Publish Advisories

GHSA-9ph3-v2vh-3qx7
GHSA-2cww-rcpx-vmvj
GHSA-36pg-p326-9j9j
GHSA-6qpm-68vc-gfr6
GHSA-8rg3-xv33-hfpc
GHSA-h3hp-g22h-899v
GHSA-j69w-hqg4-wcw5
GHSA-m37q-xj87-cf4v
GHSA-w74q-jj94-wcp5
This commit is contained in:
advisory-database[bot]
2024-04-18 18:31:51 +00:00
parent d63bd3f9a3
commit 24d4c8a265
9 changed files with 313 additions and 1 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9ph3-v2vh-3qx7",
"modified": "2024-04-09T12:30:46Z",
"modified": "2024-04-18T18:30:40Z",
"published": "2024-04-02T09:30:42Z",
"aliases": [
"CVE-2024-1300"
@@ -87,6 +87,10 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1706"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1923"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-1300"
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2cww-rcpx-vmvj",
"modified": "2024-04-18T18:30:41Z",
"published": "2024-04-18T18:30:41Z",
"aliases": [
"CVE-2024-32325"
],
"details": "TOTOLINK EX200 V4.0.3c.7646_B20201211 contains a Cross-site scripting (XSS) vulnerability through the ssid parameter in the setWiFiExtenderConfig function.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32325"
},
{
"type": "WEB",
"url": "https://github.com/4hsien/CVE-vulns/blob/main/TOTOLINK/EX200/XSS_ssid/README.md"
},
{
"type": "WEB",
"url": "https://www.totolink.net/home/menu/newstpl/menu_newstpl/products/id/144.html"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-18T17:15:48Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-36pg-p326-9j9j",
"modified": "2024-04-18T18:30:42Z",
"published": "2024-04-18T18:30:42Z",
"aliases": [
"CVE-2024-32327"
],
"details": "TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in Port Forwarding under the Firewall Page.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32327"
},
{
"type": "WEB",
"url": "https://github.com/4hsien/CVE-vulns/blob/main/TOTOLINK/N300RT/XSS_5_Port_Forwarding/README.md"
},
{
"type": "WEB",
"url": "https://www.totolink.net/home/menu/newstpl/menu_newstpl/products/id/154.html"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-18T17:15:48Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6qpm-68vc-gfr6",
"modified": "2024-04-18T18:30:42Z",
"published": "2024-04-18T18:30:42Z",
"aliases": [
"CVE-2024-32332"
],
"details": "TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in WDS Settings under the Wireless Page.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32332"
},
{
"type": "WEB",
"url": "https://github.com/4hsien/CVE-vulns/blob/main/TOTOLINK/N300RT/XSS_1_WDS_Settings/README.md"
},
{
"type": "WEB",
"url": "https://www.totolink.net/home/menu/newstpl/menu_newstpl/products/id/154.html"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-18T17:15:48Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8rg3-xv33-hfpc",
"modified": "2024-04-18T18:30:43Z",
"published": "2024-04-18T18:30:43Z",
"aliases": [
"CVE-2024-24910"
],
"details": "A local attacker can escalate privileges on affected Check Point ZoneAlarm Extreme Security NextGen, Identity Agent for Windows, and Identity Agent for Windows Terminal Server. To exploit this vulnerability, an attacker must first obtain the ability to execute local privileged code on the target system.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24910"
},
{
"type": "WEB",
"url": "https://support.checkpoint.com/results/sk/sk182219"
}
],
"database_specific": {
"cwe_ids": [
"CWE-732"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-18T18:15:09Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h3hp-g22h-899v",
"modified": "2024-04-18T18:30:41Z",
"published": "2024-04-18T18:30:41Z",
"aliases": [
"CVE-2024-32326"
],
"details": "TOTOLINK EX200 V4.0.3c.7646_B20201211 contains a Cross-site scripting (XSS) vulnerability through the key parameter in the setWiFiExtenderConfig function.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32326"
},
{
"type": "WEB",
"url": "https://github.com/4hsien/CVE-vulns/blob/main/TOTOLINK/EX200/XSS_key/README.md"
},
{
"type": "WEB",
"url": "https://www.totolink.net/home/menu/newstpl/menu_newstpl/products/id/144.html"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-18T17:15:48Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j69w-hqg4-wcw5",
"modified": "2024-04-18T18:30:42Z",
"published": "2024-04-18T18:30:42Z",
"aliases": [
"CVE-2024-32335"
],
"details": "TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in Access Control under the Wireless Page.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32335"
},
{
"type": "WEB",
"url": "https://github.com/4hsien/CVE-vulns/blob/main/TOTOLINK/N300RT/XSS_2_Access_Control/README.md"
},
{
"type": "WEB",
"url": "https://www.totolink.net/home/menu/newstpl/menu_newstpl/products/id/154.html"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-18T17:15:49Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m37q-xj87-cf4v",
"modified": "2024-04-18T18:30:42Z",
"published": "2024-04-18T18:30:42Z",
"aliases": [
"CVE-2024-32334"
],
"details": "TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in IP/Port Filtering under the Firewall Page.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32334"
},
{
"type": "WEB",
"url": "https://github.com/4hsien/CVE-vulns/blob/main/TOTOLINK/N300RT/XSS_4_IP_Port_Filtering/README.md"
},
{
"type": "WEB",
"url": "https://www.totolink.net/home/menu/newstpl/menu_newstpl/products/id/154.html"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-18T17:15:49Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w74q-jj94-wcp5",
"modified": "2024-04-18T18:30:42Z",
"published": "2024-04-18T18:30:42Z",
"aliases": [
"CVE-2024-32333"
],
"details": "TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in MAC Filtering under the Firewall Page.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32333"
},
{
"type": "WEB",
"url": "https://github.com/4hsien/CVE-vulns/blob/main/TOTOLINK/N300RT/XSS_3_MAC_Filtering/README.md"
},
{
"type": "WEB",
"url": "https://www.totolink.net/home/menu/newstpl/menu_newstpl/products/id/154.html"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-18T17:15:48Z"
}
}