workflow-cps" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.60" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "org.jenkins-ci.plugins:script-security" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.48" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-1000866" + }, + { + "type": "WEB", + "url": "https://github.com/jenkinsci/script-security-plugin/commit/16c862ae9d4038a3edbd8bdfb0fd1401a509d56b" + }, + { + "type": "WEB", + "url": "https://github.com/jenkinsci/workflow-cps-plugin/commit/0eb89aaf24065dbbdf6db84516ac1a52cd435e6d" + }, + { + "type": "WEB", + "url": "https://github.com/jenkinsci/workflow-cps-plugin/commit/e1c56eb6d85d513cb24dfe188e6f592d0ff84b38" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHBA-2019:0326" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHBA-2019:0327" + }, + { + "type": "WEB", + "url": "https://jenkins.io/security/advisory/2018-10-29/#SECURITY-1186" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", + "github_reviewed": true, + "github_reviewed_at": "2024-01-09T18:30:37Z", + "nvd_published_at": "2018-12-10T14:29:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-gqhm-4h93-rrhg/GHSA-gqhm-4h93-rrhg.json b/advisories/unreviewed/2022/05/GHSA-gqhm-4h93-rrhg/GHSA-gqhm-4h93-rrhg.json deleted file mode 100644 index 53bfdb892dc..00000000000 --- a/advisories/unreviewed/2022/05/GHSA-gqhm-4h93-rrhg/GHSA-gqhm-4h93-rrhg.json +++ /dev/null @@ -1,46 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-gqhm-4h93-rrhg", - "modified": "2022-05-13T01:48:40Z", - "published": "2022-05-13T01:48:40Z", - "aliases": [ - "CVE-2018-1000866" - ], - "details": "A sandbox bypass vulnerability exists in Pipeline: Groovy Plugin 2.59 and earlier in groovy-sandbox/src/main/java/org/kohsuke/groovy/sandbox/SandboxTransformer.java, groovy-cps/lib/src/main/java/com/cloudbees/groovy/cps/SandboxCpsTransformer.java that allows attackers with Job/Configure permission, or unauthorized attackers with SCM commit privileges and corresponding pipelines based on Jenkinsfiles set up in Jenkins, to execute arbitrary code on the Jenkins master JVM", - "severity": [ - { - "type": "CVSS_V3", - "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" - } - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-1000866" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHBA-2019:0326" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHBA-2019:0327" - }, - { - "type": "WEB", - "url": "https://jenkins.io/security/advisory/2018-10-29/#SECURITY-1186" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-269" - ], - "severity": "HIGH", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2018-12-10T14:29:00Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-29hx-4x6h-2q4x/GHSA-29hx-4x6h-2q4x.json b/advisories/unreviewed/2023/12/GHSA-29hx-4x6h-2q4x/GHSA-29hx-4x6h-2q4x.json index 58c117dcc72..aea077d77d6 100644 --- a/advisories/unreviewed/2023/12/GHSA-29hx-4x6h-2q4x/GHSA-29hx-4x6h-2q4x.json +++ b/advisories/unreviewed/2023/12/GHSA-29hx-4x6h-2q4x/GHSA-29hx-4x6h-2q4x.json @@ -25,10 +25,18 @@ "type": "WEB", "url": "https://fahrplan.events.ccc.de/congress/2023/fahrplan/events/11919.html" }, + { + "type": "WEB", + "url": "https://github.com/modzero/MZ-23-01-Poly-VoIP-Devices" + }, { "type": "WEB", "url": "https://modzero.com/en/advisories/mz-23-01-poly-voip-devices/" }, + { + "type": "WEB", + "url": "https://modzero.com/en/advisories/mz-23-01-poly-voip/" + }, { "type": "WEB", "url": "https://vuldb.com/?ctiid.249260" diff --git a/advisories/unreviewed/2023/12/GHSA-38xw-jx8m-w5wp/GHSA-38xw-jx8m-w5wp.json b/advisories/unreviewed/2023/12/GHSA-38xw-jx8m-w5wp/GHSA-38xw-jx8m-w5wp.json index cf8eac15c85..cd0eda89d63 100644 --- a/advisories/unreviewed/2023/12/GHSA-38xw-jx8m-w5wp/GHSA-38xw-jx8m-w5wp.json +++ b/advisories/unreviewed/2023/12/GHSA-38xw-jx8m-w5wp/GHSA-38xw-jx8m-w5wp.json @@ -25,10 +25,18 @@ "type": "WEB", "url": "https://fahrplan.events.ccc.de/congress/2023/fahrplan/events/11919.html" }, + { + "type": "WEB", + "url": "https://github.com/modzero/MZ-23-01-Poly-VoIP-Devices" + }, { "type": "WEB", "url": "https://modzero.com/en/advisories/mz-23-01-poly-voip-devices/" }, + { + "type": "WEB", + "url": "https://modzero.com/en/advisories/mz-23-01-poly-voip/" + }, { "type": "WEB", "url": "https://vuldb.com/?ctiid.249259" diff --git a/advisories/unreviewed/2023/12/GHSA-53qp-xq7m-xppp/GHSA-53qp-xq7m-xppp.json b/advisories/unreviewed/2023/12/GHSA-53qp-xq7m-xppp/GHSA-53qp-xq7m-xppp.json index afc95b4787e..4ea6a53ea6e 100644 --- a/advisories/unreviewed/2023/12/GHSA-53qp-xq7m-xppp/GHSA-53qp-xq7m-xppp.json +++ b/advisories/unreviewed/2023/12/GHSA-53qp-xq7m-xppp/GHSA-53qp-xq7m-xppp.json @@ -25,14 +25,26 @@ "type": "WEB", "url": "https://fahrplan.events.ccc.de/congress/2023/fahrplan/events/11919.html" }, + { + "type": "WEB", + "url": "https://github.com/modzero/MZ-23-01-Poly-VoIP-Devices" + }, { "type": "WEB", "url": "https://modzero.com/en/advisories/mz-23-01-poly-voip-devices/" }, + { + "type": "WEB", + "url": "https://modzero.com/en/advisories/mz-23-01-poly-voip/" + }, { "type": "WEB", "url": "https://modzero.com/en/blog/multiple-vulnerabilities-in-poly-products/" }, + { + "type": "WEB", + "url": "https://support.hp.com/us-en/document/ish_9929296-9929329-16/hpsbpy03896" + }, { "type": "WEB", "url": "https://vuldb.com/?ctiid.249255" diff --git a/advisories/unreviewed/2023/12/GHSA-g8c7-p5fx-vxh6/GHSA-g8c7-p5fx-vxh6.json b/advisories/unreviewed/2023/12/GHSA-g8c7-p5fx-vxh6/GHSA-g8c7-p5fx-vxh6.json index c1c6c0fb486..15a7ec0a93c 100644 --- a/advisories/unreviewed/2023/12/GHSA-g8c7-p5fx-vxh6/GHSA-g8c7-p5fx-vxh6.json +++ b/advisories/unreviewed/2023/12/GHSA-g8c7-p5fx-vxh6/GHSA-g8c7-p5fx-vxh6.json @@ -25,10 +25,18 @@ "type": "WEB", "url": "https://fahrplan.events.ccc.de/congress/2023/fahrplan/events/11919.html" }, + { + "type": "WEB", + "url": "https://github.com/modzero/MZ-23-01-Poly-VoIP-Devices" + }, { "type": "WEB", "url": "https://modzero.com/en/advisories/mz-23-01-poly-voip-devices/" }, + { + "type": "WEB", + "url": "https://modzero.com/en/advisories/mz-23-01-poly-voip/" + }, { "type": "WEB", "url": "https://modzero.com/en/blog/multiple-vulnerabilities-in-poly-products/" diff --git a/advisories/unreviewed/2023/12/GHSA-hpp6-2prw-cvwr/GHSA-hpp6-2prw-cvwr.json b/advisories/unreviewed/2023/12/GHSA-hpp6-2prw-cvwr/GHSA-hpp6-2prw-cvwr.json index f8a8dd71157..8c1efceb4b4 100644 --- a/advisories/unreviewed/2023/12/GHSA-hpp6-2prw-cvwr/GHSA-hpp6-2prw-cvwr.json +++ b/advisories/unreviewed/2023/12/GHSA-hpp6-2prw-cvwr/GHSA-hpp6-2prw-cvwr.json @@ -25,10 +25,22 @@ "type": "WEB", "url": "https://fahrplan.events.ccc.de/congress/2023/fahrplan/events/11919.html" }, + { + "type": "WEB", + "url": "https://github.com/modzero/MZ-23-01-Poly-VoIP-Devices" + }, { "type": "WEB", "url": "https://modzero.com/en/advisories/mz-23-01-poly-voip-devices/" }, + { + "type": "WEB", + "url": "https://modzero.com/en/advisories/mz-23-01-poly-voip/" + }, + { + "type": "WEB", + "url": "https://support.hp.com/us-en/document/ish_9929371-9929407-16/hpsbpy03899" + }, { "type": "WEB", "url": "https://vuldb.com/?ctiid.249258" diff --git a/advisories/unreviewed/2023/12/GHSA-rfg4-wjmf-xghf/GHSA-rfg4-wjmf-xghf.json b/advisories/unreviewed/2023/12/GHSA-rfg4-wjmf-xghf/GHSA-rfg4-wjmf-xghf.json index 016e2c9ab00..3019deb311a 100644 --- a/advisories/unreviewed/2023/12/GHSA-rfg4-wjmf-xghf/GHSA-rfg4-wjmf-xghf.json +++ b/advisories/unreviewed/2023/12/GHSA-rfg4-wjmf-xghf/GHSA-rfg4-wjmf-xghf.json @@ -25,10 +25,22 @@ "type": "WEB", "url": "https://fahrplan.events.ccc.de/congress/2023/fahrplan/events/11919.html" }, + { + "type": "WEB", + "url": "https://github.com/modzero/MZ-23-01-Poly-VoIP-Devices" + }, { "type": "WEB", "url": "https://modzero.com/en/advisories/mz-23-01-poly-voip-devices/" }, + { + "type": "WEB", + "url": "https://modzero.com/en/advisories/mz-23-01-poly-voip/" + }, + { + "type": "WEB", + "url": "https://support.hp.com/us-en/document/ish_9931565-9931594-16/hpsbpy03898" + }, { "type": "WEB", "url": "https://vuldb.com/?ctiid.249257" diff --git a/advisories/unreviewed/2023/12/GHSA-rv87-xrcf-5c22/GHSA-rv87-xrcf-5c22.json b/advisories/unreviewed/2023/12/GHSA-rv87-xrcf-5c22/GHSA-rv87-xrcf-5c22.json index d13ce903744..37a10bde309 100644 --- a/advisories/unreviewed/2023/12/GHSA-rv87-xrcf-5c22/GHSA-rv87-xrcf-5c22.json +++ b/advisories/unreviewed/2023/12/GHSA-rv87-xrcf-5c22/GHSA-rv87-xrcf-5c22.json @@ -25,14 +25,26 @@ "type": "WEB", "url": "https://fahrplan.events.ccc.de/congress/2023/fahrplan/events/11919.html" }, + { + "type": "WEB", + "url": "https://github.com/modzero/MZ-23-01-Poly-VoIP-Devices" + }, { "type": "WEB", "url": "https://modzero.com/en/advisories/mz-23-01-poly-voip-devices/" }, + { + "type": "WEB", + "url": "https://modzero.com/en/advisories/mz-23-01-poly-voip/" + }, { "type": "WEB", "url": "https://modzero.com/en/blog/multiple-vulnerabilities-in-poly-products/" }, + { + "type": "WEB", + "url": "https://support.hp.com/us-en/document/ish_9929447-9929472-16/hpsbpy03902" + }, { "type": "WEB", "url": "https://vuldb.com/?ctiid.249261" diff --git a/advisories/unreviewed/2023/12/GHSA-xgc4-wqm7-7qrj/GHSA-xgc4-wqm7-7qrj.json b/advisories/unreviewed/2023/12/GHSA-xgc4-wqm7-7qrj/GHSA-xgc4-wqm7-7qrj.json index 6db82fef110..93675c0df80 100644 --- a/advisories/unreviewed/2023/12/GHSA-xgc4-wqm7-7qrj/GHSA-xgc4-wqm7-7qrj.json +++ b/advisories/unreviewed/2023/12/GHSA-xgc4-wqm7-7qrj/GHSA-xgc4-wqm7-7qrj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xgc4-wqm7-7qrj", - "modified": "2023-12-22T03:30:33Z", + "modified": "2024-01-09T18:30:26Z", "published": "2023-12-22T03:30:33Z", "aliases": [ "CVE-2023-51708" ], "details": "Bentley eB System Management Console applications within Assetwise Integrity Information Server allow an unauthenticated user to view configuration options via a crafted request, leading to information disclosure. This affects eB System management Console before 23.00.02.03 and Assetwise ALIM For Transportation before 23.00.01.25.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-287" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-22T02:15:43Z" diff --git a/advisories/unreviewed/2024/01/GHSA-2f47-rm5c-8fr9/GHSA-2f47-rm5c-8fr9.json b/advisories/unreviewed/2024/01/GHSA-2f47-rm5c-8fr9/GHSA-2f47-rm5c-8fr9.json index a6c62fc6055..0e257926e8b 100644 --- a/advisories/unreviewed/2024/01/GHSA-2f47-rm5c-8fr9/GHSA-2f47-rm5c-8fr9.json +++ b/advisories/unreviewed/2024/01/GHSA-2f47-rm5c-8fr9/GHSA-2f47-rm5c-8fr9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2f47-rm5c-8fr9", - "modified": "2024-01-02T21:30:25Z", + "modified": "2024-01-09T18:30:26Z", "published": "2024-01-02T21:30:25Z", "aliases": [ "CVE-2023-48419" diff --git a/advisories/unreviewed/2024/01/GHSA-2w87-fjj9-j39h/GHSA-2w87-fjj9-j39h.json b/advisories/unreviewed/2024/01/GHSA-2w87-fjj9-j39h/GHSA-2w87-fjj9-j39h.json index ffa912bfcbe..3d001774583 100644 --- a/advisories/unreviewed/2024/01/GHSA-2w87-fjj9-j39h/GHSA-2w87-fjj9-j39h.json +++ b/advisories/unreviewed/2024/01/GHSA-2w87-fjj9-j39h/GHSA-2w87-fjj9-j39h.json @@ -29,6 +29,10 @@ "type": "WEB", "url": "https://software.open-xchange.com/products/appsuite/doc/Release_Notes_for_Patch_Release_6248_7.10.6_2023-09-19.pdf" }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/176421/OX-App-Suite-7.10.6-XSS-Command-Execution-LDAP-Injection.html" + }, { "type": "WEB", "url": "http://seclists.org/fulldisclosure/2024/Jan/3" diff --git a/advisories/unreviewed/2024/01/GHSA-34wv-gh47-86r8/GHSA-34wv-gh47-86r8.json b/advisories/unreviewed/2024/01/GHSA-34wv-gh47-86r8/GHSA-34wv-gh47-86r8.json new file mode 100644 index 00000000000..a2694603728 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-34wv-gh47-86r8/GHSA-34wv-gh47-86r8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-34wv-gh47-86r8", + "modified": "2024-01-09T18:30:28Z", + "published": "2024-01-09T18:30:28Z", + "aliases": [ + "CVE-2024-20666" + ], + "details": "BitLocker Security Feature Bypass Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20666" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-20666" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-09T18:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-37gw-25xx-74f7/GHSA-37gw-25xx-74f7.json b/advisories/unreviewed/2024/01/GHSA-37gw-25xx-74f7/GHSA-37gw-25xx-74f7.json new file mode 100644 index 00000000000..301d83985dc --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-37gw-25xx-74f7/GHSA-37gw-25xx-74f7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-37gw-25xx-74f7", + "modified": "2024-01-09T18:30:28Z", + "published": "2024-01-09T18:30:28Z", + "aliases": [ + "CVE-2024-20674" + ], + "details": "Windows Kerberos Security Feature Bypass Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20674" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-20674" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-09T18:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-3mhh-fjjv-vfrh/GHSA-3mhh-fjjv-vfrh.json b/advisories/unreviewed/2024/01/GHSA-3mhh-fjjv-vfrh/GHSA-3mhh-fjjv-vfrh.json new file mode 100644 index 00000000000..77850beb273 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-3mhh-fjjv-vfrh/GHSA-3mhh-fjjv-vfrh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3mhh-fjjv-vfrh", + "modified": "2024-01-09T18:30:28Z", + "published": "2024-01-09T18:30:28Z", + "aliases": [ + "CVE-2024-20676" + ], + "details": "Azure Storage Mover Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20676" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-20676" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-09T18:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-3p2x-fgmw-32pv/GHSA-3p2x-fgmw-32pv.json b/advisories/unreviewed/2024/01/GHSA-3p2x-fgmw-32pv/GHSA-3p2x-fgmw-32pv.json new file mode 100644 index 00000000000..3f386269c1e --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-3p2x-fgmw-32pv/GHSA-3p2x-fgmw-32pv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3p2x-fgmw-32pv", + "modified": "2024-01-09T18:30:28Z", + "published": "2024-01-09T18:30:28Z", + "aliases": [ + "CVE-2024-20681" + ], + "details": "Windows Subsystem for Linux Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20681" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-20681" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-09T18:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-3pg3-7f5j-x2m5/GHSA-3pg3-7f5j-x2m5.json b/advisories/unreviewed/2024/01/GHSA-3pg3-7f5j-x2m5/GHSA-3pg3-7f5j-x2m5.json new file mode 100644 index 00000000000..2c4315f36f3 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-3pg3-7f5j-x2m5/GHSA-3pg3-7f5j-x2m5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3pg3-7f5j-x2m5", + "modified": "2024-01-09T18:30:29Z", + "published": "2024-01-09T18:30:29Z", + "aliases": [ + "CVE-2024-21318" + ], + "details": "Microsoft SharePoint Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21318" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21318" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-09T18:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-3qxp-wv2v-jfc4/GHSA-3qxp-wv2v-jfc4.json b/advisories/unreviewed/2024/01/GHSA-3qxp-wv2v-jfc4/GHSA-3qxp-wv2v-jfc4.json new file mode 100644 index 00000000000..5708a0e3b70 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-3qxp-wv2v-jfc4/GHSA-3qxp-wv2v-jfc4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3qxp-wv2v-jfc4", + "modified": "2024-01-09T18:30:29Z", + "published": "2024-01-09T18:30:29Z", + "aliases": [ + "CVE-2024-21312" + ], + "details": ".NET Framework Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21312" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21312" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-09T18:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-3vm6-qcr3-wwv3/GHSA-3vm6-qcr3-wwv3.json b/advisories/unreviewed/2024/01/GHSA-3vm6-qcr3-wwv3/GHSA-3vm6-qcr3-wwv3.json index 6b83ede0406..abaf0aae0c5 100644 --- a/advisories/unreviewed/2024/01/GHSA-3vm6-qcr3-wwv3/GHSA-3vm6-qcr3-wwv3.json +++ b/advisories/unreviewed/2024/01/GHSA-3vm6-qcr3-wwv3/GHSA-3vm6-qcr3-wwv3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3vm6-qcr3-wwv3", - "modified": "2024-01-03T00:30:24Z", + "modified": "2024-01-09T18:30:26Z", "published": "2024-01-03T00:30:24Z", "aliases": [ "CVE-2023-49555" ], "details": "An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the expand_smacro function in the modules/preprocs/nasm/nasm-pp.c component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-03T00:15:09Z" diff --git a/advisories/unreviewed/2024/01/GHSA-4p4p-22cr-2gqw/GHSA-4p4p-22cr-2gqw.json b/advisories/unreviewed/2024/01/GHSA-4p4p-22cr-2gqw/GHSA-4p4p-22cr-2gqw.json index 1c31c7e964b..e5ae62ae855 100644 --- a/advisories/unreviewed/2024/01/GHSA-4p4p-22cr-2gqw/GHSA-4p4p-22cr-2gqw.json +++ b/advisories/unreviewed/2024/01/GHSA-4p4p-22cr-2gqw/GHSA-4p4p-22cr-2gqw.json @@ -29,6 +29,10 @@ "type": "WEB", "url": "https://software.open-xchange.com/products/appsuite/doc/Release_Notes_for_Patch_Release_6248_7.10.6_2023-09-19.pdf" }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/176421/OX-App-Suite-7.10.6-XSS-Command-Execution-LDAP-Injection.html" + }, { "type": "WEB", "url": "http://seclists.org/fulldisclosure/2024/Jan/3" diff --git a/advisories/unreviewed/2024/01/GHSA-4x52-4p76-xv6v/GHSA-4x52-4p76-xv6v.json b/advisories/unreviewed/2024/01/GHSA-4x52-4p76-xv6v/GHSA-4x52-4p76-xv6v.json index a08a9becc22..22e271c5dcd 100644 --- a/advisories/unreviewed/2024/01/GHSA-4x52-4p76-xv6v/GHSA-4x52-4p76-xv6v.json +++ b/advisories/unreviewed/2024/01/GHSA-4x52-4p76-xv6v/GHSA-4x52-4p76-xv6v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4x52-4p76-xv6v", - "modified": "2024-01-03T00:30:24Z", + "modified": "2024-01-09T18:30:26Z", "published": "2024-01-03T00:30:24Z", "aliases": [ "CVE-2023-49554" ], "details": "Use After Free vulnerability in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the do_directive function in the modules/preprocs/nasm/nasm-pp.c component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-03T00:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-59h3-54m2-3jm7/GHSA-59h3-54m2-3jm7.json b/advisories/unreviewed/2024/01/GHSA-59h3-54m2-3jm7/GHSA-59h3-54m2-3jm7.json new file mode 100644 index 00000000000..08bd664e995 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-59h3-54m2-3jm7/GHSA-59h3-54m2-3jm7.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-59h3-54m2-3jm7", + "modified": "2024-01-09T18:30:27Z", + "published": "2024-01-09T18:30:27Z", + "aliases": [ + "CVE-2024-0340" + ], + "details": "A vulnerability was found in vhost_new_msg in drivers/vhost/vhost.c in the Linux kernel, which does not properly initialize memory in messages passed between virtual guests and the host operating system in the vhost/vhost.c:vhost_new_msg() function. This issue can allow local privileged users to read some kernel memory contents when reading from the /dev/vhost-net device file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0340" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-0340" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2257406" + }, + { + "type": "WEB", + "url": "https://lore.kernel.org/lkml/5kn47peabxjrptkqa6dwtyus35ahf4pcj4qm4pumse33kxqpjw@mec4se5relrc/T/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-09T18:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-5f2c-q448-h62x/GHSA-5f2c-q448-h62x.json b/advisories/unreviewed/2024/01/GHSA-5f2c-q448-h62x/GHSA-5f2c-q448-h62x.json index 0d80b627ce2..e5f87458632 100644 --- a/advisories/unreviewed/2024/01/GHSA-5f2c-q448-h62x/GHSA-5f2c-q448-h62x.json +++ b/advisories/unreviewed/2024/01/GHSA-5f2c-q448-h62x/GHSA-5f2c-q448-h62x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5f2c-q448-h62x", - "modified": "2024-01-05T12:30:21Z", + "modified": "2024-01-09T18:30:27Z", "published": "2024-01-05T12:30:21Z", "aliases": [ "CVE-2023-50991" ], "details": "Buffer Overflow vulnerability in Tenda i29 versions 1.0 V1.0.0.5 and 1.0 V1.0.0.2, allows remote attackers to cause a denial of service (DoS) via the pingIp parameter in the pingSet function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-05T10:15:10Z" diff --git a/advisories/unreviewed/2024/01/GHSA-5fw3-xj86-w3c3/GHSA-5fw3-xj86-w3c3.json b/advisories/unreviewed/2024/01/GHSA-5fw3-xj86-w3c3/GHSA-5fw3-xj86-w3c3.json new file mode 100644 index 00000000000..63566ea4294 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-5fw3-xj86-w3c3/GHSA-5fw3-xj86-w3c3.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5fw3-xj86-w3c3", + "modified": "2024-01-09T18:30:27Z", + "published": "2024-01-09T18:30:27Z", + "aliases": [ + "CVE-2023-7223" + ], + "details": "A vulnerability classified as problematic has been found in Totolink T6 4.1.9cu.5241_B20210923. This affects an unknown part of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument topicurl with the input showSyslog leads to improper access controls. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-249867. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-7223" + }, + { + "type": "WEB", + "url": "https://drive.google.com/file/d/1puSOo5XrzMrctw7EtrE7DnfssOOuhRTS/view?usp=sharing" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.249867" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.249867" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-09T16:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-5q6v-3768-8xq7/GHSA-5q6v-3768-8xq7.json b/advisories/unreviewed/2024/01/GHSA-5q6v-3768-8xq7/GHSA-5q6v-3768-8xq7.json new file mode 100644 index 00000000000..58cf3632382 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-5q6v-3768-8xq7/GHSA-5q6v-3768-8xq7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5q6v-3768-8xq7", + "modified": "2024-01-09T18:30:27Z", + "published": "2024-01-09T18:30:27Z", + "aliases": [ + "CVE-2024-22164" + ], + "details": "In Splunk Enterprise Security (ES) versions below 7.1.2, an attacker can use investigation attachments to perform a denial of service (DoS) to the Investigation. The attachment endpoint does not properly limit the size of the request which lets an attacker cause the Investigation to become inaccessible.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22164" + }, + { + "type": "WEB", + "url": "https://advisory.splunk.com/advisories/SVD-2024-0101" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-09T17:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-5x77-x3qm-5v2f/GHSA-5x77-x3qm-5v2f.json b/advisories/unreviewed/2024/01/GHSA-5x77-x3qm-5v2f/GHSA-5x77-x3qm-5v2f.json new file mode 100644 index 00000000000..7fb6f5412bd --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-5x77-x3qm-5v2f/GHSA-5x77-x3qm-5v2f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5x77-x3qm-5v2f", + "modified": "2024-01-09T18:30:28Z", + "published": "2024-01-09T18:30:28Z", + "aliases": [ + "CVE-2024-20662" + ], + "details": "Windows Online Certificate Status Protocol (OCSP) Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20662" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-20662" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-09T18:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-62fm-r774-57v7/GHSA-62fm-r774-57v7.json b/advisories/unreviewed/2024/01/GHSA-62fm-r774-57v7/GHSA-62fm-r774-57v7.json new file mode 100644 index 00000000000..5509a44b14e --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-62fm-r774-57v7/GHSA-62fm-r774-57v7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-62fm-r774-57v7", + "modified": "2024-01-09T18:30:28Z", + "published": "2024-01-09T18:30:28Z", + "aliases": [ + "CVE-2024-20661" + ], + "details": "Microsoft Message Queuing Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20661" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-20661" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-09T18:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-66j8-27jm-c7ff/GHSA-66j8-27jm-c7ff.json b/advisories/unreviewed/2024/01/GHSA-66j8-27jm-c7ff/GHSA-66j8-27jm-c7ff.json new file mode 100644 index 00000000000..78b2407a68f --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-66j8-27jm-c7ff/GHSA-66j8-27jm-c7ff.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-66j8-27jm-c7ff", + "modified": "2024-01-09T18:30:29Z", + "published": "2024-01-09T18:30:29Z", + "aliases": [ + "CVE-2024-21316" + ], + "details": "Windows Server Key Distribution Service Security Feature Bypass", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21316" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21316" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-09T18:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-6ch4-5r6m-5v7w/GHSA-6ch4-5r6m-5v7w.json b/advisories/unreviewed/2024/01/GHSA-6ch4-5r6m-5v7w/GHSA-6ch4-5r6m-5v7w.json new file mode 100644 index 00000000000..68458c16c9e --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-6ch4-5r6m-5v7w/GHSA-6ch4-5r6m-5v7w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6ch4-5r6m-5v7w", + "modified": "2024-01-09T18:30:29Z", + "published": "2024-01-09T18:30:29Z", + "aliases": [ + "CVE-2024-20687" + ], + "details": "Microsoft AllJoyn API Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20687" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-20687" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-09T18:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-6fjx-3c25-3qrc/GHSA-6fjx-3c25-3qrc.json b/advisories/unreviewed/2024/01/GHSA-6fjx-3c25-3qrc/GHSA-6fjx-3c25-3qrc.json new file mode 100644 index 00000000000..652a8da75cd --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-6fjx-3c25-3qrc/GHSA-6fjx-3c25-3qrc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6fjx-3c25-3qrc", + "modified": "2024-01-09T18:30:29Z", + "published": "2024-01-09T18:30:29Z", + "aliases": [ + "CVE-2024-21306" + ], + "details": "Microsoft Bluetooth Driver Spoofing Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21306" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21306" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-09T18:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-6gw8-36pw-g34w/GHSA-6gw8-36pw-g34w.json b/advisories/unreviewed/2024/01/GHSA-6gw8-36pw-g34w/GHSA-6gw8-36pw-g34w.json new file mode 100644 index 00000000000..1899fdfab61 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-6gw8-36pw-g34w/GHSA-6gw8-36pw-g34w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6gw8-36pw-g34w", + "modified": "2024-01-09T18:30:29Z", + "published": "2024-01-09T18:30:29Z", + "aliases": [ + "CVE-2024-20699" + ], + "details": "Windows Hyper-V Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20699" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-20699" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-09T18:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-6j79-xv7w-8g6f/GHSA-6j79-xv7w-8g6f.json b/advisories/unreviewed/2024/01/GHSA-6j79-xv7w-8g6f/GHSA-6j79-xv7w-8g6f.json new file mode 100644 index 00000000000..e987fc0455b --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-6j79-xv7w-8g6f/GHSA-6j79-xv7w-8g6f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6j79-xv7w-8g6f", + "modified": "2024-01-09T18:30:28Z", + "published": "2024-01-09T18:30:28Z", + "aliases": [ + "CVE-2024-20652" + ], + "details": "Windows HTML Platforms Security Feature Bypass Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20652" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-20652" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-09T18:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-7p5c-g6m3-v67r/GHSA-7p5c-g6m3-v67r.json b/advisories/unreviewed/2024/01/GHSA-7p5c-g6m3-v67r/GHSA-7p5c-g6m3-v67r.json new file mode 100644 index 00000000000..bdb8b5f7391 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-7p5c-g6m3-v67r/GHSA-7p5c-g6m3-v67r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7p5c-g6m3-v67r", + "modified": "2024-01-09T18:30:28Z", + "published": "2024-01-09T18:30:28Z", + "aliases": [ + "CVE-2024-20656" + ], + "details": "Visual Studio Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20656" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-20656" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-09T18:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-7rrh-5xjg-2jmp/GHSA-7rrh-5xjg-2jmp.json b/advisories/unreviewed/2024/01/GHSA-7rrh-5xjg-2jmp/GHSA-7rrh-5xjg-2jmp.json new file mode 100644 index 00000000000..4fc2a15e31c --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-7rrh-5xjg-2jmp/GHSA-7rrh-5xjg-2jmp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7rrh-5xjg-2jmp", + "modified": "2024-01-09T18:30:29Z", + "published": "2024-01-09T18:30:29Z", + "aliases": [ + "CVE-2024-21311" + ], + "details": "Windows Cryptographic Services Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21311" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21311" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-09T18:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-85h2-c2jq-7mg4/GHSA-85h2-c2jq-7mg4.json b/advisories/unreviewed/2024/01/GHSA-85h2-c2jq-7mg4/GHSA-85h2-c2jq-7mg4.json new file mode 100644 index 00000000000..1d7c6275fe3 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-85h2-c2jq-7mg4/GHSA-85h2-c2jq-7mg4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-85h2-c2jq-7mg4", + "modified": "2024-01-09T18:30:28Z", + "published": "2024-01-09T18:30:28Z", + "aliases": [ + "CVE-2024-20680" + ], + "details": "Windows Message Queuing Client (MSMQC) Information Disclosure", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20680" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-20680" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-09T18:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-8g65-3569-fx34/GHSA-8g65-3569-fx34.json b/advisories/unreviewed/2024/01/GHSA-8g65-3569-fx34/GHSA-8g65-3569-fx34.json index 069fababc13..0554e00b8ec 100644 --- a/advisories/unreviewed/2024/01/GHSA-8g65-3569-fx34/GHSA-8g65-3569-fx34.json +++ b/advisories/unreviewed/2024/01/GHSA-8g65-3569-fx34/GHSA-8g65-3569-fx34.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8g65-3569-fx34", - "modified": "2024-01-03T00:30:23Z", + "modified": "2024-01-09T18:30:26Z", "published": "2024-01-03T00:30:23Z", "aliases": [ "CVE-2023-4164" @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-862" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-8g6x-mrx6-77x2/GHSA-8g6x-mrx6-77x2.json b/advisories/unreviewed/2024/01/GHSA-8g6x-mrx6-77x2/GHSA-8g6x-mrx6-77x2.json new file mode 100644 index 00000000000..1218155444d --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-8g6x-mrx6-77x2/GHSA-8g6x-mrx6-77x2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8g6x-mrx6-77x2", + "modified": "2024-01-09T18:30:29Z", + "published": "2024-01-09T18:30:29Z", + "aliases": [ + "CVE-2024-21314" + ], + "details": "Microsoft Message Queuing Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21314" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21314" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-09T18:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-92hj-6r7m-gqhh/GHSA-92hj-6r7m-gqhh.json b/advisories/unreviewed/2024/01/GHSA-92hj-6r7m-gqhh/GHSA-92hj-6r7m-gqhh.json index bca75f99b10..92fb27c05e6 100644 --- a/advisories/unreviewed/2024/01/GHSA-92hj-6r7m-gqhh/GHSA-92hj-6r7m-gqhh.json +++ b/advisories/unreviewed/2024/01/GHSA-92hj-6r7m-gqhh/GHSA-92hj-6r7m-gqhh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-92hj-6r7m-gqhh", - "modified": "2024-01-03T00:30:24Z", + "modified": "2024-01-09T18:30:27Z", "published": "2024-01-03T00:30:24Z", "aliases": [ "CVE-2023-49557" ], "details": "An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the yasm_section_bcs_first function in the libyasm/section.c component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-03T00:15:09Z" diff --git a/advisories/unreviewed/2024/01/GHSA-98g6-xh36-x2p7/GHSA-98g6-xh36-x2p7.json b/advisories/unreviewed/2024/01/GHSA-98g6-xh36-x2p7/GHSA-98g6-xh36-x2p7.json new file mode 100644 index 00000000000..9a315d10be4 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-98g6-xh36-x2p7/GHSA-98g6-xh36-x2p7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-98g6-xh36-x2p7", + "modified": "2024-01-09T18:30:27Z", + "published": "2024-01-09T18:30:27Z", + "aliases": [ + "CVE-2024-0056" + ], + "details": "Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0056" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-0056" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-09T18:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-9cx9-hjrh-cgmm/GHSA-9cx9-hjrh-cgmm.json b/advisories/unreviewed/2024/01/GHSA-9cx9-hjrh-cgmm/GHSA-9cx9-hjrh-cgmm.json new file mode 100644 index 00000000000..a9ba020a871 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-9cx9-hjrh-cgmm/GHSA-9cx9-hjrh-cgmm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9cx9-hjrh-cgmm", + "modified": "2024-01-09T18:30:28Z", + "published": "2024-01-09T18:30:28Z", + "aliases": [ + "CVE-2024-20677" + ], + "details": "

A security vulnerability exists in FBX that could lead to remote code execution. To mitigate this vulnerability, the ability to insert FBX files has been disabled in Word, Excel, PowerPoint and Outlook for Windows and Mac. Versions of Office that had this feature enabled will no longer have access to it. This includes Office 2019, Office 2021, Office LTSC for Mac 2021, and Microsoft 365.

\n

3D models in Office documents that were previously inserted from a FBX file will continue to work as expected unless the Link to File option was chosen at insert time.

\n

This change is effective as of the January 9, 2024 security update.

\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20677" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-20677" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-09T18:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-9gfv-m6hh-94gq/GHSA-9gfv-m6hh-94gq.json b/advisories/unreviewed/2024/01/GHSA-9gfv-m6hh-94gq/GHSA-9gfv-m6hh-94gq.json index 4446ecc5e93..50c88025fc0 100644 --- a/advisories/unreviewed/2024/01/GHSA-9gfv-m6hh-94gq/GHSA-9gfv-m6hh-94gq.json +++ b/advisories/unreviewed/2024/01/GHSA-9gfv-m6hh-94gq/GHSA-9gfv-m6hh-94gq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9gfv-m6hh-94gq", - "modified": "2024-01-03T00:30:23Z", + "modified": "2024-01-09T18:30:26Z", "published": "2024-01-03T00:30:23Z", "aliases": [ "CVE-2023-49553" ], "details": "An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_destroy function in the msj.c file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-02T23:15:12Z" diff --git a/advisories/unreviewed/2024/01/GHSA-9p7x-rvcj-9wg6/GHSA-9p7x-rvcj-9wg6.json b/advisories/unreviewed/2024/01/GHSA-9p7x-rvcj-9wg6/GHSA-9p7x-rvcj-9wg6.json new file mode 100644 index 00000000000..52fd854740f --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-9p7x-rvcj-9wg6/GHSA-9p7x-rvcj-9wg6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9p7x-rvcj-9wg6", + "modified": "2024-01-09T18:30:29Z", + "published": "2024-01-09T18:30:29Z", + "aliases": [ + "CVE-2024-21313" + ], + "details": "Windows TCP/IP Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21313" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21313" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-09T18:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-9rm8-w7j5-j66w/GHSA-9rm8-w7j5-j66w.json b/advisories/unreviewed/2024/01/GHSA-9rm8-w7j5-j66w/GHSA-9rm8-w7j5-j66w.json index 608ced14354..1c5b04151bd 100644 --- a/advisories/unreviewed/2024/01/GHSA-9rm8-w7j5-j66w/GHSA-9rm8-w7j5-j66w.json +++ b/advisories/unreviewed/2024/01/GHSA-9rm8-w7j5-j66w/GHSA-9rm8-w7j5-j66w.json @@ -29,6 +29,10 @@ "type": "WEB", "url": "https://software.open-xchange.com/products/appsuite/doc/Release_Notes_for_Patch_Release_6251_7.10.6_2023-09-25.pdf" }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/176422/OX-App-Suite-7.10.6-Access-Control-Cross-Site-Scripting.html" + }, { "type": "WEB", "url": "http://seclists.org/fulldisclosure/2024/Jan/4" diff --git a/advisories/unreviewed/2024/01/GHSA-9w5p-cfp8-w353/GHSA-9w5p-cfp8-w353.json b/advisories/unreviewed/2024/01/GHSA-9w5p-cfp8-w353/GHSA-9w5p-cfp8-w353.json new file mode 100644 index 00000000000..77a713237c6 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-9w5p-cfp8-w353/GHSA-9w5p-cfp8-w353.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9w5p-cfp8-w353", + "modified": "2024-01-09T18:30:28Z", + "published": "2024-01-09T18:30:28Z", + "aliases": [ + "CVE-2024-20654" + ], + "details": "Microsoft ODBC Driver Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20654" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-20654" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-09T18:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-c2cf-p6qq-wxrr/GHSA-c2cf-p6qq-wxrr.json b/advisories/unreviewed/2024/01/GHSA-c2cf-p6qq-wxrr/GHSA-c2cf-p6qq-wxrr.json new file mode 100644 index 00000000000..27f48a17829 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-c2cf-p6qq-wxrr/GHSA-c2cf-p6qq-wxrr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c2cf-p6qq-wxrr", + "modified": "2024-01-09T18:30:28Z", + "published": "2024-01-09T18:30:28Z", + "aliases": [ + "CVE-2024-20655" + ], + "details": "Microsoft Online Certificate Status Protocol (OCSP) Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20655" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-20655" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-09T18:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-cx5m-8m85-mm6m/GHSA-cx5m-8m85-mm6m.json b/advisories/unreviewed/2024/01/GHSA-cx5m-8m85-mm6m/GHSA-cx5m-8m85-mm6m.json new file mode 100644 index 00000000000..bcf76e68460 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-cx5m-8m85-mm6m/GHSA-cx5m-8m85-mm6m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cx5m-8m85-mm6m", + "modified": "2024-01-09T18:30:29Z", + "published": "2024-01-09T18:30:29Z", + "aliases": [ + "CVE-2024-20690" + ], + "details": "Windows Nearby Sharing Spoofing Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20690" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-20690" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-09T18:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-f6jr-7pgg-f497/GHSA-f6jr-7pgg-f497.json b/advisories/unreviewed/2024/01/GHSA-f6jr-7pgg-f497/GHSA-f6jr-7pgg-f497.json index a1bba1e02dc..6a7c6834bd4 100644 --- a/advisories/unreviewed/2024/01/GHSA-f6jr-7pgg-f497/GHSA-f6jr-7pgg-f497.json +++ b/advisories/unreviewed/2024/01/GHSA-f6jr-7pgg-f497/GHSA-f6jr-7pgg-f497.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f6jr-7pgg-f497", - "modified": "2024-01-03T00:30:23Z", + "modified": "2024-01-09T18:30:26Z", "published": "2024-01-03T00:30:23Z", "aliases": [ "CVE-2023-49552" ], "details": "An Out of Bounds Write in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_op_json_stringify function in the msj.c file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-02T23:15:12Z" diff --git a/advisories/unreviewed/2024/01/GHSA-f7xv-mwmj-x7p9/GHSA-f7xv-mwmj-x7p9.json b/advisories/unreviewed/2024/01/GHSA-f7xv-mwmj-x7p9/GHSA-f7xv-mwmj-x7p9.json new file mode 100644 index 00000000000..b073bbcf014 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-f7xv-mwmj-x7p9/GHSA-f7xv-mwmj-x7p9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f7xv-mwmj-x7p9", + "modified": "2024-01-09T18:30:29Z", + "published": "2024-01-09T18:30:29Z", + "aliases": [ + "CVE-2024-21325" + ], + "details": "Microsoft Printer Metadata Troubleshooter Tool Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21325" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21325" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-09T18:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-fh95-g988-p9j3/GHSA-fh95-g988-p9j3.json b/advisories/unreviewed/2024/01/GHSA-fh95-g988-p9j3/GHSA-fh95-g988-p9j3.json index a759e950c77..f3251e0e801 100644 --- a/advisories/unreviewed/2024/01/GHSA-fh95-g988-p9j3/GHSA-fh95-g988-p9j3.json +++ b/advisories/unreviewed/2024/01/GHSA-fh95-g988-p9j3/GHSA-fh95-g988-p9j3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fh95-g988-p9j3", - "modified": "2024-01-03T00:30:23Z", + "modified": "2024-01-09T18:30:26Z", "published": "2024-01-03T00:30:23Z", "aliases": [ "CVE-2023-49549" ], "details": "An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_getretvalpos function in the msj.c file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-02T23:15:12Z" diff --git a/advisories/unreviewed/2024/01/GHSA-fp7j-p7cw-gqcx/GHSA-fp7j-p7cw-gqcx.json b/advisories/unreviewed/2024/01/GHSA-fp7j-p7cw-gqcx/GHSA-fp7j-p7cw-gqcx.json new file mode 100644 index 00000000000..85ae2c26df7 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-fp7j-p7cw-gqcx/GHSA-fp7j-p7cw-gqcx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fp7j-p7cw-gqcx", + "modified": "2024-01-09T18:30:29Z", + "published": "2024-01-09T18:30:29Z", + "aliases": [ + "CVE-2024-21310" + ], + "details": "Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21310" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21310" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-09T18:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-fpg3-7wj3-x58x/GHSA-fpg3-7wj3-x58x.json b/advisories/unreviewed/2024/01/GHSA-fpg3-7wj3-x58x/GHSA-fpg3-7wj3-x58x.json new file mode 100644 index 00000000000..b482faedc79 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-fpg3-7wj3-x58x/GHSA-fpg3-7wj3-x58x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fpg3-7wj3-x58x", + "modified": "2024-01-09T18:30:28Z", + "published": "2024-01-09T18:30:28Z", + "aliases": [ + "CVE-2024-20657" + ], + "details": "Windows Group Policy Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20657" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-20657" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-09T18:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-fqmm-mm4m-5h74/GHSA-fqmm-mm4m-5h74.json b/advisories/unreviewed/2024/01/GHSA-fqmm-mm4m-5h74/GHSA-fqmm-mm4m-5h74.json new file mode 100644 index 00000000000..2ced1113c3a --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-fqmm-mm4m-5h74/GHSA-fqmm-mm4m-5h74.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fqmm-mm4m-5h74", + "modified": "2024-01-09T18:30:29Z", + "published": "2024-01-09T18:30:29Z", + "aliases": [ + "CVE-2024-20700" + ], + "details": "Windows Hyper-V Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20700" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-20700" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-09T18:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-fv65-2c76-4jh9/GHSA-fv65-2c76-4jh9.json b/advisories/unreviewed/2024/01/GHSA-fv65-2c76-4jh9/GHSA-fv65-2c76-4jh9.json new file mode 100644 index 00000000000..7d4c10ac109 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-fv65-2c76-4jh9/GHSA-fv65-2c76-4jh9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fv65-2c76-4jh9", + "modified": "2024-01-09T18:30:29Z", + "published": "2024-01-09T18:30:29Z", + "aliases": [ + "CVE-2024-21307" + ], + "details": "Remote Desktop Client Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21307" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21307" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-09T18:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-fvh6-48v9-mqh2/GHSA-fvh6-48v9-mqh2.json b/advisories/unreviewed/2024/01/GHSA-fvh6-48v9-mqh2/GHSA-fvh6-48v9-mqh2.json new file mode 100644 index 00000000000..d3ca713c735 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-fvh6-48v9-mqh2/GHSA-fvh6-48v9-mqh2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fvh6-48v9-mqh2", + "modified": "2024-01-09T18:30:29Z", + "published": "2024-01-09T18:30:29Z", + "aliases": [ + "CVE-2024-21320" + ], + "details": "Windows Themes Spoofing Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21320" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21320" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-09T18:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-g5xc-jv8h-2232/GHSA-g5xc-jv8h-2232.json b/advisories/unreviewed/2024/01/GHSA-g5xc-jv8h-2232/GHSA-g5xc-jv8h-2232.json new file mode 100644 index 00000000000..d0f2a4aea41 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-g5xc-jv8h-2232/GHSA-g5xc-jv8h-2232.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g5xc-jv8h-2232", + "modified": "2024-01-09T18:30:29Z", + "published": "2024-01-09T18:30:29Z", + "aliases": [ + "CVE-2024-20696" + ], + "details": "Windows Libarchive Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20696" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-20696" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-09T18:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-ghfh-q3pc-fx3g/GHSA-ghfh-q3pc-fx3g.json b/advisories/unreviewed/2024/01/GHSA-ghfh-q3pc-fx3g/GHSA-ghfh-q3pc-fx3g.json new file mode 100644 index 00000000000..c4f3071292f --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-ghfh-q3pc-fx3g/GHSA-ghfh-q3pc-fx3g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ghfh-q3pc-fx3g", + "modified": "2024-01-09T18:30:29Z", + "published": "2024-01-09T18:30:29Z", + "aliases": [ + "CVE-2024-20698" + ], + "details": "Windows Kernel Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20698" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-20698" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-09T18:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-hqxc-wrhh-3x6q/GHSA-hqxc-wrhh-3x6q.json b/advisories/unreviewed/2024/01/GHSA-hqxc-wrhh-3x6q/GHSA-hqxc-wrhh-3x6q.json new file mode 100644 index 00000000000..a2e4e717adc --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-hqxc-wrhh-3x6q/GHSA-hqxc-wrhh-3x6q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hqxc-wrhh-3x6q", + "modified": "2024-01-09T18:30:28Z", + "published": "2024-01-09T18:30:28Z", + "aliases": [ + "CVE-2024-20682" + ], + "details": "Windows Cryptographic Services Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20682" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-20682" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-09T18:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-hwrv-r72x-jcwr/GHSA-hwrv-r72x-jcwr.json b/advisories/unreviewed/2024/01/GHSA-hwrv-r72x-jcwr/GHSA-hwrv-r72x-jcwr.json index e4b80fc4632..4989edeadff 100644 --- a/advisories/unreviewed/2024/01/GHSA-hwrv-r72x-jcwr/GHSA-hwrv-r72x-jcwr.json +++ b/advisories/unreviewed/2024/01/GHSA-hwrv-r72x-jcwr/GHSA-hwrv-r72x-jcwr.json @@ -29,6 +29,10 @@ "type": "WEB", "url": "https://software.open-xchange.com/products/appsuite/doc/Release_Notes_for_Patch_Release_6251_7.10.6_2023-09-25.pdf" }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/176422/OX-App-Suite-7.10.6-Access-Control-Cross-Site-Scripting.html" + }, { "type": "WEB", "url": "http://seclists.org/fulldisclosure/2024/Jan/4" diff --git a/advisories/unreviewed/2024/01/GHSA-jcxm-cfv5-gp8j/GHSA-jcxm-cfv5-gp8j.json b/advisories/unreviewed/2024/01/GHSA-jcxm-cfv5-gp8j/GHSA-jcxm-cfv5-gp8j.json new file mode 100644 index 00000000000..399acf2f218 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-jcxm-cfv5-gp8j/GHSA-jcxm-cfv5-gp8j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jcxm-cfv5-gp8j", + "modified": "2024-01-09T18:30:29Z", + "published": "2024-01-09T18:30:29Z", + "aliases": [ + "CVE-2024-20694" + ], + "details": "Windows CoreMessaging Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20694" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-20694" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-09T18:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-jf4q-23f7-4mp3/GHSA-jf4q-23f7-4mp3.json b/advisories/unreviewed/2024/01/GHSA-jf4q-23f7-4mp3/GHSA-jf4q-23f7-4mp3.json new file mode 100644 index 00000000000..df0697ba3f0 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-jf4q-23f7-4mp3/GHSA-jf4q-23f7-4mp3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jf4q-23f7-4mp3", + "modified": "2024-01-09T18:30:28Z", + "published": "2024-01-09T18:30:28Z", + "aliases": [ + "CVE-2024-20663" + ], + "details": "Windows Message Queuing Client (MSMQC) Information Disclosure", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20663" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-20663" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-09T18:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-jf62-g97c-j9x3/GHSA-jf62-g97c-j9x3.json b/advisories/unreviewed/2024/01/GHSA-jf62-g97c-j9x3/GHSA-jf62-g97c-j9x3.json index 2a2bd4c631f..33c98d62248 100644 --- a/advisories/unreviewed/2024/01/GHSA-jf62-g97c-j9x3/GHSA-jf62-g97c-j9x3.json +++ b/advisories/unreviewed/2024/01/GHSA-jf62-g97c-j9x3/GHSA-jf62-g97c-j9x3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jf62-g97c-j9x3", - "modified": "2024-01-03T03:30:33Z", + "modified": "2024-01-09T18:30:27Z", "published": "2024-01-03T03:30:33Z", "aliases": [ "CVE-2023-50342" @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-639" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-jh2h-9mjq-3gvm/GHSA-jh2h-9mjq-3gvm.json b/advisories/unreviewed/2024/01/GHSA-jh2h-9mjq-3gvm/GHSA-jh2h-9mjq-3gvm.json new file mode 100644 index 00000000000..8ab0065d5f3 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-jh2h-9mjq-3gvm/GHSA-jh2h-9mjq-3gvm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jh2h-9mjq-3gvm", + "modified": "2024-01-09T18:30:28Z", + "published": "2024-01-09T18:30:28Z", + "aliases": [ + "CVE-2024-20664" + ], + "details": "Microsoft Message Queuing Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20664" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-20664" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-09T18:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-jjvf-rww2-493v/GHSA-jjvf-rww2-493v.json b/advisories/unreviewed/2024/01/GHSA-jjvf-rww2-493v/GHSA-jjvf-rww2-493v.json new file mode 100644 index 00000000000..996b178c183 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-jjvf-rww2-493v/GHSA-jjvf-rww2-493v.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jjvf-rww2-493v", + "modified": "2024-01-09T18:30:27Z", + "published": "2024-01-09T18:30:27Z", + "aliases": [ + "CVE-2023-7222" + ], + "details": "A vulnerability was found in Totolink X2000R 1.0.0-B20221212.1452. It has been declared as critical. This vulnerability affects the function formTmultiAP of the file /bin/boa of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-249856. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-7222" + }, + { + "type": "WEB", + "url": "https://github.com/jylsec/vuldb/blob/main/TOTOLINK/X2000R/formTmultiAP/README.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.249856" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.249856" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-09T16:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-jw42-5m4v-9c8g/GHSA-jw42-5m4v-9c8g.json b/advisories/unreviewed/2024/01/GHSA-jw42-5m4v-9c8g/GHSA-jw42-5m4v-9c8g.json new file mode 100644 index 00000000000..5cc1eb5c566 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-jw42-5m4v-9c8g/GHSA-jw42-5m4v-9c8g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jw42-5m4v-9c8g", + "modified": "2024-01-09T18:30:27Z", + "published": "2024-01-09T18:30:27Z", + "aliases": [ + "CVE-2024-0057" + ], + "details": "NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0057" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-0057" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-09T18:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-jw97-qgpr-gq9q/GHSA-jw97-qgpr-gq9q.json b/advisories/unreviewed/2024/01/GHSA-jw97-qgpr-gq9q/GHSA-jw97-qgpr-gq9q.json new file mode 100644 index 00000000000..1f7743a8a67 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-jw97-qgpr-gq9q/GHSA-jw97-qgpr-gq9q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jw97-qgpr-gq9q", + "modified": "2024-01-09T18:30:27Z", + "published": "2024-01-09T18:30:27Z", + "aliases": [ + "CVE-2024-0226" + ], + "details": "Synopsys Seeker versions prior to 2023.12.0 are vulnerable to a stored cross-site scripting vulnerability through a specially crafted payload.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0226" + }, + { + "type": "WEB", + "url": "https://community.synopsys.com/s/article/SIG-Product-Security-Advisory-CVE-2024-0226-Affecting-Seeker" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-09T18:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-m9vg-87mr-c2rx/GHSA-m9vg-87mr-c2rx.json b/advisories/unreviewed/2024/01/GHSA-m9vg-87mr-c2rx/GHSA-m9vg-87mr-c2rx.json new file mode 100644 index 00000000000..788b7eb9f37 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-m9vg-87mr-c2rx/GHSA-m9vg-87mr-c2rx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m9vg-87mr-c2rx", + "modified": "2024-01-09T18:30:28Z", + "published": "2024-01-09T18:30:28Z", + "aliases": [ + "CVE-2024-20653" + ], + "details": "Microsoft Common Log File System Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20653" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-20653" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-09T18:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-mw57-gv8v-cj4r/GHSA-mw57-gv8v-cj4r.json b/advisories/unreviewed/2024/01/GHSA-mw57-gv8v-cj4r/GHSA-mw57-gv8v-cj4r.json new file mode 100644 index 00000000000..a30e2a9bb5c --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-mw57-gv8v-cj4r/GHSA-mw57-gv8v-cj4r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mw57-gv8v-cj4r", + "modified": "2024-01-09T18:30:29Z", + "published": "2024-01-09T18:30:29Z", + "aliases": [ + "CVE-2024-20692" + ], + "details": "Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20692" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-20692" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-09T18:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-pc6v-rjpx-v6rm/GHSA-pc6v-rjpx-v6rm.json b/advisories/unreviewed/2024/01/GHSA-pc6v-rjpx-v6rm/GHSA-pc6v-rjpx-v6rm.json new file mode 100644 index 00000000000..e0d36f52e0c --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-pc6v-rjpx-v6rm/GHSA-pc6v-rjpx-v6rm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pc6v-rjpx-v6rm", + "modified": "2024-01-09T18:30:29Z", + "published": "2024-01-09T18:30:29Z", + "aliases": [ + "CVE-2024-21305" + ], + "details": "Hypervisor-Protected Code Integrity (HVCI) Security Feature Bypass Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21305" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21305" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-09T18:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-pgpx-675x-4jcv/GHSA-pgpx-675x-4jcv.json b/advisories/unreviewed/2024/01/GHSA-pgpx-675x-4jcv/GHSA-pgpx-675x-4jcv.json index e87ec5c9947..d8f36826bab 100644 --- a/advisories/unreviewed/2024/01/GHSA-pgpx-675x-4jcv/GHSA-pgpx-675x-4jcv.json +++ b/advisories/unreviewed/2024/01/GHSA-pgpx-675x-4jcv/GHSA-pgpx-675x-4jcv.json @@ -29,6 +29,10 @@ "type": "WEB", "url": "https://software.open-xchange.com/products/appsuite/doc/Release_Notes_for_Patch_Release_6248_7.10.6_2023-09-19.pdf" }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/176421/OX-App-Suite-7.10.6-XSS-Command-Execution-LDAP-Injection.html" + }, { "type": "WEB", "url": "http://seclists.org/fulldisclosure/2024/Jan/3" diff --git a/advisories/unreviewed/2024/01/GHSA-pjh6-2v65-x4fj/GHSA-pjh6-2v65-x4fj.json b/advisories/unreviewed/2024/01/GHSA-pjh6-2v65-x4fj/GHSA-pjh6-2v65-x4fj.json index e214c2a2f7a..e6aaae0f587 100644 --- a/advisories/unreviewed/2024/01/GHSA-pjh6-2v65-x4fj/GHSA-pjh6-2v65-x4fj.json +++ b/advisories/unreviewed/2024/01/GHSA-pjh6-2v65-x4fj/GHSA-pjh6-2v65-x4fj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pjh6-2v65-x4fj", - "modified": "2024-01-01T18:30:25Z", + "modified": "2024-01-09T18:30:26Z", "published": "2024-01-01T18:30:25Z", "aliases": [ "CVE-2023-50096" ], "details": "STMicroelectronics STSAFE-A1xx middleware before 3.3.7 allows MCU code execution if an adversary has the ability to read from and write to the I2C bus. This is caused by an StSafeA_ReceiveBytes buffer overflow in the X-CUBE-SAFEA1 Software Package for STSAFE-A sample applications (1.2.0), and thus can affect user-written code that was derived from a published sample application.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-01T18:15:09Z" diff --git a/advisories/unreviewed/2024/01/GHSA-q795-pwf5-9r9x/GHSA-q795-pwf5-9r9x.json b/advisories/unreviewed/2024/01/GHSA-q795-pwf5-9r9x/GHSA-q795-pwf5-9r9x.json index f3bae60b8a0..31b361816c9 100644 --- a/advisories/unreviewed/2024/01/GHSA-q795-pwf5-9r9x/GHSA-q795-pwf5-9r9x.json +++ b/advisories/unreviewed/2024/01/GHSA-q795-pwf5-9r9x/GHSA-q795-pwf5-9r9x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q795-pwf5-9r9x", - "modified": "2024-01-03T00:30:24Z", + "modified": "2024-01-09T18:30:27Z", "published": "2024-01-03T00:30:24Z", "aliases": [ "CVE-2023-49556" ], "details": "Buffer Overflow vulnerability in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the expr_delete_term function in the libyasm/expr.c component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-03T00:15:09Z" diff --git a/advisories/unreviewed/2024/01/GHSA-qpjw-c5c3-h83r/GHSA-qpjw-c5c3-h83r.json b/advisories/unreviewed/2024/01/GHSA-qpjw-c5c3-h83r/GHSA-qpjw-c5c3-h83r.json new file mode 100644 index 00000000000..7eb9226bd4d --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-qpjw-c5c3-h83r/GHSA-qpjw-c5c3-h83r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qpjw-c5c3-h83r", + "modified": "2024-01-09T18:30:28Z", + "published": "2024-01-09T18:30:28Z", + "aliases": [ + "CVE-2024-20660" + ], + "details": "Microsoft Message Queuing Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20660" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-20660" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-09T18:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-rh83-2fx8-8x6x/GHSA-rh83-2fx8-8x6x.json b/advisories/unreviewed/2024/01/GHSA-rh83-2fx8-8x6x/GHSA-rh83-2fx8-8x6x.json new file mode 100644 index 00000000000..391b884a7ce --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-rh83-2fx8-8x6x/GHSA-rh83-2fx8-8x6x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rh83-2fx8-8x6x", + "modified": "2024-01-09T18:30:28Z", + "published": "2024-01-09T18:30:28Z", + "aliases": [ + "CVE-2024-20672" + ], + "details": ".NET Core and Visual Studio Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20672" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-20672" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-09T18:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-rhpx-9698-w5hr/GHSA-rhpx-9698-w5hr.json b/advisories/unreviewed/2024/01/GHSA-rhpx-9698-w5hr/GHSA-rhpx-9698-w5hr.json new file mode 100644 index 00000000000..9cf487ed6dc --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-rhpx-9698-w5hr/GHSA-rhpx-9698-w5hr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rhpx-9698-w5hr", + "modified": "2024-01-09T18:30:29Z", + "published": "2024-01-09T18:30:29Z", + "aliases": [ + "CVE-2024-20691" + ], + "details": "Windows Themes Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20691" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-20691" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-09T18:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-rj8q-prqp-jwfg/GHSA-rj8q-prqp-jwfg.json b/advisories/unreviewed/2024/01/GHSA-rj8q-prqp-jwfg/GHSA-rj8q-prqp-jwfg.json new file mode 100644 index 00000000000..fa6a3214222 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-rj8q-prqp-jwfg/GHSA-rj8q-prqp-jwfg.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rj8q-prqp-jwfg", + "modified": "2024-01-09T18:30:27Z", + "published": "2024-01-09T18:30:27Z", + "aliases": [ + "CVE-2023-6129" + ], + "details": "Issue summary: The POLY1305 MAC (message authentication code) implementation\ncontains a bug that might corrupt the internal state of applications running\non PowerPC CPU based platforms if the CPU provides vector instructions.\n\nImpact summary: If an attacker can influence whether the POLY1305 MAC\nalgorithm is used, the application state might be corrupted with various\napplication dependent consequences.\n\nThe POLY1305 MAC (message authentication code) implementation in OpenSSL for\nPowerPC CPUs restores the contents of vector registers in a different order\nthan they are saved. Thus the contents of some of these vector registers\nare corrupted when returning to the caller. The vulnerable code is used only\non newer PowerPC processors supporting the PowerISA 2.07 instructions.\n\nThe consequences of this kind of internal application state corruption can\nbe various - from no consequences, if the calling application does not\ndepend on the contents of non-volatile XMM registers at all, to the worst\nconsequences, where the attacker could get complete control of the application\nprocess. However unless the compiler uses the vector registers for storing\npointers, the most likely consequence, if any, would be an incorrect result\nof some application dependent calculations or a crash leading to a denial of\nservice.\n\nThe POLY1305 MAC algorithm is most frequently used as part of the\nCHACHA20-POLY1305 AEAD (authenticated encryption with associated data)\nalgorithm. The most common usage of this AEAD cipher is with TLS protocol\nversions 1.2 and 1.3. If this cipher is enabled on the server a malicious\nclient can influence whether this AEAD cipher is used. This implies that\nTLS server applications using OpenSSL can be potentially impacted. However\nwe are currently not aware of any concrete application that would be affected\nby this issue therefore we consider this a Low severity security issue.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6129" + }, + { + "type": "WEB", + "url": "https://github.com/openssl/openssl/commit/050d26383d4e264966fb83428e72d5d48f402d35" + }, + { + "type": "WEB", + "url": "https://github.com/openssl/openssl/commit/5b139f95c9a47a55a0c54100f3837b1eee942b04" + }, + { + "type": "WEB", + "url": "https://github.com/openssl/openssl/commit/f3fc5808fe9ff74042d639839610d03b8fdcc015" + }, + { + "type": "WEB", + "url": "https://www.openssl.org/news/secadv/20240109.txt" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/01/09/1" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-09T17:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-rm58-g3gh-gqf5/GHSA-rm58-g3gh-gqf5.json b/advisories/unreviewed/2024/01/GHSA-rm58-g3gh-gqf5/GHSA-rm58-g3gh-gqf5.json index e50484418fd..e1c8bd767d6 100644 --- a/advisories/unreviewed/2024/01/GHSA-rm58-g3gh-gqf5/GHSA-rm58-g3gh-gqf5.json +++ b/advisories/unreviewed/2024/01/GHSA-rm58-g3gh-gqf5/GHSA-rm58-g3gh-gqf5.json @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://support.google.com/product-documentation/answer/14273332?hl=en&ref_topic=12974021&sjid=4533873659772963473-NA" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.249563" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/01/GHSA-rrrh-8rp4-pgc2/GHSA-rrrh-8rp4-pgc2.json b/advisories/unreviewed/2024/01/GHSA-rrrh-8rp4-pgc2/GHSA-rrrh-8rp4-pgc2.json new file mode 100644 index 00000000000..4e0f2316a7c --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-rrrh-8rp4-pgc2/GHSA-rrrh-8rp4-pgc2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rrrh-8rp4-pgc2", + "modified": "2024-01-09T18:30:29Z", + "published": "2024-01-09T18:30:29Z", + "aliases": [ + "CVE-2024-20683" + ], + "details": "Win32k Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20683" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-20683" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-09T18:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-rx9g-96r8-m5g4/GHSA-rx9g-96r8-m5g4.json b/advisories/unreviewed/2024/01/GHSA-rx9g-96r8-m5g4/GHSA-rx9g-96r8-m5g4.json new file mode 100644 index 00000000000..93236358a8c --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-rx9g-96r8-m5g4/GHSA-rx9g-96r8-m5g4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rx9g-96r8-m5g4", + "modified": "2024-01-09T18:30:29Z", + "published": "2024-01-09T18:30:29Z", + "aliases": [ + "CVE-2024-21309" + ], + "details": "Windows Kernel-Mode Driver Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21309" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21309" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-09T18:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-v2rr-hhf4-8739/GHSA-v2rr-hhf4-8739.json b/advisories/unreviewed/2024/01/GHSA-v2rr-hhf4-8739/GHSA-v2rr-hhf4-8739.json new file mode 100644 index 00000000000..679d5d8923a --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-v2rr-hhf4-8739/GHSA-v2rr-hhf4-8739.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v2rr-hhf4-8739", + "modified": "2024-01-09T18:30:27Z", + "published": "2024-01-09T18:30:27Z", + "aliases": [ + "CVE-2022-48618" + ], + "details": "The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.1, watchOS 9.2, iOS 16.2 and iPadOS 16.2, tvOS 16.2. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication. Apple is aware of a report that this issue may have been exploited against versions of iOS released before iOS 15.7.1.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48618" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213530" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213532" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213535" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213536" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-09T18:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-vw59-wm86-qh74/GHSA-vw59-wm86-qh74.json b/advisories/unreviewed/2024/01/GHSA-vw59-wm86-qh74/GHSA-vw59-wm86-qh74.json new file mode 100644 index 00000000000..70e05569024 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-vw59-wm86-qh74/GHSA-vw59-wm86-qh74.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vw59-wm86-qh74", + "modified": "2024-01-09T18:30:27Z", + "published": "2024-01-09T18:30:27Z", + "aliases": [ + "CVE-2024-0228" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is a duplicate of CVE-2024-0193.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0228" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-09T17:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-w3p5-6w9w-p383/GHSA-w3p5-6w9w-p383.json b/advisories/unreviewed/2024/01/GHSA-w3p5-6w9w-p383/GHSA-w3p5-6w9w-p383.json index b8ae22d453c..ccb5b10560f 100644 --- a/advisories/unreviewed/2024/01/GHSA-w3p5-6w9w-p383/GHSA-w3p5-6w9w-p383.json +++ b/advisories/unreviewed/2024/01/GHSA-w3p5-6w9w-p383/GHSA-w3p5-6w9w-p383.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w3p5-6w9w-p383", - "modified": "2024-01-03T00:30:24Z", + "modified": "2024-01-09T18:30:27Z", "published": "2024-01-03T00:30:24Z", "aliases": [ "CVE-2023-49558" ], "details": "An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the expand_mmac_params function in the modules/preprocs/nasm/nasm-pp.c component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-03T00:15:09Z" diff --git a/advisories/unreviewed/2024/01/GHSA-w48w-95mf-vvc4/GHSA-w48w-95mf-vvc4.json b/advisories/unreviewed/2024/01/GHSA-w48w-95mf-vvc4/GHSA-w48w-95mf-vvc4.json new file mode 100644 index 00000000000..70f47b8e811 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-w48w-95mf-vvc4/GHSA-w48w-95mf-vvc4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w48w-95mf-vvc4", + "modified": "2024-01-09T18:30:27Z", + "published": "2024-01-09T18:30:27Z", + "aliases": [ + "CVE-2024-22165" + ], + "details": "In Splunk Enterprise Security (ES) versions lower than 7.1.2, an attacker can create a malformed Investigation to perform a denial of service (DoS). The malformed investigation prevents the generation and rendering of the Investigations manager until it is deleted.
The vulnerability requires an authenticated session and access to create an Investigation. It only affects the availability of the Investigations manager, but without the manager, the Investigations functionality becomes unusable for most users.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22165" + }, + { + "type": "WEB", + "url": "https://advisory.splunk.com/advisories/SVD-2024-0102" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-09T17:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-w6xv-37jv-7cjr/GHSA-w6xv-37jv-7cjr.json b/advisories/unreviewed/2024/01/GHSA-w6xv-37jv-7cjr/GHSA-w6xv-37jv-7cjr.json new file mode 100644 index 00000000000..4b55bf4da05 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-w6xv-37jv-7cjr/GHSA-w6xv-37jv-7cjr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w6xv-37jv-7cjr", + "modified": "2024-01-09T18:30:29Z", + "published": "2024-01-09T18:30:29Z", + "aliases": [ + "CVE-2024-20697" + ], + "details": "Windows Libarchive Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20697" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-20697" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-09T18:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-wqmr-cp8m-946m/GHSA-wqmr-cp8m-946m.json b/advisories/unreviewed/2024/01/GHSA-wqmr-cp8m-946m/GHSA-wqmr-cp8m-946m.json index b357a7f1b7c..d74c762c406 100644 --- a/advisories/unreviewed/2024/01/GHSA-wqmr-cp8m-946m/GHSA-wqmr-cp8m-946m.json +++ b/advisories/unreviewed/2024/01/GHSA-wqmr-cp8m-946m/GHSA-wqmr-cp8m-946m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wqmr-cp8m-946m", - "modified": "2024-01-03T00:30:23Z", + "modified": "2024-01-09T18:30:26Z", "published": "2024-01-03T00:30:23Z", "aliases": [ "CVE-2023-48418" diff --git a/advisories/unreviewed/2024/01/GHSA-wwcg-p45r-pv65/GHSA-wwcg-p45r-pv65.json b/advisories/unreviewed/2024/01/GHSA-wwcg-p45r-pv65/GHSA-wwcg-p45r-pv65.json new file mode 100644 index 00000000000..5214c077cf4 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-wwcg-p45r-pv65/GHSA-wwcg-p45r-pv65.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wwcg-p45r-pv65", + "modified": "2024-01-09T18:30:29Z", + "published": "2024-01-09T18:30:29Z", + "aliases": [ + "CVE-2024-20686" + ], + "details": "Win32k Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20686" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-20686" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-09T18:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-x5cx-qfrc-rw4r/GHSA-x5cx-qfrc-rw4r.json b/advisories/unreviewed/2024/01/GHSA-x5cx-qfrc-rw4r/GHSA-x5cx-qfrc-rw4r.json new file mode 100644 index 00000000000..cdbb870f4a4 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-x5cx-qfrc-rw4r/GHSA-x5cx-qfrc-rw4r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x5cx-qfrc-rw4r", + "modified": "2024-01-09T18:30:28Z", + "published": "2024-01-09T18:30:28Z", + "aliases": [ + "CVE-2024-20658" + ], + "details": "Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20658" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-20658" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-09T18:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-x5gw-mqgf-fwh3/GHSA-x5gw-mqgf-fwh3.json b/advisories/unreviewed/2024/01/GHSA-x5gw-mqgf-fwh3/GHSA-x5gw-mqgf-fwh3.json index 3c585fd0ba1..ed236a22a1e 100644 --- a/advisories/unreviewed/2024/01/GHSA-x5gw-mqgf-fwh3/GHSA-x5gw-mqgf-fwh3.json +++ b/advisories/unreviewed/2024/01/GHSA-x5gw-mqgf-fwh3/GHSA-x5gw-mqgf-fwh3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x5gw-mqgf-fwh3", - "modified": "2024-01-02T21:30:25Z", + "modified": "2024-01-09T18:30:26Z", "published": "2024-01-02T21:30:25Z", "aliases": [ "CVE-2022-3010" @@ -36,7 +36,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-1391" + "CWE-1391", + "CWE-916" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-xr84-qwr9-vj33/GHSA-xr84-qwr9-vj33.json b/advisories/unreviewed/2024/01/GHSA-xr84-qwr9-vj33/GHSA-xr84-qwr9-vj33.json index 4445ec94a31..12f2dd258fd 100644 --- a/advisories/unreviewed/2024/01/GHSA-xr84-qwr9-vj33/GHSA-xr84-qwr9-vj33.json +++ b/advisories/unreviewed/2024/01/GHSA-xr84-qwr9-vj33/GHSA-xr84-qwr9-vj33.json @@ -29,6 +29,10 @@ "type": "WEB", "url": "https://software.open-xchange.com/products/appsuite/doc/Release_Notes_for_Patch_Release_6251_7.10.6_2023-09-25.pdf" }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/176422/OX-App-Suite-7.10.6-Access-Control-Cross-Site-Scripting.html" + }, { "type": "WEB", "url": "http://seclists.org/fulldisclosure/2024/Jan/4"