From 090c9ee5a527f0bddef17914436e7ab877820ebb Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 31 May 2024 20:41:43 +0000 Subject: [PATCH] Publish Advisories GHSA-cwp9-956f-vcwh GHSA-53v4-42fg-g287 --- .../2021/03/GHSA-cwp9-956f-vcwh/GHSA-cwp9-956f-vcwh.json | 4 ++-- .../2023/11/GHSA-53v4-42fg-g287/GHSA-53v4-42fg-g287.json | 7 ++++++- 2 files changed, 8 insertions(+), 3 deletions(-) diff --git a/advisories/github-reviewed/2021/03/GHSA-cwp9-956f-vcwh/GHSA-cwp9-956f-vcwh.json b/advisories/github-reviewed/2021/03/GHSA-cwp9-956f-vcwh/GHSA-cwp9-956f-vcwh.json index 251d7a3a99a..eaff306f852 100644 --- a/advisories/github-reviewed/2021/03/GHSA-cwp9-956f-vcwh/GHSA-cwp9-956f-vcwh.json +++ b/advisories/github-reviewed/2021/03/GHSA-cwp9-956f-vcwh/GHSA-cwp9-956f-vcwh.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-cwp9-956f-vcwh", - "modified": "2021-03-22T22:56:04Z", + "modified": "2024-05-31T20:40:02Z", "published": "2021-03-29T20:57:56Z", "aliases": [ "CVE-2019-1141" ], - "summary": "Out-of-bounds write", + "summary": "Out-of-bounds write in Microsoft.ChakraCore", "details": "A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1131, CVE-2019-1139, CVE-2019-1140, CVE-2019-1195, CVE-2019-1196, CVE-2019-1197.", "severity": [ { diff --git a/advisories/github-reviewed/2023/11/GHSA-53v4-42fg-g287/GHSA-53v4-42fg-g287.json b/advisories/github-reviewed/2023/11/GHSA-53v4-42fg-g287/GHSA-53v4-42fg-g287.json index eb36b9a33d3..bfa0b376c12 100644 --- a/advisories/github-reviewed/2023/11/GHSA-53v4-42fg-g287/GHSA-53v4-42fg-g287.json +++ b/advisories/github-reviewed/2023/11/GHSA-53v4-42fg-g287/GHSA-53v4-42fg-g287.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-53v4-42fg-g287", - "modified": "2024-03-14T21:30:03Z", + "modified": "2024-05-31T20:40:33Z", "published": "2023-11-28T18:30:23Z", "aliases": [ "CVE-2022-41678" @@ -95,6 +95,10 @@ "type": "WEB", "url": "https://security.netapp.com/advisory/ntap-20240216-0004" }, + { + "type": "WEB", + "url": "https://www.openwall.com/lists/oss-security/2023/11/28/1" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2023/11/28/1" @@ -102,6 +106,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-287", "CWE-502" ], "severity": "HIGH",