diff --git a/advisories/unreviewed/2024/12/GHSA-rp94-8pgp-q8f5/GHSA-rp94-8pgp-q8f5.json b/advisories/unreviewed/2024/12/GHSA-rp94-8pgp-q8f5/GHSA-rp94-8pgp-q8f5.json new file mode 100644 index 00000000000..63778facad7 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-rp94-8pgp-q8f5/GHSA-rp94-8pgp-q8f5.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rp94-8pgp-q8f5", + "modified": "2024-12-15T03:30:42Z", + "published": "2024-12-15T03:30:42Z", + "aliases": [ + "CVE-2024-55970" + ], + "details": "File Manager in Syncfusion Essential Studio for ASP.NET MVC before 27.1.55 has a traversal issue that is related to the request parameter, aka I644734.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55970" + }, + { + "type": "WEB", + "url": "https://ej2.syncfusion.com/aspnetmvc/documentation/release-notes/27.1.55?type=all" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-15T03:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-vwvq-gh67-jhjv/GHSA-vwvq-gh67-jhjv.json b/advisories/unreviewed/2024/12/GHSA-vwvq-gh67-jhjv/GHSA-vwvq-gh67-jhjv.json new file mode 100644 index 00000000000..cf5faf6a19d --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-vwvq-gh67-jhjv/GHSA-vwvq-gh67-jhjv.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vwvq-gh67-jhjv", + "modified": "2024-12-15T03:30:42Z", + "published": "2024-12-15T03:30:42Z", + "aliases": [ + "CVE-2024-56073" + ], + "details": "An issue was discovered in FastNetMon Community Edition through 1.2.7. Zero-length templates for Netflow v9 allow remote attackers to cause a denial of service (divide-by-zero error and application crash).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56073" + }, + { + "type": "WEB", + "url": "https://github.com/pavel-odintsov/fastnetmon/commit/a36718525e08ad0f2a809363001bf105efc5fe1c" + }, + { + "type": "WEB", + "url": "https://cwe.mitre.org/data/definitions/369.html" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-15T03:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-x89m-rvq3-8g32/GHSA-x89m-rvq3-8g32.json b/advisories/unreviewed/2024/12/GHSA-x89m-rvq3-8g32/GHSA-x89m-rvq3-8g32.json new file mode 100644 index 00000000000..f2380fea916 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-x89m-rvq3-8g32/GHSA-x89m-rvq3-8g32.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x89m-rvq3-8g32", + "modified": "2024-12-15T03:30:42Z", + "published": "2024-12-15T03:30:42Z", + "aliases": [ + "CVE-2024-56072" + ], + "details": "An issue was discovered in FastNetMon Community Edition through 1.2.7. The sFlow v5 plugin allows remote attackers to cause a denial of service (application crash) via a crafted packet that specifies many sFlow samples.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56072" + }, + { + "type": "WEB", + "url": "https://github.com/pavel-odintsov/fastnetmon/commit/5164a29603fff9dd445b7660a35090989f005000" + }, + { + "type": "WEB", + "url": "https://github.com/pavel-odintsov/fastnetmon/commit/65c40ee92dd5bcad1ab52cbafa1afd62cf669e48" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-15T03:15:16Z" + } +} \ No newline at end of file