diff --git a/advisories/unreviewed/2023/11/GHSA-68hx-hv9v-7v3w/GHSA-68hx-hv9v-7v3w.json b/advisories/unreviewed/2023/11/GHSA-68hx-hv9v-7v3w/GHSA-68hx-hv9v-7v3w.json index 3f44ffaeffd..5f6e80e8243 100644 --- a/advisories/unreviewed/2023/11/GHSA-68hx-hv9v-7v3w/GHSA-68hx-hv9v-7v3w.json +++ b/advisories/unreviewed/2023/11/GHSA-68hx-hv9v-7v3w/GHSA-68hx-hv9v-7v3w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-68hx-hv9v-7v3w", - "modified": "2023-11-08T18:30:31Z", + "modified": "2024-09-04T15:30:31Z", "published": "2023-11-08T18:30:31Z", "aliases": [ "CVE-2023-5759" diff --git a/advisories/unreviewed/2023/11/GHSA-8qp7-8q8f-4335/GHSA-8qp7-8q8f-4335.json b/advisories/unreviewed/2023/11/GHSA-8qp7-8q8f-4335/GHSA-8qp7-8q8f-4335.json index 03d1565bebd..2b99d9ebe81 100644 --- a/advisories/unreviewed/2023/11/GHSA-8qp7-8q8f-4335/GHSA-8qp7-8q8f-4335.json +++ b/advisories/unreviewed/2023/11/GHSA-8qp7-8q8f-4335/GHSA-8qp7-8q8f-4335.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8qp7-8q8f-4335", - "modified": "2023-11-08T18:30:31Z", + "modified": "2024-09-04T15:30:31Z", "published": "2023-11-08T18:30:31Z", "aliases": [ "CVE-2023-45319" diff --git a/advisories/unreviewed/2023/11/GHSA-m86c-6g87-95pq/GHSA-m86c-6g87-95pq.json b/advisories/unreviewed/2023/11/GHSA-m86c-6g87-95pq/GHSA-m86c-6g87-95pq.json index 1b5f3f3ed5e..c275c259be4 100644 --- a/advisories/unreviewed/2023/11/GHSA-m86c-6g87-95pq/GHSA-m86c-6g87-95pq.json +++ b/advisories/unreviewed/2023/11/GHSA-m86c-6g87-95pq/GHSA-m86c-6g87-95pq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m86c-6g87-95pq", - "modified": "2023-11-16T18:30:25Z", + "modified": "2024-09-04T15:30:32Z", "published": "2023-11-08T18:30:31Z", "aliases": [ "CVE-2023-5913" diff --git a/advisories/unreviewed/2023/11/GHSA-x43q-54p7-vw63/GHSA-x43q-54p7-vw63.json b/advisories/unreviewed/2023/11/GHSA-x43q-54p7-vw63/GHSA-x43q-54p7-vw63.json index 53ab24b98ba..bd7052258da 100644 --- a/advisories/unreviewed/2023/11/GHSA-x43q-54p7-vw63/GHSA-x43q-54p7-vw63.json +++ b/advisories/unreviewed/2023/11/GHSA-x43q-54p7-vw63/GHSA-x43q-54p7-vw63.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-226" + "CWE-226", + "CWE-269" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-4hvh-m426-wv8w/GHSA-4hvh-m426-wv8w.json b/advisories/unreviewed/2024/08/GHSA-4hvh-m426-wv8w/GHSA-4hvh-m426-wv8w.json index 97aa9637980..15d2b8d1d7d 100644 --- a/advisories/unreviewed/2024/08/GHSA-4hvh-m426-wv8w/GHSA-4hvh-m426-wv8w.json +++ b/advisories/unreviewed/2024/08/GHSA-4hvh-m426-wv8w/GHSA-4hvh-m426-wv8w.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-611" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-9chr-m38j-w26g/GHSA-9chr-m38j-w26g.json b/advisories/unreviewed/2024/08/GHSA-9chr-m38j-w26g/GHSA-9chr-m38j-w26g.json index 8d1b6d23063..6bc22c35ab7 100644 --- a/advisories/unreviewed/2024/08/GHSA-9chr-m38j-w26g/GHSA-9chr-m38j-w26g.json +++ b/advisories/unreviewed/2024/08/GHSA-9chr-m38j-w26g/GHSA-9chr-m38j-w26g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9chr-m38j-w26g", - "modified": "2024-08-30T00:31:23Z", + "modified": "2024-09-04T15:30:33Z", "published": "2024-08-30T00:31:23Z", "aliases": [ "CVE-2024-1545" @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-1256" + "CWE-1256", + "CWE-74" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-jq7g-hrpq-8mxh/GHSA-jq7g-hrpq-8mxh.json b/advisories/unreviewed/2024/08/GHSA-jq7g-hrpq-8mxh/GHSA-jq7g-hrpq-8mxh.json index f2d52a7443c..350b075f8ba 100644 --- a/advisories/unreviewed/2024/08/GHSA-jq7g-hrpq-8mxh/GHSA-jq7g-hrpq-8mxh.json +++ b/advisories/unreviewed/2024/08/GHSA-jq7g-hrpq-8mxh/GHSA-jq7g-hrpq-8mxh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jq7g-hrpq-8mxh", - "modified": "2024-08-30T06:30:38Z", + "modified": "2024-09-04T15:30:33Z", "published": "2024-08-30T06:30:38Z", "aliases": [ "CVE-2024-4401" diff --git a/advisories/unreviewed/2024/08/GHSA-p7fr-35j6-p64g/GHSA-p7fr-35j6-p64g.json b/advisories/unreviewed/2024/08/GHSA-p7fr-35j6-p64g/GHSA-p7fr-35j6-p64g.json index b3f2cef9923..a3b3a5eb40f 100644 --- a/advisories/unreviewed/2024/08/GHSA-p7fr-35j6-p64g/GHSA-p7fr-35j6-p64g.json +++ b/advisories/unreviewed/2024/08/GHSA-p7fr-35j6-p64g/GHSA-p7fr-35j6-p64g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p7fr-35j6-p64g", - "modified": "2024-08-30T00:31:23Z", + "modified": "2024-09-04T15:30:33Z", "published": "2024-08-30T00:31:23Z", "aliases": [ "CVE-2024-2881" @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-1256" + "CWE-1256", + "CWE-74" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-w782-gjg9-cjx6/GHSA-w782-gjg9-cjx6.json b/advisories/unreviewed/2024/08/GHSA-w782-gjg9-cjx6/GHSA-w782-gjg9-cjx6.json index 280bd787d04..41d765dd3a1 100644 --- a/advisories/unreviewed/2024/08/GHSA-w782-gjg9-cjx6/GHSA-w782-gjg9-cjx6.json +++ b/advisories/unreviewed/2024/08/GHSA-w782-gjg9-cjx6/GHSA-w782-gjg9-cjx6.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-203", "CWE-208" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/08/GHSA-x5hw-48mf-cq3m/GHSA-x5hw-48mf-cq3m.json b/advisories/unreviewed/2024/08/GHSA-x5hw-48mf-cq3m/GHSA-x5hw-48mf-cq3m.json index c0a23518668..36461c08cd1 100644 --- a/advisories/unreviewed/2024/08/GHSA-x5hw-48mf-cq3m/GHSA-x5hw-48mf-cq3m.json +++ b/advisories/unreviewed/2024/08/GHSA-x5hw-48mf-cq3m/GHSA-x5hw-48mf-cq3m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x5hw-48mf-cq3m", - "modified": "2024-08-30T00:31:23Z", + "modified": "2024-09-04T15:30:33Z", "published": "2024-08-30T00:31:23Z", "aliases": [ "CVE-2024-6670" diff --git a/advisories/unreviewed/2024/09/GHSA-27hp-p4cr-qf56/GHSA-27hp-p4cr-qf56.json b/advisories/unreviewed/2024/09/GHSA-27hp-p4cr-qf56/GHSA-27hp-p4cr-qf56.json new file mode 100644 index 00000000000..e41c13c3acc --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-27hp-p4cr-qf56/GHSA-27hp-p4cr-qf56.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-27hp-p4cr-qf56", + "modified": "2024-09-04T15:30:35Z", + "published": "2024-09-04T15:30:35Z", + "aliases": [ + "CVE-2024-8407" + ], + "details": "A vulnerability was found in alwindoss akademy up to 35caccea888ed63d5489e211c99edff1f62efdba. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file cmd/akademy/handler/handlers.go. The manipulation of the argument emailAddress leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8407" + }, + { + "type": "WEB", + "url": "https://github.com/alwindoss/akademy/issues/1" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.276487" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.276487" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.397340" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T14:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-4c4w-77f9-v9mq/GHSA-4c4w-77f9-v9mq.json b/advisories/unreviewed/2024/09/GHSA-4c4w-77f9-v9mq/GHSA-4c4w-77f9-v9mq.json index 87501674f4a..5784fe4a2af 100644 --- a/advisories/unreviewed/2024/09/GHSA-4c4w-77f9-v9mq/GHSA-4c4w-77f9-v9mq.json +++ b/advisories/unreviewed/2024/09/GHSA-4c4w-77f9-v9mq/GHSA-4c4w-77f9-v9mq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4c4w-77f9-v9mq", - "modified": "2024-09-04T00:31:16Z", + "modified": "2024-09-04T15:30:33Z", "published": "2024-09-04T00:31:16Z", "aliases": [ "CVE-2024-7970" ], "details": "Out of bounds write in V8 in Google Chrome prior to 128.0.6613.119 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-03T23:15:23Z" diff --git a/advisories/unreviewed/2024/09/GHSA-4j5r-p7p6-v9j4/GHSA-4j5r-p7p6-v9j4.json b/advisories/unreviewed/2024/09/GHSA-4j5r-p7p6-v9j4/GHSA-4j5r-p7p6-v9j4.json new file mode 100644 index 00000000000..1f0743582a3 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-4j5r-p7p6-v9j4/GHSA-4j5r-p7p6-v9j4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4j5r-p7p6-v9j4", + "modified": "2024-09-04T15:30:34Z", + "published": "2024-09-04T15:30:34Z", + "aliases": [ + "CVE-2024-7834" + ], + "details": "A local privilege escalation is caused by Overwolf\nloading and executing certain dynamic link library files from a user-writeable\nfolder in SYSTEM context on launch. This allows an attacker with unprivileged\naccess to the system to run arbitrary code with SYSTEM privileges by placing a\nmalicious .dll file in the respective location.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7834" + }, + { + "type": "WEB", + "url": "https://www.cirosec.de/sa/sa-2024-004" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T13:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-794f-5gfq-xmmq/GHSA-794f-5gfq-xmmq.json b/advisories/unreviewed/2024/09/GHSA-794f-5gfq-xmmq/GHSA-794f-5gfq-xmmq.json index 49ad0becd2b..3256dd6eb1b 100644 --- a/advisories/unreviewed/2024/09/GHSA-794f-5gfq-xmmq/GHSA-794f-5gfq-xmmq.json +++ b/advisories/unreviewed/2024/09/GHSA-794f-5gfq-xmmq/GHSA-794f-5gfq-xmmq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-794f-5gfq-xmmq", - "modified": "2024-09-03T15:30:46Z", + "modified": "2024-09-04T15:30:33Z", "published": "2024-09-03T15:30:46Z", "aliases": [ "CVE-2024-8383" ], "details": "Firefox normally asks for confirmation before asking the operating system to find an application to handle a scheme that the browser does not support. It did not ask before doing so for the Usenet-related schemes news: and snews:. Since most operating systems don't have a trusted newsreader installed by default, an unscrupulous program that the user downloaded could register itself as a handler. The website that served the application download could then launch that application at will This vulnerability affects Firefox < 130, Firefox ESR < 128.2, and Firefox ESR < 115.15.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -39,7 +42,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-03T13:15:05Z" diff --git a/advisories/unreviewed/2024/09/GHSA-99ph-h865-m6x2/GHSA-99ph-h865-m6x2.json b/advisories/unreviewed/2024/09/GHSA-99ph-h865-m6x2/GHSA-99ph-h865-m6x2.json new file mode 100644 index 00000000000..c443b664ce3 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-99ph-h865-m6x2/GHSA-99ph-h865-m6x2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-99ph-h865-m6x2", + "modified": "2024-09-04T15:30:36Z", + "published": "2024-09-04T15:30:36Z", + "aliases": [ + "CVE-2024-7077" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Semtek Informatics Software Consulting Inc. Semtek Sempos allows Reflected XSS.This issue affects Semtek Sempos: through 31072024.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7077" + }, + { + "type": "WEB", + "url": "https://www.usom.gov.tr/bildirim/tr-24-1396" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T15:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-c52g-pq8x-mvmm/GHSA-c52g-pq8x-mvmm.json b/advisories/unreviewed/2024/09/GHSA-c52g-pq8x-mvmm/GHSA-c52g-pq8x-mvmm.json new file mode 100644 index 00000000000..77384c71461 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-c52g-pq8x-mvmm/GHSA-c52g-pq8x-mvmm.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c52g-pq8x-mvmm", + "modified": "2024-09-04T15:30:36Z", + "published": "2024-09-04T15:30:36Z", + "aliases": [ + "CVE-2024-8409" + ], + "details": "A vulnerability classified as problematic has been found in ABCD ABCD2 up to 2.2.0-beta-1. This affects an unknown part of the file /common/show_image.php. The manipulation of the argument image leads to path traversal: '../filedir'. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8409" + }, + { + "type": "WEB", + "url": "https://github.com/peritocibernetico/ABCD_Vulnerabilities" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.276489" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.276489" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-24" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T15:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-cv3c-47qp-r5cq/GHSA-cv3c-47qp-r5cq.json b/advisories/unreviewed/2024/09/GHSA-cv3c-47qp-r5cq/GHSA-cv3c-47qp-r5cq.json new file mode 100644 index 00000000000..62b0f630a78 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-cv3c-47qp-r5cq/GHSA-cv3c-47qp-r5cq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cv3c-47qp-r5cq", + "modified": "2024-09-04T15:30:34Z", + "published": "2024-09-04T15:30:34Z", + "aliases": [ + "CVE-2024-44383" + ], + "details": "WAYOS FBM-291W v19.09.11 is vulnerable to Command Execution via msp_info_htm.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44383" + }, + { + "type": "WEB", + "url": "https://github.com/GroundCTL2MajorTom/pocs/blob/main/wayos_%20FBM_291W.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T13:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-g5jh-57wm-p79m/GHSA-g5jh-57wm-p79m.json b/advisories/unreviewed/2024/09/GHSA-g5jh-57wm-p79m/GHSA-g5jh-57wm-p79m.json new file mode 100644 index 00000000000..d847af51e4e --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-g5jh-57wm-p79m/GHSA-g5jh-57wm-p79m.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g5jh-57wm-p79m", + "modified": "2024-09-04T15:30:36Z", + "published": "2024-09-04T15:30:36Z", + "aliases": [ + "CVE-2024-8418" + ], + "details": "A flaw was found in Aardvark-dns versions 1.12.0 and 1.12.1. They contain a denial of service vulnerability due to serial processing of TCP DNS queries. This flaw allows a malicious client to keep a TCP connection open indefinitely, causing other DNS queries to time out and resulting in a denial of service for all other containers using aardvark-dns.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8418" + }, + { + "type": "WEB", + "url": "https://github.com/containers/aardvark-dns/issues/500" + }, + { + "type": "WEB", + "url": "https://github.com/containers/aardvark-dns/pull/503" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-8418" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2309683" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T15:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-gmvf-rv8w-2hrh/GHSA-gmvf-rv8w-2hrh.json b/advisories/unreviewed/2024/09/GHSA-gmvf-rv8w-2hrh/GHSA-gmvf-rv8w-2hrh.json new file mode 100644 index 00000000000..36bece813a1 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-gmvf-rv8w-2hrh/GHSA-gmvf-rv8w-2hrh.json @@ -0,0 +1,55 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gmvf-rv8w-2hrh", + "modified": "2024-09-04T15:30:35Z", + "published": "2024-09-04T15:30:35Z", + "aliases": [ + "CVE-2024-45506" + ], + "details": "HAProxy 2.9.x before 2.9.10, 3.0.x before 3.0.4, and 3.1.x through 3.1-dev6 allows a remote denial of service.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45506" + }, + { + "type": "WEB", + "url": "https://www.haproxy.org" + }, + { + "type": "WEB", + "url": "https://www.haproxy.org/download/3.1/src/CHANGELOG" + }, + { + "type": "WEB", + "url": "https://www.mail-archive.com/haproxy%40formilux.org/msg45280.html" + }, + { + "type": "WEB", + "url": "https://www.mail-archive.com/haproxy%40formilux.org/msg45281.html" + }, + { + "type": "WEB", + "url": "http://git.haproxy.org/?p=haproxy-3.0.git%3Ba=commitdiff%3Bh=c725db17e8416ffb3c1537aea756356228ce5e3c" + }, + { + "type": "WEB", + "url": "http://git.haproxy.org/?p=haproxy-3.0.git%3Ba=commitdiff%3Bh=d636e515453320c6e122c313c661a8ac7d387c7f" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T15:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-gp3v-m4q9-3v8h/GHSA-gp3v-m4q9-3v8h.json b/advisories/unreviewed/2024/09/GHSA-gp3v-m4q9-3v8h/GHSA-gp3v-m4q9-3v8h.json new file mode 100644 index 00000000000..b76f129b41e --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-gp3v-m4q9-3v8h/GHSA-gp3v-m4q9-3v8h.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gp3v-m4q9-3v8h", + "modified": "2024-09-04T15:30:35Z", + "published": "2024-09-04T15:30:35Z", + "aliases": [ + "CVE-2024-7012" + ], + "details": "An authentication bypass vulnerability has been identified in Foreman when deployed with External Authentication, due to the puppet-foreman configuration. This issue arises from Apache's mod_proxy not properly unsetting headers because of restrictions on underscores in HTTP headers, allowing authentication through a malformed header. This flaw impacts all active Satellite deployments (6.13, 6.14 and 6.15) and could potentially enable unauthorized users to gain administrative access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7012" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-7012" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2299429" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T14:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-gq4v-4f65-pcgf/GHSA-gq4v-4f65-pcgf.json b/advisories/unreviewed/2024/09/GHSA-gq4v-4f65-pcgf/GHSA-gq4v-4f65-pcgf.json new file mode 100644 index 00000000000..77a0d3ea47d --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-gq4v-4f65-pcgf/GHSA-gq4v-4f65-pcgf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gq4v-4f65-pcgf", + "modified": "2024-09-04T15:30:36Z", + "published": "2024-09-04T15:30:36Z", + "aliases": [ + "CVE-2024-7078" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Semtek Informatics Software Consulting Inc. Semtek Sempos allows SQL Injection.This issue affects Semtek Sempos: through 31072024.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7078" + }, + { + "type": "WEB", + "url": "https://www.usom.gov.tr/bildirim/tr-24-1396" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T15:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-hp6f-5xgc-789p/GHSA-hp6f-5xgc-789p.json b/advisories/unreviewed/2024/09/GHSA-hp6f-5xgc-789p/GHSA-hp6f-5xgc-789p.json index 5fc97c00a74..b2b464e614f 100644 --- a/advisories/unreviewed/2024/09/GHSA-hp6f-5xgc-789p/GHSA-hp6f-5xgc-789p.json +++ b/advisories/unreviewed/2024/09/GHSA-hp6f-5xgc-789p/GHSA-hp6f-5xgc-789p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hp6f-5xgc-789p", - "modified": "2024-09-04T00:31:15Z", + "modified": "2024-09-04T15:30:33Z", "published": "2024-09-04T00:31:15Z", "aliases": [ "CVE-2024-44809" ], "details": "A remote code execution (RCE) vulnerability exists in the Pi Camera project, version 1.0, maintained by RECANTHA. The issue arises from improper sanitization of user input passed to the \"position\" GET parameter in the tilt.php script. An attacker can exploit this by sending crafted input data that includes malicious command sequences, allowing arbitrary commands to be executed on the server with the privileges of the web server user. This vulnerability is exploitable remotely and poses significant risk if the application is exposed to untrusted networks.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-20" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-03T22:15:04Z" diff --git a/advisories/unreviewed/2024/09/GHSA-j2p5-fvjc-rrwc/GHSA-j2p5-fvjc-rrwc.json b/advisories/unreviewed/2024/09/GHSA-j2p5-fvjc-rrwc/GHSA-j2p5-fvjc-rrwc.json new file mode 100644 index 00000000000..be36f484524 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-j2p5-fvjc-rrwc/GHSA-j2p5-fvjc-rrwc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j2p5-fvjc-rrwc", + "modified": "2024-09-04T15:30:35Z", + "published": "2024-09-04T15:30:35Z", + "aliases": [ + "CVE-2024-44820" + ], + "details": "A sensitive information disclosure vulnerability exists in ZZCMS v.2023 and before within the eginfo.php file located at /3/E_bak5.1/upload/. When accessed with the query parameter phome=ShowPHPInfo, the application executes the phpinfo() function, which exposes detailed information about the PHP environment, including server configuration, loaded modules, and environment variables.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44820" + }, + { + "type": "WEB", + "url": "https://github.com/gkdgkd123/codeAudit/blob/main/CVE-2024-44820%20ZZCMS2023%20phpinfo%E6%B3%84%E9%9C%B2.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T15:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-j66j-2ghj-3fvq/GHSA-j66j-2ghj-3fvq.json b/advisories/unreviewed/2024/09/GHSA-j66j-2ghj-3fvq/GHSA-j66j-2ghj-3fvq.json new file mode 100644 index 00000000000..f8b66c77dd3 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-j66j-2ghj-3fvq/GHSA-j66j-2ghj-3fvq.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j66j-2ghj-3fvq", + "modified": "2024-09-04T15:30:36Z", + "published": "2024-09-04T15:30:36Z", + "aliases": [ + "CVE-2024-8411" + ], + "details": "A vulnerability, which was classified as problematic, has been found in ABCD ABCD2 up to 2.2.0-beta-1. This issue affects some unknown processing of the file /buscar_integrada.php. The manipulation of the argument Sub_Expresion leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8411" + }, + { + "type": "WEB", + "url": "https://github.com/peritocibernetico/ABCD_Vulnerabilities" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.276491" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.276491" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.398843" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T15:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-jm78-w78g-6wh2/GHSA-jm78-w78g-6wh2.json b/advisories/unreviewed/2024/09/GHSA-jm78-w78g-6wh2/GHSA-jm78-w78g-6wh2.json index 915d1266118..496d22f7c82 100644 --- a/advisories/unreviewed/2024/09/GHSA-jm78-w78g-6wh2/GHSA-jm78-w78g-6wh2.json +++ b/advisories/unreviewed/2024/09/GHSA-jm78-w78g-6wh2/GHSA-jm78-w78g-6wh2.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jm78-w78g-6wh2", - "modified": "2024-09-02T12:30:45Z", + "modified": "2024-09-04T15:30:33Z", "published": "2024-09-02T12:30:45Z", "aliases": [ "CVE-2024-38858" ], "details": "Improper neutralization of input in Checkmk before version 2.3.0p14 allows attackers to inject and run malicious scripts in the Robotmk logs view.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/09/GHSA-jrv3-q93v-rr48/GHSA-jrv3-q93v-rr48.json b/advisories/unreviewed/2024/09/GHSA-jrv3-q93v-rr48/GHSA-jrv3-q93v-rr48.json new file mode 100644 index 00000000000..41414380273 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-jrv3-q93v-rr48/GHSA-jrv3-q93v-rr48.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jrv3-q93v-rr48", + "modified": "2024-09-04T15:30:35Z", + "published": "2024-09-04T15:30:35Z", + "aliases": [ + "CVE-2024-7076" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Semtek Informatics Software Consulting Inc. Semtek Sempos allows Blind SQL Injection.This issue affects Semtek Sempos: through 31072024.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:C/RE:L/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7076" + }, + { + "type": "WEB", + "url": "https://www.usom.gov.tr/bildirim/tr-24-1396" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T15:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-m9pq-f54p-cgw9/GHSA-m9pq-f54p-cgw9.json b/advisories/unreviewed/2024/09/GHSA-m9pq-f54p-cgw9/GHSA-m9pq-f54p-cgw9.json new file mode 100644 index 00000000000..b5b57a0b27e --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-m9pq-f54p-cgw9/GHSA-m9pq-f54p-cgw9.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m9pq-f54p-cgw9", + "modified": "2024-09-04T15:30:36Z", + "published": "2024-09-04T15:30:36Z", + "aliases": [ + "CVE-2024-8410" + ], + "details": "A vulnerability classified as problematic was found in ABCD ABCD2 up to 2.2.0-beta-1. This vulnerability affects unknown code of the file /abcd/opac/php/otros_sitios.php. The manipulation of the argument sitio leads to path traversal. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8410" + }, + { + "type": "WEB", + "url": "https://github.com/peritocibernetico/ABCD_Vulnerabilities" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.276490" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.276490" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.398806" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T15:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-mmm5-wgvp-wp8r/GHSA-mmm5-wgvp-wp8r.json b/advisories/unreviewed/2024/09/GHSA-mmm5-wgvp-wp8r/GHSA-mmm5-wgvp-wp8r.json index 8bdd8cf011b..b2531fab661 100644 --- a/advisories/unreviewed/2024/09/GHSA-mmm5-wgvp-wp8r/GHSA-mmm5-wgvp-wp8r.json +++ b/advisories/unreviewed/2024/09/GHSA-mmm5-wgvp-wp8r/GHSA-mmm5-wgvp-wp8r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mmm5-wgvp-wp8r", - "modified": "2024-09-03T15:30:44Z", + "modified": "2024-09-04T15:30:33Z", "published": "2024-09-03T15:30:44Z", "aliases": [ "CVE-2024-6232" ], "details": "There is a MEDIUM severity vulnerability affecting CPython.\n\n\n\n\n\nRegular expressions that allowed excessive backtracking during tarfile.TarFile header parsing are vulnerable to ReDoS via specifically-crafted tar archives.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -51,7 +54,7 @@ "cwe_ids": [ "CWE-1333" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-03T13:15:05Z" diff --git a/advisories/unreviewed/2024/09/GHSA-ph32-hgpc-r5j4/GHSA-ph32-hgpc-r5j4.json b/advisories/unreviewed/2024/09/GHSA-ph32-hgpc-r5j4/GHSA-ph32-hgpc-r5j4.json index 5c0fff0da4e..03a5aa212f4 100644 --- a/advisories/unreviewed/2024/09/GHSA-ph32-hgpc-r5j4/GHSA-ph32-hgpc-r5j4.json +++ b/advisories/unreviewed/2024/09/GHSA-ph32-hgpc-r5j4/GHSA-ph32-hgpc-r5j4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-ph32-hgpc-r5j4", - "modified": "2024-09-03T15:30:45Z", + "modified": "2024-09-04T15:30:33Z", "published": "2024-09-03T15:30:45Z", "aliases": [ "CVE-2024-8382" ], "details": "Internal browser event interfaces were exposed to web content when privileged EventHandler listener callbacks ran for those events. Web content that tried to use those interfaces would not be able to use them with elevated privileges, but their presence would indicate certain browser features had been used, such as when a user opened the Dev Tools console. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, and Firefox ESR < 115.15.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -39,7 +42,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-03T13:15:05Z" diff --git a/advisories/unreviewed/2024/09/GHSA-pmjc-mxf4-8qwx/GHSA-pmjc-mxf4-8qwx.json b/advisories/unreviewed/2024/09/GHSA-pmjc-mxf4-8qwx/GHSA-pmjc-mxf4-8qwx.json new file mode 100644 index 00000000000..fcb1ea5346f --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-pmjc-mxf4-8qwx/GHSA-pmjc-mxf4-8qwx.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pmjc-mxf4-8qwx", + "modified": "2024-09-04T15:30:35Z", + "published": "2024-09-04T15:30:35Z", + "aliases": [ + "CVE-2024-7923" + ], + "details": "An authentication bypass vulnerability has been identified in Pulpcore when deployed with Gunicorn versions prior to 22.0, due to the puppet-pulpcore configuration. This issue arises from Apache's mod_proxy not properly unsetting headers because of restrictions on underscores in HTTP headers, allowing authentication through a malformed header. This flaw impacts all active Satellite deployments (6.13, 6.14 and 6.15) which are using Pulpcore version 3.0+ and could potentially enable unauthorized users to gain administrative access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7923" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-7923" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2305718" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T14:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-r3xx-2cqf-j665/GHSA-r3xx-2cqf-j665.json b/advisories/unreviewed/2024/09/GHSA-r3xx-2cqf-j665/GHSA-r3xx-2cqf-j665.json new file mode 100644 index 00000000000..96d0f25ddc9 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-r3xx-2cqf-j665/GHSA-r3xx-2cqf-j665.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r3xx-2cqf-j665", + "modified": "2024-09-04T15:30:35Z", + "published": "2024-09-04T15:30:35Z", + "aliases": [ + "CVE-2024-44819" + ], + "details": "Cross Site Scripting vulnerability in ZZCMS v.2023 and before allows a remote attacker to obtain sensitive information via a crafted script to the pagename parameter of the admin/del.php component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44819" + }, + { + "type": "WEB", + "url": "https://github.com/gkdgkd123/codeAudit/blob/main/CVE-2024-44819%20ZZCMS2023%E5%8F%8D%E5%B0%84%E5%9E%8BXSS4.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T15:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-rw7g-4966-p363/GHSA-rw7g-4966-p363.json b/advisories/unreviewed/2024/09/GHSA-rw7g-4966-p363/GHSA-rw7g-4966-p363.json index 2893d2dd740..c73a0babc33 100644 --- a/advisories/unreviewed/2024/09/GHSA-rw7g-4966-p363/GHSA-rw7g-4966-p363.json +++ b/advisories/unreviewed/2024/09/GHSA-rw7g-4966-p363/GHSA-rw7g-4966-p363.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rw7g-4966-p363", - "modified": "2024-09-04T00:31:16Z", + "modified": "2024-09-04T15:30:33Z", "published": "2024-09-04T00:31:16Z", "aliases": [ "CVE-2024-8362" ], "details": "Use after free in WebAudio in Google Chrome prior to 128.0.6613.119 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-03T23:15:23Z" diff --git a/advisories/unreviewed/2024/09/GHSA-wv2q-3c9c-q6v7/GHSA-wv2q-3c9c-q6v7.json b/advisories/unreviewed/2024/09/GHSA-wv2q-3c9c-q6v7/GHSA-wv2q-3c9c-q6v7.json new file mode 100644 index 00000000000..7d46ee619e4 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-wv2q-3c9c-q6v7/GHSA-wv2q-3c9c-q6v7.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wv2q-3c9c-q6v7", + "modified": "2024-09-04T15:30:35Z", + "published": "2024-09-04T15:30:35Z", + "aliases": [ + "CVE-2024-8408" + ], + "details": "A vulnerability was found in Linksys WRT54G 4.21.5. It has been rated as critical. Affected by this issue is the function validate_services_port of the file /apply.cgi of the component POST Parameter Handler. The manipulation of the argument services_array leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8408" + }, + { + "type": "WEB", + "url": "https://github.com/BuaaIOTTeam/Iot_Linksys/blob/main/Linksys_WRT54G_validate_services_port.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.276488" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.276488" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.398567" + }, + { + "type": "WEB", + "url": "https://www.linksys.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T14:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-xh53-849p-cfvq/GHSA-xh53-849p-cfvq.json b/advisories/unreviewed/2024/09/GHSA-xh53-849p-cfvq/GHSA-xh53-849p-cfvq.json new file mode 100644 index 00000000000..a64fe3870d0 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-xh53-849p-cfvq/GHSA-xh53-849p-cfvq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xh53-849p-cfvq", + "modified": "2024-09-04T15:30:34Z", + "published": "2024-09-04T15:30:34Z", + "aliases": [ + "CVE-2024-44400" + ], + "details": "D-Link DI-8400 16.07.26A1 is vulnerable to Command Injection via upgrade_filter_asp.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44400" + }, + { + "type": "WEB", + "url": "https://github.com/lonelylonglong/openfile-/blob/main/D-link_DI_8400-16.07.26A1_Command_Injection.md/D-link_DI_8400-16.07.26A1_Command_Injection.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T13:15:06Z" + } +} \ No newline at end of file