Publish Advisories

GHSA-c7xh-28x2-2ww8
GHSA-7953-6pvf-6rgx
GHSA-8w37-4wx3-mmg3
GHSA-44pq-qvmw-gj4m
This commit is contained in:
advisory-database[bot]
2024-08-25 18:32:08 +00:00
parent 6cd78d4534
commit 17d8c0278f
4 changed files with 53 additions and 8 deletions
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c7xh-28x2-2ww8",
"modified": "2024-03-04T03:30:26Z",
"modified": "2024-08-25T18:30:42Z",
"published": "2024-03-04T03:30:26Z",
"aliases": [
"CVE-2024-20023"
],
"details": "In flashc, there is a possible out of bounds write due to lack of valudation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541638; Issue ID: ALPS08541638.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-787"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-04T03:15:07Z"
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-434"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8w37-4wx3-mmg3",
"modified": "2024-05-22T18:30:40Z",
"modified": "2024-08-25T18:30:43Z",
"published": "2024-05-22T18:30:40Z",
"aliases": [
"CVE-2024-33224"
],
"details": "An issue in the component rtkio64.sys of Realtek Semiconductor Corp Realtek lO Driver v1.008.0823.2017 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-22T16:15:10Z"
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-44pq-qvmw-gj4m",
"modified": "2024-08-25T18:30:43Z",
"published": "2024-08-25T18:30:43Z",
"aliases": [
"CVE-2023-48957"
],
"details": "PureVPN Linux client 2.0.2-Productions fails to properly handle DNS queries, allowing them to bypass the VPN tunnel and be sent directly to the ISP or default DNS servers.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-48957"
},
{
"type": "WEB",
"url": "https://latesthackingnews.com/2023/11/13/multiple-vulnerabilities-found-in-purevpn-one-remains-unpatched"
},
{
"type": "WEB",
"url": "https://www.rafaybaloch.com/2023/11/Multiple%20Critical-Vulnerabilities-in-PureVPN.html?m=1"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-25T17:15:03Z"
}
}