Publish Advisories

GHSA-5p7x-xg54-cjrq
GHSA-6733-f273-8q48
GHSA-m658-5f72-86ff
GHSA-6cvp-282g-6jp8
GHSA-6w55-m9x6-7p2p
GHSA-94v3-rgqr-v5g3
GHSA-pf9m-g9g6-cphc
GHSA-vp7x-cv58-7w74
GHSA-7ph6-ch7r-f425
GHSA-cg3x-qc2c-6jq2
GHSA-gx25-vx95-m52w
GHSA-mj2x-c9j2-vp7g
GHSA-qx4x-h5xp-mmqx
This commit is contained in:
advisory-database[bot]
2024-08-09 18:32:23 +00:00
parent 2b765b6e14
commit 23f740f449
13 changed files with 114 additions and 37 deletions
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5p7x-xg54-cjrq",
"modified": "2024-02-26T18:30:31Z",
"modified": "2024-08-09T18:30:45Z",
"published": "2024-02-26T18:30:31Z",
"aliases": [
"CVE-2024-25770"
],
"details": "libming 0.4.8 contains a memory leak vulnerability in /libming/src/actioncompiler/listaction.c.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-401"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-26T18:15:07Z"
@@ -40,6 +40,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-122",
"CWE-787"
],
"severity": "MODERATE",
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m658-5f72-86ff",
"modified": "2024-02-21T09:31:00Z",
"modified": "2024-08-09T18:30:44Z",
"published": "2024-02-21T09:31:00Z",
"aliases": [
"CVE-2023-42838"
],
"details": "An access issue was addressed with improvements to the sandbox. This issue is fixed in macOS Ventura 13.6.3, macOS Sonoma 14.1, macOS Monterey 12.7.2. An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
}
],
"affected": [
@@ -33,9 +36,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-284"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-21T07:15:48Z"
@@ -56,7 +56,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-416"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6w55-m9x6-7p2p",
"modified": "2024-04-17T15:30:42Z",
"modified": "2024-08-09T18:30:45Z",
"published": "2024-04-17T15:30:42Z",
"aliases": [
"CVE-2024-32307"
],
"details": "Tenda FH1205 V2.0.0.7(775) firmware has a stack overflow vulnerability located via the PPW parameter in the fromWizardHandle function.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-121"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-17T13:15:08Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-94v3-rgqr-v5g3",
"modified": "2024-04-15T06:30:35Z",
"modified": "2024-08-09T18:30:45Z",
"published": "2024-04-15T06:30:35Z",
"aliases": [
"CVE-2024-32488"
],
"details": "In Foxit PDF Reader and Editor before 2024.1, Local Privilege Escalation could occur during update checks because weak permissions on the update-service folder allow attackers to place crafted DLL files there.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-280"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-15T06:15:07Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pf9m-g9g6-cphc",
"modified": "2024-05-07T00:30:34Z",
"modified": "2024-08-09T18:30:45Z",
"published": "2024-05-07T00:30:34Z",
"aliases": [
"CVE-2024-30973"
],
"details": "An issue in V-SOL G/EPON ONU HG323AC-B with firmware version V2.0.08-210715 allows an attacker to execute arbtirary code and obtain sensitive information via crafted POST request to /boaform/getASPdata/formFirewall, /boaform/getASPdata/formAcc.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-94"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-06T22:15:08Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vp7x-cv58-7w74",
"modified": "2024-07-30T03:30:51Z",
"modified": "2024-08-09T18:30:45Z",
"published": "2024-07-30T00:34:26Z",
"aliases": [
"CVE-2024-27877"
],
"details": "The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.6, macOS Monterey 12.7.6, macOS Ventura 13.6.8. Processing a maliciously crafted file may lead to a denial-of-service or potentially disclose memory contents.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"
}
],
"affected": [
@@ -47,7 +50,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-29T23:15:10Z"
@@ -0,0 +1,46 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7ph6-ch7r-f425",
"modified": "2024-08-09T18:30:44Z",
"published": "2024-08-09T18:30:44Z",
"aliases": [
"CVE-2024-23788"
],
"details": "Server-side request forgery vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to send an arbitrary HTTP request (GET) from the affected product.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23788"
},
{
"type": "WEB",
"url": "https://jp.sharp/support/taiyo/info/JVNVU94591337_en.pdf"
},
{
"type": "WEB",
"url": "https://jp.sharp/support/taiyo/info/JVNVU94591337_jp.pdf"
},
{
"type": "WEB",
"url": "https://jvn.jp/en/vu/JVNVU94591337"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-14T10:15:08Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cg3x-qc2c-6jq2",
"modified": "2024-08-08T00:31:44Z",
"modified": "2024-08-09T18:30:45Z",
"published": "2024-08-08T00:31:44Z",
"aliases": [
"CVE-2024-6892"
],
"details": "Attackers can craft a malicious link that once clicked will execute arbitrary JavaScript in the context of the Journyx web application.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
"CWE-81"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-08T00:15:40Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gx25-vx95-m52w",
"modified": "2024-08-07T00:30:47Z",
"modified": "2024-08-09T18:30:45Z",
"published": "2024-08-06T15:30:54Z",
"aliases": [
"CVE-2024-7528"
],
"details": "Incorrect garbage collection interaction in IndexedDB could have led to a use-after-free. This vulnerability affects Firefox < 129 and Firefox ESR < 128.1.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -37,9 +40,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-416"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-06T13:15:57Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mj2x-c9j2-vp7g",
"modified": "2024-08-08T18:31:20Z",
"modified": "2024-08-09T18:30:45Z",
"published": "2024-08-08T18:31:20Z",
"aliases": [
"CVE-2023-40261"
],
"details": "Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR17, 4.0.0 SR07, 4.1.0 SR04, 4.2.0 SR04, and 4.3.0 SR03 fails to validate file attributes during the Pre-Boot Authorization (PBA) process. This can be exploited by a physical attacker who is able to manipulate the contents of the system's hard disk.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
}
],
"affected": [
@@ -31,7 +34,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-08T18:15:09Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qx4x-h5xp-mmqx",
"modified": "2024-08-08T18:31:20Z",
"modified": "2024-08-09T18:30:45Z",
"published": "2024-08-08T18:31:20Z",
"aliases": [
"CVE-2023-24064"
],
"details": "Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR4 fails to validate /etc/initab during the Pre-Boot Authorization (PBA) process. This can be exploited by a physical attacker who is able to manipulate the contents of the system's hard disk.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -31,7 +34,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-08T18:15:09Z"