diff --git a/advisories/unreviewed/2024/03/GHSA-33qh-fj99-2gvg/GHSA-33qh-fj99-2gvg.json b/advisories/unreviewed/2024/03/GHSA-33qh-fj99-2gvg/GHSA-33qh-fj99-2gvg.json index 4dd1806e6ab..808534d1932 100644 --- a/advisories/unreviewed/2024/03/GHSA-33qh-fj99-2gvg/GHSA-33qh-fj99-2gvg.json +++ b/advisories/unreviewed/2024/03/GHSA-33qh-fj99-2gvg/GHSA-33qh-fj99-2gvg.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-287" + "CWE-287", + "CWE-306" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-7537-7q22-h2h7/GHSA-7537-7q22-h2h7.json b/advisories/unreviewed/2024/03/GHSA-7537-7q22-h2h7/GHSA-7537-7q22-h2h7.json index ccf51e63a40..0833c5ccbba 100644 --- a/advisories/unreviewed/2024/03/GHSA-7537-7q22-h2h7/GHSA-7537-7q22-h2h7.json +++ b/advisories/unreviewed/2024/03/GHSA-7537-7q22-h2h7/GHSA-7537-7q22-h2h7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7537-7q22-h2h7", - "modified": "2024-03-13T21:31:02Z", + "modified": "2024-12-13T18:31:54Z", "published": "2024-03-08T03:31:25Z", "aliases": [ "CVE-2024-23259" ], "details": "The issue was addressed with improved checks. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4. Processing web content may lead to a denial-of-service.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -33,7 +38,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-08T02:15:48Z" diff --git a/advisories/unreviewed/2024/03/GHSA-m6gm-m2m7-vwxg/GHSA-m6gm-m2m7-vwxg.json b/advisories/unreviewed/2024/03/GHSA-m6gm-m2m7-vwxg/GHSA-m6gm-m2m7-vwxg.json index 803fb881ec9..aeeea3617b9 100644 --- a/advisories/unreviewed/2024/03/GHSA-m6gm-m2m7-vwxg/GHSA-m6gm-m2m7-vwxg.json +++ b/advisories/unreviewed/2024/03/GHSA-m6gm-m2m7-vwxg/GHSA-m6gm-m2m7-vwxg.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-qqc8-rv37-79q5/GHSA-qqc8-rv37-79q5.json b/advisories/unreviewed/2024/03/GHSA-qqc8-rv37-79q5/GHSA-qqc8-rv37-79q5.json index c573427543e..dc65a63f6a7 100644 --- a/advisories/unreviewed/2024/03/GHSA-qqc8-rv37-79q5/GHSA-qqc8-rv37-79q5.json +++ b/advisories/unreviewed/2024/03/GHSA-qqc8-rv37-79q5/GHSA-qqc8-rv37-79q5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qqc8-rv37-79q5", - "modified": "2024-03-15T09:30:37Z", + "modified": "2024-12-13T18:31:55Z", "published": "2024-03-15T09:30:37Z", "aliases": [ "CVE-2024-28053" @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-400" + "CWE-400", + "CWE-770" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-x6jw-w885-qwpc/GHSA-x6jw-w885-qwpc.json b/advisories/unreviewed/2024/03/GHSA-x6jw-w885-qwpc/GHSA-x6jw-w885-qwpc.json index b87d2d3dffc..82e6669ff3f 100644 --- a/advisories/unreviewed/2024/03/GHSA-x6jw-w885-qwpc/GHSA-x6jw-w885-qwpc.json +++ b/advisories/unreviewed/2024/03/GHSA-x6jw-w885-qwpc/GHSA-x6jw-w885-qwpc.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-400" + "CWE-400", + "CWE-770" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-w2rm-x498-v7f9/GHSA-w2rm-x498-v7f9.json b/advisories/unreviewed/2024/05/GHSA-w2rm-x498-v7f9/GHSA-w2rm-x498-v7f9.json index 6ea9acb8967..c3a6cbd79fb 100644 --- a/advisories/unreviewed/2024/05/GHSA-w2rm-x498-v7f9/GHSA-w2rm-x498-v7f9.json +++ b/advisories/unreviewed/2024/05/GHSA-w2rm-x498-v7f9/GHSA-w2rm-x498-v7f9.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-639" + "CWE-639", + "CWE-863" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-9x5q-pwr2-hwvp/GHSA-9x5q-pwr2-hwvp.json b/advisories/unreviewed/2024/06/GHSA-9x5q-pwr2-hwvp/GHSA-9x5q-pwr2-hwvp.json index 482e2070bdc..248e14daa7a 100644 --- a/advisories/unreviewed/2024/06/GHSA-9x5q-pwr2-hwvp/GHSA-9x5q-pwr2-hwvp.json +++ b/advisories/unreviewed/2024/06/GHSA-9x5q-pwr2-hwvp/GHSA-9x5q-pwr2-hwvp.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-347" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/08/GHSA-7ph6-ch7r-f425/GHSA-7ph6-ch7r-f425.json b/advisories/unreviewed/2024/08/GHSA-7ph6-ch7r-f425/GHSA-7ph6-ch7r-f425.json index 39bd18ff3f1..75e41c20643 100644 --- a/advisories/unreviewed/2024/08/GHSA-7ph6-ch7r-f425/GHSA-7ph6-ch7r-f425.json +++ b/advisories/unreviewed/2024/08/GHSA-7ph6-ch7r-f425/GHSA-7ph6-ch7r-f425.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-918" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/08/GHSA-9c64-9pw3-wh7p/GHSA-9c64-9pw3-wh7p.json b/advisories/unreviewed/2024/08/GHSA-9c64-9pw3-wh7p/GHSA-9c64-9pw3-wh7p.json index e56ecaf91f3..7c5395c30c2 100644 --- a/advisories/unreviewed/2024/08/GHSA-9c64-9pw3-wh7p/GHSA-9c64-9pw3-wh7p.json +++ b/advisories/unreviewed/2024/08/GHSA-9c64-9pw3-wh7p/GHSA-9c64-9pw3-wh7p.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-284" + "CWE-284", + "CWE-863" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-c87h-375h-xrrv/GHSA-c87h-375h-xrrv.json b/advisories/unreviewed/2024/08/GHSA-c87h-375h-xrrv/GHSA-c87h-375h-xrrv.json index 8b6c0192916..f71f245a9db 100644 --- a/advisories/unreviewed/2024/08/GHSA-c87h-375h-xrrv/GHSA-c87h-375h-xrrv.json +++ b/advisories/unreviewed/2024/08/GHSA-c87h-375h-xrrv/GHSA-c87h-375h-xrrv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c87h-375h-xrrv", - "modified": "2024-08-14T03:31:07Z", + "modified": "2024-12-13T18:31:55Z", "published": "2024-08-13T18:31:15Z", "aliases": [ "CVE-2023-31341" diff --git a/advisories/unreviewed/2024/12/GHSA-224h-vf26-wvfw/GHSA-224h-vf26-wvfw.json b/advisories/unreviewed/2024/12/GHSA-224h-vf26-wvfw/GHSA-224h-vf26-wvfw.json index 606448277e1..3a3ba6030ee 100644 --- a/advisories/unreviewed/2024/12/GHSA-224h-vf26-wvfw/GHSA-224h-vf26-wvfw.json +++ b/advisories/unreviewed/2024/12/GHSA-224h-vf26-wvfw/GHSA-224h-vf26-wvfw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-224h-vf26-wvfw", - "modified": "2024-12-12T15:31:08Z", + "modified": "2024-12-13T18:31:56Z", "published": "2024-12-12T15:31:08Z", "aliases": [ "CVE-2024-28143" ], "details": "The password change function at /cgi/admin.cgi does not require the current/old password, which makes the application vulnerable to account takeover. An attacker can use this to forcefully set a new password within the -rsetpass+-aaction+- parameter for a user without knowing the old password, e.g. by exploiting a CSRF issue.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -27,7 +32,7 @@ "cwe_ids": [ "CWE-620" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-12T14:15:22Z" diff --git a/advisories/unreviewed/2024/12/GHSA-23x3-68r3-3j2p/GHSA-23x3-68r3-3j2p.json b/advisories/unreviewed/2024/12/GHSA-23x3-68r3-3j2p/GHSA-23x3-68r3-3j2p.json index 9c15e231755..47d22d2fbb4 100644 --- a/advisories/unreviewed/2024/12/GHSA-23x3-68r3-3j2p/GHSA-23x3-68r3-3j2p.json +++ b/advisories/unreviewed/2024/12/GHSA-23x3-68r3-3j2p/GHSA-23x3-68r3-3j2p.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-23x3-68r3-3j2p", - "modified": "2024-12-04T15:31:52Z", + "modified": "2024-12-13T18:31:55Z", "published": "2024-12-04T15:31:52Z", "aliases": [ "CVE-2024-53128" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsched/task_stack: fix object_is_on_stack() for KASAN tagged pointers\n\nWhen CONFIG_KASAN_SW_TAGS and CONFIG_KASAN_STACK are enabled, the\nobject_is_on_stack() function may produce incorrect results due to the\npresence of tags in the obj pointer, while the stack pointer does not have\ntags. This discrepancy can lead to incorrect stack object detection and\nsubsequently trigger warnings if CONFIG_DEBUG_OBJECTS is also enabled.\n\nExample of the warning:\n\nODEBUG: object 3eff800082ea7bb0 is NOT on stack ffff800082ea0000, but annotated.\n------------[ cut here ]------------\nWARNING: CPU: 0 PID: 1 at lib/debugobjects.c:557 __debug_object_init+0x330/0x364\nModules linked in:\nCPU: 0 UID: 0 PID: 1 Comm: swapper/0 Not tainted 6.12.0-rc5 #4\nHardware name: linux,dummy-virt (DT)\npstate: 600000c5 (nZCv daIF -PAN -UAO -TCO -DIT -SSBS BTYPE=--)\npc : __debug_object_init+0x330/0x364\nlr : __debug_object_init+0x330/0x364\nsp : ffff800082ea7b40\nx29: ffff800082ea7b40 x28: 98ff0000c0164518 x27: 98ff0000c0164534\nx26: ffff800082d93ec8 x25: 0000000000000001 x24: 1cff0000c00172a0\nx23: 0000000000000000 x22: ffff800082d93ed0 x21: ffff800081a24418\nx20: 3eff800082ea7bb0 x19: efff800000000000 x18: 0000000000000000\nx17: 00000000000000ff x16: 0000000000000047 x15: 206b63617473206e\nx14: 0000000000000018 x13: ffff800082ea7780 x12: 0ffff800082ea78e\nx11: 0ffff800082ea790 x10: 0ffff800082ea79d x9 : 34d77febe173e800\nx8 : 34d77febe173e800 x7 : 0000000000000001 x6 : 0000000000000001\nx5 : feff800082ea74b8 x4 : ffff800082870a90 x3 : ffff80008018d3c4\nx2 : 0000000000000001 x1 : ffff800082858810 x0 : 0000000000000050\nCall trace:\n __debug_object_init+0x330/0x364\n debug_object_init_on_stack+0x30/0x3c\n schedule_hrtimeout_range_clock+0xac/0x26c\n schedule_hrtimeout+0x1c/0x30\n wait_task_inactive+0x1d4/0x25c\n kthread_bind_mask+0x28/0x98\n init_rescuer+0x1e8/0x280\n workqueue_init+0x1a0/0x3cc\n kernel_init_freeable+0x118/0x200\n kernel_init+0x28/0x1f0\n ret_from_fork+0x10/0x20\n---[ end trace 0000000000000000 ]---\nODEBUG: object 3eff800082ea7bb0 is NOT on stack ffff800082ea0000, but annotated.\n------------[ cut here ]------------", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -25,7 +30,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-04T15:15:12Z" diff --git a/advisories/unreviewed/2024/12/GHSA-2j3v-9566-775v/GHSA-2j3v-9566-775v.json b/advisories/unreviewed/2024/12/GHSA-2j3v-9566-775v/GHSA-2j3v-9566-775v.json index 26b96c1cc6e..d1b33be4b1a 100644 --- a/advisories/unreviewed/2024/12/GHSA-2j3v-9566-775v/GHSA-2j3v-9566-775v.json +++ b/advisories/unreviewed/2024/12/GHSA-2j3v-9566-775v/GHSA-2j3v-9566-775v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2j3v-9566-775v", - "modified": "2024-12-12T21:30:47Z", + "modified": "2024-12-13T18:31:56Z", "published": "2024-12-12T21:30:47Z", "aliases": [ "CVE-2024-54811" ], "details": "A SQL injection vulnerability in /index.php in PHPGurukul Park Ticketing Management System v1.0 allows an attacker to execute arbitrary SQL commands via the \"login\" parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-12T19:15:13Z" diff --git a/advisories/unreviewed/2024/12/GHSA-3gr3-rr4m-976p/GHSA-3gr3-rr4m-976p.json b/advisories/unreviewed/2024/12/GHSA-3gr3-rr4m-976p/GHSA-3gr3-rr4m-976p.json new file mode 100644 index 00000000000..551bc587e3a --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-3gr3-rr4m-976p/GHSA-3gr3-rr4m-976p.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3gr3-rr4m-976p", + "modified": "2024-12-13T18:31:56Z", + "published": "2024-12-13T18:31:56Z", + "aliases": [ + "CVE-2024-46971" + ], + "details": "Software installed and run as a non-privileged user may conduct GPU system calls to read and write freed physical memory from the GPU.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46971" + }, + { + "type": "WEB", + "url": "https://www.imaginationtech.com/gpu-driver-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-362" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T18:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-3m98-m7jj-v78v/GHSA-3m98-m7jj-v78v.json b/advisories/unreviewed/2024/12/GHSA-3m98-m7jj-v78v/GHSA-3m98-m7jj-v78v.json index e56c8150b90..1fe5742fe93 100644 --- a/advisories/unreviewed/2024/12/GHSA-3m98-m7jj-v78v/GHSA-3m98-m7jj-v78v.json +++ b/advisories/unreviewed/2024/12/GHSA-3m98-m7jj-v78v/GHSA-3m98-m7jj-v78v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3m98-m7jj-v78v", - "modified": "2024-12-12T03:33:06Z", + "modified": "2024-12-13T18:31:55Z", "published": "2024-12-12T03:33:06Z", "aliases": [ "CVE-2024-54489" ], "details": "A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.2, macOS Ventura 13.7.2, macOS Sonoma 14.7.2. Running a mount command may unexpectedly execute arbitrary code.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -29,7 +34,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-12T02:15:30Z" diff --git a/advisories/unreviewed/2024/12/GHSA-4m3c-vp5f-8qxg/GHSA-4m3c-vp5f-8qxg.json b/advisories/unreviewed/2024/12/GHSA-4m3c-vp5f-8qxg/GHSA-4m3c-vp5f-8qxg.json index f5f08d5b714..bce468dde41 100644 --- a/advisories/unreviewed/2024/12/GHSA-4m3c-vp5f-8qxg/GHSA-4m3c-vp5f-8qxg.json +++ b/advisories/unreviewed/2024/12/GHSA-4m3c-vp5f-8qxg/GHSA-4m3c-vp5f-8qxg.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-58f5-8jq5-r8p2/GHSA-58f5-8jq5-r8p2.json b/advisories/unreviewed/2024/12/GHSA-58f5-8jq5-r8p2/GHSA-58f5-8jq5-r8p2.json index de9ac02a685..482224a6e9d 100644 --- a/advisories/unreviewed/2024/12/GHSA-58f5-8jq5-r8p2/GHSA-58f5-8jq5-r8p2.json +++ b/advisories/unreviewed/2024/12/GHSA-58f5-8jq5-r8p2/GHSA-58f5-8jq5-r8p2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-58f5-8jq5-r8p2", - "modified": "2024-12-12T03:33:06Z", + "modified": "2024-12-13T18:31:55Z", "published": "2024-12-12T03:33:06Z", "aliases": [ "CVE-2024-54510" ], "details": "A race condition was addressed with improved locking. This issue is fixed in iPadOS 17.7.3, watchOS 11.2, tvOS 18.2, macOS Sequoia 15.2, iOS 18.2 and iPadOS 18.2, macOS Ventura 13.7.2, macOS Sonoma 14.7.2. An app may be able to leak sensitive kernel state.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-362" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-12T02:15:31Z" diff --git a/advisories/unreviewed/2024/12/GHSA-5hph-wf32-7rmr/GHSA-5hph-wf32-7rmr.json b/advisories/unreviewed/2024/12/GHSA-5hph-wf32-7rmr/GHSA-5hph-wf32-7rmr.json index 3c712fca4a7..e9c8d3eab18 100644 --- a/advisories/unreviewed/2024/12/GHSA-5hph-wf32-7rmr/GHSA-5hph-wf32-7rmr.json +++ b/advisories/unreviewed/2024/12/GHSA-5hph-wf32-7rmr/GHSA-5hph-wf32-7rmr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5hph-wf32-7rmr", - "modified": "2024-12-12T21:30:46Z", + "modified": "2024-12-13T18:31:55Z", "published": "2024-12-11T00:31:27Z", "aliases": [ "CVE-2024-52865" diff --git a/advisories/unreviewed/2024/12/GHSA-5mvv-6ghv-vm4v/GHSA-5mvv-6ghv-vm4v.json b/advisories/unreviewed/2024/12/GHSA-5mvv-6ghv-vm4v/GHSA-5mvv-6ghv-vm4v.json index 79208c9fb39..b3c679cfb5e 100644 --- a/advisories/unreviewed/2024/12/GHSA-5mvv-6ghv-vm4v/GHSA-5mvv-6ghv-vm4v.json +++ b/advisories/unreviewed/2024/12/GHSA-5mvv-6ghv-vm4v/GHSA-5mvv-6ghv-vm4v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5mvv-6ghv-vm4v", - "modified": "2024-12-12T18:30:55Z", + "modified": "2024-12-13T18:31:56Z", "published": "2024-12-12T18:30:55Z", "aliases": [ "CVE-2024-54810" ], "details": "A SQL Injection vulnerability was found in /preschool/admin/password-recovery.php in PHPGurukul Pre-School Enrollment System Project v1.0, which allows remote attackers to execute arbitrary code via the mobileno parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-12T18:15:25Z" diff --git a/advisories/unreviewed/2024/12/GHSA-5xh8-mfhp-x7wc/GHSA-5xh8-mfhp-x7wc.json b/advisories/unreviewed/2024/12/GHSA-5xh8-mfhp-x7wc/GHSA-5xh8-mfhp-x7wc.json index d07ee2b7dd0..f941281f0ed 100644 --- a/advisories/unreviewed/2024/12/GHSA-5xh8-mfhp-x7wc/GHSA-5xh8-mfhp-x7wc.json +++ b/advisories/unreviewed/2024/12/GHSA-5xh8-mfhp-x7wc/GHSA-5xh8-mfhp-x7wc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5xh8-mfhp-x7wc", - "modified": "2024-12-11T18:30:42Z", + "modified": "2024-12-13T18:31:55Z", "published": "2024-12-10T18:31:07Z", "aliases": [ "CVE-2024-45493" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://us.msasafety.com/fieldserver" }, + { + "type": "WEB", + "url": "https://us.msasafety.com/security-notices" + }, { "type": "WEB", "url": "https://us.msasafety.com/security-notices:" diff --git a/advisories/unreviewed/2024/12/GHSA-622c-pfxh-44wx/GHSA-622c-pfxh-44wx.json b/advisories/unreviewed/2024/12/GHSA-622c-pfxh-44wx/GHSA-622c-pfxh-44wx.json index b8b7aa2197b..458beda8cea 100644 --- a/advisories/unreviewed/2024/12/GHSA-622c-pfxh-44wx/GHSA-622c-pfxh-44wx.json +++ b/advisories/unreviewed/2024/12/GHSA-622c-pfxh-44wx/GHSA-622c-pfxh-44wx.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-67x6-x9j4-cm73/GHSA-67x6-x9j4-cm73.json b/advisories/unreviewed/2024/12/GHSA-67x6-x9j4-cm73/GHSA-67x6-x9j4-cm73.json index 3fc5c03da5c..45520a670f1 100644 --- a/advisories/unreviewed/2024/12/GHSA-67x6-x9j4-cm73/GHSA-67x6-x9j4-cm73.json +++ b/advisories/unreviewed/2024/12/GHSA-67x6-x9j4-cm73/GHSA-67x6-x9j4-cm73.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-7r2p-cp9x-c68f/GHSA-7r2p-cp9x-c68f.json b/advisories/unreviewed/2024/12/GHSA-7r2p-cp9x-c68f/GHSA-7r2p-cp9x-c68f.json index 3bd4e08aa0f..1fca336ad55 100644 --- a/advisories/unreviewed/2024/12/GHSA-7r2p-cp9x-c68f/GHSA-7r2p-cp9x-c68f.json +++ b/advisories/unreviewed/2024/12/GHSA-7r2p-cp9x-c68f/GHSA-7r2p-cp9x-c68f.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7r2p-cp9x-c68f", - "modified": "2024-12-12T03:33:06Z", + "modified": "2024-12-13T18:31:55Z", "published": "2024-12-12T03:33:06Z", "aliases": [ "CVE-2024-54506" ], "details": "An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.2. An attacker may be able to cause unexpected system termination or arbitrary code execution in DCP firmware.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-12T02:15:31Z" diff --git a/advisories/unreviewed/2024/12/GHSA-7wvc-54wp-pv8x/GHSA-7wvc-54wp-pv8x.json b/advisories/unreviewed/2024/12/GHSA-7wvc-54wp-pv8x/GHSA-7wvc-54wp-pv8x.json index 8e3c7ff693b..8c8c6d6d044 100644 --- a/advisories/unreviewed/2024/12/GHSA-7wvc-54wp-pv8x/GHSA-7wvc-54wp-pv8x.json +++ b/advisories/unreviewed/2024/12/GHSA-7wvc-54wp-pv8x/GHSA-7wvc-54wp-pv8x.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7wvc-54wp-pv8x", - "modified": "2024-12-12T03:33:06Z", + "modified": "2024-12-13T18:31:55Z", "published": "2024-12-12T03:33:06Z", "aliases": [ "CVE-2024-54477" ], "details": "The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2, macOS Ventura 13.7.2, macOS Sonoma 14.7.2. An app may be able to access user-sensitive data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -29,7 +34,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-12T02:15:29Z" diff --git a/advisories/unreviewed/2024/12/GHSA-83g6-wm8c-3hx9/GHSA-83g6-wm8c-3hx9.json b/advisories/unreviewed/2024/12/GHSA-83g6-wm8c-3hx9/GHSA-83g6-wm8c-3hx9.json index e9fe7e56eb0..a0985fb1f31 100644 --- a/advisories/unreviewed/2024/12/GHSA-83g6-wm8c-3hx9/GHSA-83g6-wm8c-3hx9.json +++ b/advisories/unreviewed/2024/12/GHSA-83g6-wm8c-3hx9/GHSA-83g6-wm8c-3hx9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-83g6-wm8c-3hx9", - "modified": "2024-12-12T03:33:07Z", + "modified": "2024-12-13T18:31:56Z", "published": "2024-12-12T03:33:07Z", "aliases": [ "CVE-2024-54534" ], "details": "The issue was addressed with improved memory handling. This issue is fixed in watchOS 11.2, visionOS 2.2, tvOS 18.2, macOS Sequoia 15.2, Safari 18.2, iOS 18.2 and iPadOS 18.2. Processing maliciously crafted web content may lead to memory corruption.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -40,8 +45,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-12T02:15:32Z" diff --git a/advisories/unreviewed/2024/12/GHSA-84p4-9xrj-9rj5/GHSA-84p4-9xrj-9rj5.json b/advisories/unreviewed/2024/12/GHSA-84p4-9xrj-9rj5/GHSA-84p4-9xrj-9rj5.json index 031498af258..bd7ed93a7b2 100644 --- a/advisories/unreviewed/2024/12/GHSA-84p4-9xrj-9rj5/GHSA-84p4-9xrj-9rj5.json +++ b/advisories/unreviewed/2024/12/GHSA-84p4-9xrj-9rj5/GHSA-84p4-9xrj-9rj5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-84p4-9xrj-9rj5", - "modified": "2024-12-12T15:31:08Z", + "modified": "2024-12-13T18:31:56Z", "published": "2024-12-12T15:31:08Z", "aliases": [ "CVE-2024-28146" ], "details": "The application uses several hard-coded credentials to encrypt config files during backup, to decrypt the new firmware during an update and some passwords allow a direct connection to the database server of the affected device.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -27,7 +32,7 @@ "cwe_ids": [ "CWE-798" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-12T14:15:22Z" diff --git a/advisories/unreviewed/2024/12/GHSA-97qm-2h4w-qghq/GHSA-97qm-2h4w-qghq.json b/advisories/unreviewed/2024/12/GHSA-97qm-2h4w-qghq/GHSA-97qm-2h4w-qghq.json index 4cde9a234ce..feee048f3f9 100644 --- a/advisories/unreviewed/2024/12/GHSA-97qm-2h4w-qghq/GHSA-97qm-2h4w-qghq.json +++ b/advisories/unreviewed/2024/12/GHSA-97qm-2h4w-qghq/GHSA-97qm-2h4w-qghq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-97qm-2h4w-qghq", - "modified": "2024-12-12T03:33:06Z", + "modified": "2024-12-13T18:31:55Z", "published": "2024-12-12T03:33:06Z", "aliases": [ "CVE-2024-54484" ], "details": "The issue was resolved by sanitizing logging. This issue is fixed in macOS Sequoia 15.2. An app may be able to access user-sensitive data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-532" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-12T02:15:29Z" diff --git a/advisories/unreviewed/2024/12/GHSA-9q4q-76jj-4j8x/GHSA-9q4q-76jj-4j8x.json b/advisories/unreviewed/2024/12/GHSA-9q4q-76jj-4j8x/GHSA-9q4q-76jj-4j8x.json index 289d0c7209d..8e783b61b41 100644 --- a/advisories/unreviewed/2024/12/GHSA-9q4q-76jj-4j8x/GHSA-9q4q-76jj-4j8x.json +++ b/advisories/unreviewed/2024/12/GHSA-9q4q-76jj-4j8x/GHSA-9q4q-76jj-4j8x.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-9rxr-xfqc-4rq9/GHSA-9rxr-xfqc-4rq9.json b/advisories/unreviewed/2024/12/GHSA-9rxr-xfqc-4rq9/GHSA-9rxr-xfqc-4rq9.json index 382a91ca9e9..29598a4b7ce 100644 --- a/advisories/unreviewed/2024/12/GHSA-9rxr-xfqc-4rq9/GHSA-9rxr-xfqc-4rq9.json +++ b/advisories/unreviewed/2024/12/GHSA-9rxr-xfqc-4rq9/GHSA-9rxr-xfqc-4rq9.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-9vvg-xcxp-m6v9/GHSA-9vvg-xcxp-m6v9.json b/advisories/unreviewed/2024/12/GHSA-9vvg-xcxp-m6v9/GHSA-9vvg-xcxp-m6v9.json index a112a686f3f..42f7e9fbc6d 100644 --- a/advisories/unreviewed/2024/12/GHSA-9vvg-xcxp-m6v9/GHSA-9vvg-xcxp-m6v9.json +++ b/advisories/unreviewed/2024/12/GHSA-9vvg-xcxp-m6v9/GHSA-9vvg-xcxp-m6v9.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-c3f2-9wv2-2gxf/GHSA-c3f2-9wv2-2gxf.json b/advisories/unreviewed/2024/12/GHSA-c3f2-9wv2-2gxf/GHSA-c3f2-9wv2-2gxf.json index abbda805ae0..6f8cd509d07 100644 --- a/advisories/unreviewed/2024/12/GHSA-c3f2-9wv2-2gxf/GHSA-c3f2-9wv2-2gxf.json +++ b/advisories/unreviewed/2024/12/GHSA-c3f2-9wv2-2gxf/GHSA-c3f2-9wv2-2gxf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c3f2-9wv2-2gxf", - "modified": "2024-12-12T03:33:07Z", + "modified": "2024-12-13T18:31:56Z", "published": "2024-12-12T03:33:07Z", "aliases": [ "CVE-2024-54526" ], "details": "The issue was addressed with improved checks. This issue is fixed in watchOS 11.2, tvOS 18.2, macOS Sequoia 15.2, iOS 18.2 and iPadOS 18.2, macOS Ventura 13.7.2, macOS Sonoma 14.7.2. A malicious app may be able to access private information.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -41,7 +46,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-12T02:15:31Z" diff --git a/advisories/unreviewed/2024/12/GHSA-c9p4-fh3x-2qfc/GHSA-c9p4-fh3x-2qfc.json b/advisories/unreviewed/2024/12/GHSA-c9p4-fh3x-2qfc/GHSA-c9p4-fh3x-2qfc.json new file mode 100644 index 00000000000..e66cea26a7b --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-c9p4-fh3x-2qfc/GHSA-c9p4-fh3x-2qfc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c9p4-fh3x-2qfc", + "modified": "2024-12-13T18:31:56Z", + "published": "2024-12-13T18:31:56Z", + "aliases": [ + "CVE-2024-9945" + ], + "details": "An information-disclosure vulnerability exists in Fortra's GoAnywhere MFT application prior to version 7.7.0 that allows external access to the resources in certain admin root folders.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9945" + }, + { + "type": "WEB", + "url": "https://www.fortra.com/security/advisories/product-security/fi-2024-014" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T16:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-cvmq-g63x-rjjh/GHSA-cvmq-g63x-rjjh.json b/advisories/unreviewed/2024/12/GHSA-cvmq-g63x-rjjh/GHSA-cvmq-g63x-rjjh.json index 7d5861dd8b7..b80853192c7 100644 --- a/advisories/unreviewed/2024/12/GHSA-cvmq-g63x-rjjh/GHSA-cvmq-g63x-rjjh.json +++ b/advisories/unreviewed/2024/12/GHSA-cvmq-g63x-rjjh/GHSA-cvmq-g63x-rjjh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cvmq-g63x-rjjh", - "modified": "2024-12-12T18:30:55Z", + "modified": "2024-12-13T18:31:56Z", "published": "2024-12-12T18:30:55Z", "aliases": [ "CVE-2024-31670" ], "details": "rizin before v0.6.3 is vulnerable to Buffer Overflow via create_cache_bins, read_cache_accel, and rz_dyldcache_new_buf functions in librz/bin/format/mach0/dyldcache.c.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-12T18:15:23Z" diff --git a/advisories/unreviewed/2024/12/GHSA-f482-9qmq-phw9/GHSA-f482-9qmq-phw9.json b/advisories/unreviewed/2024/12/GHSA-f482-9qmq-phw9/GHSA-f482-9qmq-phw9.json index fe15929f12c..fd55c06d78e 100644 --- a/advisories/unreviewed/2024/12/GHSA-f482-9qmq-phw9/GHSA-f482-9qmq-phw9.json +++ b/advisories/unreviewed/2024/12/GHSA-f482-9qmq-phw9/GHSA-f482-9qmq-phw9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-f482-9qmq-phw9", - "modified": "2024-12-12T03:33:07Z", + "modified": "2024-12-13T18:31:56Z", "published": "2024-12-12T03:33:07Z", "aliases": [ "CVE-2024-54531" ], "details": "The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.2. An app may be able to bypass kASLR.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-12T02:15:32Z" diff --git a/advisories/unreviewed/2024/12/GHSA-hp58-68h4-82p8/GHSA-hp58-68h4-82p8.json b/advisories/unreviewed/2024/12/GHSA-hp58-68h4-82p8/GHSA-hp58-68h4-82p8.json index 8b6c349a337..2035cef8c47 100644 --- a/advisories/unreviewed/2024/12/GHSA-hp58-68h4-82p8/GHSA-hp58-68h4-82p8.json +++ b/advisories/unreviewed/2024/12/GHSA-hp58-68h4-82p8/GHSA-hp58-68h4-82p8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hp58-68h4-82p8", - "modified": "2024-12-12T03:33:06Z", + "modified": "2024-12-13T18:31:55Z", "published": "2024-12-12T03:33:06Z", "aliases": [ "CVE-2024-54479" ], "details": "The issue was addressed with improved checks. This issue is fixed in iPadOS 17.7.3, watchOS 11.2, visionOS 2.2, tvOS 18.2, macOS Sequoia 15.2, Safari 18.2, iOS 18.2 and iPadOS 18.2. Processing maliciously crafted web content may lead to an unexpected process crash.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -45,7 +50,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-12T02:15:29Z" diff --git a/advisories/unreviewed/2024/12/GHSA-hw5x-h98r-cfjc/GHSA-hw5x-h98r-cfjc.json b/advisories/unreviewed/2024/12/GHSA-hw5x-h98r-cfjc/GHSA-hw5x-h98r-cfjc.json index 67d4879f243..f84cdf680aa 100644 --- a/advisories/unreviewed/2024/12/GHSA-hw5x-h98r-cfjc/GHSA-hw5x-h98r-cfjc.json +++ b/advisories/unreviewed/2024/12/GHSA-hw5x-h98r-cfjc/GHSA-hw5x-h98r-cfjc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hw5x-h98r-cfjc", - "modified": "2024-12-12T03:33:06Z", + "modified": "2024-12-13T18:31:55Z", "published": "2024-12-12T03:33:06Z", "aliases": [ "CVE-2024-54493" ], "details": "This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.2. Privacy indicators for microphone access may be attributed incorrectly.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-12T02:15:30Z" diff --git a/advisories/unreviewed/2024/12/GHSA-jqhv-wqfx-p2mf/GHSA-jqhv-wqfx-p2mf.json b/advisories/unreviewed/2024/12/GHSA-jqhv-wqfx-p2mf/GHSA-jqhv-wqfx-p2mf.json index 3538421824c..2227ce194f0 100644 --- a/advisories/unreviewed/2024/12/GHSA-jqhv-wqfx-p2mf/GHSA-jqhv-wqfx-p2mf.json +++ b/advisories/unreviewed/2024/12/GHSA-jqhv-wqfx-p2mf/GHSA-jqhv-wqfx-p2mf.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-pc69-2jfc-f577/GHSA-pc69-2jfc-f577.json b/advisories/unreviewed/2024/12/GHSA-pc69-2jfc-f577/GHSA-pc69-2jfc-f577.json index 60f837e65d3..9a81b63dd21 100644 --- a/advisories/unreviewed/2024/12/GHSA-pc69-2jfc-f577/GHSA-pc69-2jfc-f577.json +++ b/advisories/unreviewed/2024/12/GHSA-pc69-2jfc-f577/GHSA-pc69-2jfc-f577.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pc69-2jfc-f577", - "modified": "2024-12-12T15:31:08Z", + "modified": "2024-12-13T18:31:56Z", "published": "2024-12-12T15:31:08Z", "aliases": [ "CVE-2024-28145" ], "details": "An unauthenticated attacker can perform an SQL injection by accessing the /class/dbconnect.php file and supplying malicious GET parameters. The HTTP GET parameters search, table, field, and value are vulnerable. For example, one SQL injection can be performed on the parameter \"field\" with the UNION keyword.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -27,7 +32,7 @@ "cwe_ids": [ "CWE-89" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-12T14:15:22Z" diff --git a/advisories/unreviewed/2024/12/GHSA-pr2c-m553-hpcv/GHSA-pr2c-m553-hpcv.json b/advisories/unreviewed/2024/12/GHSA-pr2c-m553-hpcv/GHSA-pr2c-m553-hpcv.json index 29c2b334a1f..9b237c10e39 100644 --- a/advisories/unreviewed/2024/12/GHSA-pr2c-m553-hpcv/GHSA-pr2c-m553-hpcv.json +++ b/advisories/unreviewed/2024/12/GHSA-pr2c-m553-hpcv/GHSA-pr2c-m553-hpcv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pr2c-m553-hpcv", - "modified": "2024-12-12T15:31:08Z", + "modified": "2024-12-13T18:31:56Z", "published": "2024-12-12T15:31:08Z", "aliases": [ "CVE-2024-50584" ], "details": "An authenticated attacker with the user/role \"Poweruser\" can perform an SQL injection by accessing the /class/template_io.php file and supplying malicious GET parameters. The \"templates\" parameter is vulnerable against blind boolean-based SQL injection attacks. SQL syntax must be injected into the JSON syntax of the templates parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -27,7 +32,7 @@ "cwe_ids": [ "CWE-89" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-12T14:15:22Z" diff --git a/advisories/unreviewed/2024/12/GHSA-q7qj-rx6w-8pxw/GHSA-q7qj-rx6w-8pxw.json b/advisories/unreviewed/2024/12/GHSA-q7qj-rx6w-8pxw/GHSA-q7qj-rx6w-8pxw.json index 4fcee78abbc..dd94d990387 100644 --- a/advisories/unreviewed/2024/12/GHSA-q7qj-rx6w-8pxw/GHSA-q7qj-rx6w-8pxw.json +++ b/advisories/unreviewed/2024/12/GHSA-q7qj-rx6w-8pxw/GHSA-q7qj-rx6w-8pxw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-q7qj-rx6w-8pxw", - "modified": "2024-12-12T03:33:06Z", + "modified": "2024-12-13T18:31:55Z", "published": "2024-12-12T03:33:06Z", "aliases": [ "CVE-2024-54494" ], "details": "A race condition was addressed with additional validation. This issue is fixed in iPadOS 17.7.3, watchOS 11.2, visionOS 2.2, tvOS 18.2, macOS Sequoia 15.2, iOS 18.2 and iPadOS 18.2, macOS Ventura 13.7.2, macOS Sonoma 14.7.2. An attacker may be able to create a read-only memory mapping that can be written to.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -48,8 +53,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-362" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-12T02:15:30Z" diff --git a/advisories/unreviewed/2024/12/GHSA-q8r8-h2xj-8948/GHSA-q8r8-h2xj-8948.json b/advisories/unreviewed/2024/12/GHSA-q8r8-h2xj-8948/GHSA-q8r8-h2xj-8948.json index f5fe5af2c58..caec1bcbdb9 100644 --- a/advisories/unreviewed/2024/12/GHSA-q8r8-h2xj-8948/GHSA-q8r8-h2xj-8948.json +++ b/advisories/unreviewed/2024/12/GHSA-q8r8-h2xj-8948/GHSA-q8r8-h2xj-8948.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-q8r8-h2xj-8948", - "modified": "2024-12-12T15:31:08Z", + "modified": "2024-12-13T18:31:56Z", "published": "2024-12-12T15:31:08Z", "aliases": [ "CVE-2024-28144" ], "details": "An attacker who can spoof the IP address and the User-Agent of a logged-in user can takeover the session because of flaws in the self-developed session management. If two users access the web interface from the same IP they are logged in as the other user.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -27,7 +32,7 @@ "cwe_ids": [ "CWE-384" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-12T14:15:22Z" diff --git a/advisories/unreviewed/2024/12/GHSA-rf45-5qvx-8pc5/GHSA-rf45-5qvx-8pc5.json b/advisories/unreviewed/2024/12/GHSA-rf45-5qvx-8pc5/GHSA-rf45-5qvx-8pc5.json index e1bcde09506..bfedb3a2569 100644 --- a/advisories/unreviewed/2024/12/GHSA-rf45-5qvx-8pc5/GHSA-rf45-5qvx-8pc5.json +++ b/advisories/unreviewed/2024/12/GHSA-rf45-5qvx-8pc5/GHSA-rf45-5qvx-8pc5.json @@ -42,6 +42,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-22", "CWE-23" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/12/GHSA-rjgf-248v-5jv2/GHSA-rjgf-248v-5jv2.json b/advisories/unreviewed/2024/12/GHSA-rjgf-248v-5jv2/GHSA-rjgf-248v-5jv2.json index 1a4388ee2c2..8823cb731e2 100644 --- a/advisories/unreviewed/2024/12/GHSA-rjgf-248v-5jv2/GHSA-rjgf-248v-5jv2.json +++ b/advisories/unreviewed/2024/12/GHSA-rjgf-248v-5jv2/GHSA-rjgf-248v-5jv2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rjgf-248v-5jv2", - "modified": "2024-12-04T15:31:52Z", + "modified": "2024-12-13T18:31:55Z", "published": "2024-12-04T15:31:52Z", "aliases": [ "CVE-2024-53129" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/rockchip: vop: Fix a dereferenced before check warning\n\nThe 'state' can't be NULL, we should check crtc_state.\n\nFix warning:\ndrivers/gpu/drm/rockchip/rockchip_drm_vop.c:1096\nvop_plane_atomic_async_check() warn: variable dereferenced before check\n'state' (see line 1077)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-04T15:15:12Z" diff --git a/advisories/unreviewed/2024/12/GHSA-rq2m-fjrh-fqx7/GHSA-rq2m-fjrh-fqx7.json b/advisories/unreviewed/2024/12/GHSA-rq2m-fjrh-fqx7/GHSA-rq2m-fjrh-fqx7.json index 86d389163fd..cc4a2581bfa 100644 --- a/advisories/unreviewed/2024/12/GHSA-rq2m-fjrh-fqx7/GHSA-rq2m-fjrh-fqx7.json +++ b/advisories/unreviewed/2024/12/GHSA-rq2m-fjrh-fqx7/GHSA-rq2m-fjrh-fqx7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rq2m-fjrh-fqx7", - "modified": "2024-12-12T03:33:06Z", + "modified": "2024-12-13T18:31:56Z", "published": "2024-12-12T03:33:06Z", "aliases": [ "CVE-2024-54508" ], "details": "The issue was addressed with improved memory handling. This issue is fixed in watchOS 11.2, visionOS 2.2, tvOS 18.2, macOS Sequoia 15.2, Safari 18.2, iOS 18.2 and iPadOS 18.2. Processing maliciously crafted web content may lead to an unexpected process crash.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -41,7 +46,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-12T02:15:31Z" diff --git a/advisories/unreviewed/2024/12/GHSA-rr64-3qwv-pgf9/GHSA-rr64-3qwv-pgf9.json b/advisories/unreviewed/2024/12/GHSA-rr64-3qwv-pgf9/GHSA-rr64-3qwv-pgf9.json new file mode 100644 index 00000000000..c27ab8e51eb --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-rr64-3qwv-pgf9/GHSA-rr64-3qwv-pgf9.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rr64-3qwv-pgf9", + "modified": "2024-12-13T18:31:56Z", + "published": "2024-12-13T18:31:56Z", + "aliases": [ + "CVE-2024-47892" + ], + "details": "Software installed and run as a non-privileged user may conduct GPU system calls to read and write freed physical memory from the GPU.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47892" + }, + { + "type": "WEB", + "url": "https://www.imaginationtech.com/gpu-driver-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-362" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T18:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-v8gj-rjxc-h27w/GHSA-v8gj-rjxc-h27w.json b/advisories/unreviewed/2024/12/GHSA-v8gj-rjxc-h27w/GHSA-v8gj-rjxc-h27w.json index 23f138974bf..206d78c6af2 100644 --- a/advisories/unreviewed/2024/12/GHSA-v8gj-rjxc-h27w/GHSA-v8gj-rjxc-h27w.json +++ b/advisories/unreviewed/2024/12/GHSA-v8gj-rjxc-h27w/GHSA-v8gj-rjxc-h27w.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-285" + "CWE-285", + "CWE-639" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-w7rc-39gw-qjww/GHSA-w7rc-39gw-qjww.json b/advisories/unreviewed/2024/12/GHSA-w7rc-39gw-qjww/GHSA-w7rc-39gw-qjww.json index daf8dca98a7..e0909f99945 100644 --- a/advisories/unreviewed/2024/12/GHSA-w7rc-39gw-qjww/GHSA-w7rc-39gw-qjww.json +++ b/advisories/unreviewed/2024/12/GHSA-w7rc-39gw-qjww/GHSA-w7rc-39gw-qjww.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-w7rc-39gw-qjww", - "modified": "2024-12-12T03:33:06Z", + "modified": "2024-12-13T18:31:55Z", "published": "2024-12-12T03:33:06Z", "aliases": [ "CVE-2024-54485" ], "details": "The issue was addressed by adding additional logic. This issue is fixed in iPadOS 17.7.3, iOS 18.2 and iPadOS 18.2. An attacker with physical access to an iOS device may be able to view notification content from the lock screen.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -25,7 +30,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-12T02:15:29Z" diff --git a/advisories/unreviewed/2024/12/GHSA-whrq-j6j3-qg32/GHSA-whrq-j6j3-qg32.json b/advisories/unreviewed/2024/12/GHSA-whrq-j6j3-qg32/GHSA-whrq-j6j3-qg32.json index 46138d95d2e..415d9cd534d 100644 --- a/advisories/unreviewed/2024/12/GHSA-whrq-j6j3-qg32/GHSA-whrq-j6j3-qg32.json +++ b/advisories/unreviewed/2024/12/GHSA-whrq-j6j3-qg32/GHSA-whrq-j6j3-qg32.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-wj3x-pcf8-r7qm/GHSA-wj3x-pcf8-r7qm.json b/advisories/unreviewed/2024/12/GHSA-wj3x-pcf8-r7qm/GHSA-wj3x-pcf8-r7qm.json index 8d0160e6d3e..0a55efc1cb0 100644 --- a/advisories/unreviewed/2024/12/GHSA-wj3x-pcf8-r7qm/GHSA-wj3x-pcf8-r7qm.json +++ b/advisories/unreviewed/2024/12/GHSA-wj3x-pcf8-r7qm/GHSA-wj3x-pcf8-r7qm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wj3x-pcf8-r7qm", - "modified": "2024-12-12T03:33:06Z", + "modified": "2024-12-13T18:31:56Z", "published": "2024-12-12T03:33:06Z", "aliases": [ "CVE-2024-54486" ], "details": "The issue was addressed with improved checks. This issue is fixed in iPadOS 17.7.3, watchOS 11.2, visionOS 2.2, tvOS 18.2, macOS Sequoia 15.2, iOS 18.2 and iPadOS 18.2, macOS Ventura 13.7.2, macOS Sonoma 14.7.2. Processing a maliciously crafted font may result in the disclosure of process memory.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -49,7 +54,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-12T02:15:30Z" diff --git a/advisories/unreviewed/2024/12/GHSA-xgmf-7r4h-7jjp/GHSA-xgmf-7r4h-7jjp.json b/advisories/unreviewed/2024/12/GHSA-xgmf-7r4h-7jjp/GHSA-xgmf-7r4h-7jjp.json index e73a00c3799..bd5bc797e47 100644 --- a/advisories/unreviewed/2024/12/GHSA-xgmf-7r4h-7jjp/GHSA-xgmf-7r4h-7jjp.json +++ b/advisories/unreviewed/2024/12/GHSA-xgmf-7r4h-7jjp/GHSA-xgmf-7r4h-7jjp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xgmf-7r4h-7jjp", - "modified": "2024-12-12T03:33:06Z", + "modified": "2024-12-13T18:31:55Z", "published": "2024-12-12T03:33:06Z", "aliases": [ "CVE-2024-54474" ], "details": "The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2, macOS Ventura 13.7.2, macOS Sonoma 14.7.2. An app may be able to access user-sensitive data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -29,7 +34,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-12T02:15:29Z" diff --git a/advisories/unreviewed/2024/12/GHSA-xjr5-22cj-7cfp/GHSA-xjr5-22cj-7cfp.json b/advisories/unreviewed/2024/12/GHSA-xjr5-22cj-7cfp/GHSA-xjr5-22cj-7cfp.json index 3237a9e0003..b2631f8c97c 100644 --- a/advisories/unreviewed/2024/12/GHSA-xjr5-22cj-7cfp/GHSA-xjr5-22cj-7cfp.json +++ b/advisories/unreviewed/2024/12/GHSA-xjr5-22cj-7cfp/GHSA-xjr5-22cj-7cfp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xjr5-22cj-7cfp", - "modified": "2024-12-12T03:33:07Z", + "modified": "2024-12-13T18:31:56Z", "published": "2024-12-12T03:33:07Z", "aliases": [ "CVE-2024-54527" ], "details": "This issue was addressed with improved checks. This issue is fixed in watchOS 11.2, tvOS 18.2, macOS Sequoia 15.2, iOS 18.2 and iPadOS 18.2, macOS Ventura 13.7.2, macOS Sonoma 14.7.2. An app may be able to access sensitive user data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -41,7 +46,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-12T02:15:31Z" diff --git a/advisories/unreviewed/2024/12/GHSA-xw58-64fr-3323/GHSA-xw58-64fr-3323.json b/advisories/unreviewed/2024/12/GHSA-xw58-64fr-3323/GHSA-xw58-64fr-3323.json index ec66da85095..86c37f6131f 100644 --- a/advisories/unreviewed/2024/12/GHSA-xw58-64fr-3323/GHSA-xw58-64fr-3323.json +++ b/advisories/unreviewed/2024/12/GHSA-xw58-64fr-3323/GHSA-xw58-64fr-3323.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xw58-64fr-3323", - "modified": "2024-12-12T03:33:07Z", + "modified": "2024-12-13T18:31:56Z", "published": "2024-12-12T03:33:07Z", "aliases": [ "CVE-2024-54528" ], "details": "A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.2, macOS Ventura 13.7.2, macOS Sonoma 14.7.2. An app may be able to overwrite arbitrary files.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -29,7 +34,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-12T02:15:32Z"