Publish Advisories

GHSA-75f4-ww24-h9gr
GHSA-6276-35wc-6mcx
GHSA-9fm8-v9c3-xg8r
GHSA-c2c4-4544-w949
GHSA-pf86-qc75-c29x
GHSA-qprp-wpvg-34qr
GHSA-v4pw-hgqp-3vv5
GHSA-wvp9-cm8c-37mr
This commit is contained in:
advisory-database[bot]
2024-03-15 03:32:13 +00:00
parent 8cb660a735
commit 18d2c9a7cf
8 changed files with 313 additions and 1 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-75f4-ww24-h9gr",
"modified": "2024-02-26T18:30:29Z",
"modified": "2024-03-15T03:30:52Z",
"published": "2024-02-26T18:30:29Z",
"aliases": [
"CVE-2024-1622"
@@ -21,6 +21,14 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1622"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/K52QRRYBHLP73RAS3CGOPBWYT7EZVP6O"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/N2N3N3SNBHSH7GN3JOLR7YUF5FCTQQ5O"
},
{
"type": "WEB",
"url": "https://www.nlnetlabs.nl/downloads/routinator/CVE-2024-1622.txt"
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6276-35wc-6mcx",
"modified": "2024-03-15T03:30:52Z",
"published": "2024-03-15T03:30:52Z",
"aliases": [
"CVE-2024-26454"
],
"details": "A Cross Site Scripting vulnerability in Healthcare-Chatbot through 9b7058a can occur via a crafted payload to the email1 or pwd1 parameter in login.php.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26454"
},
{
"type": "WEB",
"url": "https://github.com/OmRajpurkar/Healthcare-Chatbot/issues/4"
},
{
"type": "WEB",
"url": "https://medium.com/%400x0d0x0a/healthcare-chatbot-xss-cve-2024-26454-acf2607bf210"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-15T01:15:58Z"
}
}
@@ -0,0 +1,46 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9fm8-v9c3-xg8r",
"modified": "2024-03-15T03:30:52Z",
"published": "2024-03-15T03:30:52Z",
"aliases": [
"CVE-2024-1915"
],
"details": "Incorrect Pointer Scaling vulnerability in Mitsubishi Electric Corporation MELSEC-Q Series and MELSEC-L Series CPU modules allows a remote unauthenticated attacker to execute malicious code on a target product by sending a specially crafted packet.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1915"
},
{
"type": "WEB",
"url": "https://jvn.jp/vu/JVNVU99690199"
},
{
"type": "WEB",
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-074-14"
},
{
"type": "WEB",
"url": "https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2023-024_en.pdf"
}
],
"database_specific": {
"cwe_ids": [
"CWE-468"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-15T01:15:58Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c2c4-4544-w949",
"modified": "2024-03-15T03:30:52Z",
"published": "2024-03-15T03:30:52Z",
"aliases": [
"CVE-2024-26540"
],
"details": "A heap-based buffer overflow in Clmg before 3.3.3 can occur via a crafted file to cimg_library::CImg<unsigned char>::_load_analyze.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26540"
},
{
"type": "WEB",
"url": "https://github.com/GreycLab/CImg/issues/403"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-15T01:15:58Z"
}
}
@@ -0,0 +1,46 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pf86-qc75-c29x",
"modified": "2024-03-15T03:30:52Z",
"published": "2024-03-15T03:30:52Z",
"aliases": [
"CVE-2024-0803"
],
"details": "Integer Overflow or Wraparound vulnerability in Mitsubishi Electric Corporation MELSEC-Q Series and MELSEC-L Series CPU modules allows a remote unauthenticated attacker to execute malicious code on a target product by sending a specially crafted packet.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0803"
},
{
"type": "WEB",
"url": "https://jvn.jp/vu/JVNVU99690199"
},
{
"type": "WEB",
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-074-14"
},
{
"type": "WEB",
"url": "https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2023-024_en.pdf"
}
],
"database_specific": {
"cwe_ids": [
"CWE-190"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-15T01:15:57Z"
}
}
@@ -0,0 +1,46 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qprp-wpvg-34qr",
"modified": "2024-03-15T03:30:52Z",
"published": "2024-03-15T03:30:52Z",
"aliases": [
"CVE-2024-0802"
],
"details": "Incorrect Pointer Scaling vulnerability in Mitsubishi Electric Corporation MELSEC-Q Series and MELSEC-L Series CPU modules allows a remote unauthenticated attacker to read arbitrary information from a target product or execute malicious code on a target product by sending a specially crafted packet.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0802"
},
{
"type": "WEB",
"url": "https://jvn.jp/vu/JVNVU99690199"
},
{
"type": "WEB",
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-074-14"
},
{
"type": "WEB",
"url": "https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2023-024_en.pdf"
}
],
"database_specific": {
"cwe_ids": [
"CWE-468"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-15T01:15:57Z"
}
}
@@ -0,0 +1,46 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v4pw-hgqp-3vv5",
"modified": "2024-03-15T03:30:52Z",
"published": "2024-03-15T03:30:52Z",
"aliases": [
"CVE-2024-1917"
],
"details": "Integer Overflow or Wraparound vulnerability in Mitsubishi Electric Corporation MELSEC-Q Series and MELSEC-L Series CPU modules allows a remote unauthenticated attacker to execute malicious code on a target product by sending a specially crafted packet.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1917"
},
{
"type": "WEB",
"url": "https://jvn.jp/vu/JVNVU99690199"
},
{
"type": "WEB",
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-074-14"
},
{
"type": "WEB",
"url": "https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2023-024_en.pdf"
}
],
"database_specific": {
"cwe_ids": [
"CWE-190"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-15T01:15:58Z"
}
}
@@ -0,0 +1,46 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wvp9-cm8c-37mr",
"modified": "2024-03-15T03:30:52Z",
"published": "2024-03-15T03:30:52Z",
"aliases": [
"CVE-2024-1916"
],
"details": "Integer Overflow or Wraparound vulnerability in Mitsubishi Electric Corporation MELSEC-Q Series and MELSEC-L Series CPU modules allows a remote unauthenticated attacker to execute malicious code on a target product by sending a specially crafted packet.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1916"
},
{
"type": "WEB",
"url": "https://jvn.jp/vu/JVNVU99690199"
},
{
"type": "WEB",
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-074-14"
},
{
"type": "WEB",
"url": "https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2023-024_en.pdf"
}
],
"database_specific": {
"cwe_ids": [
"CWE-190"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-15T01:15:58Z"
}
}