mirror of
https://github.com/netbirdio/advisory-database.git
synced 2026-05-22 18:04:22 -07:00
Advisory Database Sync
This commit is contained in:
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-79vv-vp32-gpp7",
|
||||
"modified": "2024-05-02T14:49:13Z",
|
||||
"modified": "2024-07-05T18:34:13Z",
|
||||
"published": "2024-04-12T09:33:40Z",
|
||||
"aliases": [
|
||||
"CVE-2024-27309"
|
||||
@@ -52,6 +52,10 @@
|
||||
"type": "WEB",
|
||||
"url": "https://lists.apache.org/thread/6536rmzyg076lzzdw2xdktvnz163mjpy"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.netapp.com/advisory/ntap-20240705-0002"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "http://www.openwall.com/lists/oss-security/2024/04/12/3"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-2xp3-57p7-qf4v",
|
||||
"modified": "2024-05-02T19:35:35Z",
|
||||
"modified": "2024-07-05T18:34:13Z",
|
||||
"published": "2024-05-01T17:05:53Z",
|
||||
"aliases": [
|
||||
"CVE-2024-32962"
|
||||
@@ -68,6 +68,10 @@
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/node-saml/xml-crypto/discussions/399"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.netapp.com/advisory/ntap-20240705-0003"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.w3.org/TR/2008/REC-xmldsig-core-20080610/#sec-CoreValidation"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-q63v-rwfp-q5p2",
|
||||
"modified": "2024-07-03T18:33:40Z",
|
||||
"modified": "2024-07-05T18:34:12Z",
|
||||
"published": "2024-03-07T12:30:26Z",
|
||||
"aliases": [
|
||||
"CVE-2024-1931"
|
||||
@@ -37,6 +37,10 @@
|
||||
"type": "WEB",
|
||||
"url": "https://lists.freebsd.org/archives/freebsd-security/2024-July/000283.html"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.netapp.com/advisory/ntap-20240705-0006"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2024-1931.txt"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-wvcr-5p3p-5934",
|
||||
"modified": "2024-03-24T12:30:39Z",
|
||||
"modified": "2024-07-05T18:34:12Z",
|
||||
"published": "2024-03-24T12:30:39Z",
|
||||
"aliases": [
|
||||
"CVE-2020-36825"
|
||||
@@ -11,6 +11,10 @@
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
|
||||
},
|
||||
{
|
||||
"type": "CVSS_V4",
|
||||
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-2w87-6hh6-mqrj",
|
||||
"modified": "2024-07-03T18:39:51Z",
|
||||
"modified": "2024-07-05T18:34:13Z",
|
||||
"published": "2024-05-07T21:31:47Z",
|
||||
"aliases": [
|
||||
"CVE-2024-4030"
|
||||
@@ -76,6 +76,10 @@
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://mail.python.org/archives/list/security-announce@python.org/thread/PRGS5OR3N3PNPT4BMV2VAGN5GMUI5636"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.netapp.com/advisory/ntap-20240705-0005"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-vfg9-hgrq-rjhq",
|
||||
"modified": "2024-06-10T18:31:09Z",
|
||||
"modified": "2024-07-05T18:34:13Z",
|
||||
"published": "2024-06-10T18:31:09Z",
|
||||
"aliases": [
|
||||
"CVE-2024-37051"
|
||||
@@ -21,6 +21,10 @@
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37051"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.netapp.com/advisory/ntap-20240705-0004"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.jetbrains.com/privacy-security/issues-fixed"
|
||||
|
||||
@@ -60,7 +60,7 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
"CWE-79"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
|
||||
@@ -0,0 +1,35 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-2v2c-wv9c-g6cm",
|
||||
"modified": "2024-07-05T18:34:17Z",
|
||||
"published": "2024-07-05T18:34:17Z",
|
||||
"aliases": [
|
||||
"CVE-2024-37769"
|
||||
],
|
||||
"details": "Insecure permissions in 14Finger v1.1 allow attackers to escalate privileges from normal user to Administrator via a crafted POST request.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37769"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/b1ackc4t/14Finger/issues/12"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-07-05T16:15:05Z"
|
||||
}
|
||||
}
|
||||
@@ -36,7 +36,7 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
"CWE-79"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
|
||||
@@ -28,7 +28,7 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
"CWE-287"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
|
||||
@@ -40,7 +40,7 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
"CWE-352"
|
||||
],
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": false,
|
||||
|
||||
@@ -1,14 +1,17 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-4pp4-hqhr-q59r",
|
||||
"modified": "2024-07-02T21:32:15Z",
|
||||
"modified": "2024-07-05T18:34:16Z",
|
||||
"published": "2024-07-02T21:32:15Z",
|
||||
"aliases": [
|
||||
"CVE-2024-25088"
|
||||
],
|
||||
"details": "Improper privilege management in Jungo WinDriver before 12.5.1 allows local attackers to escalate privileges and execute arbitrary code.",
|
||||
"severity": [
|
||||
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
@@ -35,7 +38,7 @@
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-07-02T16:15:04Z"
|
||||
|
||||
@@ -0,0 +1,35 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-54wv-c7pf-j4j8",
|
||||
"modified": "2024-07-05T18:34:18Z",
|
||||
"published": "2024-07-05T18:34:18Z",
|
||||
"aliases": [
|
||||
"CVE-2024-27716"
|
||||
],
|
||||
"details": "Cross Site Scripting vulnerability in Eskooly Web Product v.3.0 and before allows a remote attacker to execute arbitrary code via the message sending and user input fields.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27716"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://blog.be-hacktive.com/eskooly-cve/cve-2024-27716-cross-site-scripting-xss-in-eskooly-web-product-less-than-v3.0"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-07-05T17:15:11Z"
|
||||
}
|
||||
}
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-5cg2-wmx6-ccqv",
|
||||
"modified": "2024-07-03T18:48:08Z",
|
||||
"modified": "2024-07-05T18:34:16Z",
|
||||
"published": "2024-07-03T18:48:08Z",
|
||||
"aliases": [
|
||||
"CVE-2024-36257"
|
||||
|
||||
@@ -0,0 +1,35 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-5qj7-735j-qhqj",
|
||||
"modified": "2024-07-05T18:34:17Z",
|
||||
"published": "2024-07-05T18:34:17Z",
|
||||
"aliases": [
|
||||
"CVE-2024-29318"
|
||||
],
|
||||
"details": "Volmarg Personal Management System 1.4.64 is vulnerable to stored cross site scripting (XSS) via upload of a SVG file with embedded javascript code.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29318"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/b-hermes/vulnerability-research/tree/main/CVE-2024-29318"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-07-05T16:15:04Z"
|
||||
}
|
||||
}
|
||||
@@ -1,14 +1,17 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-6cj7-cwrr-q8fr",
|
||||
"modified": "2024-07-02T21:32:14Z",
|
||||
"modified": "2024-07-05T18:34:14Z",
|
||||
"published": "2024-07-02T21:32:14Z",
|
||||
"aliases": [
|
||||
"CVE-2023-51776"
|
||||
],
|
||||
"details": "Improper privilege management in Jungo WinDriver before 12.1.0 allows local attackers to escalate privileges and execute arbitrary code.",
|
||||
"severity": [
|
||||
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
@@ -35,7 +38,7 @@
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-07-02T15:15:10Z"
|
||||
|
||||
@@ -1,14 +1,17 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-6jcx-jf58-7hch",
|
||||
"modified": "2024-07-02T21:32:14Z",
|
||||
"modified": "2024-07-05T18:34:14Z",
|
||||
"published": "2024-07-02T21:32:14Z",
|
||||
"aliases": [
|
||||
"CVE-2023-51778"
|
||||
],
|
||||
"details": "Out-of-Bounds Write vulnerability in Jungo WinDriver before 12.1.0 allows local attackers to cause a Windows blue screen error and Denial of Service (DoS).",
|
||||
"severity": [
|
||||
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
@@ -33,9 +36,9 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
"CWE-787"
|
||||
],
|
||||
"severity": null,
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-07-02T15:15:10Z"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-76jf-55hx-4969",
|
||||
"modified": "2024-07-03T18:48:09Z",
|
||||
"modified": "2024-07-05T18:34:16Z",
|
||||
"published": "2024-07-03T18:48:09Z",
|
||||
"aliases": [
|
||||
"CVE-2024-39361"
|
||||
|
||||
@@ -0,0 +1,35 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-927f-2f7r-vg99",
|
||||
"modified": "2024-07-05T18:34:18Z",
|
||||
"published": "2024-07-05T18:34:17Z",
|
||||
"aliases": [
|
||||
"CVE-2024-39210"
|
||||
],
|
||||
"details": "Best House Rental Management System v1.0 was discovered to contain an arbitrary file read vulnerability via the Page parameter at index.php. This vulnerability allows attackers to read arbitrary PHP files and access other sensitive information within the application.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39210"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/KRookieSec/CVE-2024-39210"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-07-05T16:15:05Z"
|
||||
}
|
||||
}
|
||||
@@ -1,14 +1,17 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-98p3-57xf-2q44",
|
||||
"modified": "2024-07-02T21:32:15Z",
|
||||
"modified": "2024-07-05T18:34:16Z",
|
||||
"published": "2024-07-02T21:32:15Z",
|
||||
"aliases": [
|
||||
"CVE-2024-25086"
|
||||
],
|
||||
"details": "Improper privilege management in Jungo WinDriver before 12.2.0 allows local attackers to escalate privileges and execute arbitrary code.",
|
||||
"severity": [
|
||||
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
@@ -35,7 +38,7 @@
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-07-02T16:15:04Z"
|
||||
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user