From 0be5b86878f9659122ba004b908afc12a2038bc7 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 21 Aug 2024 18:32:50 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-6v96-m24v-f58j.json | 65 +++++++++++++++++++ .../GHSA-f824-fhqw-5fwj.json | 2 +- .../GHSA-8gf9-j4gp-qqf3.json | 2 +- .../GHSA-p3v2-rv86-5c5f.json | 2 +- .../GHSA-gxg7-pxwf-9r28.json | 2 +- .../GHSA-53pc-8xr3-68wx.json | 2 +- .../GHSA-8mv9-w6jc-hxmg.json | 11 ++-- .../GHSA-fhx8-5c23-x7x5.json | 11 ++-- .../GHSA-h9c5-fmrg-fj53.json | 11 ++-- .../GHSA-jqmg-p26g-933q.json | 11 ++-- .../GHSA-m3mq-63hw-6hgx.json | 11 ++-- .../GHSA-88cm-g4xq-fh44.json | 2 +- .../GHSA-9fgf-m63q-p2m6.json | 11 ++-- .../GHSA-rr9m-5jgg-qrvf.json | 2 +- .../GHSA-w8pp-x465-w792.json | 11 ++-- .../GHSA-4j99-4w4w-9ff3.json | 11 ++-- .../GHSA-5vhq-c669-fmgr.json | 1 + .../GHSA-68j3-86cc-wp27.json | 11 ++-- .../GHSA-6qp2-4fq6-h4pv.json | 1 + .../GHSA-c56c-hf5f-5xjh.json | 2 +- .../GHSA-mhj4-vrcv-x4xc.json | 11 ++-- .../GHSA-25v2-v763-x228.json | 11 ++-- .../GHSA-26wc-mjpc-3f8m.json | 11 ++-- .../GHSA-3f2p-5jcv-cffx.json | 11 ++-- .../GHSA-3h4r-2q6q-wfr8.json | 2 +- .../GHSA-45vp-vx4c-9jr2.json | 11 ++-- .../GHSA-4fch-r62j-4r94.json | 2 +- .../GHSA-4p9w-ppgq-rm99.json | 11 ++-- .../GHSA-4qj8-cj7g-gfmf.json | 11 ++-- .../GHSA-5x23-w3hg-qfcx.json | 9 ++- .../GHSA-72v6-vmr5-v9qf.json | 11 ++-- .../GHSA-73px-657p-5pqg.json | 2 +- .../GHSA-75c8-gq9f-5jv5.json | 11 ++-- .../GHSA-894g-hq68-4qh8.json | 11 ++-- .../GHSA-9v24-vr9v-j466.json | 11 ++-- .../GHSA-cgvj-gwgx-p5f7.json | 11 ++-- .../GHSA-fpf5-xw2p-f3m5.json | 11 ++-- .../GHSA-gfgx-m82f-4x3g.json | 11 ++-- .../GHSA-gv9g-w43h-w5vw.json | 11 ++-- .../GHSA-j53w-25v4-j86p.json | 9 ++- .../GHSA-m484-77r4-h4vf.json | 11 ++-- .../GHSA-p7rj-mgww-3q4f.json | 11 ++-- .../GHSA-pfpp-q6gh-6xmm.json | 11 ++-- .../GHSA-pm35-jc42-34cq.json | 11 ++-- .../GHSA-q8cp-9q2j-mfj8.json | 11 ++-- .../GHSA-qghh-pcqm-r2r3.json | 11 ++-- .../GHSA-v29p-wgpj-c454.json | 11 ++-- .../GHSA-vh56-6f64-v877.json | 9 ++- .../GHSA-w4wp-6c4p-vfjm.json | 9 ++- .../GHSA-wp5v-h6j4-v39w.json | 11 ++-- .../GHSA-x27m-p9c5-jvf7.json | 11 ++-- .../GHSA-xp5x-wr7x-fp9j.json | 11 ++-- .../GHSA-xxqc-5rhp-jfq2.json | 11 ++-- .../GHSA-2pwf-wmm4-p5xg.json | 42 ++++++++++++ .../GHSA-2v3w-9hfq-fx33.json | 38 +++++++++++ .../GHSA-2vf4-v2rm-3993.json | 11 ++-- .../GHSA-2wj7-gph3-jwg6.json | 42 ++++++++++++ .../GHSA-37rg-3x55-7pmg.json | 42 ++++++++++++ .../GHSA-3fc7-hxmq-f35p.json | 39 +++++++++++ .../GHSA-3r58-6hw4-672v.json | 39 +++++++++++ .../GHSA-44v9-q98m-jg4p.json | 11 ++-- .../GHSA-45wm-mg4w-2536.json | 39 +++++++++++ .../GHSA-496j-g557-72f5.json | 42 ++++++++++++ .../GHSA-4wrc-8xjh-v948.json | 39 +++++++++++ .../GHSA-626c-c4r3-vmjg.json | 42 ++++++++++++ .../GHSA-64gw-gxfq-f34c.json | 38 +++++++++++ .../GHSA-67c5-gg2x-j6wg.json | 38 +++++++++++ .../GHSA-6cpf-rmp5-w9pp.json | 42 ++++++++++++ .../GHSA-6fqv-gvfg-wqrx.json | 39 +++++++++++ .../GHSA-7jcc-v4g6-5284.json | 35 ++++++++++ .../GHSA-8fgq-vqp8-467c.json | 38 +++++++++++ .../GHSA-8vhq-vf79-3q7c.json | 42 ++++++++++++ .../GHSA-94m4-2jpq-9j4w.json | 39 +++++++++++ .../GHSA-9j4q-qf8g-3382.json | 42 ++++++++++++ .../GHSA-9j5g-j2hj-xfpc.json | 42 ++++++++++++ .../GHSA-c62c-fvgv-j4v4.json | 1 + .../GHSA-chqm-2p4j-9jph.json | 35 ++++++++++ .../GHSA-cq2h-fx3v-v5m3.json | 42 ++++++++++++ .../GHSA-f5w2-xh59-w5p8.json | 6 +- .../GHSA-f8mh-6mf7-mh58.json | 39 +++++++++++ .../GHSA-fm2v-78x9-f367.json | 38 +++++++++++ .../GHSA-g5jq-gr6p-2c45.json | 42 ++++++++++++ .../GHSA-g6mg-qmxh-mv93.json | 35 ++++++++++ .../GHSA-g6mm-5rjg-vwhr.json | 38 +++++++++++ .../GHSA-grxj-hmrx-25w5.json | 35 ++++++++++ .../GHSA-h3rg-2ghf-ph8j.json | 11 ++-- .../GHSA-hm5h-rw9m-g27p.json | 42 ++++++++++++ .../GHSA-hxqr-gvc3-2pc3.json | 42 ++++++++++++ .../GHSA-j6mc-w8mx-r99r.json | 38 +++++++++++ .../GHSA-jqxg-gg5c-r85j.json | 39 +++++++++++ .../GHSA-m2vr-vh5r-mfq9.json | 38 +++++++++++ .../GHSA-m9m8-p797-5pq4.json | 42 ++++++++++++ .../GHSA-mv2g-4jjm-w3mg.json | 42 ++++++++++++ .../GHSA-q3pq-6mcr-hp32.json | 42 ++++++++++++ .../GHSA-q42h-967p-cm88.json | 42 ++++++++++++ .../GHSA-q5xv-4chr-x766.json | 38 +++++++++++ .../GHSA-q9rp-4m44-qjc7.json | 39 +++++++++++ .../GHSA-qhpg-jf9r-mqxq.json | 1 + .../GHSA-r3cc-j4fw-h337.json | 9 ++- .../GHSA-r3hw-cxxj-hj9v.json | 39 +++++++++++ .../GHSA-rhjx-jwv4-jj63.json | 6 +- .../GHSA-rhrw-ch52-5vhp.json | 39 +++++++++++ .../GHSA-rqxc-qv82-j8gh.json | 38 +++++++++++ .../GHSA-v4cc-wwr9-44vw.json | 3 +- .../GHSA-v735-hrpq-c278.json | 1 + .../GHSA-w5pw-gmcw-rfc8.json | 43 ++++++++++++ .../GHSA-w7cp-g8v7-r54m.json | 39 +++++++++++ .../GHSA-xr6g-6vm5-7r58.json | 42 ++++++++++++ 108 files changed, 2176 insertions(+), 181 deletions(-) create mode 100644 advisories/github-reviewed/2024/08/GHSA-6v96-m24v-f58j/GHSA-6v96-m24v-f58j.json create mode 100644 advisories/unreviewed/2024/08/GHSA-2pwf-wmm4-p5xg/GHSA-2pwf-wmm4-p5xg.json create mode 100644 advisories/unreviewed/2024/08/GHSA-2v3w-9hfq-fx33/GHSA-2v3w-9hfq-fx33.json create mode 100644 advisories/unreviewed/2024/08/GHSA-2wj7-gph3-jwg6/GHSA-2wj7-gph3-jwg6.json create mode 100644 advisories/unreviewed/2024/08/GHSA-37rg-3x55-7pmg/GHSA-37rg-3x55-7pmg.json create mode 100644 advisories/unreviewed/2024/08/GHSA-3fc7-hxmq-f35p/GHSA-3fc7-hxmq-f35p.json create mode 100644 advisories/unreviewed/2024/08/GHSA-3r58-6hw4-672v/GHSA-3r58-6hw4-672v.json create mode 100644 advisories/unreviewed/2024/08/GHSA-45wm-mg4w-2536/GHSA-45wm-mg4w-2536.json create mode 100644 advisories/unreviewed/2024/08/GHSA-496j-g557-72f5/GHSA-496j-g557-72f5.json create mode 100644 advisories/unreviewed/2024/08/GHSA-4wrc-8xjh-v948/GHSA-4wrc-8xjh-v948.json create mode 100644 advisories/unreviewed/2024/08/GHSA-626c-c4r3-vmjg/GHSA-626c-c4r3-vmjg.json create mode 100644 advisories/unreviewed/2024/08/GHSA-64gw-gxfq-f34c/GHSA-64gw-gxfq-f34c.json create mode 100644 advisories/unreviewed/2024/08/GHSA-67c5-gg2x-j6wg/GHSA-67c5-gg2x-j6wg.json create mode 100644 advisories/unreviewed/2024/08/GHSA-6cpf-rmp5-w9pp/GHSA-6cpf-rmp5-w9pp.json create mode 100644 advisories/unreviewed/2024/08/GHSA-6fqv-gvfg-wqrx/GHSA-6fqv-gvfg-wqrx.json create mode 100644 advisories/unreviewed/2024/08/GHSA-7jcc-v4g6-5284/GHSA-7jcc-v4g6-5284.json create mode 100644 advisories/unreviewed/2024/08/GHSA-8fgq-vqp8-467c/GHSA-8fgq-vqp8-467c.json create mode 100644 advisories/unreviewed/2024/08/GHSA-8vhq-vf79-3q7c/GHSA-8vhq-vf79-3q7c.json create mode 100644 advisories/unreviewed/2024/08/GHSA-94m4-2jpq-9j4w/GHSA-94m4-2jpq-9j4w.json create mode 100644 advisories/unreviewed/2024/08/GHSA-9j4q-qf8g-3382/GHSA-9j4q-qf8g-3382.json create mode 100644 advisories/unreviewed/2024/08/GHSA-9j5g-j2hj-xfpc/GHSA-9j5g-j2hj-xfpc.json create mode 100644 advisories/unreviewed/2024/08/GHSA-chqm-2p4j-9jph/GHSA-chqm-2p4j-9jph.json create mode 100644 advisories/unreviewed/2024/08/GHSA-cq2h-fx3v-v5m3/GHSA-cq2h-fx3v-v5m3.json create mode 100644 advisories/unreviewed/2024/08/GHSA-f8mh-6mf7-mh58/GHSA-f8mh-6mf7-mh58.json create mode 100644 advisories/unreviewed/2024/08/GHSA-fm2v-78x9-f367/GHSA-fm2v-78x9-f367.json create mode 100644 advisories/unreviewed/2024/08/GHSA-g5jq-gr6p-2c45/GHSA-g5jq-gr6p-2c45.json create mode 100644 advisories/unreviewed/2024/08/GHSA-g6mg-qmxh-mv93/GHSA-g6mg-qmxh-mv93.json create mode 100644 advisories/unreviewed/2024/08/GHSA-g6mm-5rjg-vwhr/GHSA-g6mm-5rjg-vwhr.json create mode 100644 advisories/unreviewed/2024/08/GHSA-grxj-hmrx-25w5/GHSA-grxj-hmrx-25w5.json create mode 100644 advisories/unreviewed/2024/08/GHSA-hm5h-rw9m-g27p/GHSA-hm5h-rw9m-g27p.json create mode 100644 advisories/unreviewed/2024/08/GHSA-hxqr-gvc3-2pc3/GHSA-hxqr-gvc3-2pc3.json create mode 100644 advisories/unreviewed/2024/08/GHSA-j6mc-w8mx-r99r/GHSA-j6mc-w8mx-r99r.json create mode 100644 advisories/unreviewed/2024/08/GHSA-jqxg-gg5c-r85j/GHSA-jqxg-gg5c-r85j.json create mode 100644 advisories/unreviewed/2024/08/GHSA-m2vr-vh5r-mfq9/GHSA-m2vr-vh5r-mfq9.json create mode 100644 advisories/unreviewed/2024/08/GHSA-m9m8-p797-5pq4/GHSA-m9m8-p797-5pq4.json create mode 100644 advisories/unreviewed/2024/08/GHSA-mv2g-4jjm-w3mg/GHSA-mv2g-4jjm-w3mg.json create mode 100644 advisories/unreviewed/2024/08/GHSA-q3pq-6mcr-hp32/GHSA-q3pq-6mcr-hp32.json create mode 100644 advisories/unreviewed/2024/08/GHSA-q42h-967p-cm88/GHSA-q42h-967p-cm88.json create mode 100644 advisories/unreviewed/2024/08/GHSA-q5xv-4chr-x766/GHSA-q5xv-4chr-x766.json create mode 100644 advisories/unreviewed/2024/08/GHSA-q9rp-4m44-qjc7/GHSA-q9rp-4m44-qjc7.json create mode 100644 advisories/unreviewed/2024/08/GHSA-r3hw-cxxj-hj9v/GHSA-r3hw-cxxj-hj9v.json create mode 100644 advisories/unreviewed/2024/08/GHSA-rhrw-ch52-5vhp/GHSA-rhrw-ch52-5vhp.json create mode 100644 advisories/unreviewed/2024/08/GHSA-rqxc-qv82-j8gh/GHSA-rqxc-qv82-j8gh.json create mode 100644 advisories/unreviewed/2024/08/GHSA-w5pw-gmcw-rfc8/GHSA-w5pw-gmcw-rfc8.json create mode 100644 advisories/unreviewed/2024/08/GHSA-w7cp-g8v7-r54m/GHSA-w7cp-g8v7-r54m.json create mode 100644 advisories/unreviewed/2024/08/GHSA-xr6g-6vm5-7r58/GHSA-xr6g-6vm5-7r58.json diff --git a/advisories/github-reviewed/2024/08/GHSA-6v96-m24v-f58j/GHSA-6v96-m24v-f58j.json b/advisories/github-reviewed/2024/08/GHSA-6v96-m24v-f58j/GHSA-6v96-m24v-f58j.json new file mode 100644 index 00000000000..00f67733e54 --- /dev/null +++ b/advisories/github-reviewed/2024/08/GHSA-6v96-m24v-f58j/GHSA-6v96-m24v-f58j.json @@ -0,0 +1,65 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6v96-m24v-f58j", + "modified": "2024-08-21T18:31:00Z", + "published": "2024-08-21T18:31:00Z", + "aliases": [ + "CVE-2024-43411" + ], + "summary": "CKEditor4 low-risk cross-site scripting (XSS) vulnerability linked to potential domain takeover", + "details": "### Affected Packages\n\nThe issue impacts only editor instances with enabled [version notifications](https://ckeditor.com/docs/ckeditor4/latest/api/CKEDITOR_config.html#cfg-versionCheck).\n\nPlease note that this feature is disabled by default in all CKEditor 4 LTS versions. Therefore, if you use CKEditor 4 LTS, it is highly unlikely that you are affected by this vulnerability. If you are unsure, please [contact us](mailto:security@cksource.com).\n\n### Impact\n\nA theoretical vulnerability has been identified in CKEditor 4.22 (and above). In a highly unlikely scenario where an attacker gains control over the https://cke4.ckeditor.com domain, they could potentially execute an attack on CKEditor 4 instances. Although the vulnerability is purely hypothetical, we have addressed it in CKEditor 4.25.0-lts to ensure compliance with security best practices.\n\n### Patches\n\nThe issue has been recognized and patched. The fix is available in version 4.25.0-lts.\n\n### For More Information\n\nIf you have any questions or comments about this advisory, please email us at [security@cksource.com](mailto:security@cksource.com).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "npm", + "name": "ckeditor4" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "4.22.0" + }, + { + "fixed": "4.25.0" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/ckeditor/ckeditor4/security/advisories/GHSA-6v96-m24v-f58j" + }, + { + "type": "WEB", + "url": "https://github.com/ckeditor/ckeditor4/commit/b5069c9cb769ea22eae1cbd7200f22b1cf2e3a7f" + }, + { + "type": "PACKAGE", + "url": "https://github.com/ckeditor/ckeditor4" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "LOW", + "github_reviewed": true, + "github_reviewed_at": "2024-08-21T18:31:00Z", + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-f824-fhqw-5fwj/GHSA-f824-fhqw-5fwj.json b/advisories/unreviewed/2022/05/GHSA-f824-fhqw-5fwj/GHSA-f824-fhqw-5fwj.json index fbbe9f09118..08312f41257 100644 --- a/advisories/unreviewed/2022/05/GHSA-f824-fhqw-5fwj/GHSA-f824-fhqw-5fwj.json +++ b/advisories/unreviewed/2022/05/GHSA-f824-fhqw-5fwj/GHSA-f824-fhqw-5fwj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f824-fhqw-5fwj", - "modified": "2023-01-31T21:30:21Z", + "modified": "2024-08-21T18:31:25Z", "published": "2022-05-24T22:00:29Z", "aliases": [ "CVE-2019-16220" diff --git a/advisories/unreviewed/2023/07/GHSA-8gf9-j4gp-qqf3/GHSA-8gf9-j4gp-qqf3.json b/advisories/unreviewed/2023/07/GHSA-8gf9-j4gp-qqf3/GHSA-8gf9-j4gp-qqf3.json index 91dc9531e14..dadc945a338 100644 --- a/advisories/unreviewed/2023/07/GHSA-8gf9-j4gp-qqf3/GHSA-8gf9-j4gp-qqf3.json +++ b/advisories/unreviewed/2023/07/GHSA-8gf9-j4gp-qqf3/GHSA-8gf9-j4gp-qqf3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8gf9-j4gp-qqf3", - "modified": "2023-12-12T15:30:58Z", + "modified": "2024-08-21T18:31:25Z", "published": "2023-07-10T18:30:49Z", "aliases": [ "CVE-2023-32250" diff --git a/advisories/unreviewed/2023/07/GHSA-p3v2-rv86-5c5f/GHSA-p3v2-rv86-5c5f.json b/advisories/unreviewed/2023/07/GHSA-p3v2-rv86-5c5f/GHSA-p3v2-rv86-5c5f.json index 320f46664e8..daed1d77fc2 100644 --- a/advisories/unreviewed/2023/07/GHSA-p3v2-rv86-5c5f/GHSA-p3v2-rv86-5c5f.json +++ b/advisories/unreviewed/2023/07/GHSA-p3v2-rv86-5c5f/GHSA-p3v2-rv86-5c5f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p3v2-rv86-5c5f", - "modified": "2023-12-12T15:30:58Z", + "modified": "2024-08-21T18:31:25Z", "published": "2023-07-10T18:30:49Z", "aliases": [ "CVE-2023-32254" diff --git a/advisories/unreviewed/2023/10/GHSA-gxg7-pxwf-9r28/GHSA-gxg7-pxwf-9r28.json b/advisories/unreviewed/2023/10/GHSA-gxg7-pxwf-9r28/GHSA-gxg7-pxwf-9r28.json index 78170e49a3d..50a50b80313 100644 --- a/advisories/unreviewed/2023/10/GHSA-gxg7-pxwf-9r28/GHSA-gxg7-pxwf-9r28.json +++ b/advisories/unreviewed/2023/10/GHSA-gxg7-pxwf-9r28/GHSA-gxg7-pxwf-9r28.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gxg7-pxwf-9r28", - "modified": "2024-01-25T09:30:20Z", + "modified": "2024-08-21T18:31:25Z", "published": "2023-10-04T21:30:22Z", "aliases": [ "CVE-2023-39191" diff --git a/advisories/unreviewed/2023/11/GHSA-53pc-8xr3-68wx/GHSA-53pc-8xr3-68wx.json b/advisories/unreviewed/2023/11/GHSA-53pc-8xr3-68wx/GHSA-53pc-8xr3-68wx.json index c5f438c7b5f..865049efac0 100644 --- a/advisories/unreviewed/2023/11/GHSA-53pc-8xr3-68wx/GHSA-53pc-8xr3-68wx.json +++ b/advisories/unreviewed/2023/11/GHSA-53pc-8xr3-68wx/GHSA-53pc-8xr3-68wx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-53pc-8xr3-68wx", - "modified": "2023-11-03T09:32:49Z", + "modified": "2024-08-21T18:31:25Z", "published": "2023-11-03T09:32:49Z", "aliases": [ "CVE-2023-1194" diff --git a/advisories/unreviewed/2024/02/GHSA-8mv9-w6jc-hxmg/GHSA-8mv9-w6jc-hxmg.json b/advisories/unreviewed/2024/02/GHSA-8mv9-w6jc-hxmg/GHSA-8mv9-w6jc-hxmg.json index 39f9c67b580..0027697cfda 100644 --- a/advisories/unreviewed/2024/02/GHSA-8mv9-w6jc-hxmg/GHSA-8mv9-w6jc-hxmg.json +++ b/advisories/unreviewed/2024/02/GHSA-8mv9-w6jc-hxmg/GHSA-8mv9-w6jc-hxmg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8mv9-w6jc-hxmg", - "modified": "2024-02-29T03:33:18Z", + "modified": "2024-08-21T18:31:25Z", "published": "2024-02-29T03:33:18Z", "aliases": [ "CVE-2024-25833" ], "details": "F-logic DataCube3 v1.0 is vulnerable to unauthenticated SQL injection, which could allow an unauthenticated malicious actor to execute arbitrary SQL queries in database.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-29T01:44:16Z" diff --git a/advisories/unreviewed/2024/03/GHSA-fhx8-5c23-x7x5/GHSA-fhx8-5c23-x7x5.json b/advisories/unreviewed/2024/03/GHSA-fhx8-5c23-x7x5/GHSA-fhx8-5c23-x7x5.json index 2ad9ea81c66..5c01f5c8e7b 100644 --- a/advisories/unreviewed/2024/03/GHSA-fhx8-5c23-x7x5/GHSA-fhx8-5c23-x7x5.json +++ b/advisories/unreviewed/2024/03/GHSA-fhx8-5c23-x7x5/GHSA-fhx8-5c23-x7x5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fhx8-5c23-x7x5", - "modified": "2024-03-01T15:31:37Z", + "modified": "2024-08-21T18:31:25Z", "published": "2024-03-01T15:31:37Z", "aliases": [ "CVE-2023-46950" ], "details": "Cross Site Scripting vulnerability in Contribsys Sidekiq v.6.5.8 allows a remote attacker to obtain sensitive information via a crafted URL to the filter functions.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-01T14:15:53Z" diff --git a/advisories/unreviewed/2024/03/GHSA-h9c5-fmrg-fj53/GHSA-h9c5-fmrg-fj53.json b/advisories/unreviewed/2024/03/GHSA-h9c5-fmrg-fj53/GHSA-h9c5-fmrg-fj53.json index 3a158c518e9..cd67436f7c7 100644 --- a/advisories/unreviewed/2024/03/GHSA-h9c5-fmrg-fj53/GHSA-h9c5-fmrg-fj53.json +++ b/advisories/unreviewed/2024/03/GHSA-h9c5-fmrg-fj53/GHSA-h9c5-fmrg-fj53.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h9c5-fmrg-fj53", - "modified": "2024-03-12T18:31:14Z", + "modified": "2024-08-21T18:31:25Z", "published": "2024-03-12T18:31:14Z", "aliases": [ "CVE-2024-28340" ], "details": "An information leak in the currentsetting.htm component of Netgear CBR40 2.5.0.28, Netgear CBK40 2.5.0.28, and Netgear CBK43 2.5.0.28 allows attackers to obtain sensitive information without any authentication required.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-12T17:15:59Z" diff --git a/advisories/unreviewed/2024/03/GHSA-jqmg-p26g-933q/GHSA-jqmg-p26g-933q.json b/advisories/unreviewed/2024/03/GHSA-jqmg-p26g-933q/GHSA-jqmg-p26g-933q.json index c593dc76ff3..f29d1453101 100644 --- a/advisories/unreviewed/2024/03/GHSA-jqmg-p26g-933q/GHSA-jqmg-p26g-933q.json +++ b/advisories/unreviewed/2024/03/GHSA-jqmg-p26g-933q/GHSA-jqmg-p26g-933q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jqmg-p26g-933q", - "modified": "2024-03-12T21:30:59Z", + "modified": "2024-08-21T18:31:25Z", "published": "2024-03-12T21:30:59Z", "aliases": [ "CVE-2023-42308" ], "details": "Cross Site Scripting (XSS) vulnerability in Manage Fastrack Subjects in Code-Projects Exam Form Submission 1.0 allows attackers to run arbitrary code via the \"Subject Name\" and \"Subject Code\" Section.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-12T21:15:55Z" diff --git a/advisories/unreviewed/2024/03/GHSA-m3mq-63hw-6hgx/GHSA-m3mq-63hw-6hgx.json b/advisories/unreviewed/2024/03/GHSA-m3mq-63hw-6hgx/GHSA-m3mq-63hw-6hgx.json index cc452e3c494..a29bd7acbec 100644 --- a/advisories/unreviewed/2024/03/GHSA-m3mq-63hw-6hgx/GHSA-m3mq-63hw-6hgx.json +++ b/advisories/unreviewed/2024/03/GHSA-m3mq-63hw-6hgx/GHSA-m3mq-63hw-6hgx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m3mq-63hw-6hgx", - "modified": "2024-03-03T09:30:38Z", + "modified": "2024-08-21T18:31:25Z", "published": "2024-03-03T09:30:38Z", "aliases": [ "CVE-2024-25842" ], "details": "An issue was discovered in Presta World \"Account Manager - Sales Representative & Dealers - CRM\" (prestasalesmanager) module for PrestaShop before version 9.0, allows remote attackers to escalate privilege and obtain sensitive information via the uploadLogo() and postProcess methods.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-03T09:15:06Z" diff --git a/advisories/unreviewed/2024/04/GHSA-88cm-g4xq-fh44/GHSA-88cm-g4xq-fh44.json b/advisories/unreviewed/2024/04/GHSA-88cm-g4xq-fh44/GHSA-88cm-g4xq-fh44.json index 314fdd25820..12e4ae8dbac 100644 --- a/advisories/unreviewed/2024/04/GHSA-88cm-g4xq-fh44/GHSA-88cm-g4xq-fh44.json +++ b/advisories/unreviewed/2024/04/GHSA-88cm-g4xq-fh44/GHSA-88cm-g4xq-fh44.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-306" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-9fgf-m63q-p2m6/GHSA-9fgf-m63q-p2m6.json b/advisories/unreviewed/2024/04/GHSA-9fgf-m63q-p2m6/GHSA-9fgf-m63q-p2m6.json index 1135b8a2cca..bbb472541a4 100644 --- a/advisories/unreviewed/2024/04/GHSA-9fgf-m63q-p2m6/GHSA-9fgf-m63q-p2m6.json +++ b/advisories/unreviewed/2024/04/GHSA-9fgf-m63q-p2m6/GHSA-9fgf-m63q-p2m6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9fgf-m63q-p2m6", - "modified": "2024-04-03T15:30:41Z", + "modified": "2024-08-21T18:31:25Z", "published": "2024-04-03T15:30:41Z", "aliases": [ "CVE-2024-30568" ], "details": "Netgear R6850 1.1.0.88 was discovered to contain a command injection vulnerability via the c4-IPAddr parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-03T13:16:02Z" diff --git a/advisories/unreviewed/2024/04/GHSA-rr9m-5jgg-qrvf/GHSA-rr9m-5jgg-qrvf.json b/advisories/unreviewed/2024/04/GHSA-rr9m-5jgg-qrvf/GHSA-rr9m-5jgg-qrvf.json index deac2d667c2..c2ffa3cf022 100644 --- a/advisories/unreviewed/2024/04/GHSA-rr9m-5jgg-qrvf/GHSA-rr9m-5jgg-qrvf.json +++ b/advisories/unreviewed/2024/04/GHSA-rr9m-5jgg-qrvf/GHSA-rr9m-5jgg-qrvf.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-w8pp-x465-w792/GHSA-w8pp-x465-w792.json b/advisories/unreviewed/2024/04/GHSA-w8pp-x465-w792/GHSA-w8pp-x465-w792.json index 1f7c9b13229..9350bc64d03 100644 --- a/advisories/unreviewed/2024/04/GHSA-w8pp-x465-w792/GHSA-w8pp-x465-w792.json +++ b/advisories/unreviewed/2024/04/GHSA-w8pp-x465-w792/GHSA-w8pp-x465-w792.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w8pp-x465-w792", - "modified": "2024-04-15T21:30:46Z", + "modified": "2024-08-21T18:31:25Z", "published": "2024-04-15T21:30:46Z", "aliases": [ "CVE-2024-28557" ], "details": "SQL Injection vulnerability in Sourcecodester php task management system v1.0, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via crafted payload to update-admin.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-15T19:15:09Z" diff --git a/advisories/unreviewed/2024/06/GHSA-4j99-4w4w-9ff3/GHSA-4j99-4w4w-9ff3.json b/advisories/unreviewed/2024/06/GHSA-4j99-4w4w-9ff3/GHSA-4j99-4w4w-9ff3.json index bfef0310be6..014883a0d70 100644 --- a/advisories/unreviewed/2024/06/GHSA-4j99-4w4w-9ff3/GHSA-4j99-4w4w-9ff3.json +++ b/advisories/unreviewed/2024/06/GHSA-4j99-4w4w-9ff3/GHSA-4j99-4w4w-9ff3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4j99-4w4w-9ff3", - "modified": "2024-06-17T21:31:10Z", + "modified": "2024-08-21T18:31:26Z", "published": "2024-06-17T21:31:10Z", "aliases": [ "CVE-2024-37828" ], "details": "A stored cross-site scripting (XSS) in Vermeg Agile Reporter v23.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Message field under the Set Broadcast Message module.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-17T21:15:51Z" diff --git a/advisories/unreviewed/2024/06/GHSA-5vhq-c669-fmgr/GHSA-5vhq-c669-fmgr.json b/advisories/unreviewed/2024/06/GHSA-5vhq-c669-fmgr/GHSA-5vhq-c669-fmgr.json index d5d4628a77f..f7825541209 100644 --- a/advisories/unreviewed/2024/06/GHSA-5vhq-c669-fmgr/GHSA-5vhq-c669-fmgr.json +++ b/advisories/unreviewed/2024/06/GHSA-5vhq-c669-fmgr/GHSA-5vhq-c669-fmgr.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-1288", "CWE-787" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/06/GHSA-68j3-86cc-wp27/GHSA-68j3-86cc-wp27.json b/advisories/unreviewed/2024/06/GHSA-68j3-86cc-wp27/GHSA-68j3-86cc-wp27.json index 5c8aece2db2..28b07c1e8ad 100644 --- a/advisories/unreviewed/2024/06/GHSA-68j3-86cc-wp27/GHSA-68j3-86cc-wp27.json +++ b/advisories/unreviewed/2024/06/GHSA-68j3-86cc-wp27/GHSA-68j3-86cc-wp27.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-68j3-86cc-wp27", - "modified": "2024-06-12T15:31:45Z", + "modified": "2024-08-21T18:31:26Z", "published": "2024-06-12T15:31:45Z", "aliases": [ "CVE-2024-36691" ], "details": "Insecure permissions in the AdminController.AjaxSave() method of PPGo_Jobs v2.8.0 allows authenticated attackers to arbitrarily modify users' account information.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-277" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-12T15:15:52Z" diff --git a/advisories/unreviewed/2024/06/GHSA-6qp2-4fq6-h4pv/GHSA-6qp2-4fq6-h4pv.json b/advisories/unreviewed/2024/06/GHSA-6qp2-4fq6-h4pv/GHSA-6qp2-4fq6-h4pv.json index fec57b77bc8..ea19c054134 100644 --- a/advisories/unreviewed/2024/06/GHSA-6qp2-4fq6-h4pv/GHSA-6qp2-4fq6-h4pv.json +++ b/advisories/unreviewed/2024/06/GHSA-6qp2-4fq6-h4pv/GHSA-6qp2-4fq6-h4pv.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-1288", "CWE-787" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/06/GHSA-c56c-hf5f-5xjh/GHSA-c56c-hf5f-5xjh.json b/advisories/unreviewed/2024/06/GHSA-c56c-hf5f-5xjh/GHSA-c56c-hf5f-5xjh.json index 0bbf3065564..4a7fe2bbe86 100644 --- a/advisories/unreviewed/2024/06/GHSA-c56c-hf5f-5xjh/GHSA-c56c-hf5f-5xjh.json +++ b/advisories/unreviewed/2024/06/GHSA-c56c-hf5f-5xjh/GHSA-c56c-hf5f-5xjh.json @@ -40,7 +40,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-426" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-mhj4-vrcv-x4xc/GHSA-mhj4-vrcv-x4xc.json b/advisories/unreviewed/2024/06/GHSA-mhj4-vrcv-x4xc/GHSA-mhj4-vrcv-x4xc.json index a3920fb787b..1ff82b82f8d 100644 --- a/advisories/unreviewed/2024/06/GHSA-mhj4-vrcv-x4xc/GHSA-mhj4-vrcv-x4xc.json +++ b/advisories/unreviewed/2024/06/GHSA-mhj4-vrcv-x4xc/GHSA-mhj4-vrcv-x4xc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mhj4-vrcv-x4xc", - "modified": "2024-06-10T15:31:02Z", + "modified": "2024-08-21T18:31:26Z", "published": "2024-06-10T15:31:02Z", "aliases": [ "CVE-2024-36528" ], "details": "nukeviet v.4.5 and before and nukeviet-egov v.1.2.02 and before have a Deserialization vulnerability which results in code execution via /admin/extensions/download.php and /admin/extensions/upload.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-502" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-10T15:15:52Z" diff --git a/advisories/unreviewed/2024/07/GHSA-25v2-v763-x228/GHSA-25v2-v763-x228.json b/advisories/unreviewed/2024/07/GHSA-25v2-v763-x228/GHSA-25v2-v763-x228.json index 5e253b0b9c0..61cbf93a848 100644 --- a/advisories/unreviewed/2024/07/GHSA-25v2-v763-x228/GHSA-25v2-v763-x228.json +++ b/advisories/unreviewed/2024/07/GHSA-25v2-v763-x228/GHSA-25v2-v763-x228.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-25v2-v763-x228", - "modified": "2024-07-12T15:31:30Z", + "modified": "2024-08-21T18:31:26Z", "published": "2024-07-12T15:31:30Z", "aliases": [ "CVE-2024-41001" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nio_uring/sqpoll: work around a potential audit memory leak\n\nkmemleak complains that there's a memory leak related to connect\nhandling:\n\nunreferenced object 0xffff0001093bdf00 (size 128):\ncomm \"iou-sqp-455\", pid 457, jiffies 4294894164\nhex dump (first 32 bytes):\n02 00 fa ea 7f 00 00 01 00 00 00 00 00 00 00 00 ................\n00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\nbacktrace (crc 2e481b1a):\n[<00000000c0a26af4>] kmemleak_alloc+0x30/0x38\n[<000000009c30bb45>] kmalloc_trace+0x228/0x358\n[<000000009da9d39f>] __audit_sockaddr+0xd0/0x138\n[<0000000089a93e34>] move_addr_to_kernel+0x1a0/0x1f8\n[<000000000b4e80e6>] io_connect_prep+0x1ec/0x2d4\n[<00000000abfbcd99>] io_submit_sqes+0x588/0x1e48\n[<00000000e7c25e07>] io_sq_thread+0x8a4/0x10e4\n[<00000000d999b491>] ret_from_fork+0x10/0x20\n\nwhich can can happen if:\n\n1) The command type does something on the prep side that triggers an\n audit call.\n2) The thread hasn't done any operations before this that triggered\n an audit call inside ->issue(), where we have audit_uring_entry()\n and audit_uring_exit().\n\nWork around this by issuing a blanket NOP operation before the SQPOLL\ndoes anything.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-401" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-12T13:15:21Z" diff --git a/advisories/unreviewed/2024/07/GHSA-26wc-mjpc-3f8m/GHSA-26wc-mjpc-3f8m.json b/advisories/unreviewed/2024/07/GHSA-26wc-mjpc-3f8m/GHSA-26wc-mjpc-3f8m.json index c26938da369..cf6dcbcb858 100644 --- a/advisories/unreviewed/2024/07/GHSA-26wc-mjpc-3f8m/GHSA-26wc-mjpc-3f8m.json +++ b/advisories/unreviewed/2024/07/GHSA-26wc-mjpc-3f8m/GHSA-26wc-mjpc-3f8m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-26wc-mjpc-3f8m", - "modified": "2024-07-02T21:32:16Z", + "modified": "2024-08-21T18:31:26Z", "published": "2024-07-02T21:32:16Z", "aliases": [ "CVE-2022-25477" ], "details": "Vulnerability in Realtek RtsPer driver for PCIe Card Reader (RtsPer.sys) before 10.0.22000.21355 and Realtek RtsUer driver for USB Card Reader (RtsUer.sys) before 10.0.22000.31274 leaks driver logs that contain addresses of kernel mode objects, weakening KASLR.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-532" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-02T19:15:11Z" diff --git a/advisories/unreviewed/2024/07/GHSA-3f2p-5jcv-cffx/GHSA-3f2p-5jcv-cffx.json b/advisories/unreviewed/2024/07/GHSA-3f2p-5jcv-cffx/GHSA-3f2p-5jcv-cffx.json index 23a839d2b09..c3a7feb557f 100644 --- a/advisories/unreviewed/2024/07/GHSA-3f2p-5jcv-cffx/GHSA-3f2p-5jcv-cffx.json +++ b/advisories/unreviewed/2024/07/GHSA-3f2p-5jcv-cffx/GHSA-3f2p-5jcv-cffx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3f2p-5jcv-cffx", - "modified": "2024-07-12T15:31:29Z", + "modified": "2024-08-21T18:31:26Z", "published": "2024-07-12T15:31:29Z", "aliases": [ "CVE-2024-40995" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: act_api: fix possible infinite loop in tcf_idr_check_alloc()\n\nsyzbot found hanging tasks waiting on rtnl_lock [1]\n\nA reproducer is available in the syzbot bug.\n\nWhen a request to add multiple actions with the same index is sent, the\nsecond request will block forever on the first request. This holds\nrtnl_lock, and causes tasks to hang.\n\nReturn -EAGAIN to prevent infinite looping, while keeping documented\nbehavior.\n\n[1]\n\nINFO: task kworker/1:0:5088 blocked for more than 143 seconds.\nNot tainted 6.9.0-rc4-syzkaller-00173-g3cdb45594619 #0\n\"echo 0 > /proc/sys/kernel/hung_task_timeout_secs\" disables this message.\ntask:kworker/1:0 state:D stack:23744 pid:5088 tgid:5088 ppid:2 flags:0x00004000\nWorkqueue: events_power_efficient reg_check_chans_work\nCall Trace:\n\ncontext_switch kernel/sched/core.c:5409 [inline]\n__schedule+0xf15/0x5d00 kernel/sched/core.c:6746\n__schedule_loop kernel/sched/core.c:6823 [inline]\nschedule+0xe7/0x350 kernel/sched/core.c:6838\nschedule_preempt_disabled+0x13/0x30 kernel/sched/core.c:6895\n__mutex_lock_common kernel/locking/mutex.c:684 [inline]\n__mutex_lock+0x5b8/0x9c0 kernel/locking/mutex.c:752\nwiphy_lock include/net/cfg80211.h:5953 [inline]\nreg_leave_invalid_chans net/wireless/reg.c:2466 [inline]\nreg_check_chans_work+0x10a/0x10e0 net/wireless/reg.c:2481", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -49,9 +52,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-835" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-12T13:15:20Z" diff --git a/advisories/unreviewed/2024/07/GHSA-3h4r-2q6q-wfr8/GHSA-3h4r-2q6q-wfr8.json b/advisories/unreviewed/2024/07/GHSA-3h4r-2q6q-wfr8/GHSA-3h4r-2q6q-wfr8.json index 8d168e18314..9a94e40880c 100644 --- a/advisories/unreviewed/2024/07/GHSA-3h4r-2q6q-wfr8/GHSA-3h4r-2q6q-wfr8.json +++ b/advisories/unreviewed/2024/07/GHSA-3h4r-2q6q-wfr8/GHSA-3h4r-2q6q-wfr8.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-45vp-vx4c-9jr2/GHSA-45vp-vx4c-9jr2.json b/advisories/unreviewed/2024/07/GHSA-45vp-vx4c-9jr2/GHSA-45vp-vx4c-9jr2.json index b1c4522d015..e335bf399e2 100644 --- a/advisories/unreviewed/2024/07/GHSA-45vp-vx4c-9jr2/GHSA-45vp-vx4c-9jr2.json +++ b/advisories/unreviewed/2024/07/GHSA-45vp-vx4c-9jr2/GHSA-45vp-vx4c-9jr2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-45vp-vx4c-9jr2", - "modified": "2024-07-16T12:30:39Z", + "modified": "2024-08-21T18:31:26Z", "published": "2024-07-16T12:30:38Z", "aliases": [ "CVE-2022-48779" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: mscc: ocelot: fix use-after-free in ocelot_vlan_del()\n\nocelot_vlan_member_del() will free the struct ocelot_bridge_vlan, so if\nthis is the same as the port's pvid_vlan which we access afterwards,\nwhat we're accessing is freed memory.\n\nFix the bug by determining whether to clear ocelot_port->pvid_vlan prior\nto calling ocelot_vlan_member_del().", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-16T12:15:03Z" diff --git a/advisories/unreviewed/2024/07/GHSA-4fch-r62j-4r94/GHSA-4fch-r62j-4r94.json b/advisories/unreviewed/2024/07/GHSA-4fch-r62j-4r94/GHSA-4fch-r62j-4r94.json index bd05399ba75..900dd63e903 100644 --- a/advisories/unreviewed/2024/07/GHSA-4fch-r62j-4r94/GHSA-4fch-r62j-4r94.json +++ b/advisories/unreviewed/2024/07/GHSA-4fch-r62j-4r94/GHSA-4fch-r62j-4r94.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4fch-r62j-4r94", - "modified": "2024-07-16T09:30:39Z", + "modified": "2024-08-21T18:31:26Z", "published": "2024-07-16T09:30:39Z", "aliases": [ "CVE-2024-3779" diff --git a/advisories/unreviewed/2024/07/GHSA-4p9w-ppgq-rm99/GHSA-4p9w-ppgq-rm99.json b/advisories/unreviewed/2024/07/GHSA-4p9w-ppgq-rm99/GHSA-4p9w-ppgq-rm99.json index 755087c4014..395f64871e5 100644 --- a/advisories/unreviewed/2024/07/GHSA-4p9w-ppgq-rm99/GHSA-4p9w-ppgq-rm99.json +++ b/advisories/unreviewed/2024/07/GHSA-4p9w-ppgq-rm99/GHSA-4p9w-ppgq-rm99.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4p9w-ppgq-rm99", - "modified": "2024-07-12T15:31:29Z", + "modified": "2024-08-21T18:31:26Z", "published": "2024-07-12T15:31:29Z", "aliases": [ "CVE-2024-40997" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncpufreq: amd-pstate: fix memory leak on CPU EPP exit\n\nThe cpudata memory from kzalloc() in amd_pstate_epp_cpu_init() is\nnot freed in the analogous exit function, so fix that.\n\n[ rjw: Subject and changelog edits ]", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-401" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-12T13:15:20Z" diff --git a/advisories/unreviewed/2024/07/GHSA-4qj8-cj7g-gfmf/GHSA-4qj8-cj7g-gfmf.json b/advisories/unreviewed/2024/07/GHSA-4qj8-cj7g-gfmf/GHSA-4qj8-cj7g-gfmf.json index 13f4cdefe8d..af83d649779 100644 --- a/advisories/unreviewed/2024/07/GHSA-4qj8-cj7g-gfmf/GHSA-4qj8-cj7g-gfmf.json +++ b/advisories/unreviewed/2024/07/GHSA-4qj8-cj7g-gfmf/GHSA-4qj8-cj7g-gfmf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4qj8-cj7g-gfmf", - "modified": "2024-07-04T21:30:50Z", + "modified": "2024-08-21T18:31:26Z", "published": "2024-07-04T21:30:50Z", "aliases": [ "CVE-2024-39935" ], "details": "jc21 NGINX Proxy Manager before 2.11.3 allows backend/internal/certificate.js OS command injection by an authenticated user (with certificate management privileges) via untrusted input to the DNS provider configuration. NOTE: this is not part of any NGINX software shipped by F5.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-04T21:15:10Z" diff --git a/advisories/unreviewed/2024/07/GHSA-5x23-w3hg-qfcx/GHSA-5x23-w3hg-qfcx.json b/advisories/unreviewed/2024/07/GHSA-5x23-w3hg-qfcx/GHSA-5x23-w3hg-qfcx.json index 8d8232fddb4..16c4000331f 100644 --- a/advisories/unreviewed/2024/07/GHSA-5x23-w3hg-qfcx/GHSA-5x23-w3hg-qfcx.json +++ b/advisories/unreviewed/2024/07/GHSA-5x23-w3hg-qfcx/GHSA-5x23-w3hg-qfcx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5x23-w3hg-qfcx", - "modified": "2024-07-12T15:31:29Z", + "modified": "2024-08-21T18:31:26Z", "published": "2024-07-12T15:31:29Z", "aliases": [ "CVE-2024-40996" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Avoid splat in pskb_pull_reason\n\nsyzkaller builds (CONFIG_DEBUG_NET=y) frequently trigger a debug\nhint in pskb_may_pull.\n\nWe'd like to retain this debug check because it might hint at integer\noverflows and other issues (kernel code should pull headers, not huge\nvalue).\n\nIn bpf case, this splat isn't interesting at all: such (nonsensical)\nbpf programs are typically generated by a fuzzer anyway.\n\nDo what Eric suggested and suppress such warning.\n\nFor CONFIG_DEBUG_NET=n we don't need the extra check because\npskb_may_pull will do the right thing: return an error without the\nWARN() backtrace.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -39,7 +42,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-12T13:15:20Z" diff --git a/advisories/unreviewed/2024/07/GHSA-72v6-vmr5-v9qf/GHSA-72v6-vmr5-v9qf.json b/advisories/unreviewed/2024/07/GHSA-72v6-vmr5-v9qf/GHSA-72v6-vmr5-v9qf.json index f8c8c35a2c7..4507b0e3e0a 100644 --- a/advisories/unreviewed/2024/07/GHSA-72v6-vmr5-v9qf/GHSA-72v6-vmr5-v9qf.json +++ b/advisories/unreviewed/2024/07/GHSA-72v6-vmr5-v9qf/GHSA-72v6-vmr5-v9qf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-72v6-vmr5-v9qf", - "modified": "2024-07-16T12:30:38Z", + "modified": "2024-08-21T18:31:26Z", "published": "2024-07-16T12:30:38Z", "aliases": [ "CVE-2022-48777" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmtd: parsers: qcom: Fix kernel panic on skipped partition\n\nIn the event of a skipped partition (case when the entry name is empty)\nthe kernel panics in the cleanup function as the name entry is NULL.\nRework the parser logic by first checking the real partition number and\nthen allocate the space and set the data for the valid partitions.\n\nThe logic was also fundamentally wrong as with a skipped partition, the\nparts number returned was incorrect by not decreasing it for the skipped\npartitions.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-16T12:15:02Z" diff --git a/advisories/unreviewed/2024/07/GHSA-73px-657p-5pqg/GHSA-73px-657p-5pqg.json b/advisories/unreviewed/2024/07/GHSA-73px-657p-5pqg/GHSA-73px-657p-5pqg.json index 7564685ed2f..a3bc5bf4fc0 100644 --- a/advisories/unreviewed/2024/07/GHSA-73px-657p-5pqg/GHSA-73px-657p-5pqg.json +++ b/advisories/unreviewed/2024/07/GHSA-73px-657p-5pqg/GHSA-73px-657p-5pqg.json @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-75c8-gq9f-5jv5/GHSA-75c8-gq9f-5jv5.json b/advisories/unreviewed/2024/07/GHSA-75c8-gq9f-5jv5/GHSA-75c8-gq9f-5jv5.json index 29d594dc185..2cae39583e7 100644 --- a/advisories/unreviewed/2024/07/GHSA-75c8-gq9f-5jv5/GHSA-75c8-gq9f-5jv5.json +++ b/advisories/unreviewed/2024/07/GHSA-75c8-gq9f-5jv5/GHSA-75c8-gq9f-5jv5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-75c8-gq9f-5jv5", - "modified": "2024-07-12T15:31:28Z", + "modified": "2024-08-21T18:31:26Z", "published": "2024-07-12T15:31:28Z", "aliases": [ "CVE-2024-40961" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: prevent possible NULL deref in fib6_nh_init()\n\nsyzbot reminds us that in6_dev_get() can return NULL.\n\nfib6_nh_init()\n ip6_validate_gw( &idev )\n ip6_route_check_nh( idev )\n *idev = in6_dev_get(dev); // can be NULL\n\nOops: general protection fault, probably for non-canonical address 0xdffffc00000000bc: 0000 [#1] PREEMPT SMP KASAN PTI\nKASAN: null-ptr-deref in range [0x00000000000005e0-0x00000000000005e7]\nCPU: 0 PID: 11237 Comm: syz-executor.3 Not tainted 6.10.0-rc2-syzkaller-00249-gbe27b8965297 #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 06/07/2024\n RIP: 0010:fib6_nh_init+0x640/0x2160 net/ipv6/route.c:3606\nCode: 00 00 fc ff df 4c 8b 64 24 58 48 8b 44 24 28 4c 8b 74 24 30 48 89 c1 48 89 44 24 28 48 8d 98 e0 05 00 00 48 89 d8 48 c1 e8 03 <42> 0f b6 04 38 84 c0 0f 85 b3 17 00 00 8b 1b 31 ff 89 de e8 b8 8b\nRSP: 0018:ffffc900032775a0 EFLAGS: 00010202\nRAX: 00000000000000bc RBX: 00000000000005e0 RCX: 0000000000000000\nRDX: 0000000000000010 RSI: ffffc90003277a54 RDI: ffff88802b3a08d8\nRBP: ffffc900032778b0 R08: 00000000000002fc R09: 0000000000000000\nR10: 00000000000002fc R11: 0000000000000000 R12: ffff88802b3a08b8\nR13: 1ffff9200064eec8 R14: ffffc90003277a00 R15: dffffc0000000000\nFS: 00007f940feb06c0(0000) GS:ffff8880b9400000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 0000000000000000 CR3: 00000000245e8000 CR4: 00000000003506f0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nCall Trace:\n \n ip6_route_info_create+0x99e/0x12b0 net/ipv6/route.c:3809\n ip6_route_add+0x28/0x160 net/ipv6/route.c:3853\n ipv6_route_ioctl+0x588/0x870 net/ipv6/route.c:4483\n inet6_ioctl+0x21a/0x280 net/ipv6/af_inet6.c:579\n sock_do_ioctl+0x158/0x460 net/socket.c:1222\n sock_ioctl+0x629/0x8e0 net/socket.c:1341\n vfs_ioctl fs/ioctl.c:51 [inline]\n __do_sys_ioctl fs/ioctl.c:907 [inline]\n __se_sys_ioctl+0xfc/0x170 fs/ioctl.c:893\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\nRIP: 0033:0x7f940f07cea9", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -49,9 +52,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-12T13:15:18Z" diff --git a/advisories/unreviewed/2024/07/GHSA-894g-hq68-4qh8/GHSA-894g-hq68-4qh8.json b/advisories/unreviewed/2024/07/GHSA-894g-hq68-4qh8/GHSA-894g-hq68-4qh8.json index 70734bbb482..5dea4624a24 100644 --- a/advisories/unreviewed/2024/07/GHSA-894g-hq68-4qh8/GHSA-894g-hq68-4qh8.json +++ b/advisories/unreviewed/2024/07/GHSA-894g-hq68-4qh8/GHSA-894g-hq68-4qh8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-894g-hq68-4qh8", - "modified": "2024-07-12T15:31:28Z", + "modified": "2024-08-21T18:31:26Z", "published": "2024-07-12T15:31:28Z", "aliases": [ "CVE-2024-40960" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: prevent possible NULL dereference in rt6_probe()\n\nsyzbot caught a NULL dereference in rt6_probe() [1]\n\nBail out if __in6_dev_get() returns NULL.\n\n[1]\nOops: general protection fault, probably for non-canonical address 0xdffffc00000000cb: 0000 [#1] PREEMPT SMP KASAN PTI\nKASAN: null-ptr-deref in range [0x0000000000000658-0x000000000000065f]\nCPU: 1 PID: 22444 Comm: syz-executor.0 Not tainted 6.10.0-rc2-syzkaller-00383-gb8481381d4e2 #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 04/02/2024\n RIP: 0010:rt6_probe net/ipv6/route.c:656 [inline]\n RIP: 0010:find_match+0x8c4/0xf50 net/ipv6/route.c:758\nCode: 14 fd f7 48 8b 85 38 ff ff ff 48 c7 45 b0 00 00 00 00 48 8d b8 5c 06 00 00 48 b8 00 00 00 00 00 fc ff df 48 89 fa 48 c1 ea 03 <0f> b6 14 02 48 89 f8 83 e0 07 83 c0 03 38 d0 7c 08 84 d2 0f 85 19\nRSP: 0018:ffffc900034af070 EFLAGS: 00010203\nRAX: dffffc0000000000 RBX: 0000000000000000 RCX: ffffc90004521000\nRDX: 00000000000000cb RSI: ffffffff8990d0cd RDI: 000000000000065c\nRBP: ffffc900034af150 R08: 0000000000000005 R09: 0000000000000000\nR10: 0000000000000001 R11: 0000000000000002 R12: 000000000000000a\nR13: 1ffff92000695e18 R14: ffff8880244a1d20 R15: 0000000000000000\nFS: 00007f4844a5a6c0(0000) GS:ffff8880b9300000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 0000001b31b27000 CR3: 000000002d42c000 CR4: 00000000003506f0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nCall Trace:\n \n rt6_nh_find_match+0xfa/0x1a0 net/ipv6/route.c:784\n nexthop_for_each_fib6_nh+0x26d/0x4a0 net/ipv4/nexthop.c:1496\n __find_rr_leaf+0x6e7/0xe00 net/ipv6/route.c:825\n find_rr_leaf net/ipv6/route.c:853 [inline]\n rt6_select net/ipv6/route.c:897 [inline]\n fib6_table_lookup+0x57e/0xa30 net/ipv6/route.c:2195\n ip6_pol_route+0x1cd/0x1150 net/ipv6/route.c:2231\n pol_lookup_func include/net/ip6_fib.h:616 [inline]\n fib6_rule_lookup+0x386/0x720 net/ipv6/fib6_rules.c:121\n ip6_route_output_flags_noref net/ipv6/route.c:2639 [inline]\n ip6_route_output_flags+0x1d0/0x640 net/ipv6/route.c:2651\n ip6_dst_lookup_tail.constprop.0+0x961/0x1760 net/ipv6/ip6_output.c:1147\n ip6_dst_lookup_flow+0x99/0x1d0 net/ipv6/ip6_output.c:1250\n rawv6_sendmsg+0xdab/0x4340 net/ipv6/raw.c:898\n inet_sendmsg+0x119/0x140 net/ipv4/af_inet.c:853\n sock_sendmsg_nosec net/socket.c:730 [inline]\n __sock_sendmsg net/socket.c:745 [inline]\n sock_write_iter+0x4b8/0x5c0 net/socket.c:1160\n new_sync_write fs/read_write.c:497 [inline]\n vfs_write+0x6b6/0x1140 fs/read_write.c:590\n ksys_write+0x1f8/0x260 fs/read_write.c:643\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xcd/0x250 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-12T13:15:18Z" diff --git a/advisories/unreviewed/2024/07/GHSA-9v24-vr9v-j466/GHSA-9v24-vr9v-j466.json b/advisories/unreviewed/2024/07/GHSA-9v24-vr9v-j466/GHSA-9v24-vr9v-j466.json index fdec2c82722..b9a0496feef 100644 --- a/advisories/unreviewed/2024/07/GHSA-9v24-vr9v-j466/GHSA-9v24-vr9v-j466.json +++ b/advisories/unreviewed/2024/07/GHSA-9v24-vr9v-j466/GHSA-9v24-vr9v-j466.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9v24-vr9v-j466", - "modified": "2024-07-16T12:30:39Z", + "modified": "2024-08-21T18:31:26Z", "published": "2024-07-16T12:30:39Z", "aliases": [ "CVE-2022-48781" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: af_alg - get rid of alg_memory_allocated\n\nalg_memory_allocated does not seem to be really used.\n\nalg_proto does have a .memory_allocated field, but no\ncorresponding .sysctl_mem.\n\nThis means sk_has_account() returns true, but all sk_prot_mem_limits()\nusers will trigger a NULL dereference [1].\n\nTHis was not a problem until SO_RESERVE_MEM addition.\n\ngeneral protection fault, probably for non-canonical address 0xdffffc0000000001: 0000 [#1] PREEMPT SMP KASAN\nKASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f]\nCPU: 1 PID: 3591 Comm: syz-executor153 Not tainted 5.17.0-rc3-syzkaller-00316-gb81b1829e7e3 #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011\nRIP: 0010:sk_prot_mem_limits include/net/sock.h:1523 [inline]\nRIP: 0010:sock_reserve_memory+0x1d7/0x330 net/core/sock.c:1000\nCode: 08 00 74 08 48 89 ef e8 27 20 bb f9 4c 03 7c 24 10 48 8b 6d 00 48 83 c5 08 48 89 e8 48 c1 e8 03 48 b9 00 00 00 00 00 fc ff df <80> 3c 08 00 74 08 48 89 ef e8 fb 1f bb f9 48 8b 6d 00 4c 89 ff 48\nRSP: 0018:ffffc90001f1fb68 EFLAGS: 00010202\nRAX: 0000000000000001 RBX: ffff88814aabc000 RCX: dffffc0000000000\nRDX: 0000000000000001 RSI: 0000000000000008 RDI: ffffffff90e18120\nRBP: 0000000000000008 R08: dffffc0000000000 R09: fffffbfff21c3025\nR10: fffffbfff21c3025 R11: 0000000000000000 R12: ffffffff8d109840\nR13: 0000000000001002 R14: 0000000000000001 R15: 0000000000000001\nFS: 0000555556e08300(0000) GS:ffff8880b9b00000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007fc74416f130 CR3: 0000000073d9e000 CR4: 00000000003506e0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nCall Trace:\n \n sock_setsockopt+0x14a9/0x3a30 net/core/sock.c:1446\n __sys_setsockopt+0x5af/0x980 net/socket.c:2176\n __do_sys_setsockopt net/socket.c:2191 [inline]\n __se_sys_setsockopt net/socket.c:2188 [inline]\n __x64_sys_setsockopt+0xb1/0xc0 net/socket.c:2188\n do_syscall_x64 arch/x86/entry/common.c:50 [inline]\n do_syscall_64+0x44/0xd0 arch/x86/entry/common.c:80\n entry_SYSCALL_64_after_hwframe+0x44/0xae\nRIP: 0033:0x7fc7440fddc9\nCode: 28 00 00 00 75 05 48 83 c4 28 c3 e8 51 15 00 00 90 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 c0 ff ff ff f7 d8 64 89 01 48\nRSP: 002b:00007ffe98f07968 EFLAGS: 00000246 ORIG_RAX: 0000000000000036\nRAX: ffffffffffffffda RBX: 0000000000000003 RCX: 00007fc7440fddc9\nRDX: 0000000000000049 RSI: 0000000000000001 RDI: 0000000000000004\nRBP: 0000000000000000 R08: 0000000000000004 R09: 00007ffe98f07990\nR10: 0000000020000000 R11: 0000000000000246 R12: 00007ffe98f0798c\nR13: 00007ffe98f079a0 R14: 00007ffe98f079e0 R15: 0000000000000000\n \nModules linked in:\n---[ end trace 0000000000000000 ]---\nRIP: 0010:sk_prot_mem_limits include/net/sock.h:1523 [inline]\nRIP: 0010:sock_reserve_memory+0x1d7/0x330 net/core/sock.c:1000\nCode: 08 00 74 08 48 89 ef e8 27 20 bb f9 4c 03 7c 24 10 48 8b 6d 00 48 83 c5 08 48 89 e8 48 c1 e8 03 48 b9 00 00 00 00 00 fc ff df <80> 3c 08 00 74 08 48 89 ef e8 fb 1f bb f9 48 8b 6d 00 4c 89 ff 48\nRSP: 0018:ffffc90001f1fb68 EFLAGS: 00010202\nRAX: 0000000000000001 RBX: ffff88814aabc000 RCX: dffffc0000000000\nRDX: 0000000000000001 RSI: 0000000000000008 RDI: ffffffff90e18120\nRBP: 0000000000000008 R08: dffffc0000000000 R09: fffffbfff21c3025\nR10: fffffbfff21c3025 R11: 0000000000000000 R12: ffffffff8d109840\nR13: 0000000000001002 R14: 0000000000000001 R15: 0000000000000001\nFS: 0000555556e08300(0000) GS:ffff8880b9b00000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007fc74416f130 CR3: 0000000073d9e000 CR4: 00000000003506e0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-16T12:15:03Z" diff --git a/advisories/unreviewed/2024/07/GHSA-cgvj-gwgx-p5f7/GHSA-cgvj-gwgx-p5f7.json b/advisories/unreviewed/2024/07/GHSA-cgvj-gwgx-p5f7/GHSA-cgvj-gwgx-p5f7.json index e40f089da0b..290d24f84b0 100644 --- a/advisories/unreviewed/2024/07/GHSA-cgvj-gwgx-p5f7/GHSA-cgvj-gwgx-p5f7.json +++ b/advisories/unreviewed/2024/07/GHSA-cgvj-gwgx-p5f7/GHSA-cgvj-gwgx-p5f7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cgvj-gwgx-p5f7", - "modified": "2024-07-16T12:30:40Z", + "modified": "2024-08-21T18:31:27Z", "published": "2024-07-16T12:30:40Z", "aliases": [ "CVE-2022-48800" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm: vmscan: remove deadlock due to throttling failing to make progress\n\nA soft lockup bug in kcompactd was reported in a private bugzilla with\nthe following visible in dmesg;\n\n watchdog: BUG: soft lockup - CPU#33 stuck for 26s! [kcompactd0:479]\n watchdog: BUG: soft lockup - CPU#33 stuck for 52s! [kcompactd0:479]\n watchdog: BUG: soft lockup - CPU#33 stuck for 78s! [kcompactd0:479]\n watchdog: BUG: soft lockup - CPU#33 stuck for 104s! [kcompactd0:479]\n\nThe machine had 256G of RAM with no swap and an earlier failed\nallocation indicated that node 0 where kcompactd was run was potentially\nunreclaimable;\n\n Node 0 active_anon:29355112kB inactive_anon:2913528kB active_file:0kB\n inactive_file:0kB unevictable:64kB isolated(anon):0kB isolated(file):0kB\n mapped:8kB dirty:0kB writeback:0kB shmem:26780kB shmem_thp:\n 0kB shmem_pmdmapped: 0kB anon_thp: 23480320kB writeback_tmp:0kB\n kernel_stack:2272kB pagetables:24500kB all_unreclaimable? yes\n\nVlastimil Babka investigated a crash dump and found that a task\nmigrating pages was trying to drain PCP lists;\n\n PID: 52922 TASK: ffff969f820e5000 CPU: 19 COMMAND: \"kworker/u128:3\"\n Call Trace:\n __schedule\n schedule\n schedule_timeout\n wait_for_completion\n __flush_work\n __drain_all_pages\n __alloc_pages_slowpath.constprop.114\n __alloc_pages\n alloc_migration_target\n migrate_pages\n migrate_to_node\n do_migrate_pages\n cpuset_migrate_mm_workfn\n process_one_work\n worker_thread\n kthread\n ret_from_fork\n\nThis failure is specific to CONFIG_PREEMPT=n builds. The root of the\nproblem is that kcompact0 is not rescheduling on a CPU while a task that\nhas isolated a large number of the pages from the LRU is waiting on\nkcompact0 to reschedule so the pages can be released. While\nshrink_inactive_list() only loops once around too_many_isolated, reclaim\ncan continue without rescheduling if sc->skipped_deactivate == 1 which\ncould happen if there was no file LRU and the inactive anon list was not\nlow.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-667" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-16T12:15:04Z" diff --git a/advisories/unreviewed/2024/07/GHSA-fpf5-xw2p-f3m5/GHSA-fpf5-xw2p-f3m5.json b/advisories/unreviewed/2024/07/GHSA-fpf5-xw2p-f3m5/GHSA-fpf5-xw2p-f3m5.json index 19983ce5fef..217bc259656 100644 --- a/advisories/unreviewed/2024/07/GHSA-fpf5-xw2p-f3m5/GHSA-fpf5-xw2p-f3m5.json +++ b/advisories/unreviewed/2024/07/GHSA-fpf5-xw2p-f3m5/GHSA-fpf5-xw2p-f3m5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fpf5-xw2p-f3m5", - "modified": "2024-07-12T15:31:29Z", + "modified": "2024-08-21T18:31:26Z", "published": "2024-07-12T15:31:29Z", "aliases": [ "CVE-2024-40994" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nptp: fix integer overflow in max_vclocks_store\n\nOn 32bit systems, the \"4 * max\" multiply can overflow. Use kcalloc()\nto do the allocation to prevent this.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-190" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-12T13:15:20Z" diff --git a/advisories/unreviewed/2024/07/GHSA-gfgx-m82f-4x3g/GHSA-gfgx-m82f-4x3g.json b/advisories/unreviewed/2024/07/GHSA-gfgx-m82f-4x3g/GHSA-gfgx-m82f-4x3g.json index f328d386d4d..0540562f662 100644 --- a/advisories/unreviewed/2024/07/GHSA-gfgx-m82f-4x3g/GHSA-gfgx-m82f-4x3g.json +++ b/advisories/unreviewed/2024/07/GHSA-gfgx-m82f-4x3g/GHSA-gfgx-m82f-4x3g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gfgx-m82f-4x3g", - "modified": "2024-07-12T15:31:29Z", + "modified": "2024-08-21T18:31:26Z", "published": "2024-07-12T15:31:29Z", "aliases": [ "CVE-2024-41000" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nblock/ioctl: prefer different overflow check\n\nRunning syzkaller with the newly reintroduced signed integer overflow\nsanitizer shows this report:\n\n[ 62.982337] ------------[ cut here ]------------\n[ 62.985692] cgroup: Invalid name\n[ 62.986211] UBSAN: signed-integer-overflow in ../block/ioctl.c:36:46\n[ 62.989370] 9pnet_fd: p9_fd_create_tcp (7343): problem connecting socket to 127.0.0.1\n[ 62.992992] 9223372036854775807 + 4095 cannot be represented in type 'long long'\n[ 62.997827] 9pnet_fd: p9_fd_create_tcp (7345): problem connecting socket to 127.0.0.1\n[ 62.999369] random: crng reseeded on system resumption\n[ 63.000634] GUP no longer grows the stack in syz-executor.2 (7353): 20002000-20003000 (20001000)\n[ 63.000668] CPU: 0 PID: 7353 Comm: syz-executor.2 Not tainted 6.8.0-rc2-00035-gb3ef86b5a957 #1\n[ 63.000677] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014\n[ 63.000682] Call Trace:\n[ 63.000686] \n[ 63.000731] dump_stack_lvl+0x93/0xd0\n[ 63.000919] __get_user_pages+0x903/0xd30\n[ 63.001030] __gup_longterm_locked+0x153e/0x1ba0\n[ 63.001041] ? _raw_read_unlock_irqrestore+0x17/0x50\n[ 63.001072] ? try_get_folio+0x29c/0x2d0\n[ 63.001083] internal_get_user_pages_fast+0x1119/0x1530\n[ 63.001109] iov_iter_extract_pages+0x23b/0x580\n[ 63.001206] bio_iov_iter_get_pages+0x4de/0x1220\n[ 63.001235] iomap_dio_bio_iter+0x9b6/0x1410\n[ 63.001297] __iomap_dio_rw+0xab4/0x1810\n[ 63.001316] iomap_dio_rw+0x45/0xa0\n[ 63.001328] ext4_file_write_iter+0xdde/0x1390\n[ 63.001372] vfs_write+0x599/0xbd0\n[ 63.001394] ksys_write+0xc8/0x190\n[ 63.001403] do_syscall_64+0xd4/0x1b0\n[ 63.001421] ? arch_exit_to_user_mode_prepare+0x3a/0x60\n[ 63.001479] entry_SYSCALL_64_after_hwframe+0x6f/0x77\n[ 63.001535] RIP: 0033:0x7f7fd3ebf539\n[ 63.001551] Code: 28 00 00 00 75 05 48 83 c4 28 c3 e8 f1 14 00 00 90 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b8 ff ff ff f7 d8 64 89 01 48\n[ 63.001562] RSP: 002b:00007f7fd32570c8 EFLAGS: 00000246 ORIG_RAX: 0000000000000001\n[ 63.001584] RAX: ffffffffffffffda RBX: 00007f7fd3ff3f80 RCX: 00007f7fd3ebf539\n[ 63.001590] RDX: 4db6d1e4f7e43360 RSI: 0000000020000000 RDI: 0000000000000004\n[ 63.001595] RBP: 00007f7fd3f1e496 R08: 0000000000000000 R09: 0000000000000000\n[ 63.001599] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000\n[ 63.001604] R13: 0000000000000006 R14: 00007f7fd3ff3f80 R15: 00007ffd415ad2b8\n...\n[ 63.018142] ---[ end trace ]---\n\nHistorically, the signed integer overflow sanitizer did not work in the\nkernel due to its interaction with `-fwrapv` but this has since been\nchanged [1] in the newest version of Clang; It was re-enabled in the\nkernel with Commit 557f8c582a9ba8ab (\"ubsan: Reintroduce signed overflow\nsanitizer\").\n\nLet's rework this overflow checking logic to not actually perform an\noverflow during the check itself, thus avoiding the UBSAN splat.\n\n[1]: https://github.com/llvm/llvm-project/pull/82432", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-190" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-12T13:15:20Z" diff --git a/advisories/unreviewed/2024/07/GHSA-gv9g-w43h-w5vw/GHSA-gv9g-w43h-w5vw.json b/advisories/unreviewed/2024/07/GHSA-gv9g-w43h-w5vw/GHSA-gv9g-w43h-w5vw.json index 90046fddbab..251f0e52bd9 100644 --- a/advisories/unreviewed/2024/07/GHSA-gv9g-w43h-w5vw/GHSA-gv9g-w43h-w5vw.json +++ b/advisories/unreviewed/2024/07/GHSA-gv9g-w43h-w5vw/GHSA-gv9g-w43h-w5vw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gv9g-w43h-w5vw", - "modified": "2024-07-16T12:30:38Z", + "modified": "2024-08-21T18:31:26Z", "published": "2024-07-16T12:30:38Z", "aliases": [ "CVE-2022-48773" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nxprtrdma: fix pointer derefs in error cases of rpcrdma_ep_create\n\nIf there are failures then we must not leave the non-NULL pointers with\nthe error value, otherwise `rpcrdma_ep_destroy` gets confused and tries\nfree them, resulting in an Oops.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-16T12:15:02Z" diff --git a/advisories/unreviewed/2024/07/GHSA-j53w-25v4-j86p/GHSA-j53w-25v4-j86p.json b/advisories/unreviewed/2024/07/GHSA-j53w-25v4-j86p/GHSA-j53w-25v4-j86p.json index b12fbf2ced0..c2e03c8d963 100644 --- a/advisories/unreviewed/2024/07/GHSA-j53w-25v4-j86p/GHSA-j53w-25v4-j86p.json +++ b/advisories/unreviewed/2024/07/GHSA-j53w-25v4-j86p/GHSA-j53w-25v4-j86p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j53w-25v4-j86p", - "modified": "2024-07-16T12:30:38Z", + "modified": "2024-08-21T18:31:26Z", "published": "2024-07-16T12:30:38Z", "aliases": [ "CVE-2021-47624" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sunrpc: fix reference count leaks in rpc_sysfs_xprt_state_change\n\nThe refcount leak issues take place in an error handling path. When the\n3rd argument buf doesn't match with \"offline\", \"online\" or \"remove\", the\nfunction simply returns -EINVAL and forgets to decrease the reference\ncount of a rpc_xprt object and a rpc_xprt_switch object increased by\nrpc_sysfs_xprt_kobj_get_xprt() and\nrpc_sysfs_xprt_kobj_get_xprt_switch(), causing reference count leaks of\nboth unused objects.\n\nFix this issue by jumping to the error handling path labelled with\nout_put when buf matches none of \"offline\", \"online\" or \"remove\".", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-16T12:15:02Z" diff --git a/advisories/unreviewed/2024/07/GHSA-m484-77r4-h4vf/GHSA-m484-77r4-h4vf.json b/advisories/unreviewed/2024/07/GHSA-m484-77r4-h4vf/GHSA-m484-77r4-h4vf.json index 707138d9458..eb8833f25dd 100644 --- a/advisories/unreviewed/2024/07/GHSA-m484-77r4-h4vf/GHSA-m484-77r4-h4vf.json +++ b/advisories/unreviewed/2024/07/GHSA-m484-77r4-h4vf/GHSA-m484-77r4-h4vf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m484-77r4-h4vf", - "modified": "2024-07-16T12:30:38Z", + "modified": "2024-08-21T18:31:26Z", "published": "2024-07-16T12:30:38Z", "aliases": [ "CVE-2021-47622" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: ufs: Fix a deadlock in the error handler\n\nThe following deadlock has been observed on a test setup:\n\n - All tags allocated\n\n - The SCSI error handler calls ufshcd_eh_host_reset_handler()\n\n - ufshcd_eh_host_reset_handler() queues work that calls\n ufshcd_err_handler()\n\n - ufshcd_err_handler() locks up as follows:\n\nWorkqueue: ufs_eh_wq_0 ufshcd_err_handler.cfi_jt\nCall trace:\n __switch_to+0x298/0x5d8\n __schedule+0x6cc/0xa94\n schedule+0x12c/0x298\n blk_mq_get_tag+0x210/0x480\n __blk_mq_alloc_request+0x1c8/0x284\n blk_get_request+0x74/0x134\n ufshcd_exec_dev_cmd+0x68/0x640\n ufshcd_verify_dev_init+0x68/0x35c\n ufshcd_probe_hba+0x12c/0x1cb8\n ufshcd_host_reset_and_restore+0x88/0x254\n ufshcd_reset_and_restore+0xd0/0x354\n ufshcd_err_handler+0x408/0xc58\n process_one_work+0x24c/0x66c\n worker_thread+0x3e8/0xa4c\n kthread+0x150/0x1b4\n ret_from_fork+0x10/0x30\n\nFix this lockup by making ufshcd_exec_dev_cmd() allocate a reserved\nrequest.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-667" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-16T12:15:02Z" diff --git a/advisories/unreviewed/2024/07/GHSA-p7rj-mgww-3q4f/GHSA-p7rj-mgww-3q4f.json b/advisories/unreviewed/2024/07/GHSA-p7rj-mgww-3q4f/GHSA-p7rj-mgww-3q4f.json index ff6b58201a2..0abd592994a 100644 --- a/advisories/unreviewed/2024/07/GHSA-p7rj-mgww-3q4f/GHSA-p7rj-mgww-3q4f.json +++ b/advisories/unreviewed/2024/07/GHSA-p7rj-mgww-3q4f/GHSA-p7rj-mgww-3q4f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p7rj-mgww-3q4f", - "modified": "2024-07-14T09:30:35Z", + "modified": "2024-08-21T18:31:26Z", "published": "2024-07-14T09:30:35Z", "aliases": [ "CVE-2023-52885" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nSUNRPC: Fix UAF in svc_tcp_listen_data_ready()\n\nAfter the listener svc_sock is freed, and before invoking svc_tcp_accept()\nfor the established child sock, there is a window that the newsock\nretaining a freed listener svc_sock in sk_user_data which cloning from\nparent. In the race window, if data is received on the newsock, we will\nobserve use-after-free report in svc_tcp_listen_data_ready().\n\nReproduce by two tasks:\n\n1. while :; do rpc.nfsd 0 ; rpc.nfsd; done\n2. while :; do echo \"\" | ncat -4 127.0.0.1 2049 ; done\n\nKASAN report:\n\n ==================================================================\n BUG: KASAN: slab-use-after-free in svc_tcp_listen_data_ready+0x1cf/0x1f0 [sunrpc]\n Read of size 8 at addr ffff888139d96228 by task nc/102553\n CPU: 7 PID: 102553 Comm: nc Not tainted 6.3.0+ #18\n Hardware name: VMware, Inc. VMware Virtual Platform/440BX Desktop Reference Platform, BIOS 6.00 11/12/2020\n Call Trace:\n \n dump_stack_lvl+0x33/0x50\n print_address_description.constprop.0+0x27/0x310\n print_report+0x3e/0x70\n kasan_report+0xae/0xe0\n svc_tcp_listen_data_ready+0x1cf/0x1f0 [sunrpc]\n tcp_data_queue+0x9f4/0x20e0\n tcp_rcv_established+0x666/0x1f60\n tcp_v4_do_rcv+0x51c/0x850\n tcp_v4_rcv+0x23fc/0x2e80\n ip_protocol_deliver_rcu+0x62/0x300\n ip_local_deliver_finish+0x267/0x350\n ip_local_deliver+0x18b/0x2d0\n ip_rcv+0x2fb/0x370\n __netif_receive_skb_one_core+0x166/0x1b0\n process_backlog+0x24c/0x5e0\n __napi_poll+0xa2/0x500\n net_rx_action+0x854/0xc90\n __do_softirq+0x1bb/0x5de\n do_softirq+0xcb/0x100\n \n \n ...\n \n\n Allocated by task 102371:\n kasan_save_stack+0x1e/0x40\n kasan_set_track+0x21/0x30\n __kasan_kmalloc+0x7b/0x90\n svc_setup_socket+0x52/0x4f0 [sunrpc]\n svc_addsock+0x20d/0x400 [sunrpc]\n __write_ports_addfd+0x209/0x390 [nfsd]\n write_ports+0x239/0x2c0 [nfsd]\n nfsctl_transaction_write+0xac/0x110 [nfsd]\n vfs_write+0x1c3/0xae0\n ksys_write+0xed/0x1c0\n do_syscall_64+0x38/0x90\n entry_SYSCALL_64_after_hwframe+0x72/0xdc\n\n Freed by task 102551:\n kasan_save_stack+0x1e/0x40\n kasan_set_track+0x21/0x30\n kasan_save_free_info+0x2a/0x50\n __kasan_slab_free+0x106/0x190\n __kmem_cache_free+0x133/0x270\n svc_xprt_free+0x1e2/0x350 [sunrpc]\n svc_xprt_destroy_all+0x25a/0x440 [sunrpc]\n nfsd_put+0x125/0x240 [nfsd]\n nfsd_svc+0x2cb/0x3c0 [nfsd]\n write_threads+0x1ac/0x2a0 [nfsd]\n nfsctl_transaction_write+0xac/0x110 [nfsd]\n vfs_write+0x1c3/0xae0\n ksys_write+0xed/0x1c0\n do_syscall_64+0x38/0x90\n entry_SYSCALL_64_after_hwframe+0x72/0xdc\n\nFix the UAF by simply doing nothing in svc_tcp_listen_data_ready()\nif state != TCP_LISTEN, that will avoid dereferencing svsk for all\nchild socket.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-14T08:15:01Z" diff --git a/advisories/unreviewed/2024/07/GHSA-pfpp-q6gh-6xmm/GHSA-pfpp-q6gh-6xmm.json b/advisories/unreviewed/2024/07/GHSA-pfpp-q6gh-6xmm/GHSA-pfpp-q6gh-6xmm.json index 53c215cf8cc..0552eb354a9 100644 --- a/advisories/unreviewed/2024/07/GHSA-pfpp-q6gh-6xmm/GHSA-pfpp-q6gh-6xmm.json +++ b/advisories/unreviewed/2024/07/GHSA-pfpp-q6gh-6xmm/GHSA-pfpp-q6gh-6xmm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pfpp-q6gh-6xmm", - "modified": "2024-07-12T15:31:28Z", + "modified": "2024-08-21T18:31:26Z", "published": "2024-07-12T15:31:28Z", "aliases": [ "CVE-2024-40952" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: fix NULL pointer dereference in ocfs2_journal_dirty()\n\nbdev->bd_super has been removed and commit 8887b94d9322 change the usage\nfrom bdev->bd_super to b_assoc_map->host->i_sb. This introduces the\nfollowing NULL pointer dereference in ocfs2_journal_dirty() since\nb_assoc_map is still not initialized. This can be easily reproduced by\nrunning xfstests generic/186, which simulate no more credits.\n\n[ 134.351592] BUG: kernel NULL pointer dereference, address: 0000000000000000\n...\n[ 134.355341] RIP: 0010:ocfs2_journal_dirty+0x14f/0x160 [ocfs2]\n...\n[ 134.365071] Call Trace:\n[ 134.365312] \n[ 134.365524] ? __die_body+0x1e/0x60\n[ 134.365868] ? page_fault_oops+0x13d/0x4f0\n[ 134.366265] ? __pfx_bit_wait_io+0x10/0x10\n[ 134.366659] ? schedule+0x27/0xb0\n[ 134.366981] ? exc_page_fault+0x6a/0x140\n[ 134.367356] ? asm_exc_page_fault+0x26/0x30\n[ 134.367762] ? ocfs2_journal_dirty+0x14f/0x160 [ocfs2]\n[ 134.368305] ? ocfs2_journal_dirty+0x13d/0x160 [ocfs2]\n[ 134.368837] ocfs2_create_new_meta_bhs.isra.51+0x139/0x2e0 [ocfs2]\n[ 134.369454] ocfs2_grow_tree+0x688/0x8a0 [ocfs2]\n[ 134.369927] ocfs2_split_and_insert.isra.67+0x35c/0x4a0 [ocfs2]\n[ 134.370521] ocfs2_split_extent+0x314/0x4d0 [ocfs2]\n[ 134.371019] ocfs2_change_extent_flag+0x174/0x410 [ocfs2]\n[ 134.371566] ocfs2_add_refcount_flag+0x3fa/0x630 [ocfs2]\n[ 134.372117] ocfs2_reflink_remap_extent+0x21b/0x4c0 [ocfs2]\n[ 134.372994] ? inode_update_timestamps+0x4a/0x120\n[ 134.373692] ? __pfx_ocfs2_journal_access_di+0x10/0x10 [ocfs2]\n[ 134.374545] ? __pfx_ocfs2_journal_access_di+0x10/0x10 [ocfs2]\n[ 134.375393] ocfs2_reflink_remap_blocks+0xe4/0x4e0 [ocfs2]\n[ 134.376197] ocfs2_remap_file_range+0x1de/0x390 [ocfs2]\n[ 134.376971] ? security_file_permission+0x29/0x50\n[ 134.377644] vfs_clone_file_range+0xfe/0x320\n[ 134.378268] ioctl_file_clone+0x45/0xa0\n[ 134.378853] do_vfs_ioctl+0x457/0x990\n[ 134.379422] __x64_sys_ioctl+0x6e/0xd0\n[ 134.379987] do_syscall_64+0x5d/0x170\n[ 134.380550] entry_SYSCALL_64_after_hwframe+0x76/0x7e\n[ 134.381231] RIP: 0033:0x7fa4926397cb\n[ 134.381786] Code: 73 01 c3 48 8b 0d bd 56 38 00 f7 d8 64 89 01 48 83 c8 ff c3 66 2e 0f 1f 84 00 00 00 00 00 90 f3 0f 1e fa b8 10 00 00 00 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 8b 0d 8d 56 38 00 f7 d8 64 89 01 48\n[ 134.383930] RSP: 002b:00007ffc2b39f7b8 EFLAGS: 00000246 ORIG_RAX: 0000000000000010\n[ 134.384854] RAX: ffffffffffffffda RBX: 0000000000000004 RCX: 00007fa4926397cb\n[ 134.385734] RDX: 00007ffc2b39f7f0 RSI: 000000004020940d RDI: 0000000000000003\n[ 134.386606] RBP: 0000000000000000 R08: 00111a82a4f015bb R09: 00007fa494221000\n[ 134.387476] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000\n[ 134.388342] R13: 0000000000f10000 R14: 0000558e844e2ac8 R15: 0000000000f10000\n[ 134.389207] \n\nFix it by only aborting transaction and journal in ocfs2_journal_dirty()\nnow, and leave ocfs2_abort() later when detecting an aborted handle,\ne.g. start next transaction. Also log the handle details in this case.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-12T13:15:17Z" diff --git a/advisories/unreviewed/2024/07/GHSA-pm35-jc42-34cq/GHSA-pm35-jc42-34cq.json b/advisories/unreviewed/2024/07/GHSA-pm35-jc42-34cq/GHSA-pm35-jc42-34cq.json index 0ad65c616c4..d2cdb5cbf0f 100644 --- a/advisories/unreviewed/2024/07/GHSA-pm35-jc42-34cq/GHSA-pm35-jc42-34cq.json +++ b/advisories/unreviewed/2024/07/GHSA-pm35-jc42-34cq/GHSA-pm35-jc42-34cq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pm35-jc42-34cq", - "modified": "2024-07-16T12:30:39Z", + "modified": "2024-08-21T18:31:26Z", "published": "2024-07-16T12:30:39Z", "aliases": [ "CVE-2022-48783" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: dsa: lantiq_gswip: fix use after free in gswip_remove()\n\nof_node_put(priv->ds->slave_mii_bus->dev.of_node) should be\ndone before mdiobus_free(priv->ds->slave_mii_bus).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-16T12:15:03Z" diff --git a/advisories/unreviewed/2024/07/GHSA-q8cp-9q2j-mfj8/GHSA-q8cp-9q2j-mfj8.json b/advisories/unreviewed/2024/07/GHSA-q8cp-9q2j-mfj8/GHSA-q8cp-9q2j-mfj8.json index e111b1e4f19..252ec2cf668 100644 --- a/advisories/unreviewed/2024/07/GHSA-q8cp-9q2j-mfj8/GHSA-q8cp-9q2j-mfj8.json +++ b/advisories/unreviewed/2024/07/GHSA-q8cp-9q2j-mfj8/GHSA-q8cp-9q2j-mfj8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q8cp-9q2j-mfj8", - "modified": "2024-07-18T12:30:51Z", + "modified": "2024-08-21T18:31:26Z", "published": "2024-07-09T12:30:56Z", "aliases": [ "CVE-2024-39487" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbonding: Fix out-of-bounds read in bond_option_arp_ip_targets_set()\n\nIn function bond_option_arp_ip_targets_set(), if newval->string is an\nempty string, newval->string+1 will point to the byte after the\nstring, causing an out-of-bound read.\n\nBUG: KASAN: slab-out-of-bounds in strlen+0x7d/0xa0 lib/string.c:418\nRead of size 1 at addr ffff8881119c4781 by task syz-executor665/8107\nCPU: 1 PID: 8107 Comm: syz-executor665 Not tainted 6.7.0-rc7 #1\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014\nCall Trace:\n \n __dump_stack lib/dump_stack.c:88 [inline]\n dump_stack_lvl+0xd9/0x150 lib/dump_stack.c:106\n print_address_description mm/kasan/report.c:364 [inline]\n print_report+0xc1/0x5e0 mm/kasan/report.c:475\n kasan_report+0xbe/0xf0 mm/kasan/report.c:588\n strlen+0x7d/0xa0 lib/string.c:418\n __fortify_strlen include/linux/fortify-string.h:210 [inline]\n in4_pton+0xa3/0x3f0 net/core/utils.c:130\n bond_option_arp_ip_targets_set+0xc2/0x910\ndrivers/net/bonding/bond_options.c:1201\n __bond_opt_set+0x2a4/0x1030 drivers/net/bonding/bond_options.c:767\n __bond_opt_set_notify+0x48/0x150 drivers/net/bonding/bond_options.c:792\n bond_opt_tryset_rtnl+0xda/0x160 drivers/net/bonding/bond_options.c:817\n bonding_sysfs_store_option+0xa1/0x120 drivers/net/bonding/bond_sysfs.c:156\n dev_attr_store+0x54/0x80 drivers/base/core.c:2366\n sysfs_kf_write+0x114/0x170 fs/sysfs/file.c:136\n kernfs_fop_write_iter+0x337/0x500 fs/kernfs/file.c:334\n call_write_iter include/linux/fs.h:2020 [inline]\n new_sync_write fs/read_write.c:491 [inline]\n vfs_write+0x96a/0xd80 fs/read_write.c:584\n ksys_write+0x122/0x250 fs/read_write.c:637\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0x40/0x110 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x63/0x6b\n---[ end trace ]---\n\nFix it by adding a check of string length before using it.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-09T10:15:04Z" diff --git a/advisories/unreviewed/2024/07/GHSA-qghh-pcqm-r2r3/GHSA-qghh-pcqm-r2r3.json b/advisories/unreviewed/2024/07/GHSA-qghh-pcqm-r2r3/GHSA-qghh-pcqm-r2r3.json index 41c3b88212c..18260792d72 100644 --- a/advisories/unreviewed/2024/07/GHSA-qghh-pcqm-r2r3/GHSA-qghh-pcqm-r2r3.json +++ b/advisories/unreviewed/2024/07/GHSA-qghh-pcqm-r2r3/GHSA-qghh-pcqm-r2r3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qghh-pcqm-r2r3", - "modified": "2024-07-12T15:31:30Z", + "modified": "2024-08-21T18:31:26Z", "published": "2024-07-12T15:31:30Z", "aliases": [ "CVE-2024-41002" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: hisilicon/sec - Fix memory leak for sec resource release\n\nThe AIV is one of the SEC resources. When releasing resources,\nit need to release the AIV resources at the same time.\nOtherwise, memory leakage occurs.\n\nThe aiv resource release is added to the sec resource release\nfunction.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-401" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-12T13:15:21Z" diff --git a/advisories/unreviewed/2024/07/GHSA-v29p-wgpj-c454/GHSA-v29p-wgpj-c454.json b/advisories/unreviewed/2024/07/GHSA-v29p-wgpj-c454/GHSA-v29p-wgpj-c454.json index 1967a4934a4..f7ce2e1426e 100644 --- a/advisories/unreviewed/2024/07/GHSA-v29p-wgpj-c454/GHSA-v29p-wgpj-c454.json +++ b/advisories/unreviewed/2024/07/GHSA-v29p-wgpj-c454/GHSA-v29p-wgpj-c454.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v29p-wgpj-c454", - "modified": "2024-07-16T12:30:39Z", + "modified": "2024-08-21T18:31:26Z", "published": "2024-07-16T12:30:39Z", "aliases": [ "CVE-2022-48782" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmctp: fix use after free\n\nClang static analysis reports this problem\nroute.c:425:4: warning: Use of memory after it is freed\n trace_mctp_key_acquire(key);\n ^~~~~~~~~~~~~~~~~~~~~~~~~~~\nWhen mctp_key_add() fails, key is freed but then is later\nused in trace_mctp_key_acquire(). Add an else statement\nto use the key only when mctp_key_add() is successful.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-16T12:15:03Z" diff --git a/advisories/unreviewed/2024/07/GHSA-vh56-6f64-v877/GHSA-vh56-6f64-v877.json b/advisories/unreviewed/2024/07/GHSA-vh56-6f64-v877/GHSA-vh56-6f64-v877.json index 80d3473489a..a610cf06dee 100644 --- a/advisories/unreviewed/2024/07/GHSA-vh56-6f64-v877/GHSA-vh56-6f64-v877.json +++ b/advisories/unreviewed/2024/07/GHSA-vh56-6f64-v877/GHSA-vh56-6f64-v877.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vh56-6f64-v877", - "modified": "2024-07-02T21:32:16Z", + "modified": "2024-08-21T18:31:26Z", "published": "2024-07-02T21:32:16Z", "aliases": [ "CVE-2022-25478" ], "details": "Vulnerability in Realtek RtsPer driver for PCIe Card Reader (RtsPer.sys) before 10.0.22000.21355 and Realtek RtsUer driver for USB Card Reader (RtsUer.sys) before 10.0.22000.31274 provides read and write access to the PCI configuration space of the device.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-02T19:15:11Z" diff --git a/advisories/unreviewed/2024/07/GHSA-w4wp-6c4p-vfjm/GHSA-w4wp-6c4p-vfjm.json b/advisories/unreviewed/2024/07/GHSA-w4wp-6c4p-vfjm/GHSA-w4wp-6c4p-vfjm.json index 8e882535a52..35c2b825a32 100644 --- a/advisories/unreviewed/2024/07/GHSA-w4wp-6c4p-vfjm/GHSA-w4wp-6c4p-vfjm.json +++ b/advisories/unreviewed/2024/07/GHSA-w4wp-6c4p-vfjm/GHSA-w4wp-6c4p-vfjm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w4wp-6c4p-vfjm", - "modified": "2024-07-16T12:30:39Z", + "modified": "2024-08-21T18:31:26Z", "published": "2024-07-16T12:30:38Z", "aliases": [ "CVE-2022-48778" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmtd: rawnand: gpmi: don't leak PM reference in error path\n\nIf gpmi_nfc_apply_timings() fails, the PM runtime usage counter must be\ndropped.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -43,7 +46,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-16T12:15:03Z" diff --git a/advisories/unreviewed/2024/07/GHSA-wp5v-h6j4-v39w/GHSA-wp5v-h6j4-v39w.json b/advisories/unreviewed/2024/07/GHSA-wp5v-h6j4-v39w/GHSA-wp5v-h6j4-v39w.json index c75dabe913e..d03be9349c7 100644 --- a/advisories/unreviewed/2024/07/GHSA-wp5v-h6j4-v39w/GHSA-wp5v-h6j4-v39w.json +++ b/advisories/unreviewed/2024/07/GHSA-wp5v-h6j4-v39w/GHSA-wp5v-h6j4-v39w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wp5v-h6j4-v39w", - "modified": "2024-07-16T21:30:49Z", + "modified": "2024-08-21T18:31:27Z", "published": "2024-07-16T21:30:49Z", "aliases": [ "CVE-2024-40393" ], "details": "Online Clinic Management System In PHP With Free Source code v1.0 was discovered to contain a SQL injection vulnerability via the user parameter at login.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-16T19:15:12Z" diff --git a/advisories/unreviewed/2024/07/GHSA-x27m-p9c5-jvf7/GHSA-x27m-p9c5-jvf7.json b/advisories/unreviewed/2024/07/GHSA-x27m-p9c5-jvf7/GHSA-x27m-p9c5-jvf7.json index 888f008eb4c..8ee4580bfd9 100644 --- a/advisories/unreviewed/2024/07/GHSA-x27m-p9c5-jvf7/GHSA-x27m-p9c5-jvf7.json +++ b/advisories/unreviewed/2024/07/GHSA-x27m-p9c5-jvf7/GHSA-x27m-p9c5-jvf7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x27m-p9c5-jvf7", - "modified": "2024-07-16T15:30:46Z", + "modified": "2024-08-21T18:31:26Z", "published": "2024-07-16T12:30:38Z", "aliases": [ "CVE-2022-48775" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nDrivers: hv: vmbus: Fix memory leak in vmbus_add_channel_kobj\n\nkobject_init_and_add() takes reference even when it fails.\nAccording to the doc of kobject_init_and_add():\n\n If this function returns an error, kobject_put() must be called to\n properly clean up the memory associated with the object.\n\nFix memory leak by calling kobject_put().", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-401" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-16T12:15:02Z" diff --git a/advisories/unreviewed/2024/07/GHSA-xp5x-wr7x-fp9j/GHSA-xp5x-wr7x-fp9j.json b/advisories/unreviewed/2024/07/GHSA-xp5x-wr7x-fp9j/GHSA-xp5x-wr7x-fp9j.json index a5648ae5b58..abcbbb502c1 100644 --- a/advisories/unreviewed/2024/07/GHSA-xp5x-wr7x-fp9j/GHSA-xp5x-wr7x-fp9j.json +++ b/advisories/unreviewed/2024/07/GHSA-xp5x-wr7x-fp9j/GHSA-xp5x-wr7x-fp9j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xp5x-wr7x-fp9j", - "modified": "2024-07-12T15:31:30Z", + "modified": "2024-08-21T18:31:26Z", "published": "2024-07-12T15:31:30Z", "aliases": [ "CVE-2024-41006" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetrom: Fix a memory leak in nr_heartbeat_expiry()\n\nsyzbot reported a memory leak in nr_create() [0].\n\nCommit 409db27e3a2e (\"netrom: Fix use-after-free of a listening socket.\")\nadded sock_hold() to the nr_heartbeat_expiry() function, where\na) a socket has a SOCK_DESTROY flag or\nb) a listening socket has a SOCK_DEAD flag.\n\nBut in the case \"a,\" when the SOCK_DESTROY flag is set, the file descriptor\nhas already been closed and the nr_release() function has been called.\nSo it makes no sense to hold the reference count because no one will\ncall another nr_destroy_socket() and put it as in the case \"b.\"\n\nnr_connect\n nr_establish_data_link\n nr_start_heartbeat\n\nnr_release\n switch (nr->state)\n case NR_STATE_3\n nr->state = NR_STATE_2\n sock_set_flag(sk, SOCK_DESTROY);\n\n nr_rx_frame\n nr_process_rx_frame\n switch (nr->state)\n case NR_STATE_2\n nr_state2_machine()\n nr_disconnect()\n nr_sk(sk)->state = NR_STATE_0\n sock_set_flag(sk, SOCK_DEAD)\n\n nr_heartbeat_expiry\n switch (nr->state)\n case NR_STATE_0\n if (sock_flag(sk, SOCK_DESTROY) ||\n (sk->sk_state == TCP_LISTEN\n && sock_flag(sk, SOCK_DEAD)))\n sock_hold() // ( !!! )\n nr_destroy_socket()\n\nTo fix the memory leak, let's call sock_hold() only for a listening socket.\n\nFound by InfoTeCS on behalf of Linux Verification Center\n(linuxtesting.org) with Syzkaller.\n\n[0]: https://syzkaller.appspot.com/bug?extid=d327a1f3b12e1e206c16", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-401" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-12T13:15:21Z" diff --git a/advisories/unreviewed/2024/07/GHSA-xxqc-5rhp-jfq2/GHSA-xxqc-5rhp-jfq2.json b/advisories/unreviewed/2024/07/GHSA-xxqc-5rhp-jfq2/GHSA-xxqc-5rhp-jfq2.json index 9e8d676988a..daa19c476f1 100644 --- a/advisories/unreviewed/2024/07/GHSA-xxqc-5rhp-jfq2/GHSA-xxqc-5rhp-jfq2.json +++ b/advisories/unreviewed/2024/07/GHSA-xxqc-5rhp-jfq2/GHSA-xxqc-5rhp-jfq2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xxqc-5rhp-jfq2", - "modified": "2024-07-16T12:30:38Z", + "modified": "2024-08-21T18:31:26Z", "published": "2024-07-16T12:30:37Z", "aliases": [ "CVE-2023-52886" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: core: Fix race by not overwriting udev->descriptor in hub_port_init()\n\nSyzbot reported an out-of-bounds read in sysfs.c:read_descriptors():\n\nBUG: KASAN: slab-out-of-bounds in read_descriptors+0x263/0x280 drivers/usb/core/sysfs.c:883\nRead of size 8 at addr ffff88801e78b8c8 by task udevd/5011\n\nCPU: 0 PID: 5011 Comm: udevd Not tainted 6.4.0-rc6-syzkaller-00195-g40f71e7cd3c6 #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 05/27/2023\nCall Trace:\n \n __dump_stack lib/dump_stack.c:88 [inline]\n dump_stack_lvl+0xd9/0x150 lib/dump_stack.c:106\n print_address_description.constprop.0+0x2c/0x3c0 mm/kasan/report.c:351\n print_report mm/kasan/report.c:462 [inline]\n kasan_report+0x11c/0x130 mm/kasan/report.c:572\n read_descriptors+0x263/0x280 drivers/usb/core/sysfs.c:883\n...\nAllocated by task 758:\n...\n __do_kmalloc_node mm/slab_common.c:966 [inline]\n __kmalloc+0x5e/0x190 mm/slab_common.c:979\n kmalloc include/linux/slab.h:563 [inline]\n kzalloc include/linux/slab.h:680 [inline]\n usb_get_configuration+0x1f7/0x5170 drivers/usb/core/config.c:887\n usb_enumerate_device drivers/usb/core/hub.c:2407 [inline]\n usb_new_device+0x12b0/0x19d0 drivers/usb/core/hub.c:2545\n\nAs analyzed by Khazhy Kumykov, the cause of this bug is a race between\nread_descriptors() and hub_port_init(): The first routine uses a field\nin udev->descriptor, not expecting it to change, while the second\noverwrites it.\n\nPrior to commit 45bf39f8df7f (\"USB: core: Don't hold device lock while\nreading the \"descriptors\" sysfs file\") this race couldn't occur,\nbecause the routines were mutually exclusive thanks to the device\nlocking. Removing that locking from read_descriptors() exposed it to\nthe race.\n\nThe best way to fix the bug is to keep hub_port_init() from changing\nudev->descriptor once udev has been initialized and registered.\nDrivers expect the descriptors stored in the kernel to be immutable;\nwe should not undermine this expectation. In fact, this change should\nhave been made long ago.\n\nSo now hub_port_init() will take an additional argument, specifying a\nbuffer in which to store the device descriptor it reads. (If udev has\nnot yet been initialized, the buffer pointer will be NULL and then\nhub_port_init() will store the device descriptor in udev as before.)\nThis eliminates the data race responsible for the out-of-bounds read.\n\nThe changes to hub_port_init() appear more extensive than they really\nare, because of indentation changes resulting from an attempt to avoid\nwriting to other parts of the usb_device structure after it has been\ninitialized. Similar changes should be made to the code that reads\nthe BOS descriptor, but that can be handled in a separate patch later\non. This patch is sufficient to fix the bug found by syzbot.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-16T10:15:02Z" diff --git a/advisories/unreviewed/2024/08/GHSA-2pwf-wmm4-p5xg/GHSA-2pwf-wmm4-p5xg.json b/advisories/unreviewed/2024/08/GHSA-2pwf-wmm4-p5xg/GHSA-2pwf-wmm4-p5xg.json new file mode 100644 index 00000000000..aa636620649 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-2pwf-wmm4-p5xg/GHSA-2pwf-wmm4-p5xg.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2pwf-wmm4-p5xg", + "modified": "2024-08-21T18:31:27Z", + "published": "2024-08-21T18:31:27Z", + "aliases": [ + "CVE-2024-6814" + ], + "details": "NETGEAR ProSAFE Network Management System getFilterString SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System. Authentication is required to exploit this vulnerability.\n\nThe specific flaw exists within the getFilterString method. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-23399.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6814" + }, + { + "type": "WEB", + "url": "https://kb.netgear.com/000066232/Security-Advisory-for-SQL-Injection-on-the-NMS300-PSV-2024-0019" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-901" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-21T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-2v3w-9hfq-fx33/GHSA-2v3w-9hfq-fx33.json b/advisories/unreviewed/2024/08/GHSA-2v3w-9hfq-fx33/GHSA-2v3w-9hfq-fx33.json new file mode 100644 index 00000000000..e0d5979ccd2 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-2v3w-9hfq-fx33/GHSA-2v3w-9hfq-fx33.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2v3w-9hfq-fx33", + "modified": "2024-08-21T18:31:28Z", + "published": "2024-08-21T18:31:28Z", + "aliases": [ + "CVE-2024-20375" + ], + "details": "A vulnerability in the SIP call processing function of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.\n\n This vulnerability is due to improper parsing of SIP messages. An attacker could exploit this vulnerability by sending a crafted SIP message to an affected Cisco Unified CM or Cisco Unified CM SME device. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition that interrupts the communications of reliant voice and video devices.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20375" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-dos-kkHq43We" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-21T17:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-2vf4-v2rm-3993/GHSA-2vf4-v2rm-3993.json b/advisories/unreviewed/2024/08/GHSA-2vf4-v2rm-3993/GHSA-2vf4-v2rm-3993.json index b58f7a2e6b9..cf38fcca3c7 100644 --- a/advisories/unreviewed/2024/08/GHSA-2vf4-v2rm-3993/GHSA-2vf4-v2rm-3993.json +++ b/advisories/unreviewed/2024/08/GHSA-2vf4-v2rm-3993/GHSA-2vf4-v2rm-3993.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2vf4-v2rm-3993", - "modified": "2024-08-20T15:32:12Z", + "modified": "2024-08-21T18:31:27Z", "published": "2024-08-20T15:32:12Z", "aliases": [ "CVE-2024-42563" ], "details": "An arbitrary file upload vulnerability in ERP commit 44bd04 allows attackers to execute arbitrary code via uploading a crafted HTML file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-20T13:15:07Z" diff --git a/advisories/unreviewed/2024/08/GHSA-2wj7-gph3-jwg6/GHSA-2wj7-gph3-jwg6.json b/advisories/unreviewed/2024/08/GHSA-2wj7-gph3-jwg6/GHSA-2wj7-gph3-jwg6.json new file mode 100644 index 00000000000..cd9b2849064 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-2wj7-gph3-jwg6/GHSA-2wj7-gph3-jwg6.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2wj7-gph3-jwg6", + "modified": "2024-08-21T18:31:28Z", + "published": "2024-08-21T18:31:28Z", + "aliases": [ + "CVE-2024-6141" + ], + "details": "Windscribe Directory Traversal Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Windscribe. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.\n\nThe specific flaw exists within the Windscribe Service. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-23441.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6141" + }, + { + "type": "WEB", + "url": "https://github.com/Windscribe/Desktop-App/blob/90a5cc3c1f50f6545f83969c2ace6b4ac2c91c4e/client/common/changelog.txt#L23" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-820" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-21T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-37rg-3x55-7pmg/GHSA-37rg-3x55-7pmg.json b/advisories/unreviewed/2024/08/GHSA-37rg-3x55-7pmg/GHSA-37rg-3x55-7pmg.json new file mode 100644 index 00000000000..c19eaf7ec88 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-37rg-3x55-7pmg/GHSA-37rg-3x55-7pmg.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-37rg-3x55-7pmg", + "modified": "2024-08-21T18:31:27Z", + "published": "2024-08-21T18:31:27Z", + "aliases": [ + "CVE-2024-7722" + ], + "details": "Foxit PDF Reader Doc Object Use-After-Free Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the handling of Doc objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-23702.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7722" + }, + { + "type": "WEB", + "url": "https://www.foxit.com/support/security-bulletins.html" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1124" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-21T16:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-3fc7-hxmq-f35p/GHSA-3fc7-hxmq-f35p.json b/advisories/unreviewed/2024/08/GHSA-3fc7-hxmq-f35p/GHSA-3fc7-hxmq-f35p.json new file mode 100644 index 00000000000..205cc920ed5 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-3fc7-hxmq-f35p/GHSA-3fc7-hxmq-f35p.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3fc7-hxmq-f35p", + "modified": "2024-08-21T18:31:28Z", + "published": "2024-08-21T18:31:28Z", + "aliases": [ + "CVE-2024-42784" + ], + "details": "A SQL injection vulnerability in \"/music/controller.php?page=view_music\" in Kashipara Music Management System v1.0 allows an attacker to execute arbitrary SQL commands via the \"id\" parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42784" + }, + { + "type": "WEB", + "url": "https://github.com/takekaramey/CVE_Writeup/blob/main/Kashipara/Music%20Management%20System%20v1.0/SQL%20Injection%20-%20View%20Music%20List.pdf" + }, + { + "type": "WEB", + "url": "https://www.kashipara.com/project/php/12978/music-management-system-in-php-php-project-source-code" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-21T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-3r58-6hw4-672v/GHSA-3r58-6hw4-672v.json b/advisories/unreviewed/2024/08/GHSA-3r58-6hw4-672v/GHSA-3r58-6hw4-672v.json new file mode 100644 index 00000000000..915c9fa2d4f --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-3r58-6hw4-672v/GHSA-3r58-6hw4-672v.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3r58-6hw4-672v", + "modified": "2024-08-21T18:31:28Z", + "published": "2024-08-21T18:31:28Z", + "aliases": [ + "CVE-2024-42782" + ], + "details": "A SQL injection vulnerability in \"/music/ajax.php?action=find_music\" in Kashipara Music Management System v1.0 allows an attacker to execute arbitrary SQL commands via the \"search\" parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42782" + }, + { + "type": "WEB", + "url": "https://github.com/takekaramey/CVE_Writeup/blob/main/Kashipara/Music%20Management%20System%20v1.0/SQL%20Injection%20-%20Find%20Music.pdf" + }, + { + "type": "WEB", + "url": "https://www.kashipara.com/project/php/12978/music-management-system-in-php-php-project-source-code" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-21T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-44v9-q98m-jg4p/GHSA-44v9-q98m-jg4p.json b/advisories/unreviewed/2024/08/GHSA-44v9-q98m-jg4p/GHSA-44v9-q98m-jg4p.json index e2eb455cd8b..46748099aae 100644 --- a/advisories/unreviewed/2024/08/GHSA-44v9-q98m-jg4p/GHSA-44v9-q98m-jg4p.json +++ b/advisories/unreviewed/2024/08/GHSA-44v9-q98m-jg4p/GHSA-44v9-q98m-jg4p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-44v9-q98m-jg4p", - "modified": "2024-08-20T15:32:13Z", + "modified": "2024-08-21T18:31:27Z", "published": "2024-08-20T15:32:13Z", "aliases": [ "CVE-2024-42608" ], "details": "Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/submit_page.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-20T14:15:09Z" diff --git a/advisories/unreviewed/2024/08/GHSA-45wm-mg4w-2536/GHSA-45wm-mg4w-2536.json b/advisories/unreviewed/2024/08/GHSA-45wm-mg4w-2536/GHSA-45wm-mg4w-2536.json new file mode 100644 index 00000000000..817d05b03be --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-45wm-mg4w-2536/GHSA-45wm-mg4w-2536.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-45wm-mg4w-2536", + "modified": "2024-08-21T18:31:28Z", + "published": "2024-08-21T18:31:28Z", + "aliases": [ + "CVE-2024-42781" + ], + "details": "A SQL injection vulnerability in \"/music/ajax.php?action=login\" of Kashipara Music Management System v1.0 allows remote attackers to execute arbitrary SQL commands and bypass Login via the email parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42781" + }, + { + "type": "WEB", + "url": "https://github.com/takekaramey/CVE_Writeup/blob/main/Kashipara/Music%20Management%20System%20v1.0/SQL%20Injection%20-%20Login.pdf" + }, + { + "type": "WEB", + "url": "https://www.kashipara.com/project/php/12978/music-management-system-in-php-php-project-source-code" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-21T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-496j-g557-72f5/GHSA-496j-g557-72f5.json b/advisories/unreviewed/2024/08/GHSA-496j-g557-72f5/GHSA-496j-g557-72f5.json new file mode 100644 index 00000000000..b6752bbbc36 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-496j-g557-72f5/GHSA-496j-g557-72f5.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-496j-g557-72f5", + "modified": "2024-08-21T18:31:27Z", + "published": "2024-08-21T18:31:27Z", + "aliases": [ + "CVE-2024-7601" + ], + "details": "Logsign Unified SecOps Platform Directory data_export_delete_all Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected installations of Logsign Unified SecOps Platform. Authentication is required to exploit this vulnerability.\n\nThe specific flaw exists within the HTTP API service, which listens on TCP port 443 by default. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to delete files in the context of root. Was ZDI-CAN-25026.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7601" + }, + { + "type": "WEB", + "url": "https://support.logsign.net/hc/en-us/articles/20617133769362-06-08-2024-Version-6-4-23-Release-Notes" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1106" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-21T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-4wrc-8xjh-v948/GHSA-4wrc-8xjh-v948.json b/advisories/unreviewed/2024/08/GHSA-4wrc-8xjh-v948/GHSA-4wrc-8xjh-v948.json new file mode 100644 index 00000000000..1ef482f973d --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-4wrc-8xjh-v948/GHSA-4wrc-8xjh-v948.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4wrc-8xjh-v948", + "modified": "2024-08-21T18:31:28Z", + "published": "2024-08-21T18:31:28Z", + "aliases": [ + "CVE-2023-29929" + ], + "details": "Buffer Overflow vulnerability found in Kemptechnologies Loadmaster before v.7.2.60.0 allows a remote attacker to casue a denial of service via the libkemplink.so, isreverse library.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29929" + }, + { + "type": "WEB", + "url": "http://kemptechnologies.com" + }, + { + "type": "WEB", + "url": "http://loadmaster.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-21T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-626c-c4r3-vmjg/GHSA-626c-c4r3-vmjg.json b/advisories/unreviewed/2024/08/GHSA-626c-c4r3-vmjg/GHSA-626c-c4r3-vmjg.json new file mode 100644 index 00000000000..505dc6e4008 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-626c-c4r3-vmjg/GHSA-626c-c4r3-vmjg.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-626c-c4r3-vmjg", + "modified": "2024-08-21T18:31:28Z", + "published": "2024-08-21T18:31:28Z", + "aliases": [ + "CVE-2024-7725" + ], + "details": "Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the handling of AcroForms. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-23928.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7725" + }, + { + "type": "WEB", + "url": "https://www.foxit.com/support/security-bulletins.html" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1127" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-21T16:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-64gw-gxfq-f34c/GHSA-64gw-gxfq-f34c.json b/advisories/unreviewed/2024/08/GHSA-64gw-gxfq-f34c/GHSA-64gw-gxfq-f34c.json new file mode 100644 index 00000000000..64e850616af --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-64gw-gxfq-f34c/GHSA-64gw-gxfq-f34c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-64gw-gxfq-f34c", + "modified": "2024-08-21T18:31:28Z", + "published": "2024-08-21T18:31:28Z", + "aliases": [ + "CVE-2024-7795" + ], + "details": "Autel MaxiCharger AC Elite Business C50 AppAuthenExchangeRandomNum Stack-Based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Business C50 EV chargers. Authentication is not required to exploit this vulnerability.\n\nThe specific flaw exists within the handling of the AppAuthenExchangeRandomNum BLE command. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the device. Was ZDI-CAN-23384.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7795" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1154" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-21T16:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-67c5-gg2x-j6wg/GHSA-67c5-gg2x-j6wg.json b/advisories/unreviewed/2024/08/GHSA-67c5-gg2x-j6wg/GHSA-67c5-gg2x-j6wg.json new file mode 100644 index 00000000000..b36cf0096dc --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-67c5-gg2x-j6wg/GHSA-67c5-gg2x-j6wg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-67c5-gg2x-j6wg", + "modified": "2024-08-21T18:31:28Z", + "published": "2024-08-21T18:31:28Z", + "aliases": [ + "CVE-2024-5725" + ], + "details": "Centreon initCurveList SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required to exploit this vulnerability.\n\nThe specific flaw exists within the initCurveList function. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to execute code in the context of the apache user. Was ZDI-CAN-22683.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5725" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-597" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-21T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-6cpf-rmp5-w9pp/GHSA-6cpf-rmp5-w9pp.json b/advisories/unreviewed/2024/08/GHSA-6cpf-rmp5-w9pp/GHSA-6cpf-rmp5-w9pp.json new file mode 100644 index 00000000000..ff4afbf6e0f --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-6cpf-rmp5-w9pp/GHSA-6cpf-rmp5-w9pp.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6cpf-rmp5-w9pp", + "modified": "2024-08-21T18:31:28Z", + "published": "2024-08-21T18:31:27Z", + "aliases": [ + "CVE-2024-7723" + ], + "details": "Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the handling of AcroForms. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-23736.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7723" + }, + { + "type": "WEB", + "url": "https://www.foxit.com/support/security-bulletins.html" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1125" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-21T16:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-6fqv-gvfg-wqrx/GHSA-6fqv-gvfg-wqrx.json b/advisories/unreviewed/2024/08/GHSA-6fqv-gvfg-wqrx/GHSA-6fqv-gvfg-wqrx.json new file mode 100644 index 00000000000..885c40e11f4 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-6fqv-gvfg-wqrx/GHSA-6fqv-gvfg-wqrx.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6fqv-gvfg-wqrx", + "modified": "2024-08-21T18:31:28Z", + "published": "2024-08-21T18:31:28Z", + "aliases": [ + "CVE-2024-42786" + ], + "details": "A SQL injection vulnerability in \"/music/view_user.php\" in Kashipara Music Management System v1.0 allows an attacker to execute arbitrary SQL commands via the \"id\" parameter of View User Profile Page.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42786" + }, + { + "type": "WEB", + "url": "https://github.com/takekaramey/CVE_Writeup/blob/main/Kashipara/Music%20Management%20System%20v1.0/SQL%20Injection%20-%20View%20Profile.pdf" + }, + { + "type": "WEB", + "url": "https://www.kashipara.com/project/php/12978/music-management-system-in-php-php-project-source-code" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-21T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-7jcc-v4g6-5284/GHSA-7jcc-v4g6-5284.json b/advisories/unreviewed/2024/08/GHSA-7jcc-v4g6-5284/GHSA-7jcc-v4g6-5284.json new file mode 100644 index 00000000000..4dcdb8ca024 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-7jcc-v4g6-5284/GHSA-7jcc-v4g6-5284.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7jcc-v4g6-5284", + "modified": "2024-08-21T18:31:28Z", + "published": "2024-08-21T18:31:28Z", + "aliases": [ + "CVE-2024-42777" + ], + "details": "An Unrestricted file upload vulnerability was found in \"/music/ajax.php?action=signup\" of Kashipara Music Management System v1.0, which allows attackers to execute arbitrary code via uploading a crafted PHP file.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42777" + }, + { + "type": "WEB", + "url": "https://github.com/takekaramey/CVE_Writeup/blob/main/Kashipara/Music%20Management%20System%20v1.0/Unrestricted%20File%20Upload%20-%20SignUp.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-21T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-8fgq-vqp8-467c/GHSA-8fgq-vqp8-467c.json b/advisories/unreviewed/2024/08/GHSA-8fgq-vqp8-467c/GHSA-8fgq-vqp8-467c.json new file mode 100644 index 00000000000..406dd2381c5 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-8fgq-vqp8-467c/GHSA-8fgq-vqp8-467c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8fgq-vqp8-467c", + "modified": "2024-08-21T18:31:28Z", + "published": "2024-08-21T18:31:28Z", + "aliases": [ + "CVE-2024-33657" + ], + "details": "This SMM vulnerability affects certain modules, allowing privileged attackers to execute arbitrary code, manipulate stack memory, and leak information from SMRAM to kernel space, potentially leading to denial-of-service attacks.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33657" + }, + { + "type": "WEB", + "url": "https://9443417.fs1.hubspotusercontent-na1.net/hubfs/9443417/Security%20Advisories/2024/AMI-SA-2024003.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-21T17:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-8vhq-vf79-3q7c/GHSA-8vhq-vf79-3q7c.json b/advisories/unreviewed/2024/08/GHSA-8vhq-vf79-3q7c/GHSA-8vhq-vf79-3q7c.json new file mode 100644 index 00000000000..293df9c36af --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-8vhq-vf79-3q7c/GHSA-8vhq-vf79-3q7c.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8vhq-vf79-3q7c", + "modified": "2024-08-21T18:31:27Z", + "published": "2024-08-21T18:31:27Z", + "aliases": [ + "CVE-2024-7604" + ], + "details": "Logsign Unified SecOps Platform Incorrect Authorization Authentication Bypass Vulnerability. This vulnerability allows local attackers to bypass authentication on affected installations of Logsign Unified SecOps Platform. Authentication is required to exploit this vulnerability.\n\nThe specific flaw exists within the HTTP API service, which listens on TCP port 443 by default. The issue results from the lack of proper validation of the user's license expiration date. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-25029.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7604" + }, + { + "type": "WEB", + "url": "https://support.logsign.net/hc/en-us/articles/20617133769362-06-08-2024-Version-6-4-23-Release-Notes" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1104" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-21T16:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-94m4-2jpq-9j4w/GHSA-94m4-2jpq-9j4w.json b/advisories/unreviewed/2024/08/GHSA-94m4-2jpq-9j4w/GHSA-94m4-2jpq-9j4w.json new file mode 100644 index 00000000000..530e58f7741 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-94m4-2jpq-9j4w/GHSA-94m4-2jpq-9j4w.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-94m4-2jpq-9j4w", + "modified": "2024-08-21T18:31:28Z", + "published": "2024-08-21T18:31:28Z", + "aliases": [ + "CVE-2024-42780" + ], + "details": "An Unrestricted file upload vulnerability was found in \"/music/ajax.php?action=save_genre\" in Kashipara Music Management System v1.0. This allows attackers to execute arbitrary code via uploading a crafted PHP file.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42780" + }, + { + "type": "WEB", + "url": "https://github.com/takekaramey/CVE_Writeup/blob/main/Kashipara/Music%20Management%20System%20v1.0/Unrestricted%20File%20Upload%20-%20Add%20New%20Genre.pdf" + }, + { + "type": "WEB", + "url": "https://www.kashipara.com/project/php/12978/music-management-system-in-php-php-project-source-code" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-21T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-9j4q-qf8g-3382/GHSA-9j4q-qf8g-3382.json b/advisories/unreviewed/2024/08/GHSA-9j4q-qf8g-3382/GHSA-9j4q-qf8g-3382.json new file mode 100644 index 00000000000..fe641c3cbee --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-9j4q-qf8g-3382/GHSA-9j4q-qf8g-3382.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9j4q-qf8g-3382", + "modified": "2024-08-21T18:31:28Z", + "published": "2024-08-21T18:31:28Z", + "aliases": [ + "CVE-2024-5930" + ], + "details": "VIPRE Advanced Security Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of VIPRE Advanced Security. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.\n\nThe specific flaw exists within the Anti Malware Service. The issue results from incorrect permissions on a file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-22345.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5930" + }, + { + "type": "WEB", + "url": "https://success.vipre.com/en_US/home-windows-release-notes/home-windows-release-notes-20240227" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-819" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-732" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-21T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-9j5g-j2hj-xfpc/GHSA-9j5g-j2hj-xfpc.json b/advisories/unreviewed/2024/08/GHSA-9j5g-j2hj-xfpc/GHSA-9j5g-j2hj-xfpc.json new file mode 100644 index 00000000000..e3bd593647c --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-9j5g-j2hj-xfpc/GHSA-9j5g-j2hj-xfpc.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9j5g-j2hj-xfpc", + "modified": "2024-08-21T18:31:28Z", + "published": "2024-08-21T18:31:28Z", + "aliases": [ + "CVE-2024-5762" + ], + "details": "Zen Cart findPluginAdminPage Local File Inclusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Zen Cart. Authentication is not required to exploit this vulnerability.\n\nThe specific flaw exists within the findPluginAdminPage function. The issue results from the lack of proper validation of user-supplied data prior to passing it to a PHP include function. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the service account. Was ZDI-CAN-21408.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5762" + }, + { + "type": "WEB", + "url": "https://docs.zen-cart.com/release/whatsnew_2.0.0" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-883" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-21T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-c62c-fvgv-j4v4/GHSA-c62c-fvgv-j4v4.json b/advisories/unreviewed/2024/08/GHSA-c62c-fvgv-j4v4/GHSA-c62c-fvgv-j4v4.json index 185be8800ad..64a66f69ecd 100644 --- a/advisories/unreviewed/2024/08/GHSA-c62c-fvgv-j4v4/GHSA-c62c-fvgv-j4v4.json +++ b/advisories/unreviewed/2024/08/GHSA-c62c-fvgv-j4v4/GHSA-c62c-fvgv-j4v4.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-400", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/08/GHSA-chqm-2p4j-9jph/GHSA-chqm-2p4j-9jph.json b/advisories/unreviewed/2024/08/GHSA-chqm-2p4j-9jph/GHSA-chqm-2p4j-9jph.json new file mode 100644 index 00000000000..c446d118628 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-chqm-2p4j-9jph/GHSA-chqm-2p4j-9jph.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-chqm-2p4j-9jph", + "modified": "2024-08-21T18:31:28Z", + "published": "2024-08-21T18:31:28Z", + "aliases": [ + "CVE-2024-42550" + ], + "details": "A cross-site scripting (XSS) vulnerability in the component /email/welcome.php of Mini Inventory and Sales Management System commit 18aa3d allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42550" + }, + { + "type": "WEB", + "url": "https://gist.github.com/topsky979/3332b6ba95f5a95aec4f635d8bb20f7c" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-21T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-cq2h-fx3v-v5m3/GHSA-cq2h-fx3v-v5m3.json b/advisories/unreviewed/2024/08/GHSA-cq2h-fx3v-v5m3/GHSA-cq2h-fx3v-v5m3.json new file mode 100644 index 00000000000..05aa67cef85 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-cq2h-fx3v-v5m3/GHSA-cq2h-fx3v-v5m3.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cq2h-fx3v-v5m3", + "modified": "2024-08-21T18:31:28Z", + "published": "2024-08-21T18:31:28Z", + "aliases": [ + "CVE-2024-5929" + ], + "details": "VIPRE Advanced Security PMAgent Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of VIPRE Advanced Security. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.\n\nThe specific flaw exists within the Patch Management Agent. The issue results from loading a file from an unsecured location. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-22316.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5929" + }, + { + "type": "WEB", + "url": "https://success.vipre.com/en_US/home-windows-release-notes/home-windows-release-notes-20240227" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-818" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-21T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-f5w2-xh59-w5p8/GHSA-f5w2-xh59-w5p8.json b/advisories/unreviewed/2024/08/GHSA-f5w2-xh59-w5p8/GHSA-f5w2-xh59-w5p8.json index 3af63857191..05c2b56ae47 100644 --- a/advisories/unreviewed/2024/08/GHSA-f5w2-xh59-w5p8/GHSA-f5w2-xh59-w5p8.json +++ b/advisories/unreviewed/2024/08/GHSA-f5w2-xh59-w5p8/GHSA-f5w2-xh59-w5p8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f5w2-xh59-w5p8", - "modified": "2024-08-12T21:31:34Z", + "modified": "2024-08-21T18:31:27Z", "published": "2024-08-12T21:31:34Z", "aliases": [ "CVE-2024-40893" @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://vulncheck.com/advisories/firewalla-bt-command-injection" + }, + { + "type": "WEB", + "url": "https://www.labs.greynoise.io/grimoire/2024-08-20-bluuid-firewalla" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/08/GHSA-f8mh-6mf7-mh58/GHSA-f8mh-6mf7-mh58.json b/advisories/unreviewed/2024/08/GHSA-f8mh-6mf7-mh58/GHSA-f8mh-6mf7-mh58.json new file mode 100644 index 00000000000..de2814f4e10 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-f8mh-6mf7-mh58/GHSA-f8mh-6mf7-mh58.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f8mh-6mf7-mh58", + "modified": "2024-08-21T18:31:28Z", + "published": "2024-08-21T18:31:28Z", + "aliases": [ + "CVE-2024-42778" + ], + "details": "An Unrestricted file upload vulnerability was found in \"/music/ajax.php?action=save_playlist\" in Kashipara Music Management System v1.0. This allows attackers to execute arbitrary code via uploading a crafted PHP file.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42778" + }, + { + "type": "WEB", + "url": "https://github.com/takekaramey/CVE_Writeup/blob/main/Kashipara/Music%20Management%20System%20v1.0/Unrestricted%20File%20Upload%20-%20Add%20New%20Playlist.pdf" + }, + { + "type": "WEB", + "url": "https://www.kashipara.com/project/php/12978/music-management-system-in-php-php-project-source-code" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-21T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-fm2v-78x9-f367/GHSA-fm2v-78x9-f367.json b/advisories/unreviewed/2024/08/GHSA-fm2v-78x9-f367/GHSA-fm2v-78x9-f367.json new file mode 100644 index 00000000000..1a95e5c0f87 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-fm2v-78x9-f367/GHSA-fm2v-78x9-f367.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fm2v-78x9-f367", + "modified": "2024-08-21T18:31:28Z", + "published": "2024-08-21T18:31:28Z", + "aliases": [ + "CVE-2024-33656" + ], + "details": "The DXE module SmmComputrace contains a vulnerability that allows local attackers to leak stack or global memory. This could lead to privilege escalation, arbitrary code execution, and bypassing OS security mechanisms", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33656" + }, + { + "type": "WEB", + "url": "https://9443417.fs1.hubspotusercontent-na1.net/hubfs/9443417/Security%20Advisories/2024/AMI-SA-2024003.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-21T17:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-g5jq-gr6p-2c45/GHSA-g5jq-gr6p-2c45.json b/advisories/unreviewed/2024/08/GHSA-g5jq-gr6p-2c45/GHSA-g5jq-gr6p-2c45.json new file mode 100644 index 00000000000..a869c594f35 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-g5jq-gr6p-2c45/GHSA-g5jq-gr6p-2c45.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g5jq-gr6p-2c45", + "modified": "2024-08-21T18:31:28Z", + "published": "2024-08-21T18:31:28Z", + "aliases": [ + "CVE-2024-7724" + ], + "details": "Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the handling of AcroForms. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-23900.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7724" + }, + { + "type": "WEB", + "url": "https://www.foxit.com/support/security-bulletins.html" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1126" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-21T16:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-g6mg-qmxh-mv93/GHSA-g6mg-qmxh-mv93.json b/advisories/unreviewed/2024/08/GHSA-g6mg-qmxh-mv93/GHSA-g6mg-qmxh-mv93.json new file mode 100644 index 00000000000..d63fcc9e9e6 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-g6mg-qmxh-mv93/GHSA-g6mg-qmxh-mv93.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g6mg-qmxh-mv93", + "modified": "2024-08-21T18:31:27Z", + "published": "2024-08-21T18:31:27Z", + "aliases": [ + "CVE-2024-43027" + ], + "details": "DrayTek Vigor 3900 before v1.5.1.5_Beta, DrayTek Vigor 2960 before v1.5.1.5_Beta and DrayTek Vigor 300B before v1.5.1.5_Beta were discovered to contain a command injection vulnerability via the action parameter at cgi-bin/mainfunction.cgi.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43027" + }, + { + "type": "WEB", + "url": "https://github.com/N1nEmAn/wp/blob/main/V3900.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-21T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-g6mm-5rjg-vwhr/GHSA-g6mm-5rjg-vwhr.json b/advisories/unreviewed/2024/08/GHSA-g6mm-5rjg-vwhr/GHSA-g6mm-5rjg-vwhr.json new file mode 100644 index 00000000000..2bfd82d3ea3 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-g6mm-5rjg-vwhr/GHSA-g6mm-5rjg-vwhr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g6mm-5rjg-vwhr", + "modified": "2024-08-21T18:31:28Z", + "published": "2024-08-21T18:31:28Z", + "aliases": [ + "CVE-2024-5723" + ], + "details": "Centreon updateServiceHost SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required to exploit this vulnerability.\n\nThe specific flaw exists within the updateServiceHost function. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to execute code in the context of the apache user. Was ZDI-CAN-23294.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5723" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-595" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-21T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-grxj-hmrx-25w5/GHSA-grxj-hmrx-25w5.json b/advisories/unreviewed/2024/08/GHSA-grxj-hmrx-25w5/GHSA-grxj-hmrx-25w5.json new file mode 100644 index 00000000000..b149a47992a --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-grxj-hmrx-25w5/GHSA-grxj-hmrx-25w5.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-grxj-hmrx-25w5", + "modified": "2024-08-21T18:31:28Z", + "published": "2024-08-21T18:31:28Z", + "aliases": [ + "CVE-2024-43022" + ], + "details": "An issue in the downloader.php component of TOSEI online store management system v4.02, v4.03, and v4.04 allows attackers to execute a directory traversal.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43022" + }, + { + "type": "WEB", + "url": "https://gist.github.com/b0rgch3n/6ba0b04da7e48ead20f10b15088fd244" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-21T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-h3rg-2ghf-ph8j/GHSA-h3rg-2ghf-ph8j.json b/advisories/unreviewed/2024/08/GHSA-h3rg-2ghf-ph8j/GHSA-h3rg-2ghf-ph8j.json index e0a8638a5d9..3ac25086ba0 100644 --- a/advisories/unreviewed/2024/08/GHSA-h3rg-2ghf-ph8j/GHSA-h3rg-2ghf-ph8j.json +++ b/advisories/unreviewed/2024/08/GHSA-h3rg-2ghf-ph8j/GHSA-h3rg-2ghf-ph8j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h3rg-2ghf-ph8j", - "modified": "2024-08-20T15:32:12Z", + "modified": "2024-08-21T18:31:27Z", "published": "2024-08-20T15:32:12Z", "aliases": [ "CVE-2024-42556" ], "details": "Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the room_type parameter at admin_room_removed.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-20T13:15:06Z" diff --git a/advisories/unreviewed/2024/08/GHSA-hm5h-rw9m-g27p/GHSA-hm5h-rw9m-g27p.json b/advisories/unreviewed/2024/08/GHSA-hm5h-rw9m-g27p/GHSA-hm5h-rw9m-g27p.json new file mode 100644 index 00000000000..2efd34868a3 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-hm5h-rw9m-g27p/GHSA-hm5h-rw9m-g27p.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hm5h-rw9m-g27p", + "modified": "2024-08-21T18:31:27Z", + "published": "2024-08-21T18:31:27Z", + "aliases": [ + "CVE-2024-21690" + ], + "details": "This High severity Reflected XSS and CSRF (Cross-Site Request Forgery) vulnerability was introduced in versions 7.19.0, 7.20.0, 8.0.0, 8.1.0, 8.2.0, 8.3.0, 8.4.0, 8.5.0, 8.6.0, 8.7.1, 8.8.0, and 8.9.0 of Confluence Data Center and Server. \n\t\n\tThis Reflected XSS and CSRF (Cross-Site Request Forgery) vulnerability, with a CVSS Score of 7.1, allows an unauthenticated attacker to execute arbitrary HTML or JavaScript code on a victims browser and force a end user to execute unwanted actions on a web application in which they're currently authenticated which has high impact to confidentiality, low impact to integrity, no impact to availability, and requires user interaction. \n\t\n\tAtlassian recommends that Confluence Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions:\n\t\t\n\t\t* Confluence Data Center and Server 7.19: Upgrade to a release greater than or equal to 7.19.26\n\t\t\n\t\t* Confluence Data Center and Server 8.5: Upgrade to a release greater than or equal to 8.5.14\n\t\t\n\t\t* Confluence Data Center and Server 9.0: Upgrade to a release greater than or equal to 9.0.1\n\t\t\n\t\t\n\t\n\tSee the release notes (https://confluence.atlassian.com/doc/confluence-release-notes-327.html). You can download the latest version of Confluence Data Center and Server from the download center (https://www.atlassian.com/software/confluence/download-archives). \n\t\n\tThis vulnerability was reported via our Bug Bounty program.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21690" + }, + { + "type": "WEB", + "url": "https://confluence.atlassian.com/pages/viewpage.action?pageId=1431535667" + }, + { + "type": "WEB", + "url": "https://jira.atlassian.com/browse/CONFSERVER-97720" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-21T16:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-hxqr-gvc3-2pc3/GHSA-hxqr-gvc3-2pc3.json b/advisories/unreviewed/2024/08/GHSA-hxqr-gvc3-2pc3/GHSA-hxqr-gvc3-2pc3.json new file mode 100644 index 00000000000..4ab0ee2f6bc --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-hxqr-gvc3-2pc3/GHSA-hxqr-gvc3-2pc3.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hxqr-gvc3-2pc3", + "modified": "2024-08-21T18:31:27Z", + "published": "2024-08-21T18:31:27Z", + "aliases": [ + "CVE-2024-7602" + ], + "details": "Logsign Unified SecOps Platform Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Logsign Unified SecOps Platform. Authentication is required to exploit this vulnerability.\n\nThe specific flaw exists within the HTTP API service, which listens on TCP port 443 by default. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to disclose information in the context of root. Was ZDI-CAN-25027.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7602" + }, + { + "type": "WEB", + "url": "https://support.logsign.net/hc/en-us/articles/20617133769362-06-08-2024-Version-6-4-23-Release-Notes" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1102" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-21T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-j6mc-w8mx-r99r/GHSA-j6mc-w8mx-r99r.json b/advisories/unreviewed/2024/08/GHSA-j6mc-w8mx-r99r/GHSA-j6mc-w8mx-r99r.json new file mode 100644 index 00000000000..3e6c50d1e91 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-j6mc-w8mx-r99r/GHSA-j6mc-w8mx-r99r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j6mc-w8mx-r99r", + "modified": "2024-08-21T18:31:27Z", + "published": "2024-08-21T18:31:27Z", + "aliases": [ + "CVE-2022-26328" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText Performance Center on Windows allows Cross-Site Scripting (XSS).This issue affects Performance Center: 12.63.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:M/U:Clear" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-26328" + }, + { + "type": "WEB", + "url": "https://portal.microfocus.com/s/article/KM000032041?language=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-21T16:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-jqxg-gg5c-r85j/GHSA-jqxg-gg5c-r85j.json b/advisories/unreviewed/2024/08/GHSA-jqxg-gg5c-r85j/GHSA-jqxg-gg5c-r85j.json new file mode 100644 index 00000000000..ba891eaaf8e --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-jqxg-gg5c-r85j/GHSA-jqxg-gg5c-r85j.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jqxg-gg5c-r85j", + "modified": "2024-08-21T18:31:28Z", + "published": "2024-08-21T18:31:28Z", + "aliases": [ + "CVE-2024-42779" + ], + "details": "An Unrestricted file upload vulnerability was found in \"/music/ajax.php?action=save_music\" in Kashipara Music Management System v1.0. This allows attackers to execute arbitrary code via uploading a crafted PHP file.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42779" + }, + { + "type": "WEB", + "url": "https://github.com/takekaramey/CVE_Writeup/blob/main/Kashipara/Music%20Management%20System%20v1.0/Unrestricted%20File%20Upload%20-%20Add%20New%20Music%20List.pdf" + }, + { + "type": "WEB", + "url": "https://www.kashipara.com/project/php/12978/music-management-system-in-php-php-project-source-code" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-21T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-m2vr-vh5r-mfq9/GHSA-m2vr-vh5r-mfq9.json b/advisories/unreviewed/2024/08/GHSA-m2vr-vh5r-mfq9/GHSA-m2vr-vh5r-mfq9.json new file mode 100644 index 00000000000..1482ad70ea7 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-m2vr-vh5r-mfq9/GHSA-m2vr-vh5r-mfq9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m2vr-vh5r-mfq9", + "modified": "2024-08-21T18:31:27Z", + "published": "2024-08-21T18:31:27Z", + "aliases": [ + "CVE-2024-6812" + ], + "details": "IrfanView WSQ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of WSQ files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-23273.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6812" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-904" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-21T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-m9m8-p797-5pq4/GHSA-m9m8-p797-5pq4.json b/advisories/unreviewed/2024/08/GHSA-m9m8-p797-5pq4/GHSA-m9m8-p797-5pq4.json new file mode 100644 index 00000000000..6e419f01945 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-m9m8-p797-5pq4/GHSA-m9m8-p797-5pq4.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m9m8-p797-5pq4", + "modified": "2024-08-21T18:31:27Z", + "published": "2024-08-21T18:31:27Z", + "aliases": [ + "CVE-2024-7603" + ], + "details": "Logsign Unified SecOps Platform Directory Traversal Arbitrary Directory Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary directories on affected installations of Logsign Unified SecOps Platform. Authentication is required to exploit this vulnerability.\n\nThe specific flaw exists within the HTTP API service, which listens on TCP port 443 by default. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to delete directories in the context of root. Was ZDI-CAN-25028.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7603" + }, + { + "type": "WEB", + "url": "https://support.logsign.net/hc/en-us/articles/20617133769362-06-08-2024-Version-6-4-23-Release-Notes" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1105" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-21T16:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-mv2g-4jjm-w3mg/GHSA-mv2g-4jjm-w3mg.json b/advisories/unreviewed/2024/08/GHSA-mv2g-4jjm-w3mg/GHSA-mv2g-4jjm-w3mg.json new file mode 100644 index 00000000000..8873f0e8074 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-mv2g-4jjm-w3mg/GHSA-mv2g-4jjm-w3mg.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mv2g-4jjm-w3mg", + "modified": "2024-08-21T18:31:28Z", + "published": "2024-08-21T18:31:28Z", + "aliases": [ + "CVE-2024-7448" + ], + "details": "Magnet Forensics AXIOM Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Magnet Forensics AXIOM. User interaction is required to exploit this vulnerability in that the target must acquire data from a malicious mobile device.\n\nThe specific flaw exists within the Android device image acquisition functionality. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-23964.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7448" + }, + { + "type": "WEB", + "url": "https://docs.magnetforensics.com/docs/axiom/release_notes.html" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1129" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-21T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-q3pq-6mcr-hp32/GHSA-q3pq-6mcr-hp32.json b/advisories/unreviewed/2024/08/GHSA-q3pq-6mcr-hp32/GHSA-q3pq-6mcr-hp32.json new file mode 100644 index 00000000000..407d357e5b0 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-q3pq-6mcr-hp32/GHSA-q3pq-6mcr-hp32.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q3pq-6mcr-hp32", + "modified": "2024-08-21T18:31:28Z", + "published": "2024-08-21T18:31:28Z", + "aliases": [ + "CVE-2024-5928" + ], + "details": "VIPRE Advanced Security PMAgent Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of VIPRE Advanced Security. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.\n\nThe specific flaw exists within the Patch Management Agent. By creating a symbolic link, an attacker can abuse the agent to delete a file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-22315.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5928" + }, + { + "type": "WEB", + "url": "https://success.vipre.com/en_US/home-windows-release-notes/home-windows-release-notes-20240227" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-817" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-21T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-q42h-967p-cm88/GHSA-q42h-967p-cm88.json b/advisories/unreviewed/2024/08/GHSA-q42h-967p-cm88/GHSA-q42h-967p-cm88.json new file mode 100644 index 00000000000..778df4fbf17 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-q42h-967p-cm88/GHSA-q42h-967p-cm88.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q42h-967p-cm88", + "modified": "2024-08-21T18:31:27Z", + "published": "2024-08-21T18:31:27Z", + "aliases": [ + "CVE-2024-7600" + ], + "details": "Logsign Unified SecOps Platform Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected installations of Logsign Unified SecOps Platform. Authentication is required to exploit this vulnerability.\n\nThe specific flaw exists within the HTTP API service, which listens on TCP port 443 by default. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to delete files in the context of root. Was ZDI-CAN-25025.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7600" + }, + { + "type": "WEB", + "url": "https://support.logsign.net/hc/en-us/articles/20617133769362-06-08-2024-Version-6-4-23-Release-Notes" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1103" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-21T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-q5xv-4chr-x766/GHSA-q5xv-4chr-x766.json b/advisories/unreviewed/2024/08/GHSA-q5xv-4chr-x766/GHSA-q5xv-4chr-x766.json new file mode 100644 index 00000000000..af1a06ac3b5 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-q5xv-4chr-x766/GHSA-q5xv-4chr-x766.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q5xv-4chr-x766", + "modified": "2024-08-21T18:31:27Z", + "published": "2024-08-21T18:31:27Z", + "aliases": [ + "CVE-2022-26327" + ], + "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in OpenText Performance Center on Windows allows Retrieve Embedded Sensitive Data.This issue affects Performance Center: 12.63.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:M/U:Clear" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-26327" + }, + { + "type": "WEB", + "url": "https://portal.microfocus.com/s/article/KM000006815?language=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-21T16:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-q9rp-4m44-qjc7/GHSA-q9rp-4m44-qjc7.json b/advisories/unreviewed/2024/08/GHSA-q9rp-4m44-qjc7/GHSA-q9rp-4m44-qjc7.json new file mode 100644 index 00000000000..7947f03f4a3 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-q9rp-4m44-qjc7/GHSA-q9rp-4m44-qjc7.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q9rp-4m44-qjc7", + "modified": "2024-08-21T18:31:27Z", + "published": "2024-08-21T18:31:27Z", + "aliases": [ + "CVE-2024-39344" + ], + "details": "An issue was discovered in the Docusign API package 8.142.14 for Salesforce. The Apttus_DocuApi__DocusignAuthentication__mdt object is installed via the marketplace from this package and stores some configuration information in a manner that could be compromised. With the default settings when installed for all users, the object can be accessible and (via its fields) could disclose some keys. These disclosed components can be combined to create a valid session via the Docusign API. This will generally lead to a complete compromise of the Docusign account because the session is for an administrator service account and may have permission to re-authenticate as specific users with the same authorization flow.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39344" + }, + { + "type": "WEB", + "url": "https://deneyed.com/blog/conga" + }, + { + "type": "WEB", + "url": "https://login.salesforce.com/packaging/installPackage.apexp?p0=04t6S000000YUDxQAO" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-21T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-qhpg-jf9r-mqxq/GHSA-qhpg-jf9r-mqxq.json b/advisories/unreviewed/2024/08/GHSA-qhpg-jf9r-mqxq/GHSA-qhpg-jf9r-mqxq.json index 7fca99c8237..d9634730a20 100644 --- a/advisories/unreviewed/2024/08/GHSA-qhpg-jf9r-mqxq/GHSA-qhpg-jf9r-mqxq.json +++ b/advisories/unreviewed/2024/08/GHSA-qhpg-jf9r-mqxq/GHSA-qhpg-jf9r-mqxq.json @@ -36,6 +36,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-190", "CWE-787" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2024/08/GHSA-r3cc-j4fw-h337/GHSA-r3cc-j4fw-h337.json b/advisories/unreviewed/2024/08/GHSA-r3cc-j4fw-h337/GHSA-r3cc-j4fw-h337.json index fe41a37a913..13e6a0ce5ee 100644 --- a/advisories/unreviewed/2024/08/GHSA-r3cc-j4fw-h337/GHSA-r3cc-j4fw-h337.json +++ b/advisories/unreviewed/2024/08/GHSA-r3cc-j4fw-h337/GHSA-r3cc-j4fw-h337.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r3cc-j4fw-h337", - "modified": "2024-08-19T06:30:54Z", + "modified": "2024-08-21T18:31:27Z", "published": "2024-08-19T06:30:54Z", "aliases": [ "CVE-2024-6843" ], "details": "The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not sanitise and escape user inputs, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks against admins", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-19T06:15:06Z" diff --git a/advisories/unreviewed/2024/08/GHSA-r3hw-cxxj-hj9v/GHSA-r3hw-cxxj-hj9v.json b/advisories/unreviewed/2024/08/GHSA-r3hw-cxxj-hj9v/GHSA-r3hw-cxxj-hj9v.json new file mode 100644 index 00000000000..818ccf6cf78 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-r3hw-cxxj-hj9v/GHSA-r3hw-cxxj-hj9v.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r3hw-cxxj-hj9v", + "modified": "2024-08-21T18:31:28Z", + "published": "2024-08-21T18:31:28Z", + "aliases": [ + "CVE-2024-42783" + ], + "details": "Kashipara Music Management System v1.0 is vulnerable to SQL Injection via /music/manage_playlist_items.php. An attacker can execute arbitrary SQL commands via the \"pid\" parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42783" + }, + { + "type": "WEB", + "url": "https://github.com/takekaramey/CVE_Writeup/blob/main/Kashipara/Music%20Management%20System%20v1.0/SQL%20Injection%20-%20Manage%20Playlist.pdf" + }, + { + "type": "WEB", + "url": "https://www.kashipara.com/project/php/12978/music-management-system-in-php-php-project-source-code" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-21T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-rhjx-jwv4-jj63/GHSA-rhjx-jwv4-jj63.json b/advisories/unreviewed/2024/08/GHSA-rhjx-jwv4-jj63/GHSA-rhjx-jwv4-jj63.json index 7874b9fdeed..5d74978e7c8 100644 --- a/advisories/unreviewed/2024/08/GHSA-rhjx-jwv4-jj63/GHSA-rhjx-jwv4-jj63.json +++ b/advisories/unreviewed/2024/08/GHSA-rhjx-jwv4-jj63/GHSA-rhjx-jwv4-jj63.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rhjx-jwv4-jj63", - "modified": "2024-08-12T21:31:34Z", + "modified": "2024-08-21T18:31:27Z", "published": "2024-08-12T21:31:34Z", "aliases": [ "CVE-2024-40892" @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://vulncheck.com/advisories/firewalla-bt-weak-credentials" + }, + { + "type": "WEB", + "url": "https://www.labs.greynoise.io/grimoire/2024-08-20-bluuid-firewalla" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/08/GHSA-rhrw-ch52-5vhp/GHSA-rhrw-ch52-5vhp.json b/advisories/unreviewed/2024/08/GHSA-rhrw-ch52-5vhp/GHSA-rhrw-ch52-5vhp.json new file mode 100644 index 00000000000..4fc8f0bc334 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-rhrw-ch52-5vhp/GHSA-rhrw-ch52-5vhp.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rhrw-ch52-5vhp", + "modified": "2024-08-21T18:31:28Z", + "published": "2024-08-21T18:31:28Z", + "aliases": [ + "CVE-2024-42785" + ], + "details": "A SQL injection vulnerability in /music/index.php?page=view_playlist in Kashipara Music Management System v1.0 allows an attacker to execute arbitrary SQL commands via the \"id\" parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42785" + }, + { + "type": "WEB", + "url": "https://github.com/takekaramey/CVE_Writeup/blob/main/Kashipara/Music%20Management%20System%20v1.0/SQL%20Injection%20-%20View%20Playlist.pdf" + }, + { + "type": "WEB", + "url": "https://www.kashipara.com/project/php/12978/music-management-system-in-php-php-project-source-code" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-21T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-rqxc-qv82-j8gh/GHSA-rqxc-qv82-j8gh.json b/advisories/unreviewed/2024/08/GHSA-rqxc-qv82-j8gh/GHSA-rqxc-qv82-j8gh.json new file mode 100644 index 00000000000..4067990733d --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-rqxc-qv82-j8gh/GHSA-rqxc-qv82-j8gh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rqxc-qv82-j8gh", + "modified": "2024-08-21T18:31:27Z", + "published": "2024-08-21T18:31:27Z", + "aliases": [ + "CVE-2024-6811" + ], + "details": "IrfanView WSQ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of WSQ files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24192.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6811" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-903" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-21T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-v4cc-wwr9-44vw/GHSA-v4cc-wwr9-44vw.json b/advisories/unreviewed/2024/08/GHSA-v4cc-wwr9-44vw/GHSA-v4cc-wwr9-44vw.json index c9f5e9e5ed5..7d4dbc1c28e 100644 --- a/advisories/unreviewed/2024/08/GHSA-v4cc-wwr9-44vw/GHSA-v4cc-wwr9-44vw.json +++ b/advisories/unreviewed/2024/08/GHSA-v4cc-wwr9-44vw/GHSA-v4cc-wwr9-44vw.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-601" + "CWE-601", + "CWE-79" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-v735-hrpq-c278/GHSA-v735-hrpq-c278.json b/advisories/unreviewed/2024/08/GHSA-v735-hrpq-c278/GHSA-v735-hrpq-c278.json index 4c5e8643a48..ac7535a52b8 100644 --- a/advisories/unreviewed/2024/08/GHSA-v735-hrpq-c278/GHSA-v735-hrpq-c278.json +++ b/advisories/unreviewed/2024/08/GHSA-v735-hrpq-c278/GHSA-v735-hrpq-c278.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-601", "CWE-79" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/08/GHSA-w5pw-gmcw-rfc8/GHSA-w5pw-gmcw-rfc8.json b/advisories/unreviewed/2024/08/GHSA-w5pw-gmcw-rfc8/GHSA-w5pw-gmcw-rfc8.json new file mode 100644 index 00000000000..edbf8ff5517 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-w5pw-gmcw-rfc8/GHSA-w5pw-gmcw-rfc8.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w5pw-gmcw-rfc8", + "modified": "2024-08-21T18:31:28Z", + "published": "2024-08-21T18:31:28Z", + "aliases": [ + "CVE-2024-40453" + ], + "details": "squirrellyjs squirrelly v9.0.0 and fixed in v.9.0.1 was discovered to contain a code injection vulnerability via the component options.varName.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40453" + }, + { + "type": "WEB", + "url": "https://github.com/squirrellyjs/squirrelly/pull/262" + }, + { + "type": "WEB", + "url": "https://github.com/squirrellyjs/squirrelly" + }, + { + "type": "WEB", + "url": "https://samuzora.com/posts/cve-2024-40453" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-21T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-w7cp-g8v7-r54m/GHSA-w7cp-g8v7-r54m.json b/advisories/unreviewed/2024/08/GHSA-w7cp-g8v7-r54m/GHSA-w7cp-g8v7-r54m.json new file mode 100644 index 00000000000..6595ce41b5e --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-w7cp-g8v7-r54m/GHSA-w7cp-g8v7-r54m.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w7cp-g8v7-r54m", + "modified": "2024-08-21T18:31:27Z", + "published": "2024-08-21T18:31:27Z", + "aliases": [ + "CVE-2024-41937" + ], + "details": "Apache Airflow, versions before 2.10.0, have a vulnerability that allows the developer of a malicious provider to execute a cross-site scripting attack when clicking on a provider documentation link. This would require the provider to be installed on the web server and the user to click the provider link.\nUsers should upgrade to 2.10.0 or later, which fixes this vulnerability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41937" + }, + { + "type": "WEB", + "url": "https://github.com/apache/airflow/pull/40933" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/lwlmgg6hqfmkpvw5py4w53hxyl37jl6d" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-21T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-xr6g-6vm5-7r58/GHSA-xr6g-6vm5-7r58.json b/advisories/unreviewed/2024/08/GHSA-xr6g-6vm5-7r58/GHSA-xr6g-6vm5-7r58.json new file mode 100644 index 00000000000..f2e4a7956f9 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-xr6g-6vm5-7r58/GHSA-xr6g-6vm5-7r58.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xr6g-6vm5-7r58", + "modified": "2024-08-21T18:31:27Z", + "published": "2024-08-21T18:31:27Z", + "aliases": [ + "CVE-2024-6813" + ], + "details": "NETGEAR ProSAFE Network Management System getSortString SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System. Authentication is required to exploit this vulnerability.\n\nThe specific flaw exists within the getSortString method. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-23207.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6813" + }, + { + "type": "WEB", + "url": "https://kb.netgear.com/000066231/Security-Advisory-for-SQL-Injection-on-the-NMS300-PSV-2024-0018" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-902" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-21T16:15:09Z" + } +} \ No newline at end of file