From 138ebcbde5035d299241a9aa7f95a3cfbacf3570 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 6 Feb 2024 03:34:15 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-xr7r-f8xq-vfvv.json | 4 ++ .../GHSA-pr96-m2pj-3g36.json | 4 ++ .../GHSA-9vh7-c87x-8q9v.json | 4 ++ .../GHSA-3h6x-952r-xr8p.json | 4 ++ .../GHSA-63fx-c7fv-hgj5.json | 4 ++ .../GHSA-73m5-j333-fcwc.json | 4 ++ .../GHSA-93px-8x98-j7p2.json | 4 ++ .../GHSA-gfh2-2mj9-m2cx.json | 4 ++ .../GHSA-q6j4-xjv3-96rj.json | 4 ++ .../GHSA-rvwq-r5pc-g3h9.json | 4 ++ .../GHSA-293v-32vx-9g86.json | 39 +++++++++++++++ .../GHSA-3298-46rv-mjjj.json | 2 +- .../GHSA-4gv8-ph4v-rwjm.json | 38 ++++++++++++++ .../GHSA-66qc-rgfw-8hq2.json | 2 +- .../GHSA-68r4-mq9j-2rrq.json | 38 ++++++++++++++ .../GHSA-694p-hcfm-p8q8.json | 50 +++++++++++++++++++ .../GHSA-8vw5-wvh5-q977.json | 38 ++++++++++++++ .../GHSA-8xpr-jq7w-573j.json | 50 +++++++++++++++++++ .../GHSA-94f4-228x-55q7.json | 38 ++++++++++++++ .../GHSA-99jr-pjjw-hqmq.json | 50 +++++++++++++++++++ .../GHSA-9fhr-gx36-jrfv.json | 39 +++++++++++++++ .../GHSA-c5g4-g3x7-x8rm.json | 39 +++++++++++++++ .../GHSA-c6f2-5665-5p8p.json | 39 +++++++++++++++ .../GHSA-frmq-mwj6-5m79.json | 38 ++++++++++++++ .../GHSA-fwwv-x7hh-wmpw.json | 38 ++++++++++++++ .../GHSA-g39j-hgm2-fxmh.json | 38 ++++++++++++++ .../GHSA-gvhv-g3h5-f6r7.json | 38 ++++++++++++++ .../GHSA-hxw7-jqv7-6h7r.json | 35 +++++++++++++ .../GHSA-j428-8h66-82p9.json | 38 ++++++++++++++ .../GHSA-j973-rvvm-fh3w.json | 38 ++++++++++++++ .../GHSA-jpv8-vxhj-7qmf.json | 38 ++++++++++++++ .../GHSA-m6p7-jxxh-vc8c.json | 38 ++++++++++++++ .../GHSA-mf94-378q-xvc3.json | 39 +++++++++++++++ .../GHSA-mfph-26j7-jm24.json | 50 +++++++++++++++++++ .../GHSA-mmfm-2hr6-jvqr.json | 50 +++++++++++++++++++ .../GHSA-mvmq-hrr8-p65f.json | 38 ++++++++++++++ .../GHSA-p3gm-xxh4-xjmg.json | 39 +++++++++++++++ .../GHSA-p3jh-mv97-74gv.json | 38 ++++++++++++++ .../GHSA-pc53-x582-24xc.json | 38 ++++++++++++++ .../GHSA-pg8c-mxmr-vcqr.json | 38 ++++++++++++++ .../GHSA-pj36-rhxp-gj4x.json | 38 ++++++++++++++ .../GHSA-qv88-9x4p-qm78.json | 35 +++++++++++++ .../GHSA-r92x-24fv-xvcc.json | 2 +- .../GHSA-r947-98rq-44mh.json | 38 ++++++++++++++ .../GHSA-v3x4-p7hr-w52x.json | 2 +- .../GHSA-v42h-5rm7-cppg.json | 50 +++++++++++++++++++ .../GHSA-vv93-j256-hpwh.json | 50 +++++++++++++++++++ .../GHSA-x4hh-7hpg-jmcg.json | 1 + .../GHSA-x547-pm2q-2cr6.json | 39 +++++++++++++++ .../GHSA-xww7-5f37-vrcg.json | 2 +- 50 files changed, 1423 insertions(+), 5 deletions(-) create mode 100644 advisories/unreviewed/2024/02/GHSA-293v-32vx-9g86/GHSA-293v-32vx-9g86.json create mode 100644 advisories/unreviewed/2024/02/GHSA-4gv8-ph4v-rwjm/GHSA-4gv8-ph4v-rwjm.json create mode 100644 advisories/unreviewed/2024/02/GHSA-68r4-mq9j-2rrq/GHSA-68r4-mq9j-2rrq.json create mode 100644 advisories/unreviewed/2024/02/GHSA-694p-hcfm-p8q8/GHSA-694p-hcfm-p8q8.json create mode 100644 advisories/unreviewed/2024/02/GHSA-8vw5-wvh5-q977/GHSA-8vw5-wvh5-q977.json create mode 100644 advisories/unreviewed/2024/02/GHSA-8xpr-jq7w-573j/GHSA-8xpr-jq7w-573j.json create mode 100644 advisories/unreviewed/2024/02/GHSA-94f4-228x-55q7/GHSA-94f4-228x-55q7.json create mode 100644 advisories/unreviewed/2024/02/GHSA-99jr-pjjw-hqmq/GHSA-99jr-pjjw-hqmq.json create mode 100644 advisories/unreviewed/2024/02/GHSA-9fhr-gx36-jrfv/GHSA-9fhr-gx36-jrfv.json create mode 100644 advisories/unreviewed/2024/02/GHSA-c5g4-g3x7-x8rm/GHSA-c5g4-g3x7-x8rm.json create mode 100644 advisories/unreviewed/2024/02/GHSA-c6f2-5665-5p8p/GHSA-c6f2-5665-5p8p.json create mode 100644 advisories/unreviewed/2024/02/GHSA-frmq-mwj6-5m79/GHSA-frmq-mwj6-5m79.json create mode 100644 advisories/unreviewed/2024/02/GHSA-fwwv-x7hh-wmpw/GHSA-fwwv-x7hh-wmpw.json create mode 100644 advisories/unreviewed/2024/02/GHSA-g39j-hgm2-fxmh/GHSA-g39j-hgm2-fxmh.json create mode 100644 advisories/unreviewed/2024/02/GHSA-gvhv-g3h5-f6r7/GHSA-gvhv-g3h5-f6r7.json create mode 100644 advisories/unreviewed/2024/02/GHSA-hxw7-jqv7-6h7r/GHSA-hxw7-jqv7-6h7r.json create mode 100644 advisories/unreviewed/2024/02/GHSA-j428-8h66-82p9/GHSA-j428-8h66-82p9.json create mode 100644 advisories/unreviewed/2024/02/GHSA-j973-rvvm-fh3w/GHSA-j973-rvvm-fh3w.json create mode 100644 advisories/unreviewed/2024/02/GHSA-jpv8-vxhj-7qmf/GHSA-jpv8-vxhj-7qmf.json create mode 100644 advisories/unreviewed/2024/02/GHSA-m6p7-jxxh-vc8c/GHSA-m6p7-jxxh-vc8c.json create mode 100644 advisories/unreviewed/2024/02/GHSA-mf94-378q-xvc3/GHSA-mf94-378q-xvc3.json create mode 100644 advisories/unreviewed/2024/02/GHSA-mfph-26j7-jm24/GHSA-mfph-26j7-jm24.json create mode 100644 advisories/unreviewed/2024/02/GHSA-mmfm-2hr6-jvqr/GHSA-mmfm-2hr6-jvqr.json create mode 100644 advisories/unreviewed/2024/02/GHSA-mvmq-hrr8-p65f/GHSA-mvmq-hrr8-p65f.json create mode 100644 advisories/unreviewed/2024/02/GHSA-p3gm-xxh4-xjmg/GHSA-p3gm-xxh4-xjmg.json create mode 100644 advisories/unreviewed/2024/02/GHSA-p3jh-mv97-74gv/GHSA-p3jh-mv97-74gv.json create mode 100644 advisories/unreviewed/2024/02/GHSA-pc53-x582-24xc/GHSA-pc53-x582-24xc.json create mode 100644 advisories/unreviewed/2024/02/GHSA-pg8c-mxmr-vcqr/GHSA-pg8c-mxmr-vcqr.json create mode 100644 advisories/unreviewed/2024/02/GHSA-pj36-rhxp-gj4x/GHSA-pj36-rhxp-gj4x.json create mode 100644 advisories/unreviewed/2024/02/GHSA-qv88-9x4p-qm78/GHSA-qv88-9x4p-qm78.json create mode 100644 advisories/unreviewed/2024/02/GHSA-r947-98rq-44mh/GHSA-r947-98rq-44mh.json create mode 100644 advisories/unreviewed/2024/02/GHSA-v42h-5rm7-cppg/GHSA-v42h-5rm7-cppg.json create mode 100644 advisories/unreviewed/2024/02/GHSA-vv93-j256-hpwh/GHSA-vv93-j256-hpwh.json create mode 100644 advisories/unreviewed/2024/02/GHSA-x547-pm2q-2cr6/GHSA-x547-pm2q-2cr6.json diff --git a/advisories/github-reviewed/2024/01/GHSA-xr7r-f8xq-vfvv/GHSA-xr7r-f8xq-vfvv.json b/advisories/github-reviewed/2024/01/GHSA-xr7r-f8xq-vfvv/GHSA-xr7r-f8xq-vfvv.json index cd3dbb4c28f..ad45a14c121 100644 --- a/advisories/github-reviewed/2024/01/GHSA-xr7r-f8xq-vfvv/GHSA-xr7r-f8xq-vfvv.json +++ b/advisories/github-reviewed/2024/01/GHSA-xr7r-f8xq-vfvv/GHSA-xr7r-f8xq-vfvv.json @@ -59,6 +59,10 @@ "type": "WEB", "url": "https://github.com/opencontainers/runc/releases/tag/v1.1.12" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SYMO3BANINS6RGFQFKPRG4FIOJ7GWYTL/" + }, { "type": "WEB", "url": "http://packetstormsecurity.com/files/176993/runc-1.1.11-File-Descriptor-Leak-Privilege-Escalation.html" diff --git a/advisories/unreviewed/2022/05/GHSA-pr96-m2pj-3g36/GHSA-pr96-m2pj-3g36.json b/advisories/unreviewed/2022/05/GHSA-pr96-m2pj-3g36/GHSA-pr96-m2pj-3g36.json index 7443c7d2224..5aed6adb2c2 100644 --- a/advisories/unreviewed/2022/05/GHSA-pr96-m2pj-3g36/GHSA-pr96-m2pj-3g36.json +++ b/advisories/unreviewed/2022/05/GHSA-pr96-m2pj-3g36/GHSA-pr96-m2pj-3g36.json @@ -50,6 +50,10 @@ "type": "WEB", "url": "http://www.debian.org/security/2014/dsa-2939" }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/02/05/8" + }, { "type": "WEB", "url": "http://www.securitytracker.com/id/1030270" diff --git a/advisories/unreviewed/2023/12/GHSA-9vh7-c87x-8q9v/GHSA-9vh7-c87x-8q9v.json b/advisories/unreviewed/2023/12/GHSA-9vh7-c87x-8q9v/GHSA-9vh7-c87x-8q9v.json index a90b25f20ae..2b14b0dcb6a 100644 --- a/advisories/unreviewed/2023/12/GHSA-9vh7-c87x-8q9v/GHSA-9vh7-c87x-8q9v.json +++ b/advisories/unreviewed/2023/12/GHSA-9vh7-c87x-8q9v/GHSA-9vh7-c87x-8q9v.json @@ -41,6 +41,10 @@ "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2253986" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7LSPIOMIJYTLZB6QKPQVVAYSUETUWKPF/" + }, { "type": "WEB", "url": "https://lore.kernel.org/netdev/20231211083758.1082853-1-jiri@resnulli.us/" diff --git a/advisories/unreviewed/2024/01/GHSA-3h6x-952r-xr8p/GHSA-3h6x-952r-xr8p.json b/advisories/unreviewed/2024/01/GHSA-3h6x-952r-xr8p/GHSA-3h6x-952r-xr8p.json index 83f5f837626..25fd0ca670b 100644 --- a/advisories/unreviewed/2024/01/GHSA-3h6x-952r-xr8p/GHSA-3h6x-952r-xr8p.json +++ b/advisories/unreviewed/2024/01/GHSA-3h6x-952r-xr8p/GHSA-3h6x-952r-xr8p.json @@ -68,6 +68,10 @@ { "type": "WEB", "url": "http://seclists.org/fulldisclosure/2024/Jan/40" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/02/05/8" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/01/GHSA-63fx-c7fv-hgj5/GHSA-63fx-c7fv-hgj5.json b/advisories/unreviewed/2024/01/GHSA-63fx-c7fv-hgj5/GHSA-63fx-c7fv-hgj5.json index 12a24a2064d..71462cdc49a 100644 --- a/advisories/unreviewed/2024/01/GHSA-63fx-c7fv-hgj5/GHSA-63fx-c7fv-hgj5.json +++ b/advisories/unreviewed/2024/01/GHSA-63fx-c7fv-hgj5/GHSA-63fx-c7fv-hgj5.json @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23849" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7LSPIOMIJYTLZB6QKPQVVAYSUETUWKPF/" + }, { "type": "WEB", "url": "https://lore.kernel.org/netdev/1705715319-19199-1-git-send-email-sharath.srinivasan%40oracle.com/" diff --git a/advisories/unreviewed/2024/01/GHSA-73m5-j333-fcwc/GHSA-73m5-j333-fcwc.json b/advisories/unreviewed/2024/01/GHSA-73m5-j333-fcwc/GHSA-73m5-j333-fcwc.json index 3ae24684f38..0a976ca99cc 100644 --- a/advisories/unreviewed/2024/01/GHSA-73m5-j333-fcwc/GHSA-73m5-j333-fcwc.json +++ b/advisories/unreviewed/2024/01/GHSA-73m5-j333-fcwc/GHSA-73m5-j333-fcwc.json @@ -68,6 +68,10 @@ { "type": "WEB", "url": "http://seclists.org/fulldisclosure/2024/Jan/40" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/02/05/8" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/01/GHSA-93px-8x98-j7p2/GHSA-93px-8x98-j7p2.json b/advisories/unreviewed/2024/01/GHSA-93px-8x98-j7p2/GHSA-93px-8x98-j7p2.json index bb0819bded0..9cb419140ea 100644 --- a/advisories/unreviewed/2024/01/GHSA-93px-8x98-j7p2/GHSA-93px-8x98-j7p2.json +++ b/advisories/unreviewed/2024/01/GHSA-93px-8x98-j7p2/GHSA-93px-8x98-j7p2.json @@ -80,6 +80,10 @@ { "type": "WEB", "url": "http://seclists.org/fulldisclosure/2024/Jan/40" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/02/05/8" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/01/GHSA-gfh2-2mj9-m2cx/GHSA-gfh2-2mj9-m2cx.json b/advisories/unreviewed/2024/01/GHSA-gfh2-2mj9-m2cx/GHSA-gfh2-2mj9-m2cx.json index 2f10f77c7ef..8c40d7d9d1c 100644 --- a/advisories/unreviewed/2024/01/GHSA-gfh2-2mj9-m2cx/GHSA-gfh2-2mj9-m2cx.json +++ b/advisories/unreviewed/2024/01/GHSA-gfh2-2mj9-m2cx/GHSA-gfh2-2mj9-m2cx.json @@ -28,6 +28,10 @@ { "type": "WEB", "url": "https://kernel.dance/f342de4e2f33e0e39165d8639387aa6c19dff660" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7LSPIOMIJYTLZB6QKPQVVAYSUETUWKPF/" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/01/GHSA-q6j4-xjv3-96rj/GHSA-q6j4-xjv3-96rj.json b/advisories/unreviewed/2024/01/GHSA-q6j4-xjv3-96rj/GHSA-q6j4-xjv3-96rj.json index baf0c0824d6..89bea21f2b8 100644 --- a/advisories/unreviewed/2024/01/GHSA-q6j4-xjv3-96rj/GHSA-q6j4-xjv3-96rj.json +++ b/advisories/unreviewed/2024/01/GHSA-q6j4-xjv3-96rj/GHSA-q6j4-xjv3-96rj.json @@ -32,6 +32,10 @@ { "type": "WEB", "url": "https://support.apple.com/en-us/HT213941" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/02/05/8" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/01/GHSA-rvwq-r5pc-g3h9/GHSA-rvwq-r5pc-g3h9.json b/advisories/unreviewed/2024/01/GHSA-rvwq-r5pc-g3h9/GHSA-rvwq-r5pc-g3h9.json index 0709db767bf..016c78f1732 100644 --- a/advisories/unreviewed/2024/01/GHSA-rvwq-r5pc-g3h9/GHSA-rvwq-r5pc-g3h9.json +++ b/advisories/unreviewed/2024/01/GHSA-rvwq-r5pc-g3h9/GHSA-rvwq-r5pc-g3h9.json @@ -40,6 +40,10 @@ { "type": "WEB", "url": "https://support.apple.com/en-us/HT213941" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/02/05/8" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/02/GHSA-293v-32vx-9g86/GHSA-293v-32vx-9g86.json b/advisories/unreviewed/2024/02/GHSA-293v-32vx-9g86/GHSA-293v-32vx-9g86.json new file mode 100644 index 00000000000..6b93f92cda8 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-293v-32vx-9g86/GHSA-293v-32vx-9g86.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-293v-32vx-9g86", + "modified": "2024-02-06T03:33:00Z", + "published": "2024-02-06T03:33:00Z", + "aliases": [ + "CVE-2024-22852" + ], + "details": "D-Link Go-RT-AC750 GORTAC750_A1_FW_v101b03 contains a stack-based buffer overflow via the function genacgi_main. This vulnerability allows attackers to enable telnet service via a specially crafted payload.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22852" + }, + { + "type": "WEB", + "url": "https://github.com/Beckaf/vunl/blob/main/D-Link/AC750/1/1.md" + }, + { + "type": "WEB", + "url": "https://www.dlink.com/en/security-bulletin/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T02:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-3298-46rv-mjjj/GHSA-3298-46rv-mjjj.json b/advisories/unreviewed/2024/02/GHSA-3298-46rv-mjjj/GHSA-3298-46rv-mjjj.json index a12d4ca554b..496dce5020c 100644 --- a/advisories/unreviewed/2024/02/GHSA-3298-46rv-mjjj/GHSA-3298-46rv-mjjj.json +++ b/advisories/unreviewed/2024/02/GHSA-3298-46rv-mjjj/GHSA-3298-46rv-mjjj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3298-46rv-mjjj", - "modified": "2024-02-01T12:30:23Z", + "modified": "2024-02-06T03:32:59Z", "published": "2024-02-01T12:30:23Z", "aliases": [ "CVE-2023-51509" diff --git a/advisories/unreviewed/2024/02/GHSA-4gv8-ph4v-rwjm/GHSA-4gv8-ph4v-rwjm.json b/advisories/unreviewed/2024/02/GHSA-4gv8-ph4v-rwjm/GHSA-4gv8-ph4v-rwjm.json new file mode 100644 index 00000000000..7fa7ba69031 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-4gv8-ph4v-rwjm/GHSA-4gv8-ph4v-rwjm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4gv8-ph4v-rwjm", + "modified": "2024-02-06T03:33:00Z", + "published": "2024-02-06T03:33:00Z", + "aliases": [ + "CVE-2024-20813" + ], + "details": "Out-of-bounds Write in padmd_vld_qtbl of libpadm.so prior to SMR Feb-2024 Release 1 allows local attacker to execute arbitrary code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20813" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=02" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T03:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-66qc-rgfw-8hq2/GHSA-66qc-rgfw-8hq2.json b/advisories/unreviewed/2024/02/GHSA-66qc-rgfw-8hq2/GHSA-66qc-rgfw-8hq2.json index 02a98c67770..41d0a065e1f 100644 --- a/advisories/unreviewed/2024/02/GHSA-66qc-rgfw-8hq2/GHSA-66qc-rgfw-8hq2.json +++ b/advisories/unreviewed/2024/02/GHSA-66qc-rgfw-8hq2/GHSA-66qc-rgfw-8hq2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-66qc-rgfw-8hq2", - "modified": "2024-02-01T12:30:23Z", + "modified": "2024-02-06T03:32:59Z", "published": "2024-02-01T12:30:23Z", "aliases": [ "CVE-2023-51691" diff --git a/advisories/unreviewed/2024/02/GHSA-68r4-mq9j-2rrq/GHSA-68r4-mq9j-2rrq.json b/advisories/unreviewed/2024/02/GHSA-68r4-mq9j-2rrq/GHSA-68r4-mq9j-2rrq.json new file mode 100644 index 00000000000..d4d40187b80 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-68r4-mq9j-2rrq/GHSA-68r4-mq9j-2rrq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-68r4-mq9j-2rrq", + "modified": "2024-02-06T03:33:00Z", + "published": "2024-02-06T03:33:00Z", + "aliases": [ + "CVE-2024-20810" + ], + "details": "Implicit intent hijacking vulnerability in Smart Suggestions prior to SMR Feb-2024 Release 1 allows attackers to get sensitive information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20810" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=02" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T03:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-694p-hcfm-p8q8/GHSA-694p-hcfm-p8q8.json b/advisories/unreviewed/2024/02/GHSA-694p-hcfm-p8q8/GHSA-694p-hcfm-p8q8.json new file mode 100644 index 00000000000..e8eb2743fc8 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-694p-hcfm-p8q8/GHSA-694p-hcfm-p8q8.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-694p-hcfm-p8q8", + "modified": "2024-02-06T03:33:00Z", + "published": "2024-02-06T03:33:00Z", + "aliases": [ + "CVE-2023-6230" + ], + "details": "Buffer overflow in the Address Book password process in authentication of Mobile Device Function of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*: Satera LBP670C Series/Satera MF750C Series firmware v03.07 and earlier sold in Japan. Color imageCLASS LBP674C/Color imageCLASS X LBP1333C/Color imageCLASS MF750C Series/Color imageCLASS X MF1333C Series firmware v03.07 and earlier sold in US. i-SENSYS LBP673Cdw/C1333P/i-SENSYS MF750C Series/C1333i Series firmware v03.07 and earlier sold in Europe.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6230" + }, + { + "type": "WEB", + "url": "https://canon.jp/support/support-info/240205vulnerability-response" + }, + { + "type": "WEB", + "url": "https://psirt.canon/advisory-information/cp2024-001/" + }, + { + "type": "WEB", + "url": "https://www.canon-europe.com/support/product-security-latest-news/" + }, + { + "type": "WEB", + "url": "https://www.usa.canon.com/support/canon-product-advisories/Service-Notice-Regarding-Vulnerability-Measure-Against-Buffer-Overflow-for-Laser-Printers-and-Small-Office-Multifunctional-Printers" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T01:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-8vw5-wvh5-q977/GHSA-8vw5-wvh5-q977.json b/advisories/unreviewed/2024/02/GHSA-8vw5-wvh5-q977/GHSA-8vw5-wvh5-q977.json new file mode 100644 index 00000000000..49fcd355750 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-8vw5-wvh5-q977/GHSA-8vw5-wvh5-q977.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8vw5-wvh5-q977", + "modified": "2024-02-06T03:33:00Z", + "published": "2024-02-06T03:33:00Z", + "aliases": [ + "CVE-2024-20827" + ], + "details": "Improper access control vulnerability in Samsung Gallery prior to version 14.5.04.4 allows physical attackers to access the picture using physical keyboard on the lockscreen.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20827" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=02" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T03:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-8xpr-jq7w-573j/GHSA-8xpr-jq7w-573j.json b/advisories/unreviewed/2024/02/GHSA-8xpr-jq7w-573j/GHSA-8xpr-jq7w-573j.json new file mode 100644 index 00000000000..d1d140ee9d0 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-8xpr-jq7w-573j/GHSA-8xpr-jq7w-573j.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8xpr-jq7w-573j", + "modified": "2024-02-06T03:33:00Z", + "published": "2024-02-06T03:33:00Z", + "aliases": [ + "CVE-2023-6234" + ], + "details": "Buffer overflow in CPCA Color LUT Resource Download process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*: Satera LBP670C Series/Satera MF750C Series firmware v03.07 and earlier sold in Japan. Color imageCLASS LBP674C/Color imageCLASS X LBP1333C/Color imageCLASS MF750C Series/Color imageCLASS X MF1333C Series firmware v03.07 and earlier sold in US. i-SENSYS LBP673Cdw/C1333P/i-SENSYS MF750C Series/C1333i Series firmware v03.07 and earlier sold in Europe.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6234" + }, + { + "type": "WEB", + "url": "https://canon.jp/support/support-info/240205vulnerability-response" + }, + { + "type": "WEB", + "url": "https://psirt.canon/advisory-information/cp2024-001/" + }, + { + "type": "WEB", + "url": "https://www.canon-europe.com/support/product-security-latest-news/" + }, + { + "type": "WEB", + "url": "https://www.usa.canon.com/support/canon-product-advisories/Service-Notice-Regarding-Vulnerability-Measure-Against-Buffer-Overflow-for-Laser-Printers-and-Small-Office-Multifunctional-Printers" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T01:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-94f4-228x-55q7/GHSA-94f4-228x-55q7.json b/advisories/unreviewed/2024/02/GHSA-94f4-228x-55q7/GHSA-94f4-228x-55q7.json new file mode 100644 index 00000000000..6ec4f74de34 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-94f4-228x-55q7/GHSA-94f4-228x-55q7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-94f4-228x-55q7", + "modified": "2024-02-06T03:33:00Z", + "published": "2024-02-06T03:33:00Z", + "aliases": [ + "CVE-2024-20817" + ], + "details": "Out out bounds Write vulnerabilities in svc1td_vld_slh of libsthmbc.so prior to SMR Feb-2024 Release 1 allows local attackers to trigger buffer overflow.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20817" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=02" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T03:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-99jr-pjjw-hqmq/GHSA-99jr-pjjw-hqmq.json b/advisories/unreviewed/2024/02/GHSA-99jr-pjjw-hqmq/GHSA-99jr-pjjw-hqmq.json new file mode 100644 index 00000000000..a57f4cd8dff --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-99jr-pjjw-hqmq/GHSA-99jr-pjjw-hqmq.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-99jr-pjjw-hqmq", + "modified": "2024-02-06T03:33:00Z", + "published": "2024-02-06T03:33:00Z", + "aliases": [ + "CVE-2023-6233" + ], + "details": "Buffer overflow in SLP attribute request process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*: Satera LBP670C Series/Satera MF750C Series firmware v03.07 and earlier sold in Japan. Color imageCLASS LBP674C/Color imageCLASS X LBP1333C/Color imageCLASS MF750C Series/Color imageCLASS X MF1333C Series firmware v03.07 and earlier sold in US. i-SENSYS LBP673Cdw/C1333P/i-SENSYS MF750C Series/C1333i Series firmware v03.07 and earlier sold in Europe.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6233" + }, + { + "type": "WEB", + "url": "https://canon.jp/support/support-info/240205vulnerability-response" + }, + { + "type": "WEB", + "url": "https://psirt.canon/advisory-information/cp2024-001/" + }, + { + "type": "WEB", + "url": "https://www.canon-europe.com/support/product-security-latest-news/" + }, + { + "type": "WEB", + "url": "https://www.usa.canon.com/support/canon-product-advisories/Service-Notice-Regarding-Vulnerability-Measure-Against-Buffer-Overflow-for-Laser-Printers-and-Small-Office-Multifunctional-Printers" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T01:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-9fhr-gx36-jrfv/GHSA-9fhr-gx36-jrfv.json b/advisories/unreviewed/2024/02/GHSA-9fhr-gx36-jrfv/GHSA-9fhr-gx36-jrfv.json new file mode 100644 index 00000000000..dd2913df0cc --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-9fhr-gx36-jrfv/GHSA-9fhr-gx36-jrfv.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9fhr-gx36-jrfv", + "modified": "2024-02-06T03:33:00Z", + "published": "2024-02-06T03:33:00Z", + "aliases": [ + "CVE-2024-22853" + ], + "details": "D-LINK Go-RT-AC750 GORTAC750_A1_FW_v101b03 has a hardcoded password for the Alphanetworks account, which allows remote attackers to obtain root access via a telnet session.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22853" + }, + { + "type": "WEB", + "url": "https://github.com/Beckaf/vunl/blob/main/D-Link/AC750/2/2.md" + }, + { + "type": "WEB", + "url": "https://www.dlink.com/en/security-bulletin/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T02:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-c5g4-g3x7-x8rm/GHSA-c5g4-g3x7-x8rm.json b/advisories/unreviewed/2024/02/GHSA-c5g4-g3x7-x8rm/GHSA-c5g4-g3x7-x8rm.json new file mode 100644 index 00000000000..bdc012d81a9 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-c5g4-g3x7-x8rm/GHSA-c5g4-g3x7-x8rm.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c5g4-g3x7-x8rm", + "modified": "2024-02-06T03:32:59Z", + "published": "2024-02-06T03:32:59Z", + "aliases": [ + "CVE-2023-47353" + ], + "details": "An issue in the com.oneed.dvr.service.DownloadFirmwareService component of IMOU GO v1.0.11 allows attackers to force the download of arbitrary files.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47353" + }, + { + "type": "WEB", + "url": "https://github.com/actuator/imou/blob/main/com.dahua.imou.go-V1.0.11.md" + }, + { + "type": "WEB", + "url": "https://play.google.com/store/apps/details?id=com.dahua.imou.go" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T01:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-c6f2-5665-5p8p/GHSA-c6f2-5665-5p8p.json b/advisories/unreviewed/2024/02/GHSA-c6f2-5665-5p8p/GHSA-c6f2-5665-5p8p.json new file mode 100644 index 00000000000..274f6e20111 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-c6f2-5665-5p8p/GHSA-c6f2-5665-5p8p.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c6f2-5665-5p8p", + "modified": "2024-02-06T03:33:00Z", + "published": "2024-02-06T03:33:00Z", + "aliases": [ + "CVE-2024-22773" + ], + "details": "Intelbras Roteador ACtion RF 1200 1.2.2 esposes the Password in Cookie resulting in Login Bypass.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22773" + }, + { + "type": "WEB", + "url": "https://medium.com/%40wagneralves_87750/poc-cve-2024-22773-febf0d3a5433" + }, + { + "type": "WEB", + "url": "https://www.youtube.com/watch?v=-r0TWJq55DU&t=7s" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T01:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-frmq-mwj6-5m79/GHSA-frmq-mwj6-5m79.json b/advisories/unreviewed/2024/02/GHSA-frmq-mwj6-5m79/GHSA-frmq-mwj6-5m79.json new file mode 100644 index 00000000000..42db4dd61b4 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-frmq-mwj6-5m79/GHSA-frmq-mwj6-5m79.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-frmq-mwj6-5m79", + "modified": "2024-02-06T03:33:00Z", + "published": "2024-02-06T03:33:00Z", + "aliases": [ + "CVE-2024-20816" + ], + "details": "Improper authentication vulnerability in onCharacteristicWriteRequest in Auto Hotspot prior to SMR Feb-2024 Release 1 allows adjacent attackers connect to victim's mobile hotspot without user awareness.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20816" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=02" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T03:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-fwwv-x7hh-wmpw/GHSA-fwwv-x7hh-wmpw.json b/advisories/unreviewed/2024/02/GHSA-fwwv-x7hh-wmpw/GHSA-fwwv-x7hh-wmpw.json new file mode 100644 index 00000000000..e494fcdd01d --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-fwwv-x7hh-wmpw/GHSA-fwwv-x7hh-wmpw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fwwv-x7hh-wmpw", + "modified": "2024-02-06T03:33:00Z", + "published": "2024-02-06T03:33:00Z", + "aliases": [ + "CVE-2024-20825" + ], + "details": "Implicit intent hijacking vulnerability in IAP of Galaxy Store prior to version 4.5.63.6 allows local attackers to access sensitive information via implicit intent.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20825" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=02" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T03:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-g39j-hgm2-fxmh/GHSA-g39j-hgm2-fxmh.json b/advisories/unreviewed/2024/02/GHSA-g39j-hgm2-fxmh/GHSA-g39j-hgm2-fxmh.json new file mode 100644 index 00000000000..0ebdf4642eb --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-g39j-hgm2-fxmh/GHSA-g39j-hgm2-fxmh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g39j-hgm2-fxmh", + "modified": "2024-02-06T03:33:00Z", + "published": "2024-02-06T03:33:00Z", + "aliases": [ + "CVE-2024-20822" + ], + "details": "Implicit intent hijacking vulnerability in AccountActivity of Galaxy Store prior to version 4.5.63.6 allows local attackers to access sensitive information via implicit intent.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20822" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=02" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T03:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-gvhv-g3h5-f6r7/GHSA-gvhv-g3h5-f6r7.json b/advisories/unreviewed/2024/02/GHSA-gvhv-g3h5-f6r7/GHSA-gvhv-g3h5-f6r7.json new file mode 100644 index 00000000000..d34d7ecb139 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-gvhv-g3h5-f6r7/GHSA-gvhv-g3h5-f6r7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gvhv-g3h5-f6r7", + "modified": "2024-02-06T03:33:00Z", + "published": "2024-02-06T03:33:00Z", + "aliases": [ + "CVE-2024-20823" + ], + "details": "Implicit intent hijacking vulnerability in SamsungAccount of Galaxy Store prior to version 4.5.63.6 allows local attackers to access sensitive information via implicit intent.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20823" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=02" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T03:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-hxw7-jqv7-6h7r/GHSA-hxw7-jqv7-6h7r.json b/advisories/unreviewed/2024/02/GHSA-hxw7-jqv7-6h7r/GHSA-hxw7-jqv7-6h7r.json new file mode 100644 index 00000000000..d38942305d5 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-hxw7-jqv7-6h7r/GHSA-hxw7-jqv7-6h7r.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hxw7-jqv7-6h7r", + "modified": "2024-02-06T03:32:59Z", + "published": "2024-02-06T03:32:59Z", + "aliases": [ + "CVE-2023-47889" + ], + "details": "The Android application BINHDRM26 com.bdrm.superreboot 1.0.3, exposes several critical actions through its exported broadcast receivers. These exposed actions can allow any app on the device to send unauthorized broadcasts, leading to unintended consequences. The vulnerability is particularly concerning because these actions include powering off, system reboot & entering recovery mode.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47889" + }, + { + "type": "WEB", + "url": "https://github.com/actuator/com.bdrm.superreboot/blob/main/CWE-925.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T01:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-j428-8h66-82p9/GHSA-j428-8h66-82p9.json b/advisories/unreviewed/2024/02/GHSA-j428-8h66-82p9/GHSA-j428-8h66-82p9.json new file mode 100644 index 00000000000..6a95ddb4efb --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-j428-8h66-82p9/GHSA-j428-8h66-82p9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j428-8h66-82p9", + "modified": "2024-02-06T03:33:00Z", + "published": "2024-02-06T03:33:00Z", + "aliases": [ + "CVE-2024-20818" + ], + "details": "Out out bounds Write vulnerabilities in svc1td_vld_elh of libsthmbc.so prior to SMR Feb-2024 Release 1 allows local attackers to trigger buffer overflow.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20818" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=02" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T03:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-j973-rvvm-fh3w/GHSA-j973-rvvm-fh3w.json b/advisories/unreviewed/2024/02/GHSA-j973-rvvm-fh3w/GHSA-j973-rvvm-fh3w.json new file mode 100644 index 00000000000..24a93ebd72e --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-j973-rvvm-fh3w/GHSA-j973-rvvm-fh3w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j973-rvvm-fh3w", + "modified": "2024-02-06T03:33:00Z", + "published": "2024-02-06T03:33:00Z", + "aliases": [ + "CVE-2024-20826" + ], + "details": "Implicit intent hijacking vulnerability in UPHelper library prior to version 4.0.0 allows local attackers to access sensitive information via implicit intent.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20826" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=02" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T03:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-jpv8-vxhj-7qmf/GHSA-jpv8-vxhj-7qmf.json b/advisories/unreviewed/2024/02/GHSA-jpv8-vxhj-7qmf/GHSA-jpv8-vxhj-7qmf.json new file mode 100644 index 00000000000..725e2969b57 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-jpv8-vxhj-7qmf/GHSA-jpv8-vxhj-7qmf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jpv8-vxhj-7qmf", + "modified": "2024-02-06T03:33:00Z", + "published": "2024-02-06T03:33:00Z", + "aliases": [ + "CVE-2024-20819" + ], + "details": "Out out bounds Write vulnerabilities in svc1td_vld_plh_ap of libsthmbc.so prior to SMR Feb-2024 Release 1 allows local attackers to trigger buffer overflow.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20819" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=02" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T03:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-m6p7-jxxh-vc8c/GHSA-m6p7-jxxh-vc8c.json b/advisories/unreviewed/2024/02/GHSA-m6p7-jxxh-vc8c/GHSA-m6p7-jxxh-vc8c.json new file mode 100644 index 00000000000..01431c7dad8 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-m6p7-jxxh-vc8c/GHSA-m6p7-jxxh-vc8c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m6p7-jxxh-vc8c", + "modified": "2024-02-06T03:33:00Z", + "published": "2024-02-06T03:33:00Z", + "aliases": [ + "CVE-2024-20812" + ], + "details": "Out-of-bounds Write in padmd_vld_htbl of libpadm.so prior to SMR Feb-2024 Release 1 allows local attacker to execute arbitrary code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20812" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=02" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T03:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-mf94-378q-xvc3/GHSA-mf94-378q-xvc3.json b/advisories/unreviewed/2024/02/GHSA-mf94-378q-xvc3/GHSA-mf94-378q-xvc3.json new file mode 100644 index 00000000000..8dde54626b6 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-mf94-378q-xvc3/GHSA-mf94-378q-xvc3.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mf94-378q-xvc3", + "modified": "2024-02-06T03:32:59Z", + "published": "2024-02-06T03:32:59Z", + "aliases": [ + "CVE-2023-47022" + ], + "details": "An issue in NCR Terminal Handler v.1.5.1 allows a remote attacker to execute arbitrary code via a crafted script to the payload parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47022" + }, + { + "type": "WEB", + "url": "https://docs.google.com/document/d/15s7NftTX2dxfcFnMqkFIyeN48xq3LceesWOhP-9xL4Y/edit?usp=sharing" + }, + { + "type": "WEB", + "url": "https://github.com/Patrick0x41/Security-Advisories/tree/main/CVE-2023-47022" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T01:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-mfph-26j7-jm24/GHSA-mfph-26j7-jm24.json b/advisories/unreviewed/2024/02/GHSA-mfph-26j7-jm24/GHSA-mfph-26j7-jm24.json new file mode 100644 index 00000000000..66be65c1d5f --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-mfph-26j7-jm24/GHSA-mfph-26j7-jm24.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mfph-26j7-jm24", + "modified": "2024-02-06T03:33:00Z", + "published": "2024-02-06T03:33:00Z", + "aliases": [ + "CVE-2024-0244" + ], + "details": "Buffer overflow in CPCA PCFAX number process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*:Satera MF750C Series firmware v03.07 and earlier sold in Japan. Color imageCLASS MF750C Series/Color imageCLASS X MF1333C firmware v03.07 and earlier sold in US. i-SENSYS MF754Cdw/C1333iF firmware v03.07 and earlier sold in Europe.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0244" + }, + { + "type": "WEB", + "url": "https://canon.jp/support/support-info/240205vulnerability-response" + }, + { + "type": "WEB", + "url": "https://psirt.canon/advisory-information/cp2024-001/" + }, + { + "type": "WEB", + "url": "https://www.canon-europe.com/support/product-security-latest-news/" + }, + { + "type": "WEB", + "url": "https://www.usa.canon.com/support/canon-product-advisories/Service-Notice-Regarding-Vulnerability-Measure-Against-Buffer-Overflow-for-Laser-Printers-and-Small-Office-Multifunctional-Printers" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T01:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-mmfm-2hr6-jvqr/GHSA-mmfm-2hr6-jvqr.json b/advisories/unreviewed/2024/02/GHSA-mmfm-2hr6-jvqr/GHSA-mmfm-2hr6-jvqr.json new file mode 100644 index 00000000000..3a087d39dd7 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-mmfm-2hr6-jvqr/GHSA-mmfm-2hr6-jvqr.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mmfm-2hr6-jvqr", + "modified": "2024-02-06T03:33:00Z", + "published": "2024-02-06T03:33:00Z", + "aliases": [ + "CVE-2023-6229" + ], + "details": "Buffer overflow in CPCA PDL Resource Download process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*: Satera LBP670C Series/Satera MF750C Series firmware v03.07 and earlier sold in Japan. Color imageCLASS LBP674C/Color imageCLASS X LBP1333C/Color imageCLASS MF750C Series/Color imageCLASS X MF1333C Series firmware v03.07 and earlier sold in US. i-SENSYS LBP673Cdw/C1333P/i-SENSYS MF750C Series/C1333i Series firmware v03.07 and earlier sold in Europe.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6229" + }, + { + "type": "WEB", + "url": "https://canon.jp/support/support-info/240205vulnerability-response" + }, + { + "type": "WEB", + "url": "https://psirt.canon/advisory-information/cp2024-001/" + }, + { + "type": "WEB", + "url": "https://www.canon-europe.com/support/product-security-latest-news/" + }, + { + "type": "WEB", + "url": "https://www.usa.canon.com/support/canon-product-advisories/Service-Notice-Regarding-Vulnerability-Measure-Against-Buffer-Overflow-for-Laser-Printers-and-Small-Office-Multifunctional-Printers" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T01:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-mvmq-hrr8-p65f/GHSA-mvmq-hrr8-p65f.json b/advisories/unreviewed/2024/02/GHSA-mvmq-hrr8-p65f/GHSA-mvmq-hrr8-p65f.json new file mode 100644 index 00000000000..6bdf8b53564 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-mvmq-hrr8-p65f/GHSA-mvmq-hrr8-p65f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mvmq-hrr8-p65f", + "modified": "2024-02-06T03:33:00Z", + "published": "2024-02-06T03:33:00Z", + "aliases": [ + "CVE-2024-20815" + ], + "details": "Improper authentication vulnerability in onCharacteristicReadRequest in Auto Hotspot prior to SMR Feb-2024 Release 1 allows adjacent attackers connect to victim's mobile hotspot without user awareness.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20815" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=02" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T03:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-p3gm-xxh4-xjmg/GHSA-p3gm-xxh4-xjmg.json b/advisories/unreviewed/2024/02/GHSA-p3gm-xxh4-xjmg/GHSA-p3gm-xxh4-xjmg.json new file mode 100644 index 00000000000..bab7f665d43 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-p3gm-xxh4-xjmg/GHSA-p3gm-xxh4-xjmg.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p3gm-xxh4-xjmg", + "modified": "2024-02-06T03:32:59Z", + "published": "2024-02-06T03:32:59Z", + "aliases": [ + "CVE-2023-46359" + ], + "details": "An OS command injection vulnerability in Hardy Barth cPH2 eCharge Ladestation v1.87.0 and earlier, may allow an unauthenticated remote attacker to execute arbitrary commands on the system via a specifically crafted arguments passed to the connectivity check feature.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46359" + }, + { + "type": "WEB", + "url": "https://www.offensity.com/en/blog/os-command-injection-in-cph2-charging-station-200-cve-2023-46359-and-cve-2023-46360/" + }, + { + "type": "WEB", + "url": "http://hardy.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T01:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-p3jh-mv97-74gv/GHSA-p3jh-mv97-74gv.json b/advisories/unreviewed/2024/02/GHSA-p3jh-mv97-74gv/GHSA-p3jh-mv97-74gv.json new file mode 100644 index 00000000000..cf9686c75fe --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-p3jh-mv97-74gv/GHSA-p3jh-mv97-74gv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p3jh-mv97-74gv", + "modified": "2024-02-06T03:33:00Z", + "published": "2024-02-06T03:33:00Z", + "aliases": [ + "CVE-2024-20814" + ], + "details": "Out-of-bounds Read in padmd_vld_ac_prog_refine of libpadm.so prior to SMR Feb-2024 Release 1 allows attacker access unauthorized information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20814" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=02" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T03:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-pc53-x582-24xc/GHSA-pc53-x582-24xc.json b/advisories/unreviewed/2024/02/GHSA-pc53-x582-24xc/GHSA-pc53-x582-24xc.json new file mode 100644 index 00000000000..43c0d3e984e --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-pc53-x582-24xc/GHSA-pc53-x582-24xc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pc53-x582-24xc", + "modified": "2024-02-06T03:33:00Z", + "published": "2024-02-06T03:33:00Z", + "aliases": [ + "CVE-2024-20820" + ], + "details": "Improper input validation in bootloader prior to SMR Feb-2024 Release 1 allows attacker to cause an Out-Of-Bounds read.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20820" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=02" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T03:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-pg8c-mxmr-vcqr/GHSA-pg8c-mxmr-vcqr.json b/advisories/unreviewed/2024/02/GHSA-pg8c-mxmr-vcqr/GHSA-pg8c-mxmr-vcqr.json new file mode 100644 index 00000000000..74364daf57c --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-pg8c-mxmr-vcqr/GHSA-pg8c-mxmr-vcqr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pg8c-mxmr-vcqr", + "modified": "2024-02-06T03:33:00Z", + "published": "2024-02-06T03:33:00Z", + "aliases": [ + "CVE-2024-20828" + ], + "details": "Improper authorization verification vulnerability in Samsung Internet prior to version 24.0 allows physical attackers to access files downloaded in SecretMode without proper authentication.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20828" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=02" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T03:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-pj36-rhxp-gj4x/GHSA-pj36-rhxp-gj4x.json b/advisories/unreviewed/2024/02/GHSA-pj36-rhxp-gj4x/GHSA-pj36-rhxp-gj4x.json new file mode 100644 index 00000000000..d95452441e5 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-pj36-rhxp-gj4x/GHSA-pj36-rhxp-gj4x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pj36-rhxp-gj4x", + "modified": "2024-02-06T03:33:00Z", + "published": "2024-02-06T03:33:00Z", + "aliases": [ + "CVE-2024-20811" + ], + "details": "Improper caller verification in GameOptimizer prior to SMR Feb-2024 Release 1 allows local attackers to configure GameOptimizer.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20811" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=02" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T03:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-qv88-9x4p-qm78/GHSA-qv88-9x4p-qm78.json b/advisories/unreviewed/2024/02/GHSA-qv88-9x4p-qm78/GHSA-qv88-9x4p-qm78.json new file mode 100644 index 00000000000..6323fd1a4c8 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-qv88-9x4p-qm78/GHSA-qv88-9x4p-qm78.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qv88-9x4p-qm78", + "modified": "2024-02-06T03:33:00Z", + "published": "2024-02-06T03:33:00Z", + "aliases": [ + "CVE-2024-24112" + ], + "details": "xmall v1.1 was discovered to contain a SQL injection vulnerability via the orderDir parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24112" + }, + { + "type": "WEB", + "url": "https://github.com/Exrick/xmall/issues/78" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T01:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-r92x-24fv-xvcc/GHSA-r92x-24fv-xvcc.json b/advisories/unreviewed/2024/02/GHSA-r92x-24fv-xvcc/GHSA-r92x-24fv-xvcc.json index 827984b068b..5b855b99fee 100644 --- a/advisories/unreviewed/2024/02/GHSA-r92x-24fv-xvcc/GHSA-r92x-24fv-xvcc.json +++ b/advisories/unreviewed/2024/02/GHSA-r92x-24fv-xvcc/GHSA-r92x-24fv-xvcc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r92x-24fv-xvcc", - "modified": "2024-02-01T12:30:23Z", + "modified": "2024-02-06T03:32:59Z", "published": "2024-02-01T12:30:23Z", "aliases": [ "CVE-2023-51506" diff --git a/advisories/unreviewed/2024/02/GHSA-r947-98rq-44mh/GHSA-r947-98rq-44mh.json b/advisories/unreviewed/2024/02/GHSA-r947-98rq-44mh/GHSA-r947-98rq-44mh.json new file mode 100644 index 00000000000..512abd987a0 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-r947-98rq-44mh/GHSA-r947-98rq-44mh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r947-98rq-44mh", + "modified": "2024-02-06T03:33:00Z", + "published": "2024-02-06T03:33:00Z", + "aliases": [ + "CVE-2024-20824" + ], + "details": "Implicit intent hijacking vulnerability in VoiceSearch of Galaxy Store prior to version 4.5.63.6 allows local attackers to access sensitive information via implicit intent.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20824" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=02" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T03:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-v3x4-p7hr-w52x/GHSA-v3x4-p7hr-w52x.json b/advisories/unreviewed/2024/02/GHSA-v3x4-p7hr-w52x/GHSA-v3x4-p7hr-w52x.json index d81137bb7fc..97ea864ba84 100644 --- a/advisories/unreviewed/2024/02/GHSA-v3x4-p7hr-w52x/GHSA-v3x4-p7hr-w52x.json +++ b/advisories/unreviewed/2024/02/GHSA-v3x4-p7hr-w52x/GHSA-v3x4-p7hr-w52x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v3x4-p7hr-w52x", - "modified": "2024-02-01T12:30:23Z", + "modified": "2024-02-06T03:32:58Z", "published": "2024-02-01T12:30:23Z", "aliases": [ "CVE-2023-51684" diff --git a/advisories/unreviewed/2024/02/GHSA-v42h-5rm7-cppg/GHSA-v42h-5rm7-cppg.json b/advisories/unreviewed/2024/02/GHSA-v42h-5rm7-cppg/GHSA-v42h-5rm7-cppg.json new file mode 100644 index 00000000000..015397e1fbb --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-v42h-5rm7-cppg/GHSA-v42h-5rm7-cppg.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v42h-5rm7-cppg", + "modified": "2024-02-06T03:33:00Z", + "published": "2024-02-06T03:33:00Z", + "aliases": [ + "CVE-2023-6231" + ], + "details": "Buffer overflow in WSD probe request process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*: Satera LBP670C Series/Satera MF750C Series firmware v03.07 and earlier sold in Japan. Color imageCLASS LBP674C/Color imageCLASS X LBP1333C/Color imageCLASS MF750C Series/Color imageCLASS X MF1333C Series firmware v03.07 and earlier sold in US. i-SENSYS LBP673Cdw/C1333P/i-SENSYS MF750C Series/C1333i Series firmware v03.07 and earlier sold in Europe.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6231" + }, + { + "type": "WEB", + "url": "https://canon.jp/support/support-info/240205vulnerability-response" + }, + { + "type": "WEB", + "url": "https://psirt.canon/advisory-information/cp2024-001/" + }, + { + "type": "WEB", + "url": "https://www.canon-europe.com/support/product-security-latest-news/" + }, + { + "type": "WEB", + "url": "https://www.usa.canon.com/support/canon-product-advisories/Service-Notice-Regarding-Vulnerability-Measure-Against-Buffer-Overflow-for-Laser-Printers-and-Small-Office-Multifunctional-Printers" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T01:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-vv93-j256-hpwh/GHSA-vv93-j256-hpwh.json b/advisories/unreviewed/2024/02/GHSA-vv93-j256-hpwh/GHSA-vv93-j256-hpwh.json new file mode 100644 index 00000000000..efd983fd94f --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-vv93-j256-hpwh/GHSA-vv93-j256-hpwh.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vv93-j256-hpwh", + "modified": "2024-02-06T03:33:00Z", + "published": "2024-02-06T03:33:00Z", + "aliases": [ + "CVE-2023-6232" + ], + "details": "Buffer overflow in the Address Book username process in authentication of Mobile Device Function of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*: Satera LBP670C Series/Satera MF750C Series firmware v03.07 and earlier sold in Japan. Color imageCLASS LBP674C/Color imageCLASS X LBP1333C/Color imageCLASS MF750C Series/Color imageCLASS X MF1333C Series firmware v03.07 and earlier sold in US. i-SENSYS LBP673Cdw/C1333P/i-SENSYS MF750C Series/C1333i Series firmware v03.07 and earlier sold in Europe.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6232" + }, + { + "type": "WEB", + "url": "https://canon.jp/support/support-info/240205vulnerability-response" + }, + { + "type": "WEB", + "url": "https://psirt.canon/advisory-information/cp2024-001/" + }, + { + "type": "WEB", + "url": "https://www.canon-europe.com/support/product-security-latest-news/" + }, + { + "type": "WEB", + "url": "https://www.usa.canon.com/support/canon-product-advisories/Service-Notice-Regarding-Vulnerability-Measure-Against-Buffer-Overflow-for-Laser-Printers-and-Small-Office-Multifunctional-Printers" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T01:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-x4hh-7hpg-jmcg/GHSA-x4hh-7hpg-jmcg.json b/advisories/unreviewed/2024/02/GHSA-x4hh-7hpg-jmcg/GHSA-x4hh-7hpg-jmcg.json index c859b0078e5..99a6b5475a4 100644 --- a/advisories/unreviewed/2024/02/GHSA-x4hh-7hpg-jmcg/GHSA-x4hh-7hpg-jmcg.json +++ b/advisories/unreviewed/2024/02/GHSA-x4hh-7hpg-jmcg/GHSA-x4hh-7hpg-jmcg.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-74", "CWE-90" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/02/GHSA-x547-pm2q-2cr6/GHSA-x547-pm2q-2cr6.json b/advisories/unreviewed/2024/02/GHSA-x547-pm2q-2cr6/GHSA-x547-pm2q-2cr6.json new file mode 100644 index 00000000000..28c3a2be44f --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-x547-pm2q-2cr6/GHSA-x547-pm2q-2cr6.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x547-pm2q-2cr6", + "modified": "2024-02-06T03:32:59Z", + "published": "2024-02-06T03:32:59Z", + "aliases": [ + "CVE-2023-46360" + ], + "details": "Hardy Barth cPH2 eCharge Ladestation v1.87.0 and earlier is vulnerable to Execution with Unnecessary Privileges.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46360" + }, + { + "type": "WEB", + "url": "https://www.offensity.com/en/blog/os-command-injection-in-cph2-charging-station-200-cve-2023-46359-and-cve-2023-46360/" + }, + { + "type": "WEB", + "url": "http://hardy.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T01:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-xww7-5f37-vrcg/GHSA-xww7-5f37-vrcg.json b/advisories/unreviewed/2024/02/GHSA-xww7-5f37-vrcg/GHSA-xww7-5f37-vrcg.json index 9e838a8cd94..78868d2bbe8 100644 --- a/advisories/unreviewed/2024/02/GHSA-xww7-5f37-vrcg/GHSA-xww7-5f37-vrcg.json +++ b/advisories/unreviewed/2024/02/GHSA-xww7-5f37-vrcg/GHSA-xww7-5f37-vrcg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xww7-5f37-vrcg", - "modified": "2024-02-01T12:30:23Z", + "modified": "2024-02-06T03:32:59Z", "published": "2024-02-01T12:30:23Z", "aliases": [ "CVE-2023-51695"