diff --git a/advisories/unreviewed/2024/01/GHSA-36xj-gcr2-cgrf/GHSA-36xj-gcr2-cgrf.json b/advisories/unreviewed/2024/01/GHSA-36xj-gcr2-cgrf/GHSA-36xj-gcr2-cgrf.json index aae1d9b755e..723a7e9dde0 100644 --- a/advisories/unreviewed/2024/01/GHSA-36xj-gcr2-cgrf/GHSA-36xj-gcr2-cgrf.json +++ b/advisories/unreviewed/2024/01/GHSA-36xj-gcr2-cgrf/GHSA-36xj-gcr2-cgrf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-36xj-gcr2-cgrf", - "modified": "2024-01-24T18:31:01Z", + "modified": "2024-02-05T15:30:23Z", "published": "2024-01-24T18:31:01Z", "aliases": [ "CVE-2023-51888" ], "details": "Buffer Overflow vulnerability in the nomath() function in Mathtex v.1.05 and before allows a remote attacker to cause a denial of service via a crafted string in the application URL.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-24T18:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-567x-h4g5-2gwq/GHSA-567x-h4g5-2gwq.json b/advisories/unreviewed/2024/01/GHSA-567x-h4g5-2gwq/GHSA-567x-h4g5-2gwq.json index 97a2c40b4a8..750b5c55b9f 100644 --- a/advisories/unreviewed/2024/01/GHSA-567x-h4g5-2gwq/GHSA-567x-h4g5-2gwq.json +++ b/advisories/unreviewed/2024/01/GHSA-567x-h4g5-2gwq/GHSA-567x-h4g5-2gwq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-567x-h4g5-2gwq", - "modified": "2024-01-24T18:31:01Z", + "modified": "2024-02-05T15:30:23Z", "published": "2024-01-24T18:31:01Z", "aliases": [ "CVE-2023-51890" ], "details": "An infinite loop issue discovered in Mathtex 1.05 and before allows a remote attackers to consume CPU resources via crafted string in the application URL.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-835" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-24T18:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-57w7-wm2r-3f6f/GHSA-57w7-wm2r-3f6f.json b/advisories/unreviewed/2024/01/GHSA-57w7-wm2r-3f6f/GHSA-57w7-wm2r-3f6f.json index 4d26ae3a0a0..5cfb7cf21bd 100644 --- a/advisories/unreviewed/2024/01/GHSA-57w7-wm2r-3f6f/GHSA-57w7-wm2r-3f6f.json +++ b/advisories/unreviewed/2024/01/GHSA-57w7-wm2r-3f6f/GHSA-57w7-wm2r-3f6f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-57w7-wm2r-3f6f", - "modified": "2024-01-24T18:31:01Z", + "modified": "2024-02-05T15:30:23Z", "published": "2024-01-24T18:31:01Z", "aliases": [ "CVE-2023-51889" ], "details": "Stack Overflow vulnerability in the validate() function in Mathtex v.1.05 and before allows a remote attacker to execute arbitrary code via crafted string in the application URL.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-24T18:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-xx65-34vr-mqrj/GHSA-xx65-34vr-mqrj.json b/advisories/unreviewed/2024/01/GHSA-xx65-34vr-mqrj/GHSA-xx65-34vr-mqrj.json index 51aad6dc782..1cd5d2a344e 100644 --- a/advisories/unreviewed/2024/01/GHSA-xx65-34vr-mqrj/GHSA-xx65-34vr-mqrj.json +++ b/advisories/unreviewed/2024/01/GHSA-xx65-34vr-mqrj/GHSA-xx65-34vr-mqrj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xx65-34vr-mqrj", - "modified": "2024-01-26T09:30:23Z", + "modified": "2024-02-05T15:30:23Z", "published": "2024-01-26T09:30:23Z", "aliases": [ "CVE-2024-23388" ], "details": "Improper authorization in handler for custom URL scheme issue in \"Mercari\" App for Android prior to version 5.78.0 allows a remote attacker to lead a user to access an arbitrary website via the vulnerable App. As a result, the user may become a victim of a phishing attack.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-26T07:15:59Z" diff --git a/advisories/unreviewed/2024/02/GHSA-27xq-w3jc-436c/GHSA-27xq-w3jc-436c.json b/advisories/unreviewed/2024/02/GHSA-27xq-w3jc-436c/GHSA-27xq-w3jc-436c.json new file mode 100644 index 00000000000..8665aa66dd6 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-27xq-w3jc-436c/GHSA-27xq-w3jc-436c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-27xq-w3jc-436c", + "modified": "2024-02-05T15:30:23Z", + "published": "2024-02-05T15:30:23Z", + "aliases": [ + "CVE-2024-23109" + ], + "details": "An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSIEM version 7.1.0 through 7.1.1 and 7.0.0 through 7.0.2 and 6.7.0 through 6.7.8 and 6.6.0 through 6.6.3 and 6.5.0 through 6.5.2 and 6.4.0 through 6.4.2 allows attacker to execute unauthorized code or commands via via crafted API requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23109" + }, + { + "type": "WEB", + "url": "https://fortiguard.com/psirt/FG-IR-23-130" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-05T14:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-5rfj-4v26-hqmw/GHSA-5rfj-4v26-hqmw.json b/advisories/unreviewed/2024/02/GHSA-5rfj-4v26-hqmw/GHSA-5rfj-4v26-hqmw.json new file mode 100644 index 00000000000..77306390b87 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-5rfj-4v26-hqmw/GHSA-5rfj-4v26-hqmw.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5rfj-4v26-hqmw", + "modified": "2024-02-05T15:30:23Z", + "published": "2024-02-05T15:30:23Z", + "aliases": [ + "CVE-2024-1225" + ], + "details": "A vulnerability classified as critical was found in QiboSoft QiboCMS X1 up to 1.0.6. Affected by this vulnerability is the function rmb_pay of the file /application/index/controller/Pay.php. The manipulation of the argument callback_class leads to deserialization. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-252847. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1225" + }, + { + "type": "WEB", + "url": "https://note.zhaoj.in/share/jDWk6INLzO12" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.252847" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.252847" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-05T13:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-chj3-8q43-rcc8/GHSA-chj3-8q43-rcc8.json b/advisories/unreviewed/2024/02/GHSA-chj3-8q43-rcc8/GHSA-chj3-8q43-rcc8.json new file mode 100644 index 00000000000..d4f84b3b420 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-chj3-8q43-rcc8/GHSA-chj3-8q43-rcc8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-chj3-8q43-rcc8", + "modified": "2024-02-05T15:30:23Z", + "published": "2024-02-05T15:30:23Z", + "aliases": [ + "CVE-2024-23108" + ], + "details": "An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSIEM version 7.1.0 through 7.1.1 and 7.0.0 through 7.0.2 and 6.7.0 through 6.7.8 and 6.6.0 through 6.6.3 and 6.5.0 through 6.5.2 and 6.4.0 through 6.4.2 allows attacker to execute unauthorized code or commands via via crafted API requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23108" + }, + { + "type": "WEB", + "url": "https://fortiguard.com/psirt/FG-IR-23-130" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-05T14:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-v9vx-4mxw-76j2/GHSA-v9vx-4mxw-76j2.json b/advisories/unreviewed/2024/02/GHSA-v9vx-4mxw-76j2/GHSA-v9vx-4mxw-76j2.json new file mode 100644 index 00000000000..5e257020e36 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-v9vx-4mxw-76j2/GHSA-v9vx-4mxw-76j2.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v9vx-4mxw-76j2", + "modified": "2024-02-05T15:30:23Z", + "published": "2024-02-05T15:30:23Z", + "aliases": [ + "CVE-2023-7216" + ], + "details": "A path traversal vulnerability was found in the CPIO utility. This issue could allow a remote unauthenticated attacker to trick a user into opening a specially crafted archive. During the extraction process, the archiver could follow symlinks outside of the intended directory, which could be utilized to run arbitrary commands on the target system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-7216" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2023-7216" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2249901" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-05T15:15:08Z" + } +} \ No newline at end of file