Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2024-11-25 18:35:44 +00:00
parent c008850279
commit 07cbdaf245
72 changed files with 965 additions and 109 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6cc5-2vg4-cc7m",
"modified": "2024-11-18T22:11:28Z",
"modified": "2024-11-25T18:33:21Z",
"published": "2019-06-10T18:05:06Z",
"aliases": [
"CVE-2019-12387"
@@ -64,6 +64,10 @@
"type": "WEB",
"url": "https://labs.twistedmatrix.com/2019/06/twisted-1921-released.html"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2G5RPDQ4BNB336HL6WW5ZJ344MAWNN7N"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2G5RPDQ4BNB336HL6WW5ZJ344MAWNN7N"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-65rm-h285-5cc5",
"modified": "2024-11-18T22:12:13Z",
"modified": "2024-11-25T18:33:21Z",
"published": "2019-08-16T14:02:35Z",
"aliases": [
"CVE-2019-12855"
@@ -60,6 +60,10 @@
"type": "PACKAGE",
"url": "https://github.com/twisted/twisted"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PLTZDMFBNFSJMBXYJNGJHENJA4H2TSMZ"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PLTZDMFBNFSJMBXYJNGJHENJA4H2TSMZ"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h96w-mmrf-2h6v",
"modified": "2024-11-18T22:30:00Z",
"modified": "2024-11-25T18:33:22Z",
"published": "2020-03-31T15:42:42Z",
"aliases": [
"CVE-2020-10108"
@@ -72,6 +72,14 @@
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2022/02/msg00021.html"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6ISMZFZBWW4EV6ETJGXAYIXN3AT7GBPL"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YW3NIL7VXSGJND2Q4BSXM3CFTAFU6T7D"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6ISMZFZBWW4EV6ETJGXAYIXN3AT7GBPL"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p5xh-vx83-mxcj",
"modified": "2024-11-18T22:24:59Z",
"modified": "2024-11-25T18:33:22Z",
"published": "2020-03-31T15:40:12Z",
"aliases": [
"CVE-2020-10109"
@@ -76,6 +76,14 @@
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2022/02/msg00021.html"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6ISMZFZBWW4EV6ETJGXAYIXN3AT7GBPL"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YW3NIL7VXSGJND2Q4BSXM3CFTAFU6T7D"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6ISMZFZBWW4EV6ETJGXAYIXN3AT7GBPL"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-92x2-jw7w-xvvx",
"modified": "2024-11-18T22:48:32Z",
"modified": "2024-11-25T18:33:22Z",
"published": "2022-02-07T22:36:00Z",
"aliases": [
"CVE-2022-21712"
@@ -68,6 +68,14 @@
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2022/02/msg00021.html"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7U6KYDTOLPICAVSR34G2WRYLFBD2YW5K"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GLKHA6WREIVAMBQD7KKWYHPHGGNKMAG6"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7U6KYDTOLPICAVSR34G2WRYLFBD2YW5K"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rv6r-3f5q-9rgx",
"modified": "2024-11-18T22:50:32Z",
"modified": "2024-11-25T18:33:22Z",
"published": "2022-03-03T19:02:08Z",
"aliases": [
"CVE-2022-21716"
@@ -72,6 +72,14 @@
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2022/03/msg00009.html"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7U6KYDTOLPICAVSR34G2WRYLFBD2YW5K"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GLKHA6WREIVAMBQD7KKWYHPHGGNKMAG6"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7U6KYDTOLPICAVSR34G2WRYLFBD2YW5K"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c2jg-hw38-jrqq",
"modified": "2024-11-18T22:51:19Z",
"modified": "2024-11-25T18:33:24Z",
"published": "2022-04-04T21:29:41Z",
"aliases": [
"CVE-2022-24801"
@@ -68,6 +68,14 @@
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2022/05/msg00003.html"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7U6KYDTOLPICAVSR34G2WRYLFBD2YW5K"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GLKHA6WREIVAMBQD7KKWYHPHGGNKMAG6"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7U6KYDTOLPICAVSR34G2WRYLFBD2YW5K"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-73q3-2843-4j2x",
"modified": "2022-10-24T19:00:17Z",
"modified": "2024-11-25T18:33:22Z",
"published": "2022-05-24T17:46:32Z",
"aliases": [
"CVE-2021-24171"
@@ -28,7 +28,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-287"
"CWE-287",
"CWE-306"
],
"severity": "CRITICAL",
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-46w2-vp86-hhwc",
"modified": "2024-02-15T09:30:36Z",
"modified": "2024-11-25T18:33:23Z",
"published": "2024-02-15T09:30:35Z",
"aliases": [
"CVE-2024-24256"
],
"details": "SQL Injection vulnerability in Yonyou space-time enterprise information integration platform v.9.0 and before allows an attacker to obtain sensitive information via the gwbhAIM parameter in the saveMove.jsp in the hr_position directory.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-15T08:15:46Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-ww2r-4hmc-9mh3",
"modified": "2024-02-21T09:31:01Z",
"modified": "2024-11-25T18:33:23Z",
"published": "2024-02-21T09:31:01Z",
"aliases": [
"CVE-2023-42889"
],
"details": "The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.1, macOS Monterey 12.7.1, macOS Ventura 13.6.1. An app may be able to bypass certain Privacy preferences.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
}
],
"affected": [
@@ -33,9 +36,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-290"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-21T07:15:50Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fpvp-qqmr-38cx",
"modified": "2024-04-05T21:32:42Z",
"modified": "2024-11-25T18:33:23Z",
"published": "2024-04-05T21:32:42Z",
"aliases": [
"CVE-2024-27231"
],
"details": "In tmu_get_tr_stats of tmu.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-125"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-05T20:15:07Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-35xf-7pfr-g5f5",
"modified": "2024-10-07T12:30:43Z",
"modified": "2024-11-25T18:33:24Z",
"published": "2024-05-20T15:31:44Z",
"aliases": [
"CVE-2024-27312"
@@ -32,7 +32,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-121"
"CWE-121",
"CWE-787"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-48w7-3xpj-xq9c",
"modified": "2024-05-14T15:32:54Z",
"modified": "2024-11-25T18:33:24Z",
"published": "2024-05-14T15:32:54Z",
"aliases": [
"CVE-2024-29166"
],
"details": "HDF5 through 1.14.3 contains a buffer overflow in H5O__linfo_decode, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-120"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-14T15:15:33Z"
@@ -32,7 +32,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-121"
"CWE-121",
"CWE-787"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-99hg-9w72-jwwc",
"modified": "2024-05-14T18:30:48Z",
"modified": "2024-11-25T18:33:24Z",
"published": "2024-05-14T18:30:48Z",
"aliases": [
"CVE-2024-33876"
],
"details": "HDF5 Library through 1.14.3 has a heap buffer overflow in H5S__point_deserialize in H5Spoint.c.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-120"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-14T15:38:10Z"
@@ -32,7 +32,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-259"
"CWE-259",
"CWE-798"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gg2x-v7xp-pj7x",
"modified": "2024-05-03T15:30:54Z",
"modified": "2024-11-25T18:33:24Z",
"published": "2024-05-03T15:30:54Z",
"aliases": [
"CVE-2023-6363"
],
"details": "Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to make improper GPU memory processing operations. If the systems memory is carefully prepared by the user, then this in turn could give them access to already freed memory.\nThis issue affects Valhall GPU Kernel Driver: from r41p0 through r47p0; Arm 5th Gen GPU Architecture Kernel Driver: from r41p0 through r47p0.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
}
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
"CWE-416"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-03T14:15:10Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gvjh-r2g7-mjgx",
"modified": "2024-05-07T21:31:46Z",
"modified": "2024-11-25T18:33:24Z",
"published": "2024-05-07T21:31:46Z",
"aliases": [
"CVE-2024-0022"
],
"details": "In multiple functions of CompanionDeviceManagerService.java, there is a possible launch NotificationAccessConfirmationActivity of another user profile due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -31,7 +34,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-07T21:15:08Z"

Some files were not shown because too many files have changed in this diff Show More