diff --git a/advisories/github-reviewed/2023/11/GHSA-gfw2-4jvh-wgfg/GHSA-gfw2-4jvh-wgfg.json b/advisories/github-reviewed/2023/11/GHSA-gfw2-4jvh-wgfg/GHSA-gfw2-4jvh-wgfg.json index 9bc272e6477..f690b08fbd0 100644 --- a/advisories/github-reviewed/2023/11/GHSA-gfw2-4jvh-wgfg/GHSA-gfw2-4jvh-wgfg.json +++ b/advisories/github-reviewed/2023/11/GHSA-gfw2-4jvh-wgfg/GHSA-gfw2-4jvh-wgfg.json @@ -60,6 +60,10 @@ "type": "WEB", "url": "https://github.com/pypa/advisory-database/tree/main/vulns/aiohttp/PYSEC-2023-246.yaml" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FUSJVQ7OQ55RWL4XAX2F5EZ73N4ZSH6U/" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VDKQ6HM3KNDU4OQI476ZWT4O7DMSIT35/" diff --git a/advisories/unreviewed/2023/11/GHSA-xgr2-4f4q-m3p9/GHSA-xgr2-4f4q-m3p9.json b/advisories/unreviewed/2023/11/GHSA-xgr2-4f4q-m3p9/GHSA-xgr2-4f4q-m3p9.json index c4072c1f062..9e8a62f0801 100644 --- a/advisories/unreviewed/2023/11/GHSA-xgr2-4f4q-m3p9/GHSA-xgr2-4f4q-m3p9.json +++ b/advisories/unreviewed/2023/11/GHSA-xgr2-4f4q-m3p9/GHSA-xgr2-4f4q-m3p9.json @@ -29,6 +29,14 @@ "type": "WEB", "url": "https://kernel.dance/93995bf4af2c5a99e2a87f0cd5ce547d31eb7630" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3OXWBKK7RTQOGGDLQGCZFS753VLGS2GD/" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3S55P23EYAWDHXZPJEVTGIRZZRICYI3Z/" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IG6IF3FUY7LVZJMFRPANAU4L4PSJ3ESQ/" diff --git a/advisories/unreviewed/2023/12/GHSA-96fh-9q43-rmjh/GHSA-96fh-9q43-rmjh.json b/advisories/unreviewed/2023/12/GHSA-96fh-9q43-rmjh/GHSA-96fh-9q43-rmjh.json index 5f5268b6185..51ec54955dc 100644 --- a/advisories/unreviewed/2023/12/GHSA-96fh-9q43-rmjh/GHSA-96fh-9q43-rmjh.json +++ b/advisories/unreviewed/2023/12/GHSA-96fh-9q43-rmjh/GHSA-96fh-9q43-rmjh.json @@ -32,6 +32,10 @@ { "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2249523" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GNEEWAACXQCEEAKSG7XX2D5YDRWLCIZJ/" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/02/GHSA-3x87-pjpc-6c9c/GHSA-3x87-pjpc-6c9c.json b/advisories/unreviewed/2024/02/GHSA-3x87-pjpc-6c9c/GHSA-3x87-pjpc-6c9c.json new file mode 100644 index 00000000000..cc38cf33c2b --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-3x87-pjpc-6c9c/GHSA-3x87-pjpc-6c9c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3x87-pjpc-6c9c", + "modified": "2024-02-05T09:30:28Z", + "published": "2024-02-05T09:30:28Z", + "aliases": [ + "CVE-2024-24864" + ], + "details": "A race condition was found in the Linux kernel's media/dvb-core in dvbdmx_write() function. This can result in a null pointer dereference issue, possibly leading to a kernel panic or denial of service issue.\n\n\n\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24864" + }, + { + "type": "WEB", + "url": "https://bugzilla.openanolis.cn/show_bug.cgi?id=8178" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-362" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-05T08:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-4fvp-9cw7-vhmc/GHSA-4fvp-9cw7-vhmc.json b/advisories/unreviewed/2024/02/GHSA-4fvp-9cw7-vhmc/GHSA-4fvp-9cw7-vhmc.json new file mode 100644 index 00000000000..29edda1bb47 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-4fvp-9cw7-vhmc/GHSA-4fvp-9cw7-vhmc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4fvp-9cw7-vhmc", + "modified": "2024-02-05T09:30:28Z", + "published": "2024-02-05T09:30:28Z", + "aliases": [ + "CVE-2024-24846" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MightyThemes Mighty Addons for Elementor allows Reflected XSS.This issue affects Mighty Addons for Elementor: from n/a through 1.9.3.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24846" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/mighty-addons/wordpress-mighty-addons-for-elementor-plugin-1-9-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-05T07:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-4x63-78pq-hqc9/GHSA-4x63-78pq-hqc9.json b/advisories/unreviewed/2024/02/GHSA-4x63-78pq-hqc9/GHSA-4x63-78pq-hqc9.json new file mode 100644 index 00000000000..e752cd73809 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-4x63-78pq-hqc9/GHSA-4x63-78pq-hqc9.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4x63-78pq-hqc9", + "modified": "2024-02-05T09:30:28Z", + "published": "2024-02-05T09:30:28Z", + "aliases": [ + "CVE-2023-7077" + ], + "details": "Sharp NEC Displays (P403, P463, P553, P703, P801, X554UN, X464UN, X554UNS, X464UNV, X474HB, X464UNS, X554UNV, X555UNS, X555UNV, X754HB, X554HB, E705, E805, E905, UN551S, UN551VS, X551UHD, X651UHD, X841UHD, X981UHD, MD551C8) allows an attacker execute remote code by sending unintended parameters in http request.\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-7077" + }, + { + "type": "WEB", + "url": "https://www.sharp-nec-displays.com/global/support/info/A4_vulnerability.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-05T07:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-56w6-jjc5-f5mr/GHSA-56w6-jjc5-f5mr.json b/advisories/unreviewed/2024/02/GHSA-56w6-jjc5-f5mr/GHSA-56w6-jjc5-f5mr.json new file mode 100644 index 00000000000..6a33ac31f70 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-56w6-jjc5-f5mr/GHSA-56w6-jjc5-f5mr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-56w6-jjc5-f5mr", + "modified": "2024-02-05T09:30:28Z", + "published": "2024-02-05T09:30:28Z", + "aliases": [ + "CVE-2024-24858" + ], + "details": "A race condition was found in the Linux kernel's net/bluetooth in {conn,adv}_{min,max}_interval_set() function. This can result in I2cap connection or broadcast abnormality issue, possibly leading to denial of service.\n\n\n\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24858" + }, + { + "type": "WEB", + "url": "https://bugzilla.openanolis.cn/show_bug.cgi?id=8154" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-362" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-05T08:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-5v8x-xh64-m4xp/GHSA-5v8x-xh64-m4xp.json b/advisories/unreviewed/2024/02/GHSA-5v8x-xh64-m4xp/GHSA-5v8x-xh64-m4xp.json new file mode 100644 index 00000000000..14811b067a8 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-5v8x-xh64-m4xp/GHSA-5v8x-xh64-m4xp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5v8x-xh64-m4xp", + "modified": "2024-02-05T09:30:28Z", + "published": "2024-02-05T09:30:28Z", + "aliases": [ + "CVE-2024-24855" + ], + "details": "A race condition was found in the Linux kernel's scsi device driver in lpfc_unregister_fcf_rescan() function. This can result in a null pointer dereference issue, possibly leading to a kernel panic or denial of service issue.\n\n\n\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24855" + }, + { + "type": "WEB", + "url": "https://bugzilla.openanolis.cn/show_bug.cgi?id=8149" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-362" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-05T08:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-67ph-hcx9-mvwp/GHSA-67ph-hcx9-mvwp.json b/advisories/unreviewed/2024/02/GHSA-67ph-hcx9-mvwp/GHSA-67ph-hcx9-mvwp.json new file mode 100644 index 00000000000..2c48cbc142e --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-67ph-hcx9-mvwp/GHSA-67ph-hcx9-mvwp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-67ph-hcx9-mvwp", + "modified": "2024-02-05T09:30:28Z", + "published": "2024-02-05T09:30:28Z", + "aliases": [ + "CVE-2024-24841" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dan's Art Add Customer for WooCommerce allows Stored XSS.This issue affects Add Customer for WooCommerce: from n/a through 1.7.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24841" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/add-customer-for-woocommerce/wordpress-add-customer-for-woocommerce-plugin-1-7-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-05T07:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-75pw-9w79-3j7q/GHSA-75pw-9w79-3j7q.json b/advisories/unreviewed/2024/02/GHSA-75pw-9w79-3j7q/GHSA-75pw-9w79-3j7q.json new file mode 100644 index 00000000000..ebd01d1c4f7 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-75pw-9w79-3j7q/GHSA-75pw-9w79-3j7q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-75pw-9w79-3j7q", + "modified": "2024-02-05T09:30:28Z", + "published": "2024-02-05T09:30:28Z", + "aliases": [ + "CVE-2024-24839" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Gordon Böhme, Antonio Leutsch Structured Content (JSON-LD) #wpsc allows Stored XSS.This issue affects Structured Content (JSON-LD) #wpsc: from n/a through 1.6.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24839" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/structured-content/wordpress-structured-content-json-ld-plugin-1-6-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-05T07:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-8j45-r236-3q9q/GHSA-8j45-r236-3q9q.json b/advisories/unreviewed/2024/02/GHSA-8j45-r236-3q9q/GHSA-8j45-r236-3q9q.json new file mode 100644 index 00000000000..8588b4a5e4c --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-8j45-r236-3q9q/GHSA-8j45-r236-3q9q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8j45-r236-3q9q", + "modified": "2024-02-05T09:30:28Z", + "published": "2024-02-05T09:30:28Z", + "aliases": [ + "CVE-2024-24859" + ], + "details": "A race condition was found in the Linux kernel's net/bluetooth in sniff_{min,max}_interval_set() function. This can result in a bluetooth sniffing exception issue, possibly leading denial of service.\n\n\n\n\n\n\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24859" + }, + { + "type": "WEB", + "url": "https://bugzilla.openanolis.cn/show_bug.cgi?id=8153" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-362" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-05T08:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-9jpc-6xx4-mc82/GHSA-9jpc-6xx4-mc82.json b/advisories/unreviewed/2024/02/GHSA-9jpc-6xx4-mc82/GHSA-9jpc-6xx4-mc82.json new file mode 100644 index 00000000000..454b19bd00c --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-9jpc-6xx4-mc82/GHSA-9jpc-6xx4-mc82.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9jpc-6xx4-mc82", + "modified": "2024-02-05T09:30:28Z", + "published": "2024-02-05T09:30:28Z", + "aliases": [ + "CVE-2024-24848" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MJS Software PT Sign Ups – Beautiful volunteer sign ups and management made easy allows Stored XSS.This issue affects PT Sign Ups – Beautiful volunteer sign ups and management made easy: from n/a through 1.0.4.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24848" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/ptoffice-sign-ups/wordpress-pt-sign-ups-plugin-1-0-4-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-05T07:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-c4c9-rwvw-5wrf/GHSA-c4c9-rwvw-5wrf.json b/advisories/unreviewed/2024/02/GHSA-c4c9-rwvw-5wrf/GHSA-c4c9-rwvw-5wrf.json new file mode 100644 index 00000000000..b8411bf5b29 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-c4c9-rwvw-5wrf/GHSA-c4c9-rwvw-5wrf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c4c9-rwvw-5wrf", + "modified": "2024-02-05T09:30:28Z", + "published": "2024-02-05T09:30:28Z", + "aliases": [ + "CVE-2024-22386" + ], + "details": "A race condition was found in the Linux kernel's drm/exynos device driver in exynos_drm_crtc_atomic_disable() function. This can result in a null pointer dereference issue, possibly leading to a kernel panic or denial of service issue.\n\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22386" + }, + { + "type": "WEB", + "url": "https://bugzilla.openanolis.cn/show_bug.cgi?id=8147" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-362" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-05T08:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-cvpw-2w45-gm65/GHSA-cvpw-2w45-gm65.json b/advisories/unreviewed/2024/02/GHSA-cvpw-2w45-gm65/GHSA-cvpw-2w45-gm65.json new file mode 100644 index 00000000000..37223518b5e --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-cvpw-2w45-gm65/GHSA-cvpw-2w45-gm65.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cvpw-2w45-gm65", + "modified": "2024-02-05T09:30:28Z", + "published": "2024-02-05T09:30:28Z", + "aliases": [ + "CVE-2024-24861" + ], + "details": "A race condition was found in the Linux kernel's media/xc4000 device driver in xc4000 xc4000_get_frequency() function. This can result in return value overflow issue, possibly leading to malfunction or denial of service issue.\n\n\n\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24861" + }, + { + "type": "WEB", + "url": "https://bugzilla.openanolis.cn/show_bug.cgi?id=8150" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-362" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-05T08:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-g6mc-rm4g-xf26/GHSA-g6mc-rm4g-xf26.json b/advisories/unreviewed/2024/02/GHSA-g6mc-rm4g-xf26/GHSA-g6mc-rm4g-xf26.json new file mode 100644 index 00000000000..6c82f54d6b5 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-g6mc-rm4g-xf26/GHSA-g6mc-rm4g-xf26.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g6mc-rm4g-xf26", + "modified": "2024-02-05T09:30:28Z", + "published": "2024-02-05T09:30:28Z", + "aliases": [ + "CVE-2024-24847" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jgadbois CalculatorPro Calculators allows Reflected XSS.This issue affects CalculatorPro Calculators: from n/a through 1.1.7.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24847" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/calculatorpro-calculators/wordpress-calculatorpro-calculators-plugin-1-1-7-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-05T07:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-gm68-3cj6-qp9p/GHSA-gm68-3cj6-qp9p.json b/advisories/unreviewed/2024/02/GHSA-gm68-3cj6-qp9p/GHSA-gm68-3cj6-qp9p.json new file mode 100644 index 00000000000..ac97e8c1861 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-gm68-3cj6-qp9p/GHSA-gm68-3cj6-qp9p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gm68-3cj6-qp9p", + "modified": "2024-02-05T09:30:28Z", + "published": "2024-02-05T09:30:28Z", + "aliases": [ + "CVE-2024-23196" + ], + "details": "A race condition was found in the Linux kernel's sound/hda device driver in snd_hdac_regmap_sync() function. This can result in a null pointer dereference issue, possibly leading to a kernel panic or denial of service issue.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23196" + }, + { + "type": "WEB", + "url": "https://bugzilla.openanolis.cn/show_bug.cgi?id=8148" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-362" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-05T08:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-jhwv-44fv-jwp5/GHSA-jhwv-44fv-jwp5.json b/advisories/unreviewed/2024/02/GHSA-jhwv-44fv-jwp5/GHSA-jhwv-44fv-jwp5.json new file mode 100644 index 00000000000..c0de923bee3 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-jhwv-44fv-jwp5/GHSA-jhwv-44fv-jwp5.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jhwv-44fv-jwp5", + "modified": "2024-02-05T09:30:28Z", + "published": "2024-02-05T09:30:28Z", + "aliases": [ + "CVE-2024-22667" + ], + "details": "Vim before 9.0.2142 has a stack-based buffer overflow because did_set_langmap in map.c calls sprintf to write to the error buffer that is passed down to the option callback functions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22667" + }, + { + "type": "WEB", + "url": "https://github.com/vim/vim/commit/b39b240c386a5a29241415541f1c99e2e6b8ce47" + }, + { + "type": "WEB", + "url": "https://gist.githubusercontent.com/henices/2467e7f22dcc2aa97a2453e197b55a0c/raw/7b54bccc9a129c604fb139266f4497ab7aaa94c7/gistfile1.txt" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-05T08:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-p453-6h64-wr8m/GHSA-p453-6h64-wr8m.json b/advisories/unreviewed/2024/02/GHSA-p453-6h64-wr8m/GHSA-p453-6h64-wr8m.json new file mode 100644 index 00000000000..1a4625594b8 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-p453-6h64-wr8m/GHSA-p453-6h64-wr8m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p453-6h64-wr8m", + "modified": "2024-02-05T09:30:28Z", + "published": "2024-02-05T09:30:28Z", + "aliases": [ + "CVE-2024-24857" + ], + "details": "A race condition was found in the Linux kernel's net/bluetooth device driver in conn_info_{min,max}_age_set() function. This can result in integrity overflow issue, possibly leading to bluetooth connection abnormality or denial of service.\n\n\n\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:N/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24857" + }, + { + "type": "WEB", + "url": "https://bugzilla.openanolis.cn/show_bug.cgi?id=8155" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-362" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-05T08:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-pv6w-6xw6-fcqg/GHSA-pv6w-6xw6-fcqg.json b/advisories/unreviewed/2024/02/GHSA-pv6w-6xw6-fcqg/GHSA-pv6w-6xw6-fcqg.json new file mode 100644 index 00000000000..c067fa04afe --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-pv6w-6xw6-fcqg/GHSA-pv6w-6xw6-fcqg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pv6w-6xw6-fcqg", + "modified": "2024-02-05T09:30:28Z", + "published": "2024-02-05T09:30:28Z", + "aliases": [ + "CVE-2024-24865" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Noah Kagan Scroll Triggered Box allows Stored XSS.This issue affects Scroll Triggered Box: from n/a through 2.3.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24865" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/dreamgrow-scroll-triggered-box/wordpress-scroll-triggered-box-plugin-2-3-cross-site-scripting-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-05T07:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-v78v-jm8m-vmmw/GHSA-v78v-jm8m-vmmw.json b/advisories/unreviewed/2024/02/GHSA-v78v-jm8m-vmmw/GHSA-v78v-jm8m-vmmw.json new file mode 100644 index 00000000000..d8d42e0d54f --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-v78v-jm8m-vmmw/GHSA-v78v-jm8m-vmmw.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v78v-jm8m-vmmw", + "modified": "2024-02-05T09:30:29Z", + "published": "2024-02-05T09:30:29Z", + "aliases": [ + "CVE-2021-4436" + ], + "details": "The 3DPrint Lite WordPress plugin before 1.9.1.5 does not have any authorisation and does not check the uploaded file in its p3dlite_handle_upload AJAX action , allowing unauthenticated users to upload arbitrary file to the web server. However, there is a .htaccess, preventing the file to be accessed on Web servers such as Apache.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-4436" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/c46ecd0d-a132-4ad6-b936-8acde3a09282/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-05T09:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-vj2q-j7r5-rxmc/GHSA-vj2q-j7r5-rxmc.json b/advisories/unreviewed/2024/02/GHSA-vj2q-j7r5-rxmc/GHSA-vj2q-j7r5-rxmc.json new file mode 100644 index 00000000000..d3571441e78 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-vj2q-j7r5-rxmc/GHSA-vj2q-j7r5-rxmc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vj2q-j7r5-rxmc", + "modified": "2024-02-05T09:30:28Z", + "published": "2024-02-05T09:30:28Z", + "aliases": [ + "CVE-2024-24860" + ], + "details": "A race condition was found in the Linux kernel's bluetooth device driver in {min,max}_key_size_set() function. This can result in a null pointer dereference issue, possibly leading to a kernel panic or denial of service issue.\n\n\n\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24860" + }, + { + "type": "WEB", + "url": "https://bugzilla.openanolis.cn/show_bug.cgi?id=8151" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-362" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-05T08:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-w6f5-cfrr-rg5r/GHSA-w6f5-cfrr-rg5r.json b/advisories/unreviewed/2024/02/GHSA-w6f5-cfrr-rg5r/GHSA-w6f5-cfrr-rg5r.json new file mode 100644 index 00000000000..48c25ae9720 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-w6f5-cfrr-rg5r/GHSA-w6f5-cfrr-rg5r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w6f5-cfrr-rg5r", + "modified": "2024-02-05T09:30:28Z", + "published": "2024-02-05T09:30:28Z", + "aliases": [ + "CVE-2024-24838" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Five Star Plugins Five Star Restaurant Reviews allows Stored XSS.This issue affects Five Star Restaurant Reviews: from n/a through 2.3.5.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24838" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/good-reviews-wp/wordpress-five-star-restaurant-reviews-plugin-2-3-5-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-05T07:15:10Z" + } +} \ No newline at end of file