Publish Advisories

GHSA-x58f-9h5m-89hm
GHSA-xc7x-w33q-rvw9
GHSA-2h7x-469p-h96j
GHSA-4m8f-h33w-f64v
GHSA-4qf8-xmx7-vj5f
GHSA-664m-m8f4-chcx
GHSA-6c5q-fg3g-qhhv
GHSA-6rp7-x538-xh3v
GHSA-867h-hqc2-ccpf
GHSA-88v3-3636-vj82
GHSA-8jjx-px56-3jpp
GHSA-gfwf-x23p-xh3q
GHSA-hf8v-3vx8-mr3v
GHSA-jg4h-m674-ch4q
GHSA-mgm7-2wjc-6f9w
GHSA-q759-j7h3-76hj
GHSA-r8r9-qqg8-94h8
GHSA-v6rx-x9wm-hrjj
GHSA-wx98-pmv5-4pf5
This commit is contained in:
advisory-database[bot]
2024-12-06 00:33:05 +00:00
parent 5a1ad12208
commit 29f2c7a7ab
19 changed files with 579 additions and 2 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x58f-9h5m-89hm",
"modified": "2024-10-22T03:31:41Z",
"modified": "2024-12-06T00:31:46Z",
"published": "2024-10-22T03:31:41Z",
"aliases": [
"CVE-2024-9677"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xc7x-w33q-rvw9",
"modified": "2024-11-20T21:30:49Z",
"modified": "2024-12-06T00:31:46Z",
"published": "2024-11-20T18:32:17Z",
"aliases": [
"CVE-2018-9481"
@@ -19,6 +19,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9481"
},
{
"type": "WEB",
"url": "https://lists.apache.org/thread.html/rcb8bae0b289d71d18a3220be256c1dfcc4d9ab49d2d6e07d1eac7c9d@%3Cdev.trafficserver.apache.org%3E"
},
{
"type": "WEB",
"url": "https://source.android.com/security/bulletin/2018-09-01"
@@ -0,0 +1,41 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2h7x-469p-h96j",
"modified": "2024-12-06T00:31:47Z",
"published": "2024-12-06T00:31:47Z",
"aliases": [
"CVE-2024-37861"
],
"details": "Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a buffer overflow via the nav2_amcl process. This vulnerability is triggered via sending a crafted .yaml file.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37861"
},
{
"type": "WEB",
"url": "https://github.com/ros-navigation/navigation2/issues/4005"
},
{
"type": "WEB",
"url": "https://github.com/ros-navigation/navigation2/issues/4335"
},
{
"type": "WEB",
"url": "https://github.com/ros-navigation/navigation2/issues/4338"
},
{
"type": "WEB",
"url": "https://github.com/GoesM/ROS-CVE-CNVDs"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-05T23:15:05Z"
}
}
@@ -0,0 +1,37 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4m8f-h33w-f64v",
"modified": "2024-12-06T00:31:48Z",
"published": "2024-12-06T00:31:48Z",
"aliases": [
"CVE-2024-38920"
],
"details": "Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggerd via remotely sending a request for change the value of dynamic-parameter`/amcl max_beams` .",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38920"
},
{
"type": "WEB",
"url": "https://github.com/ros-navigation/navigation2/issues/4379"
},
{
"type": "WEB",
"url": "https://github.com/ros-navigation/navigation2/pull/4397"
},
{
"type": "WEB",
"url": "https://github.com/GoesM/ROS-CVE-CNVDs"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-05T23:15:06Z"
}
}
@@ -0,0 +1,37 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4qf8-xmx7-vj5f",
"modified": "2024-12-06T00:31:47Z",
"published": "2024-12-06T00:31:47Z",
"aliases": [
"CVE-2024-30961"
],
"details": "Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2- ROS2-humble and navigation 2-humble allows a local attacker to execute arbitrary code via the error-thrown mechanism in nav2_bt_navigator.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30961"
},
{
"type": "WEB",
"url": "https://github.com/ros-planning/navigation2/issues/4175"
},
{
"type": "WEB",
"url": "https://github.com/ros-planning/navigation2/pull/4180"
},
{
"type": "WEB",
"url": "https://github.com/GoesM/ROS-CVE-CNVDs"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-05T23:15:05Z"
}
}
@@ -0,0 +1,29 @@
{
"schema_version": "1.4.0",
"id": "GHSA-664m-m8f4-chcx",
"modified": "2024-12-06T00:31:47Z",
"published": "2024-12-06T00:31:47Z",
"aliases": [
"CVE-2018-9390"
],
"details": "In procfile_write of gl_proc.c, there is a possible out of bounds read of a\n function pointer due to an incorrect bounds check. This could lead to local\n escalation of privilege with System execution privileges needed. User\n interaction is not needed for exploitation.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9390"
},
{
"type": "WEB",
"url": "https://source.android.com/security/bulletin/pixel/2018-06-01"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-05T23:15:04Z"
}
}
@@ -0,0 +1,29 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6c5q-fg3g-qhhv",
"modified": "2024-12-06T00:31:46Z",
"published": "2024-12-06T00:31:46Z",
"aliases": [
"CVE-2024-53457"
],
"details": "A stored cross-site scripting (XSS) vulnerability in the Device Settings section of LibreNMS v24.9.0 to v24.10.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Display Name parameter.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53457"
},
{
"type": "WEB",
"url": "https://github.com/tCu0n9/Stored-XSS-LibreNMS-Display-Name.git"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-05T22:15:20Z"
}
}
@@ -0,0 +1,29 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6rp7-x538-xh3v",
"modified": "2024-12-06T00:31:46Z",
"published": "2024-12-06T00:31:46Z",
"aliases": [
"CVE-2018-9388"
],
"details": "In store_upgrade and store_cmd of drivers/input/touchscreen/stm/ftm4_pdc.c, there are out of bound writes due to missing bounds checks or integer underflows. These could lead to escalation of privilege.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9388"
},
{
"type": "WEB",
"url": "https://source.android.com/security/bulletin/pixel/2018-06-01"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-05T23:15:04Z"
}
}
@@ -0,0 +1,37 @@
{
"schema_version": "1.4.0",
"id": "GHSA-867h-hqc2-ccpf",
"modified": "2024-12-06T00:31:48Z",
"published": "2024-12-06T00:31:48Z",
"aliases": [
"CVE-2024-37862"
],
"details": "Buffer Overflow vulnerability in Open Robotic Robotic Operating System 2 ROS2 navigation2- ROS2-humble&& navigation2-humble allows a local attacker to execute arbitrary code via a crafted .yaml file to the nav2_planner process.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37862"
},
{
"type": "WEB",
"url": "https://github.com/ros-navigation/navigation2/issues/4005"
},
{
"type": "WEB",
"url": "https://github.com/ros-navigation/navigation2/issues/4062"
},
{
"type": "WEB",
"url": "https://github.com/GoesM/ROS-CVE-CNVDs"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-05T23:15:05Z"
}
}
@@ -0,0 +1,41 @@
{
"schema_version": "1.4.0",
"id": "GHSA-88v3-3636-vj82",
"modified": "2024-12-06T00:31:47Z",
"published": "2024-12-06T00:31:47Z",
"aliases": [
"CVE-2024-37860"
],
"details": "Buffer Overflow vulnerability in Open Robotic Operating System 2 ROS2 navigation2- ROS2-humble&& navigation2-humble allows a local attacker to execute arbitrary code via a crafted .yaml file to the nav2_amcl process",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37860"
},
{
"type": "WEB",
"url": "https://github.com/ros-navigation/navigation2/issues/4005"
},
{
"type": "WEB",
"url": "https://github.com/ros-navigation/navigation2/issues/4336"
},
{
"type": "WEB",
"url": "https://github.com/ros-navigation/navigation2/issues/4339"
},
{
"type": "WEB",
"url": "https://github.com/GoesM/ROS-CVE-CNVDs"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-05T23:15:05Z"
}
}
@@ -0,0 +1,29 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8jjx-px56-3jpp",
"modified": "2024-12-06T00:31:46Z",
"published": "2024-12-06T00:31:46Z",
"aliases": [
"CVE-2018-9386"
],
"details": "In reboot_block_command of htc reboot_block driver, there is a possible\n stack buffer overflow due to a missing bounds check. This could lead to\n local escalation of privilege with System execution privileges needed. User\n interaction is not needed for exploitation.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9386"
},
{
"type": "WEB",
"url": "https://source.android.com/security/bulletin/pixel/2018-06-01"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-05T23:15:04Z"
}
}
@@ -0,0 +1,37 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gfwf-x23p-xh3q",
"modified": "2024-12-06T00:31:47Z",
"published": "2024-12-06T00:31:47Z",
"aliases": [
"CVE-2024-30962"
],
"details": "Buffer Overflow vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2- ROS2-humble and navigation 2-humble allows a local attacker to execute arbitrary code via the nav2_amcl process",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30962"
},
{
"type": "WEB",
"url": "https://github.com/ros-planning/navigation2/issues/4177"
},
{
"type": "WEB",
"url": "https://github.com/ros-planning/navigation2/pull/4206"
},
{
"type": "WEB",
"url": "https://github.com/GoesM/ROS-CVE-CNVDs"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-05T23:15:05Z"
}
}
@@ -0,0 +1,33 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hf8v-3vx8-mr3v",
"modified": "2024-12-06T00:31:47Z",
"published": "2024-12-06T00:31:47Z",
"aliases": [
"CVE-2024-30963"
],
"details": "Buffer Overflow vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2- ROS2-humble and navigation 2-humble allows a local attacker to execute arbitrary code via a crafted script.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30963"
},
{
"type": "WEB",
"url": "https://github.com/ros-planning/navigation2/issues/4157"
},
{
"type": "WEB",
"url": "https://github.com/GoesM/ROS-CVE-CNVDs"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-05T23:15:05Z"
}
}
@@ -0,0 +1,37 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jg4h-m674-ch4q",
"modified": "2024-12-06T00:31:48Z",
"published": "2024-12-06T00:31:48Z",
"aliases": [
"CVE-2024-37863"
],
"details": "Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a buffer overflow via the nav2_amcl process. This vulnerability is triggered via sending a crafted .yaml file.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37863"
},
{
"type": "WEB",
"url": "https://github.com/ros-navigation/navigation2/issues/4005"
},
{
"type": "WEB",
"url": "https://github.com/ros-navigation/navigation2/issues/4337"
},
{
"type": "WEB",
"url": "https://github.com/GoesM/ROS-CVE-CNVDs"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-05T23:15:05Z"
}
}
@@ -0,0 +1,25 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mgm7-2wjc-6f9w",
"modified": "2024-12-06T00:31:46Z",
"published": "2024-12-06T00:31:46Z",
"aliases": [
"CVE-2021-0937"
],
"details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2021-0937"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-05T22:15:19Z"
}
}
@@ -0,0 +1,29 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q759-j7h3-76hj",
"modified": "2024-12-06T00:31:47Z",
"published": "2024-12-06T00:31:47Z",
"aliases": [
"CVE-2018-9391"
],
"details": "In update_gps_sv and output_vzw_debug of\n vendor/mediatek/proprietary/hardware/connectivity/gps/gps_hal/src/gpshal_wor\n ker.c, there is a possible out of bounds write due to a missing bounds\n check. This could lead to local escalation of privilege with System\n execution privileges needed. User interaction is not needed for\n exploitation.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9391"
},
{
"type": "WEB",
"url": "https://source.android.com/security/bulletin/pixel/2018-06-01"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-05T23:15:04Z"
}
}
@@ -0,0 +1,29 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r8r9-qqg8-94h8",
"modified": "2024-12-06T00:31:46Z",
"published": "2024-12-06T00:31:46Z",
"aliases": [
"CVE-2017-13308"
],
"details": "In tscpu_write_GPIO_out and mtkts_Abts_write of mtk_ts_Abts.c, there is a possible buffer overflow in an sscanf due to improper input validation. This could lead to a local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2017-13308"
},
{
"type": "WEB",
"url": "https://source.android.com/security/bulletin/pixel/2018-06-01"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-05T22:15:18Z"
}
}
@@ -0,0 +1,37 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v6rx-x9wm-hrjj",
"modified": "2024-12-06T00:31:47Z",
"published": "2024-12-06T00:31:47Z",
"aliases": [
"CVE-2024-30964"
],
"details": "Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2- ROS2-humble and navigation 2-humble allows a local attacker to execute arbitrary code via the initial_pose_sub thread created by nav2_bt_navigator",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30964"
},
{
"type": "WEB",
"url": "https://github.com/ros-planning/navigation2/issues/4166"
},
{
"type": "WEB",
"url": "https://github.com/ros-planning/navigation2/pull/4176"
},
{
"type": "WEB",
"url": "https://github.com/GoesM/ROS-CVE-CNVDs"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-05T23:15:05Z"
}
}
@@ -0,0 +1,37 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wx98-pmv5-4pf5",
"modified": "2024-12-06T00:31:48Z",
"published": "2024-12-06T00:31:48Z",
"aliases": [
"CVE-2024-38910"
],
"details": "Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble version was discovered to contain a use-after-free in the nav2_amcl process. This vulnerability is triggered via sending a request to change dynamic parameters.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38910"
},
{
"type": "WEB",
"url": "https://github.com/ros-navigation/navigation2/issues/4379"
},
{
"type": "WEB",
"url": "https://github.com/ros-navigation/navigation2/pull/4397"
},
{
"type": "WEB",
"url": "https://github.com/GoesM/ROS-CVE-CNVDs"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-05T23:15:06Z"
}
}