From 11006880f4075e65844798ffb55778fa45d461c7 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 3 Jul 2024 18:46:39 +0000 Subject: [PATCH] Advisory Database Sync --- .../06/GHSA-23q6-wpc7-6vv9/GHSA-23q6-wpc7-6vv9.json | 11 +++++++---- .../06/GHSA-26hp-vwv6-p4qg/GHSA-26hp-vwv6-p4qg.json | 9 ++++++--- .../06/GHSA-2768-785q-97pf/GHSA-2768-785q-97pf.json | 11 +++++++---- .../06/GHSA-285m-hpgq-v7jg/GHSA-285m-hpgq-v7jg.json | 11 +++++++---- .../06/GHSA-2gf4-m97g-cvpw/GHSA-2gf4-m97g-cvpw.json | 1 + .../06/GHSA-2h9q-5qx9-w5fm/GHSA-2h9q-5qx9-w5fm.json | 11 +++++++---- .../06/GHSA-2q7f-pr29-qfh5/GHSA-2q7f-pr29-qfh5.json | 9 ++++++--- .../06/GHSA-35qw-m5x8-mjp9/GHSA-35qw-m5x8-mjp9.json | 11 +++++++---- .../06/GHSA-36cc-q99j-cg4r/GHSA-36cc-q99j-cg4r.json | 11 +++++++---- .../06/GHSA-39m6-6wm4-cm5w/GHSA-39m6-6wm4-cm5w.json | 11 +++++++---- .../06/GHSA-39wq-w29m-4ccv/GHSA-39wq-w29m-4ccv.json | 9 ++++++--- .../06/GHSA-3g94-3h93-rrf8/GHSA-3g94-3h93-rrf8.json | 2 +- .../06/GHSA-3qjq-fqq3-9cxq/GHSA-3qjq-fqq3-9cxq.json | 11 +++++++---- .../06/GHSA-3vf3-j8cr-x4g6/GHSA-3vf3-j8cr-x4g6.json | 9 ++++++--- .../06/GHSA-3w3g-gjcj-rg22/GHSA-3w3g-gjcj-rg22.json | 2 +- .../06/GHSA-3wf5-cgv3-f3xm/GHSA-3wf5-cgv3-f3xm.json | 11 +++++++---- .../06/GHSA-3wrh-pmfv-38f4/GHSA-3wrh-pmfv-38f4.json | 11 +++++++---- .../06/GHSA-3xmm-gqgf-3954/GHSA-3xmm-gqgf-3954.json | 11 +++++++---- .../06/GHSA-3xp5-7h92-mqvv/GHSA-3xp5-7h92-mqvv.json | 9 ++++++--- .../06/GHSA-438m-xg9x-7hw2/GHSA-438m-xg9x-7hw2.json | 11 +++++++---- .../06/GHSA-4586-3357-8wqx/GHSA-4586-3357-8wqx.json | 11 +++++++---- .../06/GHSA-45hc-5gcq-4f89/GHSA-45hc-5gcq-4f89.json | 11 +++++++---- .../06/GHSA-45xf-mpvq-5ggq/GHSA-45xf-mpvq-5ggq.json | 11 +++++++---- .../06/GHSA-463q-9cmj-p927/GHSA-463q-9cmj-p927.json | 11 +++++++---- .../06/GHSA-4c8g-9w4h-h6xm/GHSA-4c8g-9w4h-h6xm.json | 11 +++++++---- .../06/GHSA-4hr5-7rwf-2v8m/GHSA-4hr5-7rwf-2v8m.json | 11 +++++++---- .../06/GHSA-4hrj-6fhw-hcvf/GHSA-4hrj-6fhw-hcvf.json | 1 + .../06/GHSA-4qp3-jrq9-p7cj/GHSA-4qp3-jrq9-p7cj.json | 11 +++++++---- .../06/GHSA-4v25-p375-pcjc/GHSA-4v25-p375-pcjc.json | 11 +++++++---- .../06/GHSA-52h3-8452-j3mp/GHSA-52h3-8452-j3mp.json | 11 +++++++---- .../06/GHSA-55gj-hcpf-vg3h/GHSA-55gj-hcpf-vg3h.json | 9 ++++++--- .../06/GHSA-596p-4hx4-frm9/GHSA-596p-4hx4-frm9.json | 2 +- .../06/GHSA-59h3-wp7j-68gw/GHSA-59h3-wp7j-68gw.json | 11 +++++++---- .../06/GHSA-5f56-q773-9mqx/GHSA-5f56-q773-9mqx.json | 11 +++++++---- .../06/GHSA-5hmf-j4j4-rx89/GHSA-5hmf-j4j4-rx89.json | 2 +- .../06/GHSA-5m73-fvjx-xcxp/GHSA-5m73-fvjx-xcxp.json | 11 +++++++---- .../06/GHSA-63c3-hhxg-g55x/GHSA-63c3-hhxg-g55x.json | 11 +++++++---- .../06/GHSA-664v-jfq4-4mfq/GHSA-664v-jfq4-4mfq.json | 2 +- .../06/GHSA-68f4-m7ww-959w/GHSA-68f4-m7ww-959w.json | 11 +++++++---- .../06/GHSA-6m29-47p2-88v7/GHSA-6m29-47p2-88v7.json | 11 +++++++---- .../06/GHSA-6vrv-6qrf-5vwc/GHSA-6vrv-6qrf-5vwc.json | 11 +++++++---- .../06/GHSA-6w47-r8r6-rg62/GHSA-6w47-r8r6-rg62.json | 9 ++++++--- .../06/GHSA-6x2p-g636-5378/GHSA-6x2p-g636-5378.json | 9 ++++++--- .../06/GHSA-75hq-pffg-m782/GHSA-75hq-pffg-m782.json | 11 +++++++---- .../06/GHSA-77m3-6865-xvqj/GHSA-77m3-6865-xvqj.json | 9 ++++++--- .../06/GHSA-79gc-6j6c-pf3r/GHSA-79gc-6j6c-pf3r.json | 11 +++++++---- .../06/GHSA-7crc-mm89-h2v3/GHSA-7crc-mm89-h2v3.json | 9 ++++++--- .../06/GHSA-7f3w-mgjh-m27h/GHSA-7f3w-mgjh-m27h.json | 9 ++++++--- .../06/GHSA-7h7x-82v3-hpfw/GHSA-7h7x-82v3-hpfw.json | 2 +- .../06/GHSA-7hhm-xr5c-ff6q/GHSA-7hhm-xr5c-ff6q.json | 2 +- .../06/GHSA-7hqq-74mf-cgjh/GHSA-7hqq-74mf-cgjh.json | 11 +++++++---- .../06/GHSA-7m6w-cvrv-x8wx/GHSA-7m6w-cvrv-x8wx.json | 9 ++++++--- .../06/GHSA-7rr6-h953-f687/GHSA-7rr6-h953-f687.json | 11 +++++++---- .../06/GHSA-7x84-wx2f-425f/GHSA-7x84-wx2f-425f.json | 11 +++++++---- .../06/GHSA-82rc-cc5p-ff4m/GHSA-82rc-cc5p-ff4m.json | 11 +++++++---- .../06/GHSA-83f3-v49v-w4h7/GHSA-83f3-v49v-w4h7.json | 9 ++++++--- .../06/GHSA-844m-hq7r-wxc8/GHSA-844m-hq7r-wxc8.json | 9 ++++++--- .../06/GHSA-868x-mj3q-c3w4/GHSA-868x-mj3q-c3w4.json | 11 +++++++---- .../06/GHSA-88qc-mqvh-78h6/GHSA-88qc-mqvh-78h6.json | 11 +++++++---- .../06/GHSA-89r8-fpgw-f2hq/GHSA-89r8-fpgw-f2hq.json | 2 +- .../06/GHSA-89w5-xc64-fw9r/GHSA-89w5-xc64-fw9r.json | 11 +++++++---- .../06/GHSA-8fq9-7wwx-42v9/GHSA-8fq9-7wwx-42v9.json | 11 +++++++---- .../06/GHSA-8j3w-26mp-75xh/GHSA-8j3w-26mp-75xh.json | 11 +++++++---- .../06/GHSA-93vj-795w-gh3c/GHSA-93vj-795w-gh3c.json | 1 + .../06/GHSA-974x-72x9-f6mr/GHSA-974x-72x9-f6mr.json | 2 +- .../06/GHSA-99x5-vp7j-568g/GHSA-99x5-vp7j-568g.json | 9 ++++++--- .../06/GHSA-9fcr-j456-qxxg/GHSA-9fcr-j456-qxxg.json | 9 ++++++--- .../06/GHSA-9g5w-2h6h-7h82/GHSA-9g5w-2h6h-7h82.json | 11 +++++++---- .../06/GHSA-9gv9-r7fp-ffxq/GHSA-9gv9-r7fp-ffxq.json | 11 +++++++---- .../06/GHSA-9p2j-9mm4-8r6m/GHSA-9p2j-9mm4-8r6m.json | 1 + .../06/GHSA-9q42-j26w-29g5/GHSA-9q42-j26w-29g5.json | 11 +++++++---- .../06/GHSA-9q5f-4c6v-g36c/GHSA-9q5f-4c6v-g36c.json | 11 +++++++---- .../06/GHSA-9qvw-39px-9m92/GHSA-9qvw-39px-9m92.json | 11 +++++++---- .../06/GHSA-9wpf-m764-qmf8/GHSA-9wpf-m764-qmf8.json | 11 +++++++---- .../06/GHSA-c39h-g3mf-r3mh/GHSA-c39h-g3mf-r3mh.json | 11 +++++++---- .../06/GHSA-c4mh-cv6m-6477/GHSA-c4mh-cv6m-6477.json | 11 +++++++---- .../06/GHSA-c5vq-9hf6-g7cw/GHSA-c5vq-9hf6-g7cw.json | 2 +- .../06/GHSA-cvp2-j7mv-gx79/GHSA-cvp2-j7mv-gx79.json | 9 ++++++--- .../06/GHSA-cvwq-q64c-wrq2/GHSA-cvwq-q64c-wrq2.json | 11 +++++++---- .../06/GHSA-cw2f-ggf4-p3jf/GHSA-cw2f-ggf4-p3jf.json | 2 +- .../06/GHSA-cwx8-r7cr-cfgf/GHSA-cwx8-r7cr-cfgf.json | 11 +++++++---- .../06/GHSA-f62c-6722-rv46/GHSA-f62c-6722-rv46.json | 11 +++++++---- .../06/GHSA-f6vh-wx77-fcc5/GHSA-f6vh-wx77-fcc5.json | 9 ++++++--- .../06/GHSA-f935-6jhc-wv29/GHSA-f935-6jhc-wv29.json | 11 +++++++---- .../06/GHSA-fcqv-w7xc-5vmc/GHSA-fcqv-w7xc-5vmc.json | 11 +++++++---- .../06/GHSA-fcw5-xg8j-vw6m/GHSA-fcw5-xg8j-vw6m.json | 2 +- .../06/GHSA-fg32-7hw7-w82p/GHSA-fg32-7hw7-w82p.json | 11 +++++++---- .../06/GHSA-frw3-949h-qqfj/GHSA-frw3-949h-qqfj.json | 11 +++++++---- .../06/GHSA-fvqw-wg8v-hmcw/GHSA-fvqw-wg8v-hmcw.json | 12 ++++++++---- .../06/GHSA-fxvf-jcp9-ch47/GHSA-fxvf-jcp9-ch47.json | 11 +++++++---- .../06/GHSA-g23m-h4v3-g2qq/GHSA-g23m-h4v3-g2qq.json | 11 +++++++---- .../06/GHSA-g3vc-vgcj-26vj/GHSA-g3vc-vgcj-26vj.json | 2 +- .../06/GHSA-g7xm-f45g-5wvg/GHSA-g7xm-f45g-5wvg.json | 9 ++++++--- .../06/GHSA-gc36-qqwf-f29m/GHSA-gc36-qqwf-f29m.json | 11 +++++++---- .../06/GHSA-gc8r-pxj9-hhx3/GHSA-gc8r-pxj9-hhx3.json | 6 +++++- .../06/GHSA-gc92-5p58-4rf7/GHSA-gc92-5p58-4rf7.json | 2 +- .../06/GHSA-ggmq-9v8m-wpjv/GHSA-ggmq-9v8m-wpjv.json | 11 +++++++---- .../06/GHSA-gj92-fpwq-8c5r/GHSA-gj92-fpwq-8c5r.json | 11 +++++++---- .../06/GHSA-gm2v-mf3r-56jr/GHSA-gm2v-mf3r-56jr.json | 11 +++++++---- .../06/GHSA-gp2x-43x3-838x/GHSA-gp2x-43x3-838x.json | 11 +++++++---- .../06/GHSA-gq4w-r5jj-3rgg/GHSA-gq4w-r5jj-3rgg.json | 11 +++++++---- .../06/GHSA-h4fx-g364-89c4/GHSA-h4fx-g364-89c4.json | 11 +++++++---- .../06/GHSA-h7v5-c8v4-f6pp/GHSA-h7v5-c8v4-f6pp.json | 11 +++++++---- .../06/GHSA-h98r-frj5-jj3c/GHSA-h98r-frj5-jj3c.json | 9 ++++++--- .../06/GHSA-h9h2-6w4q-6c52/GHSA-h9h2-6w4q-6c52.json | 11 +++++++---- .../06/GHSA-hccj-9v6g-qxjv/GHSA-hccj-9v6g-qxjv.json | 11 +++++++---- .../06/GHSA-hh8j-c7wj-qpfj/GHSA-hh8j-c7wj-qpfj.json | 11 +++++++---- .../06/GHSA-hmc2-hhww-hmr3/GHSA-hmc2-hhww-hmr3.json | 11 +++++++---- .../06/GHSA-hv3w-wgcx-8ggg/GHSA-hv3w-wgcx-8ggg.json | 11 +++++++---- .../06/GHSA-hvrf-34fw-qpr2/GHSA-hvrf-34fw-qpr2.json | 11 +++++++---- .../06/GHSA-j24x-6m7r-h4gp/GHSA-j24x-6m7r-h4gp.json | 9 ++++++--- .../06/GHSA-j4rp-pq8q-wm7r/GHSA-j4rp-pq8q-wm7r.json | 11 +++++++---- .../06/GHSA-j4rv-c6x5-m7c5/GHSA-j4rv-c6x5-m7c5.json | 11 +++++++---- .../06/GHSA-j67r-3cm4-272w/GHSA-j67r-3cm4-272w.json | 1 + .../06/GHSA-j764-4v6h-pqp7/GHSA-j764-4v6h-pqp7.json | 11 +++++++---- .../06/GHSA-j776-p2rm-mmrr/GHSA-j776-p2rm-mmrr.json | 11 +++++++---- .../06/GHSA-j78x-grcm-g49w/GHSA-j78x-grcm-g49w.json | 11 +++++++---- .../06/GHSA-j85x-732x-xq8q/GHSA-j85x-732x-xq8q.json | 13 ++++++++++--- .../06/GHSA-jcpq-9r39-jhwp/GHSA-jcpq-9r39-jhwp.json | 11 +++++++---- .../06/GHSA-jp38-8m55-7qcq/GHSA-jp38-8m55-7qcq.json | 3 ++- .../06/GHSA-jpjh-5cvh-hrp7/GHSA-jpjh-5cvh-hrp7.json | 2 +- .../06/GHSA-jq84-946j-r77q/GHSA-jq84-946j-r77q.json | 11 +++++++---- .../06/GHSA-m2cr-jxg8-pr4v/GHSA-m2cr-jxg8-pr4v.json | 3 ++- .../06/GHSA-m4wv-7q3w-5mq7/GHSA-m4wv-7q3w-5mq7.json | 11 +++++++---- .../06/GHSA-m7m7-q9w5-x57c/GHSA-m7m7-q9w5-x57c.json | 9 ++++++--- .../06/GHSA-m869-mpfx-h3g2/GHSA-m869-mpfx-h3g2.json | 11 +++++++---- .../06/GHSA-m8cv-83cf-qccx/GHSA-m8cv-83cf-qccx.json | 2 +- .../06/GHSA-m8h7-pff8-m5jq/GHSA-m8h7-pff8-m5jq.json | 11 +++++++---- .../06/GHSA-m9f8-fccv-p7vh/GHSA-m9f8-fccv-p7vh.json | 2 +- .../06/GHSA-p546-cwvc-mhpj/GHSA-p546-cwvc-mhpj.json | 11 +++++++---- .../06/GHSA-p595-g9xq-jgcw/GHSA-p595-g9xq-jgcw.json | 2 +- .../06/GHSA-p5mm-8cpw-hr23/GHSA-p5mm-8cpw-hr23.json | 11 +++++++---- .../06/GHSA-p763-v5vh-f5mg/GHSA-p763-v5vh-f5mg.json | 11 +++++++---- .../06/GHSA-p9qg-6v6v-2g47/GHSA-p9qg-6v6v-2g47.json | 11 +++++++---- .../06/GHSA-phxr-ggj2-vch6/GHSA-phxr-ggj2-vch6.json | 9 ++++++--- .../06/GHSA-pq6v-hjqm-frww/GHSA-pq6v-hjqm-frww.json | 11 +++++++---- .../06/GHSA-pwf2-5r2p-9c9w/GHSA-pwf2-5r2p-9c9w.json | 2 +- .../06/GHSA-pwhf-f7xh-4q76/GHSA-pwhf-f7xh-4q76.json | 11 +++++++---- .../06/GHSA-pxf8-583j-3rmh/GHSA-pxf8-583j-3rmh.json | 11 +++++++---- .../06/GHSA-q7hf-4g47-96r8/GHSA-q7hf-4g47-96r8.json | 11 +++++++---- .../06/GHSA-qc27-qr34-95w5/GHSA-qc27-qr34-95w5.json | 11 +++++++---- .../06/GHSA-qp28-67v3-65qc/GHSA-qp28-67v3-65qc.json | 9 ++++++--- .../06/GHSA-qpxp-m569-qp25/GHSA-qpxp-m569-qp25.json | 11 +++++++---- .../06/GHSA-qqfm-9jcc-9q44/GHSA-qqfm-9jcc-9q44.json | 11 +++++++---- .../06/GHSA-qvvc-v3mj-qch5/GHSA-qvvc-v3mj-qch5.json | 2 +- .../06/GHSA-qxgm-2hhj-rw7f/GHSA-qxgm-2hhj-rw7f.json | 2 +- .../06/GHSA-r4g5-x2h5-r8gg/GHSA-r4g5-x2h5-r8gg.json | 2 +- .../06/GHSA-r6h6-9448-4q2f/GHSA-r6h6-9448-4q2f.json | 11 +++++++---- .../06/GHSA-r96m-mwvr-946h/GHSA-r96m-mwvr-946h.json | 2 +- .../06/GHSA-rcq4-qh6m-j28q/GHSA-rcq4-qh6m-j28q.json | 11 +++++++---- .../06/GHSA-rg42-f9ww-x3w7/GHSA-rg42-f9ww-x3w7.json | 2 +- .../06/GHSA-rgw4-v387-9jvw/GHSA-rgw4-v387-9jvw.json | 9 ++++++--- .../06/GHSA-rhv4-3chh-r5jc/GHSA-rhv4-3chh-r5jc.json | 4 ++-- .../06/GHSA-rmff-fqq9-pc3q/GHSA-rmff-fqq9-pc3q.json | 2 +- .../06/GHSA-rmh4-q56p-p5w5/GHSA-rmh4-q56p-p5w5.json | 11 +++++++---- .../06/GHSA-rmx5-8m2v-hpmw/GHSA-rmx5-8m2v-hpmw.json | 11 +++++++---- .../06/GHSA-rp47-r8r5-fmgm/GHSA-rp47-r8r5-fmgm.json | 11 +++++++---- .../06/GHSA-rp5x-rj69-r36x/GHSA-rp5x-rj69-r36x.json | 2 +- .../06/GHSA-rxh8-v6x2-m5h4/GHSA-rxh8-v6x2-m5h4.json | 9 ++++++--- .../06/GHSA-v23v-9j7q-mjq6/GHSA-v23v-9j7q-mjq6.json | 11 +++++++---- .../06/GHSA-v8pv-8xhp-96rh/GHSA-v8pv-8xhp-96rh.json | 2 +- .../06/GHSA-vjmq-27j9-636j/GHSA-vjmq-27j9-636j.json | 11 +++++++---- .../06/GHSA-vqcc-7gmh-v9jr/GHSA-vqcc-7gmh-v9jr.json | 11 +++++++---- .../06/GHSA-vx52-cgqj-7pvr/GHSA-vx52-cgqj-7pvr.json | 11 +++++++---- .../06/GHSA-vxqj-33jf-35x5/GHSA-vxqj-33jf-35x5.json | 12 ++++++++---- .../06/GHSA-w69w-gv35-vqjh/GHSA-w69w-gv35-vqjh.json | 2 +- .../06/GHSA-w7h8-wmjg-8jqm/GHSA-w7h8-wmjg-8jqm.json | 11 +++++++---- .../06/GHSA-w8j6-vhx2-7qvh/GHSA-w8j6-vhx2-7qvh.json | 9 ++++++--- .../06/GHSA-wr2f-45vv-3hjc/GHSA-wr2f-45vv-3hjc.json | 11 +++++++---- .../06/GHSA-wrc7-97qh-j6mh/GHSA-wrc7-97qh-j6mh.json | 11 +++++++---- .../06/GHSA-ww9f-v5vc-69w2/GHSA-ww9f-v5vc-69w2.json | 11 +++++++---- .../06/GHSA-x756-rqwh-fr4m/GHSA-x756-rqwh-fr4m.json | 11 +++++++---- .../06/GHSA-x8qf-jpxw-cwjv/GHSA-x8qf-jpxw-cwjv.json | 11 +++++++---- .../06/GHSA-xf4m-339r-jvfr/GHSA-xf4m-339r-jvfr.json | 9 ++++++--- .../06/GHSA-xhf3-pp4q-gxh5/GHSA-xhf3-pp4q-gxh5.json | 11 +++++++---- .../06/GHSA-xjc7-gh59-3hp4/GHSA-xjc7-gh59-3hp4.json | 11 +++++++---- .../06/GHSA-xjjc-xf36-3jp9/GHSA-xjjc-xf36-3jp9.json | 11 +++++++---- .../06/GHSA-xm9v-fg48-44v7/GHSA-xm9v-fg48-44v7.json | 3 ++- .../06/GHSA-xmvf-wm3q-gh2f/GHSA-xmvf-wm3q-gh2f.json | 11 +++++++---- .../06/GHSA-xp8w-jxfc-xrqq/GHSA-xp8w-jxfc-xrqq.json | 11 +++++++---- .../06/GHSA-xqg8-fm8q-c2p5/GHSA-xqg8-fm8q-c2p5.json | 11 +++++++---- .../06/GHSA-xwrr-9h7c-8mxc/GHSA-xwrr-9h7c-8mxc.json | 2 +- 182 files changed, 1025 insertions(+), 578 deletions(-) diff --git a/advisories/unreviewed/2024/06/GHSA-23q6-wpc7-6vv9/GHSA-23q6-wpc7-6vv9.json b/advisories/unreviewed/2024/06/GHSA-23q6-wpc7-6vv9/GHSA-23q6-wpc7-6vv9.json index 562897512c1..13d6503650d 100644 --- a/advisories/unreviewed/2024/06/GHSA-23q6-wpc7-6vv9/GHSA-23q6-wpc7-6vv9.json +++ b/advisories/unreviewed/2024/06/GHSA-23q6-wpc7-6vv9/GHSA-23q6-wpc7-6vv9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-23q6-wpc7-6vv9", - "modified": "2024-06-11T06:31:47Z", + "modified": "2024-07-03T18:44:42Z", "published": "2024-06-11T06:31:46Z", "aliases": [ "CVE-2024-31401" ], "details": "Cross-site scripting vulnerability in Cybozu Garoon 5.0.0 to 5.15.2 allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script on the web browser of the user who is logging in to the product.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-11T05:15:53Z" diff --git a/advisories/unreviewed/2024/06/GHSA-26hp-vwv6-p4qg/GHSA-26hp-vwv6-p4qg.json b/advisories/unreviewed/2024/06/GHSA-26hp-vwv6-p4qg/GHSA-26hp-vwv6-p4qg.json index c5b8aab3894..e34420688b5 100644 --- a/advisories/unreviewed/2024/06/GHSA-26hp-vwv6-p4qg/GHSA-26hp-vwv6-p4qg.json +++ b/advisories/unreviewed/2024/06/GHSA-26hp-vwv6-p4qg/GHSA-26hp-vwv6-p4qg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-26hp-vwv6-p4qg", - "modified": "2024-06-11T09:30:59Z", + "modified": "2024-07-03T18:44:36Z", "published": "2024-06-10T21:30:40Z", "aliases": [ "CVE-2024-27855" ], "details": "The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.5, macOS Ventura 13.6.7, iOS 17.5 and iPadOS 17.5, iOS 16.7.8 and iPadOS 16.7.8. A shortcut may be able to use sensitive data with certain actions without prompting the user.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -55,7 +58,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-10T21:15:51Z" diff --git a/advisories/unreviewed/2024/06/GHSA-2768-785q-97pf/GHSA-2768-785q-97pf.json b/advisories/unreviewed/2024/06/GHSA-2768-785q-97pf/GHSA-2768-785q-97pf.json index 1ee4265c7fb..8f9f50ae2eb 100644 --- a/advisories/unreviewed/2024/06/GHSA-2768-785q-97pf/GHSA-2768-785q-97pf.json +++ b/advisories/unreviewed/2024/06/GHSA-2768-785q-97pf/GHSA-2768-785q-97pf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2768-785q-97pf", - "modified": "2024-06-19T09:31:16Z", + "modified": "2024-07-03T18:45:50Z", "published": "2024-06-19T09:31:16Z", "aliases": [ "CVE-2024-36252" ], "details": "Improper restriction of communication channel to intended endpoints issue exists in Ricoh Streamline NX PC Client ver.3.6.x and earlier. If this vulnerability is exploited, arbitrary code may be executed on the PC where the product is installed.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-923" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-19T07:15:46Z" diff --git a/advisories/unreviewed/2024/06/GHSA-285m-hpgq-v7jg/GHSA-285m-hpgq-v7jg.json b/advisories/unreviewed/2024/06/GHSA-285m-hpgq-v7jg/GHSA-285m-hpgq-v7jg.json index df78fa9a67e..8cc73cba797 100644 --- a/advisories/unreviewed/2024/06/GHSA-285m-hpgq-v7jg/GHSA-285m-hpgq-v7jg.json +++ b/advisories/unreviewed/2024/06/GHSA-285m-hpgq-v7jg/GHSA-285m-hpgq-v7jg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-285m-hpgq-v7jg", - "modified": "2024-06-16T18:31:21Z", + "modified": "2024-07-03T18:45:32Z", "published": "2024-06-16T18:31:21Z", "aliases": [ "CVE-2024-38467" ], "details": "Shenzhen Guoxin Synthesis image system before 8.3.0 allows unauthorized user information retrieval via the queryUser API.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-16T16:15:09Z" diff --git a/advisories/unreviewed/2024/06/GHSA-2gf4-m97g-cvpw/GHSA-2gf4-m97g-cvpw.json b/advisories/unreviewed/2024/06/GHSA-2gf4-m97g-cvpw/GHSA-2gf4-m97g-cvpw.json index dc594beda26..8e08f9f57bf 100644 --- a/advisories/unreviewed/2024/06/GHSA-2gf4-m97g-cvpw/GHSA-2gf4-m97g-cvpw.json +++ b/advisories/unreviewed/2024/06/GHSA-2gf4-m97g-cvpw/GHSA-2gf4-m97g-cvpw.json @@ -40,6 +40,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/06/GHSA-2h9q-5qx9-w5fm/GHSA-2h9q-5qx9-w5fm.json b/advisories/unreviewed/2024/06/GHSA-2h9q-5qx9-w5fm/GHSA-2h9q-5qx9-w5fm.json index 08e51d710bd..7f2e345f047 100644 --- a/advisories/unreviewed/2024/06/GHSA-2h9q-5qx9-w5fm/GHSA-2h9q-5qx9-w5fm.json +++ b/advisories/unreviewed/2024/06/GHSA-2h9q-5qx9-w5fm/GHSA-2h9q-5qx9-w5fm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2h9q-5qx9-w5fm", - "modified": "2024-06-17T09:31:02Z", + "modified": "2024-07-03T18:45:36Z", "published": "2024-06-17T09:31:02Z", "aliases": [ "CVE-2024-36289" ], "details": "Reusing a nonce, key pair in encryption issue exists in \"FreeFrom - the nostr client\" App versions prior to 1.3.5 for Android and iOS. If this vulnerability is exploited, the content of direct messages (DMs) between users may be manipulated by a man-in-the-middle attack.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-323" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-17T08:15:49Z" diff --git a/advisories/unreviewed/2024/06/GHSA-2q7f-pr29-qfh5/GHSA-2q7f-pr29-qfh5.json b/advisories/unreviewed/2024/06/GHSA-2q7f-pr29-qfh5/GHSA-2q7f-pr29-qfh5.json index 3361fe5bddf..858d3da8e69 100644 --- a/advisories/unreviewed/2024/06/GHSA-2q7f-pr29-qfh5/GHSA-2q7f-pr29-qfh5.json +++ b/advisories/unreviewed/2024/06/GHSA-2q7f-pr29-qfh5/GHSA-2q7f-pr29-qfh5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2q7f-pr29-qfh5", - "modified": "2024-06-11T00:30:40Z", + "modified": "2024-07-03T18:44:41Z", "published": "2024-06-11T00:30:40Z", "aliases": [ "CVE-2024-36471" ], "details": "Import functionality is vulnerable to DNS rebinding attacks between verification and processing of the URL.  Project administrators can run these imports, which could cause Allura to read from internal services and expose them.\n\nThis issue affects Apache Allura from 1.0.1 through 1.16.0.\n\nUsers are recommended to upgrade to version 1.17.0, which fixes the issue. If you are unable to upgrade, set \"disable_entry_points.allura.importers = forge-tracker, forge-discussion\" in your .ini config file.\n\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-20" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-10T22:15:11Z" diff --git a/advisories/unreviewed/2024/06/GHSA-35qw-m5x8-mjp9/GHSA-35qw-m5x8-mjp9.json b/advisories/unreviewed/2024/06/GHSA-35qw-m5x8-mjp9/GHSA-35qw-m5x8-mjp9.json index f7b88e3db2d..67958dde8ea 100644 --- a/advisories/unreviewed/2024/06/GHSA-35qw-m5x8-mjp9/GHSA-35qw-m5x8-mjp9.json +++ b/advisories/unreviewed/2024/06/GHSA-35qw-m5x8-mjp9/GHSA-35qw-m5x8-mjp9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-35qw-m5x8-mjp9", - "modified": "2024-06-17T21:31:10Z", + "modified": "2024-07-03T18:45:42Z", "published": "2024-06-17T21:31:10Z", "aliases": [ "CVE-2024-37840" ], "details": "SQL injection vulnerability in processscore.php in Itsourcecode Learning Management System Project In PHP With Source Code v1.0 allows remote attackers to execute arbitrary SQL commands via the LessonID parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-17T19:15:58Z" diff --git a/advisories/unreviewed/2024/06/GHSA-36cc-q99j-cg4r/GHSA-36cc-q99j-cg4r.json b/advisories/unreviewed/2024/06/GHSA-36cc-q99j-cg4r/GHSA-36cc-q99j-cg4r.json index 4989ff3c2cf..a19cd45c58b 100644 --- a/advisories/unreviewed/2024/06/GHSA-36cc-q99j-cg4r/GHSA-36cc-q99j-cg4r.json +++ b/advisories/unreviewed/2024/06/GHSA-36cc-q99j-cg4r/GHSA-36cc-q99j-cg4r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-36cc-q99j-cg4r", - "modified": "2024-06-19T09:31:17Z", + "modified": "2024-07-03T18:45:50Z", "published": "2024-06-19T09:31:17Z", "aliases": [ "CVE-2024-37124" ], "details": "Use of potentially dangerous function issue exists in Ricoh Streamline NX PC Client. If this vulnerability is exploited, an attacker may create an arbitrary file in the PC where the product is installed.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-19T07:15:46Z" diff --git a/advisories/unreviewed/2024/06/GHSA-39m6-6wm4-cm5w/GHSA-39m6-6wm4-cm5w.json b/advisories/unreviewed/2024/06/GHSA-39m6-6wm4-cm5w/GHSA-39m6-6wm4-cm5w.json index 5c982601349..f3d09a4b7ba 100644 --- a/advisories/unreviewed/2024/06/GHSA-39m6-6wm4-cm5w/GHSA-39m6-6wm4-cm5w.json +++ b/advisories/unreviewed/2024/06/GHSA-39m6-6wm4-cm5w/GHSA-39m6-6wm4-cm5w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-39m6-6wm4-cm5w", - "modified": "2024-06-12T06:30:41Z", + "modified": "2024-07-03T18:44:33Z", "published": "2024-06-10T21:30:40Z", "aliases": [ "CVE-2024-27840" ], "details": "The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.6.7, macOS Monterey 12.7.5, iOS 16.7.8 and iPadOS 16.7.8, tvOS 17.5, visionOS 1.2, iOS 17.5 and iPadOS 17.5, watchOS 10.5. An attacker that has already achieved kernel code execution may be able to bypass kernel memory protections.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N" + } ], "affected": [ @@ -81,9 +84,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-786" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-10T21:15:51Z" diff --git a/advisories/unreviewed/2024/06/GHSA-39wq-w29m-4ccv/GHSA-39wq-w29m-4ccv.json b/advisories/unreviewed/2024/06/GHSA-39wq-w29m-4ccv/GHSA-39wq-w29m-4ccv.json index 888cb26488b..e34cc17a089 100644 --- a/advisories/unreviewed/2024/06/GHSA-39wq-w29m-4ccv/GHSA-39wq-w29m-4ccv.json +++ b/advisories/unreviewed/2024/06/GHSA-39wq-w29m-4ccv/GHSA-39wq-w29m-4ccv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-39wq-w29m-4ccv", - "modified": "2024-06-20T15:31:18Z", + "modified": "2024-07-03T18:46:12Z", "published": "2024-06-20T15:31:18Z", "aliases": [ "CVE-2023-49111" ], "details": "For Kiuwan installations with SSO (single sign-on) enabled, an \nunauthenticated reflected cross-site scripting attack can be performed \non the login page \"login.html\". This is possible due to the request parameter \"message\" values\n being directly included in a JavaScript block in the response. This is \nespecially critical in business environments using AD SSO \nauthentication, e.g. via ADFS, where attackers could potentially steal \nAD passwords.\n\n\n\nThis issue affects Kiuwan SAST: module remains as NULL. This would result in the missing module\nreference up/down at the device open/close, leading to a race with the\ncode execution after the module removal.\n\nFor addressing the bug, move the assignment of card->module again out\nof ifdef. The WARN_ON() is still wrapped with ifdef because the\nmodule can be really NULL when all sound drivers are built-in.\n\nNote that we keep 'ifdef MODULE' for WARN_ON(), otherwise it would\nlead to a false-positive NULL module check. Admittedly it won't catch\nperfectly, i.e. no check is performed when CONFIG_SND=y. But, it's no\nreal problem as it's only for debugging, and the condition is pretty\nrare.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -49,9 +52,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-19T14:15:20Z" diff --git a/advisories/unreviewed/2024/06/GHSA-c5vq-9hf6-g7cw/GHSA-c5vq-9hf6-g7cw.json b/advisories/unreviewed/2024/06/GHSA-c5vq-9hf6-g7cw/GHSA-c5vq-9hf6-g7cw.json index 04d93e81bd3..01a127d673b 100644 --- a/advisories/unreviewed/2024/06/GHSA-c5vq-9hf6-g7cw/GHSA-c5vq-9hf6-g7cw.json +++ b/advisories/unreviewed/2024/06/GHSA-c5vq-9hf6-g7cw/GHSA-c5vq-9hf6-g7cw.json @@ -68,7 +68,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-703" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-cvp2-j7mv-gx79/GHSA-cvp2-j7mv-gx79.json b/advisories/unreviewed/2024/06/GHSA-cvp2-j7mv-gx79/GHSA-cvp2-j7mv-gx79.json index c1af5f9831e..1c1e662f816 100644 --- a/advisories/unreviewed/2024/06/GHSA-cvp2-j7mv-gx79/GHSA-cvp2-j7mv-gx79.json +++ b/advisories/unreviewed/2024/06/GHSA-cvp2-j7mv-gx79/GHSA-cvp2-j7mv-gx79.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cvp2-j7mv-gx79", - "modified": "2024-06-11T09:30:59Z", + "modified": "2024-07-03T18:44:35Z", "published": "2024-06-10T21:30:40Z", "aliases": [ "CVE-2024-27845" ], "details": "A privacy issue was addressed with improved handling of temporary files. This issue is fixed in iOS 17.5 and iPadOS 17.5. An app may be able to access Notes attachments.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-10T21:15:51Z" diff --git a/advisories/unreviewed/2024/06/GHSA-cvwq-q64c-wrq2/GHSA-cvwq-q64c-wrq2.json b/advisories/unreviewed/2024/06/GHSA-cvwq-q64c-wrq2/GHSA-cvwq-q64c-wrq2.json index 50d3adc63ef..6230db6b15f 100644 --- a/advisories/unreviewed/2024/06/GHSA-cvwq-q64c-wrq2/GHSA-cvwq-q64c-wrq2.json +++ b/advisories/unreviewed/2024/06/GHSA-cvwq-q64c-wrq2/GHSA-cvwq-q64c-wrq2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cvwq-q64c-wrq2", - "modified": "2024-06-19T06:30:35Z", + "modified": "2024-07-03T18:45:50Z", "published": "2024-06-19T06:30:35Z", "aliases": [ "CVE-2024-35298" ], "details": "Improper authorization in handler for custom URL scheme issue in 'ZOZOTOWN' App for Android versions prior to 7.39.6 allows an attacker to lead a user to access an arbitrary website via another application installed on the user's device. As a result, the user may become a victim of a phishing attack.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-939" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-19T05:15:51Z" diff --git a/advisories/unreviewed/2024/06/GHSA-cw2f-ggf4-p3jf/GHSA-cw2f-ggf4-p3jf.json b/advisories/unreviewed/2024/06/GHSA-cw2f-ggf4-p3jf/GHSA-cw2f-ggf4-p3jf.json index 9ace5a0e01c..6b3f8bbfdb4 100644 --- a/advisories/unreviewed/2024/06/GHSA-cw2f-ggf4-p3jf/GHSA-cw2f-ggf4-p3jf.json +++ b/advisories/unreviewed/2024/06/GHSA-cw2f-ggf4-p3jf/GHSA-cw2f-ggf4-p3jf.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-346" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-cwx8-r7cr-cfgf/GHSA-cwx8-r7cr-cfgf.json b/advisories/unreviewed/2024/06/GHSA-cwx8-r7cr-cfgf/GHSA-cwx8-r7cr-cfgf.json index b7cafe48890..d032239d859 100644 --- a/advisories/unreviewed/2024/06/GHSA-cwx8-r7cr-cfgf/GHSA-cwx8-r7cr-cfgf.json +++ b/advisories/unreviewed/2024/06/GHSA-cwx8-r7cr-cfgf/GHSA-cwx8-r7cr-cfgf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cwx8-r7cr-cfgf", - "modified": "2024-06-13T21:30:54Z", + "modified": "2024-07-03T18:45:07Z", "published": "2024-06-13T21:30:54Z", "aliases": [ "CVE-2024-29787" ], "details": "In lwis_process_transactions_in_queue of lwis_transaction.c, there is a possible use after free due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-13T21:15:52Z" diff --git a/advisories/unreviewed/2024/06/GHSA-f62c-6722-rv46/GHSA-f62c-6722-rv46.json b/advisories/unreviewed/2024/06/GHSA-f62c-6722-rv46/GHSA-f62c-6722-rv46.json index 75953dd26bf..55caf69c6a7 100644 --- a/advisories/unreviewed/2024/06/GHSA-f62c-6722-rv46/GHSA-f62c-6722-rv46.json +++ b/advisories/unreviewed/2024/06/GHSA-f62c-6722-rv46/GHSA-f62c-6722-rv46.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f62c-6722-rv46", - "modified": "2024-06-17T09:31:02Z", + "modified": "2024-07-03T18:45:35Z", "published": "2024-06-17T09:31:02Z", "aliases": [ "CVE-2024-36279" ], "details": "Reliance on obfuscation or encryption of security-relevant inputs without integrity checking issue exists in \"FreeFrom - the nostr client\" App versions prior to 1.3.5 for Android and iOS. If this vulnerability is exploited, the content of direct messages (DMs) between users may be manipulated by a man-in-the-middle attack.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-649" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-17T08:15:48Z" diff --git a/advisories/unreviewed/2024/06/GHSA-f6vh-wx77-fcc5/GHSA-f6vh-wx77-fcc5.json b/advisories/unreviewed/2024/06/GHSA-f6vh-wx77-fcc5/GHSA-f6vh-wx77-fcc5.json index 69cf2cc80f5..04237e1e788 100644 --- a/advisories/unreviewed/2024/06/GHSA-f6vh-wx77-fcc5/GHSA-f6vh-wx77-fcc5.json +++ b/advisories/unreviewed/2024/06/GHSA-f6vh-wx77-fcc5/GHSA-f6vh-wx77-fcc5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f6vh-wx77-fcc5", - "modified": "2024-06-13T21:30:55Z", + "modified": "2024-07-03T18:45:15Z", "published": "2024-06-13T21:30:55Z", "aliases": [ "CVE-2024-32930" ], "details": "In plugin_ipc_handler of slc_plugin.c, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure of 4 bytes of stack memory with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-13T21:15:56Z" diff --git a/advisories/unreviewed/2024/06/GHSA-f935-6jhc-wv29/GHSA-f935-6jhc-wv29.json b/advisories/unreviewed/2024/06/GHSA-f935-6jhc-wv29/GHSA-f935-6jhc-wv29.json index 790b865de13..5cc6365417d 100644 --- a/advisories/unreviewed/2024/06/GHSA-f935-6jhc-wv29/GHSA-f935-6jhc-wv29.json +++ b/advisories/unreviewed/2024/06/GHSA-f935-6jhc-wv29/GHSA-f935-6jhc-wv29.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f935-6jhc-wv29", - "modified": "2024-06-05T21:31:28Z", + "modified": "2024-07-03T18:44:13Z", "published": "2024-06-05T21:31:28Z", "aliases": [ "CVE-2024-36670" ], "details": "idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/vpsClass_deal.php?mudi=del", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-05T19:15:15Z" diff --git a/advisories/unreviewed/2024/06/GHSA-fcqv-w7xc-5vmc/GHSA-fcqv-w7xc-5vmc.json b/advisories/unreviewed/2024/06/GHSA-fcqv-w7xc-5vmc/GHSA-fcqv-w7xc-5vmc.json index b5e827a8f7a..ca604645f39 100644 --- a/advisories/unreviewed/2024/06/GHSA-fcqv-w7xc-5vmc/GHSA-fcqv-w7xc-5vmc.json +++ b/advisories/unreviewed/2024/06/GHSA-fcqv-w7xc-5vmc/GHSA-fcqv-w7xc-5vmc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fcqv-w7xc-5vmc", - "modified": "2024-06-20T18:34:09Z", + "modified": "2024-07-03T18:46:15Z", "published": "2024-06-20T18:34:09Z", "aliases": [ "CVE-2024-37674" ], "details": "Cross Site Scripting vulnerability in Moodle CMS v3.10 allows a remote attacker to execute arbitrary code via the Field Name (name parameter) of a new activity.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-20T18:15:12Z" diff --git a/advisories/unreviewed/2024/06/GHSA-fcw5-xg8j-vw6m/GHSA-fcw5-xg8j-vw6m.json b/advisories/unreviewed/2024/06/GHSA-fcw5-xg8j-vw6m/GHSA-fcw5-xg8j-vw6m.json index f102b4c20e7..a5412eb6d0c 100644 --- a/advisories/unreviewed/2024/06/GHSA-fcw5-xg8j-vw6m/GHSA-fcw5-xg8j-vw6m.json +++ b/advisories/unreviewed/2024/06/GHSA-fcw5-xg8j-vw6m/GHSA-fcw5-xg8j-vw6m.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-fg32-7hw7-w82p/GHSA-fg32-7hw7-w82p.json b/advisories/unreviewed/2024/06/GHSA-fg32-7hw7-w82p/GHSA-fg32-7hw7-w82p.json index 4a1a0a2f0c8..b3ab2254457 100644 --- a/advisories/unreviewed/2024/06/GHSA-fg32-7hw7-w82p/GHSA-fg32-7hw7-w82p.json +++ b/advisories/unreviewed/2024/06/GHSA-fg32-7hw7-w82p/GHSA-fg32-7hw7-w82p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fg32-7hw7-w82p", - "modified": "2024-06-07T21:31:55Z", + "modified": "2024-07-03T18:44:18Z", "published": "2024-06-07T21:31:55Z", "aliases": [ "CVE-2023-49224" ], "details": "Precor touchscreen console P62, P80, and P82 contains a default SSH public key in the authorized_keys file. A remote attacker could use this key to gain root privileges.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-400" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-07T20:15:10Z" diff --git a/advisories/unreviewed/2024/06/GHSA-frw3-949h-qqfj/GHSA-frw3-949h-qqfj.json b/advisories/unreviewed/2024/06/GHSA-frw3-949h-qqfj/GHSA-frw3-949h-qqfj.json index 6fe9c8aaa78..ff9553a45cf 100644 --- a/advisories/unreviewed/2024/06/GHSA-frw3-949h-qqfj/GHSA-frw3-949h-qqfj.json +++ b/advisories/unreviewed/2024/06/GHSA-frw3-949h-qqfj/GHSA-frw3-949h-qqfj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-frw3-949h-qqfj", - "modified": "2024-06-17T18:31:35Z", + "modified": "2024-07-03T18:45:42Z", "published": "2024-06-17T18:31:35Z", "aliases": [ "CVE-2024-37794" ], "details": "Improper input validation in CVC5 Solver v1.1.3 allows attackers to cause a Denial of Service (DoS) via a crafted SMT2 input file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-20" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-17T18:15:17Z" diff --git a/advisories/unreviewed/2024/06/GHSA-fvqw-wg8v-hmcw/GHSA-fvqw-wg8v-hmcw.json b/advisories/unreviewed/2024/06/GHSA-fvqw-wg8v-hmcw/GHSA-fvqw-wg8v-hmcw.json index 1b0a6737cf7..bd21209aea4 100644 --- a/advisories/unreviewed/2024/06/GHSA-fvqw-wg8v-hmcw/GHSA-fvqw-wg8v-hmcw.json +++ b/advisories/unreviewed/2024/06/GHSA-fvqw-wg8v-hmcw/GHSA-fvqw-wg8v-hmcw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fvqw-wg8v-hmcw", - "modified": "2024-06-11T09:30:59Z", + "modified": "2024-07-03T18:44:35Z", "published": "2024-06-10T21:30:40Z", "aliases": [ "CVE-2024-27848" ], "details": "This issue was addressed with improved permissions checking. This issue is fixed in macOS Sonoma 14.5, iOS 17.5 and iPadOS 17.5. A malicious app may be able to gain root privileges.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,10 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-277", + "CWE-863" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-10T21:15:51Z" diff --git a/advisories/unreviewed/2024/06/GHSA-fxvf-jcp9-ch47/GHSA-fxvf-jcp9-ch47.json b/advisories/unreviewed/2024/06/GHSA-fxvf-jcp9-ch47/GHSA-fxvf-jcp9-ch47.json index b499624034b..bb0de28f276 100644 --- a/advisories/unreviewed/2024/06/GHSA-fxvf-jcp9-ch47/GHSA-fxvf-jcp9-ch47.json +++ b/advisories/unreviewed/2024/06/GHSA-fxvf-jcp9-ch47/GHSA-fxvf-jcp9-ch47.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fxvf-jcp9-ch47", - "modified": "2024-06-17T18:31:34Z", + "modified": "2024-07-03T18:45:42Z", "published": "2024-06-17T18:31:34Z", "aliases": [ "CVE-2024-37661" ], "details": "TP-LINK TL-7DR5130 v1.0.23 is vulnerable to forged ICMP redirect message attacks. An attacker in the same WLAN as the victim can hijack the traffic between the victim and any remote server by sending out forged ICMP redirect messages.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-940" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-17T18:15:17Z" diff --git a/advisories/unreviewed/2024/06/GHSA-g23m-h4v3-g2qq/GHSA-g23m-h4v3-g2qq.json b/advisories/unreviewed/2024/06/GHSA-g23m-h4v3-g2qq/GHSA-g23m-h4v3-g2qq.json index 58a4b4770d5..58593ec7ea4 100644 --- a/advisories/unreviewed/2024/06/GHSA-g23m-h4v3-g2qq/GHSA-g23m-h4v3-g2qq.json +++ b/advisories/unreviewed/2024/06/GHSA-g23m-h4v3-g2qq/GHSA-g23m-h4v3-g2qq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g23m-h4v3-g2qq", - "modified": "2024-06-19T12:31:21Z", + "modified": "2024-07-03T18:44:46Z", "published": "2024-06-11T15:31:13Z", "aliases": [ "CVE-2024-5688" ], "details": "If a garbage collection was triggered at the right time, a use-after-free could have occurred during object transplant. This vulnerability affects Firefox < 127 and Firefox ESR < 115.12.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-11T13:15:50Z" diff --git a/advisories/unreviewed/2024/06/GHSA-g3vc-vgcj-26vj/GHSA-g3vc-vgcj-26vj.json b/advisories/unreviewed/2024/06/GHSA-g3vc-vgcj-26vj/GHSA-g3vc-vgcj-26vj.json index 2b2ae032b0f..43d49cda1bb 100644 --- a/advisories/unreviewed/2024/06/GHSA-g3vc-vgcj-26vj/GHSA-g3vc-vgcj-26vj.json +++ b/advisories/unreviewed/2024/06/GHSA-g3vc-vgcj-26vj/GHSA-g3vc-vgcj-26vj.json @@ -56,7 +56,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-287" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-g7xm-f45g-5wvg/GHSA-g7xm-f45g-5wvg.json b/advisories/unreviewed/2024/06/GHSA-g7xm-f45g-5wvg/GHSA-g7xm-f45g-5wvg.json index ad498694452..6d71461dc05 100644 --- a/advisories/unreviewed/2024/06/GHSA-g7xm-f45g-5wvg/GHSA-g7xm-f45g-5wvg.json +++ b/advisories/unreviewed/2024/06/GHSA-g7xm-f45g-5wvg/GHSA-g7xm-f45g-5wvg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g7xm-f45g-5wvg", - "modified": "2024-06-11T00:30:40Z", + "modified": "2024-07-03T18:44:41Z", "published": "2024-06-11T00:30:40Z", "aliases": [ "CVE-2022-37019" ], "details": "Potential vulnerabilities have been identified in the system BIOS for certain HP PC products which may allow escalation of privileges and code execution. HP is releasing firmware updates to mitigate the potential vulnerabilities.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-10T23:15:49Z" diff --git a/advisories/unreviewed/2024/06/GHSA-gc36-qqwf-f29m/GHSA-gc36-qqwf-f29m.json b/advisories/unreviewed/2024/06/GHSA-gc36-qqwf-f29m/GHSA-gc36-qqwf-f29m.json index e5296f0d4f8..57119c1f49a 100644 --- a/advisories/unreviewed/2024/06/GHSA-gc36-qqwf-f29m/GHSA-gc36-qqwf-f29m.json +++ b/advisories/unreviewed/2024/06/GHSA-gc36-qqwf-f29m/GHSA-gc36-qqwf-f29m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gc36-qqwf-f29m", - "modified": "2024-06-14T15:31:25Z", + "modified": "2024-07-03T18:45:23Z", "published": "2024-06-14T15:31:25Z", "aliases": [ "CVE-2024-37644" ], "details": "TRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain a hardcoded password vulnerability in /etc/shadow.sample, which allows attackers to log in as root.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-259" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-14T15:15:52Z" diff --git a/advisories/unreviewed/2024/06/GHSA-gc8r-pxj9-hhx3/GHSA-gc8r-pxj9-hhx3.json b/advisories/unreviewed/2024/06/GHSA-gc8r-pxj9-hhx3/GHSA-gc8r-pxj9-hhx3.json index 1640e72e5c2..72ee513bf37 100644 --- a/advisories/unreviewed/2024/06/GHSA-gc8r-pxj9-hhx3/GHSA-gc8r-pxj9-hhx3.json +++ b/advisories/unreviewed/2024/06/GHSA-gc8r-pxj9-hhx3/GHSA-gc8r-pxj9-hhx3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gc8r-pxj9-hhx3", - "modified": "2024-07-03T00:34:10Z", + "modified": "2024-07-03T18:44:12Z", "published": "2024-06-05T18:30:37Z", "aliases": [ "CVE-2024-5037" @@ -29,6 +29,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:4151" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:4156" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-5037" diff --git a/advisories/unreviewed/2024/06/GHSA-gc92-5p58-4rf7/GHSA-gc92-5p58-4rf7.json b/advisories/unreviewed/2024/06/GHSA-gc92-5p58-4rf7/GHSA-gc92-5p58-4rf7.json index 1aabbf1f383..8097d35f823 100644 --- a/advisories/unreviewed/2024/06/GHSA-gc92-5p58-4rf7/GHSA-gc92-5p58-4rf7.json +++ b/advisories/unreviewed/2024/06/GHSA-gc92-5p58-4rf7/GHSA-gc92-5p58-4rf7.json @@ -84,7 +84,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-353" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-ggmq-9v8m-wpjv/GHSA-ggmq-9v8m-wpjv.json b/advisories/unreviewed/2024/06/GHSA-ggmq-9v8m-wpjv/GHSA-ggmq-9v8m-wpjv.json index ff6a7ea2165..af5b78f175f 100644 --- a/advisories/unreviewed/2024/06/GHSA-ggmq-9v8m-wpjv/GHSA-ggmq-9v8m-wpjv.json +++ b/advisories/unreviewed/2024/06/GHSA-ggmq-9v8m-wpjv/GHSA-ggmq-9v8m-wpjv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-ggmq-9v8m-wpjv", - "modified": "2024-06-19T21:32:30Z", + "modified": "2024-07-03T18:46:02Z", "published": "2024-06-19T21:32:30Z", "aliases": [ "CVE-2024-34994" ], "details": "In the module \"Channable\" (channable) up to version 3.2.1 from Channable for PrestaShop, a guest can perform SQL injection via `ChannableFeedModuleFrontController::postProcess()`.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-19T21:15:57Z" diff --git a/advisories/unreviewed/2024/06/GHSA-gj92-fpwq-8c5r/GHSA-gj92-fpwq-8c5r.json b/advisories/unreviewed/2024/06/GHSA-gj92-fpwq-8c5r/GHSA-gj92-fpwq-8c5r.json index d5df4097b46..8b5409c3a64 100644 --- a/advisories/unreviewed/2024/06/GHSA-gj92-fpwq-8c5r/GHSA-gj92-fpwq-8c5r.json +++ b/advisories/unreviewed/2024/06/GHSA-gj92-fpwq-8c5r/GHSA-gj92-fpwq-8c5r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gj92-fpwq-8c5r", - "modified": "2024-06-17T15:30:53Z", + "modified": "2024-07-03T18:45:36Z", "published": "2024-06-17T15:30:53Z", "aliases": [ "CVE-2024-37622" ], "details": "Xinhu RockOA v2.6.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the num parameter at /flow/flow.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-17T14:15:11Z" diff --git a/advisories/unreviewed/2024/06/GHSA-gm2v-mf3r-56jr/GHSA-gm2v-mf3r-56jr.json b/advisories/unreviewed/2024/06/GHSA-gm2v-mf3r-56jr/GHSA-gm2v-mf3r-56jr.json index fce82a6c613..8ca44cf109b 100644 --- a/advisories/unreviewed/2024/06/GHSA-gm2v-mf3r-56jr/GHSA-gm2v-mf3r-56jr.json +++ b/advisories/unreviewed/2024/06/GHSA-gm2v-mf3r-56jr/GHSA-gm2v-mf3r-56jr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gm2v-mf3r-56jr", - "modified": "2024-06-17T15:30:51Z", + "modified": "2024-07-03T18:45:36Z", "published": "2024-06-17T15:30:51Z", "aliases": [ "CVE-2024-36583" ], "details": "A Prototype Pollution issue in byondreal accessor <= 1.0.0 allows an attacker to execute arbitrary code via @byondreal/accessor/index.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-1321" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-17T14:15:10Z" diff --git a/advisories/unreviewed/2024/06/GHSA-gp2x-43x3-838x/GHSA-gp2x-43x3-838x.json b/advisories/unreviewed/2024/06/GHSA-gp2x-43x3-838x/GHSA-gp2x-43x3-838x.json index cb98eff296e..0dcccd9e494 100644 --- a/advisories/unreviewed/2024/06/GHSA-gp2x-43x3-838x/GHSA-gp2x-43x3-838x.json +++ b/advisories/unreviewed/2024/06/GHSA-gp2x-43x3-838x/GHSA-gp2x-43x3-838x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gp2x-43x3-838x", - "modified": "2024-06-17T03:31:07Z", + "modified": "2024-07-03T18:45:33Z", "published": "2024-06-17T03:31:07Z", "aliases": [ "CVE-2024-5163" ], "details": "Improper permission settings for mobile applications (com.transsion.carlcare) may lead to user password and account security risks.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-280" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-17T03:15:09Z" diff --git a/advisories/unreviewed/2024/06/GHSA-gq4w-r5jj-3rgg/GHSA-gq4w-r5jj-3rgg.json b/advisories/unreviewed/2024/06/GHSA-gq4w-r5jj-3rgg/GHSA-gq4w-r5jj-3rgg.json index 6306c8bee9d..d9d55b59a2b 100644 --- a/advisories/unreviewed/2024/06/GHSA-gq4w-r5jj-3rgg/GHSA-gq4w-r5jj-3rgg.json +++ b/advisories/unreviewed/2024/06/GHSA-gq4w-r5jj-3rgg/GHSA-gq4w-r5jj-3rgg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gq4w-r5jj-3rgg", - "modified": "2024-06-18T06:30:44Z", + "modified": "2024-07-03T18:45:44Z", "published": "2024-06-18T06:30:44Z", "aliases": [ "CVE-2024-5172" ], "details": "The Expert Invoice WordPress plugin through 1.0.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-18T06:15:12Z" diff --git a/advisories/unreviewed/2024/06/GHSA-h4fx-g364-89c4/GHSA-h4fx-g364-89c4.json b/advisories/unreviewed/2024/06/GHSA-h4fx-g364-89c4/GHSA-h4fx-g364-89c4.json index c21ed7c6f63..76a022265ae 100644 --- a/advisories/unreviewed/2024/06/GHSA-h4fx-g364-89c4/GHSA-h4fx-g364-89c4.json +++ b/advisories/unreviewed/2024/06/GHSA-h4fx-g364-89c4/GHSA-h4fx-g364-89c4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h4fx-g364-89c4", - "modified": "2024-06-20T18:34:08Z", + "modified": "2024-07-03T18:46:13Z", "published": "2024-06-20T18:34:08Z", "aliases": [ "CVE-2022-45929" ], "details": "Northern.tech Mender 3.3.x before 3.3.2, 3.5.x before 3.5.0, and 3.6.x before 3.6.0 has Incorrect Access Control and allows users to change their roles and could allow privilege escalation from a low-privileged read-only user to a high-privileged user.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-20T17:15:50Z" diff --git a/advisories/unreviewed/2024/06/GHSA-h7v5-c8v4-f6pp/GHSA-h7v5-c8v4-f6pp.json b/advisories/unreviewed/2024/06/GHSA-h7v5-c8v4-f6pp/GHSA-h7v5-c8v4-f6pp.json index 6ab28466c56..4bade2a8ba6 100644 --- a/advisories/unreviewed/2024/06/GHSA-h7v5-c8v4-f6pp/GHSA-h7v5-c8v4-f6pp.json +++ b/advisories/unreviewed/2024/06/GHSA-h7v5-c8v4-f6pp/GHSA-h7v5-c8v4-f6pp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h7v5-c8v4-f6pp", - "modified": "2024-06-10T18:31:06Z", + "modified": "2024-07-03T18:44:22Z", "published": "2024-06-10T18:31:06Z", "aliases": [ "CVE-2024-34332" ], "details": "An issue in SiSoftware SANDRA v31.66 (SANDRA.sys 15.18.1.1) and before allows an attacker to escalate privileges via a crafted buffer sent to the Kernel Driver using the DeviceIoControl Windows API.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-10T16:15:13Z" diff --git a/advisories/unreviewed/2024/06/GHSA-h98r-frj5-jj3c/GHSA-h98r-frj5-jj3c.json b/advisories/unreviewed/2024/06/GHSA-h98r-frj5-jj3c/GHSA-h98r-frj5-jj3c.json index 24c594efff0..ada5eec073e 100644 --- a/advisories/unreviewed/2024/06/GHSA-h98r-frj5-jj3c/GHSA-h98r-frj5-jj3c.json +++ b/advisories/unreviewed/2024/06/GHSA-h98r-frj5-jj3c/GHSA-h98r-frj5-jj3c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h98r-frj5-jj3c", - "modified": "2024-06-12T06:30:41Z", + "modified": "2024-07-03T18:44:34Z", "published": "2024-06-10T21:30:40Z", "aliases": [ "CVE-2024-27844" ], "details": "The issue was addressed with improved checks. This issue is fixed in visionOS 1.2, macOS Sonoma 14.5, Safari 17.5. A website's permission dialog may persist after navigation away from the site.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -51,7 +54,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-10T21:15:51Z" diff --git a/advisories/unreviewed/2024/06/GHSA-h9h2-6w4q-6c52/GHSA-h9h2-6w4q-6c52.json b/advisories/unreviewed/2024/06/GHSA-h9h2-6w4q-6c52/GHSA-h9h2-6w4q-6c52.json index 8c0b1dc7e69..b076cbb0b6a 100644 --- a/advisories/unreviewed/2024/06/GHSA-h9h2-6w4q-6c52/GHSA-h9h2-6w4q-6c52.json +++ b/advisories/unreviewed/2024/06/GHSA-h9h2-6w4q-6c52/GHSA-h9h2-6w4q-6c52.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h9h2-6w4q-6c52", - "modified": "2024-06-20T12:31:21Z", + "modified": "2024-07-03T18:46:09Z", "published": "2024-06-20T12:31:21Z", "aliases": [ "CVE-2022-48748" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: bridge: vlan: fix memory leak in __allowed_ingress\n\nWhen using per-vlan state, if vlan snooping and stats are disabled,\nuntagged or priority-tagged ingress frame will go to check pvid state.\nIf the port state is forwarding and the pvid state is not\nlearning/forwarding, untagged or priority-tagged frame will be dropped\nbut skb memory is not freed.\nShould free skb when __allowed_ingress returns false.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-400" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-20T12:15:13Z" diff --git a/advisories/unreviewed/2024/06/GHSA-hccj-9v6g-qxjv/GHSA-hccj-9v6g-qxjv.json b/advisories/unreviewed/2024/06/GHSA-hccj-9v6g-qxjv/GHSA-hccj-9v6g-qxjv.json index 8d2c971dd66..6957c8bf302 100644 --- a/advisories/unreviewed/2024/06/GHSA-hccj-9v6g-qxjv/GHSA-hccj-9v6g-qxjv.json +++ b/advisories/unreviewed/2024/06/GHSA-hccj-9v6g-qxjv/GHSA-hccj-9v6g-qxjv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hccj-9v6g-qxjv", - "modified": "2024-06-07T18:30:37Z", + "modified": "2024-07-03T18:44:19Z", "published": "2024-06-07T18:30:37Z", "aliases": [ "CVE-2024-30162" ], "details": "Invision Community through 4.7.16 allows remote code execution via the applications/core/modules/admin/editor/toolbar.php IPS\\core\\modules\\admin\\editor\\_toolbar::addPlugin() method. This method handles uploaded ZIP files that are extracted into the applications/core/interface/ckeditor/ckeditor/plugins/ directory without properly verifying their content. This can be exploited by admin users (with the toolbar_manage permission) to write arbitrary PHP files into that directory, leading to execution of arbitrary PHP code in the context of the web server user.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-345" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-07T17:15:50Z" diff --git a/advisories/unreviewed/2024/06/GHSA-hh8j-c7wj-qpfj/GHSA-hh8j-c7wj-qpfj.json b/advisories/unreviewed/2024/06/GHSA-hh8j-c7wj-qpfj/GHSA-hh8j-c7wj-qpfj.json index c28ae386968..e915030909d 100644 --- a/advisories/unreviewed/2024/06/GHSA-hh8j-c7wj-qpfj/GHSA-hh8j-c7wj-qpfj.json +++ b/advisories/unreviewed/2024/06/GHSA-hh8j-c7wj-qpfj/GHSA-hh8j-c7wj-qpfj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hh8j-c7wj-qpfj", - "modified": "2024-06-17T21:31:10Z", + "modified": "2024-07-03T18:45:43Z", "published": "2024-06-17T21:31:10Z", "aliases": [ "CVE-2023-37057" ], "details": "An issue in JLINK Unionman Technology Co. Ltd Jlink AX1800 v.1.0 allows a remote attacker to execute arbitrary code via the router's authentication mechanism.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-288" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-17T21:15:50Z" diff --git a/advisories/unreviewed/2024/06/GHSA-hmc2-hhww-hmr3/GHSA-hmc2-hhww-hmr3.json b/advisories/unreviewed/2024/06/GHSA-hmc2-hhww-hmr3/GHSA-hmc2-hhww-hmr3.json index ae785e53f17..9b5c89c8da2 100644 --- a/advisories/unreviewed/2024/06/GHSA-hmc2-hhww-hmr3/GHSA-hmc2-hhww-hmr3.json +++ b/advisories/unreviewed/2024/06/GHSA-hmc2-hhww-hmr3/GHSA-hmc2-hhww-hmr3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hmc2-hhww-hmr3", - "modified": "2024-06-07T00:30:36Z", + "modified": "2024-07-03T18:44:16Z", "published": "2024-06-07T00:30:36Z", "aliases": [ "CVE-2023-51847" ], "details": "An issue in obgm and Libcoap v.a3ed466 allows a remote attacker to cause a denial of service via thecoap_context_t function in the src/coap_threadsafe.c:297:3 component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-400" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-06T22:15:09Z" diff --git a/advisories/unreviewed/2024/06/GHSA-hv3w-wgcx-8ggg/GHSA-hv3w-wgcx-8ggg.json b/advisories/unreviewed/2024/06/GHSA-hv3w-wgcx-8ggg/GHSA-hv3w-wgcx-8ggg.json index 0827aae008c..6a0d449942a 100644 --- a/advisories/unreviewed/2024/06/GHSA-hv3w-wgcx-8ggg/GHSA-hv3w-wgcx-8ggg.json +++ b/advisories/unreviewed/2024/06/GHSA-hv3w-wgcx-8ggg/GHSA-hv3w-wgcx-8ggg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hv3w-wgcx-8ggg", - "modified": "2024-06-12T06:30:41Z", + "modified": "2024-07-03T18:44:30Z", "published": "2024-06-10T21:30:40Z", "aliases": [ "CVE-2024-27836" ], "details": "The issue was addressed with improved checks. This issue is fixed in visionOS 1.2, macOS Sonoma 14.5, iOS 17.5 and iPadOS 17.5. Processing a maliciously crafted image may lead to arbitrary code execution.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -49,9 +52,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-10T21:15:51Z" diff --git a/advisories/unreviewed/2024/06/GHSA-hvrf-34fw-qpr2/GHSA-hvrf-34fw-qpr2.json b/advisories/unreviewed/2024/06/GHSA-hvrf-34fw-qpr2/GHSA-hvrf-34fw-qpr2.json index d46e9923295..d44b6365215 100644 --- a/advisories/unreviewed/2024/06/GHSA-hvrf-34fw-qpr2/GHSA-hvrf-34fw-qpr2.json +++ b/advisories/unreviewed/2024/06/GHSA-hvrf-34fw-qpr2/GHSA-hvrf-34fw-qpr2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hvrf-34fw-qpr2", - "modified": "2024-06-17T18:31:35Z", + "modified": "2024-07-03T18:45:42Z", "published": "2024-06-17T18:31:35Z", "aliases": [ "CVE-2024-37795" ], "details": "A segmentation fault in CVC5 Solver v1.1.3 allows attackers to cause a Denial of Service (DoS) via a crafted SMT-LIB input file containing the `set-logic` command with specific formatting errors.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-17T18:15:17Z" diff --git a/advisories/unreviewed/2024/06/GHSA-j24x-6m7r-h4gp/GHSA-j24x-6m7r-h4gp.json b/advisories/unreviewed/2024/06/GHSA-j24x-6m7r-h4gp/GHSA-j24x-6m7r-h4gp.json index 7852a8fcc8f..2ff4f2fd94e 100644 --- a/advisories/unreviewed/2024/06/GHSA-j24x-6m7r-h4gp/GHSA-j24x-6m7r-h4gp.json +++ b/advisories/unreviewed/2024/06/GHSA-j24x-6m7r-h4gp/GHSA-j24x-6m7r-h4gp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j24x-6m7r-h4gp", - "modified": "2024-06-12T06:30:41Z", + "modified": "2024-07-03T18:44:32Z", "published": "2024-06-10T21:30:40Z", "aliases": [ "CVE-2024-27838" ], "details": "The issue was addressed by adding additional logic. This issue is fixed in tvOS 17.5, iOS 16.7.8 and iPadOS 16.7.8, visionOS 1.2, Safari 17.5, iOS 17.5 and iPadOS 17.5, watchOS 10.5, macOS Sonoma 14.5. A maliciously crafted webpage may be able to fingerprint the user.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -55,7 +58,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-10T21:15:51Z" diff --git a/advisories/unreviewed/2024/06/GHSA-j4rp-pq8q-wm7r/GHSA-j4rp-pq8q-wm7r.json b/advisories/unreviewed/2024/06/GHSA-j4rp-pq8q-wm7r/GHSA-j4rp-pq8q-wm7r.json index da47b454a0d..7fb19c8dff4 100644 --- a/advisories/unreviewed/2024/06/GHSA-j4rp-pq8q-wm7r/GHSA-j4rp-pq8q-wm7r.json +++ b/advisories/unreviewed/2024/06/GHSA-j4rp-pq8q-wm7r/GHSA-j4rp-pq8q-wm7r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j4rp-pq8q-wm7r", - "modified": "2024-06-16T15:30:44Z", + "modified": "2024-07-03T18:45:32Z", "published": "2024-06-16T15:30:44Z", "aliases": [ "CVE-2024-38448" ], "details": "htags in GNU Global through 6.6.12 allows code execution in situations where dbpath (aka -d) is untrusted, because shell metacharacters may be used.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-16T14:15:09Z" diff --git a/advisories/unreviewed/2024/06/GHSA-j4rv-c6x5-m7c5/GHSA-j4rv-c6x5-m7c5.json b/advisories/unreviewed/2024/06/GHSA-j4rv-c6x5-m7c5/GHSA-j4rv-c6x5-m7c5.json index 37ee9cd241d..65796bc811c 100644 --- a/advisories/unreviewed/2024/06/GHSA-j4rv-c6x5-m7c5/GHSA-j4rv-c6x5-m7c5.json +++ b/advisories/unreviewed/2024/06/GHSA-j4rv-c6x5-m7c5/GHSA-j4rv-c6x5-m7c5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j4rv-c6x5-m7c5", - "modified": "2024-06-13T21:30:55Z", + "modified": "2024-07-03T18:45:13Z", "published": "2024-06-13T21:30:55Z", "aliases": [ "CVE-2024-32929" ], "details": "In gpu_slc_get_region of pixel_gpu_slc.c, there is a possible EoP due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-13T21:15:56Z" diff --git a/advisories/unreviewed/2024/06/GHSA-j67r-3cm4-272w/GHSA-j67r-3cm4-272w.json b/advisories/unreviewed/2024/06/GHSA-j67r-3cm4-272w/GHSA-j67r-3cm4-272w.json index edd6d9a08cd..762f2874c9e 100644 --- a/advisories/unreviewed/2024/06/GHSA-j67r-3cm4-272w/GHSA-j67r-3cm4-272w.json +++ b/advisories/unreviewed/2024/06/GHSA-j67r-3cm4-272w/GHSA-j67r-3cm4-272w.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-290", "CWE-357" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/06/GHSA-j764-4v6h-pqp7/GHSA-j764-4v6h-pqp7.json b/advisories/unreviewed/2024/06/GHSA-j764-4v6h-pqp7/GHSA-j764-4v6h-pqp7.json index 4a57eb84d76..ba62c135339 100644 --- a/advisories/unreviewed/2024/06/GHSA-j764-4v6h-pqp7/GHSA-j764-4v6h-pqp7.json +++ b/advisories/unreviewed/2024/06/GHSA-j764-4v6h-pqp7/GHSA-j764-4v6h-pqp7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j764-4v6h-pqp7", - "modified": "2024-06-30T12:31:10Z", + "modified": "2024-07-03T18:45:30Z", "published": "2024-06-16T15:30:44Z", "aliases": [ "CVE-2024-38441" ], "details": "Netatalk 3.2.0 has an off-by-one error and resultant heap-based buffer overflow because of setting ibuf[len] to '\\0' in FPMapName in afp_mapname in etc/afp/directory.c.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-16T13:15:53Z" diff --git a/advisories/unreviewed/2024/06/GHSA-j776-p2rm-mmrr/GHSA-j776-p2rm-mmrr.json b/advisories/unreviewed/2024/06/GHSA-j776-p2rm-mmrr/GHSA-j776-p2rm-mmrr.json index ee87221927d..a05e0c79f03 100644 --- a/advisories/unreviewed/2024/06/GHSA-j776-p2rm-mmrr/GHSA-j776-p2rm-mmrr.json +++ b/advisories/unreviewed/2024/06/GHSA-j776-p2rm-mmrr/GHSA-j776-p2rm-mmrr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j776-p2rm-mmrr", - "modified": "2024-06-11T09:30:59Z", + "modified": "2024-07-03T18:44:36Z", "published": "2024-06-10T21:30:40Z", "aliases": [ "CVE-2024-27885" ], "details": "This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sonoma 14.5, macOS Ventura 13.6.7, macOS Monterey 12.7.5. An app may be able to modify protected parts of the file system.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-59" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-10T21:15:51Z" diff --git a/advisories/unreviewed/2024/06/GHSA-j78x-grcm-g49w/GHSA-j78x-grcm-g49w.json b/advisories/unreviewed/2024/06/GHSA-j78x-grcm-g49w/GHSA-j78x-grcm-g49w.json index 3a1d7a67374..5ce884909cc 100644 --- a/advisories/unreviewed/2024/06/GHSA-j78x-grcm-g49w/GHSA-j78x-grcm-g49w.json +++ b/advisories/unreviewed/2024/06/GHSA-j78x-grcm-g49w/GHSA-j78x-grcm-g49w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j78x-grcm-g49w", - "modified": "2024-06-14T15:31:24Z", + "modified": "2024-07-03T18:45:22Z", "published": "2024-06-14T15:31:24Z", "aliases": [ "CVE-2024-37639" ], "details": "TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via eport in the function setIpPortFilterRules.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-14T14:15:10Z" diff --git a/advisories/unreviewed/2024/06/GHSA-j85x-732x-xq8q/GHSA-j85x-732x-xq8q.json b/advisories/unreviewed/2024/06/GHSA-j85x-732x-xq8q/GHSA-j85x-732x-xq8q.json index 6726d903ab8..e2acf8b873b 100644 --- a/advisories/unreviewed/2024/06/GHSA-j85x-732x-xq8q/GHSA-j85x-732x-xq8q.json +++ b/advisories/unreviewed/2024/06/GHSA-j85x-732x-xq8q/GHSA-j85x-732x-xq8q.json @@ -1,14 +1,21 @@ { "schema_version": "1.4.0", "id": "GHSA-j85x-732x-xq8q", - "modified": "2024-06-06T21:30:38Z", + "modified": "2024-07-03T18:44:14Z", "published": "2024-06-06T21:30:38Z", "aliases": [ "CVE-2024-32752" ], "details": "Under certain circumstances communications between the ICU tool and an iSTAR Pro door controller is susceptible to Machine-in-the-Middle attacks which could impact door control and configuration.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } ], "affected": [ @@ -31,7 +38,7 @@ "cwe_ids": [ "CWE-306" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-06T21:15:48Z" diff --git a/advisories/unreviewed/2024/06/GHSA-jcpq-9r39-jhwp/GHSA-jcpq-9r39-jhwp.json b/advisories/unreviewed/2024/06/GHSA-jcpq-9r39-jhwp/GHSA-jcpq-9r39-jhwp.json index 6ed436aa011..a99f5956486 100644 --- a/advisories/unreviewed/2024/06/GHSA-jcpq-9r39-jhwp/GHSA-jcpq-9r39-jhwp.json +++ b/advisories/unreviewed/2024/06/GHSA-jcpq-9r39-jhwp/GHSA-jcpq-9r39-jhwp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jcpq-9r39-jhwp", - "modified": "2024-06-14T18:31:43Z", + "modified": "2024-07-03T18:45:25Z", "published": "2024-06-14T18:31:43Z", "aliases": [ "CVE-2024-37643" ], "details": "TRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain a stack overflow vulnerability via the submit-url parameter at /formPasswordAuth .", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-14T16:15:12Z" diff --git a/advisories/unreviewed/2024/06/GHSA-jp38-8m55-7qcq/GHSA-jp38-8m55-7qcq.json b/advisories/unreviewed/2024/06/GHSA-jp38-8m55-7qcq/GHSA-jp38-8m55-7qcq.json index 457ac26877a..d4262c00dcf 100644 --- a/advisories/unreviewed/2024/06/GHSA-jp38-8m55-7qcq/GHSA-jp38-8m55-7qcq.json +++ b/advisories/unreviewed/2024/06/GHSA-jp38-8m55-7qcq/GHSA-jp38-8m55-7qcq.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-787" + "CWE-787", + "CWE-94" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-jpjh-5cvh-hrp7/GHSA-jpjh-5cvh-hrp7.json b/advisories/unreviewed/2024/06/GHSA-jpjh-5cvh-hrp7/GHSA-jpjh-5cvh-hrp7.json index b3a26541bde..64d0d8cac5e 100644 --- a/advisories/unreviewed/2024/06/GHSA-jpjh-5cvh-hrp7/GHSA-jpjh-5cvh-hrp7.json +++ b/advisories/unreviewed/2024/06/GHSA-jpjh-5cvh-hrp7/GHSA-jpjh-5cvh-hrp7.json @@ -60,7 +60,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-786" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-jq84-946j-r77q/GHSA-jq84-946j-r77q.json b/advisories/unreviewed/2024/06/GHSA-jq84-946j-r77q/GHSA-jq84-946j-r77q.json index 1f239db1d5e..5277f1fb935 100644 --- a/advisories/unreviewed/2024/06/GHSA-jq84-946j-r77q/GHSA-jq84-946j-r77q.json +++ b/advisories/unreviewed/2024/06/GHSA-jq84-946j-r77q/GHSA-jq84-946j-r77q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jq84-946j-r77q", - "modified": "2024-06-14T15:31:24Z", + "modified": "2024-07-03T18:45:22Z", "published": "2024-06-14T15:31:24Z", "aliases": [ "CVE-2024-37640" ], "details": "TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid5g in the function setWiFiEasyGuestCfg.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-14T14:15:11Z" diff --git a/advisories/unreviewed/2024/06/GHSA-m2cr-jxg8-pr4v/GHSA-m2cr-jxg8-pr4v.json b/advisories/unreviewed/2024/06/GHSA-m2cr-jxg8-pr4v/GHSA-m2cr-jxg8-pr4v.json index cc22f57dacf..88bc93e0924 100644 --- a/advisories/unreviewed/2024/06/GHSA-m2cr-jxg8-pr4v/GHSA-m2cr-jxg8-pr4v.json +++ b/advisories/unreviewed/2024/06/GHSA-m2cr-jxg8-pr4v/GHSA-m2cr-jxg8-pr4v.json @@ -36,7 +36,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-319" + "CWE-319", + "CWE-89" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-m4wv-7q3w-5mq7/GHSA-m4wv-7q3w-5mq7.json b/advisories/unreviewed/2024/06/GHSA-m4wv-7q3w-5mq7/GHSA-m4wv-7q3w-5mq7.json index a95efdee6e5..57665d660f6 100644 --- a/advisories/unreviewed/2024/06/GHSA-m4wv-7q3w-5mq7/GHSA-m4wv-7q3w-5mq7.json +++ b/advisories/unreviewed/2024/06/GHSA-m4wv-7q3w-5mq7/GHSA-m4wv-7q3w-5mq7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m4wv-7q3w-5mq7", - "modified": "2024-06-13T21:30:54Z", + "modified": "2024-07-03T18:45:07Z", "published": "2024-06-13T21:30:54Z", "aliases": [ "CVE-2024-32891" ], "details": "In sec_media_unprotect of media.c, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-362" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-13T21:15:53Z" diff --git a/advisories/unreviewed/2024/06/GHSA-m7m7-q9w5-x57c/GHSA-m7m7-q9w5-x57c.json b/advisories/unreviewed/2024/06/GHSA-m7m7-q9w5-x57c/GHSA-m7m7-q9w5-x57c.json index 92e703fd189..8718de536aa 100644 --- a/advisories/unreviewed/2024/06/GHSA-m7m7-q9w5-x57c/GHSA-m7m7-q9w5-x57c.json +++ b/advisories/unreviewed/2024/06/GHSA-m7m7-q9w5-x57c/GHSA-m7m7-q9w5-x57c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m7m7-q9w5-x57c", - "modified": "2024-06-20T06:30:54Z", + "modified": "2024-07-03T18:46:08Z", "published": "2024-06-20T06:30:54Z", "aliases": [ "CVE-2024-5475" ], "details": "The Responsive video embed WordPress plugin before 0.5.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-20T06:15:10Z" diff --git a/advisories/unreviewed/2024/06/GHSA-m869-mpfx-h3g2/GHSA-m869-mpfx-h3g2.json b/advisories/unreviewed/2024/06/GHSA-m869-mpfx-h3g2/GHSA-m869-mpfx-h3g2.json index 3bc651a4a13..a9c3f94e1b5 100644 --- a/advisories/unreviewed/2024/06/GHSA-m869-mpfx-h3g2/GHSA-m869-mpfx-h3g2.json +++ b/advisories/unreviewed/2024/06/GHSA-m869-mpfx-h3g2/GHSA-m869-mpfx-h3g2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m869-mpfx-h3g2", - "modified": "2024-06-17T15:30:49Z", + "modified": "2024-07-03T18:45:28Z", "published": "2024-06-16T03:30:34Z", "aliases": [ "CVE-2024-38395" ], "details": "In iTerm2 before 3.5.2, the \"Terminal may report window title\" setting is not honored, and thus remote code execution might occur but \"is not trivially exploitable.\"", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-16T01:15:48Z" diff --git a/advisories/unreviewed/2024/06/GHSA-m8cv-83cf-qccx/GHSA-m8cv-83cf-qccx.json b/advisories/unreviewed/2024/06/GHSA-m8cv-83cf-qccx/GHSA-m8cv-83cf-qccx.json index ee32905f40f..e7c851f53bd 100644 --- a/advisories/unreviewed/2024/06/GHSA-m8cv-83cf-qccx/GHSA-m8cv-83cf-qccx.json +++ b/advisories/unreviewed/2024/06/GHSA-m8cv-83cf-qccx/GHSA-m8cv-83cf-qccx.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-400" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-m8h7-pff8-m5jq/GHSA-m8h7-pff8-m5jq.json b/advisories/unreviewed/2024/06/GHSA-m8h7-pff8-m5jq/GHSA-m8h7-pff8-m5jq.json index ae512ca4633..4f7f2e8ec1f 100644 --- a/advisories/unreviewed/2024/06/GHSA-m8h7-pff8-m5jq/GHSA-m8h7-pff8-m5jq.json +++ b/advisories/unreviewed/2024/06/GHSA-m8h7-pff8-m5jq/GHSA-m8h7-pff8-m5jq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m8h7-pff8-m5jq", - "modified": "2024-06-20T15:31:18Z", + "modified": "2024-07-03T18:46:12Z", "published": "2024-06-20T15:31:18Z", "aliases": [ "CVE-2023-49112" ], "details": "Kiuwan provides an API endpoint\n\n/saas/rest/v1/info/application\n\nto get information about any \napplication, providing only its name via the \"application\" parameter. This endpoint lacks proper access \ncontrol mechanisms, allowing other authenticated users to read \ninformation about applications, even though they have not been granted \nthe necessary rights to do so.\n\n\n\nThis issue affects Kiuwan SAST: tbo.resource may be NULL in amdgpu_vm_bo_update.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-20T12:15:15Z" diff --git a/advisories/unreviewed/2024/06/GHSA-p595-g9xq-jgcw/GHSA-p595-g9xq-jgcw.json b/advisories/unreviewed/2024/06/GHSA-p595-g9xq-jgcw/GHSA-p595-g9xq-jgcw.json index bba9bfbfec2..3fea9caee3e 100644 --- a/advisories/unreviewed/2024/06/GHSA-p595-g9xq-jgcw/GHSA-p595-g9xq-jgcw.json +++ b/advisories/unreviewed/2024/06/GHSA-p595-g9xq-jgcw/GHSA-p595-g9xq-jgcw.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-p5mm-8cpw-hr23/GHSA-p5mm-8cpw-hr23.json b/advisories/unreviewed/2024/06/GHSA-p5mm-8cpw-hr23/GHSA-p5mm-8cpw-hr23.json index 20de467f618..fe17cc27e49 100644 --- a/advisories/unreviewed/2024/06/GHSA-p5mm-8cpw-hr23/GHSA-p5mm-8cpw-hr23.json +++ b/advisories/unreviewed/2024/06/GHSA-p5mm-8cpw-hr23/GHSA-p5mm-8cpw-hr23.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p5mm-8cpw-hr23", - "modified": "2024-06-19T21:32:30Z", + "modified": "2024-07-03T18:46:02Z", "published": "2024-06-19T21:32:30Z", "aliases": [ "CVE-2024-33836" ], "details": "In the module \"JA Marketplace\" (jamarketplace) up to version 9.0.1 from JA Module for PrestaShop, a guest can upload files with extensions .php. In version 6.X, the method `JmarketplaceproductModuleFrontController::init()` and in version 8.X, the method `JmarketplaceSellerproductModuleFrontController::init()` allow upload of .php files, which will lead to a critical vulnerability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-19T21:15:56Z" diff --git a/advisories/unreviewed/2024/06/GHSA-p763-v5vh-f5mg/GHSA-p763-v5vh-f5mg.json b/advisories/unreviewed/2024/06/GHSA-p763-v5vh-f5mg/GHSA-p763-v5vh-f5mg.json index 6dd2ff387fe..7570908aa83 100644 --- a/advisories/unreviewed/2024/06/GHSA-p763-v5vh-f5mg/GHSA-p763-v5vh-f5mg.json +++ b/advisories/unreviewed/2024/06/GHSA-p763-v5vh-f5mg/GHSA-p763-v5vh-f5mg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p763-v5vh-f5mg", - "modified": "2024-06-07T15:30:40Z", + "modified": "2024-07-03T18:44:18Z", "published": "2024-06-07T15:30:40Z", "aliases": [ "CVE-2024-36792" ], "details": "An issue in the implementation of the WPS in Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 allows attackers to gain access to the router's pin.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-316" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-07T15:15:50Z" diff --git a/advisories/unreviewed/2024/06/GHSA-p9qg-6v6v-2g47/GHSA-p9qg-6v6v-2g47.json b/advisories/unreviewed/2024/06/GHSA-p9qg-6v6v-2g47/GHSA-p9qg-6v6v-2g47.json index 9b7aa72130d..f7c9c5d6184 100644 --- a/advisories/unreviewed/2024/06/GHSA-p9qg-6v6v-2g47/GHSA-p9qg-6v6v-2g47.json +++ b/advisories/unreviewed/2024/06/GHSA-p9qg-6v6v-2g47/GHSA-p9qg-6v6v-2g47.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p9qg-6v6v-2g47", - "modified": "2024-06-17T15:30:54Z", + "modified": "2024-07-03T18:45:36Z", "published": "2024-06-17T15:30:54Z", "aliases": [ "CVE-2024-38469" ], "details": "zhimengzhe iBarn v1.5 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the $search parameter at /pay.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-80" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-17T14:15:12Z" diff --git a/advisories/unreviewed/2024/06/GHSA-phxr-ggj2-vch6/GHSA-phxr-ggj2-vch6.json b/advisories/unreviewed/2024/06/GHSA-phxr-ggj2-vch6/GHSA-phxr-ggj2-vch6.json index 60d024a6c2d..79449dd817d 100644 --- a/advisories/unreviewed/2024/06/GHSA-phxr-ggj2-vch6/GHSA-phxr-ggj2-vch6.json +++ b/advisories/unreviewed/2024/06/GHSA-phxr-ggj2-vch6/GHSA-phxr-ggj2-vch6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-phxr-ggj2-vch6", - "modified": "2024-06-20T15:31:18Z", + "modified": "2024-07-03T18:46:12Z", "published": "2024-06-20T15:31:18Z", "aliases": [ "CVE-2023-49113" ], "details": "The Kiuwan Local Analyzer (KLA) Java scanning application contains several \nhard-coded secrets in plain text format. In some cases, this can \npotentially compromise the confidentiality of the scan results. Several credentials were found in the JAR files of the Kiuwan Local Analyzer.\n\nThe\n JAR file \"lib.engine/insight/optimyth-insight.jar\" contains the file \n\"InsightServicesConfig.properties\", which has the configuration tokens \n\"insight.github.user\" as well as \"insight.github.password\" prefilled \nwith credentials. At least the specified username corresponds to a valid\n GitHub account. The\n JAR file \"lib.engine/insight/optimyth-insight.jar\" also contains the \nfile \"es/als/security/Encryptor.properties\", in which the key used for \nencrypting the results of any performed scan.\n\n\n\n\nThis issue affects Kiuwan SAST: reg, which is not same\nas port id. port id should be derived from chan_info array.\nSo fix this. Without this, its possible that we could corrupt\nstruct wcd938x_sdw_priv by accessing port_map array out of range\nwith channel id instead of port id.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-400" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-20T11:15:55Z" diff --git a/advisories/unreviewed/2024/06/GHSA-qp28-67v3-65qc/GHSA-qp28-67v3-65qc.json b/advisories/unreviewed/2024/06/GHSA-qp28-67v3-65qc/GHSA-qp28-67v3-65qc.json index d1864f3b9ba..93f5d906c8e 100644 --- a/advisories/unreviewed/2024/06/GHSA-qp28-67v3-65qc/GHSA-qp28-67v3-65qc.json +++ b/advisories/unreviewed/2024/06/GHSA-qp28-67v3-65qc/GHSA-qp28-67v3-65qc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qp28-67v3-65qc", - "modified": "2024-06-17T06:30:34Z", + "modified": "2024-07-03T18:45:34Z", "published": "2024-06-17T06:30:34Z", "aliases": [ "CVE-2024-3236" ], "details": "The Popup Builder WordPress plugin before 1.1.33 does not sanitise and escape some of its Notification fields, which could allow users such as contributor and above to perform Stored Cross-Site Scripting attacks.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-17T06:15:08Z" diff --git a/advisories/unreviewed/2024/06/GHSA-qpxp-m569-qp25/GHSA-qpxp-m569-qp25.json b/advisories/unreviewed/2024/06/GHSA-qpxp-m569-qp25/GHSA-qpxp-m569-qp25.json index 7d744df6f4a..a9c7d5e954a 100644 --- a/advisories/unreviewed/2024/06/GHSA-qpxp-m569-qp25/GHSA-qpxp-m569-qp25.json +++ b/advisories/unreviewed/2024/06/GHSA-qpxp-m569-qp25/GHSA-qpxp-m569-qp25.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qpxp-m569-qp25", - "modified": "2024-06-20T12:31:21Z", + "modified": "2024-07-03T18:46:09Z", "published": "2024-06-20T12:31:21Z", "aliases": [ "CVE-2022-48747" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nblock: Fix wrong offset in bio_truncate()\n\nbio_truncate() clears the buffer outside of last block of bdev, however\ncurrent bio_truncate() is using the wrong offset of page. So it can\nreturn the uninitialized data.\n\nThis happened when both of truncated/corrupted FS and userspace (via\nbdev) are trying to read the last of bdev.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-908" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-20T12:15:12Z" diff --git a/advisories/unreviewed/2024/06/GHSA-qqfm-9jcc-9q44/GHSA-qqfm-9jcc-9q44.json b/advisories/unreviewed/2024/06/GHSA-qqfm-9jcc-9q44/GHSA-qqfm-9jcc-9q44.json index 3f05f5a61a4..24286086e4c 100644 --- a/advisories/unreviewed/2024/06/GHSA-qqfm-9jcc-9q44/GHSA-qqfm-9jcc-9q44.json +++ b/advisories/unreviewed/2024/06/GHSA-qqfm-9jcc-9q44/GHSA-qqfm-9jcc-9q44.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qqfm-9jcc-9q44", - "modified": "2024-06-16T03:30:34Z", + "modified": "2024-07-03T18:45:29Z", "published": "2024-06-16T03:30:34Z", "aliases": [ "CVE-2024-38427" ], "details": "In International Color Consortium DemoIccMAX before 85ce74e, a logic flaw in CIccTagXmlProfileSequenceId::ParseXml in IccXML/IccLibXML/IccTagXml.cpp results in unconditionally returning false.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-252" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-16T02:15:08Z" diff --git a/advisories/unreviewed/2024/06/GHSA-qvvc-v3mj-qch5/GHSA-qvvc-v3mj-qch5.json b/advisories/unreviewed/2024/06/GHSA-qvvc-v3mj-qch5/GHSA-qvvc-v3mj-qch5.json index 15c2621bfdd..80962496c09 100644 --- a/advisories/unreviewed/2024/06/GHSA-qvvc-v3mj-qch5/GHSA-qvvc-v3mj-qch5.json +++ b/advisories/unreviewed/2024/06/GHSA-qvvc-v3mj-qch5/GHSA-qvvc-v3mj-qch5.json @@ -56,7 +56,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-119" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-qxgm-2hhj-rw7f/GHSA-qxgm-2hhj-rw7f.json b/advisories/unreviewed/2024/06/GHSA-qxgm-2hhj-rw7f/GHSA-qxgm-2hhj-rw7f.json index cad18ff0d91..49351148bbc 100644 --- a/advisories/unreviewed/2024/06/GHSA-qxgm-2hhj-rw7f/GHSA-qxgm-2hhj-rw7f.json +++ b/advisories/unreviewed/2024/06/GHSA-qxgm-2hhj-rw7f/GHSA-qxgm-2hhj-rw7f.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-783" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-r4g5-x2h5-r8gg/GHSA-r4g5-x2h5-r8gg.json b/advisories/unreviewed/2024/06/GHSA-r4g5-x2h5-r8gg/GHSA-r4g5-x2h5-r8gg.json index 62976fd7ec4..3a28a6289d1 100644 --- a/advisories/unreviewed/2024/06/GHSA-r4g5-x2h5-r8gg/GHSA-r4g5-x2h5-r8gg.json +++ b/advisories/unreviewed/2024/06/GHSA-r4g5-x2h5-r8gg/GHSA-r4g5-x2h5-r8gg.json @@ -45,7 +45,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-r6h6-9448-4q2f/GHSA-r6h6-9448-4q2f.json b/advisories/unreviewed/2024/06/GHSA-r6h6-9448-4q2f/GHSA-r6h6-9448-4q2f.json index 11be22dfa7e..a62af473593 100644 --- a/advisories/unreviewed/2024/06/GHSA-r6h6-9448-4q2f/GHSA-r6h6-9448-4q2f.json +++ b/advisories/unreviewed/2024/06/GHSA-r6h6-9448-4q2f/GHSA-r6h6-9448-4q2f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r6h6-9448-4q2f", - "modified": "2024-06-27T15:30:40Z", + "modified": "2024-07-03T18:45:57Z", "published": "2024-06-19T15:30:54Z", "aliases": [ "CVE-2024-38612" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: sr: fix invalid unregister error path\n\nThe error path of seg6_init() is wrong in case CONFIG_IPV6_SEG6_LWTUNNEL\nis not defined. In that case if seg6_hmac_init() fails, the\ngenl_unregister_family() isn't called.\n\nThis issue exist since commit 46738b1317e1 (\"ipv6: sr: add option to control\nlwtunnel support\"), and commit 5559cea2d5aa (\"ipv6: sr: fix possible\nuse-after-free and null-ptr-deref\") replaced unregister_pernet_subsys()\nwith genl_unregister_family() in this error path.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -61,9 +64,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-19T14:15:21Z" diff --git a/advisories/unreviewed/2024/06/GHSA-r96m-mwvr-946h/GHSA-r96m-mwvr-946h.json b/advisories/unreviewed/2024/06/GHSA-r96m-mwvr-946h/GHSA-r96m-mwvr-946h.json index 70e865ad18b..9e27d5e24b1 100644 --- a/advisories/unreviewed/2024/06/GHSA-r96m-mwvr-946h/GHSA-r96m-mwvr-946h.json +++ b/advisories/unreviewed/2024/06/GHSA-r96m-mwvr-946h/GHSA-r96m-mwvr-946h.json @@ -37,7 +37,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-rcq4-qh6m-j28q/GHSA-rcq4-qh6m-j28q.json b/advisories/unreviewed/2024/06/GHSA-rcq4-qh6m-j28q/GHSA-rcq4-qh6m-j28q.json index 293cc79fa2f..bc7fbd1c7b8 100644 --- a/advisories/unreviewed/2024/06/GHSA-rcq4-qh6m-j28q/GHSA-rcq4-qh6m-j28q.json +++ b/advisories/unreviewed/2024/06/GHSA-rcq4-qh6m-j28q/GHSA-rcq4-qh6m-j28q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rcq4-qh6m-j28q", - "modified": "2024-06-24T15:31:43Z", + "modified": "2024-07-03T18:46:13Z", "published": "2024-06-20T18:34:09Z", "aliases": [ "CVE-2024-33335" ], "details": "SQL Injection vulnerability in H3C SeaSQL DWS v.2.0 allows a remote attacker to execute arbitrary code via a crafted file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-20T17:15:50Z" diff --git a/advisories/unreviewed/2024/06/GHSA-rg42-f9ww-x3w7/GHSA-rg42-f9ww-x3w7.json b/advisories/unreviewed/2024/06/GHSA-rg42-f9ww-x3w7/GHSA-rg42-f9ww-x3w7.json index ab83eab7a7d..30918cb80ca 100644 --- a/advisories/unreviewed/2024/06/GHSA-rg42-f9ww-x3w7/GHSA-rg42-f9ww-x3w7.json +++ b/advisories/unreviewed/2024/06/GHSA-rg42-f9ww-x3w7/GHSA-rg42-f9ww-x3w7.json @@ -40,7 +40,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-358" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-rgw4-v387-9jvw/GHSA-rgw4-v387-9jvw.json b/advisories/unreviewed/2024/06/GHSA-rgw4-v387-9jvw/GHSA-rgw4-v387-9jvw.json index 9f57d558ddc..6899b390d9f 100644 --- a/advisories/unreviewed/2024/06/GHSA-rgw4-v387-9jvw/GHSA-rgw4-v387-9jvw.json +++ b/advisories/unreviewed/2024/06/GHSA-rgw4-v387-9jvw/GHSA-rgw4-v387-9jvw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rgw4-v387-9jvw", - "modified": "2024-06-14T06:34:48Z", + "modified": "2024-07-03T18:45:17Z", "published": "2024-06-14T06:34:48Z", "aliases": [ "CVE-2024-2218" ], "details": "The LuckyWP Table of Contents WordPress plugin through 2.1.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-14T06:15:11Z" diff --git a/advisories/unreviewed/2024/06/GHSA-rhv4-3chh-r5jc/GHSA-rhv4-3chh-r5jc.json b/advisories/unreviewed/2024/06/GHSA-rhv4-3chh-r5jc/GHSA-rhv4-3chh-r5jc.json index 1ad1edee83b..608c4bb3893 100644 --- a/advisories/unreviewed/2024/06/GHSA-rhv4-3chh-r5jc/GHSA-rhv4-3chh-r5jc.json +++ b/advisories/unreviewed/2024/06/GHSA-rhv4-3chh-r5jc/GHSA-rhv4-3chh-r5jc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rhv4-3chh-r5jc", - "modified": "2024-06-18T06:30:43Z", + "modified": "2024-07-03T18:45:43Z", "published": "2024-06-18T06:30:43Z", "aliases": [ "CVE-2024-37081" @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-556" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-rmff-fqq9-pc3q/GHSA-rmff-fqq9-pc3q.json b/advisories/unreviewed/2024/06/GHSA-rmff-fqq9-pc3q/GHSA-rmff-fqq9-pc3q.json index bb93e62cadb..8f3957b1ebe 100644 --- a/advisories/unreviewed/2024/06/GHSA-rmff-fqq9-pc3q/GHSA-rmff-fqq9-pc3q.json +++ b/advisories/unreviewed/2024/06/GHSA-rmff-fqq9-pc3q/GHSA-rmff-fqq9-pc3q.json @@ -41,7 +41,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-rmh4-q56p-p5w5/GHSA-rmh4-q56p-p5w5.json b/advisories/unreviewed/2024/06/GHSA-rmh4-q56p-p5w5/GHSA-rmh4-q56p-p5w5.json index 924bc73ffb4..34beda2d4fe 100644 --- a/advisories/unreviewed/2024/06/GHSA-rmh4-q56p-p5w5/GHSA-rmh4-q56p-p5w5.json +++ b/advisories/unreviewed/2024/06/GHSA-rmh4-q56p-p5w5/GHSA-rmh4-q56p-p5w5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rmh4-q56p-p5w5", - "modified": "2024-06-13T21:30:55Z", + "modified": "2024-07-03T18:45:13Z", "published": "2024-06-13T21:30:55Z", "aliases": [ "CVE-2024-32925" ], "details": "In dhd_prot_txstatus_process of dhd_msgbuf.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-13T21:15:56Z" diff --git a/advisories/unreviewed/2024/06/GHSA-rmx5-8m2v-hpmw/GHSA-rmx5-8m2v-hpmw.json b/advisories/unreviewed/2024/06/GHSA-rmx5-8m2v-hpmw/GHSA-rmx5-8m2v-hpmw.json index c2b769ba205..b19df5b63c0 100644 --- a/advisories/unreviewed/2024/06/GHSA-rmx5-8m2v-hpmw/GHSA-rmx5-8m2v-hpmw.json +++ b/advisories/unreviewed/2024/06/GHSA-rmx5-8m2v-hpmw/GHSA-rmx5-8m2v-hpmw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rmx5-8m2v-hpmw", - "modified": "2024-06-18T18:31:19Z", + "modified": "2024-07-03T18:45:47Z", "published": "2024-06-18T18:31:19Z", "aliases": [ "CVE-2024-37802" ], "details": "CodeProjects Health Care hospital Management System v1.0 was discovered to contain a SQL injection vulnerability in the Patient Info module via the searvalu parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-18T17:15:52Z" diff --git a/advisories/unreviewed/2024/06/GHSA-rp47-r8r5-fmgm/GHSA-rp47-r8r5-fmgm.json b/advisories/unreviewed/2024/06/GHSA-rp47-r8r5-fmgm/GHSA-rp47-r8r5-fmgm.json index 0091b1a4b44..6a830a0fedf 100644 --- a/advisories/unreviewed/2024/06/GHSA-rp47-r8r5-fmgm/GHSA-rp47-r8r5-fmgm.json +++ b/advisories/unreviewed/2024/06/GHSA-rp47-r8r5-fmgm/GHSA-rp47-r8r5-fmgm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rp47-r8r5-fmgm", - "modified": "2024-06-11T06:31:47Z", + "modified": "2024-07-03T18:44:46Z", "published": "2024-06-11T06:31:47Z", "aliases": [ "CVE-2024-31397" ], "details": "Improper handling of extra values issue exists in Cybozu Garoon 5.0.0 to 5.15.2. If this vulnerability is exploited, a user who can log in to the product with the administrative privilege may be able to cause a denial-of-service (DoS) condition.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-231" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-11T06:15:10Z" diff --git a/advisories/unreviewed/2024/06/GHSA-rp5x-rj69-r36x/GHSA-rp5x-rj69-r36x.json b/advisories/unreviewed/2024/06/GHSA-rp5x-rj69-r36x/GHSA-rp5x-rj69-r36x.json index 55aa799257c..3ce3c3e1f45 100644 --- a/advisories/unreviewed/2024/06/GHSA-rp5x-rj69-r36x/GHSA-rp5x-rj69-r36x.json +++ b/advisories/unreviewed/2024/06/GHSA-rp5x-rj69-r36x/GHSA-rp5x-rj69-r36x.json @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-400" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-rxh8-v6x2-m5h4/GHSA-rxh8-v6x2-m5h4.json b/advisories/unreviewed/2024/06/GHSA-rxh8-v6x2-m5h4/GHSA-rxh8-v6x2-m5h4.json index 20571fef490..21af7327a9f 100644 --- a/advisories/unreviewed/2024/06/GHSA-rxh8-v6x2-m5h4/GHSA-rxh8-v6x2-m5h4.json +++ b/advisories/unreviewed/2024/06/GHSA-rxh8-v6x2-m5h4/GHSA-rxh8-v6x2-m5h4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rxh8-v6x2-m5h4", - "modified": "2024-06-09T18:30:36Z", + "modified": "2024-07-03T18:44:21Z", "published": "2024-06-09T18:30:36Z", "aliases": [ "CVE-2024-32715" ], "details": "Missing Authorization vulnerability in Olive Themes Olive One Click Demo Import.This issue affects Olive One Click Demo Import: from n/a through 1.1.1.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-862" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-09T17:15:49Z" diff --git a/advisories/unreviewed/2024/06/GHSA-v23v-9j7q-mjq6/GHSA-v23v-9j7q-mjq6.json b/advisories/unreviewed/2024/06/GHSA-v23v-9j7q-mjq6/GHSA-v23v-9j7q-mjq6.json index 81a36ffde0f..4801398cb78 100644 --- a/advisories/unreviewed/2024/06/GHSA-v23v-9j7q-mjq6/GHSA-v23v-9j7q-mjq6.json +++ b/advisories/unreviewed/2024/06/GHSA-v23v-9j7q-mjq6/GHSA-v23v-9j7q-mjq6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v23v-9j7q-mjq6", - "modified": "2024-06-18T18:31:19Z", + "modified": "2024-07-03T18:45:46Z", "published": "2024-06-18T18:31:19Z", "aliases": [ "CVE-2024-37800" ], "details": "CodeProjects Restaurant Reservation System v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Date parameter at index.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-18T17:15:52Z" diff --git a/advisories/unreviewed/2024/06/GHSA-v8pv-8xhp-96rh/GHSA-v8pv-8xhp-96rh.json b/advisories/unreviewed/2024/06/GHSA-v8pv-8xhp-96rh/GHSA-v8pv-8xhp-96rh.json index f85335318a6..a5378d4695b 100644 --- a/advisories/unreviewed/2024/06/GHSA-v8pv-8xhp-96rh/GHSA-v8pv-8xhp-96rh.json +++ b/advisories/unreviewed/2024/06/GHSA-v8pv-8xhp-96rh/GHSA-v8pv-8xhp-96rh.json @@ -92,7 +92,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-400" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-vjmq-27j9-636j/GHSA-vjmq-27j9-636j.json b/advisories/unreviewed/2024/06/GHSA-vjmq-27j9-636j/GHSA-vjmq-27j9-636j.json index 1419f5f5b2d..7fd74291209 100644 --- a/advisories/unreviewed/2024/06/GHSA-vjmq-27j9-636j/GHSA-vjmq-27j9-636j.json +++ b/advisories/unreviewed/2024/06/GHSA-vjmq-27j9-636j/GHSA-vjmq-27j9-636j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vjmq-27j9-636j", - "modified": "2024-06-19T15:30:52Z", + "modified": "2024-07-03T18:45:53Z", "published": "2024-06-19T15:30:52Z", "aliases": [ "CVE-2024-38541" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nof: module: add buffer overflow check in of_modalias()\n\nIn of_modalias(), if the buffer happens to be too small even for the 1st\nsnprintf() call, the len parameter will become negative and str parameter\n(if not NULL initially) will point beyond the buffer's end. Add the buffer\noverflow check after the 1st snprintf() call and fix such check after the\nstrlen() call (accounting for the terminating NUL char).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-19T14:15:14Z" diff --git a/advisories/unreviewed/2024/06/GHSA-vqcc-7gmh-v9jr/GHSA-vqcc-7gmh-v9jr.json b/advisories/unreviewed/2024/06/GHSA-vqcc-7gmh-v9jr/GHSA-vqcc-7gmh-v9jr.json index b3431229244..1ec104c4533 100644 --- a/advisories/unreviewed/2024/06/GHSA-vqcc-7gmh-v9jr/GHSA-vqcc-7gmh-v9jr.json +++ b/advisories/unreviewed/2024/06/GHSA-vqcc-7gmh-v9jr/GHSA-vqcc-7gmh-v9jr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vqcc-7gmh-v9jr", - "modified": "2024-06-14T15:31:24Z", + "modified": "2024-07-03T18:45:19Z", "published": "2024-06-14T15:31:24Z", "aliases": [ "CVE-2024-37637" ], "details": "TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid5g in the function setWizardCfg.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-14T14:15:10Z" diff --git a/advisories/unreviewed/2024/06/GHSA-vx52-cgqj-7pvr/GHSA-vx52-cgqj-7pvr.json b/advisories/unreviewed/2024/06/GHSA-vx52-cgqj-7pvr/GHSA-vx52-cgqj-7pvr.json index 2b3e810edc8..a2e35300333 100644 --- a/advisories/unreviewed/2024/06/GHSA-vx52-cgqj-7pvr/GHSA-vx52-cgqj-7pvr.json +++ b/advisories/unreviewed/2024/06/GHSA-vx52-cgqj-7pvr/GHSA-vx52-cgqj-7pvr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vx52-cgqj-7pvr", - "modified": "2024-06-14T18:31:43Z", + "modified": "2024-07-03T18:45:24Z", "published": "2024-06-14T18:31:43Z", "aliases": [ "CVE-2024-37641" ], "details": "TRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain a stack overflow via the submit-url parameter at /formNewSchedule", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-14T16:15:12Z" diff --git a/advisories/unreviewed/2024/06/GHSA-vxqj-33jf-35x5/GHSA-vxqj-33jf-35x5.json b/advisories/unreviewed/2024/06/GHSA-vxqj-33jf-35x5/GHSA-vxqj-33jf-35x5.json index ba6baadc1fa..6ac8b65c1a1 100644 --- a/advisories/unreviewed/2024/06/GHSA-vxqj-33jf-35x5/GHSA-vxqj-33jf-35x5.json +++ b/advisories/unreviewed/2024/06/GHSA-vxqj-33jf-35x5/GHSA-vxqj-33jf-35x5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vxqj-33jf-35x5", - "modified": "2024-06-12T06:30:41Z", + "modified": "2024-07-03T18:44:36Z", "published": "2024-06-10T21:30:40Z", "aliases": [ "CVE-2024-27857" ], "details": "An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in visionOS 1.2, macOS Sonoma 14.5, tvOS 17.5, iOS 17.5 and iPadOS 17.5. A remote attacker may be able to cause unexpected app termination or arbitrary code execution.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -57,9 +60,10 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-119", + "CWE-94" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-10T21:15:51Z" diff --git a/advisories/unreviewed/2024/06/GHSA-w69w-gv35-vqjh/GHSA-w69w-gv35-vqjh.json b/advisories/unreviewed/2024/06/GHSA-w69w-gv35-vqjh/GHSA-w69w-gv35-vqjh.json index a3531662aa6..d9f528b82cd 100644 --- a/advisories/unreviewed/2024/06/GHSA-w69w-gv35-vqjh/GHSA-w69w-gv35-vqjh.json +++ b/advisories/unreviewed/2024/06/GHSA-w69w-gv35-vqjh/GHSA-w69w-gv35-vqjh.json @@ -49,7 +49,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-w7h8-wmjg-8jqm/GHSA-w7h8-wmjg-8jqm.json b/advisories/unreviewed/2024/06/GHSA-w7h8-wmjg-8jqm/GHSA-w7h8-wmjg-8jqm.json index 50d7b6bbc6f..a75ac0d255c 100644 --- a/advisories/unreviewed/2024/06/GHSA-w7h8-wmjg-8jqm/GHSA-w7h8-wmjg-8jqm.json +++ b/advisories/unreviewed/2024/06/GHSA-w7h8-wmjg-8jqm/GHSA-w7h8-wmjg-8jqm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w7h8-wmjg-8jqm", - "modified": "2024-06-13T21:30:52Z", + "modified": "2024-07-03T18:45:02Z", "published": "2024-06-13T21:30:52Z", "aliases": [ "CVE-2024-37634" ], "details": "TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid in the function setWiFiEasyCfg.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-13T19:15:52Z" diff --git a/advisories/unreviewed/2024/06/GHSA-w8j6-vhx2-7qvh/GHSA-w8j6-vhx2-7qvh.json b/advisories/unreviewed/2024/06/GHSA-w8j6-vhx2-7qvh/GHSA-w8j6-vhx2-7qvh.json index 6f0e55c6782..217ad6f3ad2 100644 --- a/advisories/unreviewed/2024/06/GHSA-w8j6-vhx2-7qvh/GHSA-w8j6-vhx2-7qvh.json +++ b/advisories/unreviewed/2024/06/GHSA-w8j6-vhx2-7qvh/GHSA-w8j6-vhx2-7qvh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w8j6-vhx2-7qvh", - "modified": "2024-06-14T06:34:48Z", + "modified": "2024-07-03T18:45:17Z", "published": "2024-06-14T06:34:48Z", "aliases": [ "CVE-2024-3965" ], "details": "The Pray For Me WordPress plugin through 1.0.4 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-14T06:15:12Z" diff --git a/advisories/unreviewed/2024/06/GHSA-wr2f-45vv-3hjc/GHSA-wr2f-45vv-3hjc.json b/advisories/unreviewed/2024/06/GHSA-wr2f-45vv-3hjc/GHSA-wr2f-45vv-3hjc.json index a61b074ae66..82673e61ed8 100644 --- a/advisories/unreviewed/2024/06/GHSA-wr2f-45vv-3hjc/GHSA-wr2f-45vv-3hjc.json +++ b/advisories/unreviewed/2024/06/GHSA-wr2f-45vv-3hjc/GHSA-wr2f-45vv-3hjc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wr2f-45vv-3hjc", - "modified": "2024-06-11T21:32:17Z", + "modified": "2024-07-03T18:44:48Z", "published": "2024-06-11T21:32:17Z", "aliases": [ "CVE-2024-34405" ], "details": "Improper deep link validation in McAfee Security: Antivirus VPN for Android before 8.3.0 could allow an attacker to launch an arbitrary URL within the app.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-11T19:16:07Z" diff --git a/advisories/unreviewed/2024/06/GHSA-wrc7-97qh-j6mh/GHSA-wrc7-97qh-j6mh.json b/advisories/unreviewed/2024/06/GHSA-wrc7-97qh-j6mh/GHSA-wrc7-97qh-j6mh.json index 3ccfe783e20..39038ff17aa 100644 --- a/advisories/unreviewed/2024/06/GHSA-wrc7-97qh-j6mh/GHSA-wrc7-97qh-j6mh.json +++ b/advisories/unreviewed/2024/06/GHSA-wrc7-97qh-j6mh/GHSA-wrc7-97qh-j6mh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wrc7-97qh-j6mh", - "modified": "2024-06-10T18:31:06Z", + "modified": "2024-07-03T18:44:20Z", "published": "2024-06-09T15:31:10Z", "aliases": [ "CVE-2024-37535" ], "details": "GNOME VTE before 0.76.3 allows an attacker to cause a denial of service (memory consumption) via a window resize escape sequence, a related issue to CVE-2000-0476.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-400" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-09T15:16:00Z" diff --git a/advisories/unreviewed/2024/06/GHSA-ww9f-v5vc-69w2/GHSA-ww9f-v5vc-69w2.json b/advisories/unreviewed/2024/06/GHSA-ww9f-v5vc-69w2/GHSA-ww9f-v5vc-69w2.json index e4760b49f10..f05c6caeedc 100644 --- a/advisories/unreviewed/2024/06/GHSA-ww9f-v5vc-69w2/GHSA-ww9f-v5vc-69w2.json +++ b/advisories/unreviewed/2024/06/GHSA-ww9f-v5vc-69w2/GHSA-ww9f-v5vc-69w2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-ww9f-v5vc-69w2", - "modified": "2024-06-11T18:30:46Z", + "modified": "2024-07-03T18:44:48Z", "published": "2024-06-11T18:30:45Z", "aliases": [ "CVE-2024-36650" ], "details": "TOTOLINK AC1200 Wireless Dual Band Gigabit Router firmware A3100R V4.1.2cu.5247_B20211129, in the cgi function `setNoticeCfg` of the file `/lib/cste_modules/system.so`, the length of the user input string `NoticeUrl` is not checked. This can lead to a buffer overflow, allowing attackers to construct malicious HTTP or MQTT requests to cause a denial-of-service attack.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-11T16:15:29Z" diff --git a/advisories/unreviewed/2024/06/GHSA-x756-rqwh-fr4m/GHSA-x756-rqwh-fr4m.json b/advisories/unreviewed/2024/06/GHSA-x756-rqwh-fr4m/GHSA-x756-rqwh-fr4m.json index 301d14c41e3..f31d15fab3c 100644 --- a/advisories/unreviewed/2024/06/GHSA-x756-rqwh-fr4m/GHSA-x756-rqwh-fr4m.json +++ b/advisories/unreviewed/2024/06/GHSA-x756-rqwh-fr4m/GHSA-x756-rqwh-fr4m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x756-rqwh-fr4m", - "modified": "2024-06-13T21:30:54Z", + "modified": "2024-07-03T18:45:07Z", "published": "2024-06-13T21:30:54Z", "aliases": [ "CVE-2024-29786" ], "details": "In pktproc_fill_data_addr_without_bm of link_rx_pktproc.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-13T21:15:52Z" diff --git a/advisories/unreviewed/2024/06/GHSA-x8qf-jpxw-cwjv/GHSA-x8qf-jpxw-cwjv.json b/advisories/unreviewed/2024/06/GHSA-x8qf-jpxw-cwjv/GHSA-x8qf-jpxw-cwjv.json index 5f58c8d09f6..052735e9f8f 100644 --- a/advisories/unreviewed/2024/06/GHSA-x8qf-jpxw-cwjv/GHSA-x8qf-jpxw-cwjv.json +++ b/advisories/unreviewed/2024/06/GHSA-x8qf-jpxw-cwjv/GHSA-x8qf-jpxw-cwjv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x8qf-jpxw-cwjv", - "modified": "2024-06-13T21:30:55Z", + "modified": "2024-07-03T18:45:12Z", "published": "2024-06-13T21:30:55Z", "aliases": [ "CVE-2024-32907" ], "details": "In memcall_add of memlog.c, there is a possible buffer overflow due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-20" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-13T21:15:54Z" diff --git a/advisories/unreviewed/2024/06/GHSA-xf4m-339r-jvfr/GHSA-xf4m-339r-jvfr.json b/advisories/unreviewed/2024/06/GHSA-xf4m-339r-jvfr/GHSA-xf4m-339r-jvfr.json index 0fea278bf18..0529e094dc5 100644 --- a/advisories/unreviewed/2024/06/GHSA-xf4m-339r-jvfr/GHSA-xf4m-339r-jvfr.json +++ b/advisories/unreviewed/2024/06/GHSA-xf4m-339r-jvfr/GHSA-xf4m-339r-jvfr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xf4m-339r-jvfr", - "modified": "2024-06-12T06:30:41Z", + "modified": "2024-07-03T18:44:35Z", "published": "2024-06-10T21:30:40Z", "aliases": [ "CVE-2024-27850" ], "details": "This issue was addressed with improvements to the noise injection algorithm. This issue is fixed in visionOS 1.2, macOS Sonoma 14.5, Safari 17.5, iOS 17.5 and iPadOS 17.5. A maliciously crafted webpage may be able to fingerprint the user.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -43,7 +46,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-10T21:15:51Z" diff --git a/advisories/unreviewed/2024/06/GHSA-xhf3-pp4q-gxh5/GHSA-xhf3-pp4q-gxh5.json b/advisories/unreviewed/2024/06/GHSA-xhf3-pp4q-gxh5/GHSA-xhf3-pp4q-gxh5.json index 8a48c29fc04..0b4ed465eb6 100644 --- a/advisories/unreviewed/2024/06/GHSA-xhf3-pp4q-gxh5/GHSA-xhf3-pp4q-gxh5.json +++ b/advisories/unreviewed/2024/06/GHSA-xhf3-pp4q-gxh5/GHSA-xhf3-pp4q-gxh5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xhf3-pp4q-gxh5", - "modified": "2024-06-17T18:31:33Z", + "modified": "2024-07-03T18:45:37Z", "published": "2024-06-17T18:31:33Z", "aliases": [ "CVE-2024-0397" ], "details": "A defect was discovered in the Python “ssl” module where there is a memory\nrace condition with the ssl.SSLContext methods “cert_store_stats()” and\n“get_ca_certs()”. The race condition can be triggered if the methods are\ncalled at the same time as certificates are loaded into the SSLContext,\nsuch as during the TLS handshake with a certificate directory configured.\nThis issue is fixed in CPython 3.10.14, 3.11.9, 3.12.3, and 3.13.0a5.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H" + } ], "affected": [ @@ -61,9 +64,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-362" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-17T16:15:10Z" diff --git a/advisories/unreviewed/2024/06/GHSA-xjc7-gh59-3hp4/GHSA-xjc7-gh59-3hp4.json b/advisories/unreviewed/2024/06/GHSA-xjc7-gh59-3hp4/GHSA-xjc7-gh59-3hp4.json index 6e773b59185..457fcd0c37c 100644 --- a/advisories/unreviewed/2024/06/GHSA-xjc7-gh59-3hp4/GHSA-xjc7-gh59-3hp4.json +++ b/advisories/unreviewed/2024/06/GHSA-xjc7-gh59-3hp4/GHSA-xjc7-gh59-3hp4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xjc7-gh59-3hp4", - "modified": "2024-06-13T21:30:54Z", + "modified": "2024-07-03T18:45:09Z", "published": "2024-06-13T21:30:54Z", "aliases": [ "CVE-2024-32893" ], "details": "In _s5e9865_mif_set_rate of exynos_dvfs.c, there is a possible out of bounds read due to improper casting. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-13T21:15:53Z" diff --git a/advisories/unreviewed/2024/06/GHSA-xjjc-xf36-3jp9/GHSA-xjjc-xf36-3jp9.json b/advisories/unreviewed/2024/06/GHSA-xjjc-xf36-3jp9/GHSA-xjjc-xf36-3jp9.json index 27a8840f1bf..b73504708dc 100644 --- a/advisories/unreviewed/2024/06/GHSA-xjjc-xf36-3jp9/GHSA-xjjc-xf36-3jp9.json +++ b/advisories/unreviewed/2024/06/GHSA-xjjc-xf36-3jp9/GHSA-xjjc-xf36-3jp9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xjjc-xf36-3jp9", - "modified": "2024-06-17T18:31:33Z", + "modified": "2024-07-03T18:45:22Z", "published": "2024-06-14T15:31:25Z", "aliases": [ "CVE-2024-33374" ], "details": "Incorrect access control in the UART/Serial interface on the LB-LINK BL-W1210M v2.0 router allows attackers to access the root terminal without authentication.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-14T15:15:50Z" diff --git a/advisories/unreviewed/2024/06/GHSA-xm9v-fg48-44v7/GHSA-xm9v-fg48-44v7.json b/advisories/unreviewed/2024/06/GHSA-xm9v-fg48-44v7/GHSA-xm9v-fg48-44v7.json index cbf7c02a375..75d0918c10e 100644 --- a/advisories/unreviewed/2024/06/GHSA-xm9v-fg48-44v7/GHSA-xm9v-fg48-44v7.json +++ b/advisories/unreviewed/2024/06/GHSA-xm9v-fg48-44v7/GHSA-xm9v-fg48-44v7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xm9v-fg48-44v7", - "modified": "2024-06-15T00:31:15Z", + "modified": "2024-07-03T18:45:28Z", "published": "2024-06-15T00:31:15Z", "aliases": [ "CVE-2024-30119" @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-326", "CWE-522" ], "severity": "LOW", diff --git a/advisories/unreviewed/2024/06/GHSA-xmvf-wm3q-gh2f/GHSA-xmvf-wm3q-gh2f.json b/advisories/unreviewed/2024/06/GHSA-xmvf-wm3q-gh2f/GHSA-xmvf-wm3q-gh2f.json index 05d0355b802..555db21de36 100644 --- a/advisories/unreviewed/2024/06/GHSA-xmvf-wm3q-gh2f/GHSA-xmvf-wm3q-gh2f.json +++ b/advisories/unreviewed/2024/06/GHSA-xmvf-wm3q-gh2f/GHSA-xmvf-wm3q-gh2f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xmvf-wm3q-gh2f", - "modified": "2024-06-17T09:31:02Z", + "modified": "2024-07-03T18:45:35Z", "published": "2024-06-17T09:31:02Z", "aliases": [ "CVE-2024-36277" ], "details": "Improper verification of cryptographic signature issue exists in \"FreeFrom - the nostr client\" App versions prior to 1.3.5 for Android and iOS. The affected app cannot detect event data with invalid signatures.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-347" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-17T08:15:48Z" diff --git a/advisories/unreviewed/2024/06/GHSA-xp8w-jxfc-xrqq/GHSA-xp8w-jxfc-xrqq.json b/advisories/unreviewed/2024/06/GHSA-xp8w-jxfc-xrqq/GHSA-xp8w-jxfc-xrqq.json index 6fdbd6493fa..f6f1e22ddf5 100644 --- a/advisories/unreviewed/2024/06/GHSA-xp8w-jxfc-xrqq/GHSA-xp8w-jxfc-xrqq.json +++ b/advisories/unreviewed/2024/06/GHSA-xp8w-jxfc-xrqq/GHSA-xp8w-jxfc-xrqq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xp8w-jxfc-xrqq", - "modified": "2024-06-10T18:31:06Z", + "modified": "2024-07-03T18:44:22Z", "published": "2024-06-10T18:31:06Z", "aliases": [ "CVE-2024-26507" ], "details": "An issue in FinalWire AIRDA Extreme, AIDA64 Engineer, AIDA64 Business, AIDA64 Network Audit v.7.00.6700 and before allows a local attacker to escalate privileges via the DeviceIoControl call associated with MmMapIoSpace, IoAllocateMdl, MmBuildMdlForNonPagedPool, or MmMapLockedPages components.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-1286" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-10T16:15:12Z" diff --git a/advisories/unreviewed/2024/06/GHSA-xqg8-fm8q-c2p5/GHSA-xqg8-fm8q-c2p5.json b/advisories/unreviewed/2024/06/GHSA-xqg8-fm8q-c2p5/GHSA-xqg8-fm8q-c2p5.json index f9a2550e042..777708ae290 100644 --- a/advisories/unreviewed/2024/06/GHSA-xqg8-fm8q-c2p5/GHSA-xqg8-fm8q-c2p5.json +++ b/advisories/unreviewed/2024/06/GHSA-xqg8-fm8q-c2p5/GHSA-xqg8-fm8q-c2p5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xqg8-fm8q-c2p5", - "modified": "2024-06-13T21:30:55Z", + "modified": "2024-07-03T18:45:13Z", "published": "2024-06-13T21:30:55Z", "aliases": [ "CVE-2024-32909" ], "details": "In handle_msg of main.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-13T21:15:55Z" diff --git a/advisories/unreviewed/2024/06/GHSA-xwrr-9h7c-8mxc/GHSA-xwrr-9h7c-8mxc.json b/advisories/unreviewed/2024/06/GHSA-xwrr-9h7c-8mxc/GHSA-xwrr-9h7c-8mxc.json index 19266482e36..a9cf3ed27fc 100644 --- a/advisories/unreviewed/2024/06/GHSA-xwrr-9h7c-8mxc/GHSA-xwrr-9h7c-8mxc.json +++ b/advisories/unreviewed/2024/06/GHSA-xwrr-9h7c-8mxc/GHSA-xwrr-9h7c-8mxc.json @@ -41,7 +41,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], "severity": null, "github_reviewed": false,