diff --git a/advisories/unreviewed/2024/06/GHSA-299v-fghf-v92x/GHSA-299v-fghf-v92x.json b/advisories/unreviewed/2024/06/GHSA-299v-fghf-v92x/GHSA-299v-fghf-v92x.json index 5c5a914cdfb..76fc3a0df69 100644 --- a/advisories/unreviewed/2024/06/GHSA-299v-fghf-v92x/GHSA-299v-fghf-v92x.json +++ b/advisories/unreviewed/2024/06/GHSA-299v-fghf-v92x/GHSA-299v-fghf-v92x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-299v-fghf-v92x", - "modified": "2024-06-18T15:30:35Z", + "modified": "2024-08-23T03:30:59Z", "published": "2024-06-18T15:30:35Z", "aliases": [ "CVE-2024-6116" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/06/GHSA-3vq2-9cm2-rhrv/GHSA-3vq2-9cm2-rhrv.json b/advisories/unreviewed/2024/06/GHSA-3vq2-9cm2-rhrv/GHSA-3vq2-9cm2-rhrv.json index 6f035da26e2..5ea8399b933 100644 --- a/advisories/unreviewed/2024/06/GHSA-3vq2-9cm2-rhrv/GHSA-3vq2-9cm2-rhrv.json +++ b/advisories/unreviewed/2024/06/GHSA-3vq2-9cm2-rhrv/GHSA-3vq2-9cm2-rhrv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3vq2-9cm2-rhrv", - "modified": "2024-06-21T03:30:33Z", + "modified": "2024-08-23T03:30:59Z", "published": "2024-06-21T03:30:33Z", "aliases": [ "CVE-2024-6216" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/06/GHSA-4395-qwxq-qcc7/GHSA-4395-qwxq-qcc7.json b/advisories/unreviewed/2024/06/GHSA-4395-qwxq-qcc7/GHSA-4395-qwxq-qcc7.json index c9bcc3479dd..370627314d9 100644 --- a/advisories/unreviewed/2024/06/GHSA-4395-qwxq-qcc7/GHSA-4395-qwxq-qcc7.json +++ b/advisories/unreviewed/2024/06/GHSA-4395-qwxq-qcc7/GHSA-4395-qwxq-qcc7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4395-qwxq-qcc7", - "modified": "2024-06-21T00:33:13Z", + "modified": "2024-08-23T03:30:59Z", "published": "2024-06-21T00:33:13Z", "aliases": [ "CVE-2024-6212" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/06/GHSA-4wf7-5pg3-w9j6/GHSA-4wf7-5pg3-w9j6.json b/advisories/unreviewed/2024/06/GHSA-4wf7-5pg3-w9j6/GHSA-4wf7-5pg3-w9j6.json index facc5ba045e..dc15dc92c92 100644 --- a/advisories/unreviewed/2024/06/GHSA-4wf7-5pg3-w9j6/GHSA-4wf7-5pg3-w9j6.json +++ b/advisories/unreviewed/2024/06/GHSA-4wf7-5pg3-w9j6/GHSA-4wf7-5pg3-w9j6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4wf7-5pg3-w9j6", - "modified": "2024-06-11T06:31:47Z", + "modified": "2024-08-23T03:30:57Z", "published": "2024-06-11T06:31:47Z", "aliases": [ "CVE-2024-31398" ], "details": "Insertion of sensitive information into sent data issue exists in Cybozu Garoon 5.0.0 to 5.15.2. If this vulnerability is exploited, a user who can log in to the product may obtain information on the list of users.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-11T06:15:10Z" diff --git a/advisories/unreviewed/2024/06/GHSA-4xv7-gmf4-mjpg/GHSA-4xv7-gmf4-mjpg.json b/advisories/unreviewed/2024/06/GHSA-4xv7-gmf4-mjpg/GHSA-4xv7-gmf4-mjpg.json index eedc55e72b0..c8689202d7f 100644 --- a/advisories/unreviewed/2024/06/GHSA-4xv7-gmf4-mjpg/GHSA-4xv7-gmf4-mjpg.json +++ b/advisories/unreviewed/2024/06/GHSA-4xv7-gmf4-mjpg/GHSA-4xv7-gmf4-mjpg.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-562p-f5h4-c4cw/GHSA-562p-f5h4-c4cw.json b/advisories/unreviewed/2024/06/GHSA-562p-f5h4-c4cw/GHSA-562p-f5h4-c4cw.json index fc49943bf16..8fb10abfaef 100644 --- a/advisories/unreviewed/2024/06/GHSA-562p-f5h4-c4cw/GHSA-562p-f5h4-c4cw.json +++ b/advisories/unreviewed/2024/06/GHSA-562p-f5h4-c4cw/GHSA-562p-f5h4-c4cw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-562p-f5h4-c4cw", - "modified": "2024-06-21T03:30:33Z", + "modified": "2024-08-23T03:30:59Z", "published": "2024-06-21T03:30:33Z", "aliases": [ "CVE-2024-6214" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/06/GHSA-5qjp-9vcm-q2j2/GHSA-5qjp-9vcm-q2j2.json b/advisories/unreviewed/2024/06/GHSA-5qjp-9vcm-q2j2/GHSA-5qjp-9vcm-q2j2.json index f3b822f82c3..c2cb2250ab2 100644 --- a/advisories/unreviewed/2024/06/GHSA-5qjp-9vcm-q2j2/GHSA-5qjp-9vcm-q2j2.json +++ b/advisories/unreviewed/2024/06/GHSA-5qjp-9vcm-q2j2/GHSA-5qjp-9vcm-q2j2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5qjp-9vcm-q2j2", - "modified": "2024-06-18T15:30:35Z", + "modified": "2024-08-23T03:30:59Z", "published": "2024-06-18T15:30:35Z", "aliases": [ "CVE-2024-6111" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/06/GHSA-628h-r6p2-r4vv/GHSA-628h-r6p2-r4vv.json b/advisories/unreviewed/2024/06/GHSA-628h-r6p2-r4vv/GHSA-628h-r6p2-r4vv.json index afe87709101..8358c6e6e0e 100644 --- a/advisories/unreviewed/2024/06/GHSA-628h-r6p2-r4vv/GHSA-628h-r6p2-r4vv.json +++ b/advisories/unreviewed/2024/06/GHSA-628h-r6p2-r4vv/GHSA-628h-r6p2-r4vv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-628h-r6p2-r4vv", - "modified": "2024-06-21T03:30:33Z", + "modified": "2024-08-23T03:30:59Z", "published": "2024-06-21T03:30:33Z", "aliases": [ "CVE-2024-6213" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/06/GHSA-6p38-mpcr-g57w/GHSA-6p38-mpcr-g57w.json b/advisories/unreviewed/2024/06/GHSA-6p38-mpcr-g57w/GHSA-6p38-mpcr-g57w.json index 45559790fe8..e652f2b836c 100644 --- a/advisories/unreviewed/2024/06/GHSA-6p38-mpcr-g57w/GHSA-6p38-mpcr-g57w.json +++ b/advisories/unreviewed/2024/06/GHSA-6p38-mpcr-g57w/GHSA-6p38-mpcr-g57w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6p38-mpcr-g57w", - "modified": "2024-06-18T15:30:35Z", + "modified": "2024-08-23T03:30:59Z", "published": "2024-06-18T15:30:35Z", "aliases": [ "CVE-2024-6112" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/06/GHSA-6v98-q8cq-9rx2/GHSA-6v98-q8cq-9rx2.json b/advisories/unreviewed/2024/06/GHSA-6v98-q8cq-9rx2/GHSA-6v98-q8cq-9rx2.json index f3520ff9d1d..ffec68d30ea 100644 --- a/advisories/unreviewed/2024/06/GHSA-6v98-q8cq-9rx2/GHSA-6v98-q8cq-9rx2.json +++ b/advisories/unreviewed/2024/06/GHSA-6v98-q8cq-9rx2/GHSA-6v98-q8cq-9rx2.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-c3qr-8rx9-m6r2/GHSA-c3qr-8rx9-m6r2.json b/advisories/unreviewed/2024/06/GHSA-c3qr-8rx9-m6r2/GHSA-c3qr-8rx9-m6r2.json index a04ddda7ef1..f3e46981150 100644 --- a/advisories/unreviewed/2024/06/GHSA-c3qr-8rx9-m6r2/GHSA-c3qr-8rx9-m6r2.json +++ b/advisories/unreviewed/2024/06/GHSA-c3qr-8rx9-m6r2/GHSA-c3qr-8rx9-m6r2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c3qr-8rx9-m6r2", - "modified": "2024-06-21T03:30:33Z", + "modified": "2024-08-23T03:30:59Z", "published": "2024-06-21T03:30:33Z", "aliases": [ "CVE-2024-6215" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/06/GHSA-j732-2x82-535h/GHSA-j732-2x82-535h.json b/advisories/unreviewed/2024/06/GHSA-j732-2x82-535h/GHSA-j732-2x82-535h.json index 5fed4e15258..bde6bcde6f6 100644 --- a/advisories/unreviewed/2024/06/GHSA-j732-2x82-535h/GHSA-j732-2x82-535h.json +++ b/advisories/unreviewed/2024/06/GHSA-j732-2x82-535h/GHSA-j732-2x82-535h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j732-2x82-535h", - "modified": "2024-06-11T06:31:47Z", + "modified": "2024-08-23T03:30:58Z", "published": "2024-06-11T06:31:47Z", "aliases": [ "CVE-2024-31402" ], "details": "Incorrect authorization vulnerability in Cybozu Garoon 5.0.0 to 5.15.2 allows a remote authenticated attacker to delete the data of Shared To-Dos.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-11T06:15:10Z" diff --git a/advisories/unreviewed/2024/06/GHSA-jwr6-46q6-xcr4/GHSA-jwr6-46q6-xcr4.json b/advisories/unreviewed/2024/06/GHSA-jwr6-46q6-xcr4/GHSA-jwr6-46q6-xcr4.json index cf415162dd4..b80b317fd9f 100644 --- a/advisories/unreviewed/2024/06/GHSA-jwr6-46q6-xcr4/GHSA-jwr6-46q6-xcr4.json +++ b/advisories/unreviewed/2024/06/GHSA-jwr6-46q6-xcr4/GHSA-jwr6-46q6-xcr4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jwr6-46q6-xcr4", - "modified": "2024-06-11T06:31:47Z", + "modified": "2024-08-23T03:30:57Z", "published": "2024-06-11T06:31:47Z", "aliases": [ "CVE-2024-31399" ], "details": "Excessive platform resource consumption within a loop issue exists in Cybozu Garoon 5.0.0 to 5.15.2. If this vulnerability is exploited, processing a crafted mail may cause a denial-of-service (DoS) condition.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-11T06:15:10Z" diff --git a/advisories/unreviewed/2024/06/GHSA-m9w6-r7wm-g37h/GHSA-m9w6-r7wm-g37h.json b/advisories/unreviewed/2024/06/GHSA-m9w6-r7wm-g37h/GHSA-m9w6-r7wm-g37h.json index e3c412aecc6..01367d9d906 100644 --- a/advisories/unreviewed/2024/06/GHSA-m9w6-r7wm-g37h/GHSA-m9w6-r7wm-g37h.json +++ b/advisories/unreviewed/2024/06/GHSA-m9w6-r7wm-g37h/GHSA-m9w6-r7wm-g37h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m9w6-r7wm-g37h", - "modified": "2024-06-18T15:30:35Z", + "modified": "2024-08-23T03:30:59Z", "published": "2024-06-18T15:30:35Z", "aliases": [ "CVE-2024-6115" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/06/GHSA-rwxj-58wx-7h6x/GHSA-rwxj-58wx-7h6x.json b/advisories/unreviewed/2024/06/GHSA-rwxj-58wx-7h6x/GHSA-rwxj-58wx-7h6x.json index ed6ec0433bd..d812ee392ec 100644 --- a/advisories/unreviewed/2024/06/GHSA-rwxj-58wx-7h6x/GHSA-rwxj-58wx-7h6x.json +++ b/advisories/unreviewed/2024/06/GHSA-rwxj-58wx-7h6x/GHSA-rwxj-58wx-7h6x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rwxj-58wx-7h6x", - "modified": "2024-06-21T03:30:33Z", + "modified": "2024-08-23T03:30:59Z", "published": "2024-06-21T03:30:33Z", "aliases": [ "CVE-2024-6217" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/06/GHSA-wx67-x394-5q2f/GHSA-wx67-x394-5q2f.json b/advisories/unreviewed/2024/06/GHSA-wx67-x394-5q2f/GHSA-wx67-x394-5q2f.json index 9f8d13a009f..1d1931e609c 100644 --- a/advisories/unreviewed/2024/06/GHSA-wx67-x394-5q2f/GHSA-wx67-x394-5q2f.json +++ b/advisories/unreviewed/2024/06/GHSA-wx67-x394-5q2f/GHSA-wx67-x394-5q2f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wx67-x394-5q2f", - "modified": "2024-08-19T06:30:52Z", + "modified": "2024-08-23T03:30:58Z", "published": "2024-06-11T15:31:15Z", "aliases": [ "CVE-2024-23111" diff --git a/advisories/unreviewed/2024/07/GHSA-22g4-7m96-g7pp/GHSA-22g4-7m96-g7pp.json b/advisories/unreviewed/2024/07/GHSA-22g4-7m96-g7pp/GHSA-22g4-7m96-g7pp.json index a19ce2d19bc..3900e5bfe56 100644 --- a/advisories/unreviewed/2024/07/GHSA-22g4-7m96-g7pp/GHSA-22g4-7m96-g7pp.json +++ b/advisories/unreviewed/2024/07/GHSA-22g4-7m96-g7pp/GHSA-22g4-7m96-g7pp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-22g4-7m96-g7pp", - "modified": "2024-07-30T21:31:27Z", + "modified": "2024-08-23T03:30:59Z", "published": "2024-07-30T21:31:27Z", "aliases": [ "CVE-2024-41437" ], "details": "A heap buffer overflow in the function cp_unfilter() (/vendor/cute_png.h) of hicolor v0.5.0 allows attackers to cause a Denial of Service (DoS) via a crafted PNG file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-30T19:15:10Z" diff --git a/advisories/unreviewed/2024/07/GHSA-h4gx-rc62-wcvc/GHSA-h4gx-rc62-wcvc.json b/advisories/unreviewed/2024/07/GHSA-h4gx-rc62-wcvc/GHSA-h4gx-rc62-wcvc.json index 2a676386f53..a812522f97d 100644 --- a/advisories/unreviewed/2024/07/GHSA-h4gx-rc62-wcvc/GHSA-h4gx-rc62-wcvc.json +++ b/advisories/unreviewed/2024/07/GHSA-h4gx-rc62-wcvc/GHSA-h4gx-rc62-wcvc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h4gx-rc62-wcvc", - "modified": "2024-07-30T21:31:27Z", + "modified": "2024-08-23T03:30:59Z", "published": "2024-07-30T21:31:27Z", "aliases": [ "CVE-2024-41439" ], "details": "A heap buffer overflow in the function cp_block() (/vendor/cute_png.h) of hicolor v0.5.0 allows attackers to cause a Denial of Service (DoS) via a crafted PNG file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-30T19:15:11Z" diff --git a/advisories/unreviewed/2024/08/GHSA-23fw-5352-7h9v/GHSA-23fw-5352-7h9v.json b/advisories/unreviewed/2024/08/GHSA-23fw-5352-7h9v/GHSA-23fw-5352-7h9v.json new file mode 100644 index 00000000000..0722145dab9 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-23fw-5352-7h9v/GHSA-23fw-5352-7h9v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-23fw-5352-7h9v", + "modified": "2024-08-23T03:30:59Z", + "published": "2024-08-23T03:30:59Z", + "aliases": [ + "CVE-2024-43477" + ], + "details": "Improper access control in Decentralized Identity Services allows an unathenticated attacker to disable Verifiable ID's on another tenant.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43477" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43477" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-23T02:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-38qw-v9q4-hm9j/GHSA-38qw-v9q4-hm9j.json b/advisories/unreviewed/2024/08/GHSA-38qw-v9q4-hm9j/GHSA-38qw-v9q4-hm9j.json index cfe40616502..b681bc3a555 100644 --- a/advisories/unreviewed/2024/08/GHSA-38qw-v9q4-hm9j/GHSA-38qw-v9q4-hm9j.json +++ b/advisories/unreviewed/2024/08/GHSA-38qw-v9q4-hm9j/GHSA-38qw-v9q4-hm9j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-38qw-v9q4-hm9j", - "modified": "2024-08-22T06:30:29Z", + "modified": "2024-08-23T03:30:59Z", "published": "2024-08-22T06:30:29Z", "aliases": [ "CVE-2022-48931" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nconfigfs: fix a race in configfs_{,un}register_subsystem()\n\nWhen configfs_register_subsystem() or configfs_unregister_subsystem()\nis executing link_group() or unlink_group(),\nit is possible that two processes add or delete list concurrently.\nSome unfortunate interleavings of them can cause kernel panic.\n\nOne of cases is:\nA --> B --> C --> D\nA <-- B <-- C <-- D\n\n delete list_head *B | delete list_head *C\n--------------------------------|-----------------------------------\nconfigfs_unregister_subsystem | configfs_unregister_subsystem\n unlink_group | unlink_group\n unlink_obj | unlink_obj\n list_del_init | list_del_init\n __list_del_entry | __list_del_entry\n __list_del | __list_del\n // next == C |\n next->prev = prev |\n | next->prev = prev\n prev->next = next |\n | // prev == B\n | prev->next = next\n\nFix this by adding mutex when calling link_group() or unlink_group(),\nbut parent configfs_subsystem is NULL when config_item is root.\nSo I create a mutex configfs_subsystem_mutex.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-362" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-22T04:15:16Z" diff --git a/advisories/unreviewed/2024/08/GHSA-3r8w-q925-6wvv/GHSA-3r8w-q925-6wvv.json b/advisories/unreviewed/2024/08/GHSA-3r8w-q925-6wvv/GHSA-3r8w-q925-6wvv.json index a07b2784fa1..c2dae86693c 100644 --- a/advisories/unreviewed/2024/08/GHSA-3r8w-q925-6wvv/GHSA-3r8w-q925-6wvv.json +++ b/advisories/unreviewed/2024/08/GHSA-3r8w-q925-6wvv/GHSA-3r8w-q925-6wvv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3r8w-q925-6wvv", - "modified": "2024-08-22T03:31:34Z", + "modified": "2024-08-23T03:30:59Z", "published": "2024-08-22T03:31:34Z", "aliases": [ "CVE-2022-48925" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/cma: Do not change route.addr.src_addr outside state checks\n\nIf the state is not idle then resolve_prepare_src() should immediately\nfail and no change to global state should happen. However, it\nunconditionally overwrites the src_addr trying to build a temporary any\naddress.\n\nFor instance if the state is already RDMA_CM_LISTEN then this will corrupt\nthe src_addr and would cause the test in cma_cancel_operation():\n\n if (cma_any_addr(cma_src_addr(id_priv)) && !id_priv->cma_dev)\n\nWhich would manifest as this trace from syzkaller:\n\n BUG: KASAN: use-after-free in __list_add_valid+0x93/0xa0 lib/list_debug.c:26\n Read of size 8 at addr ffff8881546491e0 by task syz-executor.1/32204\n\n CPU: 1 PID: 32204 Comm: syz-executor.1 Not tainted 5.12.0-rc8-syzkaller #0\n Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011\n Call Trace:\n __dump_stack lib/dump_stack.c:79 [inline]\n dump_stack+0x141/0x1d7 lib/dump_stack.c:120\n print_address_description.constprop.0.cold+0x5b/0x2f8 mm/kasan/report.c:232\n __kasan_report mm/kasan/report.c:399 [inline]\n kasan_report.cold+0x7c/0xd8 mm/kasan/report.c:416\n __list_add_valid+0x93/0xa0 lib/list_debug.c:26\n __list_add include/linux/list.h:67 [inline]\n list_add_tail include/linux/list.h:100 [inline]\n cma_listen_on_all drivers/infiniband/core/cma.c:2557 [inline]\n rdma_listen+0x787/0xe00 drivers/infiniband/core/cma.c:3751\n ucma_listen+0x16a/0x210 drivers/infiniband/core/ucma.c:1102\n ucma_write+0x259/0x350 drivers/infiniband/core/ucma.c:1732\n vfs_write+0x28e/0xa30 fs/read_write.c:603\n ksys_write+0x1ee/0x250 fs/read_write.c:658\n do_syscall_64+0x2d/0x70 arch/x86/entry/common.c:46\n entry_SYSCALL_64_after_hwframe+0x44/0xae\n\nThis is indicating that an rdma_id_private was destroyed without doing\ncma_cancel_listens().\n\nInstead of trying to re-use the src_addr memory to indirectly create an\nany address derived from the dst build one explicitly on the stack and\nbind to that as any other normal flow would do. rdma_bind_addr() will copy\nit over the src_addr once it knows the state is valid.\n\nThis is similar to commit bc0bdc5afaa7 (\"RDMA/cma: Do not change\nroute.addr.src_addr.ss_family\")", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-22T02:15:08Z" diff --git a/advisories/unreviewed/2024/08/GHSA-4qph-c4vr-m25p/GHSA-4qph-c4vr-m25p.json b/advisories/unreviewed/2024/08/GHSA-4qph-c4vr-m25p/GHSA-4qph-c4vr-m25p.json index 8ff1e77397e..da81e60fc4b 100644 --- a/advisories/unreviewed/2024/08/GHSA-4qph-c4vr-m25p/GHSA-4qph-c4vr-m25p.json +++ b/advisories/unreviewed/2024/08/GHSA-4qph-c4vr-m25p/GHSA-4qph-c4vr-m25p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4qph-c4vr-m25p", - "modified": "2024-08-22T06:30:29Z", + "modified": "2024-08-23T03:30:59Z", "published": "2024-08-22T06:30:29Z", "aliases": [ "CVE-2022-48935" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: unregister flowtable hooks on netns exit\n\nUnregister flowtable hooks before they are releases via\nnf_tables_flowtable_destroy() otherwise hook core reports UAF.\n\nBUG: KASAN: use-after-free in nf_hook_entries_grow+0x5a7/0x700 net/netfilter/core.c:142 net/netfilter/core.c:142\nRead of size 4 at addr ffff8880736f7438 by task syz-executor579/3666\n\nCPU: 0 PID: 3666 Comm: syz-executor579 Not tainted 5.16.0-rc5-syzkaller #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011\nCall Trace:\n \n __dump_stack lib/dump_stack.c:88 [inline]\n __dump_stack lib/dump_stack.c:88 [inline] lib/dump_stack.c:106\n dump_stack_lvl+0x1dc/0x2d8 lib/dump_stack.c:106 lib/dump_stack.c:106\n print_address_description+0x65/0x380 mm/kasan/report.c:247 mm/kasan/report.c:247\n __kasan_report mm/kasan/report.c:433 [inline]\n __kasan_report mm/kasan/report.c:433 [inline] mm/kasan/report.c:450\n kasan_report+0x19a/0x1f0 mm/kasan/report.c:450 mm/kasan/report.c:450\n nf_hook_entries_grow+0x5a7/0x700 net/netfilter/core.c:142 net/netfilter/core.c:142\n __nf_register_net_hook+0x27e/0x8d0 net/netfilter/core.c:429 net/netfilter/core.c:429\n nf_register_net_hook+0xaa/0x180 net/netfilter/core.c:571 net/netfilter/core.c:571\n nft_register_flowtable_net_hooks+0x3c5/0x730 net/netfilter/nf_tables_api.c:7232 net/netfilter/nf_tables_api.c:7232\n nf_tables_newflowtable+0x2022/0x2cf0 net/netfilter/nf_tables_api.c:7430 net/netfilter/nf_tables_api.c:7430\n nfnetlink_rcv_batch net/netfilter/nfnetlink.c:513 [inline]\n nfnetlink_rcv_skb_batch net/netfilter/nfnetlink.c:634 [inline]\n nfnetlink_rcv_batch net/netfilter/nfnetlink.c:513 [inline] net/netfilter/nfnetlink.c:652\n nfnetlink_rcv_skb_batch net/netfilter/nfnetlink.c:634 [inline] net/netfilter/nfnetlink.c:652\n nfnetlink_rcv+0x10e6/0x2550 net/netfilter/nfnetlink.c:652 net/netfilter/nfnetlink.c:652\n\n__nft_release_hook() calls nft_unregister_flowtable_net_hooks() which\nonly unregisters the hooks, then after RCU grace period, it is\nguaranteed that no packets add new entries to the flowtable (no flow\noffload rules and flowtable hooks are reachable from packet path), so it\nis safe to call nf_flow_table_free() which cleans up the remaining\nentries from the flowtable (both software and hardware) and it unbinds\nthe flow_block.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-22T04:15:16Z" diff --git a/advisories/unreviewed/2024/08/GHSA-5752-wxxv-m9xh/GHSA-5752-wxxv-m9xh.json b/advisories/unreviewed/2024/08/GHSA-5752-wxxv-m9xh/GHSA-5752-wxxv-m9xh.json index 35db83f68fa..0cbd4851d60 100644 --- a/advisories/unreviewed/2024/08/GHSA-5752-wxxv-m9xh/GHSA-5752-wxxv-m9xh.json +++ b/advisories/unreviewed/2024/08/GHSA-5752-wxxv-m9xh/GHSA-5752-wxxv-m9xh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5752-wxxv-m9xh", - "modified": "2024-08-22T06:30:29Z", + "modified": "2024-08-23T03:30:59Z", "published": "2024-08-22T06:30:29Z", "aliases": [ "CVE-2022-48929" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix crash due to out of bounds access into reg2btf_ids.\n\nWhen commit e6ac2450d6de (\"bpf: Support bpf program calling kernel function\") added\nkfunc support, it defined reg2btf_ids as a cheap way to translate the verifier\nreg type to the appropriate btf_vmlinux BTF ID, however\ncommit c25b2ae13603 (\"bpf: Replace PTR_TO_XXX_OR_NULL with PTR_TO_XXX | PTR_MAYBE_NULL\")\nmoved the __BPF_REG_TYPE_MAX from the last member of bpf_reg_type enum to after\nthe base register types, and defined other variants using type flag\ncomposition. However, now, the direct usage of reg->type to index into\nreg2btf_ids may no longer fall into __BPF_REG_TYPE_MAX range, and hence lead to\nout of bounds access and kernel crash on dereference of bad pointer.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-22T04:15:15Z" diff --git a/advisories/unreviewed/2024/08/GHSA-92cr-jqq3-99x4/GHSA-92cr-jqq3-99x4.json b/advisories/unreviewed/2024/08/GHSA-92cr-jqq3-99x4/GHSA-92cr-jqq3-99x4.json index f3a03d7bda6..1ef9a7397be 100644 --- a/advisories/unreviewed/2024/08/GHSA-92cr-jqq3-99x4/GHSA-92cr-jqq3-99x4.json +++ b/advisories/unreviewed/2024/08/GHSA-92cr-jqq3-99x4/GHSA-92cr-jqq3-99x4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-92cr-jqq3-99x4", - "modified": "2024-08-22T06:30:29Z", + "modified": "2024-08-23T03:30:59Z", "published": "2024-08-22T06:30:29Z", "aliases": [ "CVE-2022-48933" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: fix memory leak during stateful obj update\n\nstateful objects can be updated from the control plane.\nThe transaction logic allocates a temporary object for this purpose.\n\nThe ->init function was called for this object, so plain kfree() leaks\nresources. We must call ->destroy function of the object.\n\nnft_obj_destroy does this, but it also decrements the module refcount,\nbut the update path doesn't increment it.\n\nTo avoid special-casing the update object release, do module_get for\nthe update case too and release it via nft_obj_destroy().", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-401" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-22T04:15:16Z" diff --git a/advisories/unreviewed/2024/08/GHSA-95mr-34pq-hc3c/GHSA-95mr-34pq-hc3c.json b/advisories/unreviewed/2024/08/GHSA-95mr-34pq-hc3c/GHSA-95mr-34pq-hc3c.json index 4cd47c82bf2..652731fa401 100644 --- a/advisories/unreviewed/2024/08/GHSA-95mr-34pq-hc3c/GHSA-95mr-34pq-hc3c.json +++ b/advisories/unreviewed/2024/08/GHSA-95mr-34pq-hc3c/GHSA-95mr-34pq-hc3c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-95mr-34pq-hc3c", - "modified": "2024-08-22T06:30:29Z", + "modified": "2024-08-23T03:30:59Z", "published": "2024-08-22T06:30:29Z", "aliases": [ "CVE-2022-48930" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/ib_srp: Fix a deadlock\n\nRemove the flush_workqueue(system_long_wq) call since flushing\nsystem_long_wq is deadlock-prone and since that call is redundant with a\npreceding cancel_work_sync()", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-667" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-22T04:15:15Z" diff --git a/advisories/unreviewed/2024/08/GHSA-f8v3-3x87-4mpx/GHSA-f8v3-3x87-4mpx.json b/advisories/unreviewed/2024/08/GHSA-f8v3-3x87-4mpx/GHSA-f8v3-3x87-4mpx.json index 9f15df4a29d..641675343e4 100644 --- a/advisories/unreviewed/2024/08/GHSA-f8v3-3x87-4mpx/GHSA-f8v3-3x87-4mpx.json +++ b/advisories/unreviewed/2024/08/GHSA-f8v3-3x87-4mpx/GHSA-f8v3-3x87-4mpx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f8v3-3x87-4mpx", - "modified": "2024-08-22T06:30:28Z", + "modified": "2024-08-23T03:30:59Z", "published": "2024-08-22T06:30:28Z", "aliases": [ "CVE-2022-48927" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\niio: adc: tsc2046: fix memory corruption by preventing array overflow\n\nOn one side we have indio_dev->num_channels includes all physical channels +\ntimestamp channel. On other side we have an array allocated only for\nphysical channels. So, fix memory corruption by ARRAY_SIZE() instead of\nnum_channels variable.\n\nNote the first case is a cleanup rather than a fix as the software\ntimestamp channel bit in active_scanmask is never set by the IIO core.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-22T04:15:15Z" diff --git a/advisories/unreviewed/2024/08/GHSA-gc88-hrfw-f9hq/GHSA-gc88-hrfw-f9hq.json b/advisories/unreviewed/2024/08/GHSA-gc88-hrfw-f9hq/GHSA-gc88-hrfw-f9hq.json index 117c8faef44..d7bf6b9243d 100644 --- a/advisories/unreviewed/2024/08/GHSA-gc88-hrfw-f9hq/GHSA-gc88-hrfw-f9hq.json +++ b/advisories/unreviewed/2024/08/GHSA-gc88-hrfw-f9hq/GHSA-gc88-hrfw-f9hq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gc88-hrfw-f9hq", - "modified": "2024-08-22T06:30:28Z", + "modified": "2024-08-23T03:30:59Z", "published": "2024-08-22T06:30:28Z", "aliases": [ "CVE-2022-48926" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: rndis: add spinlock for rndis response list\n\nThere's no lock for rndis response list. It could cause list corruption\nif there're two different list_add at the same time like below.\nIt's better to add in rndis_add_response / rndis_free_response\n/ rndis_get_next_response to prevent any race condition on response list.\n\n[ 361.894299] [1: irq/191-dwc3:16979] list_add corruption.\nnext->prev should be prev (ffffff80651764d0),\nbut was ffffff883dc36f80. (next=ffffff80651764d0).\n\n[ 361.904380] [1: irq/191-dwc3:16979] Call trace:\n[ 361.904391] [1: irq/191-dwc3:16979] __list_add_valid+0x74/0x90\n[ 361.904401] [1: irq/191-dwc3:16979] rndis_msg_parser+0x168/0x8c0\n[ 361.904409] [1: irq/191-dwc3:16979] rndis_command_complete+0x24/0x84\n[ 361.904417] [1: irq/191-dwc3:16979] usb_gadget_giveback_request+0x20/0xe4\n[ 361.904426] [1: irq/191-dwc3:16979] dwc3_gadget_giveback+0x44/0x60\n[ 361.904434] [1: irq/191-dwc3:16979] dwc3_ep0_complete_data+0x1e8/0x3a0\n[ 361.904442] [1: irq/191-dwc3:16979] dwc3_ep0_interrupt+0x29c/0x3dc\n[ 361.904450] [1: irq/191-dwc3:16979] dwc3_process_event_entry+0x78/0x6cc\n[ 361.904457] [1: irq/191-dwc3:16979] dwc3_process_event_buf+0xa0/0x1ec\n[ 361.904465] [1: irq/191-dwc3:16979] dwc3_thread_interrupt+0x34/0x5c", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -55,7 +58,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-22T04:15:15Z" diff --git a/advisories/unreviewed/2024/08/GHSA-rc6x-q5fh-8f53/GHSA-rc6x-q5fh-8f53.json b/advisories/unreviewed/2024/08/GHSA-rc6x-q5fh-8f53/GHSA-rc6x-q5fh-8f53.json index b536eaf7cf1..7c310a3f07e 100644 --- a/advisories/unreviewed/2024/08/GHSA-rc6x-q5fh-8f53/GHSA-rc6x-q5fh-8f53.json +++ b/advisories/unreviewed/2024/08/GHSA-rc6x-q5fh-8f53/GHSA-rc6x-q5fh-8f53.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rc6x-q5fh-8f53", - "modified": "2024-08-22T06:30:28Z", + "modified": "2024-08-23T03:30:59Z", "published": "2024-08-22T06:30:28Z", "aliases": [ "CVE-2022-48928" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\niio: adc: men_z188_adc: Fix a resource leak in an error handling path\n\nIf iio_device_register() fails, a previous ioremap() is left unbalanced.\n\nUpdate the error handling path and add the missing iounmap() call, as\nalready done in the remove function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-401" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-22T04:15:15Z" diff --git a/advisories/unreviewed/2024/08/GHSA-v382-g65v-f2p8/GHSA-v382-g65v-f2p8.json b/advisories/unreviewed/2024/08/GHSA-v382-g65v-f2p8/GHSA-v382-g65v-f2p8.json new file mode 100644 index 00000000000..954b25845c1 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-v382-g65v-f2p8/GHSA-v382-g65v-f2p8.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v382-g65v-f2p8", + "modified": "2024-08-23T03:30:59Z", + "published": "2024-08-23T03:30:59Z", + "aliases": [ + "CVE-2024-7559" + ], + "details": "The File Manager Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and capability checks in the mk_file_folder_manager AJAX action in all versions up to, and including, 8.3.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7559" + }, + { + "type": "WEB", + "url": "https://filemanagerpro.io/file-manager-pro" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/f4b45791-4b85-4a2d-8019-1d438bd694cb?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-23T03:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-vpr7-cgq2-g5rr/GHSA-vpr7-cgq2-g5rr.json b/advisories/unreviewed/2024/08/GHSA-vpr7-cgq2-g5rr/GHSA-vpr7-cgq2-g5rr.json index 715ff64a934..c01a3102a3d 100644 --- a/advisories/unreviewed/2024/08/GHSA-vpr7-cgq2-g5rr/GHSA-vpr7-cgq2-g5rr.json +++ b/advisories/unreviewed/2024/08/GHSA-vpr7-cgq2-g5rr/GHSA-vpr7-cgq2-g5rr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vpr7-cgq2-g5rr", - "modified": "2024-08-22T06:30:29Z", + "modified": "2024-08-23T03:30:59Z", "published": "2024-08-22T06:30:29Z", "aliases": [ "CVE-2022-48932" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5: DR, Fix slab-out-of-bounds in mlx5_cmd_dr_create_fte\n\nWhen adding a rule with 32 destinations, we hit the following out-of-band\naccess issue:\n\n BUG: KASAN: slab-out-of-bounds in mlx5_cmd_dr_create_fte+0x18ee/0x1e70\n\nThis patch fixes the issue by both increasing the allocated buffers to\naccommodate for the needed actions and by checking the number of actions\nto prevent this issue when a rule with too many actions is provided.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-22T04:15:16Z"