From 14d10961cd9bf8b9759df80b417d19e66437099f Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 25 Oct 2024 12:32:47 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-2gcm-q52r-gph2.json | 35 ++++++++++++ .../GHSA-2pm2-9wvh-w2w9.json | 35 ++++++++++++ .../GHSA-36m8-cp45-7q2q.json | 35 ++++++++++++ .../GHSA-3gf6-9h52-xpf6.json | 54 +++++++++++++++++++ .../GHSA-45r2-8wpc-4rw9.json | 35 ++++++++++++ .../GHSA-4fc9-vhvw-cw2f.json | 35 ++++++++++++ .../GHSA-5g6c-ffg5-vxc6.json | 46 ++++++++++++++++ .../GHSA-5jh7-6r77-pm4f.json | 35 ++++++++++++ .../GHSA-5wjq-vh7w-3844.json | 35 ++++++++++++ .../GHSA-65xh-8r3w-xrf3.json | 35 ++++++++++++ .../GHSA-6f44-88r9-jjfp.json | 35 ++++++++++++ .../GHSA-6m58-669r-3v4p.json | 35 ++++++++++++ .../GHSA-7hc4-q4r5-h48x.json | 38 +++++++++++++ .../GHSA-7pcw-338g-2xgr.json | 35 ++++++++++++ .../GHSA-94c5-h25f-5w58.json | 35 ++++++++++++ .../GHSA-98qv-5frh-cx73.json | 35 ++++++++++++ .../GHSA-9vq5-h4gw-g3q3.json | 35 ++++++++++++ .../GHSA-fjxq-w7vf-g7jh.json | 35 ++++++++++++ .../GHSA-g2hg-pf39-5q37.json | 35 ++++++++++++ .../GHSA-g4v7-5988-5c48.json | 35 ++++++++++++ .../GHSA-gq7f-7qpp-gf55.json | 35 ++++++++++++ .../GHSA-j6fp-rq6r-f49m.json | 54 +++++++++++++++++++ .../GHSA-jc3p-f86q-23rh.json | 35 ++++++++++++ .../GHSA-phfx-3hch-p62r.json | 35 ++++++++++++ .../GHSA-q5ff-63c8-hcx3.json | 35 ++++++++++++ .../GHSA-qrgq-qh39-4rq7.json | 35 ++++++++++++ .../GHSA-r57c-j457-568g.json | 35 ++++++++++++ .../GHSA-rmrx-hhmg-hqq9.json | 54 +++++++++++++++++++ .../GHSA-v3hx-qxqq-j8jp.json | 35 ++++++++++++ .../GHSA-vh43-qg6g-8gcm.json | 35 ++++++++++++ .../GHSA-vmh6-j5p9-57pc.json | 35 ++++++++++++ .../GHSA-w65r-wfp3-r7w5.json | 38 +++++++++++++ .../GHSA-wmgg-3q6m-rjp9.json | 54 +++++++++++++++++++ .../GHSA-wp8x-3mwg-2pgw.json | 35 ++++++++++++ .../GHSA-xv6q-xxx5-mmp4.json | 35 ++++++++++++ 35 files changed, 1318 insertions(+) create mode 100644 advisories/unreviewed/2024/10/GHSA-2gcm-q52r-gph2/GHSA-2gcm-q52r-gph2.json create mode 100644 advisories/unreviewed/2024/10/GHSA-2pm2-9wvh-w2w9/GHSA-2pm2-9wvh-w2w9.json create mode 100644 advisories/unreviewed/2024/10/GHSA-36m8-cp45-7q2q/GHSA-36m8-cp45-7q2q.json create mode 100644 advisories/unreviewed/2024/10/GHSA-3gf6-9h52-xpf6/GHSA-3gf6-9h52-xpf6.json create mode 100644 advisories/unreviewed/2024/10/GHSA-45r2-8wpc-4rw9/GHSA-45r2-8wpc-4rw9.json create mode 100644 advisories/unreviewed/2024/10/GHSA-4fc9-vhvw-cw2f/GHSA-4fc9-vhvw-cw2f.json create mode 100644 advisories/unreviewed/2024/10/GHSA-5g6c-ffg5-vxc6/GHSA-5g6c-ffg5-vxc6.json create mode 100644 advisories/unreviewed/2024/10/GHSA-5jh7-6r77-pm4f/GHSA-5jh7-6r77-pm4f.json create mode 100644 advisories/unreviewed/2024/10/GHSA-5wjq-vh7w-3844/GHSA-5wjq-vh7w-3844.json create mode 100644 advisories/unreviewed/2024/10/GHSA-65xh-8r3w-xrf3/GHSA-65xh-8r3w-xrf3.json create mode 100644 advisories/unreviewed/2024/10/GHSA-6f44-88r9-jjfp/GHSA-6f44-88r9-jjfp.json create mode 100644 advisories/unreviewed/2024/10/GHSA-6m58-669r-3v4p/GHSA-6m58-669r-3v4p.json create mode 100644 advisories/unreviewed/2024/10/GHSA-7hc4-q4r5-h48x/GHSA-7hc4-q4r5-h48x.json create mode 100644 advisories/unreviewed/2024/10/GHSA-7pcw-338g-2xgr/GHSA-7pcw-338g-2xgr.json create mode 100644 advisories/unreviewed/2024/10/GHSA-94c5-h25f-5w58/GHSA-94c5-h25f-5w58.json create mode 100644 advisories/unreviewed/2024/10/GHSA-98qv-5frh-cx73/GHSA-98qv-5frh-cx73.json create mode 100644 advisories/unreviewed/2024/10/GHSA-9vq5-h4gw-g3q3/GHSA-9vq5-h4gw-g3q3.json create mode 100644 advisories/unreviewed/2024/10/GHSA-fjxq-w7vf-g7jh/GHSA-fjxq-w7vf-g7jh.json create mode 100644 advisories/unreviewed/2024/10/GHSA-g2hg-pf39-5q37/GHSA-g2hg-pf39-5q37.json create mode 100644 advisories/unreviewed/2024/10/GHSA-g4v7-5988-5c48/GHSA-g4v7-5988-5c48.json create mode 100644 advisories/unreviewed/2024/10/GHSA-gq7f-7qpp-gf55/GHSA-gq7f-7qpp-gf55.json create mode 100644 advisories/unreviewed/2024/10/GHSA-j6fp-rq6r-f49m/GHSA-j6fp-rq6r-f49m.json create mode 100644 advisories/unreviewed/2024/10/GHSA-jc3p-f86q-23rh/GHSA-jc3p-f86q-23rh.json create mode 100644 advisories/unreviewed/2024/10/GHSA-phfx-3hch-p62r/GHSA-phfx-3hch-p62r.json create mode 100644 advisories/unreviewed/2024/10/GHSA-q5ff-63c8-hcx3/GHSA-q5ff-63c8-hcx3.json create mode 100644 advisories/unreviewed/2024/10/GHSA-qrgq-qh39-4rq7/GHSA-qrgq-qh39-4rq7.json create mode 100644 advisories/unreviewed/2024/10/GHSA-r57c-j457-568g/GHSA-r57c-j457-568g.json create mode 100644 advisories/unreviewed/2024/10/GHSA-rmrx-hhmg-hqq9/GHSA-rmrx-hhmg-hqq9.json create mode 100644 advisories/unreviewed/2024/10/GHSA-v3hx-qxqq-j8jp/GHSA-v3hx-qxqq-j8jp.json create mode 100644 advisories/unreviewed/2024/10/GHSA-vh43-qg6g-8gcm/GHSA-vh43-qg6g-8gcm.json create mode 100644 advisories/unreviewed/2024/10/GHSA-vmh6-j5p9-57pc/GHSA-vmh6-j5p9-57pc.json create mode 100644 advisories/unreviewed/2024/10/GHSA-w65r-wfp3-r7w5/GHSA-w65r-wfp3-r7w5.json create mode 100644 advisories/unreviewed/2024/10/GHSA-wmgg-3q6m-rjp9/GHSA-wmgg-3q6m-rjp9.json create mode 100644 advisories/unreviewed/2024/10/GHSA-wp8x-3mwg-2pgw/GHSA-wp8x-3mwg-2pgw.json create mode 100644 advisories/unreviewed/2024/10/GHSA-xv6q-xxx5-mmp4/GHSA-xv6q-xxx5-mmp4.json diff --git a/advisories/unreviewed/2024/10/GHSA-2gcm-q52r-gph2/GHSA-2gcm-q52r-gph2.json b/advisories/unreviewed/2024/10/GHSA-2gcm-q52r-gph2/GHSA-2gcm-q52r-gph2.json new file mode 100644 index 00000000000..6e295f460b6 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-2gcm-q52r-gph2/GHSA-2gcm-q52r-gph2.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2gcm-q52r-gph2", + "modified": "2024-10-25T12:31:33Z", + "published": "2024-10-25T12:31:33Z", + "aliases": [ + "CVE-2024-47018" + ], + "details": "In pmucal_rae_handle_seq_int of flexpmu_cal_rae.c, there is a possible out of bounds read due to a buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47018" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/pixel/2024-10-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-25T11:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-2pm2-9wvh-w2w9/GHSA-2pm2-9wvh-w2w9.json b/advisories/unreviewed/2024/10/GHSA-2pm2-9wvh-w2w9/GHSA-2pm2-9wvh-w2w9.json new file mode 100644 index 00000000000..83e649ac873 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-2pm2-9wvh-w2w9/GHSA-2pm2-9wvh-w2w9.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2pm2-9wvh-w2w9", + "modified": "2024-10-25T12:31:32Z", + "published": "2024-10-25T12:31:32Z", + "aliases": [ + "CVE-2024-47013" + ], + "details": "In pmucal_rae_handle_seq_int of flexpmu_cal_rae.c, there is a possible arbitrary write due to uninitialized data. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47013" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/pixel/2024-10-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-25T11:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-36m8-cp45-7q2q/GHSA-36m8-cp45-7q2q.json b/advisories/unreviewed/2024/10/GHSA-36m8-cp45-7q2q/GHSA-36m8-cp45-7q2q.json new file mode 100644 index 00000000000..fa6db62238c --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-36m8-cp45-7q2q/GHSA-36m8-cp45-7q2q.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-36m8-cp45-7q2q", + "modified": "2024-10-25T12:31:32Z", + "published": "2024-10-25T12:31:32Z", + "aliases": [ + "CVE-2024-44100" + ], + "details": "N/A", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44100" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/pixel/2024-10-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-25T11:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-3gf6-9h52-xpf6/GHSA-3gf6-9h52-xpf6.json b/advisories/unreviewed/2024/10/GHSA-3gf6-9h52-xpf6/GHSA-3gf6-9h52-xpf6.json new file mode 100644 index 00000000000..8070beef007 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-3gf6-9h52-xpf6/GHSA-3gf6-9h52-xpf6.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3gf6-9h52-xpf6", + "modified": "2024-10-25T12:31:32Z", + "published": "2024-10-25T12:31:32Z", + "aliases": [ + "CVE-2024-10376" + ], + "details": "A vulnerability was found in ESAFENET CDG 5. It has been declared as critical. This vulnerability affects the function actionPassOrNotAutoSign of the file /com/esafenet/servlet/service/processsign/AutoSignService.java. The manipulation of the argument UniqueId leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10376" + }, + { + "type": "WEB", + "url": "https://flowus.cn/share/127494ce-0d4c-4773-9fc0-810e26841c4b?code=G8A6P3" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.281806" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.281806" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.426083" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-25T11:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-45r2-8wpc-4rw9/GHSA-45r2-8wpc-4rw9.json b/advisories/unreviewed/2024/10/GHSA-45r2-8wpc-4rw9/GHSA-45r2-8wpc-4rw9.json new file mode 100644 index 00000000000..795dd8580db --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-45r2-8wpc-4rw9/GHSA-45r2-8wpc-4rw9.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-45r2-8wpc-4rw9", + "modified": "2024-10-25T12:31:33Z", + "published": "2024-10-25T12:31:33Z", + "aliases": [ + "CVE-2024-47034" + ], + "details": "there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47034" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/pixel/2024-10-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-25T11:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-4fc9-vhvw-cw2f/GHSA-4fc9-vhvw-cw2f.json b/advisories/unreviewed/2024/10/GHSA-4fc9-vhvw-cw2f/GHSA-4fc9-vhvw-cw2f.json new file mode 100644 index 00000000000..ab3328e9501 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-4fc9-vhvw-cw2f/GHSA-4fc9-vhvw-cw2f.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4fc9-vhvw-cw2f", + "modified": "2024-10-25T12:31:33Z", + "published": "2024-10-25T12:31:33Z", + "aliases": [ + "CVE-2024-47022" + ], + "details": "N/A", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47022" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/pixel/2024-10-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-25T11:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-5g6c-ffg5-vxc6/GHSA-5g6c-ffg5-vxc6.json b/advisories/unreviewed/2024/10/GHSA-5g6c-ffg5-vxc6/GHSA-5g6c-ffg5-vxc6.json new file mode 100644 index 00000000000..c23632a54a2 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-5g6c-ffg5-vxc6/GHSA-5g6c-ffg5-vxc6.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5g6c-ffg5-vxc6", + "modified": "2024-10-25T12:31:34Z", + "published": "2024-10-25T12:31:33Z", + "aliases": [ + "CVE-2024-10374" + ], + "details": "The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpmem_loginout shortcode in all versions up to, and including, 3.4.9.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10374" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3172530" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/wp-members/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/5ea93a49-0e1a-4a24-8f6b-03e624f517d4?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-25T12:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-5jh7-6r77-pm4f/GHSA-5jh7-6r77-pm4f.json b/advisories/unreviewed/2024/10/GHSA-5jh7-6r77-pm4f/GHSA-5jh7-6r77-pm4f.json new file mode 100644 index 00000000000..0b36f64c631 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-5jh7-6r77-pm4f/GHSA-5jh7-6r77-pm4f.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5jh7-6r77-pm4f", + "modified": "2024-10-25T12:31:33Z", + "published": "2024-10-25T12:31:33Z", + "aliases": [ + "CVE-2024-47016" + ], + "details": "there is a possible privilege escalation due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47016" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/pixel/2024-10-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-25T11:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-5wjq-vh7w-3844/GHSA-5wjq-vh7w-3844.json b/advisories/unreviewed/2024/10/GHSA-5wjq-vh7w-3844/GHSA-5wjq-vh7w-3844.json new file mode 100644 index 00000000000..f327a4b5c45 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-5wjq-vh7w-3844/GHSA-5wjq-vh7w-3844.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5wjq-vh7w-3844", + "modified": "2024-10-25T12:31:33Z", + "published": "2024-10-25T12:31:33Z", + "aliases": [ + "CVE-2024-47041" + ], + "details": "In valid_address of syscall.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47041" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/pixel/2024-10-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-25T11:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-65xh-8r3w-xrf3/GHSA-65xh-8r3w-xrf3.json b/advisories/unreviewed/2024/10/GHSA-65xh-8r3w-xrf3/GHSA-65xh-8r3w-xrf3.json new file mode 100644 index 00000000000..a5ba3fdae76 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-65xh-8r3w-xrf3/GHSA-65xh-8r3w-xrf3.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-65xh-8r3w-xrf3", + "modified": "2024-10-25T12:31:32Z", + "published": "2024-10-25T12:31:32Z", + "aliases": [ + "CVE-2024-44098" + ], + "details": "In lwis_device_event_states_clear_locked of lwis_event.c, there is a possible privilege escalation due to a double free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44098" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/pixel/2024-10-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-25T11:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-6f44-88r9-jjfp/GHSA-6f44-88r9-jjfp.json b/advisories/unreviewed/2024/10/GHSA-6f44-88r9-jjfp/GHSA-6f44-88r9-jjfp.json new file mode 100644 index 00000000000..a2ac718d887 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-6f44-88r9-jjfp/GHSA-6f44-88r9-jjfp.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6f44-88r9-jjfp", + "modified": "2024-10-25T12:31:33Z", + "published": "2024-10-25T12:31:33Z", + "aliases": [ + "CVE-2024-47025" + ], + "details": "In ppmp_protect_buf of drm_fw.c, there is a possible information disclosure due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47025" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/pixel/2024-10-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-25T11:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-6m58-669r-3v4p/GHSA-6m58-669r-3v4p.json b/advisories/unreviewed/2024/10/GHSA-6m58-669r-3v4p/GHSA-6m58-669r-3v4p.json new file mode 100644 index 00000000000..7928257386f --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-6m58-669r-3v4p/GHSA-6m58-669r-3v4p.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6m58-669r-3v4p", + "modified": "2024-10-25T12:31:32Z", + "published": "2024-10-25T12:31:32Z", + "aliases": [ + "CVE-2024-44101" + ], + "details": "there is a possible Null Pointer Dereference (modem crash) due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44101" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/pixel/2024-10-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-25T11:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-7hc4-q4r5-h48x/GHSA-7hc4-q4r5-h48x.json b/advisories/unreviewed/2024/10/GHSA-7hc4-q4r5-h48x/GHSA-7hc4-q4r5-h48x.json new file mode 100644 index 00000000000..69e6724f682 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-7hc4-q4r5-h48x/GHSA-7hc4-q4r5-h48x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7hc4-q4r5-h48x", + "modified": "2024-10-25T12:31:34Z", + "published": "2024-10-25T12:31:33Z", + "aliases": [ + "CVE-2024-47481" + ], + "details": "Dell Data Lakehouse, version(s) 1.0.0.0, 1.1.0., contain(s) an Improper Access Control vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47481" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000240535/dsa-2024-419-security-update-for-dell-data-lakehouse-system-software-for-multiple-third-party-component-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-25T11:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-7pcw-338g-2xgr/GHSA-7pcw-338g-2xgr.json b/advisories/unreviewed/2024/10/GHSA-7pcw-338g-2xgr/GHSA-7pcw-338g-2xgr.json new file mode 100644 index 00000000000..b23bacec344 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-7pcw-338g-2xgr/GHSA-7pcw-338g-2xgr.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7pcw-338g-2xgr", + "modified": "2024-10-25T12:31:33Z", + "published": "2024-10-25T12:31:33Z", + "aliases": [ + "CVE-2024-47023" + ], + "details": "there is a possible man-in-the-middle attack due to a logic error in the code. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47023" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/pixel/2024-10-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-25T11:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-94c5-h25f-5w58/GHSA-94c5-h25f-5w58.json b/advisories/unreviewed/2024/10/GHSA-94c5-h25f-5w58/GHSA-94c5-h25f-5w58.json new file mode 100644 index 00000000000..46f9508aa46 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-94c5-h25f-5w58/GHSA-94c5-h25f-5w58.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-94c5-h25f-5w58", + "modified": "2024-10-25T12:31:33Z", + "published": "2024-10-25T12:31:33Z", + "aliases": [ + "CVE-2024-47024" + ], + "details": "In vring_size of external/headers/include/virtio/virtio_ring.h, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47024" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/pixel/2024-10-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-25T11:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-98qv-5frh-cx73/GHSA-98qv-5frh-cx73.json b/advisories/unreviewed/2024/10/GHSA-98qv-5frh-cx73/GHSA-98qv-5frh-cx73.json new file mode 100644 index 00000000000..952d4ef1a36 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-98qv-5frh-cx73/GHSA-98qv-5frh-cx73.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-98qv-5frh-cx73", + "modified": "2024-10-25T12:31:33Z", + "published": "2024-10-25T12:31:33Z", + "aliases": [ + "CVE-2024-47020" + ], + "details": "N/A", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47020" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/pixel/2024-10-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-25T11:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-9vq5-h4gw-g3q3/GHSA-9vq5-h4gw-g3q3.json b/advisories/unreviewed/2024/10/GHSA-9vq5-h4gw-g3q3/GHSA-9vq5-h4gw-g3q3.json new file mode 100644 index 00000000000..fc415ca9217 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-9vq5-h4gw-g3q3/GHSA-9vq5-h4gw-g3q3.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9vq5-h4gw-g3q3", + "modified": "2024-10-25T12:31:32Z", + "published": "2024-10-25T12:31:32Z", + "aliases": [ + "CVE-2024-47014" + ], + "details": "N/A", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47014" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/pixel/2024-10-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-25T11:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-fjxq-w7vf-g7jh/GHSA-fjxq-w7vf-g7jh.json b/advisories/unreviewed/2024/10/GHSA-fjxq-w7vf-g7jh/GHSA-fjxq-w7vf-g7jh.json new file mode 100644 index 00000000000..ba06f2576b8 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-fjxq-w7vf-g7jh/GHSA-fjxq-w7vf-g7jh.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fjxq-w7vf-g7jh", + "modified": "2024-10-25T12:31:33Z", + "published": "2024-10-25T12:31:33Z", + "aliases": [ + "CVE-2024-47030" + ], + "details": "N/A", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47030" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/pixel/2024-10-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-25T11:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-g2hg-pf39-5q37/GHSA-g2hg-pf39-5q37.json b/advisories/unreviewed/2024/10/GHSA-g2hg-pf39-5q37/GHSA-g2hg-pf39-5q37.json new file mode 100644 index 00000000000..7619c19b286 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-g2hg-pf39-5q37/GHSA-g2hg-pf39-5q37.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g2hg-pf39-5q37", + "modified": "2024-10-25T12:31:33Z", + "published": "2024-10-25T12:31:33Z", + "aliases": [ + "CVE-2024-47027" + ], + "details": "In sm_mem_compat_get_vmm_obj of lib/sm/shared_mem.c, there is a possible arbitrary physical memory access due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47027" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/pixel/2024-10-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-25T11:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-g4v7-5988-5c48/GHSA-g4v7-5988-5c48.json b/advisories/unreviewed/2024/10/GHSA-g4v7-5988-5c48/GHSA-g4v7-5988-5c48.json new file mode 100644 index 00000000000..67f76cdccbe --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-g4v7-5988-5c48/GHSA-g4v7-5988-5c48.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g4v7-5988-5c48", + "modified": "2024-10-25T12:31:33Z", + "published": "2024-10-25T12:31:33Z", + "aliases": [ + "CVE-2024-47017" + ], + "details": "In ufshc_scsi_cmd of ufs.c, there is a possible stack variable use after free due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47017" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/pixel/2024-10-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-25T11:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-gq7f-7qpp-gf55/GHSA-gq7f-7qpp-gf55.json b/advisories/unreviewed/2024/10/GHSA-gq7f-7qpp-gf55/GHSA-gq7f-7qpp-gf55.json new file mode 100644 index 00000000000..f93eac50000 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-gq7f-7qpp-gf55/GHSA-gq7f-7qpp-gf55.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gq7f-7qpp-gf55", + "modified": "2024-10-25T12:31:33Z", + "published": "2024-10-25T12:31:33Z", + "aliases": [ + "CVE-2024-47035" + ], + "details": "In vring_init of external/headers/include/virtio/virtio_ring.h, there is a possible out of bounds write due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47035" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/pixel/2024-10-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-25T11:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-j6fp-rq6r-f49m/GHSA-j6fp-rq6r-f49m.json b/advisories/unreviewed/2024/10/GHSA-j6fp-rq6r-f49m/GHSA-j6fp-rq6r-f49m.json new file mode 100644 index 00000000000..2deffdce774 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-j6fp-rq6r-f49m/GHSA-j6fp-rq6r-f49m.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j6fp-rq6r-f49m", + "modified": "2024-10-25T12:31:32Z", + "published": "2024-10-25T12:31:32Z", + "aliases": [ + "CVE-2024-10377" + ], + "details": "A vulnerability was found in ESAFENET CDG 5. It has been rated as critical. This issue affects the function actionPassDecryptApplication1 of the file /com/esafenet/servlet/client/DecryptApplicationService.java. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. This is a different issue than CVE-2024-10069. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10377" + }, + { + "type": "WEB", + "url": "https://flowus.cn/share/1234f712-c774-4a26-a922-809e0a356405?code=G8A6P3" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.281807" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.281807" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.426085" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-25T11:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-jc3p-f86q-23rh/GHSA-jc3p-f86q-23rh.json b/advisories/unreviewed/2024/10/GHSA-jc3p-f86q-23rh/GHSA-jc3p-f86q-23rh.json new file mode 100644 index 00000000000..15bffbe7829 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-jc3p-f86q-23rh/GHSA-jc3p-f86q-23rh.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jc3p-f86q-23rh", + "modified": "2024-10-25T12:31:32Z", + "published": "2024-10-25T12:31:32Z", + "aliases": [ + "CVE-2024-47012" + ], + "details": "In mm_GetMobileIdIndexForNsUpdate of mm_GmmPduCodec.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47012" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/pixel/2024-10-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-25T11:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-phfx-3hch-p62r/GHSA-phfx-3hch-p62r.json b/advisories/unreviewed/2024/10/GHSA-phfx-3hch-p62r/GHSA-phfx-3hch-p62r.json new file mode 100644 index 00000000000..1683b7acba0 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-phfx-3hch-p62r/GHSA-phfx-3hch-p62r.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-phfx-3hch-p62r", + "modified": "2024-10-25T12:31:32Z", + "published": "2024-10-25T12:31:32Z", + "aliases": [ + "CVE-2024-44099" + ], + "details": "There is a possible Local bypass of user interaction due to an insecure default value. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44099" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/pixel/2024-10-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-25T11:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-q5ff-63c8-hcx3/GHSA-q5ff-63c8-hcx3.json b/advisories/unreviewed/2024/10/GHSA-q5ff-63c8-hcx3/GHSA-q5ff-63c8-hcx3.json new file mode 100644 index 00000000000..3c196a0339b --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-q5ff-63c8-hcx3/GHSA-q5ff-63c8-hcx3.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q5ff-63c8-hcx3", + "modified": "2024-10-25T12:31:33Z", + "published": "2024-10-25T12:31:33Z", + "aliases": [ + "CVE-2024-47028" + ], + "details": "In ffu_flash_pack of ffu.c, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47028" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/pixel/2024-10-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-25T11:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-qrgq-qh39-4rq7/GHSA-qrgq-qh39-4rq7.json b/advisories/unreviewed/2024/10/GHSA-qrgq-qh39-4rq7/GHSA-qrgq-qh39-4rq7.json new file mode 100644 index 00000000000..f46afa49d4c --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-qrgq-qh39-4rq7/GHSA-qrgq-qh39-4rq7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qrgq-qh39-4rq7", + "modified": "2024-10-25T12:31:33Z", + "published": "2024-10-25T12:31:33Z", + "aliases": [ + "CVE-2024-47015" + ], + "details": "In ProtocolMiscHwConfigChangeAdapter::GetData() of protocolmiscadapter.cpp, there is a possible out-of-bounds read due to a missing bounds check. This could lead to local information disclosure with baseband firmware compromise required. User Interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47015" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/pixel/2024-10-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-25T11:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-r57c-j457-568g/GHSA-r57c-j457-568g.json b/advisories/unreviewed/2024/10/GHSA-r57c-j457-568g/GHSA-r57c-j457-568g.json new file mode 100644 index 00000000000..379959f1b81 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-r57c-j457-568g/GHSA-r57c-j457-568g.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r57c-j457-568g", + "modified": "2024-10-25T12:31:33Z", + "published": "2024-10-25T12:31:33Z", + "aliases": [ + "CVE-2024-47031" + ], + "details": "N/A", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47031" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/pixel/2024-10-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-25T11:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-rmrx-hhmg-hqq9/GHSA-rmrx-hhmg-hqq9.json b/advisories/unreviewed/2024/10/GHSA-rmrx-hhmg-hqq9/GHSA-rmrx-hhmg-hqq9.json new file mode 100644 index 00000000000..a3b32d54a5c --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-rmrx-hhmg-hqq9/GHSA-rmrx-hhmg-hqq9.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rmrx-hhmg-hqq9", + "modified": "2024-10-25T12:31:34Z", + "published": "2024-10-25T12:31:34Z", + "aliases": [ + "CVE-2024-10379" + ], + "details": "A vulnerability classified as problematic was found in ESAFENET CDG 5. Affected by this vulnerability is the function actionViewDecyptFile of the file /com/esafenet/servlet/client/DecryptApplicationService.java. The manipulation of the argument decryptFileId with the input ../../../Windows/System32/drivers/etc/hosts leads to path traversal: '../filedir'. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The affected function has a typo and is missing an R. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10379" + }, + { + "type": "WEB", + "url": "https://flowus.cn/share/0b03c61a-76a5-4f45-9ee7-a88e0f21d539?code=G8A6P3" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.281809" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.281809" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.426087" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-24" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-25T12:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-v3hx-qxqq-j8jp/GHSA-v3hx-qxqq-j8jp.json b/advisories/unreviewed/2024/10/GHSA-v3hx-qxqq-j8jp/GHSA-v3hx-qxqq-j8jp.json new file mode 100644 index 00000000000..d4124bd4cff --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-v3hx-qxqq-j8jp/GHSA-v3hx-qxqq-j8jp.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v3hx-qxqq-j8jp", + "modified": "2024-10-25T12:31:33Z", + "published": "2024-10-25T12:31:33Z", + "aliases": [ + "CVE-2024-47026" + ], + "details": "In gsc_gsa_rescue of gsc_gsa.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47026" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/pixel/2024-10-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-25T11:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-vh43-qg6g-8gcm/GHSA-vh43-qg6g-8gcm.json b/advisories/unreviewed/2024/10/GHSA-vh43-qg6g-8gcm/GHSA-vh43-qg6g-8gcm.json new file mode 100644 index 00000000000..6d96b0e39c4 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-vh43-qg6g-8gcm/GHSA-vh43-qg6g-8gcm.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vh43-qg6g-8gcm", + "modified": "2024-10-25T12:31:33Z", + "published": "2024-10-25T12:31:33Z", + "aliases": [ + "CVE-2024-47021" + ], + "details": "In sms_ExtractCbLanguage of sms_CellBroadcast.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47021" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/pixel/2024-10-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-25T11:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-vmh6-j5p9-57pc/GHSA-vmh6-j5p9-57pc.json b/advisories/unreviewed/2024/10/GHSA-vmh6-j5p9-57pc/GHSA-vmh6-j5p9-57pc.json new file mode 100644 index 00000000000..d2ddfc1baa8 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-vmh6-j5p9-57pc/GHSA-vmh6-j5p9-57pc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vmh6-j5p9-57pc", + "modified": "2024-10-25T12:31:33Z", + "published": "2024-10-25T12:31:33Z", + "aliases": [ + "CVE-2024-47029" + ], + "details": "In TrustySharedMemoryManager::GetSharedMemory of ondevice/trusty/trusty_shared_memory_manager.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47029" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/pixel/2024-10-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-25T11:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-w65r-wfp3-r7w5/GHSA-w65r-wfp3-r7w5.json b/advisories/unreviewed/2024/10/GHSA-w65r-wfp3-r7w5/GHSA-w65r-wfp3-r7w5.json new file mode 100644 index 00000000000..0ef8b2fd539 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-w65r-wfp3-r7w5/GHSA-w65r-wfp3-r7w5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w65r-wfp3-r7w5", + "modified": "2024-10-25T12:31:33Z", + "published": "2024-10-25T12:31:33Z", + "aliases": [ + "CVE-2024-47483" + ], + "details": "Dell Data Lakehouse, version(s) 1.0.0.0 and 1.1.0.0, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47483" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000240535/dsa-2024-419-security-update-for-dell-data-lakehouse-system-software-for-multiple-third-party-component-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-25T11:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-wmgg-3q6m-rjp9/GHSA-wmgg-3q6m-rjp9.json b/advisories/unreviewed/2024/10/GHSA-wmgg-3q6m-rjp9/GHSA-wmgg-3q6m-rjp9.json new file mode 100644 index 00000000000..55cf9d68ec8 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-wmgg-3q6m-rjp9/GHSA-wmgg-3q6m-rjp9.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wmgg-3q6m-rjp9", + "modified": "2024-10-25T12:31:34Z", + "published": "2024-10-25T12:31:34Z", + "aliases": [ + "CVE-2024-10378" + ], + "details": "A vulnerability classified as critical has been found in ESAFENET CDG 5. Affected is the function actionViewCDGRenewFile of the file /com/esafenet/servlet/client/CDGRenewApplicationService.java. The manipulation of the argument CDGRenewFileId leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10378" + }, + { + "type": "WEB", + "url": "https://flowus.cn/share/5d03f1d5-695a-421b-8445-2273774ea97a?code=G8A6P3" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.281808" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.281808" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.426086" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-25T12:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-wp8x-3mwg-2pgw/GHSA-wp8x-3mwg-2pgw.json b/advisories/unreviewed/2024/10/GHSA-wp8x-3mwg-2pgw/GHSA-wp8x-3mwg-2pgw.json new file mode 100644 index 00000000000..aec22949aa2 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-wp8x-3mwg-2pgw/GHSA-wp8x-3mwg-2pgw.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wp8x-3mwg-2pgw", + "modified": "2024-10-25T12:31:33Z", + "published": "2024-10-25T12:31:33Z", + "aliases": [ + "CVE-2024-47033" + ], + "details": "In lwis_allocator_free of lwis_allocator.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47033" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/pixel/2024-10-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-25T11:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-xv6q-xxx5-mmp4/GHSA-xv6q-xxx5-mmp4.json b/advisories/unreviewed/2024/10/GHSA-xv6q-xxx5-mmp4/GHSA-xv6q-xxx5-mmp4.json new file mode 100644 index 00000000000..13481cac862 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-xv6q-xxx5-mmp4/GHSA-xv6q-xxx5-mmp4.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xv6q-xxx5-mmp4", + "modified": "2024-10-25T12:31:33Z", + "published": "2024-10-25T12:31:33Z", + "aliases": [ + "CVE-2024-47019" + ], + "details": "In ProtocolEmbmsSaiListAdapter::Init() of protocolembmsadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with baseband firmware compromise required. User Interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47019" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/pixel/2024-10-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-25T11:15:16Z" + } +} \ No newline at end of file