diff --git a/advisories/unreviewed/2024/02/GHSA-5p7x-xg54-cjrq/GHSA-5p7x-xg54-cjrq.json b/advisories/unreviewed/2024/02/GHSA-5p7x-xg54-cjrq/GHSA-5p7x-xg54-cjrq.json index 728bb8e270c..d743e8710f5 100644 --- a/advisories/unreviewed/2024/02/GHSA-5p7x-xg54-cjrq/GHSA-5p7x-xg54-cjrq.json +++ b/advisories/unreviewed/2024/02/GHSA-5p7x-xg54-cjrq/GHSA-5p7x-xg54-cjrq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5p7x-xg54-cjrq", - "modified": "2024-02-26T18:30:31Z", + "modified": "2024-08-09T18:30:45Z", "published": "2024-02-26T18:30:31Z", "aliases": [ "CVE-2024-25770" ], "details": "libming 0.4.8 contains a memory leak vulnerability in /libming/src/actioncompiler/listaction.c.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-401" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-26T18:15:07Z" diff --git a/advisories/unreviewed/2024/02/GHSA-6733-f273-8q48/GHSA-6733-f273-8q48.json b/advisories/unreviewed/2024/02/GHSA-6733-f273-8q48/GHSA-6733-f273-8q48.json index ec04ff48893..60c1c4095aa 100644 --- a/advisories/unreviewed/2024/02/GHSA-6733-f273-8q48/GHSA-6733-f273-8q48.json +++ b/advisories/unreviewed/2024/02/GHSA-6733-f273-8q48/GHSA-6733-f273-8q48.json @@ -40,6 +40,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-122", "CWE-787" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/02/GHSA-m658-5f72-86ff/GHSA-m658-5f72-86ff.json b/advisories/unreviewed/2024/02/GHSA-m658-5f72-86ff/GHSA-m658-5f72-86ff.json index 3cbb073c2a8..0db7911fb71 100644 --- a/advisories/unreviewed/2024/02/GHSA-m658-5f72-86ff/GHSA-m658-5f72-86ff.json +++ b/advisories/unreviewed/2024/02/GHSA-m658-5f72-86ff/GHSA-m658-5f72-86ff.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m658-5f72-86ff", - "modified": "2024-02-21T09:31:00Z", + "modified": "2024-08-09T18:30:44Z", "published": "2024-02-21T09:31:00Z", "aliases": [ "CVE-2023-42838" ], "details": "An access issue was addressed with improvements to the sandbox. This issue is fixed in macOS Ventura 13.6.3, macOS Sonoma 14.1, macOS Monterey 12.7.2. An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-21T07:15:48Z" diff --git a/advisories/unreviewed/2024/03/GHSA-6cvp-282g-6jp8/GHSA-6cvp-282g-6jp8.json b/advisories/unreviewed/2024/03/GHSA-6cvp-282g-6jp8/GHSA-6cvp-282g-6jp8.json index dff4f336551..b9bbc18bfaf 100644 --- a/advisories/unreviewed/2024/03/GHSA-6cvp-282g-6jp8/GHSA-6cvp-282g-6jp8.json +++ b/advisories/unreviewed/2024/03/GHSA-6cvp-282g-6jp8/GHSA-6cvp-282g-6jp8.json @@ -56,7 +56,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-6w55-m9x6-7p2p/GHSA-6w55-m9x6-7p2p.json b/advisories/unreviewed/2024/04/GHSA-6w55-m9x6-7p2p/GHSA-6w55-m9x6-7p2p.json index 4ba59e47b86..66afa87b069 100644 --- a/advisories/unreviewed/2024/04/GHSA-6w55-m9x6-7p2p/GHSA-6w55-m9x6-7p2p.json +++ b/advisories/unreviewed/2024/04/GHSA-6w55-m9x6-7p2p/GHSA-6w55-m9x6-7p2p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6w55-m9x6-7p2p", - "modified": "2024-04-17T15:30:42Z", + "modified": "2024-08-09T18:30:45Z", "published": "2024-04-17T15:30:42Z", "aliases": [ "CVE-2024-32307" ], "details": "Tenda FH1205 V2.0.0.7(775) firmware has a stack overflow vulnerability located via the PPW parameter in the fromWizardHandle function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T13:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-94v3-rgqr-v5g3/GHSA-94v3-rgqr-v5g3.json b/advisories/unreviewed/2024/04/GHSA-94v3-rgqr-v5g3/GHSA-94v3-rgqr-v5g3.json index ac31c5715ab..8736b96a9a0 100644 --- a/advisories/unreviewed/2024/04/GHSA-94v3-rgqr-v5g3/GHSA-94v3-rgqr-v5g3.json +++ b/advisories/unreviewed/2024/04/GHSA-94v3-rgqr-v5g3/GHSA-94v3-rgqr-v5g3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-94v3-rgqr-v5g3", - "modified": "2024-04-15T06:30:35Z", + "modified": "2024-08-09T18:30:45Z", "published": "2024-04-15T06:30:35Z", "aliases": [ "CVE-2024-32488" ], "details": "In Foxit PDF Reader and Editor before 2024.1, Local Privilege Escalation could occur during update checks because weak permissions on the update-service folder allow attackers to place crafted DLL files there.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-280" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-15T06:15:07Z" diff --git a/advisories/unreviewed/2024/05/GHSA-pf9m-g9g6-cphc/GHSA-pf9m-g9g6-cphc.json b/advisories/unreviewed/2024/05/GHSA-pf9m-g9g6-cphc/GHSA-pf9m-g9g6-cphc.json index 8775190c18e..376dad7b3fd 100644 --- a/advisories/unreviewed/2024/05/GHSA-pf9m-g9g6-cphc/GHSA-pf9m-g9g6-cphc.json +++ b/advisories/unreviewed/2024/05/GHSA-pf9m-g9g6-cphc/GHSA-pf9m-g9g6-cphc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pf9m-g9g6-cphc", - "modified": "2024-05-07T00:30:34Z", + "modified": "2024-08-09T18:30:45Z", "published": "2024-05-07T00:30:34Z", "aliases": [ "CVE-2024-30973" ], "details": "An issue in V-SOL G/EPON ONU HG323AC-B with firmware version V2.0.08-210715 allows an attacker to execute arbtirary code and obtain sensitive information via crafted POST request to /boaform/getASPdata/formFirewall, /boaform/getASPdata/formAcc.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-06T22:15:08Z" diff --git a/advisories/unreviewed/2024/07/GHSA-vp7x-cv58-7w74/GHSA-vp7x-cv58-7w74.json b/advisories/unreviewed/2024/07/GHSA-vp7x-cv58-7w74/GHSA-vp7x-cv58-7w74.json index 5dfbf769a7a..f912bcf9fb9 100644 --- a/advisories/unreviewed/2024/07/GHSA-vp7x-cv58-7w74/GHSA-vp7x-cv58-7w74.json +++ b/advisories/unreviewed/2024/07/GHSA-vp7x-cv58-7w74/GHSA-vp7x-cv58-7w74.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vp7x-cv58-7w74", - "modified": "2024-07-30T03:30:51Z", + "modified": "2024-08-09T18:30:45Z", "published": "2024-07-30T00:34:26Z", "aliases": [ "CVE-2024-27877" ], "details": "The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.6, macOS Monterey 12.7.6, macOS Ventura 13.6.8. Processing a maliciously crafted file may lead to a denial-of-service or potentially disclose memory contents.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H" + } ], "affected": [ @@ -47,7 +50,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T23:15:10Z" diff --git a/advisories/unreviewed/2024/08/GHSA-7ph6-ch7r-f425/GHSA-7ph6-ch7r-f425.json b/advisories/unreviewed/2024/08/GHSA-7ph6-ch7r-f425/GHSA-7ph6-ch7r-f425.json new file mode 100644 index 00000000000..cb57da06555 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-7ph6-ch7r-f425/GHSA-7ph6-ch7r-f425.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7ph6-ch7r-f425", + "modified": "2024-08-09T18:30:44Z", + "published": "2024-08-09T18:30:44Z", + "aliases": [ + "CVE-2024-23788" + ], + "details": "Server-side request forgery vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to send an arbitrary HTTP request (GET) from the affected product.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23788" + }, + { + "type": "WEB", + "url": "https://jp.sharp/support/taiyo/info/JVNVU94591337_en.pdf" + }, + { + "type": "WEB", + "url": "https://jp.sharp/support/taiyo/info/JVNVU94591337_jp.pdf" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/vu/JVNVU94591337" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-14T10:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-cg3x-qc2c-6jq2/GHSA-cg3x-qc2c-6jq2.json b/advisories/unreviewed/2024/08/GHSA-cg3x-qc2c-6jq2/GHSA-cg3x-qc2c-6jq2.json index 43c18f9a1c4..9ea92df96b8 100644 --- a/advisories/unreviewed/2024/08/GHSA-cg3x-qc2c-6jq2/GHSA-cg3x-qc2c-6jq2.json +++ b/advisories/unreviewed/2024/08/GHSA-cg3x-qc2c-6jq2/GHSA-cg3x-qc2c-6jq2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cg3x-qc2c-6jq2", - "modified": "2024-08-08T00:31:44Z", + "modified": "2024-08-09T18:30:45Z", "published": "2024-08-08T00:31:44Z", "aliases": [ "CVE-2024-6892" ], "details": "Attackers can craft a malicious link that once clicked will execute arbitrary JavaScript in the context of the Journyx web application.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-81" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-08T00:15:40Z" diff --git a/advisories/unreviewed/2024/08/GHSA-gx25-vx95-m52w/GHSA-gx25-vx95-m52w.json b/advisories/unreviewed/2024/08/GHSA-gx25-vx95-m52w/GHSA-gx25-vx95-m52w.json index bcf1fdf36fe..97daef5c174 100644 --- a/advisories/unreviewed/2024/08/GHSA-gx25-vx95-m52w/GHSA-gx25-vx95-m52w.json +++ b/advisories/unreviewed/2024/08/GHSA-gx25-vx95-m52w/GHSA-gx25-vx95-m52w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gx25-vx95-m52w", - "modified": "2024-08-07T00:30:47Z", + "modified": "2024-08-09T18:30:45Z", "published": "2024-08-06T15:30:54Z", "aliases": [ "CVE-2024-7528" ], "details": "Incorrect garbage collection interaction in IndexedDB could have led to a use-after-free. This vulnerability affects Firefox < 129 and Firefox ESR < 128.1.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-06T13:15:57Z" diff --git a/advisories/unreviewed/2024/08/GHSA-mj2x-c9j2-vp7g/GHSA-mj2x-c9j2-vp7g.json b/advisories/unreviewed/2024/08/GHSA-mj2x-c9j2-vp7g/GHSA-mj2x-c9j2-vp7g.json index d7fa2e51983..8d29dcfdbbb 100644 --- a/advisories/unreviewed/2024/08/GHSA-mj2x-c9j2-vp7g/GHSA-mj2x-c9j2-vp7g.json +++ b/advisories/unreviewed/2024/08/GHSA-mj2x-c9j2-vp7g/GHSA-mj2x-c9j2-vp7g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mj2x-c9j2-vp7g", - "modified": "2024-08-08T18:31:20Z", + "modified": "2024-08-09T18:30:45Z", "published": "2024-08-08T18:31:20Z", "aliases": [ "CVE-2023-40261" ], "details": "Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR17, 4.0.0 SR07, 4.1.0 SR04, 4.2.0 SR04, and 4.3.0 SR03 fails to validate file attributes during the Pre-Boot Authorization (PBA) process. This can be exploited by a physical attacker who is able to manipulate the contents of the system's hard disk.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-08T18:15:09Z" diff --git a/advisories/unreviewed/2024/08/GHSA-qx4x-h5xp-mmqx/GHSA-qx4x-h5xp-mmqx.json b/advisories/unreviewed/2024/08/GHSA-qx4x-h5xp-mmqx/GHSA-qx4x-h5xp-mmqx.json index 31f952e51b1..806a6ed84ef 100644 --- a/advisories/unreviewed/2024/08/GHSA-qx4x-h5xp-mmqx/GHSA-qx4x-h5xp-mmqx.json +++ b/advisories/unreviewed/2024/08/GHSA-qx4x-h5xp-mmqx/GHSA-qx4x-h5xp-mmqx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qx4x-h5xp-mmqx", - "modified": "2024-08-08T18:31:20Z", + "modified": "2024-08-09T18:30:45Z", "published": "2024-08-08T18:31:20Z", "aliases": [ "CVE-2023-24064" ], "details": "Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR4 fails to validate /etc/initab during the Pre-Boot Authorization (PBA) process. This can be exploited by a physical attacker who is able to manipulate the contents of the system's hard disk.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-08T18:15:09Z"