From 0986d3c64d0213b71b48e26e290f7c434e14fafb Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 25 Jun 2024 06:32:02 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-252v-9w3r-w4vm.json | 35 +++++++++ .../GHSA-3g4h-66cq-c8vg.json | 6 +- .../GHSA-489p-q5cq-r62h.json | 35 +++++++++ .../GHSA-4hgg-qgc6-rv76.json | 35 +++++++++ .../GHSA-57q2-23pw-7c8w.json | 38 ++++++++++ .../GHSA-78rj-c2qq-g3pc.json | 35 +++++++++ .../GHSA-7967-r4q5-m6jj.json | 35 +++++++++ .../GHSA-7p6q-hqg2-6cpg.json | 6 +- .../GHSA-8242-gggm-vvxx.json | 74 +++++++++++++++++++ .../GHSA-888r-932r-wcrp.json | 42 +++++++++++ .../GHSA-9gqj-qmq3-h3hc.json | 35 +++++++++ .../GHSA-9qhj-jvm3-j484.json | 35 +++++++++ .../GHSA-cqrv-6jr2-m8qj.json | 35 +++++++++ .../GHSA-ffvh-2c66-6xgp.json | 38 ++++++++++ .../GHSA-fg6c-4jx9-vvgm.json | 35 +++++++++ .../GHSA-gjhw-gp72-3cj2.json | 35 +++++++++ .../GHSA-h257-p73p-qx36.json | 35 +++++++++ .../GHSA-jm6p-8vc7-99q9.json | 6 +- .../GHSA-jxj9-c3m8-f8q8.json | 35 +++++++++ .../GHSA-mhg9-7866-m76h.json | 35 +++++++++ .../GHSA-rxxp-gpv7-w3c9.json | 35 +++++++++ .../GHSA-vc2p-rvx8-vfx3.json | 35 +++++++++ .../GHSA-w28f-v4hj-9fxg.json | 35 +++++++++ .../GHSA-w5cj-9xrv-rhgm.json | 38 ++++++++++ .../GHSA-x3jm-2wx8-ccv4.json | 35 +++++++++ .../GHSA-x6j2-4hm4-hxj3.json | 35 +++++++++ 26 files changed, 875 insertions(+), 3 deletions(-) create mode 100644 advisories/unreviewed/2024/06/GHSA-252v-9w3r-w4vm/GHSA-252v-9w3r-w4vm.json create mode 100644 advisories/unreviewed/2024/06/GHSA-489p-q5cq-r62h/GHSA-489p-q5cq-r62h.json create mode 100644 advisories/unreviewed/2024/06/GHSA-4hgg-qgc6-rv76/GHSA-4hgg-qgc6-rv76.json create mode 100644 advisories/unreviewed/2024/06/GHSA-57q2-23pw-7c8w/GHSA-57q2-23pw-7c8w.json create mode 100644 advisories/unreviewed/2024/06/GHSA-78rj-c2qq-g3pc/GHSA-78rj-c2qq-g3pc.json create mode 100644 advisories/unreviewed/2024/06/GHSA-7967-r4q5-m6jj/GHSA-7967-r4q5-m6jj.json create mode 100644 advisories/unreviewed/2024/06/GHSA-8242-gggm-vvxx/GHSA-8242-gggm-vvxx.json create mode 100644 advisories/unreviewed/2024/06/GHSA-888r-932r-wcrp/GHSA-888r-932r-wcrp.json create mode 100644 advisories/unreviewed/2024/06/GHSA-9gqj-qmq3-h3hc/GHSA-9gqj-qmq3-h3hc.json create mode 100644 advisories/unreviewed/2024/06/GHSA-9qhj-jvm3-j484/GHSA-9qhj-jvm3-j484.json create mode 100644 advisories/unreviewed/2024/06/GHSA-cqrv-6jr2-m8qj/GHSA-cqrv-6jr2-m8qj.json create mode 100644 advisories/unreviewed/2024/06/GHSA-ffvh-2c66-6xgp/GHSA-ffvh-2c66-6xgp.json create mode 100644 advisories/unreviewed/2024/06/GHSA-fg6c-4jx9-vvgm/GHSA-fg6c-4jx9-vvgm.json create mode 100644 advisories/unreviewed/2024/06/GHSA-gjhw-gp72-3cj2/GHSA-gjhw-gp72-3cj2.json create mode 100644 advisories/unreviewed/2024/06/GHSA-h257-p73p-qx36/GHSA-h257-p73p-qx36.json create mode 100644 advisories/unreviewed/2024/06/GHSA-jxj9-c3m8-f8q8/GHSA-jxj9-c3m8-f8q8.json create mode 100644 advisories/unreviewed/2024/06/GHSA-mhg9-7866-m76h/GHSA-mhg9-7866-m76h.json create mode 100644 advisories/unreviewed/2024/06/GHSA-rxxp-gpv7-w3c9/GHSA-rxxp-gpv7-w3c9.json create mode 100644 advisories/unreviewed/2024/06/GHSA-vc2p-rvx8-vfx3/GHSA-vc2p-rvx8-vfx3.json create mode 100644 advisories/unreviewed/2024/06/GHSA-w28f-v4hj-9fxg/GHSA-w28f-v4hj-9fxg.json create mode 100644 advisories/unreviewed/2024/06/GHSA-w5cj-9xrv-rhgm/GHSA-w5cj-9xrv-rhgm.json create mode 100644 advisories/unreviewed/2024/06/GHSA-x3jm-2wx8-ccv4/GHSA-x3jm-2wx8-ccv4.json create mode 100644 advisories/unreviewed/2024/06/GHSA-x6j2-4hm4-hxj3/GHSA-x6j2-4hm4-hxj3.json diff --git a/advisories/unreviewed/2024/06/GHSA-252v-9w3r-w4vm/GHSA-252v-9w3r-w4vm.json b/advisories/unreviewed/2024/06/GHSA-252v-9w3r-w4vm/GHSA-252v-9w3r-w4vm.json new file mode 100644 index 00000000000..492a60f6d6c --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-252v-9w3r-w4vm/GHSA-252v-9w3r-w4vm.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-252v-9w3r-w4vm", + "modified": "2024-06-25T06:30:39Z", + "published": "2024-06-25T06:30:39Z", + "aliases": [ + "CVE-2024-4757" + ], + "details": "The Logo Manager For Enamad WordPress plugin through 0.7.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4757" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/b54b55e0-b184-4c90-ba94-feda0997bf2a" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-25T06:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-3g4h-66cq-c8vg/GHSA-3g4h-66cq-c8vg.json b/advisories/unreviewed/2024/06/GHSA-3g4h-66cq-c8vg/GHSA-3g4h-66cq-c8vg.json index 480016ad80f..d91c9958a12 100644 --- a/advisories/unreviewed/2024/06/GHSA-3g4h-66cq-c8vg/GHSA-3g4h-66cq-c8vg.json +++ b/advisories/unreviewed/2024/06/GHSA-3g4h-66cq-c8vg/GHSA-3g4h-66cq-c8vg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3g4h-66cq-c8vg", - "modified": "2024-06-24T09:30:53Z", + "modified": "2024-06-25T06:30:38Z", "published": "2024-06-24T09:30:53Z", "aliases": [ "CVE-2024-36495" @@ -25,6 +25,10 @@ { "type": "WEB", "url": "https://www.faronics.com/en-uk/document-library/document/winselect-standard-release-notes" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jun/12" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/06/GHSA-489p-q5cq-r62h/GHSA-489p-q5cq-r62h.json b/advisories/unreviewed/2024/06/GHSA-489p-q5cq-r62h/GHSA-489p-q5cq-r62h.json new file mode 100644 index 00000000000..a3e1054d001 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-489p-q5cq-r62h/GHSA-489p-q5cq-r62h.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-489p-q5cq-r62h", + "modified": "2024-06-25T06:30:39Z", + "published": "2024-06-25T06:30:39Z", + "aliases": [ + "CVE-2024-23158" + ], + "details": "A maliciously crafted IGES file, when parsed in ASMImport229A.dll through Autodesk applications, can be used to cause a use-after-free vulnerability. A malicious actor can leverage this vulnerability to cause a crash or execute arbitrary code in the context of the current process.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23158" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0010" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-25T04:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-4hgg-qgc6-rv76/GHSA-4hgg-qgc6-rv76.json b/advisories/unreviewed/2024/06/GHSA-4hgg-qgc6-rv76/GHSA-4hgg-qgc6-rv76.json new file mode 100644 index 00000000000..0778f241035 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-4hgg-qgc6-rv76/GHSA-4hgg-qgc6-rv76.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4hgg-qgc6-rv76", + "modified": "2024-06-25T06:30:39Z", + "published": "2024-06-25T06:30:39Z", + "aliases": [ + "CVE-2024-23154" + ], + "details": "A maliciously crafted SLDPRT file, when parsed in ODXSW_DLL.dll through Autodesk applications, can be used to cause a Heap-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23154" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0010" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-25T04:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-57q2-23pw-7c8w/GHSA-57q2-23pw-7c8w.json b/advisories/unreviewed/2024/06/GHSA-57q2-23pw-7c8w/GHSA-57q2-23pw-7c8w.json new file mode 100644 index 00000000000..74d4235b945 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-57q2-23pw-7c8w/GHSA-57q2-23pw-7c8w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-57q2-23pw-7c8w", + "modified": "2024-06-25T06:30:39Z", + "published": "2024-06-25T06:30:39Z", + "aliases": [ + "CVE-2024-32855" + ], + "details": "Dell Client Platform BIOS contains an Out-of-bounds Write vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information tampering.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32855" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000225627/dsa-2024-123" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-25T04:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-78rj-c2qq-g3pc/GHSA-78rj-c2qq-g3pc.json b/advisories/unreviewed/2024/06/GHSA-78rj-c2qq-g3pc/GHSA-78rj-c2qq-g3pc.json new file mode 100644 index 00000000000..b5d49286ebb --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-78rj-c2qq-g3pc/GHSA-78rj-c2qq-g3pc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-78rj-c2qq-g3pc", + "modified": "2024-06-25T06:30:38Z", + "published": "2024-06-25T06:30:38Z", + "aliases": [ + "CVE-2024-23150" + ], + "details": "A maliciously crafted PRT file, when parsed in odxug_dll.dll through Autodesk applications, can force an Out-of-Bounds Write. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23150" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0010" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-25T04:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-7967-r4q5-m6jj/GHSA-7967-r4q5-m6jj.json b/advisories/unreviewed/2024/06/GHSA-7967-r4q5-m6jj/GHSA-7967-r4q5-m6jj.json new file mode 100644 index 00000000000..c5c28e570fa --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-7967-r4q5-m6jj/GHSA-7967-r4q5-m6jj.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7967-r4q5-m6jj", + "modified": "2024-06-25T06:30:39Z", + "published": "2024-06-25T06:30:39Z", + "aliases": [ + "CVE-2024-23157" + ], + "details": "A maliciously crafted SLDASM or SLDPRT file, when parsed in ODXSW_DLL.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, along with other vulnerabilities, can lead to code execution in the current process.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23157" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0010" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-25T04:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-7p6q-hqg2-6cpg/GHSA-7p6q-hqg2-6cpg.json b/advisories/unreviewed/2024/06/GHSA-7p6q-hqg2-6cpg/GHSA-7p6q-hqg2-6cpg.json index cad562163d1..6dc5e053e32 100644 --- a/advisories/unreviewed/2024/06/GHSA-7p6q-hqg2-6cpg/GHSA-7p6q-hqg2-6cpg.json +++ b/advisories/unreviewed/2024/06/GHSA-7p6q-hqg2-6cpg/GHSA-7p6q-hqg2-6cpg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7p6q-hqg2-6cpg", - "modified": "2024-06-24T09:30:53Z", + "modified": "2024-06-25T06:30:38Z", "published": "2024-06-24T09:30:53Z", "aliases": [ "CVE-2024-36497" @@ -25,6 +25,10 @@ { "type": "WEB", "url": "https://www.faronics.com/en-uk/document-library/document/winselect-standard-release-notes" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jun/12" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/06/GHSA-8242-gggm-vvxx/GHSA-8242-gggm-vvxx.json b/advisories/unreviewed/2024/06/GHSA-8242-gggm-vvxx/GHSA-8242-gggm-vvxx.json new file mode 100644 index 00000000000..6503bc88801 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-8242-gggm-vvxx/GHSA-8242-gggm-vvxx.json @@ -0,0 +1,74 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8242-gggm-vvxx", + "modified": "2024-06-25T06:30:40Z", + "published": "2024-06-25T06:30:40Z", + "aliases": [ + "CVE-2024-6297" + ], + "details": "Several plugins for WordPress hosted on WordPress.org have been compromised and injected with malicious PHP scripts. A malicious threat actor compromised the source code of various plugins and injected code that exfiltrates database credentials and is used to create new, malicious, administrator users and send that data back to a server. Currently, not all plugins have been patched and we strongly recommend uninstalling the plugins for the time being and running a complete malware scan.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6297" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/blaze-widget/trunk/blaze_widget.php" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/contact-form-7-multi-step-addon/trunk/trx-contact-form-7-multi-step-addon.php" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/simply-show-hooks/trunk/index.php" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/social-warfare/tags/4.4.6.4/trunk/social-warfare.php#L54" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/social-warfare/tags/4.4.6.4/trunk/social-warfare.php#L583" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wrapper-link-elementor/trunk/wrapper.php?rev=3106508" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3105893" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3106042%40social-warfare&new=3106042%40social-warfare&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://wordpress.org/support/topic/a-security-message-from-the-plugin-review-team" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/56d24bc8-4a1a-4e60-aec5-960703a6058a?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-25T04:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-888r-932r-wcrp/GHSA-888r-932r-wcrp.json b/advisories/unreviewed/2024/06/GHSA-888r-932r-wcrp/GHSA-888r-932r-wcrp.json new file mode 100644 index 00000000000..4934c6cbfe3 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-888r-932r-wcrp/GHSA-888r-932r-wcrp.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-888r-932r-wcrp", + "modified": "2024-06-25T06:30:40Z", + "published": "2024-06-25T06:30:40Z", + "aliases": [ + "CVE-2024-5431" + ], + "details": "The WPCafe – Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.2.25 via the reservation_extra_field shortcode parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to include remote files on the server, potentially resulting in code execution", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5431" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wp-cafe/tags/2.2.25/core/shortcodes/views/reservation/reservation-form-template.php#L178" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/5c5e7ed1-7eb8-4ce7-9dd6-0f7937b6f671?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-25T06:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-9gqj-qmq3-h3hc/GHSA-9gqj-qmq3-h3hc.json b/advisories/unreviewed/2024/06/GHSA-9gqj-qmq3-h3hc/GHSA-9gqj-qmq3-h3hc.json new file mode 100644 index 00000000000..0fa47f3c31e --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-9gqj-qmq3-h3hc/GHSA-9gqj-qmq3-h3hc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9gqj-qmq3-h3hc", + "modified": "2024-06-25T06:30:39Z", + "published": "2024-06-25T06:30:39Z", + "aliases": [ + "CVE-2024-37003" + ], + "details": "A maliciously crafted DWG and SLDPRT file, when parsed in opennurbs.dll and ODXSW_DLL.dll through Autodesk applications, can be used to cause a Stack-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37003" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-25T04:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-9qhj-jvm3-j484/GHSA-9qhj-jvm3-j484.json b/advisories/unreviewed/2024/06/GHSA-9qhj-jvm3-j484/GHSA-9qhj-jvm3-j484.json new file mode 100644 index 00000000000..d2423f66c1a --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-9qhj-jvm3-j484/GHSA-9qhj-jvm3-j484.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9qhj-jvm3-j484", + "modified": "2024-06-25T06:30:38Z", + "published": "2024-06-25T06:30:38Z", + "aliases": [ + "CVE-2024-23151" + ], + "details": "A maliciously crafted 3DM file, when parsed in ASMkern229A.dll through Autodesk applications, can force an Out-of-Bounds Write. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23151" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0010" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-25T04:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-cqrv-6jr2-m8qj/GHSA-cqrv-6jr2-m8qj.json b/advisories/unreviewed/2024/06/GHSA-cqrv-6jr2-m8qj/GHSA-cqrv-6jr2-m8qj.json new file mode 100644 index 00000000000..ea6a3f2427a --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-cqrv-6jr2-m8qj/GHSA-cqrv-6jr2-m8qj.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cqrv-6jr2-m8qj", + "modified": "2024-06-25T06:30:39Z", + "published": "2024-06-25T06:30:39Z", + "aliases": [ + "CVE-2024-23153" + ], + "details": "A maliciously crafted MODEL file, when parsed in libodx.dll through Autodesk applications, can force an Out-of-Bounds Read. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23153" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0010" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-25T04:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-ffvh-2c66-6xgp/GHSA-ffvh-2c66-6xgp.json b/advisories/unreviewed/2024/06/GHSA-ffvh-2c66-6xgp/GHSA-ffvh-2c66-6xgp.json new file mode 100644 index 00000000000..5e4faf90858 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-ffvh-2c66-6xgp/GHSA-ffvh-2c66-6xgp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ffvh-2c66-6xgp", + "modified": "2024-06-25T06:30:39Z", + "published": "2024-06-25T06:30:39Z", + "aliases": [ + "CVE-2024-4196" + ], + "details": "An improper input validation vulnerability was discovered in Avaya IP Office that could allow remote command or code execution via a specially crafted web request to the Web Control component. Affected versions include all versions prior to 11.1.3.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4196" + }, + { + "type": "WEB", + "url": "https://download.avaya.com/css/public/documents/101090768" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-25T04:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-fg6c-4jx9-vvgm/GHSA-fg6c-4jx9-vvgm.json b/advisories/unreviewed/2024/06/GHSA-fg6c-4jx9-vvgm/GHSA-fg6c-4jx9-vvgm.json new file mode 100644 index 00000000000..eff926273f5 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-fg6c-4jx9-vvgm/GHSA-fg6c-4jx9-vvgm.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fg6c-4jx9-vvgm", + "modified": "2024-06-25T06:30:39Z", + "published": "2024-06-25T06:30:39Z", + "aliases": [ + "CVE-2024-37007" + ], + "details": "A maliciously crafted X_B and X_T file, when parsed in pskernel.DLL through Autodesk applications, can cause a use-after-free vulnerability. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37007" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0010" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-25T04:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-gjhw-gp72-3cj2/GHSA-gjhw-gp72-3cj2.json b/advisories/unreviewed/2024/06/GHSA-gjhw-gp72-3cj2/GHSA-gjhw-gp72-3cj2.json new file mode 100644 index 00000000000..0e31d5f88bd --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-gjhw-gp72-3cj2/GHSA-gjhw-gp72-3cj2.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gjhw-gp72-3cj2", + "modified": "2024-06-25T06:30:39Z", + "published": "2024-06-25T06:30:39Z", + "aliases": [ + "CVE-2024-23152" + ], + "details": "A maliciously crafted 3DM file, when parsed in opennurbs.dll through Autodesk applications, can force an Out-of-Bounds Read. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23152" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0010" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-25T04:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-h257-p73p-qx36/GHSA-h257-p73p-qx36.json b/advisories/unreviewed/2024/06/GHSA-h257-p73p-qx36/GHSA-h257-p73p-qx36.json new file mode 100644 index 00000000000..ae479112adc --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-h257-p73p-qx36/GHSA-h257-p73p-qx36.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h257-p73p-qx36", + "modified": "2024-06-25T06:30:39Z", + "published": "2024-06-25T06:30:39Z", + "aliases": [ + "CVE-2024-37005" + ], + "details": "A maliciously crafted X_B and X_T file, when parsed in pskernel.DLL through Autodesk applications, can force an Out-of-Bound Read. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37005" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-25T04:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-jm6p-8vc7-99q9/GHSA-jm6p-8vc7-99q9.json b/advisories/unreviewed/2024/06/GHSA-jm6p-8vc7-99q9/GHSA-jm6p-8vc7-99q9.json index abf638501d2..08c60c1ed1c 100644 --- a/advisories/unreviewed/2024/06/GHSA-jm6p-8vc7-99q9/GHSA-jm6p-8vc7-99q9.json +++ b/advisories/unreviewed/2024/06/GHSA-jm6p-8vc7-99q9/GHSA-jm6p-8vc7-99q9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jm6p-8vc7-99q9", - "modified": "2024-06-24T09:30:53Z", + "modified": "2024-06-25T06:30:38Z", "published": "2024-06-24T09:30:53Z", "aliases": [ "CVE-2024-36496" @@ -25,6 +25,10 @@ { "type": "WEB", "url": "https://www.faronics.com/en-uk/document-library/document/winselect-standard-release-notes" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jun/12" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/06/GHSA-jxj9-c3m8-f8q8/GHSA-jxj9-c3m8-f8q8.json b/advisories/unreviewed/2024/06/GHSA-jxj9-c3m8-f8q8/GHSA-jxj9-c3m8-f8q8.json new file mode 100644 index 00000000000..c0295905fa6 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-jxj9-c3m8-f8q8/GHSA-jxj9-c3m8-f8q8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jxj9-c3m8-f8q8", + "modified": "2024-06-25T06:30:39Z", + "published": "2024-06-25T06:30:39Z", + "aliases": [ + "CVE-2024-37006" + ], + "details": "A maliciously crafted CATPRODUCT file, when parsed in CC5Dll.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execution in the context of the current process.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37006" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-25T04:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-mhg9-7866-m76h/GHSA-mhg9-7866-m76h.json b/advisories/unreviewed/2024/06/GHSA-mhg9-7866-m76h/GHSA-mhg9-7866-m76h.json new file mode 100644 index 00000000000..d45d8a689ef --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-mhg9-7866-m76h/GHSA-mhg9-7866-m76h.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mhg9-7866-m76h", + "modified": "2024-06-25T06:30:39Z", + "published": "2024-06-25T06:30:39Z", + "aliases": [ + "CVE-2024-37004" + ], + "details": "A maliciously crafted SLDPRT file, when parsed in ASMKERN229A.dll through Autodesk applications, can cause a use-after-free vulnerability. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37004" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-25T04:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-rxxp-gpv7-w3c9/GHSA-rxxp-gpv7-w3c9.json b/advisories/unreviewed/2024/06/GHSA-rxxp-gpv7-w3c9/GHSA-rxxp-gpv7-w3c9.json new file mode 100644 index 00000000000..83d5a9f18f3 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-rxxp-gpv7-w3c9/GHSA-rxxp-gpv7-w3c9.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rxxp-gpv7-w3c9", + "modified": "2024-06-25T06:30:40Z", + "published": "2024-06-25T06:30:39Z", + "aliases": [ + "CVE-2024-4759" + ], + "details": "The Mime Types Extended WordPress plugin through 0.11 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4759" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/1c7547fa-539a-4890-a94d-c57b3d025507" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-25T06:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-vc2p-rvx8-vfx3/GHSA-vc2p-rvx8-vfx3.json b/advisories/unreviewed/2024/06/GHSA-vc2p-rvx8-vfx3/GHSA-vc2p-rvx8-vfx3.json new file mode 100644 index 00000000000..98b38a0f9ad --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-vc2p-rvx8-vfx3/GHSA-vc2p-rvx8-vfx3.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vc2p-rvx8-vfx3", + "modified": "2024-06-25T06:30:39Z", + "published": "2024-06-25T06:30:39Z", + "aliases": [ + "CVE-2024-23159" + ], + "details": "A maliciously crafted STP file, when parsed in stp_aim_x64_vc15d.dll through Autodesk applications, can be used to uninitialized variables. This vulnerability, along with other vulnerabilities, can lead to code execution in the current process.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23159" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0010" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-457" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-25T04:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-w28f-v4hj-9fxg/GHSA-w28f-v4hj-9fxg.json b/advisories/unreviewed/2024/06/GHSA-w28f-v4hj-9fxg/GHSA-w28f-v4hj-9fxg.json new file mode 100644 index 00000000000..114fc152ae3 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-w28f-v4hj-9fxg/GHSA-w28f-v4hj-9fxg.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w28f-v4hj-9fxg", + "modified": "2024-06-25T06:30:39Z", + "published": "2024-06-25T06:30:39Z", + "aliases": [ + "CVE-2024-36999" + ], + "details": "A maliciously crafted 3DM file, when parsed in opennurbs.dll through Autodesk applications, can force an Out-of-Bounds Write. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36999" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0010" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-25T04:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-w5cj-9xrv-rhgm/GHSA-w5cj-9xrv-rhgm.json b/advisories/unreviewed/2024/06/GHSA-w5cj-9xrv-rhgm/GHSA-w5cj-9xrv-rhgm.json new file mode 100644 index 00000000000..febf8b1e38b --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-w5cj-9xrv-rhgm/GHSA-w5cj-9xrv-rhgm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w5cj-9xrv-rhgm", + "modified": "2024-06-25T06:30:39Z", + "published": "2024-06-25T06:30:39Z", + "aliases": [ + "CVE-2024-4197" + ], + "details": "An unrestricted file upload vulnerability in Avaya IP Office was discovered that could allow remote command or code execution via the One-X component. Affected versions include all versions prior to 11.1.3.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4197" + }, + { + "type": "WEB", + "url": "https://download.avaya.com/css/public/documents/101090768" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-25T04:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-x3jm-2wx8-ccv4/GHSA-x3jm-2wx8-ccv4.json b/advisories/unreviewed/2024/06/GHSA-x3jm-2wx8-ccv4/GHSA-x3jm-2wx8-ccv4.json new file mode 100644 index 00000000000..ef0d2a0f38c --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-x3jm-2wx8-ccv4/GHSA-x3jm-2wx8-ccv4.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x3jm-2wx8-ccv4", + "modified": "2024-06-25T06:30:39Z", + "published": "2024-06-25T06:30:39Z", + "aliases": [ + "CVE-2024-23155" + ], + "details": "A maliciously crafted MODEL file, when parsed in atf_asm_interface.dll through Autodesk applications, can be used to cause a Heap-based Buffer Overflow. A malicious actor can leverage this vulnerability to cause a crash or execute arbitrary code in the context of the current process.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23155" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0010" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-25T04:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-x6j2-4hm4-hxj3/GHSA-x6j2-4hm4-hxj3.json b/advisories/unreviewed/2024/06/GHSA-x6j2-4hm4-hxj3/GHSA-x6j2-4hm4-hxj3.json new file mode 100644 index 00000000000..989d60fe690 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-x6j2-4hm4-hxj3/GHSA-x6j2-4hm4-hxj3.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x6j2-4hm4-hxj3", + "modified": "2024-06-25T06:30:39Z", + "published": "2024-06-25T06:30:39Z", + "aliases": [ + "CVE-2024-23156" + ], + "details": "A maliciously crafted 3DM file, when parsed in opennurbs.dll and ASMkern229A.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, along with other vulnerabilities, can lead to code execution in the current process.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23156" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0010" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-25T04:15:13Z" + } +} \ No newline at end of file