diff --git a/advisories/unreviewed/2024/06/GHSA-294x-pcj2-wqf8/GHSA-294x-pcj2-wqf8.json b/advisories/unreviewed/2024/06/GHSA-294x-pcj2-wqf8/GHSA-294x-pcj2-wqf8.json new file mode 100644 index 00000000000..85e253a1a12 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-294x-pcj2-wqf8/GHSA-294x-pcj2-wqf8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-294x-pcj2-wqf8", + "modified": "2024-06-28T00:33:31Z", + "published": "2024-06-28T00:33:31Z", + "aliases": [ + "CVE-2024-36059" + ], + "details": "Directory Traversal vulnerability in Kalkitech ASE ASE61850 IEDSmart upto and including version 2.3.5 allows attackers to read/write arbitrary files via the IEC61850 File Transfer protocol.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36059" + }, + { + "type": "WEB", + "url": "https://kalkitech.com/wp-content/uploads/2024/05/CYB_60704_Advisory_v1.0.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-27T22:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-68wq-r58h-5q45/GHSA-68wq-r58h-5q45.json b/advisories/unreviewed/2024/06/GHSA-68wq-r58h-5q45/GHSA-68wq-r58h-5q45.json new file mode 100644 index 00000000000..75d59bf0672 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-68wq-r58h-5q45/GHSA-68wq-r58h-5q45.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-68wq-r58h-5q45", + "modified": "2024-06-28T00:33:31Z", + "published": "2024-06-28T00:33:31Z", + "aliases": [ + "CVE-2024-4395" + ], + "details": "The XPC service within the audit functionality of Jamf Compliance Editor before version 1.3.1 on macOS can lead to local privilege escalation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4395" + }, + { + "type": "WEB", + "url": "https://github.com/Jamf-Concepts/jamf-compliance-editor/raw/v1.3.1/Jamf%20Compliance%20Editor%20-%20User%20Guide.pdf" + }, + { + "type": "WEB", + "url": "https://github.com/Jamf-Concepts/jamf-compliance-editor/releases/download/v1.3.1/JamfComplianceEditor.v1.3.1.pkg" + }, + { + "type": "WEB", + "url": "https://khronokernel.com/macos/2024/05/01/CVE-2024-4395.html" + }, + { + "type": "WEB", + "url": "https://trusted.jamf.com/docs/establishing-compliance-baselines#support" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-27T22:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-cgvx-9447-vcch/GHSA-cgvx-9447-vcch.json b/advisories/unreviewed/2024/06/GHSA-cgvx-9447-vcch/GHSA-cgvx-9447-vcch.json new file mode 100644 index 00000000000..4f419e73e42 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-cgvx-9447-vcch/GHSA-cgvx-9447-vcch.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cgvx-9447-vcch", + "modified": "2024-06-28T00:33:31Z", + "published": "2024-06-28T00:33:31Z", + "aliases": [ + "CVE-2024-39705" + ], + "details": "NLTK through 3.8.1 allows remote code execution if untrusted packages have pickled Python code, and the integrated data package download functionality is used. This affects, for example, averaged_perceptron_tagger and punkt.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39705" + }, + { + "type": "WEB", + "url": "https://github.com/nltk/nltk/issues/2522" + }, + { + "type": "WEB", + "url": "https://github.com/nltk/nltk/issues/3266" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-27T22:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-cm55-w5wp-4fgq/GHSA-cm55-w5wp-4fgq.json b/advisories/unreviewed/2024/06/GHSA-cm55-w5wp-4fgq/GHSA-cm55-w5wp-4fgq.json new file mode 100644 index 00000000000..a0cd486c1d3 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-cm55-w5wp-4fgq/GHSA-cm55-w5wp-4fgq.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cm55-w5wp-4fgq", + "modified": "2024-06-28T00:33:31Z", + "published": "2024-06-28T00:33:31Z", + "aliases": [ + "CVE-2024-6071" + ], + "details": "PTC Creo Elements/Direct License Server exposes a web interface which can be used by unauthenticated remote attackers to execute arbitrary OS commands on the server.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6071" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-177-02" + }, + { + "type": "WEB", + "url": "https://www.ptc.com/en/support/article/CS417607" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-27T23:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-ff7q-6vwh-v9m4/GHSA-ff7q-6vwh-v9m4.json b/advisories/unreviewed/2024/06/GHSA-ff7q-6vwh-v9m4/GHSA-ff7q-6vwh-v9m4.json new file mode 100644 index 00000000000..782cab7bd0e --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-ff7q-6vwh-v9m4/GHSA-ff7q-6vwh-v9m4.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ff7q-6vwh-v9m4", + "modified": "2024-06-28T00:33:31Z", + "published": "2024-06-28T00:33:31Z", + "aliases": [ + "CVE-2023-52892" + ], + "details": "In phpseclib before 1.0.22, 2.x before 2.0.46, and 3.x before 3.0.33, some characters in Subject Alternative Name fields in TLS certificates are incorrectly allowed to have a special meaning in regular expressions (such as a + wildcard), leading to name confusion in X.509 certificate host verification.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52892" + }, + { + "type": "WEB", + "url": "https://github.com/phpseclib/phpseclib/issues/1943" + }, + { + "type": "WEB", + "url": "https://github.com/phpseclib/phpseclib/commit/6cd6e8ceab9f2b55c8cd81d2192bf98cbeaf4627" + }, + { + "type": "WEB", + "url": "https://github.com/phpseclib/phpseclib/releases/tag/3.0.33" + }, + { + "type": "WEB", + "url": "https://github.com/x509-name-testing/name_testing_artifacts" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-27T22:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-hrvr-7x5w-xpmq/GHSA-hrvr-7x5w-xpmq.json b/advisories/unreviewed/2024/06/GHSA-hrvr-7x5w-xpmq/GHSA-hrvr-7x5w-xpmq.json index 14bfcbd2878..762721221f7 100644 --- a/advisories/unreviewed/2024/06/GHSA-hrvr-7x5w-xpmq/GHSA-hrvr-7x5w-xpmq.json +++ b/advisories/unreviewed/2024/06/GHSA-hrvr-7x5w-xpmq/GHSA-hrvr-7x5w-xpmq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hrvr-7x5w-xpmq", - "modified": "2024-06-27T21:32:09Z", + "modified": "2024-06-28T00:33:31Z", "published": "2024-06-27T21:32:09Z", "aliases": [ "CVE-2024-5642" @@ -22,9 +22,17 @@ "type": "WEB", "url": "https://github.com/python/cpython/pull/23014" }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/39258d3595300bc7b952854c915f63ae2d4b9c3e" + }, { "type": "WEB", "url": "https://jbp.io/2024/06/27/cve-2024-5535-openssl-memory-safety.html" + }, + { + "type": "WEB", + "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/PLP2JI3PJY33YG6P5BZYSSNU66HASXBQ" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/06/GHSA-vfjj-rqvw-qh77/GHSA-vfjj-rqvw-qh77.json b/advisories/unreviewed/2024/06/GHSA-vfjj-rqvw-qh77/GHSA-vfjj-rqvw-qh77.json new file mode 100644 index 00000000000..9ba67d86757 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-vfjj-rqvw-qh77/GHSA-vfjj-rqvw-qh77.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vfjj-rqvw-qh77", + "modified": "2024-06-28T00:33:31Z", + "published": "2024-06-28T00:33:31Z", + "aliases": [ + "CVE-2016-20022" + ], + "details": "In the Linux kernel before 4.8, usb_parse_endpoint in drivers/usb/core/config.c does not validate the wMaxPacketSize field of an endpoint descriptor. NOTE: This vulnerability only affects products that are no longer supported by the supplier.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2016-20022" + }, + { + "type": "WEB", + "url": "https://github.com/torvalds/linux/commit/aed9d65ac3278d4febd8665bd7db59ef53e825fe" + }, + { + "type": "WEB", + "url": "https://lore.kernel.org/lkml/1486322541-8206-8-git-send-email-w%401wt.eu" + }, + { + "type": "WEB", + "url": "https://www.spinics.net/lists/linux-usb/msg144177.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-27T23:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-xpvm-9wx5-vjpw/GHSA-xpvm-9wx5-vjpw.json b/advisories/unreviewed/2024/06/GHSA-xpvm-9wx5-vjpw/GHSA-xpvm-9wx5-vjpw.json index 8d87c87285c..db9e4c82211 100644 --- a/advisories/unreviewed/2024/06/GHSA-xpvm-9wx5-vjpw/GHSA-xpvm-9wx5-vjpw.json +++ b/advisories/unreviewed/2024/06/GHSA-xpvm-9wx5-vjpw/GHSA-xpvm-9wx5-vjpw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xpvm-9wx5-vjpw", - "modified": "2024-06-07T03:31:04Z", + "modified": "2024-06-28T00:33:30Z", "published": "2024-06-07T03:31:04Z", "aliases": [ "CVE-2022-4968" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-4968" }, + { + "type": "WEB", + "url": "https://github.com/canonical/netplan/commit/4c39b75b5c6ae7d976bda6da68da60d9a7f085ee" + }, { "type": "WEB", "url": "https://bugs.launchpad.net/netplan/+bug/1987842" @@ -36,7 +40,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-497" ], "severity": "MODERATE", "github_reviewed": false,