From 27a55c2c9de9908ec6f2d0641350bfddf3fd1d60 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 4 Nov 2024 03:32:02 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-34x9-x6hh-cvvw.json | 35 +++++++++++ .../GHSA-4g7x-pvhw-3mph.json | 35 +++++++++++ .../GHSA-4r9r-m8vg-chxf.json | 35 +++++++++++ .../GHSA-5qcc-6h23-g9c6.json | 58 +++++++++++++++++++ .../GHSA-79m4-m83j-wqr4.json | 35 +++++++++++ .../GHSA-7fwp-9vj9-hr6v.json | 54 +++++++++++++++++ .../GHSA-8fqg-98qq-f4p9.json | 58 +++++++++++++++++++ .../GHSA-9c8g-4qx4-v74x.json | 35 +++++++++++ .../GHSA-9w8c-9425-p69g.json | 35 +++++++++++ .../GHSA-cc49-h52c-hm2r.json | 35 +++++++++++ .../GHSA-ch3r-qc65-hpfh.json | 54 +++++++++++++++++ .../GHSA-f3jh-3x43-rfcx.json | 35 +++++++++++ .../GHSA-gcgg-hvp7-xgf7.json | 35 +++++++++++ .../GHSA-h6p4-x9fh-hx9v.json | 58 +++++++++++++++++++ .../GHSA-m62c-rp67-pw2c.json | 35 +++++++++++ .../GHSA-mgx7-9xcp-cmj3.json | 35 +++++++++++ .../GHSA-mjqq-m93c-hjjr.json | 58 +++++++++++++++++++ .../GHSA-p7r4-g84v-785w.json | 58 +++++++++++++++++++ .../GHSA-ph42-jmfw-fmpf.json | 35 +++++++++++ .../GHSA-pxqj-m825-g6fc.json | 35 +++++++++++ .../GHSA-r6cq-w3q4-7rwf.json | 54 +++++++++++++++++ .../GHSA-r6pj-4h6q-3r9q.json | 35 +++++++++++ .../GHSA-v45x-45vv-7hm9.json | 35 +++++++++++ .../GHSA-vg89-xvr7-m96m.json | 35 +++++++++++ .../GHSA-vr4g-h59r-642r.json | 54 +++++++++++++++++ .../GHSA-w346-ppfv-63m8.json | 58 +++++++++++++++++++ .../GHSA-w9p5-xqxf-xvx7.json | 35 +++++++++++ .../GHSA-wjq7-92jr-r24h.json | 35 +++++++++++ .../GHSA-x6g6-7cr3-c8p4.json | 35 +++++++++++ 29 files changed, 1229 insertions(+) create mode 100644 advisories/unreviewed/2024/11/GHSA-34x9-x6hh-cvvw/GHSA-34x9-x6hh-cvvw.json create mode 100644 advisories/unreviewed/2024/11/GHSA-4g7x-pvhw-3mph/GHSA-4g7x-pvhw-3mph.json create mode 100644 advisories/unreviewed/2024/11/GHSA-4r9r-m8vg-chxf/GHSA-4r9r-m8vg-chxf.json create mode 100644 advisories/unreviewed/2024/11/GHSA-5qcc-6h23-g9c6/GHSA-5qcc-6h23-g9c6.json create mode 100644 advisories/unreviewed/2024/11/GHSA-79m4-m83j-wqr4/GHSA-79m4-m83j-wqr4.json create mode 100644 advisories/unreviewed/2024/11/GHSA-7fwp-9vj9-hr6v/GHSA-7fwp-9vj9-hr6v.json create mode 100644 advisories/unreviewed/2024/11/GHSA-8fqg-98qq-f4p9/GHSA-8fqg-98qq-f4p9.json create mode 100644 advisories/unreviewed/2024/11/GHSA-9c8g-4qx4-v74x/GHSA-9c8g-4qx4-v74x.json create mode 100644 advisories/unreviewed/2024/11/GHSA-9w8c-9425-p69g/GHSA-9w8c-9425-p69g.json create mode 100644 advisories/unreviewed/2024/11/GHSA-cc49-h52c-hm2r/GHSA-cc49-h52c-hm2r.json create mode 100644 advisories/unreviewed/2024/11/GHSA-ch3r-qc65-hpfh/GHSA-ch3r-qc65-hpfh.json create mode 100644 advisories/unreviewed/2024/11/GHSA-f3jh-3x43-rfcx/GHSA-f3jh-3x43-rfcx.json create mode 100644 advisories/unreviewed/2024/11/GHSA-gcgg-hvp7-xgf7/GHSA-gcgg-hvp7-xgf7.json create mode 100644 advisories/unreviewed/2024/11/GHSA-h6p4-x9fh-hx9v/GHSA-h6p4-x9fh-hx9v.json create mode 100644 advisories/unreviewed/2024/11/GHSA-m62c-rp67-pw2c/GHSA-m62c-rp67-pw2c.json create mode 100644 advisories/unreviewed/2024/11/GHSA-mgx7-9xcp-cmj3/GHSA-mgx7-9xcp-cmj3.json create mode 100644 advisories/unreviewed/2024/11/GHSA-mjqq-m93c-hjjr/GHSA-mjqq-m93c-hjjr.json create mode 100644 advisories/unreviewed/2024/11/GHSA-p7r4-g84v-785w/GHSA-p7r4-g84v-785w.json create mode 100644 advisories/unreviewed/2024/11/GHSA-ph42-jmfw-fmpf/GHSA-ph42-jmfw-fmpf.json create mode 100644 advisories/unreviewed/2024/11/GHSA-pxqj-m825-g6fc/GHSA-pxqj-m825-g6fc.json create mode 100644 advisories/unreviewed/2024/11/GHSA-r6cq-w3q4-7rwf/GHSA-r6cq-w3q4-7rwf.json create mode 100644 advisories/unreviewed/2024/11/GHSA-r6pj-4h6q-3r9q/GHSA-r6pj-4h6q-3r9q.json create mode 100644 advisories/unreviewed/2024/11/GHSA-v45x-45vv-7hm9/GHSA-v45x-45vv-7hm9.json create mode 100644 advisories/unreviewed/2024/11/GHSA-vg89-xvr7-m96m/GHSA-vg89-xvr7-m96m.json create mode 100644 advisories/unreviewed/2024/11/GHSA-vr4g-h59r-642r/GHSA-vr4g-h59r-642r.json create mode 100644 advisories/unreviewed/2024/11/GHSA-w346-ppfv-63m8/GHSA-w346-ppfv-63m8.json create mode 100644 advisories/unreviewed/2024/11/GHSA-w9p5-xqxf-xvx7/GHSA-w9p5-xqxf-xvx7.json create mode 100644 advisories/unreviewed/2024/11/GHSA-wjq7-92jr-r24h/GHSA-wjq7-92jr-r24h.json create mode 100644 advisories/unreviewed/2024/11/GHSA-x6g6-7cr3-c8p4/GHSA-x6g6-7cr3-c8p4.json diff --git a/advisories/unreviewed/2024/11/GHSA-34x9-x6hh-cvvw/GHSA-34x9-x6hh-cvvw.json b/advisories/unreviewed/2024/11/GHSA-34x9-x6hh-cvvw/GHSA-34x9-x6hh-cvvw.json new file mode 100644 index 00000000000..8ee52efca1e --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-34x9-x6hh-cvvw/GHSA-34x9-x6hh-cvvw.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-34x9-x6hh-cvvw", + "modified": "2024-11-04T03:30:40Z", + "published": "2024-11-04T03:30:40Z", + "aliases": [ + "CVE-2024-20120" + ], + "details": "In KeyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08956986; Issue ID: MSV-1575.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20120" + }, + { + "type": "WEB", + "url": "https://corp.mediatek.com/product-security-bulletin/November-2024" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T02:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-4g7x-pvhw-3mph/GHSA-4g7x-pvhw-3mph.json b/advisories/unreviewed/2024/11/GHSA-4g7x-pvhw-3mph/GHSA-4g7x-pvhw-3mph.json new file mode 100644 index 00000000000..b7f9a8665a5 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-4g7x-pvhw-3mph/GHSA-4g7x-pvhw-3mph.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4g7x-pvhw-3mph", + "modified": "2024-11-04T03:30:40Z", + "published": "2024-11-04T03:30:40Z", + "aliases": [ + "CVE-2024-20112" + ], + "details": "In isp, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09071481; Issue ID: MSV-1730.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20112" + }, + { + "type": "WEB", + "url": "https://corp.mediatek.com/product-security-bulletin/November-2024" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T02:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-4r9r-m8vg-chxf/GHSA-4r9r-m8vg-chxf.json b/advisories/unreviewed/2024/11/GHSA-4r9r-m8vg-chxf/GHSA-4r9r-m8vg-chxf.json new file mode 100644 index 00000000000..91464a8c318 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-4r9r-m8vg-chxf/GHSA-4r9r-m8vg-chxf.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4r9r-m8vg-chxf", + "modified": "2024-11-04T03:30:40Z", + "published": "2024-11-04T03:30:40Z", + "aliases": [ + "CVE-2024-20117" + ], + "details": "In vdec, there is a possible out of bounds read due to improper structure design. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09008925; Issue ID: MSV-1681.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20117" + }, + { + "type": "WEB", + "url": "https://corp.mediatek.com/product-security-bulletin/November-2024" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T02:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-5qcc-6h23-g9c6/GHSA-5qcc-6h23-g9c6.json b/advisories/unreviewed/2024/11/GHSA-5qcc-6h23-g9c6/GHSA-5qcc-6h23-g9c6.json new file mode 100644 index 00000000000..51bcab0c12d --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-5qcc-6h23-g9c6/GHSA-5qcc-6h23-g9c6.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5qcc-6h23-g9c6", + "modified": "2024-11-04T03:30:40Z", + "published": "2024-11-04T03:30:39Z", + "aliases": [ + "CVE-2024-10753" + ], + "details": "A vulnerability was found in PHPGurukul Online Shopping Portal 2.0. It has been declared as problematic. This vulnerability affects unknown code of the file admin/assets/plugins/DataTables/media/unit_testing/templates/dom_data_two_headers.php. The manipulation of the argument scripts leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10753" + }, + { + "type": "WEB", + "url": "https://github.com/secuserx/CVE/blob/main/%5BXSS%20vulnerability%5D%20found%20in%20Online%20Shopping%20Portal%202.0%20-%20(dom_data_two_headers.php).md" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.282922" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.282922" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.436375" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T02:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-79m4-m83j-wqr4/GHSA-79m4-m83j-wqr4.json b/advisories/unreviewed/2024/11/GHSA-79m4-m83j-wqr4/GHSA-79m4-m83j-wqr4.json new file mode 100644 index 00000000000..bcf79b84233 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-79m4-m83j-wqr4/GHSA-79m4-m83j-wqr4.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-79m4-m83j-wqr4", + "modified": "2024-11-04T03:30:39Z", + "published": "2024-11-04T03:30:39Z", + "aliases": [ + "CVE-2024-20104" + ], + "details": "In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09073261; Issue ID: MSV-1772.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20104" + }, + { + "type": "WEB", + "url": "https://corp.mediatek.com/product-security-bulletin/November-2024" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T02:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-7fwp-9vj9-hr6v/GHSA-7fwp-9vj9-hr6v.json b/advisories/unreviewed/2024/11/GHSA-7fwp-9vj9-hr6v/GHSA-7fwp-9vj9-hr6v.json new file mode 100644 index 00000000000..a5f5cbbc62d --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-7fwp-9vj9-hr6v/GHSA-7fwp-9vj9-hr6v.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7fwp-9vj9-hr6v", + "modified": "2024-11-04T03:30:39Z", + "published": "2024-11-04T03:30:39Z", + "aliases": [ + "CVE-2024-10752" + ], + "details": "A vulnerability was found in Codezips Pet Shop Management System 1.0. It has been classified as critical. This affects an unknown part of the file /productsadd.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The initial researcher advisory mentions contradicting file names to be affected.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10752" + }, + { + "type": "WEB", + "url": "https://github.com/primaryboy/CVE/issues/1" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.282921" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.282921" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.436316" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T02:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-8fqg-98qq-f4p9/GHSA-8fqg-98qq-f4p9.json b/advisories/unreviewed/2024/11/GHSA-8fqg-98qq-f4p9/GHSA-8fqg-98qq-f4p9.json new file mode 100644 index 00000000000..17e9cd1e308 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-8fqg-98qq-f4p9/GHSA-8fqg-98qq-f4p9.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8fqg-98qq-f4p9", + "modified": "2024-11-04T03:30:40Z", + "published": "2024-11-04T03:30:40Z", + "aliases": [ + "CVE-2024-10756" + ], + "details": "A vulnerability classified as problematic was found in PHPGurukul Online Shopping Portal 2.0. Affected by this vulnerability is an unknown functionality of the file /admin/assets/plugins/DataTables/media/unit_testing/templates/html_table.php. The manipulation of the argument scripts leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10756" + }, + { + "type": "WEB", + "url": "https://github.com/secuserx/CVE/blob/main/%5BXSS%20vulnerability%5D%20found%20in%20Online%20Shopping%20Portal%202.0%20-%20(html_table.php).md" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.282925" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.282925" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.436381" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T03:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-9c8g-4qx4-v74x/GHSA-9c8g-4qx4-v74x.json b/advisories/unreviewed/2024/11/GHSA-9c8g-4qx4-v74x/GHSA-9c8g-4qx4-v74x.json new file mode 100644 index 00000000000..b8026e96795 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-9c8g-4qx4-v74x/GHSA-9c8g-4qx4-v74x.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9c8g-4qx4-v74x", + "modified": "2024-11-04T03:30:40Z", + "published": "2024-11-04T03:30:40Z", + "aliases": [ + "CVE-2024-20109" + ], + "details": "In ccu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09065928; Issue ID: MSV-1763.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20109" + }, + { + "type": "WEB", + "url": "https://corp.mediatek.com/product-security-bulletin/November-2024" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T02:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-9w8c-9425-p69g/GHSA-9w8c-9425-p69g.json b/advisories/unreviewed/2024/11/GHSA-9w8c-9425-p69g/GHSA-9w8c-9425-p69g.json new file mode 100644 index 00000000000..4fa669862be --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-9w8c-9425-p69g/GHSA-9w8c-9425-p69g.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9w8c-9425-p69g", + "modified": "2024-11-04T03:30:40Z", + "published": "2024-11-04T03:30:40Z", + "aliases": [ + "CVE-2024-20121" + ], + "details": "In KeyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08956986; Issue ID: MSV-1574.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20121" + }, + { + "type": "WEB", + "url": "https://corp.mediatek.com/product-security-bulletin/November-2024" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T02:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-cc49-h52c-hm2r/GHSA-cc49-h52c-hm2r.json b/advisories/unreviewed/2024/11/GHSA-cc49-h52c-hm2r/GHSA-cc49-h52c-hm2r.json new file mode 100644 index 00000000000..62e5ac375f9 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-cc49-h52c-hm2r/GHSA-cc49-h52c-hm2r.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cc49-h52c-hm2r", + "modified": "2024-11-04T03:30:40Z", + "published": "2024-11-04T03:30:40Z", + "aliases": [ + "CVE-2024-20119" + ], + "details": "In mms, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09062301; Issue ID: MSV-1620.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20119" + }, + { + "type": "WEB", + "url": "https://corp.mediatek.com/product-security-bulletin/November-2024" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-123" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T02:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-ch3r-qc65-hpfh/GHSA-ch3r-qc65-hpfh.json b/advisories/unreviewed/2024/11/GHSA-ch3r-qc65-hpfh/GHSA-ch3r-qc65-hpfh.json new file mode 100644 index 00000000000..76d31db475c --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-ch3r-qc65-hpfh/GHSA-ch3r-qc65-hpfh.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ch3r-qc65-hpfh", + "modified": "2024-11-04T03:30:39Z", + "published": "2024-11-04T03:30:39Z", + "aliases": [ + "CVE-2024-10748" + ], + "details": "A vulnerability, which was classified as problematic, has been found in Cosmote Greece What's Up App 4.47.3 on Android. This issue affects some unknown processing of the file gr/desquared/kmmsharedmodule/db/RealmDB.java of the component Realm Database Handler. The manipulation of the argument defaultRealmKey leads to use of default cryptographic key. Local access is required to approach this attack. The complexity of an attack is rather high. The exploitation is known to be difficult. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10748" + }, + { + "type": "WEB", + "url": "https://github.com/secuserx/CVE/blob/main/%5BHardcoded%20Realm%20Database%20Encryption%20Key%5D%20found%20in%20What's%20UP%20Android%20App%204.47.3%20-%20(RealmDB.java).md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.282917" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.282917" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.432429" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1394" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T01:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-f3jh-3x43-rfcx/GHSA-f3jh-3x43-rfcx.json b/advisories/unreviewed/2024/11/GHSA-f3jh-3x43-rfcx/GHSA-f3jh-3x43-rfcx.json new file mode 100644 index 00000000000..ec4c20fc537 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-f3jh-3x43-rfcx/GHSA-f3jh-3x43-rfcx.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f3jh-3x43-rfcx", + "modified": "2024-11-04T03:30:40Z", + "published": "2024-11-04T03:30:40Z", + "aliases": [ + "CVE-2024-20113" + ], + "details": "In ccu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09036814; Issue ID: MSV-1715.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20113" + }, + { + "type": "WEB", + "url": "https://corp.mediatek.com/product-security-bulletin/November-2024" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T02:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-gcgg-hvp7-xgf7/GHSA-gcgg-hvp7-xgf7.json b/advisories/unreviewed/2024/11/GHSA-gcgg-hvp7-xgf7/GHSA-gcgg-hvp7-xgf7.json new file mode 100644 index 00000000000..af854ca1827 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-gcgg-hvp7-xgf7/GHSA-gcgg-hvp7-xgf7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gcgg-hvp7-xgf7", + "modified": "2024-11-04T03:30:40Z", + "published": "2024-11-04T03:30:40Z", + "aliases": [ + "CVE-2024-20114" + ], + "details": "In ccu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09037038; Issue ID: MSV-1714.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20114" + }, + { + "type": "WEB", + "url": "https://corp.mediatek.com/product-security-bulletin/November-2024" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T02:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-h6p4-x9fh-hx9v/GHSA-h6p4-x9fh-hx9v.json b/advisories/unreviewed/2024/11/GHSA-h6p4-x9fh-hx9v/GHSA-h6p4-x9fh-hx9v.json new file mode 100644 index 00000000000..21e7fb5abb2 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-h6p4-x9fh-hx9v/GHSA-h6p4-x9fh-hx9v.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h6p4-x9fh-hx9v", + "modified": "2024-11-04T03:30:40Z", + "published": "2024-11-04T03:30:40Z", + "aliases": [ + "CVE-2024-10754" + ], + "details": "A vulnerability was found in PHPGurukul Online Shopping Portal 2.0. It has been rated as problematic. This issue affects some unknown processing of the file /admin/assets/plugins/DataTables/media/unit_testing/templates/dymanic_table.php. The manipulation of the argument scripts leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10754" + }, + { + "type": "WEB", + "url": "https://github.com/secuserx/CVE/blob/main/%5BXSS%20vulnerability%5D%20found%20in%20Online%20Shopping%20Portal%202.0%20-%20(dymanic_table.php).md" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.282923" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.282923" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.436376" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T03:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-m62c-rp67-pw2c/GHSA-m62c-rp67-pw2c.json b/advisories/unreviewed/2024/11/GHSA-m62c-rp67-pw2c/GHSA-m62c-rp67-pw2c.json new file mode 100644 index 00000000000..722c7ce2166 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-m62c-rp67-pw2c/GHSA-m62c-rp67-pw2c.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m62c-rp67-pw2c", + "modified": "2024-11-04T03:30:40Z", + "published": "2024-11-04T03:30:40Z", + "aliases": [ + "CVE-2024-20107" + ], + "details": "In da, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09124360; Issue ID: MSV-1823.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20107" + }, + { + "type": "WEB", + "url": "https://corp.mediatek.com/product-security-bulletin/November-2024" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T02:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-mgx7-9xcp-cmj3/GHSA-mgx7-9xcp-cmj3.json b/advisories/unreviewed/2024/11/GHSA-mgx7-9xcp-cmj3/GHSA-mgx7-9xcp-cmj3.json new file mode 100644 index 00000000000..498fe8dc000 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-mgx7-9xcp-cmj3/GHSA-mgx7-9xcp-cmj3.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mgx7-9xcp-cmj3", + "modified": "2024-11-04T03:30:40Z", + "published": "2024-11-04T03:30:40Z", + "aliases": [ + "CVE-2024-20108" + ], + "details": "In atci, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09082988; Issue ID: MSV-1774.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20108" + }, + { + "type": "WEB", + "url": "https://corp.mediatek.com/product-security-bulletin/November-2024" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T02:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-mjqq-m93c-hjjr/GHSA-mjqq-m93c-hjjr.json b/advisories/unreviewed/2024/11/GHSA-mjqq-m93c-hjjr/GHSA-mjqq-m93c-hjjr.json new file mode 100644 index 00000000000..ba2d7fbfe47 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-mjqq-m93c-hjjr/GHSA-mjqq-m93c-hjjr.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mjqq-m93c-hjjr", + "modified": "2024-11-04T03:30:40Z", + "published": "2024-11-04T03:30:40Z", + "aliases": [ + "CVE-2024-10755" + ], + "details": "A vulnerability classified as problematic has been found in PHPGurukul Online Shopping Portal 2.0. Affected is an unknown function of the file /admin/assets/plugins/DataTables/media/unit_testing/templates/empty_table.php. The manipulation of the argument scripts leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10755" + }, + { + "type": "WEB", + "url": "https://github.com/secuserx/CVE/blob/main/%5BXSS%20vulnerability%5D%20found%20in%20Online%20Shopping%20Portal%202.0%20-%20(empty_table.php).md" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.282924" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.282924" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.436377" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T03:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-p7r4-g84v-785w/GHSA-p7r4-g84v-785w.json b/advisories/unreviewed/2024/11/GHSA-p7r4-g84v-785w/GHSA-p7r4-g84v-785w.json new file mode 100644 index 00000000000..0a2eda173ba --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-p7r4-g84v-785w/GHSA-p7r4-g84v-785w.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p7r4-g84v-785w", + "modified": "2024-11-04T03:30:39Z", + "published": "2024-11-04T03:30:39Z", + "aliases": [ + "CVE-2024-10750" + ], + "details": "A vulnerability has been found in Tenda i22 1.0.0.3(4687) and classified as problematic. Affected by this vulnerability is the function websReadEvent of the file /goform/GetIPTV?fgHPOST/goform/SysToo. The manipulation of the argument Content-Length leads to null pointer dereference. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10750" + }, + { + "type": "WEB", + "url": "https://github.com/xiaobor123/tenda-vul-i22" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.282919" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.282919" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.435407" + }, + { + "type": "WEB", + "url": "https://www.tenda.com.cn" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T02:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-ph42-jmfw-fmpf/GHSA-ph42-jmfw-fmpf.json b/advisories/unreviewed/2024/11/GHSA-ph42-jmfw-fmpf/GHSA-ph42-jmfw-fmpf.json new file mode 100644 index 00000000000..b81529ca81d --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-ph42-jmfw-fmpf/GHSA-ph42-jmfw-fmpf.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ph42-jmfw-fmpf", + "modified": "2024-11-04T03:30:40Z", + "published": "2024-11-04T03:30:40Z", + "aliases": [ + "CVE-2024-20110" + ], + "details": "In ccu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09065887; Issue ID: MSV-1762.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20110" + }, + { + "type": "WEB", + "url": "https://corp.mediatek.com/product-security-bulletin/November-2024" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T02:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-pxqj-m825-g6fc/GHSA-pxqj-m825-g6fc.json b/advisories/unreviewed/2024/11/GHSA-pxqj-m825-g6fc/GHSA-pxqj-m825-g6fc.json new file mode 100644 index 00000000000..c9fade1fa75 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-pxqj-m825-g6fc/GHSA-pxqj-m825-g6fc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pxqj-m825-g6fc", + "modified": "2024-11-04T03:30:40Z", + "published": "2024-11-04T03:30:40Z", + "aliases": [ + "CVE-2024-20122" + ], + "details": "In vdec, there is a possible out of bounds read due to improper structure design. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09008925; Issue ID: MSV-1572.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20122" + }, + { + "type": "WEB", + "url": "https://corp.mediatek.com/product-security-bulletin/November-2024" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T02:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-r6cq-w3q4-7rwf/GHSA-r6cq-w3q4-7rwf.json b/advisories/unreviewed/2024/11/GHSA-r6cq-w3q4-7rwf/GHSA-r6cq-w3q4-7rwf.json new file mode 100644 index 00000000000..074a3cc4bf4 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-r6cq-w3q4-7rwf/GHSA-r6cq-w3q4-7rwf.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r6cq-w3q4-7rwf", + "modified": "2024-11-04T03:30:39Z", + "published": "2024-11-04T03:30:39Z", + "aliases": [ + "CVE-2024-10749" + ], + "details": "A vulnerability, which was classified as critical, was found in ThinkAdmin up to 6.1.67. Affected is the function script of the file /app/admin/controller/api/Plugs.php. The manipulation of the argument uptoken leads to deserialization. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10749" + }, + { + "type": "WEB", + "url": "https://github.com/pwysec/Xmwcq/blob/main/1.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.282918" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.282918" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.432436" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T01:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-r6pj-4h6q-3r9q/GHSA-r6pj-4h6q-3r9q.json b/advisories/unreviewed/2024/11/GHSA-r6pj-4h6q-3r9q/GHSA-r6pj-4h6q-3r9q.json new file mode 100644 index 00000000000..9682fde5eeb --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-r6pj-4h6q-3r9q/GHSA-r6pj-4h6q-3r9q.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r6pj-4h6q-3r9q", + "modified": "2024-11-04T03:30:40Z", + "published": "2024-11-04T03:30:40Z", + "aliases": [ + "CVE-2024-20111" + ], + "details": "In ccu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09065033; Issue ID: MSV-1754.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20111" + }, + { + "type": "WEB", + "url": "https://corp.mediatek.com/product-security-bulletin/November-2024" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T02:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-v45x-45vv-7hm9/GHSA-v45x-45vv-7hm9.json b/advisories/unreviewed/2024/11/GHSA-v45x-45vv-7hm9/GHSA-v45x-45vv-7hm9.json new file mode 100644 index 00000000000..071611f0fd5 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-v45x-45vv-7hm9/GHSA-v45x-45vv-7hm9.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v45x-45vv-7hm9", + "modified": "2024-11-04T03:30:40Z", + "published": "2024-11-04T03:30:40Z", + "aliases": [ + "CVE-2024-20115" + ], + "details": "In ccu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09036695; Issue ID: MSV-1713.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20115" + }, + { + "type": "WEB", + "url": "https://corp.mediatek.com/product-security-bulletin/November-2024" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T02:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-vg89-xvr7-m96m/GHSA-vg89-xvr7-m96m.json b/advisories/unreviewed/2024/11/GHSA-vg89-xvr7-m96m/GHSA-vg89-xvr7-m96m.json new file mode 100644 index 00000000000..84f9b7f2122 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-vg89-xvr7-m96m/GHSA-vg89-xvr7-m96m.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vg89-xvr7-m96m", + "modified": "2024-11-04T03:30:40Z", + "published": "2024-11-04T03:30:40Z", + "aliases": [ + "CVE-2024-20106" + ], + "details": "In m4u, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08960505; Issue ID: MSV-1590.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20106" + }, + { + "type": "WEB", + "url": "https://corp.mediatek.com/product-security-bulletin/November-2024" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-843" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T02:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-vr4g-h59r-642r/GHSA-vr4g-h59r-642r.json b/advisories/unreviewed/2024/11/GHSA-vr4g-h59r-642r/GHSA-vr4g-h59r-642r.json new file mode 100644 index 00000000000..c2b4b3347c0 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-vr4g-h59r-642r/GHSA-vr4g-h59r-642r.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vr4g-h59r-642r", + "modified": "2024-11-04T03:30:39Z", + "published": "2024-11-04T03:30:39Z", + "aliases": [ + "CVE-2024-10751" + ], + "details": "A vulnerability was found in Codezips ISP Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file pay.php. The manipulation of the argument customer leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10751" + }, + { + "type": "WEB", + "url": "https://github.com/JiangJiangCC/CVE/issues/1" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.282920" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.282920" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.436296" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T02:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-w346-ppfv-63m8/GHSA-w346-ppfv-63m8.json b/advisories/unreviewed/2024/11/GHSA-w346-ppfv-63m8/GHSA-w346-ppfv-63m8.json new file mode 100644 index 00000000000..28827c25461 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-w346-ppfv-63m8/GHSA-w346-ppfv-63m8.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w346-ppfv-63m8", + "modified": "2024-11-04T03:30:40Z", + "published": "2024-11-04T03:30:40Z", + "aliases": [ + "CVE-2024-10757" + ], + "details": "A vulnerability, which was classified as problematic, has been found in PHPGurukul Online Shopping Portal 2.0. Affected by this issue is some unknown functionality of the file /admin/assets/plugins/DataTables/media/unit_testing/templates/js_data.php. The manipulation of the argument scripts leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10757" + }, + { + "type": "WEB", + "url": "https://github.com/secuserx/CVE/blob/main/%5BXSS%20vulnerability%5D%20found%20in%20Online%20Shopping%20Portal%202.0%20-%20(js_data.php).md" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.282926" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.282926" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.436391" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T03:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-w9p5-xqxf-xvx7/GHSA-w9p5-xqxf-xvx7.json b/advisories/unreviewed/2024/11/GHSA-w9p5-xqxf-xvx7/GHSA-w9p5-xqxf-xvx7.json new file mode 100644 index 00000000000..eb89f72933e --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-w9p5-xqxf-xvx7/GHSA-w9p5-xqxf-xvx7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w9p5-xqxf-xvx7", + "modified": "2024-11-04T03:30:40Z", + "published": "2024-11-04T03:30:40Z", + "aliases": [ + "CVE-2024-20118" + ], + "details": "In mms, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09062392; Issue ID: MSV-1621.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20118" + }, + { + "type": "WEB", + "url": "https://corp.mediatek.com/product-security-bulletin/November-2024" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-123" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T02:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-wjq7-92jr-r24h/GHSA-wjq7-92jr-r24h.json b/advisories/unreviewed/2024/11/GHSA-wjq7-92jr-r24h/GHSA-wjq7-92jr-r24h.json new file mode 100644 index 00000000000..1d5680f787d --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-wjq7-92jr-r24h/GHSA-wjq7-92jr-r24h.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wjq7-92jr-r24h", + "modified": "2024-11-04T03:30:40Z", + "published": "2024-11-04T03:30:40Z", + "aliases": [ + "CVE-2024-20123" + ], + "details": "In vdec, there is a possible out of bounds read due to improper structure design. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09008925; Issue ID: MSV-1569.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20123" + }, + { + "type": "WEB", + "url": "https://corp.mediatek.com/product-security-bulletin/November-2024" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T02:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-x6g6-7cr3-c8p4/GHSA-x6g6-7cr3-c8p4.json b/advisories/unreviewed/2024/11/GHSA-x6g6-7cr3-c8p4/GHSA-x6g6-7cr3-c8p4.json new file mode 100644 index 00000000000..171010bef61 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-x6g6-7cr3-c8p4/GHSA-x6g6-7cr3-c8p4.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x6g6-7cr3-c8p4", + "modified": "2024-11-04T03:30:40Z", + "published": "2024-11-04T03:30:40Z", + "aliases": [ + "CVE-2024-20124" + ], + "details": "In vdec, there is a possible out of bounds read due to improper structure design. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09008925; Issue ID: MSV-1568.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20124" + }, + { + "type": "WEB", + "url": "https://corp.mediatek.com/product-security-bulletin/November-2024" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T02:15:17Z" + } +} \ No newline at end of file