diff --git a/advisories/unreviewed/2024/05/GHSA-23x8-g5mh-phmc/GHSA-23x8-g5mh-phmc.json b/advisories/unreviewed/2024/05/GHSA-23x8-g5mh-phmc/GHSA-23x8-g5mh-phmc.json
index 570e8369085..9750fa8c9ce 100644
--- a/advisories/unreviewed/2024/05/GHSA-23x8-g5mh-phmc/GHSA-23x8-g5mh-phmc.json
+++ b/advisories/unreviewed/2024/05/GHSA-23x8-g5mh-phmc/GHSA-23x8-g5mh-phmc.json
@@ -64,6 +64,7 @@
],
"database_specific": {
"cwe_ids": [
+ "CWE-400",
"CWE-667"
],
"severity": "MODERATE",
diff --git a/advisories/unreviewed/2024/05/GHSA-2874-f7gx-365p/GHSA-2874-f7gx-365p.json b/advisories/unreviewed/2024/05/GHSA-2874-f7gx-365p/GHSA-2874-f7gx-365p.json
index 5f5a17c4998..e6a400b2357 100644
--- a/advisories/unreviewed/2024/05/GHSA-2874-f7gx-365p/GHSA-2874-f7gx-365p.json
+++ b/advisories/unreviewed/2024/05/GHSA-2874-f7gx-365p/GHSA-2874-f7gx-365p.json
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-294"
],
"severity": "HIGH",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/05/GHSA-29gq-rw72-mrqg/GHSA-29gq-rw72-mrqg.json b/advisories/unreviewed/2024/05/GHSA-29gq-rw72-mrqg/GHSA-29gq-rw72-mrqg.json
index e8d72b87350..44f471e8b3d 100644
--- a/advisories/unreviewed/2024/05/GHSA-29gq-rw72-mrqg/GHSA-29gq-rw72-mrqg.json
+++ b/advisories/unreviewed/2024/05/GHSA-29gq-rw72-mrqg/GHSA-29gq-rw72-mrqg.json
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-120"
],
"severity": "HIGH",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/05/GHSA-2rm2-mwc8-f72w/GHSA-2rm2-mwc8-f72w.json b/advisories/unreviewed/2024/05/GHSA-2rm2-mwc8-f72w/GHSA-2rm2-mwc8-f72w.json
index 237ce196001..e7e9d82931e 100644
--- a/advisories/unreviewed/2024/05/GHSA-2rm2-mwc8-f72w/GHSA-2rm2-mwc8-f72w.json
+++ b/advisories/unreviewed/2024/05/GHSA-2rm2-mwc8-f72w/GHSA-2rm2-mwc8-f72w.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2rm2-mwc8-f72w",
- "modified": "2024-05-31T18:31:15Z",
+ "modified": "2024-07-03T18:43:56Z",
"published": "2024-05-31T18:31:15Z",
"aliases": [
"CVE-2021-44534"
],
"details": "Insufficient user input filtering leads to arbitrary file read by non-authenticated attacker, which results in sensitive information disclosure.\n",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-200"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-31T18:15:09Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-32mg-q3wg-529p/GHSA-32mg-q3wg-529p.json b/advisories/unreviewed/2024/05/GHSA-32mg-q3wg-529p/GHSA-32mg-q3wg-529p.json
index 2718aa82251..9331efa2358 100644
--- a/advisories/unreviewed/2024/05/GHSA-32mg-q3wg-529p/GHSA-32mg-q3wg-529p.json
+++ b/advisories/unreviewed/2024/05/GHSA-32mg-q3wg-529p/GHSA-32mg-q3wg-529p.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-32mg-q3wg-529p",
- "modified": "2024-05-21T21:30:28Z",
+ "modified": "2024-07-03T18:43:03Z",
"published": "2024-05-21T21:30:28Z",
"aliases": [
"CVE-2024-34274"
],
"details": "OpenBD 20210306203917-6cbe797 is vulnerable to Deserialization of Untrusted Data. The cookies bdglobals and bdclient_spot of the OpenBD software uses serialized data, which can be used to execute arbitrary code on the system. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:P/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-502"
],
- "severity": null,
+ "severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-21T20:15:08Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-34xf-292h-46f4/GHSA-34xf-292h-46f4.json b/advisories/unreviewed/2024/05/GHSA-34xf-292h-46f4/GHSA-34xf-292h-46f4.json
index df78abe1f6e..ceb70053441 100644
--- a/advisories/unreviewed/2024/05/GHSA-34xf-292h-46f4/GHSA-34xf-292h-46f4.json
+++ b/advisories/unreviewed/2024/05/GHSA-34xf-292h-46f4/GHSA-34xf-292h-46f4.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-34xf-292h-46f4",
- "modified": "2024-05-22T09:31:45Z",
+ "modified": "2024-07-03T18:43:05Z",
"published": "2024-05-22T09:31:45Z",
"aliases": [
"CVE-2021-47441"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmlxsw: thermal: Fix out-of-bounds memory accesses\n\nCurrently, mlxsw allows cooling states to be set above the maximum\ncooling state supported by the driver:\n\n # cat /sys/class/thermal/thermal_zone2/cdev0/type\n mlxsw_fan\n # cat /sys/class/thermal/thermal_zone2/cdev0/max_state\n 10\n # echo 18 > /sys/class/thermal/thermal_zone2/cdev0/cur_state\n # echo $?\n 0\n\nThis results in out-of-bounds memory accesses when thermal state\ntransition statistics are enabled (CONFIG_THERMAL_STATISTICS=y), as the\ntransition table is accessed with a too large index (state) [1].\n\nAccording to the thermal maintainer, it is the responsibility of the\ndriver to reject such operations [2].\n\nTherefore, return an error when the state to be set exceeds the maximum\ncooling state supported by the driver.\n\nTo avoid dead code, as suggested by the thermal maintainer [3],\npartially revert commit a421ce088ac8 (\"mlxsw: core: Extend cooling\ndevice with cooling levels\") that tried to interpret these invalid\ncooling states (above the maximum) in a special way. The cooling levels\narray is not removed in order to prevent the fans going below 20% PWM,\nwhich would cause them to get stuck at 0% PWM.\n\n[1]\nBUG: KASAN: slab-out-of-bounds in thermal_cooling_device_stats_update+0x271/0x290\nRead of size 4 at addr ffff8881052f7bf8 by task kworker/0:0/5\n\nCPU: 0 PID: 5 Comm: kworker/0:0 Not tainted 5.15.0-rc3-custom-45935-gce1adf704b14 #122\nHardware name: Mellanox Technologies Ltd. \"MSN2410-CB2FO\"/\"SA000874\", BIOS 4.6.5 03/08/2016\nWorkqueue: events_freezable_power_ thermal_zone_device_check\nCall Trace:\n dump_stack_lvl+0x8b/0xb3\n print_address_description.constprop.0+0x1f/0x140\n kasan_report.cold+0x7f/0x11b\n thermal_cooling_device_stats_update+0x271/0x290\n __thermal_cdev_update+0x15e/0x4e0\n thermal_cdev_update+0x9f/0xe0\n step_wise_throttle+0x770/0xee0\n thermal_zone_device_update+0x3f6/0xdf0\n process_one_work+0xa42/0x1770\n worker_thread+0x62f/0x13e0\n kthread+0x3ee/0x4e0\n ret_from_fork+0x1f/0x30\n\nAllocated by task 1:\n kasan_save_stack+0x1b/0x40\n __kasan_kmalloc+0x7c/0x90\n thermal_cooling_device_setup_sysfs+0x153/0x2c0\n __thermal_cooling_device_register.part.0+0x25b/0x9c0\n thermal_cooling_device_register+0xb3/0x100\n mlxsw_thermal_init+0x5c5/0x7e0\n __mlxsw_core_bus_device_register+0xcb3/0x19c0\n mlxsw_core_bus_device_register+0x56/0xb0\n mlxsw_pci_probe+0x54f/0x710\n local_pci_probe+0xc6/0x170\n pci_device_probe+0x2b2/0x4d0\n really_probe+0x293/0xd10\n __driver_probe_device+0x2af/0x440\n driver_probe_device+0x51/0x1e0\n __driver_attach+0x21b/0x530\n bus_for_each_dev+0x14c/0x1d0\n bus_add_driver+0x3ac/0x650\n driver_register+0x241/0x3d0\n mlxsw_sp_module_init+0xa2/0x174\n do_one_initcall+0xee/0x5f0\n kernel_init_freeable+0x45a/0x4de\n kernel_init+0x1f/0x210\n ret_from_fork+0x1f/0x30\n\nThe buggy address belongs to the object at ffff8881052f7800\n which belongs to the cache kmalloc-1k of size 1024\nThe buggy address is located 1016 bytes inside of\n 1024-byte region [ffff8881052f7800, ffff8881052f7c00)\nThe buggy address belongs to the page:\npage:0000000052355272 refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x1052f0\nhead:0000000052355272 order:3 compound_mapcount:0 compound_pincount:0\nflags: 0x200000000010200(slab|head|node=0|zone=2)\nraw: 0200000000010200 ffffea0005034800 0000000300000003 ffff888100041dc0\nraw: 0000000000000000 0000000000100010 00000001ffffffff 0000000000000000\npage dumped because: kasan: bad access detected\n\nMemory state around the buggy address:\n ffff8881052f7a80: 00 00 00 00 00 00 04 fc fc fc fc fc fc fc fc fc\n ffff8881052f7b00: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc\n>ffff8881052f7b80: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc\n ^\n ffff8881052f7c00: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc\n ffff8881052f7c80: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc\n\n[2] https://lore.kernel.org/linux-pm/9aca37cb-1629-5c67-\n---truncated---",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H"
+ }
],
"affected": [
@@ -37,9 +40,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-787"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-22T07:15:09Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-3c77-6pw4-hr87/GHSA-3c77-6pw4-hr87.json b/advisories/unreviewed/2024/05/GHSA-3c77-6pw4-hr87/GHSA-3c77-6pw4-hr87.json
index dac7680cb63..cc8e64d9a23 100644
--- a/advisories/unreviewed/2024/05/GHSA-3c77-6pw4-hr87/GHSA-3c77-6pw4-hr87.json
+++ b/advisories/unreviewed/2024/05/GHSA-3c77-6pw4-hr87/GHSA-3c77-6pw4-hr87.json
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-89"
],
"severity": "HIGH",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/05/GHSA-3cg6-xv3h-2wj2/GHSA-3cg6-xv3h-2wj2.json b/advisories/unreviewed/2024/05/GHSA-3cg6-xv3h-2wj2/GHSA-3cg6-xv3h-2wj2.json
index 2561ca1a878..80413d0bf28 100644
--- a/advisories/unreviewed/2024/05/GHSA-3cg6-xv3h-2wj2/GHSA-3cg6-xv3h-2wj2.json
+++ b/advisories/unreviewed/2024/05/GHSA-3cg6-xv3h-2wj2/GHSA-3cg6-xv3h-2wj2.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3cg6-xv3h-2wj2",
- "modified": "2024-05-31T18:31:14Z",
+ "modified": "2024-07-03T18:43:56Z",
"published": "2024-05-31T18:31:14Z",
"aliases": [
"CVE-2024-28736"
],
"details": "An issue in Debezium Community debezium-ui v.2.5 allows a local attacker to execute arbitrary code via the refresh page function.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-256"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-31T16:15:09Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-3wqm-ppwr-mjfv/GHSA-3wqm-ppwr-mjfv.json b/advisories/unreviewed/2024/05/GHSA-3wqm-ppwr-mjfv/GHSA-3wqm-ppwr-mjfv.json
index 0d2d4fc38a1..f4ef9075391 100644
--- a/advisories/unreviewed/2024/05/GHSA-3wqm-ppwr-mjfv/GHSA-3wqm-ppwr-mjfv.json
+++ b/advisories/unreviewed/2024/05/GHSA-3wqm-ppwr-mjfv/GHSA-3wqm-ppwr-mjfv.json
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/05/GHSA-4433-jwm9-48r5/GHSA-4433-jwm9-48r5.json b/advisories/unreviewed/2024/05/GHSA-4433-jwm9-48r5/GHSA-4433-jwm9-48r5.json
index 318a20cd375..97ed2412c54 100644
--- a/advisories/unreviewed/2024/05/GHSA-4433-jwm9-48r5/GHSA-4433-jwm9-48r5.json
+++ b/advisories/unreviewed/2024/05/GHSA-4433-jwm9-48r5/GHSA-4433-jwm9-48r5.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4433-jwm9-48r5",
- "modified": "2024-06-10T18:31:03Z",
+ "modified": "2024-07-03T18:43:14Z",
"published": "2024-05-22T18:30:42Z",
"aliases": [
"CVE-2024-5158"
],
"details": "Type Confusion in V8 in Google Chrome prior to 125.0.6422.76 allowed a remote attacker to potentially perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -37,9 +40,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-22"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-22T16:15:10Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-448x-875q-xjq4/GHSA-448x-875q-xjq4.json b/advisories/unreviewed/2024/05/GHSA-448x-875q-xjq4/GHSA-448x-875q-xjq4.json
index 09af523a52c..5bb704362fe 100644
--- a/advisories/unreviewed/2024/05/GHSA-448x-875q-xjq4/GHSA-448x-875q-xjq4.json
+++ b/advisories/unreviewed/2024/05/GHSA-448x-875q-xjq4/GHSA-448x-875q-xjq4.json
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-89"
],
"severity": "HIGH",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/05/GHSA-45hj-5gpj-93h8/GHSA-45hj-5gpj-93h8.json b/advisories/unreviewed/2024/05/GHSA-45hj-5gpj-93h8/GHSA-45hj-5gpj-93h8.json
index cfe85fd261f..b319f3da610 100644
--- a/advisories/unreviewed/2024/05/GHSA-45hj-5gpj-93h8/GHSA-45hj-5gpj-93h8.json
+++ b/advisories/unreviewed/2024/05/GHSA-45hj-5gpj-93h8/GHSA-45hj-5gpj-93h8.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-45hj-5gpj-93h8",
- "modified": "2024-05-22T09:31:45Z",
+ "modified": "2024-07-03T18:43:06Z",
"published": "2024-05-22T09:31:45Z",
"aliases": [
"CVE-2021-47456"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: peak_pci: peak_pci_remove(): fix UAF\n\nWhen remove the module peek_pci, referencing 'chan' again after\nreleasing 'dev' will cause UAF.\n\nFix this by releasing 'dev' later.\n\nThe following log reveals it:\n\n[ 35.961814 ] BUG: KASAN: use-after-free in peak_pci_remove+0x16f/0x270 [peak_pci]\n[ 35.963414 ] Read of size 8 at addr ffff888136998ee8 by task modprobe/5537\n[ 35.965513 ] Call Trace:\n[ 35.965718 ] dump_stack_lvl+0xa8/0xd1\n[ 35.966028 ] print_address_description+0x87/0x3b0\n[ 35.966420 ] kasan_report+0x172/0x1c0\n[ 35.966725 ] ? peak_pci_remove+0x16f/0x270 [peak_pci]\n[ 35.967137 ] ? trace_irq_enable_rcuidle+0x10/0x170\n[ 35.967529 ] ? peak_pci_remove+0x16f/0x270 [peak_pci]\n[ 35.967945 ] __asan_report_load8_noabort+0x14/0x20\n[ 35.968346 ] peak_pci_remove+0x16f/0x270 [peak_pci]\n[ 35.968752 ] pci_device_remove+0xa9/0x250",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -53,9 +56,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-416"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-22T07:15:10Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-45q4-h8rr-hgx2/GHSA-45q4-h8rr-hgx2.json b/advisories/unreviewed/2024/05/GHSA-45q4-h8rr-hgx2/GHSA-45q4-h8rr-hgx2.json
index d4305a749c2..b049f391aea 100644
--- a/advisories/unreviewed/2024/05/GHSA-45q4-h8rr-hgx2/GHSA-45q4-h8rr-hgx2.json
+++ b/advisories/unreviewed/2024/05/GHSA-45q4-h8rr-hgx2/GHSA-45q4-h8rr-hgx2.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-45q4-h8rr-hgx2",
- "modified": "2024-05-21T21:30:27Z",
+ "modified": "2024-07-03T18:43:03Z",
"published": "2024-05-21T21:30:27Z",
"aliases": [
"CVE-2024-35060"
],
"details": "An issue in the YAML Python library of NASA AIT-Core v2.5.2 allows attackers to execute arbitrary commands via supplying a crafted YAML file.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-319"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-21T19:15:10Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-47p2-vwpg-v462/GHSA-47p2-vwpg-v462.json b/advisories/unreviewed/2024/05/GHSA-47p2-vwpg-v462/GHSA-47p2-vwpg-v462.json
index 5741d7fa4fa..8ebeba4bfba 100644
--- a/advisories/unreviewed/2024/05/GHSA-47p2-vwpg-v462/GHSA-47p2-vwpg-v462.json
+++ b/advisories/unreviewed/2024/05/GHSA-47p2-vwpg-v462/GHSA-47p2-vwpg-v462.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-47p2-vwpg-v462",
- "modified": "2024-05-21T15:31:38Z",
+ "modified": "2024-07-03T18:42:41Z",
"published": "2024-05-21T15:31:38Z",
"aliases": [
"CVE-2024-35385"
],
"details": "An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_mk_ffi_sig function in the mjs.c file.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-125"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-21T14:15:12Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-47rw-4rpj-m5g9/GHSA-47rw-4rpj-m5g9.json b/advisories/unreviewed/2024/05/GHSA-47rw-4rpj-m5g9/GHSA-47rw-4rpj-m5g9.json
index 39f5a1d71c5..2af5d5bbdb2 100644
--- a/advisories/unreviewed/2024/05/GHSA-47rw-4rpj-m5g9/GHSA-47rw-4rpj-m5g9.json
+++ b/advisories/unreviewed/2024/05/GHSA-47rw-4rpj-m5g9/GHSA-47rw-4rpj-m5g9.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-47rw-4rpj-m5g9",
- "modified": "2024-05-21T18:31:19Z",
+ "modified": "2024-07-03T18:42:53Z",
"published": "2024-05-21T18:31:19Z",
"aliases": [
"CVE-2023-52735"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf, sockmap: Don't let sock_map_{close,destroy,unhash} call itself\n\nsock_map proto callbacks should never call themselves by design. Protect\nagainst bugs like [1] and break out of the recursive loop to avoid a stack\noverflow in favor of a resource leak.\n\n[1] https://lore.kernel.org/all/00000000000073b14905ef2e7401@google.com/",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
+ }
],
"affected": [
@@ -33,9 +36,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-120"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-21T16:15:13Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-4cr2-ccp7-92rr/GHSA-4cr2-ccp7-92rr.json b/advisories/unreviewed/2024/05/GHSA-4cr2-ccp7-92rr/GHSA-4cr2-ccp7-92rr.json
index 9e707a12db8..45e2f8a1f23 100644
--- a/advisories/unreviewed/2024/05/GHSA-4cr2-ccp7-92rr/GHSA-4cr2-ccp7-92rr.json
+++ b/advisories/unreviewed/2024/05/GHSA-4cr2-ccp7-92rr/GHSA-4cr2-ccp7-92rr.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4cr2-ccp7-92rr",
- "modified": "2024-06-26T00:31:43Z",
+ "modified": "2024-07-03T18:42:26Z",
"published": "2024-05-17T15:31:12Z",
"aliases": [
"CVE-2024-35854"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmlxsw: spectrum_acl_tcam: Fix possible use-after-free during rehash\n\nThe rehash delayed work migrates filters from one region to another\naccording to the number of available credits.\n\nThe migrated from region is destroyed at the end of the work if the\nnumber of credits is non-negative as the assumption is that this is\nindicative of migration being complete. This assumption is incorrect as\na non-negative number of credits can also be the result of a failed\nmigration.\n\nThe destruction of a region that still has filters referencing it can\nresult in a use-after-free [1].\n\nFix by not destroying the region if migration failed.\n\n[1]\nBUG: KASAN: slab-use-after-free in mlxsw_sp_acl_ctcam_region_entry_remove+0x21d/0x230\nRead of size 8 at addr ffff8881735319e8 by task kworker/0:31/3858\n\nCPU: 0 PID: 3858 Comm: kworker/0:31 Tainted: G W 6.9.0-rc2-custom-00782-gf2275c2157d8 #5\nHardware name: Mellanox Technologies Ltd. MSN3700/VMOD0005, BIOS 5.11 01/06/2019\nWorkqueue: mlxsw_core mlxsw_sp_acl_tcam_vregion_rehash_work\nCall Trace:\n \n dump_stack_lvl+0xc6/0x120\n print_report+0xce/0x670\n kasan_report+0xd7/0x110\n mlxsw_sp_acl_ctcam_region_entry_remove+0x21d/0x230\n mlxsw_sp_acl_ctcam_entry_del+0x2e/0x70\n mlxsw_sp_acl_atcam_entry_del+0x81/0x210\n mlxsw_sp_acl_tcam_vchunk_migrate_all+0x3cd/0xb50\n mlxsw_sp_acl_tcam_vregion_rehash_work+0x157/0x1300\n process_one_work+0x8eb/0x19b0\n worker_thread+0x6c9/0xf70\n kthread+0x2c9/0x3b0\n ret_from_fork+0x4d/0x80\n ret_from_fork_asm+0x1a/0x30\n \n\nAllocated by task 174:\n kasan_save_stack+0x33/0x60\n kasan_save_track+0x14/0x30\n __kasan_kmalloc+0x8f/0xa0\n __kmalloc+0x19c/0x360\n mlxsw_sp_acl_tcam_region_create+0xdf/0x9c0\n mlxsw_sp_acl_tcam_vregion_rehash_work+0x954/0x1300\n process_one_work+0x8eb/0x19b0\n worker_thread+0x6c9/0xf70\n kthread+0x2c9/0x3b0\n ret_from_fork+0x4d/0x80\n ret_from_fork_asm+0x1a/0x30\n\nFreed by task 7:\n kasan_save_stack+0x33/0x60\n kasan_save_track+0x14/0x30\n kasan_save_free_info+0x3b/0x60\n poison_slab_object+0x102/0x170\n __kasan_slab_free+0x14/0x30\n kfree+0xc1/0x290\n mlxsw_sp_acl_tcam_region_destroy+0x272/0x310\n mlxsw_sp_acl_tcam_vregion_rehash_work+0x731/0x1300\n process_one_work+0x8eb/0x19b0\n worker_thread+0x6c9/0xf70\n kthread+0x2c9/0x3b0\n ret_from_fork+0x4d/0x80\n ret_from_fork_asm+0x1a/0x30",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -53,9 +56,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-416"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-17T15:15:22Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-4fpw-6gvj-w9xf/GHSA-4fpw-6gvj-w9xf.json b/advisories/unreviewed/2024/05/GHSA-4fpw-6gvj-w9xf/GHSA-4fpw-6gvj-w9xf.json
index a979d6ebb5c..c774d64679b 100644
--- a/advisories/unreviewed/2024/05/GHSA-4fpw-6gvj-w9xf/GHSA-4fpw-6gvj-w9xf.json
+++ b/advisories/unreviewed/2024/05/GHSA-4fpw-6gvj-w9xf/GHSA-4fpw-6gvj-w9xf.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4fpw-6gvj-w9xf",
- "modified": "2024-05-22T09:31:46Z",
+ "modified": "2024-07-03T18:43:06Z",
"published": "2024-05-22T09:31:46Z",
"aliases": [
"CVE-2024-32988"
],
"details": "'OfferBox' App for Android versions 2.0.0 to 2.3.17 and 'OfferBox' App for iOS versions 2.1.7 to 2.6.14 use a hard-coded secret key for JWT. Secret key for JWT may be retrieved if the application binary is reverse-engineered.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-798"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-22T08:15:10Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-4fx7-5ppw-hmcq/GHSA-4fx7-5ppw-hmcq.json b/advisories/unreviewed/2024/05/GHSA-4fx7-5ppw-hmcq/GHSA-4fx7-5ppw-hmcq.json
index 54fd7c4c253..2b61859956b 100644
--- a/advisories/unreviewed/2024/05/GHSA-4fx7-5ppw-hmcq/GHSA-4fx7-5ppw-hmcq.json
+++ b/advisories/unreviewed/2024/05/GHSA-4fx7-5ppw-hmcq/GHSA-4fx7-5ppw-hmcq.json
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-89"
],
"severity": "HIGH",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/05/GHSA-4gxj-5mmr-7pxq/GHSA-4gxj-5mmr-7pxq.json b/advisories/unreviewed/2024/05/GHSA-4gxj-5mmr-7pxq/GHSA-4gxj-5mmr-7pxq.json
index 8cae7f51b84..304eda89fa2 100644
--- a/advisories/unreviewed/2024/05/GHSA-4gxj-5mmr-7pxq/GHSA-4gxj-5mmr-7pxq.json
+++ b/advisories/unreviewed/2024/05/GHSA-4gxj-5mmr-7pxq/GHSA-4gxj-5mmr-7pxq.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4gxj-5mmr-7pxq",
- "modified": "2024-05-21T18:31:24Z",
+ "modified": "2024-07-03T18:43:00Z",
"published": "2024-05-21T18:31:24Z",
"aliases": [
"CVE-2024-35058"
],
"details": "An issue in the API wait function of NASA AIT-Core v2.5.2 allows attackers to execute arbitrary code via supplying a crafted string.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-319"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-21T18:15:09Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-4h53-xcvw-8wpx/GHSA-4h53-xcvw-8wpx.json b/advisories/unreviewed/2024/05/GHSA-4h53-xcvw-8wpx/GHSA-4h53-xcvw-8wpx.json
index ff92bf650c3..94a3bad73c0 100644
--- a/advisories/unreviewed/2024/05/GHSA-4h53-xcvw-8wpx/GHSA-4h53-xcvw-8wpx.json
+++ b/advisories/unreviewed/2024/05/GHSA-4h53-xcvw-8wpx/GHSA-4h53-xcvw-8wpx.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4h53-xcvw-8wpx",
- "modified": "2024-06-26T00:31:42Z",
+ "modified": "2024-07-03T18:42:22Z",
"published": "2024-05-17T12:31:01Z",
"aliases": [
"CVE-2024-27431"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncpumap: Zero-initialise xdp_rxq_info struct before running XDP program\n\nWhen running an XDP program that is attached to a cpumap entry, we don't\ninitialise the xdp_rxq_info data structure being used in the xdp_buff\nthat backs the XDP program invocation. Tobias noticed that this leads to\nrandom values being returned as the xdp_md->rx_queue_index value for XDP\nprograms running in a cpumap.\n\nThis means we're basically returning the contents of the uninitialised\nmemory, which is bad. Fix this by zero-initialising the rxq data\nstructure before running the XDP program.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -49,9 +52,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-908"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-17T12:15:16Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-4h92-hv7c-rccv/GHSA-4h92-hv7c-rccv.json b/advisories/unreviewed/2024/05/GHSA-4h92-hv7c-rccv/GHSA-4h92-hv7c-rccv.json
index 526f2e8decd..435dca65540 100644
--- a/advisories/unreviewed/2024/05/GHSA-4h92-hv7c-rccv/GHSA-4h92-hv7c-rccv.json
+++ b/advisories/unreviewed/2024/05/GHSA-4h92-hv7c-rccv/GHSA-4h92-hv7c-rccv.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4h92-hv7c-rccv",
- "modified": "2024-05-23T18:30:55Z",
+ "modified": "2024-07-03T18:43:28Z",
"published": "2024-05-23T18:30:55Z",
"aliases": [
"CVE-2024-35081"
],
"details": "LuckyFrameWeb v3.5.2 was discovered to contain an arbitrary file deletion vulnerability via the fileName parameter in the fileDownload method.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
+ }
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-22"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-23T17:15:30Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-4v6f-9gh9-62jj/GHSA-4v6f-9gh9-62jj.json b/advisories/unreviewed/2024/05/GHSA-4v6f-9gh9-62jj/GHSA-4v6f-9gh9-62jj.json
index 89330bde0bf..852431aa005 100644
--- a/advisories/unreviewed/2024/05/GHSA-4v6f-9gh9-62jj/GHSA-4v6f-9gh9-62jj.json
+++ b/advisories/unreviewed/2024/05/GHSA-4v6f-9gh9-62jj/GHSA-4v6f-9gh9-62jj.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4v6f-9gh9-62jj",
- "modified": "2024-06-26T00:31:43Z",
+ "modified": "2024-07-03T18:42:30Z",
"published": "2024-05-19T09:34:47Z",
"aliases": [
"CVE-2024-35899"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: flush pending destroy work before exit_net release\n\nSimilar to 2c9f0293280e (\"netfilter: nf_tables: flush pending destroy\nwork before netlink notifier\") to address a race between exit_net and\nthe destroy workqueue.\n\nThe trace below shows an element to be released via destroy workqueue\nwhile exit_net path (triggered via module removal) has already released\nthe set that is used in such transaction.\n\n[ 1360.547789] BUG: KASAN: slab-use-after-free in nf_tables_trans_destroy_work+0x3f5/0x590 [nf_tables]\n[ 1360.547861] Read of size 8 at addr ffff888140500cc0 by task kworker/4:1/152465\n[ 1360.547870] CPU: 4 PID: 152465 Comm: kworker/4:1 Not tainted 6.8.0+ #359\n[ 1360.547882] Workqueue: events nf_tables_trans_destroy_work [nf_tables]\n[ 1360.547984] Call Trace:\n[ 1360.547991] \n[ 1360.547998] dump_stack_lvl+0x53/0x70\n[ 1360.548014] print_report+0xc4/0x610\n[ 1360.548026] ? __virt_addr_valid+0xba/0x160\n[ 1360.548040] ? __pfx__raw_spin_lock_irqsave+0x10/0x10\n[ 1360.548054] ? nf_tables_trans_destroy_work+0x3f5/0x590 [nf_tables]\n[ 1360.548176] kasan_report+0xae/0xe0\n[ 1360.548189] ? nf_tables_trans_destroy_work+0x3f5/0x590 [nf_tables]\n[ 1360.548312] nf_tables_trans_destroy_work+0x3f5/0x590 [nf_tables]\n[ 1360.548447] ? __pfx_nf_tables_trans_destroy_work+0x10/0x10 [nf_tables]\n[ 1360.548577] ? _raw_spin_unlock_irq+0x18/0x30\n[ 1360.548591] process_one_work+0x2f1/0x670\n[ 1360.548610] worker_thread+0x4d3/0x760\n[ 1360.548627] ? __pfx_worker_thread+0x10/0x10\n[ 1360.548640] kthread+0x16b/0x1b0\n[ 1360.548653] ? __pfx_kthread+0x10/0x10\n[ 1360.548665] ret_from_fork+0x2f/0x50\n[ 1360.548679] ? __pfx_kthread+0x10/0x10\n[ 1360.548690] ret_from_fork_asm+0x1a/0x30\n[ 1360.548707] \n\n[ 1360.548719] Allocated by task 192061:\n[ 1360.548726] kasan_save_stack+0x20/0x40\n[ 1360.548739] kasan_save_track+0x14/0x30\n[ 1360.548750] __kasan_kmalloc+0x8f/0xa0\n[ 1360.548760] __kmalloc_node+0x1f1/0x450\n[ 1360.548771] nf_tables_newset+0x10c7/0x1b50 [nf_tables]\n[ 1360.548883] nfnetlink_rcv_batch+0xbc4/0xdc0 [nfnetlink]\n[ 1360.548909] nfnetlink_rcv+0x1a8/0x1e0 [nfnetlink]\n[ 1360.548927] netlink_unicast+0x367/0x4f0\n[ 1360.548935] netlink_sendmsg+0x34b/0x610\n[ 1360.548944] ____sys_sendmsg+0x4d4/0x510\n[ 1360.548953] ___sys_sendmsg+0xc9/0x120\n[ 1360.548961] __sys_sendmsg+0xbe/0x140\n[ 1360.548971] do_syscall_64+0x55/0x120\n[ 1360.548982] entry_SYSCALL_64_after_hwframe+0x55/0x5d\n\n[ 1360.548994] Freed by task 192222:\n[ 1360.548999] kasan_save_stack+0x20/0x40\n[ 1360.549009] kasan_save_track+0x14/0x30\n[ 1360.549019] kasan_save_free_info+0x3b/0x60\n[ 1360.549028] poison_slab_object+0x100/0x180\n[ 1360.549036] __kasan_slab_free+0x14/0x30\n[ 1360.549042] kfree+0xb6/0x260\n[ 1360.549049] __nft_release_table+0x473/0x6a0 [nf_tables]\n[ 1360.549131] nf_tables_exit_net+0x170/0x240 [nf_tables]\n[ 1360.549221] ops_exit_list+0x50/0xa0\n[ 1360.549229] free_exit_list+0x101/0x140\n[ 1360.549236] unregister_pernet_operations+0x107/0x160\n[ 1360.549245] unregister_pernet_subsys+0x1c/0x30\n[ 1360.549254] nf_tables_module_exit+0x43/0x80 [nf_tables]\n[ 1360.549345] __do_sys_delete_module+0x253/0x370\n[ 1360.549352] do_syscall_64+0x55/0x120\n[ 1360.549360] entry_SYSCALL_64_after_hwframe+0x55/0x5d\n\n(gdb) list *__nft_release_table+0x473\n0x1e033 is in __nft_release_table (net/netfilter/nf_tables_api.c:11354).\n11349 list_for_each_entry_safe(flowtable, nf, &table->flowtables, list) {\n11350 list_del(&flowtable->list);\n11351 nft_use_dec(&table->use);\n11352 nf_tables_flowtable_destroy(flowtable);\n11353 }\n11354 list_for_each_entry_safe(set, ns, &table->sets, list) {\n11355 list_del(&set->list);\n11356 nft_use_dec(&table->use);\n11357 if (set->flags & (NFT_SET_MAP | NFT_SET_OBJECT))\n11358 nft_map_deactivat\n---truncated---",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H"
+ }
],
"affected": [
@@ -53,9 +56,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-362"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-19T09:15:10Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-4w7m-g8vh-4gh7/GHSA-4w7m-g8vh-4gh7.json b/advisories/unreviewed/2024/05/GHSA-4w7m-g8vh-4gh7/GHSA-4w7m-g8vh-4gh7.json
index e94dd02bb98..f67cf6d7935 100644
--- a/advisories/unreviewed/2024/05/GHSA-4w7m-g8vh-4gh7/GHSA-4w7m-g8vh-4gh7.json
+++ b/advisories/unreviewed/2024/05/GHSA-4w7m-g8vh-4gh7/GHSA-4w7m-g8vh-4gh7.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4w7m-g8vh-4gh7",
- "modified": "2024-05-20T18:31:23Z",
+ "modified": "2024-07-03T18:42:38Z",
"published": "2024-05-20T18:31:23Z",
"aliases": [
"CVE-2024-35576"
],
"details": "Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function formSetIptv.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:N"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-121"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-20T18:15:10Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-5h39-x96v-hf62/GHSA-5h39-x96v-hf62.json b/advisories/unreviewed/2024/05/GHSA-5h39-x96v-hf62/GHSA-5h39-x96v-hf62.json
index db8bc1c4ed6..df1fe0d4828 100644
--- a/advisories/unreviewed/2024/05/GHSA-5h39-x96v-hf62/GHSA-5h39-x96v-hf62.json
+++ b/advisories/unreviewed/2024/05/GHSA-5h39-x96v-hf62/GHSA-5h39-x96v-hf62.json
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-434"
],
"severity": "HIGH",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/05/GHSA-5vcp-m87w-9x8h/GHSA-5vcp-m87w-9x8h.json b/advisories/unreviewed/2024/05/GHSA-5vcp-m87w-9x8h/GHSA-5vcp-m87w-9x8h.json
index ef05b9c0f25..b6962b545f5 100644
--- a/advisories/unreviewed/2024/05/GHSA-5vcp-m87w-9x8h/GHSA-5vcp-m87w-9x8h.json
+++ b/advisories/unreviewed/2024/05/GHSA-5vcp-m87w-9x8h/GHSA-5vcp-m87w-9x8h.json
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-89"
],
"severity": "HIGH",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/05/GHSA-678w-qrpp-9pjw/GHSA-678w-qrpp-9pjw.json b/advisories/unreviewed/2024/05/GHSA-678w-qrpp-9pjw/GHSA-678w-qrpp-9pjw.json
index 5d8834d4290..2b6c3db3cdc 100644
--- a/advisories/unreviewed/2024/05/GHSA-678w-qrpp-9pjw/GHSA-678w-qrpp-9pjw.json
+++ b/advisories/unreviewed/2024/05/GHSA-678w-qrpp-9pjw/GHSA-678w-qrpp-9pjw.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-678w-qrpp-9pjw",
- "modified": "2024-05-21T18:31:23Z",
+ "modified": "2024-07-03T18:42:58Z",
"published": "2024-05-21T18:31:23Z",
"aliases": [
"CVE-2024-31845"
],
"details": "An issue was discovered in Italtel Embrace 1.6.4. The product does not neutralize or incorrectly neutralizes output that is written to logs. The web application writes logs using a GET query string parameter. This parameter can be modified by an attacker, so that every action he performs is attributed to a different user. This can be exploited without authentication.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-117"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-21T16:15:26Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-6gvx-hwp2-7mfq/GHSA-6gvx-hwp2-7mfq.json b/advisories/unreviewed/2024/05/GHSA-6gvx-hwp2-7mfq/GHSA-6gvx-hwp2-7mfq.json
index 900a963bed1..eaaa153ce88 100644
--- a/advisories/unreviewed/2024/05/GHSA-6gvx-hwp2-7mfq/GHSA-6gvx-hwp2-7mfq.json
+++ b/advisories/unreviewed/2024/05/GHSA-6gvx-hwp2-7mfq/GHSA-6gvx-hwp2-7mfq.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6gvx-hwp2-7mfq",
- "modified": "2024-05-20T18:31:23Z",
+ "modified": "2024-07-03T18:42:38Z",
"published": "2024-05-20T18:31:23Z",
"aliases": [
"CVE-2024-31714"
],
"details": "Buffer Overflow vulnerability in Waxlab wax v.0.9-3 and before allows an attacker to cause a denial of service via the Lua library component.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-121"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-20T18:15:10Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-6qx7-m4qh-j7cp/GHSA-6qx7-m4qh-j7cp.json b/advisories/unreviewed/2024/05/GHSA-6qx7-m4qh-j7cp/GHSA-6qx7-m4qh-j7cp.json
index f3a78fa95da..e33c3ae87a3 100644
--- a/advisories/unreviewed/2024/05/GHSA-6qx7-m4qh-j7cp/GHSA-6qx7-m4qh-j7cp.json
+++ b/advisories/unreviewed/2024/05/GHSA-6qx7-m4qh-j7cp/GHSA-6qx7-m4qh-j7cp.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6qx7-m4qh-j7cp",
- "modified": "2024-05-21T15:31:44Z",
+ "modified": "2024-07-03T18:42:50Z",
"published": "2024-05-21T15:31:44Z",
"aliases": [
"CVE-2021-47367"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nvirtio-net: fix pages leaking when building skb in big mode\n\nWe try to use build_skb() if we had sufficient tailroom. But we forget\nto release the unused pages chained via private in big mode which will\nleak pages. Fixing this by release the pages after building the skb in\nbig mode.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
+ }
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-119"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-21T15:15:22Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-6v79-q248-ccmv/GHSA-6v79-q248-ccmv.json b/advisories/unreviewed/2024/05/GHSA-6v79-q248-ccmv/GHSA-6v79-q248-ccmv.json
index 9d951459d79..60036028ae2 100644
--- a/advisories/unreviewed/2024/05/GHSA-6v79-q248-ccmv/GHSA-6v79-q248-ccmv.json
+++ b/advisories/unreviewed/2024/05/GHSA-6v79-q248-ccmv/GHSA-6v79-q248-ccmv.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6v79-q248-ccmv",
- "modified": "2024-05-17T15:31:09Z",
+ "modified": "2024-07-03T18:42:23Z",
"published": "2024-05-17T15:31:09Z",
"aliases": [
"CVE-2024-34919"
],
"details": "An arbitrary file upload vulnerability in the component \\modstudent\\controller.php of Pisay Online E-Learning System using PHP/MySQL v1.0 allows attackers to execute arbitrary code via uploading a crafted file.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-74"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-17T14:15:10Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-7492-64vw-mc4f/GHSA-7492-64vw-mc4f.json b/advisories/unreviewed/2024/05/GHSA-7492-64vw-mc4f/GHSA-7492-64vw-mc4f.json
index fff2de81baf..9a917e9a9ed 100644
--- a/advisories/unreviewed/2024/05/GHSA-7492-64vw-mc4f/GHSA-7492-64vw-mc4f.json
+++ b/advisories/unreviewed/2024/05/GHSA-7492-64vw-mc4f/GHSA-7492-64vw-mc4f.json
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-89"
],
"severity": "CRITICAL",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/05/GHSA-74p7-wfqr-638p/GHSA-74p7-wfqr-638p.json b/advisories/unreviewed/2024/05/GHSA-74p7-wfqr-638p/GHSA-74p7-wfqr-638p.json
index 5bb6d6886d0..a2e616cc5da 100644
--- a/advisories/unreviewed/2024/05/GHSA-74p7-wfqr-638p/GHSA-74p7-wfqr-638p.json
+++ b/advisories/unreviewed/2024/05/GHSA-74p7-wfqr-638p/GHSA-74p7-wfqr-638p.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-74p7-wfqr-638p",
- "modified": "2024-05-23T18:30:55Z",
+ "modified": "2024-07-03T18:43:28Z",
"published": "2024-05-23T18:30:55Z",
"aliases": [
"CVE-2024-34928"
],
"details": "A SQL injection vulnerability in /model/update_subject_routing.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the grade parameter.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-89"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-23T17:15:29Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-74qf-46c3-qxv8/GHSA-74qf-46c3-qxv8.json b/advisories/unreviewed/2024/05/GHSA-74qf-46c3-qxv8/GHSA-74qf-46c3-qxv8.json
index 6ea3d05ac98..4703c2e29a1 100644
--- a/advisories/unreviewed/2024/05/GHSA-74qf-46c3-qxv8/GHSA-74qf-46c3-qxv8.json
+++ b/advisories/unreviewed/2024/05/GHSA-74qf-46c3-qxv8/GHSA-74qf-46c3-qxv8.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-74qf-46c3-qxv8",
- "modified": "2024-05-21T15:31:43Z",
+ "modified": "2024-07-03T18:42:49Z",
"published": "2024-05-21T15:31:43Z",
"aliases": [
"CVE-2021-47356"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmISDN: fix possible use-after-free in HFC_cleanup()\n\nThis module's remove path calls del_timer(). However, that function\ndoes not wait until the timer handler finishes. This means that the\ntimer handler may still be running after the driver's remove function\nhas finished, which would result in a use-after-free.\n\nFix by calling del_timer_sync(), which makes sure the timer handler\nhas finished, and unable to re-schedule itself.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
+ }
],
"affected": [
@@ -57,9 +60,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-416"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-21T15:15:21Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-7chq-mr2c-3p6c/GHSA-7chq-mr2c-3p6c.json b/advisories/unreviewed/2024/05/GHSA-7chq-mr2c-3p6c/GHSA-7chq-mr2c-3p6c.json
index 7903c94c21a..6bc56819d21 100644
--- a/advisories/unreviewed/2024/05/GHSA-7chq-mr2c-3p6c/GHSA-7chq-mr2c-3p6c.json
+++ b/advisories/unreviewed/2024/05/GHSA-7chq-mr2c-3p6c/GHSA-7chq-mr2c-3p6c.json
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-89"
],
"severity": "HIGH",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/05/GHSA-7fq3-h5p4-7j98/GHSA-7fq3-h5p4-7j98.json b/advisories/unreviewed/2024/05/GHSA-7fq3-h5p4-7j98/GHSA-7fq3-h5p4-7j98.json
index eda6e08500c..ec4c2da336f 100644
--- a/advisories/unreviewed/2024/05/GHSA-7fq3-h5p4-7j98/GHSA-7fq3-h5p4-7j98.json
+++ b/advisories/unreviewed/2024/05/GHSA-7fq3-h5p4-7j98/GHSA-7fq3-h5p4-7j98.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7fq3-h5p4-7j98",
- "modified": "2024-05-21T15:31:44Z",
+ "modified": "2024-07-03T18:42:50Z",
"published": "2024-05-21T15:31:44Z",
"aliases": [
"CVE-2021-47378"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnvme-rdma: destroy cm id before destroy qp to avoid use after free\n\nWe should always destroy cm_id before destroy qp to avoid to get cma\nevent after qp was destroyed, which may lead to use after free.\nIn RDMA connection establishment error flow, don't destroy qp in cm\nevent handler.Just report cm_error to upper level, qp will be destroy\nin nvme_rdma_alloc_queue() after destroy cm id.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -33,9 +36,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-416"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-21T15:15:23Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-7gxw-6q7r-q63r/GHSA-7gxw-6q7r-q63r.json b/advisories/unreviewed/2024/05/GHSA-7gxw-6q7r-q63r/GHSA-7gxw-6q7r-q63r.json
index d2cfb1d1447..e5da71e5aaf 100644
--- a/advisories/unreviewed/2024/05/GHSA-7gxw-6q7r-q63r/GHSA-7gxw-6q7r-q63r.json
+++ b/advisories/unreviewed/2024/05/GHSA-7gxw-6q7r-q63r/GHSA-7gxw-6q7r-q63r.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7gxw-6q7r-q63r",
- "modified": "2024-06-26T00:31:42Z",
+ "modified": "2024-07-03T18:42:22Z",
"published": "2024-05-17T15:31:09Z",
"aliases": [
"CVE-2023-52672"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\npipe: wakeup wr_wait after setting max_usage\n\nCommit c73be61cede5 (\"pipe: Add general notification queue support\") a\nregression was introduced that would lock up resized pipes under certain\nconditions. See the reproducer in [1].\n\nThe commit resizing the pipe ring size was moved to a different\nfunction, doing that moved the wakeup for pipe->wr_wait before actually\nraising pipe->max_usage. If a pipe was full before the resize occured it\nwould result in the wakeup never actually triggering pipe_write.\n\nSet @max_usage and @nr_accounted before waking writers if this isn't a\nwatch queue.\n\n[Christian Brauner : rewrite to account for watch queues]",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -49,9 +52,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-400"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-17T14:15:10Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-7hrf-mgqx-vhg4/GHSA-7hrf-mgqx-vhg4.json b/advisories/unreviewed/2024/05/GHSA-7hrf-mgqx-vhg4/GHSA-7hrf-mgqx-vhg4.json
index d3b07fe4ec4..723c8d0cc34 100644
--- a/advisories/unreviewed/2024/05/GHSA-7hrf-mgqx-vhg4/GHSA-7hrf-mgqx-vhg4.json
+++ b/advisories/unreviewed/2024/05/GHSA-7hrf-mgqx-vhg4/GHSA-7hrf-mgqx-vhg4.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7hrf-mgqx-vhg4",
- "modified": "2024-05-21T15:31:44Z",
+ "modified": "2024-07-03T18:42:50Z",
"published": "2024-05-21T15:31:44Z",
"aliases": [
"CVE-2021-47368"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nenetc: Fix illegal access when reading affinity_hint\n\nirq_set_affinity_hit() stores a reference to the cpumask_t\nparameter in the irq descriptor, and that reference can be\naccessed later from irq_affinity_hint_proc_show(). Since\nthe cpu_mask parameter passed to irq_set_affinity_hit() has\nonly temporary storage (it's on the stack memory), later\naccesses to it are illegal. Thus reads from the corresponding\nprocfs affinity_hint file can result in paging request oops.\n\nThe issue is fixed by the get_cpu_mask() helper, which provides\na permanent storage for the cpumask_t parameter.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
+ }
],
"affected": [
@@ -37,9 +40,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-400"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-21T15:15:22Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-7pr3-9p48-wx7x/GHSA-7pr3-9p48-wx7x.json b/advisories/unreviewed/2024/05/GHSA-7pr3-9p48-wx7x/GHSA-7pr3-9p48-wx7x.json
index 966e86218af..72987aa77e8 100644
--- a/advisories/unreviewed/2024/05/GHSA-7pr3-9p48-wx7x/GHSA-7pr3-9p48-wx7x.json
+++ b/advisories/unreviewed/2024/05/GHSA-7pr3-9p48-wx7x/GHSA-7pr3-9p48-wx7x.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7pr3-9p48-wx7x",
- "modified": "2024-05-21T18:31:19Z",
+ "modified": "2024-07-03T18:42:52Z",
"published": "2024-05-21T18:31:19Z",
"aliases": [
"CVE-2023-52733"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ns390/decompressor: specify __decompress() buf len to avoid overflow\n\nHistorically calls to __decompress() didn't specify \"out_len\" parameter\non many architectures including s390, expecting that no writes beyond\nuncompressed kernel image are performed. This has changed since commit\n2aa14b1ab2c4 (\"zstd: import usptream v1.5.2\") which includes zstd library\ncommit 6a7ede3dfccb (\"Reduce size of dctx by reutilizing dst buffer\n(#2751)\"). Now zstd decompression code might store literal buffer in\nthe unwritten portion of the destination buffer. Since \"out_len\" is\nnot set, it is considered to be unlimited and hence free to use for\noptimization needs. On s390 this might corrupt initrd or ipl report\nwhich are often placed right after the decompressor buffer. Luckily the\nsize of uncompressed kernel image is already known to the decompressor,\nso to avoid the problem simply specify it in the \"out_len\" parameter.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -41,9 +44,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-120"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-21T16:15:13Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-7qhx-cw4f-c3v5/GHSA-7qhx-cw4f-c3v5.json b/advisories/unreviewed/2024/05/GHSA-7qhx-cw4f-c3v5/GHSA-7qhx-cw4f-c3v5.json
index da1b1f5d74a..eb59c176b3e 100644
--- a/advisories/unreviewed/2024/05/GHSA-7qhx-cw4f-c3v5/GHSA-7qhx-cw4f-c3v5.json
+++ b/advisories/unreviewed/2024/05/GHSA-7qhx-cw4f-c3v5/GHSA-7qhx-cw4f-c3v5.json
@@ -28,7 +28,8 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-20"
+ "CWE-20",
+ "CWE-269"
],
"severity": "HIGH",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/05/GHSA-7rp9-cgvf-834p/GHSA-7rp9-cgvf-834p.json b/advisories/unreviewed/2024/05/GHSA-7rp9-cgvf-834p/GHSA-7rp9-cgvf-834p.json
index 8fe8a4256d8..7ab91bc44ad 100644
--- a/advisories/unreviewed/2024/05/GHSA-7rp9-cgvf-834p/GHSA-7rp9-cgvf-834p.json
+++ b/advisories/unreviewed/2024/05/GHSA-7rp9-cgvf-834p/GHSA-7rp9-cgvf-834p.json
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/05/GHSA-85f4-3cvc-fmrq/GHSA-85f4-3cvc-fmrq.json b/advisories/unreviewed/2024/05/GHSA-85f4-3cvc-fmrq/GHSA-85f4-3cvc-fmrq.json
index 3508aadaa7e..eb694bbe6d3 100644
--- a/advisories/unreviewed/2024/05/GHSA-85f4-3cvc-fmrq/GHSA-85f4-3cvc-fmrq.json
+++ b/advisories/unreviewed/2024/05/GHSA-85f4-3cvc-fmrq/GHSA-85f4-3cvc-fmrq.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-85f4-3cvc-fmrq",
- "modified": "2024-05-22T21:30:34Z",
+ "modified": "2024-07-03T18:43:08Z",
"published": "2024-05-22T15:31:00Z",
"aliases": [
"CVE-2024-35475"
],
"details": "A Cross-Site Request Forgery (CSRF) vulnerability was discovered in OpenKM Community Edition on or before version 6.3.12. The vulnerability exists in /admin/DatabaseQuery, which allows an attacker to manipulate a victim with administrative privileges to execute arbitrary SQL commands.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-352"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-22T14:15:08Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-85r3-pmq2-p897/GHSA-85r3-pmq2-p897.json b/advisories/unreviewed/2024/05/GHSA-85r3-pmq2-p897/GHSA-85r3-pmq2-p897.json
index 8247e6941b1..4207920c15f 100644
--- a/advisories/unreviewed/2024/05/GHSA-85r3-pmq2-p897/GHSA-85r3-pmq2-p897.json
+++ b/advisories/unreviewed/2024/05/GHSA-85r3-pmq2-p897/GHSA-85r3-pmq2-p897.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-85r3-pmq2-p897",
- "modified": "2024-05-19T00:30:42Z",
+ "modified": "2024-07-03T18:42:28Z",
"published": "2024-05-19T00:30:42Z",
"aliases": [
"CVE-2024-28063"
],
"details": "Kiteworks Totemomail through 7.0.0 allows /responsiveUI/EnvelopeOpenServlet envelopeRecipient reflected XSS.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-18T22:15:07Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-8gjf-xqc3-q68r/GHSA-8gjf-xqc3-q68r.json b/advisories/unreviewed/2024/05/GHSA-8gjf-xqc3-q68r/GHSA-8gjf-xqc3-q68r.json
index d17e7723879..7b0f85db147 100644
--- a/advisories/unreviewed/2024/05/GHSA-8gjf-xqc3-q68r/GHSA-8gjf-xqc3-q68r.json
+++ b/advisories/unreviewed/2024/05/GHSA-8gjf-xqc3-q68r/GHSA-8gjf-xqc3-q68r.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8gjf-xqc3-q68r",
- "modified": "2024-05-21T18:31:21Z",
+ "modified": "2024-07-03T18:42:57Z",
"published": "2024-05-21T18:31:21Z",
"aliases": [
"CVE-2023-52810"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfs/jfs: Add check for negative db_l2nbperpage\n\nl2nbperpage is log2(number of blks per page), and the minimum legal\nvalue should be 0, not negative.\n\nIn the case of l2nbperpage being negative, an error will occur\nwhen subsequently used as shift exponent.\n\nSyzbot reported this bug:\n\nUBSAN: shift-out-of-bounds in fs/jfs/jfs_dmap.c:799:12\nshift exponent -16777216 is negative",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -57,9 +60,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-1335"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-21T16:15:19Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-8mwf-wgf7-7qpx/GHSA-8mwf-wgf7-7qpx.json b/advisories/unreviewed/2024/05/GHSA-8mwf-wgf7-7qpx/GHSA-8mwf-wgf7-7qpx.json
index 25188124c3c..c47d7c3a565 100644
--- a/advisories/unreviewed/2024/05/GHSA-8mwf-wgf7-7qpx/GHSA-8mwf-wgf7-7qpx.json
+++ b/advisories/unreviewed/2024/05/GHSA-8mwf-wgf7-7qpx/GHSA-8mwf-wgf7-7qpx.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8mwf-wgf7-7qpx",
- "modified": "2024-06-10T18:31:05Z",
+ "modified": "2024-07-03T18:43:53Z",
"published": "2024-05-31T00:30:43Z",
"aliases": [
"CVE-2024-5497"
],
"details": "Out of bounds memory access in Keyboard Inputs in Google Chrome prior to 125.0.6422.141 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -37,9 +40,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-125"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-30T23:15:48Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-8qvr-jr3j-p3rg/GHSA-8qvr-jr3j-p3rg.json b/advisories/unreviewed/2024/05/GHSA-8qvr-jr3j-p3rg/GHSA-8qvr-jr3j-p3rg.json
index ad31bce3daa..0928f96c68d 100644
--- a/advisories/unreviewed/2024/05/GHSA-8qvr-jr3j-p3rg/GHSA-8qvr-jr3j-p3rg.json
+++ b/advisories/unreviewed/2024/05/GHSA-8qvr-jr3j-p3rg/GHSA-8qvr-jr3j-p3rg.json
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-269"
],
"severity": "HIGH",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/05/GHSA-8v6f-ww2f-hcqw/GHSA-8v6f-ww2f-hcqw.json b/advisories/unreviewed/2024/05/GHSA-8v6f-ww2f-hcqw/GHSA-8v6f-ww2f-hcqw.json
index 112867bff98..f78a5a48d20 100644
--- a/advisories/unreviewed/2024/05/GHSA-8v6f-ww2f-hcqw/GHSA-8v6f-ww2f-hcqw.json
+++ b/advisories/unreviewed/2024/05/GHSA-8v6f-ww2f-hcqw/GHSA-8v6f-ww2f-hcqw.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8v6f-ww2f-hcqw",
- "modified": "2024-05-21T15:31:44Z",
+ "modified": "2024-07-03T18:42:50Z",
"published": "2024-05-21T15:31:44Z",
"aliases": [
"CVE-2021-47371"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnexthop: Fix memory leaks in nexthop notification chain listeners\n\nsyzkaller discovered memory leaks [1] that can be reduced to the\nfollowing commands:\n\n # ip nexthop add id 1 blackhole\n # devlink dev reload pci/0000:06:00.0\n\nAs part of the reload flow, mlxsw will unregister its netdevs and then\nunregister from the nexthop notification chain. Before unregistering\nfrom the notification chain, mlxsw will receive delete notifications for\nnexthop objects using netdevs registered by mlxsw or their uppers. mlxsw\nwill not receive notifications for nexthops using netdevs that are not\ndismantled as part of the reload flow. For example, the blackhole\nnexthop above that internally uses the loopback netdev as its nexthop\ndevice.\n\nOne way to fix this problem is to have listeners flush their nexthop\ntables after unregistering from the notification chain. This is\nerror-prone as evident by this patch and also not symmetric with the\nregistration path where a listener receives a dump of all the existing\nnexthops.\n\nTherefore, fix this problem by replaying delete notifications for the\nlistener being unregistered. This is symmetric to the registration path\nand also consistent with the netdev notification chain.\n\nThe above means that unregister_nexthop_notifier(), like\nregister_nexthop_notifier(), will have to take RTNL in order to iterate\nover the existing nexthops and that any callers of the function cannot\nhold RTNL. This is true for mlxsw and netdevsim, but not for the VXLAN\ndriver. To avoid a deadlock, change the latter to unregister its nexthop\nlistener without holding RTNL, making it symmetric to the registration\npath.\n\n[1]\nunreferenced object 0xffff88806173d600 (size 512):\n comm \"syz-executor.0\", pid 1290, jiffies 4295583142 (age 143.507s)\n hex dump (first 32 bytes):\n 41 9d 1e 60 80 88 ff ff 08 d6 73 61 80 88 ff ff A..`......sa....\n 08 d6 73 61 80 88 ff ff 01 00 00 00 00 00 00 00 ..sa............\n backtrace:\n [] kmemleak_alloc_recursive include/linux/kmemleak.h:43 [inline]\n [] slab_post_alloc_hook+0x96/0x490 mm/slab.h:522\n [] slab_alloc_node mm/slub.c:3206 [inline]\n [] slab_alloc mm/slub.c:3214 [inline]\n [] kmem_cache_alloc_trace+0x163/0x370 mm/slub.c:3231\n [] kmalloc include/linux/slab.h:591 [inline]\n [] kzalloc include/linux/slab.h:721 [inline]\n [] mlxsw_sp_nexthop_obj_group_create drivers/net/ethernet/mellanox/mlxsw/spectrum_router.c:4918 [inline]\n [] mlxsw_sp_nexthop_obj_new drivers/net/ethernet/mellanox/mlxsw/spectrum_router.c:5054 [inline]\n [] mlxsw_sp_nexthop_obj_event+0x59a/0x2910 drivers/net/ethernet/mellanox/mlxsw/spectrum_router.c:5239\n [] notifier_call_chain+0xbd/0x210 kernel/notifier.c:83\n [] blocking_notifier_call_chain kernel/notifier.c:318 [inline]\n [] blocking_notifier_call_chain+0x72/0xa0 kernel/notifier.c:306\n [] call_nexthop_notifiers+0x156/0x310 net/ipv4/nexthop.c:244\n [] insert_nexthop net/ipv4/nexthop.c:2336 [inline]\n [] nexthop_add net/ipv4/nexthop.c:2644 [inline]\n [] rtm_new_nexthop+0x14e8/0x4d10 net/ipv4/nexthop.c:2913\n [] rtnetlink_rcv_msg+0x448/0xbf0 net/core/rtnetlink.c:5572\n [] netlink_rcv_skb+0x173/0x480 net/netlink/af_netlink.c:2504\n [] rtnetlink_rcv+0x22/0x30 net/core/rtnetlink.c:5590\n [] netlink_unicast_kernel net/netlink/af_netlink.c:1314 [inline]\n [] netlink_unicast+0x5ae/0x7f0 net/netlink/af_netlink.c:1340\n [] netlink_sendmsg+0x8e1/0xe30 net/netlink/af_netlink.c:1929\n [] sock_sendmsg_nosec net/socket.c:704 [inline\n---truncated---",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
+ }
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-400"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-21T15:15:23Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-8w7w-2rv7-qqw7/GHSA-8w7w-2rv7-qqw7.json b/advisories/unreviewed/2024/05/GHSA-8w7w-2rv7-qqw7/GHSA-8w7w-2rv7-qqw7.json
index 1b1fd2df8ef..f9770863295 100644
--- a/advisories/unreviewed/2024/05/GHSA-8w7w-2rv7-qqw7/GHSA-8w7w-2rv7-qqw7.json
+++ b/advisories/unreviewed/2024/05/GHSA-8w7w-2rv7-qqw7/GHSA-8w7w-2rv7-qqw7.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8w7w-2rv7-qqw7",
- "modified": "2024-05-21T15:31:43Z",
+ "modified": "2024-07-03T18:42:48Z",
"published": "2024-05-21T15:31:43Z",
"aliases": [
"CVE-2021-47327"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\niommu/arm-smmu: Fix arm_smmu_device refcount leak when arm_smmu_rpm_get fails\n\narm_smmu_rpm_get() invokes pm_runtime_get_sync(), which increases the\nrefcount of the \"smmu\" even though the return value is less than 0.\n\nThe reference counting issue happens in some error handling paths of\narm_smmu_rpm_get() in its caller functions. When arm_smmu_rpm_get()\nfails, the caller functions forget to decrease the refcount of \"smmu\"\nincreased by arm_smmu_rpm_get(), causing a refcount leak.\n\nFix this issue by calling pm_runtime_resume_and_get() instead of\npm_runtime_get_sync() in arm_smmu_rpm_get(), which can keep the refcount\nbalanced in case of failure.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
+ }
],
"affected": [
@@ -41,9 +44,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-911"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-21T15:15:19Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-8xgv-q88p-ghq4/GHSA-8xgv-q88p-ghq4.json b/advisories/unreviewed/2024/05/GHSA-8xgv-q88p-ghq4/GHSA-8xgv-q88p-ghq4.json
index a8ed2d9becb..642cb045362 100644
--- a/advisories/unreviewed/2024/05/GHSA-8xgv-q88p-ghq4/GHSA-8xgv-q88p-ghq4.json
+++ b/advisories/unreviewed/2024/05/GHSA-8xgv-q88p-ghq4/GHSA-8xgv-q88p-ghq4.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8xgv-q88p-ghq4",
- "modified": "2024-06-10T18:31:05Z",
+ "modified": "2024-07-03T18:43:53Z",
"published": "2024-05-31T00:30:43Z",
"aliases": [
"CVE-2024-5496"
],
"details": "Use after free in Media Session in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -37,9 +40,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-416"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-30T23:15:48Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-924x-9wjq-6fqr/GHSA-924x-9wjq-6fqr.json b/advisories/unreviewed/2024/05/GHSA-924x-9wjq-6fqr/GHSA-924x-9wjq-6fqr.json
index ecf8a40df7a..c54b0663026 100644
--- a/advisories/unreviewed/2024/05/GHSA-924x-9wjq-6fqr/GHSA-924x-9wjq-6fqr.json
+++ b/advisories/unreviewed/2024/05/GHSA-924x-9wjq-6fqr/GHSA-924x-9wjq-6fqr.json
@@ -25,7 +25,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-352"
],
"severity": null,
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/05/GHSA-94xj-w4jr-wvfv/GHSA-94xj-w4jr-wvfv.json b/advisories/unreviewed/2024/05/GHSA-94xj-w4jr-wvfv/GHSA-94xj-w4jr-wvfv.json
index 1a78f628934..6ae78edd4ca 100644
--- a/advisories/unreviewed/2024/05/GHSA-94xj-w4jr-wvfv/GHSA-94xj-w4jr-wvfv.json
+++ b/advisories/unreviewed/2024/05/GHSA-94xj-w4jr-wvfv/GHSA-94xj-w4jr-wvfv.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-94xj-w4jr-wvfv",
- "modified": "2024-05-23T18:30:55Z",
+ "modified": "2024-07-03T18:43:28Z",
"published": "2024-05-23T18:30:55Z",
"aliases": [
"CVE-2024-34933"
],
"details": "A SQL injection vulnerability in /model/update_grade.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the admission_fee parameter.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-89"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-23T17:15:30Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-999v-p9fh-4w86/GHSA-999v-p9fh-4w86.json b/advisories/unreviewed/2024/05/GHSA-999v-p9fh-4w86/GHSA-999v-p9fh-4w86.json
index 9c989c6d554..d619d0d0468 100644
--- a/advisories/unreviewed/2024/05/GHSA-999v-p9fh-4w86/GHSA-999v-p9fh-4w86.json
+++ b/advisories/unreviewed/2024/05/GHSA-999v-p9fh-4w86/GHSA-999v-p9fh-4w86.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-999v-p9fh-4w86",
- "modified": "2024-05-19T21:30:23Z",
+ "modified": "2024-07-03T18:42:33Z",
"published": "2024-05-19T21:30:23Z",
"aliases": [
"CVE-2024-36078"
],
"details": "In Zammad before 6.3.1, a Ruby gem bundled by Zammad is installed with world-writable file permissions. This allowed a local attacker on the server to modify the gem's files, injecting arbitrary code into Zammad processes (which run with the environment and permissions of the Zammad user).",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-94"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-19T20:15:08Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-9f7p-5f7w-qjm5/GHSA-9f7p-5f7w-qjm5.json b/advisories/unreviewed/2024/05/GHSA-9f7p-5f7w-qjm5/GHSA-9f7p-5f7w-qjm5.json
index e371e0b2351..a7e54a86e37 100644
--- a/advisories/unreviewed/2024/05/GHSA-9f7p-5f7w-qjm5/GHSA-9f7p-5f7w-qjm5.json
+++ b/advisories/unreviewed/2024/05/GHSA-9f7p-5f7w-qjm5/GHSA-9f7p-5f7w-qjm5.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9f7p-5f7w-qjm5",
- "modified": "2024-05-17T06:31:16Z",
+ "modified": "2024-07-03T18:42:21Z",
"published": "2024-05-17T06:31:16Z",
"aliases": [
"CVE-2024-2697"
],
"details": "The socialdriver-framework WordPress plugin before 2024.0.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-17T06:15:51Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-9hhf-j948-m466/GHSA-9hhf-j948-m466.json b/advisories/unreviewed/2024/05/GHSA-9hhf-j948-m466/GHSA-9hhf-j948-m466.json
index 4a8cb041091..17ea491b511 100644
--- a/advisories/unreviewed/2024/05/GHSA-9hhf-j948-m466/GHSA-9hhf-j948-m466.json
+++ b/advisories/unreviewed/2024/05/GHSA-9hhf-j948-m466/GHSA-9hhf-j948-m466.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9hhf-j948-m466",
- "modified": "2024-05-21T18:31:22Z",
+ "modified": "2024-07-03T18:42:57Z",
"published": "2024-05-21T18:31:22Z",
"aliases": [
"CVE-2023-52832"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: don't return unset power in ieee80211_get_tx_power()\n\nWe can get a UBSAN warning if ieee80211_get_tx_power() returns the\nINT_MIN value mac80211 internally uses for \"unset power level\".\n\n UBSAN: signed-integer-overflow in net/wireless/nl80211.c:3816:5\n -2147483648 * 100 cannot be represented in type 'int'\n CPU: 0 PID: 20433 Comm: insmod Tainted: G WC OE\n Call Trace:\n dump_stack+0x74/0x92\n ubsan_epilogue+0x9/0x50\n handle_overflow+0x8d/0xd0\n __ubsan_handle_mul_overflow+0xe/0x10\n nl80211_send_iface+0x688/0x6b0 [cfg80211]\n [...]\n cfg80211_register_wdev+0x78/0xb0 [cfg80211]\n cfg80211_netdev_notifier_call+0x200/0x620 [cfg80211]\n [...]\n ieee80211_if_add+0x60e/0x8f0 [mac80211]\n ieee80211_register_hw+0xda5/0x1170 [mac80211]\n\nIn this case, simply return an error instead, to indicate\nthat no data is available.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
+ }
],
"affected": [
@@ -57,9 +60,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-920"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-21T16:15:20Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-9pf7-cj2r-vr62/GHSA-9pf7-cj2r-vr62.json b/advisories/unreviewed/2024/05/GHSA-9pf7-cj2r-vr62/GHSA-9pf7-cj2r-vr62.json
index db2d52a831a..52c4f44b6b0 100644
--- a/advisories/unreviewed/2024/05/GHSA-9pf7-cj2r-vr62/GHSA-9pf7-cj2r-vr62.json
+++ b/advisories/unreviewed/2024/05/GHSA-9pf7-cj2r-vr62/GHSA-9pf7-cj2r-vr62.json
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-288"
],
"severity": "HIGH",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/05/GHSA-c24q-2hx9-mjpc/GHSA-c24q-2hx9-mjpc.json b/advisories/unreviewed/2024/05/GHSA-c24q-2hx9-mjpc/GHSA-c24q-2hx9-mjpc.json
index 34f88acc6a3..9533cec37e5 100644
--- a/advisories/unreviewed/2024/05/GHSA-c24q-2hx9-mjpc/GHSA-c24q-2hx9-mjpc.json
+++ b/advisories/unreviewed/2024/05/GHSA-c24q-2hx9-mjpc/GHSA-c24q-2hx9-mjpc.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c24q-2hx9-mjpc",
- "modified": "2024-06-10T18:31:03Z",
+ "modified": "2024-07-03T18:43:17Z",
"published": "2024-05-22T18:30:42Z",
"aliases": [
"CVE-2024-5160"
],
"details": "Heap buffer overflow in Dawn in Google Chrome prior to 125.0.6422.76 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -37,9 +40,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-122"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-22T16:15:11Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-c45j-7735-f4r2/GHSA-c45j-7735-f4r2.json b/advisories/unreviewed/2024/05/GHSA-c45j-7735-f4r2/GHSA-c45j-7735-f4r2.json
index db7f7ff6ddc..8049ee3d7b1 100644
--- a/advisories/unreviewed/2024/05/GHSA-c45j-7735-f4r2/GHSA-c45j-7735-f4r2.json
+++ b/advisories/unreviewed/2024/05/GHSA-c45j-7735-f4r2/GHSA-c45j-7735-f4r2.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c45j-7735-f4r2",
- "modified": "2024-05-21T18:31:14Z",
+ "modified": "2024-07-03T18:42:40Z",
"published": "2024-05-20T21:31:09Z",
"aliases": [
"CVE-2024-33900"
],
"details": "KeePassXC 2.7.7 allows attackers to recover cleartext credentials.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N"
+ }
],
"affected": [
@@ -37,9 +40,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-316"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-20T21:15:09Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-c5j5-pffr-9wgm/GHSA-c5j5-pffr-9wgm.json b/advisories/unreviewed/2024/05/GHSA-c5j5-pffr-9wgm/GHSA-c5j5-pffr-9wgm.json
index 4f79b7034ed..a9acada4290 100644
--- a/advisories/unreviewed/2024/05/GHSA-c5j5-pffr-9wgm/GHSA-c5j5-pffr-9wgm.json
+++ b/advisories/unreviewed/2024/05/GHSA-c5j5-pffr-9wgm/GHSA-c5j5-pffr-9wgm.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c5j5-pffr-9wgm",
- "modified": "2024-06-26T00:31:43Z",
+ "modified": "2024-07-03T18:42:26Z",
"published": "2024-05-17T15:31:12Z",
"aliases": [
"CVE-2024-35853"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmlxsw: spectrum_acl_tcam: Fix memory leak during rehash\n\nThe rehash delayed work migrates filters from one region to another.\nThis is done by iterating over all chunks (all the filters with the same\npriority) in the region and in each chunk iterating over all the\nfilters.\n\nIf the migration fails, the code tries to migrate the filters back to\nthe old region. However, the rollback itself can also fail in which case\nanother migration will be erroneously performed. Besides the fact that\nthis ping pong is not a very good idea, it also creates a problem.\n\nEach virtual chunk references two chunks: The currently used one\n('vchunk->chunk') and a backup ('vchunk->chunk2'). During migration the\nfirst holds the chunk we want to migrate filters to and the second holds\nthe chunk we are migrating filters from.\n\nThe code currently assumes - but does not verify - that the backup chunk\ndoes not exist (NULL) if the currently used chunk does not reference the\ntarget region. This assumption breaks when we are trying to rollback a\nrollback, resulting in the backup chunk being overwritten and leaked\n[1].\n\nFix by not rolling back a failed rollback and add a warning to avoid\nfuture cases.\n\n[1]\nWARNING: CPU: 5 PID: 1063 at lib/parman.c:291 parman_destroy+0x17/0x20\nModules linked in:\nCPU: 5 PID: 1063 Comm: kworker/5:11 Tainted: G W 6.9.0-rc2-custom-00784-gc6a05c468a0b #14\nHardware name: Mellanox Technologies Ltd. MSN3700/VMOD0005, BIOS 5.11 01/06/2019\nWorkqueue: mlxsw_core mlxsw_sp_acl_tcam_vregion_rehash_work\nRIP: 0010:parman_destroy+0x17/0x20\n[...]\nCall Trace:\n \n mlxsw_sp_acl_atcam_region_fini+0x19/0x60\n mlxsw_sp_acl_tcam_region_destroy+0x49/0xf0\n mlxsw_sp_acl_tcam_vregion_rehash_work+0x1f1/0x470\n process_one_work+0x151/0x370\n worker_thread+0x2cb/0x3e0\n kthread+0xd0/0x100\n ret_from_fork+0x34/0x50\n ret_from_fork_asm+0x1a/0x30\n ",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H"
+ }
],
"affected": [
@@ -53,9 +56,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-416"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-17T15:15:22Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-c84w-j8mj-57ch/GHSA-c84w-j8mj-57ch.json b/advisories/unreviewed/2024/05/GHSA-c84w-j8mj-57ch/GHSA-c84w-j8mj-57ch.json
index 237d3fc7bfb..5da5d2efa0d 100644
--- a/advisories/unreviewed/2024/05/GHSA-c84w-j8mj-57ch/GHSA-c84w-j8mj-57ch.json
+++ b/advisories/unreviewed/2024/05/GHSA-c84w-j8mj-57ch/GHSA-c84w-j8mj-57ch.json
@@ -57,7 +57,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-476"
],
"severity": null,
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/05/GHSA-c97j-6qv5-jqj7/GHSA-c97j-6qv5-jqj7.json b/advisories/unreviewed/2024/05/GHSA-c97j-6qv5-jqj7/GHSA-c97j-6qv5-jqj7.json
index a9777de8000..ecc3b8564c2 100644
--- a/advisories/unreviewed/2024/05/GHSA-c97j-6qv5-jqj7/GHSA-c97j-6qv5-jqj7.json
+++ b/advisories/unreviewed/2024/05/GHSA-c97j-6qv5-jqj7/GHSA-c97j-6qv5-jqj7.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c97j-6qv5-jqj7",
- "modified": "2024-05-21T15:31:43Z",
+ "modified": "2024-07-03T18:42:49Z",
"published": "2024-05-21T15:31:43Z",
"aliases": [
"CVE-2021-47354"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/sched: Avoid data corruptions\n\nWait for all dependencies of a job to complete before\nkilling it to avoid data corruptions.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
+ }
],
"affected": [
@@ -41,9 +44,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-787"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-21T15:15:21Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-c989-6j3h-w4c3/GHSA-c989-6j3h-w4c3.json b/advisories/unreviewed/2024/05/GHSA-c989-6j3h-w4c3/GHSA-c989-6j3h-w4c3.json
index 2ad5421bb39..fbd1cddcef0 100644
--- a/advisories/unreviewed/2024/05/GHSA-c989-6j3h-w4c3/GHSA-c989-6j3h-w4c3.json
+++ b/advisories/unreviewed/2024/05/GHSA-c989-6j3h-w4c3/GHSA-c989-6j3h-w4c3.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c989-6j3h-w4c3",
- "modified": "2024-05-23T18:30:55Z",
+ "modified": "2024-07-03T18:42:51Z",
"published": "2024-05-21T15:31:45Z",
"aliases": [
"CVE-2024-33529"
],
"details": "ILIAS 7 before 7.30 and ILIAS 8 before 8.11 as well as ILIAS 9.0 allow remote authenticated attackers with administrative privileges to execute operating system commands via file uploads with dangerous types.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -31,7 +34,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-21T15:15:29Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-cm35-f8g3-r786/GHSA-cm35-f8g3-r786.json b/advisories/unreviewed/2024/05/GHSA-cm35-f8g3-r786/GHSA-cm35-f8g3-r786.json
index dbff7104463..4bf4f57da2a 100644
--- a/advisories/unreviewed/2024/05/GHSA-cm35-f8g3-r786/GHSA-cm35-f8g3-r786.json
+++ b/advisories/unreviewed/2024/05/GHSA-cm35-f8g3-r786/GHSA-cm35-f8g3-r786.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cm35-f8g3-r786",
- "modified": "2024-05-21T15:31:42Z",
+ "modified": "2024-07-03T18:42:46Z",
"published": "2024-05-21T15:31:42Z",
"aliases": [
"CVE-2021-47323"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwatchdog: sc520_wdt: Fix possible use-after-free in wdt_turnoff()\n\nThis module's remove path calls del_timer(). However, that function\ndoes not wait until the timer handler finishes. This means that the\ntimer handler may still be running after the driver's remove function\nhas finished, which would result in a use-after-free.\n\nFix by calling del_timer_sync(), which makes sure the timer handler\nhas finished, and unable to re-schedule itself.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -57,9 +60,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-416"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-21T15:15:19Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-cqj4-2pfx-qgmr/GHSA-cqj4-2pfx-qgmr.json b/advisories/unreviewed/2024/05/GHSA-cqj4-2pfx-qgmr/GHSA-cqj4-2pfx-qgmr.json
index 9daf6164cd8..9fc1a26120e 100644
--- a/advisories/unreviewed/2024/05/GHSA-cqj4-2pfx-qgmr/GHSA-cqj4-2pfx-qgmr.json
+++ b/advisories/unreviewed/2024/05/GHSA-cqj4-2pfx-qgmr/GHSA-cqj4-2pfx-qgmr.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cqj4-2pfx-qgmr",
- "modified": "2024-05-22T09:31:45Z",
+ "modified": "2024-07-03T18:43:06Z",
"published": "2024-05-22T09:31:45Z",
"aliases": [
"CVE-2021-47464"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\naudit: fix possible null-pointer dereference in audit_filter_rules\n\nFix possible null-pointer dereference in audit_filter_rules.\n\naudit_filter_rules() error: we previously assumed 'ctx' could be null",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -37,9 +40,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-476"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-22T07:15:11Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-cv8j-wfmq-4fjv/GHSA-cv8j-wfmq-4fjv.json b/advisories/unreviewed/2024/05/GHSA-cv8j-wfmq-4fjv/GHSA-cv8j-wfmq-4fjv.json
index 0432330e487..c2500b83080 100644
--- a/advisories/unreviewed/2024/05/GHSA-cv8j-wfmq-4fjv/GHSA-cv8j-wfmq-4fjv.json
+++ b/advisories/unreviewed/2024/05/GHSA-cv8j-wfmq-4fjv/GHSA-cv8j-wfmq-4fjv.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cv8j-wfmq-4fjv",
- "modified": "2024-05-21T15:31:42Z",
+ "modified": "2024-07-03T18:42:45Z",
"published": "2024-05-21T15:31:42Z",
"aliases": [
"CVE-2021-47295"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: sched: fix memory leak in tcindex_partial_destroy_work\n\nSyzbot reported memory leak in tcindex_set_parms(). The problem was in\nnon-freed perfect hash in tcindex_partial_destroy_work().\n\nIn tcindex_set_parms() new tcindex_data is allocated and some fields from\nold one are copied to new one, but not the perfect hash. Since\ntcindex_partial_destroy_work() is the destroy function for old\ntcindex_data, we need to free perfect hash to avoid memory leak.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -37,9 +40,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-400"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-21T15:15:17Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-f353-mfhf-jfh7/GHSA-f353-mfhf-jfh7.json b/advisories/unreviewed/2024/05/GHSA-f353-mfhf-jfh7/GHSA-f353-mfhf-jfh7.json
index 5261b9a92e9..5cc149f5bcb 100644
--- a/advisories/unreviewed/2024/05/GHSA-f353-mfhf-jfh7/GHSA-f353-mfhf-jfh7.json
+++ b/advisories/unreviewed/2024/05/GHSA-f353-mfhf-jfh7/GHSA-f353-mfhf-jfh7.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f353-mfhf-jfh7",
- "modified": "2024-05-21T15:31:43Z",
+ "modified": "2024-07-03T18:42:48Z",
"published": "2024-05-21T15:31:43Z",
"aliases": [
"CVE-2021-47329"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: megaraid_sas: Fix resource leak in case of probe failure\n\nThe driver doesn't clean up all the allocated resources properly when\nscsi_add_host(), megasas_start_aen() function fails during the PCI device\nprobe.\n\nClean up all those resources.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -41,9 +44,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-400"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-21T15:15:19Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-f6rr-qfxh-hcf9/GHSA-f6rr-qfxh-hcf9.json b/advisories/unreviewed/2024/05/GHSA-f6rr-qfxh-hcf9/GHSA-f6rr-qfxh-hcf9.json
index 7d7a526521a..63c5cabea10 100644
--- a/advisories/unreviewed/2024/05/GHSA-f6rr-qfxh-hcf9/GHSA-f6rr-qfxh-hcf9.json
+++ b/advisories/unreviewed/2024/05/GHSA-f6rr-qfxh-hcf9/GHSA-f6rr-qfxh-hcf9.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f6rr-qfxh-hcf9",
- "modified": "2024-06-10T18:31:05Z",
+ "modified": "2024-07-03T18:43:53Z",
"published": "2024-05-31T00:30:43Z",
"aliases": [
"CVE-2024-5493"
],
"details": "Heap buffer overflow in WebRTC in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -37,9 +40,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-122"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-30T23:15:48Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-f7vw-6h99-wmxg/GHSA-f7vw-6h99-wmxg.json b/advisories/unreviewed/2024/05/GHSA-f7vw-6h99-wmxg/GHSA-f7vw-6h99-wmxg.json
index 04e92f7285f..e6ece0d390e 100644
--- a/advisories/unreviewed/2024/05/GHSA-f7vw-6h99-wmxg/GHSA-f7vw-6h99-wmxg.json
+++ b/advisories/unreviewed/2024/05/GHSA-f7vw-6h99-wmxg/GHSA-f7vw-6h99-wmxg.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f7vw-6h99-wmxg",
- "modified": "2024-05-23T06:30:45Z",
+ "modified": "2024-07-03T18:43:23Z",
"published": "2024-05-23T06:30:45Z",
"aliases": [
"CVE-2024-2220"
],
"details": "The Button contact VR WordPress plugin through 4.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N"
+ }
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-23T06:15:08Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-f835-w392-m6qf/GHSA-f835-w392-m6qf.json b/advisories/unreviewed/2024/05/GHSA-f835-w392-m6qf/GHSA-f835-w392-m6qf.json
index 206f2241553..25bc60fac5e 100644
--- a/advisories/unreviewed/2024/05/GHSA-f835-w392-m6qf/GHSA-f835-w392-m6qf.json
+++ b/advisories/unreviewed/2024/05/GHSA-f835-w392-m6qf/GHSA-f835-w392-m6qf.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f835-w392-m6qf",
- "modified": "2024-06-10T18:31:03Z",
+ "modified": "2024-07-03T18:43:25Z",
"published": "2024-05-23T09:30:28Z",
"aliases": [
"CVE-2024-36013"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: L2CAP: Fix slab-use-after-free in l2cap_connect()\n\nExtend a critical section to prevent chan from early freeing.\nAlso make the l2cap_connect() return type void. Nothing is using the\nreturned value but it is ugly to return a potentially freed pointer.\nMaking it void will help with backports because earlier kernels did use\nthe return value. Now the compile will break for kernels where this\npatch is not a complete fix.\n\nCall stack summary:\n\n[use]\nl2cap_bredr_sig_cmd\n l2cap_connect\n ┌ mutex_lock(&conn->chan_lock);\n │ chan = pchan->ops->new_connection(pchan); <- alloc chan\n │ __l2cap_chan_add(conn, chan);\n │ l2cap_chan_hold(chan);\n │ list_add(&chan->list, &conn->chan_l); ... (1)\n └ mutex_unlock(&conn->chan_lock);\n chan->conf_state ... (4) <- use after free\n\n[free]\nl2cap_conn_del\n┌ mutex_lock(&conn->chan_lock);\n│ foreach chan in conn->chan_l: ... (2)\n│ l2cap_chan_put(chan);\n│ l2cap_chan_destroy\n│ kfree(chan) ... (3) <- chan freed\n└ mutex_unlock(&conn->chan_lock);\n\n==================================================================\nBUG: KASAN: slab-use-after-free in instrument_atomic_read\ninclude/linux/instrumented.h:68 [inline]\nBUG: KASAN: slab-use-after-free in _test_bit\ninclude/asm-generic/bitops/instrumented-non-atomic.h:141 [inline]\nBUG: KASAN: slab-use-after-free in l2cap_connect+0xa67/0x11a0\nnet/bluetooth/l2cap_core.c:4260\nRead of size 8 at addr ffff88810bf040a0 by task kworker/u3:1/311",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:A/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -41,9 +44,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-416"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-23T07:15:08Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-fj3f-4ff6-fm9r/GHSA-fj3f-4ff6-fm9r.json b/advisories/unreviewed/2024/05/GHSA-fj3f-4ff6-fm9r/GHSA-fj3f-4ff6-fm9r.json
index f1b7c4e8436..938b2b07561 100644
--- a/advisories/unreviewed/2024/05/GHSA-fj3f-4ff6-fm9r/GHSA-fj3f-4ff6-fm9r.json
+++ b/advisories/unreviewed/2024/05/GHSA-fj3f-4ff6-fm9r/GHSA-fj3f-4ff6-fm9r.json
@@ -32,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-269"
],
"severity": "HIGH",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/05/GHSA-fmrc-w6m3-5hv4/GHSA-fmrc-w6m3-5hv4.json b/advisories/unreviewed/2024/05/GHSA-fmrc-w6m3-5hv4/GHSA-fmrc-w6m3-5hv4.json
index c2d40c8bcc5..c002a022794 100644
--- a/advisories/unreviewed/2024/05/GHSA-fmrc-w6m3-5hv4/GHSA-fmrc-w6m3-5hv4.json
+++ b/advisories/unreviewed/2024/05/GHSA-fmrc-w6m3-5hv4/GHSA-fmrc-w6m3-5hv4.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fmrc-w6m3-5hv4",
- "modified": "2024-06-26T00:31:43Z",
+ "modified": "2024-07-03T18:42:25Z",
"published": "2024-05-17T15:31:12Z",
"aliases": [
"CVE-2024-35845"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: iwlwifi: dbg-tlv: ensure NUL termination\n\nThe iwl_fw_ini_debug_info_tlv is used as a string, so we must\nensure the string is terminated correctly before using it.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
+ }
],
"affected": [
@@ -53,9 +56,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-134"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-17T15:15:21Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-fpq3-4hc6-6rvg/GHSA-fpq3-4hc6-6rvg.json b/advisories/unreviewed/2024/05/GHSA-fpq3-4hc6-6rvg/GHSA-fpq3-4hc6-6rvg.json
index b9aed9c0833..b4509f086f8 100644
--- a/advisories/unreviewed/2024/05/GHSA-fpq3-4hc6-6rvg/GHSA-fpq3-4hc6-6rvg.json
+++ b/advisories/unreviewed/2024/05/GHSA-fpq3-4hc6-6rvg/GHSA-fpq3-4hc6-6rvg.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fpq3-4hc6-6rvg",
- "modified": "2024-05-21T15:31:43Z",
+ "modified": "2024-07-03T18:42:47Z",
"published": "2024-05-21T15:31:43Z",
"aliases": [
"CVE-2021-47324"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwatchdog: Fix possible use-after-free in wdt_startup()\n\nThis module's remove path calls del_timer(). However, that function\ndoes not wait until the timer handler finishes. This means that the\ntimer handler may still be running after the driver's remove function\nhas finished, which would result in a use-after-free.\n\nFix by calling del_timer_sync(), which makes sure the timer handler\nhas finished, and unable to re-schedule itself.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -57,9 +60,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-416"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-21T15:15:19Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-fv2x-w8xf-gxpq/GHSA-fv2x-w8xf-gxpq.json b/advisories/unreviewed/2024/05/GHSA-fv2x-w8xf-gxpq/GHSA-fv2x-w8xf-gxpq.json
index 59c89aebb72..e104ccaf597 100644
--- a/advisories/unreviewed/2024/05/GHSA-fv2x-w8xf-gxpq/GHSA-fv2x-w8xf-gxpq.json
+++ b/advisories/unreviewed/2024/05/GHSA-fv2x-w8xf-gxpq/GHSA-fv2x-w8xf-gxpq.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fv2x-w8xf-gxpq",
- "modified": "2024-06-10T18:31:05Z",
+ "modified": "2024-07-03T18:43:53Z",
"published": "2024-05-31T00:30:43Z",
"aliases": [
"CVE-2024-5494"
],
"details": "Use after free in Dawn in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -37,9 +40,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-416"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-30T23:15:48Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-g2cf-q8fg-whrr/GHSA-g2cf-q8fg-whrr.json b/advisories/unreviewed/2024/05/GHSA-g2cf-q8fg-whrr/GHSA-g2cf-q8fg-whrr.json
index a67070c26ea..956140b1022 100644
--- a/advisories/unreviewed/2024/05/GHSA-g2cf-q8fg-whrr/GHSA-g2cf-q8fg-whrr.json
+++ b/advisories/unreviewed/2024/05/GHSA-g2cf-q8fg-whrr/GHSA-g2cf-q8fg-whrr.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g2cf-q8fg-whrr",
- "modified": "2024-05-19T09:34:46Z",
+ "modified": "2024-07-03T18:42:30Z",
"published": "2024-05-19T09:34:46Z",
"aliases": [
"CVE-2024-35869"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: guarantee refcounted children from parent session\n\nAvoid potential use-after-free bugs when walking DFS referrals,\nmounting and performing DFS failover by ensuring that all children\nfrom parent @tcon->ses are also refcounted. They're all needed across\nthe entire DFS mount. Get rid of @tcon->dfs_ses_list while we're at\nit, too.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -33,9 +36,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-416"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-19T09:15:08Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-g6c3-xp3q-wqw7/GHSA-g6c3-xp3q-wqw7.json b/advisories/unreviewed/2024/05/GHSA-g6c3-xp3q-wqw7/GHSA-g6c3-xp3q-wqw7.json
index e3bbafad8fb..5848e6ce99f 100644
--- a/advisories/unreviewed/2024/05/GHSA-g6c3-xp3q-wqw7/GHSA-g6c3-xp3q-wqw7.json
+++ b/advisories/unreviewed/2024/05/GHSA-g6c3-xp3q-wqw7/GHSA-g6c3-xp3q-wqw7.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g6c3-xp3q-wqw7",
- "modified": "2024-06-27T15:30:39Z",
+ "modified": "2024-07-03T18:42:22Z",
"published": "2024-05-17T15:31:09Z",
"aliases": [
"CVE-2023-52670"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nrpmsg: virtio: Free driver_override when rpmsg_remove()\n\nFree driver_override when rpmsg_remove(), otherwise\nthe following memory leak will occur:\n\nunreferenced object 0xffff0000d55d7080 (size 128):\n comm \"kworker/u8:2\", pid 56, jiffies 4294893188 (age 214.272s)\n hex dump (first 32 bytes):\n 72 70 6d 73 67 5f 6e 73 00 00 00 00 00 00 00 00 rpmsg_ns........\n 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n backtrace:\n [<000000009c94c9c1>] __kmem_cache_alloc_node+0x1f8/0x320\n [<000000002300d89b>] __kmalloc_node_track_caller+0x44/0x70\n [<00000000228a60c3>] kstrndup+0x4c/0x90\n [<0000000077158695>] driver_set_override+0xd0/0x164\n [<000000003e9c4ea5>] rpmsg_register_device_override+0x98/0x170\n [<000000001c0c89a8>] rpmsg_ns_register_device+0x24/0x30\n [<000000008bbf8fa2>] rpmsg_probe+0x2e0/0x3ec\n [<00000000e65a68df>] virtio_dev_probe+0x1c0/0x280\n [<00000000443331cc>] really_probe+0xbc/0x2dc\n [<00000000391064b1>] __driver_probe_device+0x78/0xe0\n [<00000000a41c9a5b>] driver_probe_device+0xd8/0x160\n [<000000009c3bd5df>] __device_attach_driver+0xb8/0x140\n [<0000000043cd7614>] bus_for_each_drv+0x7c/0xd4\n [<000000003b929a36>] __device_attach+0x9c/0x19c\n [<00000000a94e0ba8>] device_initial_probe+0x14/0x20\n [<000000003c999637>] bus_probe_device+0xa0/0xac",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -61,9 +64,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-401"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-17T14:15:10Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-g9gx-3ccx-85w8/GHSA-g9gx-3ccx-85w8.json b/advisories/unreviewed/2024/05/GHSA-g9gx-3ccx-85w8/GHSA-g9gx-3ccx-85w8.json
index 90f368f0877..c054c6d8c0d 100644
--- a/advisories/unreviewed/2024/05/GHSA-g9gx-3ccx-85w8/GHSA-g9gx-3ccx-85w8.json
+++ b/advisories/unreviewed/2024/05/GHSA-g9gx-3ccx-85w8/GHSA-g9gx-3ccx-85w8.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g9gx-3ccx-85w8",
- "modified": "2024-06-25T21:31:13Z",
+ "modified": "2024-07-03T18:42:25Z",
"published": "2024-05-17T15:31:11Z",
"aliases": [
"CVE-2023-52696"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\npowerpc/powernv: Add a null pointer check in opal_powercap_init()\n\nkasprintf() returns a pointer to dynamically allocated memory\nwhich can be NULL upon failure.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -53,9 +56,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-476"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-17T15:15:20Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-gc47-vpxp-52x2/GHSA-gc47-vpxp-52x2.json b/advisories/unreviewed/2024/05/GHSA-gc47-vpxp-52x2/GHSA-gc47-vpxp-52x2.json
index 8fec05118d3..109b6aaa593 100644
--- a/advisories/unreviewed/2024/05/GHSA-gc47-vpxp-52x2/GHSA-gc47-vpxp-52x2.json
+++ b/advisories/unreviewed/2024/05/GHSA-gc47-vpxp-52x2/GHSA-gc47-vpxp-52x2.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gc47-vpxp-52x2",
- "modified": "2024-05-20T15:31:46Z",
+ "modified": "2024-07-03T18:42:37Z",
"published": "2024-05-20T15:31:46Z",
"aliases": [
"CVE-2024-34953"
],
"details": "An issue in taurusxin ncmdump v1.3.2 allows attackers to cause a Denial of Service (DoS) via memory exhaustion by supplying a crafted .ncm file",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -45,9 +48,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-400"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-20T14:15:09Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-gc8r-vh42-27g4/GHSA-gc8r-vh42-27g4.json b/advisories/unreviewed/2024/05/GHSA-gc8r-vh42-27g4/GHSA-gc8r-vh42-27g4.json
index e85c79ccaab..71eb212c662 100644
--- a/advisories/unreviewed/2024/05/GHSA-gc8r-vh42-27g4/GHSA-gc8r-vh42-27g4.json
+++ b/advisories/unreviewed/2024/05/GHSA-gc8r-vh42-27g4/GHSA-gc8r-vh42-27g4.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gc8r-vh42-27g4",
- "modified": "2024-05-21T15:31:40Z",
+ "modified": "2024-07-03T18:42:43Z",
"published": "2024-05-21T15:31:40Z",
"aliases": [
"CVE-2021-47242"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: fix soft lookup in subflow_error_report()\n\nMaxim reported a soft lookup in subflow_error_report():\n\n watchdog: BUG: soft lockup - CPU#0 stuck for 22s! [swapper/0:0]\n RIP: 0010:native_queued_spin_lock_slowpath\n RSP: 0018:ffffa859c0003bc0 EFLAGS: 00000202\n RAX: 0000000000000101 RBX: 0000000000000001 RCX: 0000000000000000\n RDX: ffff9195c2772d88 RSI: 0000000000000000 RDI: ffff9195c2772d88\n RBP: ffff9195c2772d00 R08: 00000000000067b0 R09: c6e31da9eb1e44f4\n R10: ffff9195ef379700 R11: ffff9195edb50710 R12: ffff9195c2772d88\n R13: ffff9195f500e3d0 R14: ffff9195ef379700 R15: ffff9195ef379700\n FS: 0000000000000000(0000) GS:ffff91961f400000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 000000c000407000 CR3: 0000000002988000 CR4: 00000000000006f0\n Call Trace:\n \n _raw_spin_lock_bh\n subflow_error_report\n mptcp_subflow_data_available\n __mptcp_move_skbs_from_subflow\n mptcp_data_ready\n tcp_data_queue\n tcp_rcv_established\n tcp_v4_do_rcv\n tcp_v4_rcv\n ip_protocol_deliver_rcu\n ip_local_deliver_finish\n __netif_receive_skb_one_core\n netif_receive_skb\n rtl8139_poll 8139too\n __napi_poll\n net_rx_action\n __do_softirq\n __irq_exit_rcu\n common_interrupt\n \n\nThe calling function - mptcp_subflow_data_available() - can be invoked\nfrom different contexts:\n- plain ssk socket lock\n- ssk socket lock + mptcp_data_lock\n- ssk socket lock + mptcp_data_lock + msk socket lock.\n\nSince subflow_error_report() tries to acquire the mptcp_data_lock, the\nlatter two call chains will cause soft lookup.\n\nThis change addresses the issue moving the error reporting call to\nouter functions, where the held locks list is known and the we can\nacquire only the needed one.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-1281"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-21T15:15:13Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-gcpc-53j8-75v3/GHSA-gcpc-53j8-75v3.json b/advisories/unreviewed/2024/05/GHSA-gcpc-53j8-75v3/GHSA-gcpc-53j8-75v3.json
index 464758403e3..d505af6f574 100644
--- a/advisories/unreviewed/2024/05/GHSA-gcpc-53j8-75v3/GHSA-gcpc-53j8-75v3.json
+++ b/advisories/unreviewed/2024/05/GHSA-gcpc-53j8-75v3/GHSA-gcpc-53j8-75v3.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gcpc-53j8-75v3",
- "modified": "2024-05-31T00:30:44Z",
+ "modified": "2024-07-03T18:43:54Z",
"published": "2024-05-31T00:30:44Z",
"aliases": [
"CVE-2024-37017"
],
"details": "asdcplib (aka AS-DCP Lib) 2.13.1 has a heap-based buffer over-read in ASDCP::TimedText::MXFReader::h__Reader::MD_to_TimedText_TDesc in AS_DCP_TimedText.cpp in libasdcp.so.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-120"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-31T00:15:08Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-gpgj-87v4-mj9r/GHSA-gpgj-87v4-mj9r.json b/advisories/unreviewed/2024/05/GHSA-gpgj-87v4-mj9r/GHSA-gpgj-87v4-mj9r.json
index c1e2c456d1c..5fe68bf190d 100644
--- a/advisories/unreviewed/2024/05/GHSA-gpgj-87v4-mj9r/GHSA-gpgj-87v4-mj9r.json
+++ b/advisories/unreviewed/2024/05/GHSA-gpgj-87v4-mj9r/GHSA-gpgj-87v4-mj9r.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gpgj-87v4-mj9r",
- "modified": "2024-05-17T15:31:09Z",
+ "modified": "2024-07-03T18:42:25Z",
"published": "2024-05-17T15:31:09Z",
"aliases": [
"CVE-2024-35799"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Prevent crash when disable stream\n\n[Why]\nDisabling stream encoder invokes a function that no longer exists.\n\n[How]\nCheck if the function declaration is NULL in disable stream encoder.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -37,9 +40,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-400"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-17T14:15:12Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-gqx6-737f-q6m3/GHSA-gqx6-737f-q6m3.json b/advisories/unreviewed/2024/05/GHSA-gqx6-737f-q6m3/GHSA-gqx6-737f-q6m3.json
index a878f884f6b..558e708c163 100644
--- a/advisories/unreviewed/2024/05/GHSA-gqx6-737f-q6m3/GHSA-gqx6-737f-q6m3.json
+++ b/advisories/unreviewed/2024/05/GHSA-gqx6-737f-q6m3/GHSA-gqx6-737f-q6m3.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gqx6-737f-q6m3",
- "modified": "2024-05-21T12:30:52Z",
+ "modified": "2024-07-03T18:42:40Z",
"published": "2024-05-21T12:30:52Z",
"aliases": [
"CVE-2024-4988"
],
"details": "The mobile application (com.transsion.videocallenhancer) interface has improper permission control, which can lead to the risk of private file leakage.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
+ }
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-284"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-21T10:15:11Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-h8rm-f377-9c5v/GHSA-h8rm-f377-9c5v.json b/advisories/unreviewed/2024/05/GHSA-h8rm-f377-9c5v/GHSA-h8rm-f377-9c5v.json
index dfeba2666f3..82a70cd1b41 100644
--- a/advisories/unreviewed/2024/05/GHSA-h8rm-f377-9c5v/GHSA-h8rm-f377-9c5v.json
+++ b/advisories/unreviewed/2024/05/GHSA-h8rm-f377-9c5v/GHSA-h8rm-f377-9c5v.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h8rm-f377-9c5v",
- "modified": "2024-05-22T09:31:46Z",
+ "modified": "2024-07-03T18:43:08Z",
"published": "2024-05-22T09:31:46Z",
"aliases": [
"CVE-2021-47486"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nriscv, bpf: Fix potential NULL dereference\n\nThe bpf_jit_binary_free() function requires a non-NULL argument. When\nthe RISC-V BPF JIT fails to converge in NR_JIT_ITERATIONS steps,\njit_data->header will be NULL, which triggers a NULL\ndereference. Avoid this by checking the argument, prior calling the\nfunction.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -33,9 +36,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-476"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-22T09:15:10Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-h8rv-v4gm-prcg/GHSA-h8rv-v4gm-prcg.json b/advisories/unreviewed/2024/05/GHSA-h8rv-v4gm-prcg/GHSA-h8rv-v4gm-prcg.json
index 0a2f076ced7..ce42298cf20 100644
--- a/advisories/unreviewed/2024/05/GHSA-h8rv-v4gm-prcg/GHSA-h8rv-v4gm-prcg.json
+++ b/advisories/unreviewed/2024/05/GHSA-h8rv-v4gm-prcg/GHSA-h8rv-v4gm-prcg.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h8rv-v4gm-prcg",
- "modified": "2024-05-22T06:30:38Z",
+ "modified": "2024-07-03T18:43:05Z",
"published": "2024-05-22T06:30:38Z",
"aliases": [
"CVE-2024-30419"
],
"details": "Cross-site scripting vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.12, Ver.3.0.x series versions prior to Ver.3.0.32, Ver.2.11.x series versions prior to Ver.2.11.61, Ver.2.10.x series versions prior to Ver.2.10.53, and Ver.2.9 and earlier versions. If this vulnerability is exploited, a user with a contributor or higher privilege who can log in to the product may execute an arbitrary script on the web browser of the user who accessed the website using the product.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
+ }
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-22T05:15:52Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-h9h4-qmr7-m6fj/GHSA-h9h4-qmr7-m6fj.json b/advisories/unreviewed/2024/05/GHSA-h9h4-qmr7-m6fj/GHSA-h9h4-qmr7-m6fj.json
index c6d5da69429..50e1cc4216e 100644
--- a/advisories/unreviewed/2024/05/GHSA-h9h4-qmr7-m6fj/GHSA-h9h4-qmr7-m6fj.json
+++ b/advisories/unreviewed/2024/05/GHSA-h9h4-qmr7-m6fj/GHSA-h9h4-qmr7-m6fj.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h9h4-qmr7-m6fj",
- "modified": "2024-05-22T15:31:00Z",
+ "modified": "2024-07-03T18:43:09Z",
"published": "2024-05-22T15:31:00Z",
"aliases": [
"CVE-2024-35555"
],
"details": "idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/share_switch.php?mudi=switch&dataType=newsWeb&fieldName=state&fieldName2=state&tabName=infoWeb&dataID=40.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-352"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-22T14:15:09Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-hc62-cr99-v89f/GHSA-hc62-cr99-v89f.json b/advisories/unreviewed/2024/05/GHSA-hc62-cr99-v89f/GHSA-hc62-cr99-v89f.json
index 34e3b825333..26053ca5f1b 100644
--- a/advisories/unreviewed/2024/05/GHSA-hc62-cr99-v89f/GHSA-hc62-cr99-v89f.json
+++ b/advisories/unreviewed/2024/05/GHSA-hc62-cr99-v89f/GHSA-hc62-cr99-v89f.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hc62-cr99-v89f",
- "modified": "2024-05-23T18:30:55Z",
+ "modified": "2024-07-03T18:43:28Z",
"published": "2024-05-23T18:30:55Z",
"aliases": [
"CVE-2024-35084"
],
"details": "J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in SysMsgPushMapper.xml.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-89"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-23T17:15:30Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-hgw6-479w-27jj/GHSA-hgw6-479w-27jj.json b/advisories/unreviewed/2024/05/GHSA-hgw6-479w-27jj/GHSA-hgw6-479w-27jj.json
index bff281d7ffb..9d28f955f0e 100644
--- a/advisories/unreviewed/2024/05/GHSA-hgw6-479w-27jj/GHSA-hgw6-479w-27jj.json
+++ b/advisories/unreviewed/2024/05/GHSA-hgw6-479w-27jj/GHSA-hgw6-479w-27jj.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hgw6-479w-27jj",
- "modified": "2024-06-27T12:30:46Z",
+ "modified": "2024-07-03T18:42:36Z",
"published": "2024-05-20T12:30:28Z",
"aliases": [
"CVE-2024-35960"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5: Properly link new fs rules into the tree\n\nPreviously, add_rule_fg would only add newly created rules from the\nhandle into the tree when they had a refcount of 1. On the other hand,\ncreate_flow_handle tries hard to find and reference already existing\nidentical rules instead of creating new ones.\n\nThese two behaviors can result in a situation where create_flow_handle\n1) creates a new rule and references it, then\n2) in a subsequent step during the same handle creation references it\n again,\nresulting in a rule with a refcount of 2 that is not linked into the\ntree, will have a NULL parent and root and will result in a crash when\nthe flow group is deleted because del_sw_hw_rule, invoked on rule\ndeletion, assumes node->parent is != NULL.\n\nThis happened in the wild, due to another bug related to incorrect\nhandling of duplicate pkt_reformat ids, which lead to the code in\ncreate_flow_handle incorrectly referencing a just-added rule in the same\nflow handle, resulting in the problem described above. Full details are\nat [1].\n\nThis patch changes add_rule_fg to add new rules without parents into\nthe tree, properly initializing them and avoiding the crash. This makes\nit more consistent with how rules are added to an FTE in\ncreate_flow_handle.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
+ }
],
"affected": [
@@ -61,9 +64,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-476"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-20T10:15:11Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-hh94-frj2-pf9r/GHSA-hh94-frj2-pf9r.json b/advisories/unreviewed/2024/05/GHSA-hh94-frj2-pf9r/GHSA-hh94-frj2-pf9r.json
index 75c8e5d0d40..5ae7f1170a5 100644
--- a/advisories/unreviewed/2024/05/GHSA-hh94-frj2-pf9r/GHSA-hh94-frj2-pf9r.json
+++ b/advisories/unreviewed/2024/05/GHSA-hh94-frj2-pf9r/GHSA-hh94-frj2-pf9r.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hh94-frj2-pf9r",
- "modified": "2024-05-21T15:31:40Z",
+ "modified": "2024-07-03T18:42:42Z",
"published": "2024-05-21T15:31:40Z",
"aliases": [
"CVE-2021-47241"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nethtool: strset: fix message length calculation\n\nOuter nest for ETHTOOL_A_STRSET_STRINGSETS is not accounted for.\nThis may result in ETHTOOL_MSG_STRSET_GET producing a warning like:\n\n calculated message payload length (684) not sufficient\n WARNING: CPU: 0 PID: 30967 at net/ethtool/netlink.c:369 ethnl_default_doit+0x87a/0xa20\n\nand a splat.\n\nAs usually with such warnings three conditions must be met for the warning\nto trigger:\n - there must be no skb size rounding up (e.g. reply_size of 684);\n - string set must be per-device (so that the header gets populated);\n - the device name must be at least 12 characters long.\n\nall in all with current user space it looks like reading priv flags\nis the only place this could potentially happen. Or with syzbot :)",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -33,9 +36,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-266"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-21T15:15:13Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-hh96-p296-x7m4/GHSA-hh96-p296-x7m4.json b/advisories/unreviewed/2024/05/GHSA-hh96-p296-x7m4/GHSA-hh96-p296-x7m4.json
index c93271e9a6f..e67597806ad 100644
--- a/advisories/unreviewed/2024/05/GHSA-hh96-p296-x7m4/GHSA-hh96-p296-x7m4.json
+++ b/advisories/unreviewed/2024/05/GHSA-hh96-p296-x7m4/GHSA-hh96-p296-x7m4.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hh96-p296-x7m4",
- "modified": "2024-06-27T15:30:39Z",
+ "modified": "2024-07-03T18:42:21Z",
"published": "2024-05-17T12:31:00Z",
"aliases": [
"CVE-2024-27405"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: ncm: Avoid dropping datagrams of properly parsed NTBs\n\nIt is observed sometimes when tethering is used over NCM with Windows 11\nas host, at some instances, the gadget_giveback has one byte appended at\nthe end of a proper NTB. When the NTB is parsed, unwrap call looks for\nany leftover bytes in SKB provided by u_ether and if there are any pending\nbytes, it treats them as a separate NTB and parses it. But in case the\nsecond NTB (as per unwrap call) is faulty/corrupt, all the datagrams that\nwere parsed properly in the first NTB and saved in rx_list are dropped.\n\nAdding a few custom traces showed the following:\n[002] d..1 7828.532866: dwc3_gadget_giveback: ep1out:\nreq 000000003868811a length 1025/16384 zsI ==> 0\n[002] d..1 7828.532867: ncm_unwrap_ntb: K: ncm_unwrap_ntb toprocess: 1025\n[002] d..1 7828.532867: ncm_unwrap_ntb: K: ncm_unwrap_ntb nth: 1751999342\n[002] d..1 7828.532868: ncm_unwrap_ntb: K: ncm_unwrap_ntb seq: 0xce67\n[002] d..1 7828.532868: ncm_unwrap_ntb: K: ncm_unwrap_ntb blk_len: 0x400\n[002] d..1 7828.532868: ncm_unwrap_ntb: K: ncm_unwrap_ntb ndp_len: 0x10\n[002] d..1 7828.532869: ncm_unwrap_ntb: K: Parsed NTB with 1 frames\n\nIn this case, the giveback is of 1025 bytes and block length is 1024.\nThe rest 1 byte (which is 0x00) won't be parsed resulting in drop of\nall datagrams in rx_list.\n\nSame is case with packets of size 2048:\n[002] d..1 7828.557948: dwc3_gadget_giveback: ep1out:\nreq 0000000011dfd96e length 2049/16384 zsI ==> 0\n[002] d..1 7828.557949: ncm_unwrap_ntb: K: ncm_unwrap_ntb nth: 1751999342\n[002] d..1 7828.557950: ncm_unwrap_ntb: K: ncm_unwrap_ntb blk_len: 0x800\n\nLecroy shows one byte coming in extra confirming that the byte is coming\nin from PC:\n\n Transfer 2959 - Bytes Transferred(1025) Timestamp((18.524 843 590)\n - Transaction 8391 - Data(1025 bytes) Timestamp(18.524 843 590)\n --- Packet 4063861\n Data(1024 bytes)\n Duration(2.117us) Idle(14.700ns) Timestamp(18.524 843 590)\n --- Packet 4063863\n Data(1 byte)\n Duration(66.160ns) Time(282.000ns) Timestamp(18.524 845 722)\n\nAccording to Windows driver, no ZLP is needed if wBlockLength is non-zero,\nbecause the non-zero wBlockLength has already told the function side the\nsize of transfer to be expected. However, there are in-market NCM devices\nthat rely on ZLP as long as the wBlockLength is multiple of wMaxPacketSize.\nTo deal with such devices, it pads an extra 0 at end so the transfer is no\nlonger multiple of wMaxPacketSize.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -61,9 +64,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-476"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-17T12:15:10Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-hp4h-jp42-gc6q/GHSA-hp4h-jp42-gc6q.json b/advisories/unreviewed/2024/05/GHSA-hp4h-jp42-gc6q/GHSA-hp4h-jp42-gc6q.json
index 634b9172f8b..20e7f42affd 100644
--- a/advisories/unreviewed/2024/05/GHSA-hp4h-jp42-gc6q/GHSA-hp4h-jp42-gc6q.json
+++ b/advisories/unreviewed/2024/05/GHSA-hp4h-jp42-gc6q/GHSA-hp4h-jp42-gc6q.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hp4h-jp42-gc6q",
- "modified": "2024-05-17T09:31:00Z",
+ "modified": "2024-07-03T18:42:21Z",
"published": "2024-05-17T09:31:00Z",
"aliases": [
"CVE-2024-35110"
],
"details": "A reflected XSS vulnerability has been found in YzmCMS 7.1. The vulnerability exists in yzmphp/core/class/application.class.php: when logged-in users access a malicious link, their cookies can be captured by an attacker.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-17T08:15:06Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-hp7j-hj47-34vh/GHSA-hp7j-hj47-34vh.json b/advisories/unreviewed/2024/05/GHSA-hp7j-hj47-34vh/GHSA-hp7j-hj47-34vh.json
index 845549e1c77..1532fb2ca5c 100644
--- a/advisories/unreviewed/2024/05/GHSA-hp7j-hj47-34vh/GHSA-hp7j-hj47-34vh.json
+++ b/advisories/unreviewed/2024/05/GHSA-hp7j-hj47-34vh/GHSA-hp7j-hj47-34vh.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hp7j-hj47-34vh",
- "modified": "2024-05-20T18:31:21Z",
+ "modified": "2024-07-03T18:42:37Z",
"published": "2024-05-20T15:31:44Z",
"aliases": [
"CVE-2023-49330"
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-89"
],
"severity": "HIGH",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/05/GHSA-hpp5-56vf-wwqg/GHSA-hpp5-56vf-wwqg.json b/advisories/unreviewed/2024/05/GHSA-hpp5-56vf-wwqg/GHSA-hpp5-56vf-wwqg.json
index caf388deb35..73a104aa4f5 100644
--- a/advisories/unreviewed/2024/05/GHSA-hpp5-56vf-wwqg/GHSA-hpp5-56vf-wwqg.json
+++ b/advisories/unreviewed/2024/05/GHSA-hpp5-56vf-wwqg/GHSA-hpp5-56vf-wwqg.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hpp5-56vf-wwqg",
- "modified": "2024-05-22T06:30:38Z",
+ "modified": "2024-07-03T18:43:05Z",
"published": "2024-05-22T06:30:38Z",
"aliases": [
"CVE-2024-31340"
],
"details": "TP-Link Tether versions prior to 4.5.13 and TP-Link Tapo versions prior to 3.3.6 do not properly validate certificates, which may allow a remote unauthenticated attacker to eavesdrop on an encrypted communication via a man-in-the-middle attack.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
+ }
],
"affected": [
@@ -35,7 +38,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-22T06:15:12Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-hq29-fr4v-2847/GHSA-hq29-fr4v-2847.json b/advisories/unreviewed/2024/05/GHSA-hq29-fr4v-2847/GHSA-hq29-fr4v-2847.json
index a14c8f3cfe3..646d7c847ba 100644
--- a/advisories/unreviewed/2024/05/GHSA-hq29-fr4v-2847/GHSA-hq29-fr4v-2847.json
+++ b/advisories/unreviewed/2024/05/GHSA-hq29-fr4v-2847/GHSA-hq29-fr4v-2847.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hq29-fr4v-2847",
- "modified": "2024-05-21T15:31:44Z",
+ "modified": "2024-07-03T18:42:50Z",
"published": "2024-05-21T15:31:44Z",
"aliases": [
"CVE-2021-47369"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ns390/qeth: fix NULL deref in qeth_clear_working_pool_list()\n\nWhen qeth_set_online() calls qeth_clear_working_pool_list() to roll\nback after an error exit from qeth_hardsetup_card(), we are at risk of\naccessing card->qdio.in_q before it was allocated by\nqeth_alloc_qdio_queues() via qeth_mpc_initialize().\n\nqeth_clear_working_pool_list() then dereferences NULL, and by writing to\nqueue->bufs[i].pool_entry scribbles all over the CPU's lowcore.\nResulting in a crash when those lowcore areas are used next (eg. on\nthe next machine-check interrupt).\n\nSuch a scenario would typically happen when the device is first set\nonline and its queues aren't allocated yet. An early IO error or certain\nmisconfigs (eg. mismatched transport mode, bad portno) then cause us to\nerror out from qeth_hardsetup_card() with card->qdio.in_q still being\nNULL.\n\nFix it by checking the pointer for NULL before accessing it.\n\nNote that we also have (rare) paths inside qeth_mpc_initialize() where\na configuration change can cause us to free the existing queues,\nexpecting that subsequent code will allocate them again. If we then\nerror out before that re-allocation happens, the same bug occurs.\n\nRoot-caused-by: Heiko Carstens ",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -33,9 +36,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-476"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-21T15:15:22Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-hqfv-mf6j-g3j6/GHSA-hqfv-mf6j-g3j6.json b/advisories/unreviewed/2024/05/GHSA-hqfv-mf6j-g3j6/GHSA-hqfv-mf6j-g3j6.json
index 6b5bd0fbf79..668b0bd055d 100644
--- a/advisories/unreviewed/2024/05/GHSA-hqfv-mf6j-g3j6/GHSA-hqfv-mf6j-g3j6.json
+++ b/advisories/unreviewed/2024/05/GHSA-hqfv-mf6j-g3j6/GHSA-hqfv-mf6j-g3j6.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hqfv-mf6j-g3j6",
- "modified": "2024-06-10T18:31:05Z",
+ "modified": "2024-07-03T18:43:54Z",
"published": "2024-05-31T00:30:44Z",
"aliases": [
"CVE-2024-5499"
],
"details": "Out of bounds write in Streams API in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -37,9 +40,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-787"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-30T23:15:48Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-j8hx-6rxw-p4r9/GHSA-j8hx-6rxw-p4r9.json b/advisories/unreviewed/2024/05/GHSA-j8hx-6rxw-p4r9/GHSA-j8hx-6rxw-p4r9.json
index 550ff80b791..c6c271686c7 100644
--- a/advisories/unreviewed/2024/05/GHSA-j8hx-6rxw-p4r9/GHSA-j8hx-6rxw-p4r9.json
+++ b/advisories/unreviewed/2024/05/GHSA-j8hx-6rxw-p4r9/GHSA-j8hx-6rxw-p4r9.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j8hx-6rxw-p4r9",
- "modified": "2024-05-21T15:31:40Z",
+ "modified": "2024-07-03T18:42:42Z",
"published": "2024-05-21T15:31:39Z",
"aliases": [
"CVE-2021-47230"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: x86: Immediately reset the MMU context when the SMM flag is cleared\n\nImmediately reset the MMU context when the vCPU's SMM flag is cleared so\nthat the SMM flag in the MMU role is always synchronized with the vCPU's\nflag. If RSM fails (which isn't correctly emulated), KVM will bail\nwithout calling post_leave_smm() and leave the MMU in a bad state.\n\nThe bad MMU role can lead to a NULL pointer dereference when grabbing a\nshadow page's rmap for a page fault as the initial lookups for the gfn\nwill happen with the vCPU's SMM flag (=0), whereas the rmap lookup will\nuse the shadow page's SMM flag, which comes from the MMU (=1). SMM has\nan entirely different set of memslots, and so the initial lookup can find\na memslot (SMM=0) and then explode on the rmap memslot lookup (SMM=1).\n\n general protection fault, probably for non-canonical address 0xdffffc0000000000: 0000 [#1] PREEMPT SMP KASAN\n KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]\n CPU: 1 PID: 8410 Comm: syz-executor382 Not tainted 5.13.0-rc5-syzkaller #0\n Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011\n RIP: 0010:__gfn_to_rmap arch/x86/kvm/mmu/mmu.c:935 [inline]\n RIP: 0010:gfn_to_rmap+0x2b0/0x4d0 arch/x86/kvm/mmu/mmu.c:947\n Code: <42> 80 3c 20 00 74 08 4c 89 ff e8 f1 79 a9 00 4c 89 fb 4d 8b 37 44\n RSP: 0018:ffffc90000ffef98 EFLAGS: 00010246\n RAX: 0000000000000000 RBX: ffff888015b9f414 RCX: ffff888019669c40\n RDX: 0000000000000000 RSI: 0000000000000001 RDI: 0000000000000001\n RBP: 0000000000000001 R08: ffffffff811d9cdb R09: ffffed10065a6002\n R10: ffffed10065a6002 R11: 0000000000000000 R12: dffffc0000000000\n R13: 0000000000000003 R14: 0000000000000001 R15: 0000000000000000\n FS: 000000000124b300(0000) GS:ffff8880b9b00000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 0000000000000000 CR3: 0000000028e31000 CR4: 00000000001526e0\n DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n Call Trace:\n rmap_add arch/x86/kvm/mmu/mmu.c:965 [inline]\n mmu_set_spte+0x862/0xe60 arch/x86/kvm/mmu/mmu.c:2604\n __direct_map arch/x86/kvm/mmu/mmu.c:2862 [inline]\n direct_page_fault+0x1f74/0x2b70 arch/x86/kvm/mmu/mmu.c:3769\n kvm_mmu_do_page_fault arch/x86/kvm/mmu.h:124 [inline]\n kvm_mmu_page_fault+0x199/0x1440 arch/x86/kvm/mmu/mmu.c:5065\n vmx_handle_exit+0x26/0x160 arch/x86/kvm/vmx/vmx.c:6122\n vcpu_enter_guest+0x3bdd/0x9630 arch/x86/kvm/x86.c:9428\n vcpu_run+0x416/0xc20 arch/x86/kvm/x86.c:9494\n kvm_arch_vcpu_ioctl_run+0x4e8/0xa40 arch/x86/kvm/x86.c:9722\n kvm_vcpu_ioctl+0x70f/0xbb0 arch/x86/kvm/../../../virt/kvm/kvm_main.c:3460\n vfs_ioctl fs/ioctl.c:51 [inline]\n __do_sys_ioctl fs/ioctl.c:1069 [inline]\n __se_sys_ioctl+0xfb/0x170 fs/ioctl.c:1055\n do_syscall_64+0x3f/0xb0 arch/x86/entry/common.c:47\n entry_SYSCALL_64_after_hwframe+0x44/0xae\n RIP: 0033:0x440ce9",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H"
+ }
],
"affected": [
@@ -37,9 +40,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-476"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-21T15:15:12Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-jf28-v5f6-cvpr/GHSA-jf28-v5f6-cvpr.json b/advisories/unreviewed/2024/05/GHSA-jf28-v5f6-cvpr/GHSA-jf28-v5f6-cvpr.json
index 537bdd1e806..470dc03d9cc 100644
--- a/advisories/unreviewed/2024/05/GHSA-jf28-v5f6-cvpr/GHSA-jf28-v5f6-cvpr.json
+++ b/advisories/unreviewed/2024/05/GHSA-jf28-v5f6-cvpr/GHSA-jf28-v5f6-cvpr.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jf28-v5f6-cvpr",
- "modified": "2024-05-21T18:31:24Z",
+ "modified": "2024-07-03T18:42:59Z",
"published": "2024-05-21T18:31:24Z",
"aliases": [
"CVE-2024-35057"
],
"details": "An issue in NASA AIT-Core v2.5.2 allows attackers to execute arbitrary code via a crafted packet.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-319"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-21T18:15:09Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-jmm7-6r74-7f4p/GHSA-jmm7-6r74-7f4p.json b/advisories/unreviewed/2024/05/GHSA-jmm7-6r74-7f4p/GHSA-jmm7-6r74-7f4p.json
index c38aa028c66..7e06c1672c8 100644
--- a/advisories/unreviewed/2024/05/GHSA-jmm7-6r74-7f4p/GHSA-jmm7-6r74-7f4p.json
+++ b/advisories/unreviewed/2024/05/GHSA-jmm7-6r74-7f4p/GHSA-jmm7-6r74-7f4p.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jmm7-6r74-7f4p",
- "modified": "2024-05-21T15:31:45Z",
+ "modified": "2024-07-03T18:42:51Z",
"published": "2024-05-21T15:31:45Z",
"aliases": [
"CVE-2021-47403"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nipack: ipoctal: fix module reference leak\n\nA reference to the carrier module was taken on every open but was only\nreleased once when the final reference to the tty struct was dropped.\n\nFix this by taking the module reference and initialising the tty driver\ndata when installing the tty.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
+ }
],
"affected": [
@@ -53,9 +56,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-200"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-21T15:15:25Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-jmrp-7793-gxc2/GHSA-jmrp-7793-gxc2.json b/advisories/unreviewed/2024/05/GHSA-jmrp-7793-gxc2/GHSA-jmrp-7793-gxc2.json
index 3f857fd29b9..854f8fc3e49 100644
--- a/advisories/unreviewed/2024/05/GHSA-jmrp-7793-gxc2/GHSA-jmrp-7793-gxc2.json
+++ b/advisories/unreviewed/2024/05/GHSA-jmrp-7793-gxc2/GHSA-jmrp-7793-gxc2.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jmrp-7793-gxc2",
- "modified": "2024-05-21T18:31:22Z",
+ "modified": "2024-07-03T18:42:58Z",
"published": "2024-05-21T18:31:22Z",
"aliases": [
"CVE-2023-52861"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm: bridge: it66121: Fix invalid connector dereference\n\nFix the NULL pointer dereference when no monitor is connected, and the\nsound card is opened from userspace.\n\nInstead return an empty buffer (of zeroes) as the EDID information to\nthe sound framework if there is no connector attached.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -37,9 +40,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-476"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-21T16:15:23Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-jpvc-w686-44qr/GHSA-jpvc-w686-44qr.json b/advisories/unreviewed/2024/05/GHSA-jpvc-w686-44qr/GHSA-jpvc-w686-44qr.json
index e912e84747e..fed829561ec 100644
--- a/advisories/unreviewed/2024/05/GHSA-jpvc-w686-44qr/GHSA-jpvc-w686-44qr.json
+++ b/advisories/unreviewed/2024/05/GHSA-jpvc-w686-44qr/GHSA-jpvc-w686-44qr.json
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-89"
],
"severity": "CRITICAL",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/05/GHSA-jq29-8xm6-ccxq/GHSA-jq29-8xm6-ccxq.json b/advisories/unreviewed/2024/05/GHSA-jq29-8xm6-ccxq/GHSA-jq29-8xm6-ccxq.json
index 5bebf116ab3..bca40daccc2 100644
--- a/advisories/unreviewed/2024/05/GHSA-jq29-8xm6-ccxq/GHSA-jq29-8xm6-ccxq.json
+++ b/advisories/unreviewed/2024/05/GHSA-jq29-8xm6-ccxq/GHSA-jq29-8xm6-ccxq.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jq29-8xm6-ccxq",
- "modified": "2024-05-21T15:31:43Z",
+ "modified": "2024-07-03T18:42:48Z",
"published": "2024-05-21T15:31:43Z",
"aliases": [
"CVE-2021-47348"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Avoid HDCP over-read and corruption\n\nInstead of reading the desired 5 bytes of the actual target field,\nthe code was reading 8. This could result in a corrupted value if the\ntrailing 3 bytes were non-zero, so instead use an appropriately sized\nand zero-initialized bounce buffer, and read only 5 bytes before casting\nto u64.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
+ }
],
"affected": [
@@ -37,9 +40,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-119"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-21T15:15:21Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-jq74-w56w-cjqw/GHSA-jq74-w56w-cjqw.json b/advisories/unreviewed/2024/05/GHSA-jq74-w56w-cjqw/GHSA-jq74-w56w-cjqw.json
index b25a8607a23..64722e9079c 100644
--- a/advisories/unreviewed/2024/05/GHSA-jq74-w56w-cjqw/GHSA-jq74-w56w-cjqw.json
+++ b/advisories/unreviewed/2024/05/GHSA-jq74-w56w-cjqw/GHSA-jq74-w56w-cjqw.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jq74-w56w-cjqw",
- "modified": "2024-05-22T15:31:01Z",
+ "modified": "2024-07-03T18:43:13Z",
"published": "2024-05-22T15:31:01Z",
"aliases": [
"CVE-2024-35559"
],
"details": "idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoMove_deal.php?mudi=rev&nohrefStr=close.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-352"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-22T14:15:09Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-jv5x-8v9f-frx2/GHSA-jv5x-8v9f-frx2.json b/advisories/unreviewed/2024/05/GHSA-jv5x-8v9f-frx2/GHSA-jv5x-8v9f-frx2.json
index 1e83d4aec96..afbc5cf2cbc 100644
--- a/advisories/unreviewed/2024/05/GHSA-jv5x-8v9f-frx2/GHSA-jv5x-8v9f-frx2.json
+++ b/advisories/unreviewed/2024/05/GHSA-jv5x-8v9f-frx2/GHSA-jv5x-8v9f-frx2.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jv5x-8v9f-frx2",
- "modified": "2024-05-21T15:31:40Z",
+ "modified": "2024-07-03T18:42:42Z",
"published": "2024-05-21T15:31:40Z",
"aliases": [
"CVE-2021-47238"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ipv4: fix memory leak in ip_mc_add1_src\n\nBUG: memory leak\nunreferenced object 0xffff888101bc4c00 (size 32):\n comm \"syz-executor527\", pid 360, jiffies 4294807421 (age 19.329s)\n hex dump (first 32 bytes):\n 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n 01 00 00 00 00 00 00 00 ac 14 14 bb 00 00 02 00 ................\n backtrace:\n [<00000000f17c5244>] kmalloc include/linux/slab.h:558 [inline]\n [<00000000f17c5244>] kzalloc include/linux/slab.h:688 [inline]\n [<00000000f17c5244>] ip_mc_add1_src net/ipv4/igmp.c:1971 [inline]\n [<00000000f17c5244>] ip_mc_add_src+0x95f/0xdb0 net/ipv4/igmp.c:2095\n [<000000001cb99709>] ip_mc_source+0x84c/0xea0 net/ipv4/igmp.c:2416\n [<0000000052cf19ed>] do_ip_setsockopt net/ipv4/ip_sockglue.c:1294 [inline]\n [<0000000052cf19ed>] ip_setsockopt+0x114b/0x30c0 net/ipv4/ip_sockglue.c:1423\n [<00000000477edfbc>] raw_setsockopt+0x13d/0x170 net/ipv4/raw.c:857\n [<00000000e75ca9bb>] __sys_setsockopt+0x158/0x270 net/socket.c:2117\n [<00000000bdb993a8>] __do_sys_setsockopt net/socket.c:2128 [inline]\n [<00000000bdb993a8>] __se_sys_setsockopt net/socket.c:2125 [inline]\n [<00000000bdb993a8>] __x64_sys_setsockopt+0xba/0x150 net/socket.c:2125\n [<000000006a1ffdbd>] do_syscall_64+0x40/0x80 arch/x86/entry/common.c:47\n [<00000000b11467c4>] entry_SYSCALL_64_after_hwframe+0x44/0xae\n\nIn commit 24803f38a5c0 (\"igmp: do not remove igmp souce list info when set\nlink down\"), the ip_mc_clear_src() in ip_mc_destroy_dev() was removed,\nbecause it was also called in igmpv3_clear_delrec().\n\nRough callgraph:\n\ninetdev_destroy\n-> ip_mc_destroy_dev\n -> igmpv3_clear_delrec\n -> ip_mc_clear_src\n-> RCU_INIT_POINTER(dev->ip_ptr, NULL)\n\nHowever, ip_mc_clear_src() called in igmpv3_clear_delrec() doesn't\nrelease in_dev->mc_list->sources. And RCU_INIT_POINTER() assigns the\nNULL to dev->ip_ptr. As a result, in_dev cannot be obtained through\ninetdev_by_index() and then in_dev->mc_list->sources cannot be released\nby ip_mc_del1_src() in the sock_close. Rough call sequence goes like:\n\nsock_close\n-> __sock_release\n -> inet_release\n -> ip_mc_drop_socket\n -> inetdev_by_index\n -> ip_mc_leave_src\n -> ip_mc_del_src\n -> ip_mc_del1_src\n\nSo we still need to call ip_mc_clear_src() in ip_mc_destroy_dev() to free\nin_dev->mc_list->sources.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -49,9 +52,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-400"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-21T15:15:13Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-jwg9-47h4-mj73/GHSA-jwg9-47h4-mj73.json b/advisories/unreviewed/2024/05/GHSA-jwg9-47h4-mj73/GHSA-jwg9-47h4-mj73.json
index b35463b21dd..bac40b50150 100644
--- a/advisories/unreviewed/2024/05/GHSA-jwg9-47h4-mj73/GHSA-jwg9-47h4-mj73.json
+++ b/advisories/unreviewed/2024/05/GHSA-jwg9-47h4-mj73/GHSA-jwg9-47h4-mj73.json
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-89"
],
"severity": "HIGH",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/05/GHSA-m2qc-57j3-6fh6/GHSA-m2qc-57j3-6fh6.json b/advisories/unreviewed/2024/05/GHSA-m2qc-57j3-6fh6/GHSA-m2qc-57j3-6fh6.json
index a06175dc373..9b2e7d42264 100644
--- a/advisories/unreviewed/2024/05/GHSA-m2qc-57j3-6fh6/GHSA-m2qc-57j3-6fh6.json
+++ b/advisories/unreviewed/2024/05/GHSA-m2qc-57j3-6fh6/GHSA-m2qc-57j3-6fh6.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m2qc-57j3-6fh6",
- "modified": "2024-05-20T12:30:27Z",
+ "modified": "2024-07-03T18:42:34Z",
"published": "2024-05-20T12:30:27Z",
"aliases": [
"CVE-2024-35948"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbcachefs: Check for journal entries overruning end of sb clean section\n\nFix a missing bounds check in superblock validation.\n\nNote that we don't yet have repair code for this case - repair code for\nindividual items is generally low priority, since the whole superblock\nis checksummed, validated prior to write, and we have backups.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-400"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-20T10:15:09Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-m78v-2mx6-xmm7/GHSA-m78v-2mx6-xmm7.json b/advisories/unreviewed/2024/05/GHSA-m78v-2mx6-xmm7/GHSA-m78v-2mx6-xmm7.json
index 34cecbf8039..327375f401d 100644
--- a/advisories/unreviewed/2024/05/GHSA-m78v-2mx6-xmm7/GHSA-m78v-2mx6-xmm7.json
+++ b/advisories/unreviewed/2024/05/GHSA-m78v-2mx6-xmm7/GHSA-m78v-2mx6-xmm7.json
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-89"
],
"severity": "CRITICAL",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/05/GHSA-m7wf-2qxg-448x/GHSA-m7wf-2qxg-448x.json b/advisories/unreviewed/2024/05/GHSA-m7wf-2qxg-448x/GHSA-m7wf-2qxg-448x.json
index c8978698892..65169e6b82f 100644
--- a/advisories/unreviewed/2024/05/GHSA-m7wf-2qxg-448x/GHSA-m7wf-2qxg-448x.json
+++ b/advisories/unreviewed/2024/05/GHSA-m7wf-2qxg-448x/GHSA-m7wf-2qxg-448x.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m7wf-2qxg-448x",
- "modified": "2024-06-27T15:30:39Z",
+ "modified": "2024-07-03T18:42:36Z",
"published": "2024-05-20T12:30:28Z",
"aliases": [
"CVE-2024-35955"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nkprobes: Fix possible use-after-free issue on kprobe registration\n\nWhen unloading a module, its state is changing MODULE_STATE_LIVE ->\n MODULE_STATE_GOING -> MODULE_STATE_UNFORMED. Each change will take\na time. `is_module_text_address()` and `__module_text_address()`\nworks with MODULE_STATE_LIVE and MODULE_STATE_GOING.\nIf we use `is_module_text_address()` and `__module_text_address()`\nseparately, there is a chance that the first one is succeeded but the\nnext one is failed because module->state becomes MODULE_STATE_UNFORMED\nbetween those operations.\n\nIn `check_kprobe_address_safe()`, if the second `__module_text_address()`\nis failed, that is ignored because it expected a kernel_text address.\nBut it may have failed simply because module->state has been changed\nto MODULE_STATE_UNFORMED. In this case, arm_kprobe() will try to modify\nnon-exist module text address (use-after-free).\n\nTo fix this problem, we should not use separated `is_module_text_address()`\nand `__module_text_address()`, but use only `__module_text_address()`\nonce and do `try_module_get(module)` which is only available with\nMODULE_STATE_LIVE.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -61,9 +64,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-416"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-20T10:15:10Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-mm62-pv5h-xg4v/GHSA-mm62-pv5h-xg4v.json b/advisories/unreviewed/2024/05/GHSA-mm62-pv5h-xg4v/GHSA-mm62-pv5h-xg4v.json
index db0bb5fd9d4..817d7bdbf7f 100644
--- a/advisories/unreviewed/2024/05/GHSA-mm62-pv5h-xg4v/GHSA-mm62-pv5h-xg4v.json
+++ b/advisories/unreviewed/2024/05/GHSA-mm62-pv5h-xg4v/GHSA-mm62-pv5h-xg4v.json
@@ -25,7 +25,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-352"
],
"severity": null,
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/05/GHSA-mpcf-6x99-gw9r/GHSA-mpcf-6x99-gw9r.json b/advisories/unreviewed/2024/05/GHSA-mpcf-6x99-gw9r/GHSA-mpcf-6x99-gw9r.json
index 64f57236300..9dbfff5dbe7 100644
--- a/advisories/unreviewed/2024/05/GHSA-mpcf-6x99-gw9r/GHSA-mpcf-6x99-gw9r.json
+++ b/advisories/unreviewed/2024/05/GHSA-mpcf-6x99-gw9r/GHSA-mpcf-6x99-gw9r.json
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-89"
],
"severity": "CRITICAL",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/05/GHSA-mwxg-grq3-792c/GHSA-mwxg-grq3-792c.json b/advisories/unreviewed/2024/05/GHSA-mwxg-grq3-792c/GHSA-mwxg-grq3-792c.json
index d581b77739d..098b2130b16 100644
--- a/advisories/unreviewed/2024/05/GHSA-mwxg-grq3-792c/GHSA-mwxg-grq3-792c.json
+++ b/advisories/unreviewed/2024/05/GHSA-mwxg-grq3-792c/GHSA-mwxg-grq3-792c.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mwxg-grq3-792c",
- "modified": "2024-05-17T18:30:42Z",
+ "modified": "2024-07-03T18:42:26Z",
"published": "2024-05-17T18:30:42Z",
"aliases": [
"CVE-2024-31974"
],
"details": "The com.solarized.firedown (aka Solarized FireDown Browser & Downloader) application 1.0.76 for Android allows a remote attacker to execute arbitrary JavaScript code via a crafted intent. com.solarized.firedown.IntentActivity uses a WebView component to display web content and doesn't adequately sanitize the URI or any extra data passed in the intent by any installed application (with no permissions).",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-94"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-17T16:15:07Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-mxwx-46p7-hcm6/GHSA-mxwx-46p7-hcm6.json b/advisories/unreviewed/2024/05/GHSA-mxwx-46p7-hcm6/GHSA-mxwx-46p7-hcm6.json
index ea19e47348d..c68dc51915b 100644
--- a/advisories/unreviewed/2024/05/GHSA-mxwx-46p7-hcm6/GHSA-mxwx-46p7-hcm6.json
+++ b/advisories/unreviewed/2024/05/GHSA-mxwx-46p7-hcm6/GHSA-mxwx-46p7-hcm6.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mxwx-46p7-hcm6",
- "modified": "2024-05-21T15:31:42Z",
+ "modified": "2024-07-03T18:42:45Z",
"published": "2024-05-21T15:31:42Z",
"aliases": [
"CVE-2021-47313"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncpufreq: CPPC: Fix potential memleak in cppc_cpufreq_cpu_init\n\nIt's a classic example of memleak, we allocate something, we fail and\nnever free the resources.\n\nMake sure we free all resources on policy ->init() failures.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -33,9 +36,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-400"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-21T15:15:18Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-p4g5-chr9-3gf5/GHSA-p4g5-chr9-3gf5.json b/advisories/unreviewed/2024/05/GHSA-p4g5-chr9-3gf5/GHSA-p4g5-chr9-3gf5.json
index eaf0076d5a9..6ee06d1b9d8 100644
--- a/advisories/unreviewed/2024/05/GHSA-p4g5-chr9-3gf5/GHSA-p4g5-chr9-3gf5.json
+++ b/advisories/unreviewed/2024/05/GHSA-p4g5-chr9-3gf5/GHSA-p4g5-chr9-3gf5.json
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-288"
],
"severity": "CRITICAL",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/05/GHSA-p52g-7jqp-23j6/GHSA-p52g-7jqp-23j6.json b/advisories/unreviewed/2024/05/GHSA-p52g-7jqp-23j6/GHSA-p52g-7jqp-23j6.json
index 609b918b92c..d00855bc1ec 100644
--- a/advisories/unreviewed/2024/05/GHSA-p52g-7jqp-23j6/GHSA-p52g-7jqp-23j6.json
+++ b/advisories/unreviewed/2024/05/GHSA-p52g-7jqp-23j6/GHSA-p52g-7jqp-23j6.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p52g-7jqp-23j6",
- "modified": "2024-05-17T18:30:42Z",
+ "modified": "2024-07-03T18:42:27Z",
"published": "2024-05-17T18:30:42Z",
"aliases": [
"CVE-2024-34241"
],
"details": "A cross-site scripting (XSS) vulnerability in Rocketsoft Rocket LMS 1.9 allows an administrator to store a JavaScript payload using the admin web interface when creating new courses and new course notifications.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-17T16:15:08Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-p886-4435-7m79/GHSA-p886-4435-7m79.json b/advisories/unreviewed/2024/05/GHSA-p886-4435-7m79/GHSA-p886-4435-7m79.json
index 9188ab7d2d6..08b7bfc15f3 100644
--- a/advisories/unreviewed/2024/05/GHSA-p886-4435-7m79/GHSA-p886-4435-7m79.json
+++ b/advisories/unreviewed/2024/05/GHSA-p886-4435-7m79/GHSA-p886-4435-7m79.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p886-4435-7m79",
- "modified": "2024-05-21T18:31:21Z",
+ "modified": "2024-07-03T18:42:54Z",
"published": "2024-05-21T18:31:21Z",
"aliases": [
"CVE-2023-52801"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\niommufd: Fix missing update of domains_itree after splitting iopt_area\n\nIn iopt_area_split(), if the original iopt_area has filled a domain and is\nlinked to domains_itree, pages_nodes have to be properly\nreinserted. Otherwise the domains_itree becomes corrupted and we will UAF.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
+ }
],
"affected": [
@@ -33,9 +36,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-284"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-21T16:15:18Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-p8qv-h5rp-h2hw/GHSA-p8qv-h5rp-h2hw.json b/advisories/unreviewed/2024/05/GHSA-p8qv-h5rp-h2hw/GHSA-p8qv-h5rp-h2hw.json
index 87279c7d24a..8ac259990f3 100644
--- a/advisories/unreviewed/2024/05/GHSA-p8qv-h5rp-h2hw/GHSA-p8qv-h5rp-h2hw.json
+++ b/advisories/unreviewed/2024/05/GHSA-p8qv-h5rp-h2hw/GHSA-p8qv-h5rp-h2hw.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p8qv-h5rp-h2hw",
- "modified": "2024-05-17T12:31:00Z",
+ "modified": "2024-07-03T18:42:21Z",
"published": "2024-05-17T12:31:00Z",
"aliases": [
"CVE-2024-27407"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfs/ntfs3: Fixed overflow check in mi_enum_attr()",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -33,9 +36,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-120"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-17T12:15:11Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-pc2v-g9xh-4hcw/GHSA-pc2v-g9xh-4hcw.json b/advisories/unreviewed/2024/05/GHSA-pc2v-g9xh-4hcw/GHSA-pc2v-g9xh-4hcw.json
index 2ae60b28d1e..ed4df458cdb 100644
--- a/advisories/unreviewed/2024/05/GHSA-pc2v-g9xh-4hcw/GHSA-pc2v-g9xh-4hcw.json
+++ b/advisories/unreviewed/2024/05/GHSA-pc2v-g9xh-4hcw/GHSA-pc2v-g9xh-4hcw.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pc2v-g9xh-4hcw",
- "modified": "2024-05-22T15:31:01Z",
+ "modified": "2024-07-03T18:43:11Z",
"published": "2024-05-22T15:31:00Z",
"aliases": [
"CVE-2024-35557"
],
"details": "idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/vpsApi_deal.php?mudi=rev&nohrefStr=close.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-352"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-22T14:15:09Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-pcwf-v3ph-3p9v/GHSA-pcwf-v3ph-3p9v.json b/advisories/unreviewed/2024/05/GHSA-pcwf-v3ph-3p9v/GHSA-pcwf-v3ph-3p9v.json
index d568c63133b..b344c81b6dd 100644
--- a/advisories/unreviewed/2024/05/GHSA-pcwf-v3ph-3p9v/GHSA-pcwf-v3ph-3p9v.json
+++ b/advisories/unreviewed/2024/05/GHSA-pcwf-v3ph-3p9v/GHSA-pcwf-v3ph-3p9v.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pcwf-v3ph-3p9v",
- "modified": "2024-05-21T15:31:41Z",
+ "modified": "2024-07-03T18:42:45Z",
"published": "2024-05-21T15:31:41Z",
"aliases": [
"CVE-2021-47284"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nisdn: mISDN: netjet: Fix crash in nj_probe:\n\n'nj_setup' in netjet.c might fail with -EIO and in this case\n'card->irq' is initialized and is bigger than zero. A subsequent call to\n'nj_release' will free the irq that has not been requested.\n\nFix this bug by deleting the previous assignment to 'card->irq' and just\nkeep the assignment before 'request_irq'.\n\nThe KASAN's log reveals it:\n\n[ 3.354615 ] WARNING: CPU: 0 PID: 1 at kernel/irq/manage.c:1826\nfree_irq+0x100/0x480\n[ 3.355112 ] Modules linked in:\n[ 3.355310 ] CPU: 0 PID: 1 Comm: swapper/0 Not tainted\n5.13.0-rc1-00144-g25a1298726e #13\n[ 3.355816 ] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS\nrel-1.12.0-59-gc9ba5276e321-prebuilt.qemu.org 04/01/2014\n[ 3.356552 ] RIP: 0010:free_irq+0x100/0x480\n[ 3.356820 ] Code: 6e 08 74 6f 4d 89 f4 e8 5e ac 09 00 4d 8b 74 24 18\n4d 85 f6 75 e3 e8 4f ac 09 00 8b 75 c8 48 c7 c7 78 c1 2e 85 e8 e0 cf f5\nff <0f> 0b 48 8b 75 c0 4c 89 ff e8 72 33 0b 03 48 8b 43 40 4c 8b a0 80\n[ 3.358012 ] RSP: 0000:ffffc90000017b48 EFLAGS: 00010082\n[ 3.358357 ] RAX: 0000000000000000 RBX: ffff888104dc8000 RCX:\n0000000000000000\n[ 3.358814 ] RDX: ffff8881003c8000 RSI: ffffffff8124a9e6 RDI:\n00000000ffffffff\n[ 3.359272 ] RBP: ffffc90000017b88 R08: 0000000000000000 R09:\n0000000000000000\n[ 3.359732 ] R10: ffffc900000179f0 R11: 0000000000001d04 R12:\n0000000000000000\n[ 3.360195 ] R13: ffff888107dc6000 R14: ffff888107dc6928 R15:\nffff888104dc80a8\n[ 3.360652 ] FS: 0000000000000000(0000) GS:ffff88817bc00000(0000)\nknlGS:0000000000000000\n[ 3.361170 ] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 3.361538 ] CR2: 0000000000000000 CR3: 000000000582e000 CR4:\n00000000000006f0\n[ 3.362003 ] DR0: 0000000000000000 DR1: 0000000000000000 DR2:\n0000000000000000\n[ 3.362175 ] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7:\n0000000000000400\n[ 3.362175 ] Call Trace:\n[ 3.362175 ] nj_release+0x51/0x1e0\n[ 3.362175 ] nj_probe+0x450/0x950\n[ 3.362175 ] ? pci_device_remove+0x110/0x110\n[ 3.362175 ] local_pci_probe+0x45/0xa0\n[ 3.362175 ] pci_device_probe+0x12b/0x1d0\n[ 3.362175 ] really_probe+0x2a9/0x610\n[ 3.362175 ] driver_probe_device+0x90/0x1d0\n[ 3.362175 ] ? mutex_lock_nested+0x1b/0x20\n[ 3.362175 ] device_driver_attach+0x68/0x70\n[ 3.362175 ] __driver_attach+0x124/0x1b0\n[ 3.362175 ] ? device_driver_attach+0x70/0x70\n[ 3.362175 ] bus_for_each_dev+0xbb/0x110\n[ 3.362175 ] ? rdinit_setup+0x45/0x45\n[ 3.362175 ] driver_attach+0x27/0x30\n[ 3.362175 ] bus_add_driver+0x1eb/0x2a0\n[ 3.362175 ] driver_register+0xa9/0x180\n[ 3.362175 ] __pci_register_driver+0x82/0x90\n[ 3.362175 ] ? w6692_init+0x38/0x38\n[ 3.362175 ] nj_init+0x36/0x38\n[ 3.362175 ] do_one_initcall+0x7f/0x3d0\n[ 3.362175 ] ? rdinit_setup+0x45/0x45\n[ 3.362175 ] ? rcu_read_lock_sched_held+0x4f/0x80\n[ 3.362175 ] kernel_init_freeable+0x2aa/0x301\n[ 3.362175 ] ? rest_init+0x2c0/0x2c0\n[ 3.362175 ] kernel_init+0x18/0x190\n[ 3.362175 ] ? rest_init+0x2c0/0x2c0\n[ 3.362175 ] ? rest_init+0x2c0/0x2c0\n[ 3.362175 ] ret_from_fork+0x1f/0x30\n[ 3.362175 ] Kernel panic - not syncing: panic_on_warn set ...\n[ 3.362175 ] CPU: 0 PID: 1 Comm: swapper/0 Not tainted\n5.13.0-rc1-00144-g25a1298726e #13\n[ 3.362175 ] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS\nrel-1.12.0-59-gc9ba5276e321-prebuilt.qemu.org 04/01/2014\n[ 3.362175 ] Call Trace:\n[ 3.362175 ] dump_stack+0xba/0xf5\n[ 3.362175 ] ? free_irq+0x100/0x480\n[ 3.362175 ] panic+0x15a/0x3f2\n[ 3.362175 ] ? __warn+0xf2/0x150\n[ 3.362175 ] ? free_irq+0x100/0x480\n[ 3.362175 ] __warn+0x108/0x150\n[ 3.362175 ] ? free_irq+0x100/0x480\n[ 3.362175 ] report_bug+0x119/0x1c0\n[ 3.362175 ] handle_bug+0x3b/0x80\n[ 3.362175 ] exc_invalid_op+0x18/0x70\n[ 3.362175 ] asm_exc_invalid_op+0x12/0x20\n[ 3.362175 ] RIP: 0010:free_irq+0x100\n---truncated---",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -53,9 +56,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-400"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-21T15:15:16Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-pvgx-v84j-v63h/GHSA-pvgx-v84j-v63h.json b/advisories/unreviewed/2024/05/GHSA-pvgx-v84j-v63h/GHSA-pvgx-v84j-v63h.json
index 17f13f3c511..549afbe173f 100644
--- a/advisories/unreviewed/2024/05/GHSA-pvgx-v84j-v63h/GHSA-pvgx-v84j-v63h.json
+++ b/advisories/unreviewed/2024/05/GHSA-pvgx-v84j-v63h/GHSA-pvgx-v84j-v63h.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pvgx-v84j-v63h",
- "modified": "2024-05-23T06:30:46Z",
+ "modified": "2024-07-03T18:43:24Z",
"published": "2024-05-23T06:30:46Z",
"aliases": [
"CVE-2024-4388"
],
"details": "This does not validate a path generated with user input when downloading files, allowing unauthenticated user to download arbitrary files from the server",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
+ }
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-23T06:15:11Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-px85-vjfw-cm92/GHSA-px85-vjfw-cm92.json b/advisories/unreviewed/2024/05/GHSA-px85-vjfw-cm92/GHSA-px85-vjfw-cm92.json
index 47937ca7f1a..1f34c9bf026 100644
--- a/advisories/unreviewed/2024/05/GHSA-px85-vjfw-cm92/GHSA-px85-vjfw-cm92.json
+++ b/advisories/unreviewed/2024/05/GHSA-px85-vjfw-cm92/GHSA-px85-vjfw-cm92.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-px85-vjfw-cm92",
- "modified": "2024-05-21T15:31:41Z",
+ "modified": "2024-07-03T18:42:44Z",
"published": "2024-05-21T15:31:41Z",
"aliases": [
"CVE-2021-47274"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntracing: Correct the length check which causes memory corruption\n\nWe've suffered from severe kernel crashes due to memory corruption on\nour production environment, like,\n\nCall Trace:\n[1640542.554277] general protection fault: 0000 [#1] SMP PTI\n[1640542.554856] CPU: 17 PID: 26996 Comm: python Kdump: loaded Tainted:G\n[1640542.556629] RIP: 0010:kmem_cache_alloc+0x90/0x190\n[1640542.559074] RSP: 0018:ffffb16faa597df8 EFLAGS: 00010286\n[1640542.559587] RAX: 0000000000000000 RBX: 0000000000400200 RCX:\n0000000006e931bf\n[1640542.560323] RDX: 0000000006e931be RSI: 0000000000400200 RDI:\nffff9a45ff004300\n[1640542.560996] RBP: 0000000000400200 R08: 0000000000023420 R09:\n0000000000000000\n[1640542.561670] R10: 0000000000000000 R11: 0000000000000000 R12:\nffffffff9a20608d\n[1640542.562366] R13: ffff9a45ff004300 R14: ffff9a45ff004300 R15:\n696c662f65636976\n[1640542.563128] FS: 00007f45d7c6f740(0000) GS:ffff9a45ff840000(0000)\nknlGS:0000000000000000\n[1640542.563937] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[1640542.564557] CR2: 00007f45d71311a0 CR3: 000000189d63e004 CR4:\n00000000003606e0\n[1640542.565279] DR0: 0000000000000000 DR1: 0000000000000000 DR2:\n0000000000000000\n[1640542.566069] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7:\n0000000000000400\n[1640542.566742] Call Trace:\n[1640542.567009] anon_vma_clone+0x5d/0x170\n[1640542.567417] __split_vma+0x91/0x1a0\n[1640542.567777] do_munmap+0x2c6/0x320\n[1640542.568128] vm_munmap+0x54/0x70\n[1640542.569990] __x64_sys_munmap+0x22/0x30\n[1640542.572005] do_syscall_64+0x5b/0x1b0\n[1640542.573724] entry_SYSCALL_64_after_hwframe+0x44/0xa9\n[1640542.575642] RIP: 0033:0x7f45d6e61e27\n\nJames Wang has reproduced it stably on the latest 4.19 LTS.\nAfter some debugging, we finally proved that it's due to ftrace\nbuffer out-of-bound access using a debug tool as follows:\n[ 86.775200] BUG: Out-of-bounds write at addr 0xffff88aefe8b7000\n[ 86.780806] no_context+0xdf/0x3c0\n[ 86.784327] __do_page_fault+0x252/0x470\n[ 86.788367] do_page_fault+0x32/0x140\n[ 86.792145] page_fault+0x1e/0x30\n[ 86.795576] strncpy_from_unsafe+0x66/0xb0\n[ 86.799789] fetch_memory_string+0x25/0x40\n[ 86.804002] fetch_deref_string+0x51/0x60\n[ 86.808134] kprobe_trace_func+0x32d/0x3a0\n[ 86.812347] kprobe_dispatcher+0x45/0x50\n[ 86.816385] kprobe_ftrace_handler+0x90/0xf0\n[ 86.820779] ftrace_ops_assist_func+0xa1/0x140\n[ 86.825340] 0xffffffffc00750bf\n[ 86.828603] do_sys_open+0x5/0x1f0\n[ 86.832124] do_syscall_64+0x5b/0x1b0\n[ 86.835900] entry_SYSCALL_64_after_hwframe+0x44/0xa9\n\ncommit b220c049d519 (\"tracing: Check length before giving out\nthe filter buffer\") adds length check to protect trace data\noverflow introduced in 0fc1b09ff1ff, seems that this fix can't prevent\noverflow entirely, the length check should also take the sizeof\nentry->array[0] into account, since this array[0] is filled the\nlength of trace data and occupy addtional space and risk overflow.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -49,9 +52,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-125"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-21T15:15:15Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-q2r6-2h2c-pqr7/GHSA-q2r6-2h2c-pqr7.json b/advisories/unreviewed/2024/05/GHSA-q2r6-2h2c-pqr7/GHSA-q2r6-2h2c-pqr7.json
index 8ae0472a823..11f53aca6a0 100644
--- a/advisories/unreviewed/2024/05/GHSA-q2r6-2h2c-pqr7/GHSA-q2r6-2h2c-pqr7.json
+++ b/advisories/unreviewed/2024/05/GHSA-q2r6-2h2c-pqr7/GHSA-q2r6-2h2c-pqr7.json
@@ -28,6 +28,7 @@
],
"database_specific": {
"cwe_ids": [
+ "CWE-707",
"CWE-86"
],
"severity": "HIGH",
diff --git a/advisories/unreviewed/2024/05/GHSA-q6fh-vc2v-h383/GHSA-q6fh-vc2v-h383.json b/advisories/unreviewed/2024/05/GHSA-q6fh-vc2v-h383/GHSA-q6fh-vc2v-h383.json
index b66a7d2bc3b..fc341b4dbb3 100644
--- a/advisories/unreviewed/2024/05/GHSA-q6fh-vc2v-h383/GHSA-q6fh-vc2v-h383.json
+++ b/advisories/unreviewed/2024/05/GHSA-q6fh-vc2v-h383/GHSA-q6fh-vc2v-h383.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q6fh-vc2v-h383",
- "modified": "2024-05-23T06:30:46Z",
+ "modified": "2024-07-03T18:43:25Z",
"published": "2024-05-23T06:30:46Z",
"aliases": [
"CVE-2024-4399"
],
"details": "The does not validate a parameter before making a request to it, which could allow unauthenticated users to perform SSRF attack",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
+ }
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-23T06:15:11Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-q96x-mjr8-2jrj/GHSA-q96x-mjr8-2jrj.json b/advisories/unreviewed/2024/05/GHSA-q96x-mjr8-2jrj/GHSA-q96x-mjr8-2jrj.json
index 20e9b8f56f2..03157da7d67 100644
--- a/advisories/unreviewed/2024/05/GHSA-q96x-mjr8-2jrj/GHSA-q96x-mjr8-2jrj.json
+++ b/advisories/unreviewed/2024/05/GHSA-q96x-mjr8-2jrj/GHSA-q96x-mjr8-2jrj.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q96x-mjr8-2jrj",
- "modified": "2024-05-23T06:30:45Z",
+ "modified": "2024-07-03T18:43:24Z",
"published": "2024-05-23T06:30:45Z",
"aliases": [
"CVE-2024-3917"
],
"details": "The Pet Manager WordPress plugin through 1.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
+ }
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-23T06:15:10Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-qgvq-jr42-r2gx/GHSA-qgvq-jr42-r2gx.json b/advisories/unreviewed/2024/05/GHSA-qgvq-jr42-r2gx/GHSA-qgvq-jr42-r2gx.json
index 5705e6dd746..1df13cdca11 100644
--- a/advisories/unreviewed/2024/05/GHSA-qgvq-jr42-r2gx/GHSA-qgvq-jr42-r2gx.json
+++ b/advisories/unreviewed/2024/05/GHSA-qgvq-jr42-r2gx/GHSA-qgvq-jr42-r2gx.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qgvq-jr42-r2gx",
- "modified": "2024-05-21T18:31:22Z",
+ "modified": "2024-07-03T18:42:57Z",
"published": "2024-05-21T18:31:22Z",
"aliases": [
"CVE-2023-52844"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: vidtv: psi: Add check for kstrdup\n\nAdd check for the return value of kstrdup() and return the error\nif it fails in order to avoid NULL pointer dereference.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -45,9 +48,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-476"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-21T16:15:21Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-qgw5-pr98-x2mx/GHSA-qgw5-pr98-x2mx.json b/advisories/unreviewed/2024/05/GHSA-qgw5-pr98-x2mx/GHSA-qgw5-pr98-x2mx.json
index b0b508a14d4..7b21335dd68 100644
--- a/advisories/unreviewed/2024/05/GHSA-qgw5-pr98-x2mx/GHSA-qgw5-pr98-x2mx.json
+++ b/advisories/unreviewed/2024/05/GHSA-qgw5-pr98-x2mx/GHSA-qgw5-pr98-x2mx.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qgw5-pr98-x2mx",
- "modified": "2024-05-22T21:30:35Z",
+ "modified": "2024-07-03T18:43:18Z",
"published": "2024-05-22T21:30:35Z",
"aliases": [
"CVE-2024-35627"
],
"details": "tileserver-gl up to v4.4.10 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /data/v3/?key.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-22T19:15:09Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-qmp7-vwf7-6g2g/GHSA-qmp7-vwf7-6g2g.json b/advisories/unreviewed/2024/05/GHSA-qmp7-vwf7-6g2g/GHSA-qmp7-vwf7-6g2g.json
index 8a0f310f860..90748a8bdd2 100644
--- a/advisories/unreviewed/2024/05/GHSA-qmp7-vwf7-6g2g/GHSA-qmp7-vwf7-6g2g.json
+++ b/advisories/unreviewed/2024/05/GHSA-qmp7-vwf7-6g2g/GHSA-qmp7-vwf7-6g2g.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qmp7-vwf7-6g2g",
- "modified": "2024-06-10T18:31:03Z",
+ "modified": "2024-07-03T18:43:15Z",
"published": "2024-05-22T18:30:42Z",
"aliases": [
"CVE-2024-5159"
],
"details": "Heap buffer overflow in ANGLE in Google Chrome prior to 125.0.6422.76 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -37,9 +40,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-122"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-22T16:15:11Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-qr27-wgh8-6hcg/GHSA-qr27-wgh8-6hcg.json b/advisories/unreviewed/2024/05/GHSA-qr27-wgh8-6hcg/GHSA-qr27-wgh8-6hcg.json
index 602ea3dd5f0..80a625b1078 100644
--- a/advisories/unreviewed/2024/05/GHSA-qr27-wgh8-6hcg/GHSA-qr27-wgh8-6hcg.json
+++ b/advisories/unreviewed/2024/05/GHSA-qr27-wgh8-6hcg/GHSA-qr27-wgh8-6hcg.json
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-89"
],
"severity": "CRITICAL",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/05/GHSA-qxx4-523c-98q7/GHSA-qxx4-523c-98q7.json b/advisories/unreviewed/2024/05/GHSA-qxx4-523c-98q7/GHSA-qxx4-523c-98q7.json
index dfddb1d42b2..86c0ad7541e 100644
--- a/advisories/unreviewed/2024/05/GHSA-qxx4-523c-98q7/GHSA-qxx4-523c-98q7.json
+++ b/advisories/unreviewed/2024/05/GHSA-qxx4-523c-98q7/GHSA-qxx4-523c-98q7.json
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-280"
],
"severity": "LOW",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/05/GHSA-r4ww-r2x2-fj39/GHSA-r4ww-r2x2-fj39.json b/advisories/unreviewed/2024/05/GHSA-r4ww-r2x2-fj39/GHSA-r4ww-r2x2-fj39.json
index 0035f8c565b..d8f9e7de4f9 100644
--- a/advisories/unreviewed/2024/05/GHSA-r4ww-r2x2-fj39/GHSA-r4ww-r2x2-fj39.json
+++ b/advisories/unreviewed/2024/05/GHSA-r4ww-r2x2-fj39/GHSA-r4ww-r2x2-fj39.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r4ww-r2x2-fj39",
- "modified": "2024-05-17T15:31:09Z",
+ "modified": "2024-07-03T18:42:25Z",
"published": "2024-05-17T15:31:09Z",
"aliases": [
"CVE-2024-35801"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/fpu: Keep xfd_state in sync with MSR_IA32_XFD\n\nCommit 672365477ae8 (\"x86/fpu: Update XFD state where required\") and\ncommit 8bf26758ca96 (\"x86/fpu: Add XFD state to fpstate\") introduced a\nper CPU variable xfd_state to keep the MSR_IA32_XFD value cached, in\norder to avoid unnecessary writes to the MSR.\n\nOn CPU hotplug MSR_IA32_XFD is reset to the init_fpstate.xfd, which\nwipes out any stale state. But the per CPU cached xfd value is not\nreset, which brings them out of sync.\n\nAs a consequence a subsequent xfd_update_state() might fail to update\nthe MSR which in turn can result in XRSTOR raising a #NM in kernel\nspace, which crashes the kernel.\n\nTo fix this, introduce xfd_set_state() to write xfd_state together\nwith MSR_IA32_XFD, and use it in all places that set MSR_IA32_XFD.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -41,9 +44,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-416"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-17T14:15:12Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-r8g7-9pvc-p6p6/GHSA-r8g7-9pvc-p6p6.json b/advisories/unreviewed/2024/05/GHSA-r8g7-9pvc-p6p6/GHSA-r8g7-9pvc-p6p6.json
index 30e3a08da4d..ccccceeab9c 100644
--- a/advisories/unreviewed/2024/05/GHSA-r8g7-9pvc-p6p6/GHSA-r8g7-9pvc-p6p6.json
+++ b/advisories/unreviewed/2024/05/GHSA-r8g7-9pvc-p6p6/GHSA-r8g7-9pvc-p6p6.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r8g7-9pvc-p6p6",
- "modified": "2024-05-22T15:31:01Z",
+ "modified": "2024-07-03T18:43:12Z",
"published": "2024-05-22T15:31:01Z",
"aliases": [
"CVE-2024-35558"
],
"details": "idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/ca_deal.php?mudi=rev&nohrefStr=close.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-22T14:15:09Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-rfmp-947p-v557/GHSA-rfmp-947p-v557.json b/advisories/unreviewed/2024/05/GHSA-rfmp-947p-v557/GHSA-rfmp-947p-v557.json
index f3073abdaf3..5d048fc86f2 100644
--- a/advisories/unreviewed/2024/05/GHSA-rfmp-947p-v557/GHSA-rfmp-947p-v557.json
+++ b/advisories/unreviewed/2024/05/GHSA-rfmp-947p-v557/GHSA-rfmp-947p-v557.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rfmp-947p-v557",
- "modified": "2024-05-23T18:30:56Z",
+ "modified": "2024-07-03T18:43:29Z",
"published": "2024-05-23T18:30:56Z",
"aliases": [
"CVE-2024-35086"
],
"details": "J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in BpmTaskFromMapper.xml .",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-89"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-23T17:15:30Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-rg5r-x6g3-c6xm/GHSA-rg5r-x6g3-c6xm.json b/advisories/unreviewed/2024/05/GHSA-rg5r-x6g3-c6xm/GHSA-rg5r-x6g3-c6xm.json
index 49ac58ec671..06336af687d 100644
--- a/advisories/unreviewed/2024/05/GHSA-rg5r-x6g3-c6xm/GHSA-rg5r-x6g3-c6xm.json
+++ b/advisories/unreviewed/2024/05/GHSA-rg5r-x6g3-c6xm/GHSA-rg5r-x6g3-c6xm.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rg5r-x6g3-c6xm",
- "modified": "2024-05-31T03:30:32Z",
+ "modified": "2024-07-03T18:43:54Z",
"published": "2024-05-31T03:30:32Z",
"aliases": [
"CVE-2024-32850"
],
"details": "Improper neutralization of special elements used in a command ('Command Injection') exists in SkyBridge MB-A100/MB-A110 firmware Ver. 4.2.2 and earlier and SkyBridge BASIC MB-A130 firmware Ver. 1.5.5 and earlier. If the remote monitoring and control function is enabled on the product, an attacker with access to the product may execute an arbitrary command or login to the product with the administrator privilege.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-78"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-31T02:15:08Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-rh7c-r5m3-cjr3/GHSA-rh7c-r5m3-cjr3.json b/advisories/unreviewed/2024/05/GHSA-rh7c-r5m3-cjr3/GHSA-rh7c-r5m3-cjr3.json
index 2ea676ccd4c..dd5a57d1884 100644
--- a/advisories/unreviewed/2024/05/GHSA-rh7c-r5m3-cjr3/GHSA-rh7c-r5m3-cjr3.json
+++ b/advisories/unreviewed/2024/05/GHSA-rh7c-r5m3-cjr3/GHSA-rh7c-r5m3-cjr3.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rh7c-r5m3-cjr3",
- "modified": "2024-05-21T18:31:23Z",
+ "modified": "2024-07-03T18:42:58Z",
"published": "2024-05-21T18:31:23Z",
"aliases": [
"CVE-2023-52858"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nclk: mediatek: clk-mt7629: Add check for mtk_alloc_clk_data\n\nAdd the check for the return value of mtk_alloc_clk_data() in order to\navoid NULL pointer dereference.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -49,9 +52,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-476"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-21T16:15:22Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-rj6m-4w95-fg67/GHSA-rj6m-4w95-fg67.json b/advisories/unreviewed/2024/05/GHSA-rj6m-4w95-fg67/GHSA-rj6m-4w95-fg67.json
index 7a0667e8bac..f104dcd7935 100644
--- a/advisories/unreviewed/2024/05/GHSA-rj6m-4w95-fg67/GHSA-rj6m-4w95-fg67.json
+++ b/advisories/unreviewed/2024/05/GHSA-rj6m-4w95-fg67/GHSA-rj6m-4w95-fg67.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rj6m-4w95-fg67",
- "modified": "2024-06-26T00:31:43Z",
+ "modified": "2024-07-03T18:42:36Z",
"published": "2024-05-20T12:30:29Z",
"aliases": [
"CVE-2024-35976"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nxsk: validate user input for XDP_{UMEM|COMPLETION}_FILL_RING\n\nsyzbot reported an illegal copy in xsk_setsockopt() [1]\n\nMake sure to validate setsockopt() @optlen parameter.\n\n[1]\n\n BUG: KASAN: slab-out-of-bounds in copy_from_sockptr_offset include/linux/sockptr.h:49 [inline]\n BUG: KASAN: slab-out-of-bounds in copy_from_sockptr include/linux/sockptr.h:55 [inline]\n BUG: KASAN: slab-out-of-bounds in xsk_setsockopt+0x909/0xa40 net/xdp/xsk.c:1420\nRead of size 4 at addr ffff888028c6cde3 by task syz-executor.0/7549\n\nCPU: 0 PID: 7549 Comm: syz-executor.0 Not tainted 6.8.0-syzkaller-08951-gfe46a7dd189e #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 03/27/2024\nCall Trace:\n \n __dump_stack lib/dump_stack.c:88 [inline]\n dump_stack_lvl+0x241/0x360 lib/dump_stack.c:114\n print_address_description mm/kasan/report.c:377 [inline]\n print_report+0x169/0x550 mm/kasan/report.c:488\n kasan_report+0x143/0x180 mm/kasan/report.c:601\n copy_from_sockptr_offset include/linux/sockptr.h:49 [inline]\n copy_from_sockptr include/linux/sockptr.h:55 [inline]\n xsk_setsockopt+0x909/0xa40 net/xdp/xsk.c:1420\n do_sock_setsockopt+0x3af/0x720 net/socket.c:2311\n __sys_setsockopt+0x1ae/0x250 net/socket.c:2334\n __do_sys_setsockopt net/socket.c:2343 [inline]\n __se_sys_setsockopt net/socket.c:2340 [inline]\n __x64_sys_setsockopt+0xb5/0xd0 net/socket.c:2340\n do_syscall_64+0xfb/0x240\n entry_SYSCALL_64_after_hwframe+0x6d/0x75\nRIP: 0033:0x7fb40587de69\nCode: 28 00 00 00 75 05 48 83 c4 28 c3 e8 e1 20 00 00 90 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b0 ff ff ff f7 d8 64 89 01 48\nRSP: 002b:00007fb40665a0c8 EFLAGS: 00000246 ORIG_RAX: 0000000000000036\nRAX: ffffffffffffffda RBX: 00007fb4059abf80 RCX: 00007fb40587de69\nRDX: 0000000000000005 RSI: 000000000000011b RDI: 0000000000000006\nRBP: 00007fb4058ca47a R08: 0000000000000002 R09: 0000000000000000\nR10: 0000000020001980 R11: 0000000000000246 R12: 0000000000000000\nR13: 000000000000000b R14: 00007fb4059abf80 R15: 00007fff57ee4d08\n \n\nAllocated by task 7549:\n kasan_save_stack mm/kasan/common.c:47 [inline]\n kasan_save_track+0x3f/0x80 mm/kasan/common.c:68\n poison_kmalloc_redzone mm/kasan/common.c:370 [inline]\n __kasan_kmalloc+0x98/0xb0 mm/kasan/common.c:387\n kasan_kmalloc include/linux/kasan.h:211 [inline]\n __do_kmalloc_node mm/slub.c:3966 [inline]\n __kmalloc+0x233/0x4a0 mm/slub.c:3979\n kmalloc include/linux/slab.h:632 [inline]\n __cgroup_bpf_run_filter_setsockopt+0xd2f/0x1040 kernel/bpf/cgroup.c:1869\n do_sock_setsockopt+0x6b4/0x720 net/socket.c:2293\n __sys_setsockopt+0x1ae/0x250 net/socket.c:2334\n __do_sys_setsockopt net/socket.c:2343 [inline]\n __se_sys_setsockopt net/socket.c:2340 [inline]\n __x64_sys_setsockopt+0xb5/0xd0 net/socket.c:2340\n do_syscall_64+0xfb/0x240\n entry_SYSCALL_64_after_hwframe+0x6d/0x75\n\nThe buggy address belongs to the object at ffff888028c6cde0\n which belongs to the cache kmalloc-8 of size 8\nThe buggy address is located 1 bytes to the right of\n allocated 2-byte region [ffff888028c6cde0, ffff888028c6cde2)\n\nThe buggy address belongs to the physical page:\npage:ffffea0000a31b00 refcount:1 mapcount:0 mapping:0000000000000000 index:0xffff888028c6c9c0 pfn:0x28c6c\nanon flags: 0xfff00000000800(slab|node=0|zone=1|lastcpupid=0x7ff)\npage_type: 0xffffffff()\nraw: 00fff00000000800 ffff888014c41280 0000000000000000 dead000000000001\nraw: ffff888028c6c9c0 0000000080800057 00000001ffffffff 0000000000000000\npage dumped because: kasan: bad access detected\npage_owner tracks the page as allocated\npage last allocated via order 0, migratetype Unmovable, gfp_mask 0x112cc0(GFP_USER|__GFP_NOWARN|__GFP_NORETRY), pid 6648, tgid 6644 (syz-executor.0), ts 133906047828, free_ts 133859922223\n set_page_owner include/linux/page_owner.h:31 [inline]\n post_alloc_hook+0x1ea/0x210 mm/page_alloc.c:1533\n prep_new_page mm/page_alloc.c:\n---truncated---",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
+ }
],
"affected": [
@@ -53,9 +56,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-787"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-20T10:15:12Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-rmqp-6x5x-g7fg/GHSA-rmqp-6x5x-g7fg.json b/advisories/unreviewed/2024/05/GHSA-rmqp-6x5x-g7fg/GHSA-rmqp-6x5x-g7fg.json
index 705c39c0fdd..3d2350ee301 100644
--- a/advisories/unreviewed/2024/05/GHSA-rmqp-6x5x-g7fg/GHSA-rmqp-6x5x-g7fg.json
+++ b/advisories/unreviewed/2024/05/GHSA-rmqp-6x5x-g7fg/GHSA-rmqp-6x5x-g7fg.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rmqp-6x5x-g7fg",
- "modified": "2024-05-21T15:31:40Z",
+ "modified": "2024-07-03T18:42:42Z",
"published": "2024-05-21T15:31:40Z",
"aliases": [
"CVE-2021-47232"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: j1939: fix Use-after-Free, hold skb ref while in use\n\nThis patch fixes a Use-after-Free found by the syzbot.\n\nThe problem is that a skb is taken from the per-session skb queue,\nwithout incrementing the ref count. This leads to a Use-after-Free if\nthe skb is taken concurrently from the session queue due to a CTS.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -37,9 +40,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-416"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-21T15:15:12Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-rqvp-j9p2-fcwx/GHSA-rqvp-j9p2-fcwx.json b/advisories/unreviewed/2024/05/GHSA-rqvp-j9p2-fcwx/GHSA-rqvp-j9p2-fcwx.json
index 47765fad6b8..5a97773df20 100644
--- a/advisories/unreviewed/2024/05/GHSA-rqvp-j9p2-fcwx/GHSA-rqvp-j9p2-fcwx.json
+++ b/advisories/unreviewed/2024/05/GHSA-rqvp-j9p2-fcwx/GHSA-rqvp-j9p2-fcwx.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rqvp-j9p2-fcwx",
- "modified": "2024-05-17T15:31:10Z",
+ "modified": "2024-07-03T18:42:25Z",
"published": "2024-05-17T15:31:10Z",
"aliases": [
"CVE-2024-35814"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nswiotlb: Fix double-allocation of slots due to broken alignment handling\n\nCommit bbb73a103fbb (\"swiotlb: fix a braino in the alignment check fix\"),\nwhich was a fix for commit 0eee5ae10256 (\"swiotlb: fix slot alignment\nchecks\"), causes a functional regression with vsock in a virtual machine\nusing bouncing via a restricted DMA SWIOTLB pool.\n\nWhen virtio allocates the virtqueues for the vsock device using\ndma_alloc_coherent(), the SWIOTLB search can return page-unaligned\nallocations if 'area->index' was left unaligned by a previous allocation\nfrom the buffer:\n\n # Final address in brackets is the SWIOTLB address returned to the caller\n | virtio-pci 0000:00:07.0: orig_addr 0x0 alloc_size 0x2000, iotlb_align_mask 0x800 stride 0x2: got slot 1645-1649/7168 (0x98326800)\n | virtio-pci 0000:00:07.0: orig_addr 0x0 alloc_size 0x2000, iotlb_align_mask 0x800 stride 0x2: got slot 1649-1653/7168 (0x98328800)\n | virtio-pci 0000:00:07.0: orig_addr 0x0 alloc_size 0x2000, iotlb_align_mask 0x800 stride 0x2: got slot 1653-1657/7168 (0x9832a800)\n\nThis ends badly (typically buffer corruption and/or a hang) because\nswiotlb_alloc() is expecting a page-aligned allocation and so blindly\nreturns a pointer to the 'struct page' corresponding to the allocation,\ntherefore double-allocating the first half (2KiB slot) of the 4KiB page.\n\nFix the problem by treating the allocation alignment separately to any\nadditional alignment requirements from the device, using the maximum\nof the two as the stride to search the buffer slots and taking care\nto ensure a minimum of page-alignment for buffers larger than a page.\n\nThis also resolves swiotlb allocation failures occuring due to the\ninclusion of ~PAGE_MASK in 'iotlb_align_mask' for large allocations and\nresulting in alignment requirements exceeding swiotlb_max_mapping_size().",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
+ }
],
"affected": [
@@ -37,9 +40,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-1055"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-17T14:15:15Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-rrq5-86rg-xjm7/GHSA-rrq5-86rg-xjm7.json b/advisories/unreviewed/2024/05/GHSA-rrq5-86rg-xjm7/GHSA-rrq5-86rg-xjm7.json
index 8f0f5f828b7..a9e998f55d5 100644
--- a/advisories/unreviewed/2024/05/GHSA-rrq5-86rg-xjm7/GHSA-rrq5-86rg-xjm7.json
+++ b/advisories/unreviewed/2024/05/GHSA-rrq5-86rg-xjm7/GHSA-rrq5-86rg-xjm7.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rrq5-86rg-xjm7",
- "modified": "2024-06-10T18:31:02Z",
+ "modified": "2024-07-03T18:42:26Z",
"published": "2024-05-17T18:30:42Z",
"aliases": [
"CVE-2024-34058"
],
"details": "The WebTop package for NethServer 7 and 8 allows stored XSS (for example, via the Subject field if an e-mail message).",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -33,9 +36,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-79"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-17T16:15:08Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-rw3m-9ff4-qmp2/GHSA-rw3m-9ff4-qmp2.json b/advisories/unreviewed/2024/05/GHSA-rw3m-9ff4-qmp2/GHSA-rw3m-9ff4-qmp2.json
index 81538ab2f1c..880803bd948 100644
--- a/advisories/unreviewed/2024/05/GHSA-rw3m-9ff4-qmp2/GHSA-rw3m-9ff4-qmp2.json
+++ b/advisories/unreviewed/2024/05/GHSA-rw3m-9ff4-qmp2/GHSA-rw3m-9ff4-qmp2.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rw3m-9ff4-qmp2",
- "modified": "2024-05-21T21:30:27Z",
+ "modified": "2024-07-03T18:42:33Z",
"published": "2024-05-19T21:30:23Z",
"aliases": [
"CVE-2024-36076"
],
"details": "Syslifters SysReptor before 2024.40 has a CSRF vulnerability for WebSocket connections.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-352"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-19T20:15:07Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-rwj3-qwqm-gg8c/GHSA-rwj3-qwqm-gg8c.json b/advisories/unreviewed/2024/05/GHSA-rwj3-qwqm-gg8c/GHSA-rwj3-qwqm-gg8c.json
index c0332538ef4..b97022632bd 100644
--- a/advisories/unreviewed/2024/05/GHSA-rwj3-qwqm-gg8c/GHSA-rwj3-qwqm-gg8c.json
+++ b/advisories/unreviewed/2024/05/GHSA-rwj3-qwqm-gg8c/GHSA-rwj3-qwqm-gg8c.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rwj3-qwqm-gg8c",
- "modified": "2024-05-19T18:30:33Z",
+ "modified": "2024-07-03T18:42:30Z",
"published": "2024-05-19T18:30:33Z",
"aliases": [
"CVE-2024-36053"
],
"details": "In the mintupload package through 4.2.0 for Linux Mint, service-name mishandling leads to command injection via shell metacharacters in check_connection, drop_data_received_cb, and Service.remove. A user can modify a service name in a ~/.linuxmint/mintUpload/services/service file.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -33,9 +36,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-20"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-19T16:15:45Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-v44p-g5j5-r658/GHSA-v44p-g5j5-r658.json b/advisories/unreviewed/2024/05/GHSA-v44p-g5j5-r658/GHSA-v44p-g5j5-r658.json
index 86bbd77bd8c..a2a42adaed3 100644
--- a/advisories/unreviewed/2024/05/GHSA-v44p-g5j5-r658/GHSA-v44p-g5j5-r658.json
+++ b/advisories/unreviewed/2024/05/GHSA-v44p-g5j5-r658/GHSA-v44p-g5j5-r658.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v44p-g5j5-r658",
- "modified": "2024-05-17T15:31:12Z",
+ "modified": "2024-07-03T18:42:25Z",
"published": "2024-05-17T15:31:12Z",
"aliases": [
"CVE-2024-35843"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\niommu/vt-d: Use device rbtree in iopf reporting path\n\nThe existing I/O page fault handler currently locates the PCI device by\ncalling pci_get_domain_bus_and_slot(). This function searches the list\nof all PCI devices until the desired device is found. To improve lookup\nefficiency, replace it with device_rbtree_find() to search the device\nwithin the probed device rbtree.\n\nThe I/O page fault is initiated by the device, which does not have any\nsynchronization mechanism with the software to ensure that the device\nstays in the probed device tree. Theoretically, a device could be released\nby the IOMMU subsystem after device_rbtree_find() and before\niopf_get_dev_fault_param(), which would cause a use-after-free problem.\n\nAdd a mutex to synchronize the I/O page fault reporting path and the IOMMU\nrelease device path. This lock doesn't introduce any performance overhead,\nas the conflict between I/O page fault reporting and device releasing is\nvery rare.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
+ }
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-416"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-17T15:15:21Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-v5pv-v2xp-jjp2/GHSA-v5pv-v2xp-jjp2.json b/advisories/unreviewed/2024/05/GHSA-v5pv-v2xp-jjp2/GHSA-v5pv-v2xp-jjp2.json
index 4a583d8f285..7061d4fb441 100644
--- a/advisories/unreviewed/2024/05/GHSA-v5pv-v2xp-jjp2/GHSA-v5pv-v2xp-jjp2.json
+++ b/advisories/unreviewed/2024/05/GHSA-v5pv-v2xp-jjp2/GHSA-v5pv-v2xp-jjp2.json
@@ -25,7 +25,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-352"
],
"severity": null,
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/05/GHSA-v65g-g8c7-vvqm/GHSA-v65g-g8c7-vvqm.json b/advisories/unreviewed/2024/05/GHSA-v65g-g8c7-vvqm/GHSA-v65g-g8c7-vvqm.json
index d33a7c8aec7..f1dc14be849 100644
--- a/advisories/unreviewed/2024/05/GHSA-v65g-g8c7-vvqm/GHSA-v65g-g8c7-vvqm.json
+++ b/advisories/unreviewed/2024/05/GHSA-v65g-g8c7-vvqm/GHSA-v65g-g8c7-vvqm.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v65g-g8c7-vvqm",
- "modified": "2024-05-23T18:30:55Z",
+ "modified": "2024-07-03T18:43:28Z",
"published": "2024-05-23T18:30:55Z",
"aliases": [
"CVE-2024-34930"
],
"details": "A SQL injection vulnerability in /model/all_events1.php in Campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the month parameter.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-89"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-23T17:15:29Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-vf5p-pgqg-rxgw/GHSA-vf5p-pgqg-rxgw.json b/advisories/unreviewed/2024/05/GHSA-vf5p-pgqg-rxgw/GHSA-vf5p-pgqg-rxgw.json
index 8a624dac0cc..af217d577c6 100644
--- a/advisories/unreviewed/2024/05/GHSA-vf5p-pgqg-rxgw/GHSA-vf5p-pgqg-rxgw.json
+++ b/advisories/unreviewed/2024/05/GHSA-vf5p-pgqg-rxgw/GHSA-vf5p-pgqg-rxgw.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vf5p-pgqg-rxgw",
- "modified": "2024-05-23T18:30:55Z",
+ "modified": "2024-07-03T18:43:26Z",
"published": "2024-05-23T18:30:55Z",
"aliases": [
"CVE-2024-34927"
],
"details": "A SQL injection vulnerability in /model/update_classroom.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the name parameter.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-89"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-23T17:15:29Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-vf5r-hx7h-7rvc/GHSA-vf5r-hx7h-7rvc.json b/advisories/unreviewed/2024/05/GHSA-vf5r-hx7h-7rvc/GHSA-vf5r-hx7h-7rvc.json
index fa55d2ff538..2a503caed29 100644
--- a/advisories/unreviewed/2024/05/GHSA-vf5r-hx7h-7rvc/GHSA-vf5r-hx7h-7rvc.json
+++ b/advisories/unreviewed/2024/05/GHSA-vf5r-hx7h-7rvc/GHSA-vf5r-hx7h-7rvc.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vf5r-hx7h-7rvc",
- "modified": "2024-06-27T15:30:39Z",
+ "modified": "2024-07-03T18:42:25Z",
"published": "2024-05-17T15:31:10Z",
"aliases": [
"CVE-2024-35821"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nubifs: Set page uptodate in the correct place\n\nPage cache reads are lockless, so setting the freshly allocated page\nuptodate before we've overwritten it with the data it's supposed to have\nin it will allow a simultaneous reader to see old data. Move the call\nto SetPageUptodate into ubifs_write_end(), which is after we copied the\nnew data into the page.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
+ }
],
"affected": [
@@ -65,9 +68,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-772"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-17T14:15:17Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-vq53-2g5p-3wf9/GHSA-vq53-2g5p-3wf9.json b/advisories/unreviewed/2024/05/GHSA-vq53-2g5p-3wf9/GHSA-vq53-2g5p-3wf9.json
index 3d06af11dba..01ae9a06892 100644
--- a/advisories/unreviewed/2024/05/GHSA-vq53-2g5p-3wf9/GHSA-vq53-2g5p-3wf9.json
+++ b/advisories/unreviewed/2024/05/GHSA-vq53-2g5p-3wf9/GHSA-vq53-2g5p-3wf9.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vq53-2g5p-3wf9",
- "modified": "2024-05-23T18:30:55Z",
+ "modified": "2024-07-03T18:43:01Z",
"published": "2024-05-21T21:30:27Z",
"aliases": [
"CVE-2024-33525"
],
"details": "A Stored Cross-site Scripting (XSS) vulnerability in the \"Import of organizational units and title of organizational unit\" feature in ILIAS 7.20 to 7.30 and ILIAS 8.4 to 8.10 as well as ILIAS 9.0 allows remote authenticated attackers with administrative privileges to inject arbitrary web script or HTML via XML file upload.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:L"
+ }
],
"affected": [
@@ -37,9 +40,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-21T19:15:10Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-vqrf-777q-wcmm/GHSA-vqrf-777q-wcmm.json b/advisories/unreviewed/2024/05/GHSA-vqrf-777q-wcmm/GHSA-vqrf-777q-wcmm.json
index c0c152f85da..b795b56ab5e 100644
--- a/advisories/unreviewed/2024/05/GHSA-vqrf-777q-wcmm/GHSA-vqrf-777q-wcmm.json
+++ b/advisories/unreviewed/2024/05/GHSA-vqrf-777q-wcmm/GHSA-vqrf-777q-wcmm.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vqrf-777q-wcmm",
- "modified": "2024-05-31T21:30:54Z",
+ "modified": "2024-07-03T18:44:04Z",
"published": "2024-05-31T21:30:54Z",
"aliases": [
"CVE-2024-36845"
],
"details": "An invalid pointer in the modbus_receive() function of libmodbus v3.1.6 allows attackers to cause a Denial of Service (DoS) via a crafted message sent to the unit-test-server.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-400"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-31T20:15:10Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-vrx5-g53m-hhm7/GHSA-vrx5-g53m-hhm7.json b/advisories/unreviewed/2024/05/GHSA-vrx5-g53m-hhm7/GHSA-vrx5-g53m-hhm7.json
index d56647c44e9..818591c7d3b 100644
--- a/advisories/unreviewed/2024/05/GHSA-vrx5-g53m-hhm7/GHSA-vrx5-g53m-hhm7.json
+++ b/advisories/unreviewed/2024/05/GHSA-vrx5-g53m-hhm7/GHSA-vrx5-g53m-hhm7.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vrx5-g53m-hhm7",
- "modified": "2024-05-21T15:31:44Z",
+ "modified": "2024-07-03T18:42:51Z",
"published": "2024-05-21T15:31:44Z",
"aliases": [
"CVE-2021-47389"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: SVM: fix missing sev_decommission in sev_receive_start\n\nDECOMMISSION the current SEV context if binding an ASID fails after\nRECEIVE_START. Per AMD's SEV API, RECEIVE_START generates a new guest\ncontext and thus needs to be paired with DECOMMISSION:\n\n The RECEIVE_START command is the only command other than the LAUNCH_START\n command that generates a new guest context and guest handle.\n\nThe missing DECOMMISSION can result in subsequent SEV launch failures,\nas the firmware leaks memory and might not able to allocate more SEV\nguest contexts in the future.\n\nNote, LAUNCH_START suffered the same bug, but was previously fixed by\ncommit 934002cd660b (\"KVM: SVM: Call SEV Guest Decommission if ASID\nbinding fails\").",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
+ }
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-400"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-21T15:15:24Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-w2mp-xqqj-8v36/GHSA-w2mp-xqqj-8v36.json b/advisories/unreviewed/2024/05/GHSA-w2mp-xqqj-8v36/GHSA-w2mp-xqqj-8v36.json
index 36bcb74d693..ad8d7ddbff7 100644
--- a/advisories/unreviewed/2024/05/GHSA-w2mp-xqqj-8v36/GHSA-w2mp-xqqj-8v36.json
+++ b/advisories/unreviewed/2024/05/GHSA-w2mp-xqqj-8v36/GHSA-w2mp-xqqj-8v36.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w2mp-xqqj-8v36",
- "modified": "2024-05-31T06:30:27Z",
+ "modified": "2024-07-03T18:43:54Z",
"published": "2024-05-31T06:30:27Z",
"aliases": [
"CVE-2024-23847"
],
"details": "Incorrect default permissions issue exists in Unifier and Unifier Cast Version.5.0 or later, and the patch \"20240527\" not applied. If this vulnerability is exploited, arbitrary code may be executed with LocalSystem privilege. As a result, a malicious program may be installed, data may be modified or deleted.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
+ }
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-276"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-31T06:15:10Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-w2mr-3frj-pxv2/GHSA-w2mr-3frj-pxv2.json b/advisories/unreviewed/2024/05/GHSA-w2mr-3frj-pxv2/GHSA-w2mr-3frj-pxv2.json
index c7aadad0740..28d55759488 100644
--- a/advisories/unreviewed/2024/05/GHSA-w2mr-3frj-pxv2/GHSA-w2mr-3frj-pxv2.json
+++ b/advisories/unreviewed/2024/05/GHSA-w2mr-3frj-pxv2/GHSA-w2mr-3frj-pxv2.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w2mr-3frj-pxv2",
- "modified": "2024-05-21T15:31:38Z",
+ "modified": "2024-07-03T18:42:41Z",
"published": "2024-05-21T15:31:38Z",
"aliases": [
"CVE-2024-35361"
],
"details": "MTab Bookmark v1.9.5 has an SQL injection vulnerability in /LinkStore/getIcon. An attacker can execute arbitrary SQL statements through this vulnerability without requiring any user rights.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-89"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-21T13:15:09Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-w3rx-jq2m-66pw/GHSA-w3rx-jq2m-66pw.json b/advisories/unreviewed/2024/05/GHSA-w3rx-jq2m-66pw/GHSA-w3rx-jq2m-66pw.json
index 8362cee90d1..e9c6074c3f5 100644
--- a/advisories/unreviewed/2024/05/GHSA-w3rx-jq2m-66pw/GHSA-w3rx-jq2m-66pw.json
+++ b/advisories/unreviewed/2024/05/GHSA-w3rx-jq2m-66pw/GHSA-w3rx-jq2m-66pw.json
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-89"
],
"severity": "HIGH",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/05/GHSA-w7g4-69hj-jcrq/GHSA-w7g4-69hj-jcrq.json b/advisories/unreviewed/2024/05/GHSA-w7g4-69hj-jcrq/GHSA-w7g4-69hj-jcrq.json
index 35b04bd0e18..9c5e82b2ec8 100644
--- a/advisories/unreviewed/2024/05/GHSA-w7g4-69hj-jcrq/GHSA-w7g4-69hj-jcrq.json
+++ b/advisories/unreviewed/2024/05/GHSA-w7g4-69hj-jcrq/GHSA-w7g4-69hj-jcrq.json
@@ -37,7 +37,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-416"
],
"severity": null,
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/05/GHSA-w7j7-m99g-gcgq/GHSA-w7j7-m99g-gcgq.json b/advisories/unreviewed/2024/05/GHSA-w7j7-m99g-gcgq/GHSA-w7j7-m99g-gcgq.json
index e727b68d600..ddf60a8a46e 100644
--- a/advisories/unreviewed/2024/05/GHSA-w7j7-m99g-gcgq/GHSA-w7j7-m99g-gcgq.json
+++ b/advisories/unreviewed/2024/05/GHSA-w7j7-m99g-gcgq/GHSA-w7j7-m99g-gcgq.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w7j7-m99g-gcgq",
- "modified": "2024-05-21T15:31:41Z",
+ "modified": "2024-07-03T18:42:43Z",
"published": "2024-05-21T15:31:41Z",
"aliases": [
"CVE-2021-47259"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nNFS: Fix use-after-free in nfs4_init_client()\n\nKASAN reports a use-after-free when attempting to mount two different\nexports through two different NICs that belong to the same server.\n\nOlga was able to hit this with kernels starting somewhere between 5.7\nand 5.10, but I traced the patch that introduced the clear_bit() call to\n4.13. So something must have changed in the refcounting of the clp\npointer to make this call to nfs_put_client() the very last one.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -45,9 +48,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-416"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-21T15:15:14Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-wgf9-7m97-x4xg/GHSA-wgf9-7m97-x4xg.json b/advisories/unreviewed/2024/05/GHSA-wgf9-7m97-x4xg/GHSA-wgf9-7m97-x4xg.json
index cabd55e93a0..fd7a989b00f 100644
--- a/advisories/unreviewed/2024/05/GHSA-wgf9-7m97-x4xg/GHSA-wgf9-7m97-x4xg.json
+++ b/advisories/unreviewed/2024/05/GHSA-wgf9-7m97-x4xg/GHSA-wgf9-7m97-x4xg.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wgf9-7m97-x4xg",
- "modified": "2024-05-21T18:31:20Z",
+ "modified": "2024-07-03T18:42:53Z",
"published": "2024-05-21T18:31:20Z",
"aliases": [
"CVE-2023-52765"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmfd: qcom-spmi-pmic: Fix revid implementation\n\nThe Qualcomm SPMI PMIC revid implementation is broken in multiple ways.\n\nFirst, it assumes that just because the sibling base device has been\nregistered that means that it is also bound to a driver, which may not\nbe the case (e.g. due to probe deferral or asynchronous probe). This\ncould trigger a NULL-pointer dereference when attempting to access the\ndriver data of the unbound device.\n\nSecond, it accesses driver data of a sibling device directly and without\nany locking, which means that the driver data may be freed while it is\nbeing accessed (e.g. on driver unbind).\n\nThird, it leaks a struct device reference to the sibling device which is\nlooked up using the spmi_device_from_of() every time a function (child)\ndevice is calling the revid function (e.g. on probe).\n\nFix this mess by reimplementing the revid lookup so that it is done only\nat probe of the PMIC device; the base device fetches the revid info from\nthe hardware, while any secondary SPMI device fetches the information\nfrom the base device and caches it so that it can be accessed safely\nfrom its children. If the base device has not been probed yet then probe\nof a secondary device is deferred.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -37,9 +40,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-476"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-21T16:15:15Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-wwjj-qw24-qw82/GHSA-wwjj-qw24-qw82.json b/advisories/unreviewed/2024/05/GHSA-wwjj-qw24-qw82/GHSA-wwjj-qw24-qw82.json
index 4c3e1d2f695..043d667ed00 100644
--- a/advisories/unreviewed/2024/05/GHSA-wwjj-qw24-qw82/GHSA-wwjj-qw24-qw82.json
+++ b/advisories/unreviewed/2024/05/GHSA-wwjj-qw24-qw82/GHSA-wwjj-qw24-qw82.json
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-89"
],
"severity": "HIGH",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/05/GHSA-x44g-rjjf-p8x3/GHSA-x44g-rjjf-p8x3.json b/advisories/unreviewed/2024/05/GHSA-x44g-rjjf-p8x3/GHSA-x44g-rjjf-p8x3.json
index 5071dd38147..1c7dfd750e1 100644
--- a/advisories/unreviewed/2024/05/GHSA-x44g-rjjf-p8x3/GHSA-x44g-rjjf-p8x3.json
+++ b/advisories/unreviewed/2024/05/GHSA-x44g-rjjf-p8x3/GHSA-x44g-rjjf-p8x3.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x44g-rjjf-p8x3",
- "modified": "2024-05-17T21:31:47Z",
+ "modified": "2024-07-03T18:42:28Z",
"published": "2024-05-17T21:31:47Z",
"aliases": [
"CVE-2024-34959"
],
"details": "DedeCMS V5.7.113 is vulnerable to Cross Site Scripting (XSS) via sys_data_replace.php.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-17T20:15:07Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-xcxv-fxc3-wxmc/GHSA-xcxv-fxc3-wxmc.json b/advisories/unreviewed/2024/05/GHSA-xcxv-fxc3-wxmc/GHSA-xcxv-fxc3-wxmc.json
index ef965055430..70a14713f5e 100644
--- a/advisories/unreviewed/2024/05/GHSA-xcxv-fxc3-wxmc/GHSA-xcxv-fxc3-wxmc.json
+++ b/advisories/unreviewed/2024/05/GHSA-xcxv-fxc3-wxmc/GHSA-xcxv-fxc3-wxmc.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xcxv-fxc3-wxmc",
- "modified": "2024-05-20T18:31:23Z",
+ "modified": "2024-07-03T18:42:38Z",
"published": "2024-05-20T18:31:23Z",
"aliases": [
"CVE-2024-35571"
],
"details": "Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function formSetIptv.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-120"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-20T18:15:10Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-xgm7-3x53-gq2c/GHSA-xgm7-3x53-gq2c.json b/advisories/unreviewed/2024/05/GHSA-xgm7-3x53-gq2c/GHSA-xgm7-3x53-gq2c.json
index 6c35f15ede5..661a6fade7a 100644
--- a/advisories/unreviewed/2024/05/GHSA-xgm7-3x53-gq2c/GHSA-xgm7-3x53-gq2c.json
+++ b/advisories/unreviewed/2024/05/GHSA-xgm7-3x53-gq2c/GHSA-xgm7-3x53-gq2c.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xgm7-3x53-gq2c",
- "modified": "2024-05-22T09:31:46Z",
+ "modified": "2024-07-03T18:43:07Z",
"published": "2024-05-22T09:31:46Z",
"aliases": [
"CVE-2021-47482"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: batman-adv: fix error handling\n\nSyzbot reported ODEBUG warning in batadv_nc_mesh_free(). The problem was\nin wrong error handling in batadv_mesh_init().\n\nBefore this patch batadv_mesh_init() was calling batadv_mesh_free() in case\nof any batadv_*_init() calls failure. This approach may work well, when\nthere is some kind of indicator, which can tell which parts of batadv are\ninitialized; but there isn't any.\n\nAll written above lead to cleaning up uninitialized fields. Even if we hide\nODEBUG warning by initializing bat_priv->nc.work, syzbot was able to hit\nGPF in batadv_nc_purge_paths(), because hash pointer in still NULL. [1]\n\nTo fix these bugs we can unwind batadv_*_init() calls one by one.\nIt is good approach for 2 reasons: 1) It fixes bugs on error handling\npath 2) It improves the performance, since we won't call unneeded\nbatadv_*_free() functions.\n\nSo, this patch makes all batadv_*_init() clean up all allocated memory\nbefore returning with an error to no call correspoing batadv_*_free()\nand open-codes batadv_mesh_free() with proper order to avoid touching\nuninitialized fields.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -53,9 +56,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-544"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-22T09:15:10Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-xhvq-7mc2-jx9w/GHSA-xhvq-7mc2-jx9w.json b/advisories/unreviewed/2024/05/GHSA-xhvq-7mc2-jx9w/GHSA-xhvq-7mc2-jx9w.json
index ad5d06bfd84..db9a4674f45 100644
--- a/advisories/unreviewed/2024/05/GHSA-xhvq-7mc2-jx9w/GHSA-xhvq-7mc2-jx9w.json
+++ b/advisories/unreviewed/2024/05/GHSA-xhvq-7mc2-jx9w/GHSA-xhvq-7mc2-jx9w.json
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-89"
],
"severity": "HIGH",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/05/GHSA-xj74-qf7m-54cx/GHSA-xj74-qf7m-54cx.json b/advisories/unreviewed/2024/05/GHSA-xj74-qf7m-54cx/GHSA-xj74-qf7m-54cx.json
index 0277236e4c1..ee10c759a61 100644
--- a/advisories/unreviewed/2024/05/GHSA-xj74-qf7m-54cx/GHSA-xj74-qf7m-54cx.json
+++ b/advisories/unreviewed/2024/05/GHSA-xj74-qf7m-54cx/GHSA-xj74-qf7m-54cx.json
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-89"
],
"severity": "CRITICAL",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/05/GHSA-xm44-79f8-q8r7/GHSA-xm44-79f8-q8r7.json b/advisories/unreviewed/2024/05/GHSA-xm44-79f8-q8r7/GHSA-xm44-79f8-q8r7.json
index 62490484dae..88b12d05ce6 100644
--- a/advisories/unreviewed/2024/05/GHSA-xm44-79f8-q8r7/GHSA-xm44-79f8-q8r7.json
+++ b/advisories/unreviewed/2024/05/GHSA-xm44-79f8-q8r7/GHSA-xm44-79f8-q8r7.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xm44-79f8-q8r7",
- "modified": "2024-05-21T18:31:24Z",
+ "modified": "2024-07-03T18:42:58Z",
"published": "2024-05-21T18:31:23Z",
"aliases": [
"CVE-2024-22274"
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-94"
],
"severity": "HIGH",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/05/GHSA-xw27-hxmj-gm8p/GHSA-xw27-hxmj-gm8p.json b/advisories/unreviewed/2024/05/GHSA-xw27-hxmj-gm8p/GHSA-xw27-hxmj-gm8p.json
index 61b68a2b6b7..653510d2bf2 100644
--- a/advisories/unreviewed/2024/05/GHSA-xw27-hxmj-gm8p/GHSA-xw27-hxmj-gm8p.json
+++ b/advisories/unreviewed/2024/05/GHSA-xw27-hxmj-gm8p/GHSA-xw27-hxmj-gm8p.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xw27-hxmj-gm8p",
- "modified": "2024-05-21T18:31:23Z",
+ "modified": "2024-07-03T18:42:58Z",
"published": "2024-05-21T18:31:23Z",
"aliases": [
"CVE-2023-52869"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\npstore/platform: Add check for kstrdup\n\nAdd check for the return value of kstrdup() and return the error\nif it fails in order to avoid NULL pointer dereference.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -45,9 +48,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-476"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-21T16:15:23Z"
diff --git a/advisories/unreviewed/2024/06/GHSA-42v5-55fh-293w/GHSA-42v5-55fh-293w.json b/advisories/unreviewed/2024/06/GHSA-42v5-55fh-293w/GHSA-42v5-55fh-293w.json
index 292341920f7..e4a18750e9e 100644
--- a/advisories/unreviewed/2024/06/GHSA-42v5-55fh-293w/GHSA-42v5-55fh-293w.json
+++ b/advisories/unreviewed/2024/06/GHSA-42v5-55fh-293w/GHSA-42v5-55fh-293w.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-42v5-55fh-293w",
- "modified": "2024-06-03T15:30:56Z",
+ "modified": "2024-07-03T18:44:06Z",
"published": "2024-06-03T15:30:56Z",
"aliases": [
"CVE-2024-36568"
],
"details": "Sourcecodester Gas Agency Management System v1.0 is vulnerable to SQL Injection via /gasmark/editbrand.php?id=.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-94"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-03T14:15:09Z"
diff --git a/advisories/unreviewed/2024/06/GHSA-5w4f-cwfr-f344/GHSA-5w4f-cwfr-f344.json b/advisories/unreviewed/2024/06/GHSA-5w4f-cwfr-f344/GHSA-5w4f-cwfr-f344.json
index 99583aa9659..6d1c5b6edf6 100644
--- a/advisories/unreviewed/2024/06/GHSA-5w4f-cwfr-f344/GHSA-5w4f-cwfr-f344.json
+++ b/advisories/unreviewed/2024/06/GHSA-5w4f-cwfr-f344/GHSA-5w4f-cwfr-f344.json
@@ -61,7 +61,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-125"
],
"severity": null,
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/06/GHSA-62p2-52h6-r43q/GHSA-62p2-52h6-r43q.json b/advisories/unreviewed/2024/06/GHSA-62p2-52h6-r43q/GHSA-62p2-52h6-r43q.json
index 8f709be1da5..6d5d088a0fb 100644
--- a/advisories/unreviewed/2024/06/GHSA-62p2-52h6-r43q/GHSA-62p2-52h6-r43q.json
+++ b/advisories/unreviewed/2024/06/GHSA-62p2-52h6-r43q/GHSA-62p2-52h6-r43q.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-62p2-52h6-r43q",
- "modified": "2024-06-03T03:31:04Z",
+ "modified": "2024-07-03T18:44:05Z",
"published": "2024-06-03T03:31:04Z",
"aliases": [
"CVE-2024-20073"
],
"details": "In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00367704; Issue ID: MSV-1411.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
"CWE-787"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-03T02:15:09Z"
diff --git a/advisories/unreviewed/2024/06/GHSA-6hhg-pw9g-vcjq/GHSA-6hhg-pw9g-vcjq.json b/advisories/unreviewed/2024/06/GHSA-6hhg-pw9g-vcjq/GHSA-6hhg-pw9g-vcjq.json
index 40d6ff6e564..04a74034b10 100644
--- a/advisories/unreviewed/2024/06/GHSA-6hhg-pw9g-vcjq/GHSA-6hhg-pw9g-vcjq.json
+++ b/advisories/unreviewed/2024/06/GHSA-6hhg-pw9g-vcjq/GHSA-6hhg-pw9g-vcjq.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6hhg-pw9g-vcjq",
- "modified": "2024-06-03T15:30:57Z",
+ "modified": "2024-07-03T18:44:07Z",
"published": "2024-06-03T15:30:57Z",
"aliases": [
"CVE-2024-36728"
],
"details": "TRENDnet TEW-827DRU devices through 2.06B04 contain a stack-based buffer overflow in the ssi binary. The overflow allows an authenticated user to execute arbitrary code by POSTing to apply.cgi via the action vlan_setting with a sufficiently long dns1 or dns 2 key.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-121"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-03T14:15:09Z"
diff --git a/advisories/unreviewed/2024/06/GHSA-6wg2-qrp2-pr4c/GHSA-6wg2-qrp2-pr4c.json b/advisories/unreviewed/2024/06/GHSA-6wg2-qrp2-pr4c/GHSA-6wg2-qrp2-pr4c.json
index 031fee758bb..45b2536988f 100644
--- a/advisories/unreviewed/2024/06/GHSA-6wg2-qrp2-pr4c/GHSA-6wg2-qrp2-pr4c.json
+++ b/advisories/unreviewed/2024/06/GHSA-6wg2-qrp2-pr4c/GHSA-6wg2-qrp2-pr4c.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6wg2-qrp2-pr4c",
- "modified": "2024-06-03T06:30:53Z",
+ "modified": "2024-07-03T18:44:05Z",
"published": "2024-06-03T06:30:53Z",
"aliases": [
"CVE-2023-42427"
],
"details": "Cross-site scripting vulnerability exists in UNIVERSAL PASSPORT RX versions 1.0.0 to 1.0.7, which may allow a remote authenticated attacker to execute an arbitrary script on the web browser of the user who is using the product.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-03T04:15:08Z"
diff --git a/advisories/unreviewed/2024/06/GHSA-73vq-gv6j-qxx9/GHSA-73vq-gv6j-qxx9.json b/advisories/unreviewed/2024/06/GHSA-73vq-gv6j-qxx9/GHSA-73vq-gv6j-qxx9.json
index 5162c0ad275..a2d61d788c5 100644
--- a/advisories/unreviewed/2024/06/GHSA-73vq-gv6j-qxx9/GHSA-73vq-gv6j-qxx9.json
+++ b/advisories/unreviewed/2024/06/GHSA-73vq-gv6j-qxx9/GHSA-73vq-gv6j-qxx9.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-73vq-gv6j-qxx9",
- "modified": "2024-06-03T03:31:04Z",
+ "modified": "2024-07-03T18:44:05Z",
"published": "2024-06-03T03:31:04Z",
"aliases": [
"CVE-2024-20074"
],
"details": "In dmc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08668110; Issue ID: MSV-1333.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
"CWE-787"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-03T02:15:09Z"
diff --git a/advisories/unreviewed/2024/06/GHSA-8hj4-6vg4-8r5g/GHSA-8hj4-6vg4-8r5g.json b/advisories/unreviewed/2024/06/GHSA-8hj4-6vg4-8r5g/GHSA-8hj4-6vg4-8r5g.json
index 3c80b0db8fc..a5b904cbe20 100644
--- a/advisories/unreviewed/2024/06/GHSA-8hj4-6vg4-8r5g/GHSA-8hj4-6vg4-8r5g.json
+++ b/advisories/unreviewed/2024/06/GHSA-8hj4-6vg4-8r5g/GHSA-8hj4-6vg4-8r5g.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8hj4-6vg4-8r5g",
- "modified": "2024-06-03T03:31:04Z",
+ "modified": "2024-07-03T18:44:05Z",
"published": "2024-06-03T03:31:04Z",
"aliases": [
"CVE-2024-20072"
],
"details": "In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00364732; Issue ID: MSV-1332.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
"CWE-787"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-03T02:15:09Z"
diff --git a/advisories/unreviewed/2024/06/GHSA-c7fp-f8xf-wg7c/GHSA-c7fp-f8xf-wg7c.json b/advisories/unreviewed/2024/06/GHSA-c7fp-f8xf-wg7c/GHSA-c7fp-f8xf-wg7c.json
index fa7d5de1ef0..252a1faeb90 100644
--- a/advisories/unreviewed/2024/06/GHSA-c7fp-f8xf-wg7c/GHSA-c7fp-f8xf-wg7c.json
+++ b/advisories/unreviewed/2024/06/GHSA-c7fp-f8xf-wg7c/GHSA-c7fp-f8xf-wg7c.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c7fp-f8xf-wg7c",
- "modified": "2024-06-03T03:31:04Z",
+ "modified": "2024-07-03T18:44:05Z",
"published": "2024-06-03T03:31:04Z",
"aliases": [
"CVE-2024-20071"
],
"details": "In wlan driver, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00364733; Issue ID: MSV-1331.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
"CWE-125"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-03T02:15:09Z"
diff --git a/advisories/unreviewed/2024/06/GHSA-fghj-2j25-cqqp/GHSA-fghj-2j25-cqqp.json b/advisories/unreviewed/2024/06/GHSA-fghj-2j25-cqqp/GHSA-fghj-2j25-cqqp.json
index 071d89b63a1..da002800b8a 100644
--- a/advisories/unreviewed/2024/06/GHSA-fghj-2j25-cqqp/GHSA-fghj-2j25-cqqp.json
+++ b/advisories/unreviewed/2024/06/GHSA-fghj-2j25-cqqp/GHSA-fghj-2j25-cqqp.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fghj-2j25-cqqp",
- "modified": "2024-06-03T21:30:43Z",
+ "modified": "2024-07-03T18:44:08Z",
"published": "2024-06-03T21:30:43Z",
"aliases": [
"CVE-2022-0555"
],
"details": "Subiquity Shows Guided Storage Passphrase in Plaintext with Read-all Permissions",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -37,9 +40,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-256"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-03T19:15:09Z"
diff --git a/advisories/unreviewed/2024/06/GHSA-fvxr-pgg5-fxr4/GHSA-fvxr-pgg5-fxr4.json b/advisories/unreviewed/2024/06/GHSA-fvxr-pgg5-fxr4/GHSA-fvxr-pgg5-fxr4.json
index e752ca0ea6c..ee2f6f6e564 100644
--- a/advisories/unreviewed/2024/06/GHSA-fvxr-pgg5-fxr4/GHSA-fvxr-pgg5-fxr4.json
+++ b/advisories/unreviewed/2024/06/GHSA-fvxr-pgg5-fxr4/GHSA-fvxr-pgg5-fxr4.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fvxr-pgg5-fxr4",
- "modified": "2024-06-03T06:30:53Z",
+ "modified": "2024-07-03T18:44:05Z",
"published": "2024-06-03T06:30:53Z",
"aliases": [
"CVE-2023-51436"
],
"details": "Cross-site scripting vulnerability exists in UNIVERSAL PASSPORT RX versions 1.0.0 to 1.0.8, which may allow a remote authenticated attacker with an administrative privilege to execute an arbitrary script on the web browser of the user who is using the product. ",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
+ }
],
"affected": [
@@ -31,7 +34,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-03T04:15:09Z"
diff --git a/advisories/unreviewed/2024/06/GHSA-j32x-p3fr-rqvr/GHSA-j32x-p3fr-rqvr.json b/advisories/unreviewed/2024/06/GHSA-j32x-p3fr-rqvr/GHSA-j32x-p3fr-rqvr.json
index cef245f48fa..dc931f454b6 100644
--- a/advisories/unreviewed/2024/06/GHSA-j32x-p3fr-rqvr/GHSA-j32x-p3fr-rqvr.json
+++ b/advisories/unreviewed/2024/06/GHSA-j32x-p3fr-rqvr/GHSA-j32x-p3fr-rqvr.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j32x-p3fr-rqvr",
- "modified": "2024-06-04T06:30:37Z",
+ "modified": "2024-07-03T18:44:09Z",
"published": "2024-06-04T06:30:37Z",
"aliases": [
"CVE-2024-4057"
],
"details": "The Gutenberg Blocks with AI by Kadence WP WordPress plugin before 3.2.37 does not validate and escape some of its block attributes before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
+ }
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-04T06:15:10Z"
diff --git a/advisories/unreviewed/2024/06/GHSA-pvhg-jw6p-89xf/GHSA-pvhg-jw6p-89xf.json b/advisories/unreviewed/2024/06/GHSA-pvhg-jw6p-89xf/GHSA-pvhg-jw6p-89xf.json
index a1ad32e2d2f..00dfcb5f271 100644
--- a/advisories/unreviewed/2024/06/GHSA-pvhg-jw6p-89xf/GHSA-pvhg-jw6p-89xf.json
+++ b/advisories/unreviewed/2024/06/GHSA-pvhg-jw6p-89xf/GHSA-pvhg-jw6p-89xf.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pvhg-jw6p-89xf",
- "modified": "2024-06-03T21:30:45Z",
+ "modified": "2024-07-03T18:44:08Z",
"published": "2024-06-03T21:30:45Z",
"aliases": [
"CVE-2023-52162"
],
"details": "Mercusys MW325R EU V3 (Firmware MW325R(EU)_V3_1.11.0 Build 221019) is vulnerable to a stack-based buffer overflow, which could allow an attacker to execute arbitrary code. Exploiting the vulnerability requires authentication.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-121"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-03T20:15:08Z"
diff --git a/advisories/unreviewed/2024/06/GHSA-q77r-932j-wm8q/GHSA-q77r-932j-wm8q.json b/advisories/unreviewed/2024/06/GHSA-q77r-932j-wm8q/GHSA-q77r-932j-wm8q.json
index 325ca893f48..ae32ee2096a 100644
--- a/advisories/unreviewed/2024/06/GHSA-q77r-932j-wm8q/GHSA-q77r-932j-wm8q.json
+++ b/advisories/unreviewed/2024/06/GHSA-q77r-932j-wm8q/GHSA-q77r-932j-wm8q.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q77r-932j-wm8q",
- "modified": "2024-06-03T21:30:46Z",
+ "modified": "2024-07-03T18:44:09Z",
"published": "2024-06-03T21:30:46Z",
"aliases": [
"CVE-2024-36782"
],
"details": "TOTOLINK CP300 V2.0.4-B20201102 was discovered to contain a hardcoded password vulnerability in /etc/shadow.sample, which allows attackers to log in as root.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-798"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-03T21:15:08Z"
diff --git a/advisories/unreviewed/2024/06/GHSA-q7c5-j4r5-8whv/GHSA-q7c5-j4r5-8whv.json b/advisories/unreviewed/2024/06/GHSA-q7c5-j4r5-8whv/GHSA-q7c5-j4r5-8whv.json
index 498dd37d501..38bbc5dc749 100644
--- a/advisories/unreviewed/2024/06/GHSA-q7c5-j4r5-8whv/GHSA-q7c5-j4r5-8whv.json
+++ b/advisories/unreviewed/2024/06/GHSA-q7c5-j4r5-8whv/GHSA-q7c5-j4r5-8whv.json
@@ -25,7 +25,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-121"
],
"severity": null,
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/06/GHSA-rvgq-w6rq-jcjp/GHSA-rvgq-w6rq-jcjp.json b/advisories/unreviewed/2024/06/GHSA-rvgq-w6rq-jcjp/GHSA-rvgq-w6rq-jcjp.json
index 639aa18aae3..a05e8eec7b2 100644
--- a/advisories/unreviewed/2024/06/GHSA-rvgq-w6rq-jcjp/GHSA-rvgq-w6rq-jcjp.json
+++ b/advisories/unreviewed/2024/06/GHSA-rvgq-w6rq-jcjp/GHSA-rvgq-w6rq-jcjp.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rvgq-w6rq-jcjp",
- "modified": "2024-06-03T18:30:50Z",
+ "modified": "2024-07-03T18:44:07Z",
"published": "2024-06-03T18:30:50Z",
"aliases": [
"CVE-2024-37019"
],
"details": "Northern.tech Mender Enterprise before 3.6.4 and 3.7.x before 3.7.4 has Weak Authentication.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-287"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-03T18:15:08Z"
diff --git a/advisories/unreviewed/2024/06/GHSA-wgv8-jq5p-77cr/GHSA-wgv8-jq5p-77cr.json b/advisories/unreviewed/2024/06/GHSA-wgv8-jq5p-77cr/GHSA-wgv8-jq5p-77cr.json
index b448cd91cc9..f08dabff4a7 100644
--- a/advisories/unreviewed/2024/06/GHSA-wgv8-jq5p-77cr/GHSA-wgv8-jq5p-77cr.json
+++ b/advisories/unreviewed/2024/06/GHSA-wgv8-jq5p-77cr/GHSA-wgv8-jq5p-77cr.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wgv8-jq5p-77cr",
- "modified": "2024-06-03T15:30:57Z",
+ "modified": "2024-07-03T18:44:07Z",
"published": "2024-06-03T15:30:57Z",
"aliases": [
"CVE-2024-36569"
],
"details": "Sourcecodester Gas Agency Management System v1.0 is vulnerable to arbitrary code execution via editClientImage.php.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-98"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-03T14:15:09Z"
diff --git a/advisories/unreviewed/2024/06/GHSA-x9wv-6vfj-6m33/GHSA-x9wv-6vfj-6m33.json b/advisories/unreviewed/2024/06/GHSA-x9wv-6vfj-6m33/GHSA-x9wv-6vfj-6m33.json
index 945ff7a96f6..91a5bd69c43 100644
--- a/advisories/unreviewed/2024/06/GHSA-x9wv-6vfj-6m33/GHSA-x9wv-6vfj-6m33.json
+++ b/advisories/unreviewed/2024/06/GHSA-x9wv-6vfj-6m33/GHSA-x9wv-6vfj-6m33.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x9wv-6vfj-6m33",
- "modified": "2024-06-03T03:31:04Z",
+ "modified": "2024-07-03T18:44:05Z",
"published": "2024-06-03T03:31:04Z",
"aliases": [
"CVE-2024-20067"
],
"details": "In modem, there is a possible out of bounds write due to improper input invalidation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01267285; Issue ID: MSV-1462.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
"CWE-787"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-03T02:15:08Z"