diff --git a/advisories/unreviewed/2022/04/GHSA-65pf-462r-g52c/GHSA-65pf-462r-g52c.json b/advisories/unreviewed/2022/04/GHSA-65pf-462r-g52c/GHSA-65pf-462r-g52c.json index 26298533de2..50f388f551b 100644 --- a/advisories/unreviewed/2022/04/GHSA-65pf-462r-g52c/GHSA-65pf-462r-g52c.json +++ b/advisories/unreviewed/2022/04/GHSA-65pf-462r-g52c/GHSA-65pf-462r-g52c.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-125" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-hcpv-8j4p-29jp/GHSA-hcpv-8j4p-29jp.json b/advisories/unreviewed/2022/05/GHSA-hcpv-8j4p-29jp/GHSA-hcpv-8j4p-29jp.json index d6d72b11f17..b5ebb11470e 100644 --- a/advisories/unreviewed/2022/05/GHSA-hcpv-8j4p-29jp/GHSA-hcpv-8j4p-29jp.json +++ b/advisories/unreviewed/2022/05/GHSA-hcpv-8j4p-29jp/GHSA-hcpv-8j4p-29jp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hcpv-8j4p-29jp", - "modified": "2024-03-21T03:33:11Z", + "modified": "2024-10-29T18:30:32Z", "published": "2022-05-17T04:14:52Z", "aliases": [ "CVE-2014-9426" ], "details": "** DISPUTED ** The apprentice_load function in libmagic/apprentice.c in the Fileinfo component in PHP through 5.6.4 attempts to perform a free operation on a stack-based character array, which allows remote attackers to cause a denial of service (memory corruption or application crash) or possibly have unspecified other impact via unknown vectors. NOTE: this is disputed by the vendor because the standard erealloc behavior makes the free operation unreachable.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-hxwc-4mmq-5hhj/GHSA-hxwc-4mmq-5hhj.json b/advisories/unreviewed/2022/05/GHSA-hxwc-4mmq-5hhj/GHSA-hxwc-4mmq-5hhj.json index 924c38144c5..efae57180ea 100644 --- a/advisories/unreviewed/2022/05/GHSA-hxwc-4mmq-5hhj/GHSA-hxwc-4mmq-5hhj.json +++ b/advisories/unreviewed/2022/05/GHSA-hxwc-4mmq-5hhj/GHSA-hxwc-4mmq-5hhj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hxwc-4mmq-5hhj", - "modified": "2024-03-21T03:33:11Z", + "modified": "2024-10-29T18:30:32Z", "published": "2022-05-17T01:30:04Z", "aliases": [ "CVE-2013-7030" ], "details": "** DISPUTED ** The TFTP service in Cisco Unified Communications Manager (aka CUCM or Unified CM) allows remote attackers to obtain sensitive information from a phone via an RRQ operation, as demonstrated by discovering a cleartext UseUserCredential field in an SPDefault.cnf.xml file. NOTE: the vendor reportedly disputes the significance of this report, stating that this is an expected default behavior, and that the product's documentation describes use of the TFTP Encrypted Config option in addressing this issue.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/08/GHSA-mx26-3rqj-88q7/GHSA-mx26-3rqj-88q7.json b/advisories/unreviewed/2022/08/GHSA-mx26-3rqj-88q7/GHSA-mx26-3rqj-88q7.json index 6c65310b44a..49a4e6b8f4a 100644 --- a/advisories/unreviewed/2022/08/GHSA-mx26-3rqj-88q7/GHSA-mx26-3rqj-88q7.json +++ b/advisories/unreviewed/2022/08/GHSA-mx26-3rqj-88q7/GHSA-mx26-3rqj-88q7.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-732", "CWE-863" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/09/GHSA-c43m-486j-j32p/GHSA-c43m-486j-j32p.json b/advisories/unreviewed/2022/09/GHSA-c43m-486j-j32p/GHSA-c43m-486j-j32p.json index 22af5fcf042..bc8c346cf04 100644 --- a/advisories/unreviewed/2022/09/GHSA-c43m-486j-j32p/GHSA-c43m-486j-j32p.json +++ b/advisories/unreviewed/2022/09/GHSA-c43m-486j-j32p/GHSA-c43m-486j-j32p.json @@ -84,6 +84,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-1284", "CWE-20" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/11/GHSA-h3fq-ggc9-j2q9/GHSA-h3fq-ggc9-j2q9.json b/advisories/unreviewed/2022/11/GHSA-h3fq-ggc9-j2q9/GHSA-h3fq-ggc9-j2q9.json index 9bda1aeab2d..67850ba8c80 100644 --- a/advisories/unreviewed/2022/11/GHSA-h3fq-ggc9-j2q9/GHSA-h3fq-ggc9-j2q9.json +++ b/advisories/unreviewed/2022/11/GHSA-h3fq-ggc9-j2q9/GHSA-h3fq-ggc9-j2q9.json @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/01/GHSA-wv48-pvf9-qv86/GHSA-wv48-pvf9-qv86.json b/advisories/unreviewed/2023/01/GHSA-wv48-pvf9-qv86/GHSA-wv48-pvf9-qv86.json index d3a957cf35a..d077faa41f6 100644 --- a/advisories/unreviewed/2023/01/GHSA-wv48-pvf9-qv86/GHSA-wv48-pvf9-qv86.json +++ b/advisories/unreviewed/2023/01/GHSA-wv48-pvf9-qv86/GHSA-wv48-pvf9-qv86.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-203", "CWE-668" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2023/07/GHSA-22r3-hxrp-33gc/GHSA-22r3-hxrp-33gc.json b/advisories/unreviewed/2023/07/GHSA-22r3-hxrp-33gc/GHSA-22r3-hxrp-33gc.json index 146049f8d38..92fae513059 100644 --- a/advisories/unreviewed/2023/07/GHSA-22r3-hxrp-33gc/GHSA-22r3-hxrp-33gc.json +++ b/advisories/unreviewed/2023/07/GHSA-22r3-hxrp-33gc/GHSA-22r3-hxrp-33gc.json @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-522" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/07/GHSA-jfwr-hq92-w8gg/GHSA-jfwr-hq92-w8gg.json b/advisories/unreviewed/2023/07/GHSA-jfwr-hq92-w8gg/GHSA-jfwr-hq92-w8gg.json index 88c13d063d9..393c9809798 100644 --- a/advisories/unreviewed/2023/07/GHSA-jfwr-hq92-w8gg/GHSA-jfwr-hq92-w8gg.json +++ b/advisories/unreviewed/2023/07/GHSA-jfwr-hq92-w8gg/GHSA-jfwr-hq92-w8gg.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-120", "CWE-787" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2023/07/GHSA-xc42-985m-4jpv/GHSA-xc42-985m-4jpv.json b/advisories/unreviewed/2023/07/GHSA-xc42-985m-4jpv/GHSA-xc42-985m-4jpv.json index 5e6ec42aaeb..a1c2c0b297f 100644 --- a/advisories/unreviewed/2023/07/GHSA-xc42-985m-4jpv/GHSA-xc42-985m-4jpv.json +++ b/advisories/unreviewed/2023/07/GHSA-xc42-985m-4jpv/GHSA-xc42-985m-4jpv.json @@ -40,7 +40,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-346" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/12/GHSA-rjjc-gg9m-vhv8/GHSA-rjjc-gg9m-vhv8.json b/advisories/unreviewed/2023/12/GHSA-rjjc-gg9m-vhv8/GHSA-rjjc-gg9m-vhv8.json index a48508a8df7..5e3c9690717 100644 --- a/advisories/unreviewed/2023/12/GHSA-rjjc-gg9m-vhv8/GHSA-rjjc-gg9m-vhv8.json +++ b/advisories/unreviewed/2023/12/GHSA-rjjc-gg9m-vhv8/GHSA-rjjc-gg9m-vhv8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rjjc-gg9m-vhv8", - "modified": "2024-01-04T21:30:22Z", + "modified": "2024-10-29T18:30:33Z", "published": "2023-12-21T15:30:33Z", "aliases": [ "CVE-2023-7047" @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-3p53-237x-3cww/GHSA-3p53-237x-3cww.json b/advisories/unreviewed/2024/03/GHSA-3p53-237x-3cww/GHSA-3p53-237x-3cww.json index 703c270bbe6..c3c08607575 100644 --- a/advisories/unreviewed/2024/03/GHSA-3p53-237x-3cww/GHSA-3p53-237x-3cww.json +++ b/advisories/unreviewed/2024/03/GHSA-3p53-237x-3cww/GHSA-3p53-237x-3cww.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3p53-237x-3cww", - "modified": "2024-05-01T18:30:36Z", + "modified": "2024-10-29T18:30:34Z", "published": "2024-03-15T18:30:38Z", "aliases": [ "CVE-2024-2193" ], "details": "A Speculative Race Condition (SRC) vulnerability that impacts modern CPU architectures supporting speculative execution (related to Spectre V1) has been disclosed. An unauthenticated attacker can exploit this vulnerability to disclose arbitrary data from the CPU using race conditions to access the speculative executable code paths.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -69,9 +72,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-362" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-15T18:15:08Z" diff --git a/advisories/unreviewed/2024/03/GHSA-73f5-wqmw-37vp/GHSA-73f5-wqmw-37vp.json b/advisories/unreviewed/2024/03/GHSA-73f5-wqmw-37vp/GHSA-73f5-wqmw-37vp.json index 5c0b447d7fb..526efe3350d 100644 --- a/advisories/unreviewed/2024/03/GHSA-73f5-wqmw-37vp/GHSA-73f5-wqmw-37vp.json +++ b/advisories/unreviewed/2024/03/GHSA-73f5-wqmw-37vp/GHSA-73f5-wqmw-37vp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-73f5-wqmw-37vp", - "modified": "2024-06-27T12:30:43Z", + "modified": "2024-10-29T18:30:34Z", "published": "2024-03-03T00:30:30Z", "aliases": [ "CVE-2022-48627" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nvt: fix memory overlapping when deleting chars in the buffer\n\nA memory overlapping copy occurs when deleting a long line. This memory\noverlapping copy can cause data corruption when scr_memcpyw is optimized\nto memcpy because memcpy does not ensure its behavior if the destination\nbuffer overlaps with the source buffer. The line buffer is not always\nbroken, because the memcpy utilizes the hardware acceleration, whose\nresult is not deterministic.\n\nFix this problem by using replacing the scr_memcpyw with scr_memmovew.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -51,7 +54,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-02T22:15:46Z" diff --git a/advisories/unreviewed/2024/03/GHSA-97xx-95pm-5qv6/GHSA-97xx-95pm-5qv6.json b/advisories/unreviewed/2024/03/GHSA-97xx-95pm-5qv6/GHSA-97xx-95pm-5qv6.json index ec0c98ab8d8..76b6fe5bfca 100644 --- a/advisories/unreviewed/2024/03/GHSA-97xx-95pm-5qv6/GHSA-97xx-95pm-5qv6.json +++ b/advisories/unreviewed/2024/03/GHSA-97xx-95pm-5qv6/GHSA-97xx-95pm-5qv6.json @@ -76,7 +76,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-436" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-f3f2-9wgq-fw79/GHSA-f3f2-9wgq-fw79.json b/advisories/unreviewed/2024/03/GHSA-f3f2-9wgq-fw79/GHSA-f3f2-9wgq-fw79.json index 4deac234efe..86e544366cd 100644 --- a/advisories/unreviewed/2024/03/GHSA-f3f2-9wgq-fw79/GHSA-f3f2-9wgq-fw79.json +++ b/advisories/unreviewed/2024/03/GHSA-f3f2-9wgq-fw79/GHSA-f3f2-9wgq-fw79.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f3f2-9wgq-fw79", - "modified": "2024-03-05T18:31:13Z", + "modified": "2024-10-29T18:30:34Z", "published": "2024-03-05T18:31:13Z", "aliases": [ "CVE-2022-46088" ], "details": "Online Flight Booking Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the feedback form.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-05T16:15:49Z" diff --git a/advisories/unreviewed/2024/04/GHSA-j8m8-8v3g-v4jq/GHSA-j8m8-8v3g-v4jq.json b/advisories/unreviewed/2024/04/GHSA-j8m8-8v3g-v4jq/GHSA-j8m8-8v3g-v4jq.json index 9778bd83a40..46ca2961b65 100644 --- a/advisories/unreviewed/2024/04/GHSA-j8m8-8v3g-v4jq/GHSA-j8m8-8v3g-v4jq.json +++ b/advisories/unreviewed/2024/04/GHSA-j8m8-8v3g-v4jq/GHSA-j8m8-8v3g-v4jq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j8m8-8v3g-v4jq", - "modified": "2024-04-12T09:33:40Z", + "modified": "2024-10-29T18:30:34Z", "published": "2024-04-12T09:33:40Z", "aliases": [ "CVE-2024-22526" ], "details": "Buffer Overflow vulnerability in bandisoft bandiview v7.0, allows local attackers to cause a denial of service (DoS) via exr image file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-12T07:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-m5xj-5946-r5xw/GHSA-m5xj-5946-r5xw.json b/advisories/unreviewed/2024/04/GHSA-m5xj-5946-r5xw/GHSA-m5xj-5946-r5xw.json index b7381ee7f67..b67137eb03d 100644 --- a/advisories/unreviewed/2024/04/GHSA-m5xj-5946-r5xw/GHSA-m5xj-5946-r5xw.json +++ b/advisories/unreviewed/2024/04/GHSA-m5xj-5946-r5xw/GHSA-m5xj-5946-r5xw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m5xj-5946-r5xw", - "modified": "2024-04-24T06:30:31Z", + "modified": "2024-10-29T18:30:34Z", "published": "2024-04-24T06:30:31Z", "aliases": [ "CVE-2024-2402" ], "details": "The Better Comments WordPress plugin before 1.5.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-24T05:15:47Z" diff --git a/advisories/unreviewed/2024/04/GHSA-mxvm-x858-3gm2/GHSA-mxvm-x858-3gm2.json b/advisories/unreviewed/2024/04/GHSA-mxvm-x858-3gm2/GHSA-mxvm-x858-3gm2.json index 2e4ba6978cb..adfc0902ed1 100644 --- a/advisories/unreviewed/2024/04/GHSA-mxvm-x858-3gm2/GHSA-mxvm-x858-3gm2.json +++ b/advisories/unreviewed/2024/04/GHSA-mxvm-x858-3gm2/GHSA-mxvm-x858-3gm2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mxvm-x858-3gm2", - "modified": "2024-04-28T15:30:29Z", + "modified": "2024-10-29T18:30:34Z", "published": "2024-04-28T15:30:29Z", "aliases": [ "CVE-2022-48636" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ns390/dasd: fix Oops in dasd_alias_get_start_dev due to missing pavgroup\n\nFix Oops in dasd_alias_get_start_dev() function caused by the pavgroup\npointer being NULL.\n\nThe pavgroup pointer is checked on the entrance of the function but\nwithout the lcu->lock being held. Therefore there is a race window\nbetween dasd_alias_get_start_dev() and _lcu_update() which sets\npavgroup to NULL with the lcu->lock held.\n\nFix by checking the pavgroup pointer with lcu->lock held.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-28T13:15:06Z" diff --git a/advisories/unreviewed/2024/04/GHSA-xrxq-p636-j73q/GHSA-xrxq-p636-j73q.json b/advisories/unreviewed/2024/04/GHSA-xrxq-p636-j73q/GHSA-xrxq-p636-j73q.json index b6a0e7dc545..96c6e2bdcdf 100644 --- a/advisories/unreviewed/2024/04/GHSA-xrxq-p636-j73q/GHSA-xrxq-p636-j73q.json +++ b/advisories/unreviewed/2024/04/GHSA-xrxq-p636-j73q/GHSA-xrxq-p636-j73q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xrxq-p636-j73q", - "modified": "2024-04-28T15:30:29Z", + "modified": "2024-10-29T18:30:34Z", "published": "2024-04-28T15:30:29Z", "aliases": [ "CVE-2022-48650" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: qla2xxx: Fix memory leak in __qlt_24xx_handle_abts()\n\nCommit 8f394da36a36 (\"scsi: qla2xxx: Drop TARGET_SCF_LOOKUP_LUN_FROM_TAG\")\nmade the __qlt_24xx_handle_abts() function return early if\ntcm_qla2xxx_find_cmd_by_tag() didn't find a command, but it missed to clean\nup the allocated memory for the management command.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-28T13:15:07Z" diff --git a/advisories/unreviewed/2024/05/GHSA-4vrv-4wc3-4q25/GHSA-4vrv-4wc3-4q25.json b/advisories/unreviewed/2024/05/GHSA-4vrv-4wc3-4q25/GHSA-4vrv-4wc3-4q25.json index d9339b4c4be..3c2f1af040a 100644 --- a/advisories/unreviewed/2024/05/GHSA-4vrv-4wc3-4q25/GHSA-4vrv-4wc3-4q25.json +++ b/advisories/unreviewed/2024/05/GHSA-4vrv-4wc3-4q25/GHSA-4vrv-4wc3-4q25.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-276", "CWE-284" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/05/GHSA-6gvx-hwp2-7mfq/GHSA-6gvx-hwp2-7mfq.json b/advisories/unreviewed/2024/05/GHSA-6gvx-hwp2-7mfq/GHSA-6gvx-hwp2-7mfq.json index eaaa153ce88..11591cdb876 100644 --- a/advisories/unreviewed/2024/05/GHSA-6gvx-hwp2-7mfq/GHSA-6gvx-hwp2-7mfq.json +++ b/advisories/unreviewed/2024/05/GHSA-6gvx-hwp2-7mfq/GHSA-6gvx-hwp2-7mfq.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-125" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-7jgq-6qw7-j88f/GHSA-7jgq-6qw7-j88f.json b/advisories/unreviewed/2024/05/GHSA-7jgq-6qw7-j88f/GHSA-7jgq-6qw7-j88f.json index f0cc7ac3678..fd82a005d20 100644 --- a/advisories/unreviewed/2024/05/GHSA-7jgq-6qw7-j88f/GHSA-7jgq-6qw7-j88f.json +++ b/advisories/unreviewed/2024/05/GHSA-7jgq-6qw7-j88f/GHSA-7jgq-6qw7-j88f.json @@ -40,7 +40,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-288" + "CWE-288", + "CWE-306" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-7pxj-w55v-hwp4/GHSA-7pxj-w55v-hwp4.json b/advisories/unreviewed/2024/05/GHSA-7pxj-w55v-hwp4/GHSA-7pxj-w55v-hwp4.json index b0b24dcbf23..a480f57bdbe 100644 --- a/advisories/unreviewed/2024/05/GHSA-7pxj-w55v-hwp4/GHSA-7pxj-w55v-hwp4.json +++ b/advisories/unreviewed/2024/05/GHSA-7pxj-w55v-hwp4/GHSA-7pxj-w55v-hwp4.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-763", "CWE-822" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/05/GHSA-7q29-7r79-pg2f/GHSA-7q29-7r79-pg2f.json b/advisories/unreviewed/2024/05/GHSA-7q29-7r79-pg2f/GHSA-7q29-7r79-pg2f.json index 962a808b7ad..744c40a5cad 100644 --- a/advisories/unreviewed/2024/05/GHSA-7q29-7r79-pg2f/GHSA-7q29-7r79-pg2f.json +++ b/advisories/unreviewed/2024/05/GHSA-7q29-7r79-pg2f/GHSA-7q29-7r79-pg2f.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-125" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-c3rm-r6pr-rg5j/GHSA-c3rm-r6pr-rg5j.json b/advisories/unreviewed/2024/05/GHSA-c3rm-r6pr-rg5j/GHSA-c3rm-r6pr-rg5j.json index 5ed2e635db7..42640426329 100644 --- a/advisories/unreviewed/2024/05/GHSA-c3rm-r6pr-rg5j/GHSA-c3rm-r6pr-rg5j.json +++ b/advisories/unreviewed/2024/05/GHSA-c3rm-r6pr-rg5j/GHSA-c3rm-r6pr-rg5j.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-125" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-cpx5-6mwc-hxp6/GHSA-cpx5-6mwc-hxp6.json b/advisories/unreviewed/2024/05/GHSA-cpx5-6mwc-hxp6/GHSA-cpx5-6mwc-hxp6.json index 7320923292a..98efac5281c 100644 --- a/advisories/unreviewed/2024/05/GHSA-cpx5-6mwc-hxp6/GHSA-cpx5-6mwc-hxp6.json +++ b/advisories/unreviewed/2024/05/GHSA-cpx5-6mwc-hxp6/GHSA-cpx5-6mwc-hxp6.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-m3x3-867j-f35f/GHSA-m3x3-867j-f35f.json b/advisories/unreviewed/2024/05/GHSA-m3x3-867j-f35f/GHSA-m3x3-867j-f35f.json index 5e9eac60f08..969e39b5119 100644 --- a/advisories/unreviewed/2024/05/GHSA-m3x3-867j-f35f/GHSA-m3x3-867j-f35f.json +++ b/advisories/unreviewed/2024/05/GHSA-m3x3-867j-f35f/GHSA-m3x3-867j-f35f.json @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-203" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-p98r-qmj8-g8hj/GHSA-p98r-qmj8-g8hj.json b/advisories/unreviewed/2024/05/GHSA-p98r-qmj8-g8hj/GHSA-p98r-qmj8-g8hj.json index e8ad0cd8c52..6dee078b0af 100644 --- a/advisories/unreviewed/2024/05/GHSA-p98r-qmj8-g8hj/GHSA-p98r-qmj8-g8hj.json +++ b/advisories/unreviewed/2024/05/GHSA-p98r-qmj8-g8hj/GHSA-p98r-qmj8-g8hj.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-125" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-wx4f-9wf4-26p4/GHSA-wx4f-9wf4-26p4.json b/advisories/unreviewed/2024/05/GHSA-wx4f-9wf4-26p4/GHSA-wx4f-9wf4-26p4.json index 60b336bb0df..78336b1a583 100644 --- a/advisories/unreviewed/2024/05/GHSA-wx4f-9wf4-26p4/GHSA-wx4f-9wf4-26p4.json +++ b/advisories/unreviewed/2024/05/GHSA-wx4f-9wf4-26p4/GHSA-wx4f-9wf4-26p4.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-26ch-39wc-5m9p/GHSA-26ch-39wc-5m9p.json b/advisories/unreviewed/2024/06/GHSA-26ch-39wc-5m9p/GHSA-26ch-39wc-5m9p.json index 68c4ec15fe4..b4a3cdada31 100644 --- a/advisories/unreviewed/2024/06/GHSA-26ch-39wc-5m9p/GHSA-26ch-39wc-5m9p.json +++ b/advisories/unreviewed/2024/06/GHSA-26ch-39wc-5m9p/GHSA-26ch-39wc-5m9p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-26ch-39wc-5m9p", - "modified": "2024-06-07T00:30:37Z", + "modified": "2024-10-29T18:30:34Z", "published": "2024-06-07T00:30:36Z", "aliases": [ "CVE-2024-24192" ], "details": "robdns commit d76d2e6 was discovered to contain a heap overflow via the component block->filename at /src/zonefile-insertion.c.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-06T22:15:10Z" diff --git a/advisories/unreviewed/2024/06/GHSA-3q9p-8qv6-vmjm/GHSA-3q9p-8qv6-vmjm.json b/advisories/unreviewed/2024/06/GHSA-3q9p-8qv6-vmjm/GHSA-3q9p-8qv6-vmjm.json index 6d2b0837658..24b10bfd42f 100644 --- a/advisories/unreviewed/2024/06/GHSA-3q9p-8qv6-vmjm/GHSA-3q9p-8qv6-vmjm.json +++ b/advisories/unreviewed/2024/06/GHSA-3q9p-8qv6-vmjm/GHSA-3q9p-8qv6-vmjm.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-8jg8-869p-gv73/GHSA-8jg8-869p-gv73.json b/advisories/unreviewed/2024/06/GHSA-8jg8-869p-gv73/GHSA-8jg8-869p-gv73.json index 749072aaa2a..dedf72db12b 100644 --- a/advisories/unreviewed/2024/06/GHSA-8jg8-869p-gv73/GHSA-8jg8-869p-gv73.json +++ b/advisories/unreviewed/2024/06/GHSA-8jg8-869p-gv73/GHSA-8jg8-869p-gv73.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8jg8-869p-gv73", - "modified": "2024-06-07T06:30:30Z", + "modified": "2024-10-29T18:30:34Z", "published": "2024-06-07T06:30:30Z", "aliases": [ "CVE-2024-3288" ], "details": "The Logo Slider WordPress plugin before 4.0.0 does not validate and escape some of its Slider Settings before outputting them back in attributes, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-07T06:15:10Z" diff --git a/advisories/unreviewed/2024/06/GHSA-8w8q-fcp2-6wqf/GHSA-8w8q-fcp2-6wqf.json b/advisories/unreviewed/2024/06/GHSA-8w8q-fcp2-6wqf/GHSA-8w8q-fcp2-6wqf.json index 55667614035..9002abecd91 100644 --- a/advisories/unreviewed/2024/06/GHSA-8w8q-fcp2-6wqf/GHSA-8w8q-fcp2-6wqf.json +++ b/advisories/unreviewed/2024/06/GHSA-8w8q-fcp2-6wqf/GHSA-8w8q-fcp2-6wqf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8w8q-fcp2-6wqf", - "modified": "2024-06-07T06:30:29Z", + "modified": "2024-10-29T18:30:34Z", "published": "2024-06-07T06:30:29Z", "aliases": [ "CVE-2024-4902" @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-qm74-8w86-q753/GHSA-qm74-8w86-q753.json b/advisories/unreviewed/2024/06/GHSA-qm74-8w86-q753/GHSA-qm74-8w86-q753.json index 73b7c500c87..50ad7f9b047 100644 --- a/advisories/unreviewed/2024/06/GHSA-qm74-8w86-q753/GHSA-qm74-8w86-q753.json +++ b/advisories/unreviewed/2024/06/GHSA-qm74-8w86-q753/GHSA-qm74-8w86-q753.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qm74-8w86-q753", - "modified": "2024-06-07T00:30:37Z", + "modified": "2024-10-29T18:30:34Z", "published": "2024-06-07T00:30:37Z", "aliases": [ "CVE-2024-24195" ], "details": "robdns commit d76d2e6 was discovered to contain a misaligned address at /src/zonefile-insertion.c.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-06T22:15:10Z" diff --git a/advisories/unreviewed/2024/06/GHSA-wr9r-v3gv-6cj3/GHSA-wr9r-v3gv-6cj3.json b/advisories/unreviewed/2024/06/GHSA-wr9r-v3gv-6cj3/GHSA-wr9r-v3gv-6cj3.json index 957422c737c..efd1bd49bdb 100644 --- a/advisories/unreviewed/2024/06/GHSA-wr9r-v3gv-6cj3/GHSA-wr9r-v3gv-6cj3.json +++ b/advisories/unreviewed/2024/06/GHSA-wr9r-v3gv-6cj3/GHSA-wr9r-v3gv-6cj3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wr9r-v3gv-6cj3", - "modified": "2024-06-07T06:30:30Z", + "modified": "2024-10-29T18:30:34Z", "published": "2024-06-07T06:30:30Z", "aliases": [ "CVE-2024-5612" @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-82cg-8mxr-gw2q/GHSA-82cg-8mxr-gw2q.json b/advisories/unreviewed/2024/08/GHSA-82cg-8mxr-gw2q/GHSA-82cg-8mxr-gw2q.json index 0ea8f2f2736..37b6d7c5f2e 100644 --- a/advisories/unreviewed/2024/08/GHSA-82cg-8mxr-gw2q/GHSA-82cg-8mxr-gw2q.json +++ b/advisories/unreviewed/2024/08/GHSA-82cg-8mxr-gw2q/GHSA-82cg-8mxr-gw2q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-82cg-8mxr-gw2q", - "modified": "2024-08-19T06:30:54Z", + "modified": "2024-10-29T18:30:35Z", "published": "2024-08-17T12:30:32Z", "aliases": [ "CVE-2024-43841" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: virt_wifi: avoid reporting connection success with wrong SSID\n\nWhen user issues a connection with a different SSID than the one\nvirt_wifi has advertised, the __cfg80211_connect_result() will\ntrigger the warning: WARN_ON(bss_not_found).\n\nThe issue is because the connection code in virt_wifi does not\ncheck the SSID from user space (it only checks the BSSID), and\nvirt_wifi will call cfg80211_connect_result() with WLAN_STATUS_SUCCESS\neven if the SSID is different from the one virt_wifi has advertised.\nEventually cfg80211 won't be able to find the cfg80211_bss and generate\nthe warning.\n\nFixed it by checking the SSID (from user space) in the connection code.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -51,7 +54,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-17T10:15:09Z" diff --git a/advisories/unreviewed/2024/08/GHSA-c6m8-29qv-7wq9/GHSA-c6m8-29qv-7wq9.json b/advisories/unreviewed/2024/08/GHSA-c6m8-29qv-7wq9/GHSA-c6m8-29qv-7wq9.json index 0641677310d..6a43edf4aa0 100644 --- a/advisories/unreviewed/2024/08/GHSA-c6m8-29qv-7wq9/GHSA-c6m8-29qv-7wq9.json +++ b/advisories/unreviewed/2024/08/GHSA-c6m8-29qv-7wq9/GHSA-c6m8-29qv-7wq9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c6m8-29qv-7wq9", - "modified": "2024-08-17T12:30:33Z", + "modified": "2024-10-29T18:30:35Z", "published": "2024-08-17T12:30:32Z", "aliases": [ "CVE-2024-43840" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf, arm64: Fix trampoline for BPF_TRAMP_F_CALL_ORIG\n\nWhen BPF_TRAMP_F_CALL_ORIG is set, the trampoline calls\n__bpf_tramp_enter() and __bpf_tramp_exit() functions, passing them\nthe struct bpf_tramp_image *im pointer as an argument in R0.\n\nThe trampoline generation code uses emit_addr_mov_i64() to emit\ninstructions for moving the bpf_tramp_image address into R0, but\nemit_addr_mov_i64() assumes the address to be in the vmalloc() space\nand uses only 48 bits. Because bpf_tramp_image is allocated using\nkzalloc(), its address can use more than 48-bits, in this case the\ntrampoline will pass an invalid address to __bpf_tramp_enter/exit()\ncausing a kernel crash.\n\nFix this by using emit_a64_mov_i64() in place of emit_addr_mov_i64()\nas it can work with addresses that are greater than 48-bits.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-17T10:15:09Z" diff --git a/advisories/unreviewed/2024/08/GHSA-hrq9-fvj6-g7g7/GHSA-hrq9-fvj6-g7g7.json b/advisories/unreviewed/2024/08/GHSA-hrq9-fvj6-g7g7/GHSA-hrq9-fvj6-g7g7.json index 902151c57a7..8b4fa6573af 100644 --- a/advisories/unreviewed/2024/08/GHSA-hrq9-fvj6-g7g7/GHSA-hrq9-fvj6-g7g7.json +++ b/advisories/unreviewed/2024/08/GHSA-hrq9-fvj6-g7g7/GHSA-hrq9-fvj6-g7g7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hrq9-fvj6-g7g7", - "modified": "2024-08-17T12:30:32Z", + "modified": "2024-10-29T18:30:35Z", "published": "2024-08-17T12:30:32Z", "aliases": [ "CVE-2024-43838" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: fix overflow check in adjust_jmp_off()\n\nadjust_jmp_off() incorrectly used the insn->imm field for all overflow check,\nwhich is incorrect as that should only be done or the BPF_JMP32 | BPF_JA case,\nnot the general jump instruction case. Fix it by using insn->off for overflow\ncheck in the general case.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-190" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-17T10:15:09Z" diff --git a/advisories/unreviewed/2024/08/GHSA-r657-mr7r-rf9x/GHSA-r657-mr7r-rf9x.json b/advisories/unreviewed/2024/08/GHSA-r657-mr7r-rf9x/GHSA-r657-mr7r-rf9x.json index 42483ae46fc..799b3c34afe 100644 --- a/advisories/unreviewed/2024/08/GHSA-r657-mr7r-rf9x/GHSA-r657-mr7r-rf9x.json +++ b/advisories/unreviewed/2024/08/GHSA-r657-mr7r-rf9x/GHSA-r657-mr7r-rf9x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r657-mr7r-rf9x", - "modified": "2024-08-17T12:30:33Z", + "modified": "2024-10-29T18:30:35Z", "published": "2024-08-17T12:30:33Z", "aliases": [ "CVE-2024-43843" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nriscv, bpf: Fix out-of-bounds issue when preparing trampoline image\n\nWe get the size of the trampoline image during the dry run phase and\nallocate memory based on that size. The allocated image will then be\npopulated with instructions during the real patch phase. But after\ncommit 26ef208c209a (\"bpf: Use arch_bpf_trampoline_size\"), the `im`\nargument is inconsistent in the dry run and real patch phase. This may\ncause emit_imm in RV64 to generate a different number of instructions\nwhen generating the 'im' address, potentially causing out-of-bounds\nissues. Let's emit the maximum number of instructions for the \"im\"\naddress during dry run to fix this problem.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-131" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-17T10:15:09Z" diff --git a/advisories/unreviewed/2024/09/GHSA-hjpg-cfqw-g6jv/GHSA-hjpg-cfqw-g6jv.json b/advisories/unreviewed/2024/09/GHSA-hjpg-cfqw-g6jv/GHSA-hjpg-cfqw-g6jv.json index 1dbac154f06..077c1ab2b08 100644 --- a/advisories/unreviewed/2024/09/GHSA-hjpg-cfqw-g6jv/GHSA-hjpg-cfqw-g6jv.json +++ b/advisories/unreviewed/2024/09/GHSA-hjpg-cfqw-g6jv/GHSA-hjpg-cfqw-g6jv.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-306" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-r95v-7x7v-phw8/GHSA-r95v-7x7v-phw8.json b/advisories/unreviewed/2024/09/GHSA-r95v-7x7v-phw8/GHSA-r95v-7x7v-phw8.json index b174334c458..797e4ef7ebc 100644 --- a/advisories/unreviewed/2024/09/GHSA-r95v-7x7v-phw8/GHSA-r95v-7x7v-phw8.json +++ b/advisories/unreviewed/2024/09/GHSA-r95v-7x7v-phw8/GHSA-r95v-7x7v-phw8.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-284" + "CWE-284", + "CWE-863" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-2298-pcfp-56j2/GHSA-2298-pcfp-56j2.json b/advisories/unreviewed/2024/10/GHSA-2298-pcfp-56j2/GHSA-2298-pcfp-56j2.json index daf4b9f60c2..93358247bca 100644 --- a/advisories/unreviewed/2024/10/GHSA-2298-pcfp-56j2/GHSA-2298-pcfp-56j2.json +++ b/advisories/unreviewed/2024/10/GHSA-2298-pcfp-56j2/GHSA-2298-pcfp-56j2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2298-pcfp-56j2", - "modified": "2024-10-28T21:30:34Z", + "modified": "2024-10-29T18:30:36Z", "published": "2024-10-28T21:30:34Z", "aliases": [ "CVE-2024-44123" ], "details": "A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15, iOS 18 and iPadOS 18. A malicious app with root privileges may be able to access keyboard input and location information without user consent.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-28T21:15:05Z" diff --git a/advisories/unreviewed/2024/10/GHSA-24gv-qfv8-v7f5/GHSA-24gv-qfv8-v7f5.json b/advisories/unreviewed/2024/10/GHSA-24gv-qfv8-v7f5/GHSA-24gv-qfv8-v7f5.json index 9d5f6612243..e317f1d10ba 100644 --- a/advisories/unreviewed/2024/10/GHSA-24gv-qfv8-v7f5/GHSA-24gv-qfv8-v7f5.json +++ b/advisories/unreviewed/2024/10/GHSA-24gv-qfv8-v7f5/GHSA-24gv-qfv8-v7f5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-24gv-qfv8-v7f5", - "modified": "2024-10-21T18:30:59Z", + "modified": "2024-10-29T18:30:35Z", "published": "2024-10-21T18:30:59Z", "aliases": [ "CVE-2024-49983" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\next4: drop ppath from ext4_ext_replay_update_ex() to avoid double-free\n\nWhen calling ext4_force_split_extent_at() in ext4_ext_replay_update_ex(),\nthe 'ppath' is updated but it is the 'path' that is freed, thus potentially\ntriggering a double-free in the following process:\n\next4_ext_replay_update_ex\n ppath = path\n ext4_force_split_extent_at(&ppath)\n ext4_split_extent_at\n ext4_ext_insert_extent\n ext4_ext_create_new_leaf\n ext4_ext_grow_indepth\n ext4_find_extent\n if (depth > path[0].p_maxdepth)\n kfree(path) ---> path First freed\n *orig_path = path = NULL ---> null ppath\n kfree(path) ---> path double-free !!!\n\nSo drop the unnecessary ppath and use path directly to avoid this problem.\nAnd use ext4_find_extent() directly to update path, avoiding unnecessary\nmemory allocation and freeing. Also, propagate the error returned by\next4_find_extent() instead of using strange error codes.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -49,9 +52,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-415" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T18:15:18Z" diff --git a/advisories/unreviewed/2024/10/GHSA-25m4-rhwx-m523/GHSA-25m4-rhwx-m523.json b/advisories/unreviewed/2024/10/GHSA-25m4-rhwx-m523/GHSA-25m4-rhwx-m523.json new file mode 100644 index 00000000000..377c647d3e3 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-25m4-rhwx-m523/GHSA-25m4-rhwx-m523.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-25m4-rhwx-m523", + "modified": "2024-10-29T18:30:37Z", + "published": "2024-10-29T18:30:37Z", + "aliases": [ + "CVE-2024-8924" + ], + "details": "ServiceNow has addressed a blind SQL injection vulnerability that was identified in the Now Platform. This vulnerability could enable an unauthenticated user to extract unauthorized information. ServiceNow deployed an update to hosted instances, and ServiceNow provided the update to our partners and self-hosted customers. Further, the vulnerability is addressed in the listed patches and hot fixes.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8924" + }, + { + "type": "WEB", + "url": "https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB1706072" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-29T17:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-28pg-93m7-9jmx/GHSA-28pg-93m7-9jmx.json b/advisories/unreviewed/2024/10/GHSA-28pg-93m7-9jmx/GHSA-28pg-93m7-9jmx.json index 17e28d4d529..971b9563ded 100644 --- a/advisories/unreviewed/2024/10/GHSA-28pg-93m7-9jmx/GHSA-28pg-93m7-9jmx.json +++ b/advisories/unreviewed/2024/10/GHSA-28pg-93m7-9jmx/GHSA-28pg-93m7-9jmx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-28pg-93m7-9jmx", - "modified": "2024-10-28T03:30:39Z", + "modified": "2024-10-29T18:30:35Z", "published": "2024-10-28T03:30:39Z", "aliases": [ "CVE-2024-50067" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nuprobe: avoid out-of-bounds memory access of fetching args\n\nUprobe needs to fetch args into a percpu buffer, and then copy to ring\nbuffer to avoid non-atomic context problem.\n\nSometimes user-space strings, arrays can be very large, but the size of\npercpu buffer is only page size. And store_trace_args() won't check\nwhether these data exceeds a single page or not, caused out-of-bounds\nmemory access.\n\nIt could be reproduced by following steps:\n1. build kernel with CONFIG_KASAN enabled\n2. save follow program as test.c\n\n```\n\\#include \n\\#include \n\\#include \n\n// If string length large than MAX_STRING_SIZE, the fetch_store_strlen()\n// will return 0, cause __get_data_size() return shorter size, and\n// store_trace_args() will not trigger out-of-bounds access.\n// So make string length less than 4096.\n\\#define STRLEN 4093\n\nvoid generate_string(char *str, int n)\n{\n int i;\n for (i = 0; i < n; ++i)\n {\n char c = i % 26 + 'a';\n str[i] = c;\n }\n str[n-1] = '\\0';\n}\n\nvoid print_string(char *str)\n{\n printf(\"%s\\n\", str);\n}\n\nint main()\n{\n char tmp[STRLEN];\n\n generate_string(tmp, STRLEN);\n print_string(tmp);\n\n return 0;\n}\n```\n3. compile program\n`gcc -o test test.c`\n\n4. get the offset of `print_string()`\n```\nobjdump -t test | grep -w print_string\n0000000000401199 g F .text 000000000000001b print_string\n```\n\n5. configure uprobe with offset 0x1199\n```\noff=0x1199\n\ncd /sys/kernel/debug/tracing/\necho \"p /root/test:${off} arg1=+0(%di):ustring arg2=\\$comm arg3=+0(%di):ustring\"\n > uprobe_events\necho 1 > events/uprobes/enable\necho 1 > tracing_on\n```\n\n6. run `test`, and kasan will report error.\n==================================================================\nBUG: KASAN: use-after-free in strncpy_from_user+0x1d6/0x1f0\nWrite of size 8 at addr ffff88812311c004 by task test/499CPU: 0 UID: 0 PID: 499 Comm: test Not tainted 6.12.0-rc3+ #18\nHardware name: Red Hat KVM, BIOS 1.16.0-4.al8 04/01/2014\nCall Trace:\n \n dump_stack_lvl+0x55/0x70\n print_address_description.constprop.0+0x27/0x310\n kasan_report+0x10f/0x120\n ? strncpy_from_user+0x1d6/0x1f0\n strncpy_from_user+0x1d6/0x1f0\n ? rmqueue.constprop.0+0x70d/0x2ad0\n process_fetch_insn+0xb26/0x1470\n ? __pfx_process_fetch_insn+0x10/0x10\n ? _raw_spin_lock+0x85/0xe0\n ? __pfx__raw_spin_lock+0x10/0x10\n ? __pte_offset_map+0x1f/0x2d0\n ? unwind_next_frame+0xc5f/0x1f80\n ? arch_stack_walk+0x68/0xf0\n ? is_bpf_text_address+0x23/0x30\n ? kernel_text_address.part.0+0xbb/0xd0\n ? __kernel_text_address+0x66/0xb0\n ? unwind_get_return_address+0x5e/0xa0\n ? __pfx_stack_trace_consume_entry+0x10/0x10\n ? arch_stack_walk+0xa2/0xf0\n ? _raw_spin_lock_irqsave+0x8b/0xf0\n ? __pfx__raw_spin_lock_irqsave+0x10/0x10\n ? depot_alloc_stack+0x4c/0x1f0\n ? _raw_spin_unlock_irqrestore+0xe/0x30\n ? stack_depot_save_flags+0x35d/0x4f0\n ? kasan_save_stack+0x34/0x50\n ? kasan_save_stack+0x24/0x50\n ? mutex_lock+0x91/0xe0\n ? __pfx_mutex_lock+0x10/0x10\n prepare_uprobe_buffer.part.0+0x2cd/0x500\n uprobe_dispatcher+0x2c3/0x6a0\n ? __pfx_uprobe_dispatcher+0x10/0x10\n ? __kasan_slab_alloc+0x4d/0x90\n handler_chain+0xdd/0x3e0\n handle_swbp+0x26e/0x3d0\n ? __pfx_handle_swbp+0x10/0x10\n ? uprobe_pre_sstep_notifier+0x151/0x1b0\n irqentry_exit_to_user_mode+0xe2/0x1b0\n asm_exc_int3+0x39/0x40\nRIP: 0033:0x401199\nCode: 01 c2 0f b6 45 fb 88 02 83 45 fc 01 8b 45 fc 3b 45 e4 7c b7 8b 45 e4 48 98 48 8d 50 ff 48 8b 45 e8 48 01 d0 ce\nRSP: 002b:00007ffdf00576a8 EFLAGS: 00000206\nRAX: 00007ffdf00576b0 RBX: 0000000000000000 RCX: 0000000000000ff2\nRDX: 0000000000000ffc RSI: 0000000000000ffd RDI: 00007ffdf00576b0\nRBP: 00007ffdf00586b0 R08: 00007feb2f9c0d20 R09: 00007feb2f9c0d20\nR10: 0000000000000001 R11: 0000000000000202 R12: 0000000000401040\nR13: 00007ffdf0058780 R14: 0000000000000000 R15: 0000000000000000\n \n\nThis commit enforces the buffer's maxlen less than a page-size to avoid\nstore_trace_args() out-of-memory access.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-28T01:15:02Z" diff --git a/advisories/unreviewed/2024/10/GHSA-2jwm-7wcx-f364/GHSA-2jwm-7wcx-f364.json b/advisories/unreviewed/2024/10/GHSA-2jwm-7wcx-f364/GHSA-2jwm-7wcx-f364.json index e81ac5a47f0..43bbd98201f 100644 --- a/advisories/unreviewed/2024/10/GHSA-2jwm-7wcx-f364/GHSA-2jwm-7wcx-f364.json +++ b/advisories/unreviewed/2024/10/GHSA-2jwm-7wcx-f364/GHSA-2jwm-7wcx-f364.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2jwm-7wcx-f364", - "modified": "2024-10-21T21:30:50Z", + "modified": "2024-10-29T18:30:35Z", "published": "2024-10-21T21:30:50Z", "aliases": [ "CVE-2022-48949" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nigb: Initialize mailbox message for VF reset\n\nWhen a MAC address is not assigned to the VF, that portion of the message\nsent to the VF is not set. The memory, however, is allocated from the\nstack meaning that information may be leaked to the VM. Initialize the\nmessage buffer to 0 so that no information is passed to the VM in this\ncase.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-908" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T20:15:06Z" diff --git a/advisories/unreviewed/2024/10/GHSA-2wmm-cc27-75cj/GHSA-2wmm-cc27-75cj.json b/advisories/unreviewed/2024/10/GHSA-2wmm-cc27-75cj/GHSA-2wmm-cc27-75cj.json index 0d3b30d12fd..264445d5221 100644 --- a/advisories/unreviewed/2024/10/GHSA-2wmm-cc27-75cj/GHSA-2wmm-cc27-75cj.json +++ b/advisories/unreviewed/2024/10/GHSA-2wmm-cc27-75cj/GHSA-2wmm-cc27-75cj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2wmm-cc27-75cj", - "modified": "2024-10-28T21:30:34Z", + "modified": "2024-10-29T18:30:36Z", "published": "2024-10-28T21:30:34Z", "aliases": [ "CVE-2024-40867" ], "details": "A custom URL scheme handling issue was addressed with improved input validation. This issue is fixed in iOS 18.1 and iPadOS 18.1. A remote attacker may be able to break out of Web Content sandbox.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-28T21:15:04Z" diff --git a/advisories/unreviewed/2024/10/GHSA-3xw3-m65r-4f37/GHSA-3xw3-m65r-4f37.json b/advisories/unreviewed/2024/10/GHSA-3xw3-m65r-4f37/GHSA-3xw3-m65r-4f37.json new file mode 100644 index 00000000000..92fd6af2562 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-3xw3-m65r-4f37/GHSA-3xw3-m65r-4f37.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3xw3-m65r-4f37", + "modified": "2024-10-29T18:30:37Z", + "published": "2024-10-29T18:30:37Z", + "aliases": [ + "CVE-2024-9988" + ], + "details": "The Crypto plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.15. This is due to missing validation on the user being supplied in the 'crypto_connect_ajax_process::register' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the username.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9988" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/crypto/tags/2.10/includes/class-crypto_connect_ajax_register.php#L91" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/7bfe87cf-9883-4f8f-a0f5-23bbc7bb9b7c?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-288" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-29T17:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-49rw-j488-xw8m/GHSA-49rw-j488-xw8m.json b/advisories/unreviewed/2024/10/GHSA-49rw-j488-xw8m/GHSA-49rw-j488-xw8m.json new file mode 100644 index 00000000000..0a7b10ed767 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-49rw-j488-xw8m/GHSA-49rw-j488-xw8m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-49rw-j488-xw8m", + "modified": "2024-10-29T18:30:34Z", + "published": "2024-10-29T18:30:33Z", + "aliases": [ + "CVE-2023-32644" + ], + "details": "Protection mechanism failure for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via adjacent access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32644" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00947.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-693" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-14T14:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-4jv6-884h-v282/GHSA-4jv6-884h-v282.json b/advisories/unreviewed/2024/10/GHSA-4jv6-884h-v282/GHSA-4jv6-884h-v282.json index 9e99552409e..439f83836f9 100644 --- a/advisories/unreviewed/2024/10/GHSA-4jv6-884h-v282/GHSA-4jv6-884h-v282.json +++ b/advisories/unreviewed/2024/10/GHSA-4jv6-884h-v282/GHSA-4jv6-884h-v282.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4jv6-884h-v282", - "modified": "2024-10-29T15:32:04Z", + "modified": "2024-10-29T18:30:36Z", "published": "2024-10-29T15:32:04Z", "aliases": [ "CVE-2024-10463" ], "details": "Video frames could have been leaked between origins in some situations. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Firefox ESR < 115.17, Thunderbird < 128.4, and Thunderbird < 132.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-203" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-29T13:15:04Z" diff --git a/advisories/unreviewed/2024/10/GHSA-4wjh-chq6-qh88/GHSA-4wjh-chq6-qh88.json b/advisories/unreviewed/2024/10/GHSA-4wjh-chq6-qh88/GHSA-4wjh-chq6-qh88.json index b6d6cf17b2b..74e6acce2a5 100644 --- a/advisories/unreviewed/2024/10/GHSA-4wjh-chq6-qh88/GHSA-4wjh-chq6-qh88.json +++ b/advisories/unreviewed/2024/10/GHSA-4wjh-chq6-qh88/GHSA-4wjh-chq6-qh88.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4wjh-chq6-qh88", - "modified": "2024-10-29T15:32:04Z", + "modified": "2024-10-29T18:30:36Z", "published": "2024-10-29T15:32:04Z", "aliases": [ "CVE-2024-10466" ], "details": "By sending a specially crafted push message, a remote server could have hung the parent process, causing the browser to become unresponsive. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-29T13:15:04Z" diff --git a/advisories/unreviewed/2024/10/GHSA-57xc-4245-hh9c/GHSA-57xc-4245-hh9c.json b/advisories/unreviewed/2024/10/GHSA-57xc-4245-hh9c/GHSA-57xc-4245-hh9c.json index bf7ff3e8158..b71b7347cec 100644 --- a/advisories/unreviewed/2024/10/GHSA-57xc-4245-hh9c/GHSA-57xc-4245-hh9c.json +++ b/advisories/unreviewed/2024/10/GHSA-57xc-4245-hh9c/GHSA-57xc-4245-hh9c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-57xc-4245-hh9c", - "modified": "2024-10-21T18:30:56Z", + "modified": "2024-10-29T18:30:35Z", "published": "2024-10-21T18:30:56Z", "aliases": [ "CVE-2024-40746" ], "details": "A stored cross-site scripting (XSS) vulnerability in HikaShop Joomla Component < 5.1.1 allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload in the `description` parameter of any product. The `description `parameter is not sanitised in the backend.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T17:15:03Z" diff --git a/advisories/unreviewed/2024/10/GHSA-5mqf-fxgc-8r6w/GHSA-5mqf-fxgc-8r6w.json b/advisories/unreviewed/2024/10/GHSA-5mqf-fxgc-8r6w/GHSA-5mqf-fxgc-8r6w.json index dbed0a7ab96..ee2db50a128 100644 --- a/advisories/unreviewed/2024/10/GHSA-5mqf-fxgc-8r6w/GHSA-5mqf-fxgc-8r6w.json +++ b/advisories/unreviewed/2024/10/GHSA-5mqf-fxgc-8r6w/GHSA-5mqf-fxgc-8r6w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5mqf-fxgc-8r6w", - "modified": "2024-10-21T18:31:00Z", + "modified": "2024-10-29T18:30:35Z", "published": "2024-10-21T18:31:00Z", "aliases": [ "CVE-2024-49999" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nafs: Fix the setting of the server responding flag\n\nIn afs_wait_for_operation(), we set transcribe the call responded flag to\nthe server record that we used after doing the fileserver iteration loop -\nbut it's possible to exit the loop having had a response from the server\nthat we've discarded (e.g. it returned an abort or we started receiving\ndata, but the call didn't complete).\n\nThis means that op->server might be NULL, but we don't check that before\nattempting to set the server flag.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T18:15:19Z" diff --git a/advisories/unreviewed/2024/10/GHSA-643q-778f-w3wx/GHSA-643q-778f-w3wx.json b/advisories/unreviewed/2024/10/GHSA-643q-778f-w3wx/GHSA-643q-778f-w3wx.json index 7f53e5713d0..ed5c220f982 100644 --- a/advisories/unreviewed/2024/10/GHSA-643q-778f-w3wx/GHSA-643q-778f-w3wx.json +++ b/advisories/unreviewed/2024/10/GHSA-643q-778f-w3wx/GHSA-643q-778f-w3wx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-643q-778f-w3wx", - "modified": "2024-10-25T00:33:06Z", + "modified": "2024-10-29T18:30:35Z", "published": "2024-10-25T00:33:06Z", "aliases": [ "CVE-2024-41617" ], "details": "Money Manager EX WebApp (web-money-manager-ex) 1.2.2 is vulnerable to Incorrect Access Control. The `redirect_if_not_loggedin` function in `functions_security.php` fails to terminate script execution after redirecting unauthenticated users. This flaw allows an unauthenticated attacker to upload arbitrary files, potentially leading to Remote Code Execution.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-24T22:15:03Z" diff --git a/advisories/unreviewed/2024/10/GHSA-66c4-2g2v-54qw/GHSA-66c4-2g2v-54qw.json b/advisories/unreviewed/2024/10/GHSA-66c4-2g2v-54qw/GHSA-66c4-2g2v-54qw.json new file mode 100644 index 00000000000..126eabc1539 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-66c4-2g2v-54qw/GHSA-66c4-2g2v-54qw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-66c4-2g2v-54qw", + "modified": "2024-10-29T18:30:36Z", + "published": "2024-10-29T18:30:36Z", + "aliases": [ + "CVE-2024-10452" + ], + "details": "Organization admins can delete pending invites created in an organization they are not part of.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10452" + }, + { + "type": "WEB", + "url": "https://grafana.com/security/security-advisories/cve-2024-10452" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-639" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-29T16:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-6q42-xcp7-qvr5/GHSA-6q42-xcp7-qvr5.json b/advisories/unreviewed/2024/10/GHSA-6q42-xcp7-qvr5/GHSA-6q42-xcp7-qvr5.json index 2229f420714..3deb0e76dd5 100644 --- a/advisories/unreviewed/2024/10/GHSA-6q42-xcp7-qvr5/GHSA-6q42-xcp7-qvr5.json +++ b/advisories/unreviewed/2024/10/GHSA-6q42-xcp7-qvr5/GHSA-6q42-xcp7-qvr5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6q42-xcp7-qvr5", - "modified": "2024-10-28T21:30:34Z", + "modified": "2024-10-29T18:30:36Z", "published": "2024-10-28T21:30:34Z", "aliases": [ "CVE-2024-44122" ], "details": "A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.1, macOS Sequoia 15, macOS Sonoma 14.7.1. An application may be able to break out of its sandbox.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-28T21:15:05Z" diff --git a/advisories/unreviewed/2024/10/GHSA-6rc3-wcpj-59ch/GHSA-6rc3-wcpj-59ch.json b/advisories/unreviewed/2024/10/GHSA-6rc3-wcpj-59ch/GHSA-6rc3-wcpj-59ch.json index c6967e34b62..1b88c63693e 100644 --- a/advisories/unreviewed/2024/10/GHSA-6rc3-wcpj-59ch/GHSA-6rc3-wcpj-59ch.json +++ b/advisories/unreviewed/2024/10/GHSA-6rc3-wcpj-59ch/GHSA-6rc3-wcpj-59ch.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6rc3-wcpj-59ch", - "modified": "2024-10-29T15:32:04Z", + "modified": "2024-10-29T18:30:36Z", "published": "2024-10-29T15:32:04Z", "aliases": [ "CVE-2024-10462" ], "details": "Truncation of a long URL could have allowed origin spoofing in a permission prompt. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-290" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-29T13:15:03Z" diff --git a/advisories/unreviewed/2024/10/GHSA-6rpv-3c7j-v6g2/GHSA-6rpv-3c7j-v6g2.json b/advisories/unreviewed/2024/10/GHSA-6rpv-3c7j-v6g2/GHSA-6rpv-3c7j-v6g2.json new file mode 100644 index 00000000000..7ed83b11beb --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-6rpv-3c7j-v6g2/GHSA-6rpv-3c7j-v6g2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6rpv-3c7j-v6g2", + "modified": "2024-10-29T18:30:34Z", + "published": "2024-10-29T18:30:33Z", + "aliases": [ + "CVE-2023-32651" + ], + "details": "Improper validation of specified type of input for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via adjacent access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32651" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00947.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1287" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-14T14:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-748f-44g2-h43m/GHSA-748f-44g2-h43m.json b/advisories/unreviewed/2024/10/GHSA-748f-44g2-h43m/GHSA-748f-44g2-h43m.json new file mode 100644 index 00000000000..0634befd042 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-748f-44g2-h43m/GHSA-748f-44g2-h43m.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-748f-44g2-h43m", + "modified": "2024-10-29T18:30:36Z", + "published": "2024-10-29T18:30:36Z", + "aliases": [ + "CVE-2024-25566" + ], + "details": "An Open-Redirect vulnerability exists in PingAM where well-crafted requests may cause improper validation of redirect URLs. This could allow an attacker to redirect end-users to malicious sites under their control, simplifying phishing attacks", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25566" + }, + { + "type": "WEB", + "url": "https://backstage.forgerock.com/downloads/browse/am/featured" + }, + { + "type": "WEB", + "url": "https://backstage.forgerock.com/knowledge/advisories/article/a63463303" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-29T16:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-74x7-28x6-q6gc/GHSA-74x7-28x6-q6gc.json b/advisories/unreviewed/2024/10/GHSA-74x7-28x6-q6gc/GHSA-74x7-28x6-q6gc.json index 5aa4eb424f9..3934eea05de 100644 --- a/advisories/unreviewed/2024/10/GHSA-74x7-28x6-q6gc/GHSA-74x7-28x6-q6gc.json +++ b/advisories/unreviewed/2024/10/GHSA-74x7-28x6-q6gc/GHSA-74x7-28x6-q6gc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-74x7-28x6-q6gc", - "modified": "2024-10-24T18:30:43Z", + "modified": "2024-10-29T18:30:35Z", "published": "2024-10-24T18:30:43Z", "aliases": [ "CVE-2024-44206" ], "details": "An issue in the handling of URL protocols was addressed with improved logic. This issue is fixed in tvOS 17.6, visionOS 1.3, Safari 17.6, watchOS 10.6, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6. A user may be able to bypass some web content restrictions.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -47,7 +50,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-24T17:15:16Z" diff --git a/advisories/unreviewed/2024/10/GHSA-7mwx-v6fm-m2ph/GHSA-7mwx-v6fm-m2ph.json b/advisories/unreviewed/2024/10/GHSA-7mwx-v6fm-m2ph/GHSA-7mwx-v6fm-m2ph.json new file mode 100644 index 00000000000..1a480ea6261 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-7mwx-v6fm-m2ph/GHSA-7mwx-v6fm-m2ph.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7mwx-v6fm-m2ph", + "modified": "2024-10-29T18:30:33Z", + "published": "2024-10-29T18:30:33Z", + "aliases": [ + "CVE-2023-28715" + ], + "details": "Improper access control in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.2 may allow an authenticated user to potentially enable denial of service via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28715" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00956.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-14T14:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-85gr-f847-q6cw/GHSA-85gr-f847-q6cw.json b/advisories/unreviewed/2024/10/GHSA-85gr-f847-q6cw/GHSA-85gr-f847-q6cw.json new file mode 100644 index 00000000000..9d9edf11e7a --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-85gr-f847-q6cw/GHSA-85gr-f847-q6cw.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-85gr-f847-q6cw", + "modified": "2024-10-29T18:30:34Z", + "published": "2024-10-29T18:30:33Z", + "aliases": [ + "CVE-2023-34351" + ], + "details": "Buffer underflow in some Intel(R) PCM software before version 202307 may allow an unauthenticated user to potentially enable denial of service via network access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-34351" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00954.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-124", + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-14T14:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-8jgf-8r3g-hxh8/GHSA-8jgf-8r3g-hxh8.json b/advisories/unreviewed/2024/10/GHSA-8jgf-8r3g-hxh8/GHSA-8jgf-8r3g-hxh8.json index 27f2f59c711..53472e76aa0 100644 --- a/advisories/unreviewed/2024/10/GHSA-8jgf-8r3g-hxh8/GHSA-8jgf-8r3g-hxh8.json +++ b/advisories/unreviewed/2024/10/GHSA-8jgf-8r3g-hxh8/GHSA-8jgf-8r3g-hxh8.json @@ -52,7 +52,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-290" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-8wp6-p8r2-jh2m/GHSA-8wp6-p8r2-jh2m.json b/advisories/unreviewed/2024/10/GHSA-8wp6-p8r2-jh2m/GHSA-8wp6-p8r2-jh2m.json new file mode 100644 index 00000000000..e52d0c70d4c --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-8wp6-p8r2-jh2m/GHSA-8wp6-p8r2-jh2m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8wp6-p8r2-jh2m", + "modified": "2024-10-29T18:30:37Z", + "published": "2024-10-29T18:30:37Z", + "aliases": [ + "CVE-2024-50459" + ], + "details": "Missing Authorization vulnerability in HM Plugin WordPress Stripe Donation and Payment Plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress Stripe Donation and Payment Plugin: from n/a through 3.2.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50459" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-stripe-donation/wordpress-aidwp-plugin-3-2-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-29T17:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-9v98-vwhg-6x24/GHSA-9v98-vwhg-6x24.json b/advisories/unreviewed/2024/10/GHSA-9v98-vwhg-6x24/GHSA-9v98-vwhg-6x24.json index a3c8329fdcc..e9b343d6ef5 100644 --- a/advisories/unreviewed/2024/10/GHSA-9v98-vwhg-6x24/GHSA-9v98-vwhg-6x24.json +++ b/advisories/unreviewed/2024/10/GHSA-9v98-vwhg-6x24/GHSA-9v98-vwhg-6x24.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9v98-vwhg-6x24", - "modified": "2024-10-29T15:32:04Z", + "modified": "2024-10-29T18:30:36Z", "published": "2024-10-29T15:32:04Z", "aliases": [ "CVE-2024-10467" ], "details": "Memory safety bugs present in Firefox 131, Firefox ESR 128.3, and Thunderbird 128.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-29T13:15:04Z" diff --git a/advisories/unreviewed/2024/10/GHSA-9vq2-w47q-3pjh/GHSA-9vq2-w47q-3pjh.json b/advisories/unreviewed/2024/10/GHSA-9vq2-w47q-3pjh/GHSA-9vq2-w47q-3pjh.json index 3fc9b55aa55..8dc3dc00a8b 100644 --- a/advisories/unreviewed/2024/10/GHSA-9vq2-w47q-3pjh/GHSA-9vq2-w47q-3pjh.json +++ b/advisories/unreviewed/2024/10/GHSA-9vq2-w47q-3pjh/GHSA-9vq2-w47q-3pjh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9vq2-w47q-3pjh", - "modified": "2024-10-28T21:30:35Z", + "modified": "2024-10-29T18:30:36Z", "published": "2024-10-28T21:30:35Z", "aliases": [ "CVE-2024-44156" ], "details": "A path deletion vulnerability was addressed by preventing vulnerable code from running with privileges. This issue is fixed in macOS Ventura 13.7.1, macOS Sonoma 14.7.1. An app may be able to bypass Privacy preferences.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-28T21:15:05Z" diff --git a/advisories/unreviewed/2024/10/GHSA-9xrj-2966-hg7q/GHSA-9xrj-2966-hg7q.json b/advisories/unreviewed/2024/10/GHSA-9xrj-2966-hg7q/GHSA-9xrj-2966-hg7q.json index 8b079d0ad9a..3547e404225 100644 --- a/advisories/unreviewed/2024/10/GHSA-9xrj-2966-hg7q/GHSA-9xrj-2966-hg7q.json +++ b/advisories/unreviewed/2024/10/GHSA-9xrj-2966-hg7q/GHSA-9xrj-2966-hg7q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9xrj-2966-hg7q", - "modified": "2024-10-21T18:31:00Z", + "modified": "2024-10-29T18:30:35Z", "published": "2024-10-21T18:31:00Z", "aliases": [ "CVE-2024-49997" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ethernet: lantiq_etop: fix memory disclosure\n\nWhen applying padding, the buffer is not zeroed, which results in memory\ndisclosure. The mentioned data is observed on the wire. This patch uses\nskb_put_padto() to pad Ethernet frames properly. The mentioned function\nzeroes the expanded buffer.\n\nIn case the packet cannot be padded it is silently dropped. Statistics\nare also not incremented. This driver does not support statistics in the\nold 32-bit format or the new 64-bit format. These will be added in the\nfuture. In its current form, the patch should be easily backported to\nstable versions.\n\nEthernet MACs on Amazon-SE and Danube cannot do padding of the packets\nin hardware, so software padding must be applied.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -49,9 +52,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-212" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T18:15:19Z" diff --git a/advisories/unreviewed/2024/10/GHSA-c3gg-vqm5-638v/GHSA-c3gg-vqm5-638v.json b/advisories/unreviewed/2024/10/GHSA-c3gg-vqm5-638v/GHSA-c3gg-vqm5-638v.json new file mode 100644 index 00000000000..07185c618ed --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-c3gg-vqm5-638v/GHSA-c3gg-vqm5-638v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c3gg-vqm5-638v", + "modified": "2024-10-29T18:30:37Z", + "published": "2024-10-29T18:30:37Z", + "aliases": [ + "CVE-2024-50466" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in DarkMySite DarkMySite – Advanced Dark Mode Plugin for WordPress darkmysite allows Cross Site Request Forgery.This issue affects DarkMySite – Advanced Dark Mode Plugin for WordPress: from n/a through 1.2.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50466" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/darkmysite/wordpress-darkmysite-advanced-dark-mode-plugin-for-wordpress-plugin-1-2-8-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-29T17:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-c83g-cgfm-hc33/GHSA-c83g-cgfm-hc33.json b/advisories/unreviewed/2024/10/GHSA-c83g-cgfm-hc33/GHSA-c83g-cgfm-hc33.json index c1dd3fcf584..ec8796c7e37 100644 --- a/advisories/unreviewed/2024/10/GHSA-c83g-cgfm-hc33/GHSA-c83g-cgfm-hc33.json +++ b/advisories/unreviewed/2024/10/GHSA-c83g-cgfm-hc33/GHSA-c83g-cgfm-hc33.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c83g-cgfm-hc33", - "modified": "2024-10-28T21:30:35Z", + "modified": "2024-10-29T18:30:36Z", "published": "2024-10-28T21:30:35Z", "aliases": [ "CVE-2024-44159" ], "details": "A path deletion vulnerability was addressed by preventing vulnerable code from running with privileges. This issue is fixed in macOS Ventura 13.7.1, macOS Sonoma 14.7.1. An app may be able to bypass Privacy preferences.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-28T21:15:05Z" diff --git a/advisories/unreviewed/2024/10/GHSA-cm5g-3pgc-8rg4/GHSA-cm5g-3pgc-8rg4.json b/advisories/unreviewed/2024/10/GHSA-cm5g-3pgc-8rg4/GHSA-cm5g-3pgc-8rg4.json new file mode 100644 index 00000000000..b766a5ce3d0 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-cm5g-3pgc-8rg4/GHSA-cm5g-3pgc-8rg4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cm5g-3pgc-8rg4", + "modified": "2024-10-29T18:30:37Z", + "published": "2024-10-29T18:30:37Z", + "aliases": [ + "CVE-2024-10491" + ], + "details": "A vulnerability has been identified in the Express response.links function, allowing for arbitrary resource injection in the Link header when unsanitized data is used.\n\nThe issue arises from improper sanitization in `Link` header values, which can allow a combination of characters like `,`, `;`, and `<>` to preload malicious resources.\n\nThis vulnerability is especially relevant for dynamic parameters.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10491" + }, + { + "type": "WEB", + "url": "https://www.herodevs.com/vulnerability-directory/cve-2024-10491" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-29T17:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-crcx-wcr8-prj5/GHSA-crcx-wcr8-prj5.json b/advisories/unreviewed/2024/10/GHSA-crcx-wcr8-prj5/GHSA-crcx-wcr8-prj5.json index a6b9baeb38d..a2258d66181 100644 --- a/advisories/unreviewed/2024/10/GHSA-crcx-wcr8-prj5/GHSA-crcx-wcr8-prj5.json +++ b/advisories/unreviewed/2024/10/GHSA-crcx-wcr8-prj5/GHSA-crcx-wcr8-prj5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-crcx-wcr8-prj5", - "modified": "2024-10-25T00:33:06Z", + "modified": "2024-10-29T18:30:35Z", "published": "2024-10-25T00:33:06Z", "aliases": [ "CVE-2024-41618" ], "details": "Money Manager EX WebApp (web-money-manager-ex) 1.2.2 is vulnerable to SQL Injection in the `transaction_delete_group` function. The vulnerability is due to improper sanitization of user input in the `TrDeleteArr` parameter, which is directly incorporated into an SQL query.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-24T22:15:03Z" diff --git a/advisories/unreviewed/2024/10/GHSA-cvcv-6ggr-f8x8/GHSA-cvcv-6ggr-f8x8.json b/advisories/unreviewed/2024/10/GHSA-cvcv-6ggr-f8x8/GHSA-cvcv-6ggr-f8x8.json new file mode 100644 index 00000000000..c28bfc0cb8f --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-cvcv-6ggr-f8x8/GHSA-cvcv-6ggr-f8x8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cvcv-6ggr-f8x8", + "modified": "2024-10-29T18:30:33Z", + "published": "2024-10-29T18:30:33Z", + "aliases": [ + "CVE-2023-28374" + ], + "details": "Improper input validation for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via adjacent access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28374" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00947.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-14T14:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-cwg2-qmg3-3f6x/GHSA-cwg2-qmg3-3f6x.json b/advisories/unreviewed/2024/10/GHSA-cwg2-qmg3-3f6x/GHSA-cwg2-qmg3-3f6x.json new file mode 100644 index 00000000000..7a44ad952a6 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-cwg2-qmg3-3f6x/GHSA-cwg2-qmg3-3f6x.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cwg2-qmg3-3f6x", + "modified": "2024-10-29T18:30:37Z", + "published": "2024-10-29T18:30:36Z", + "aliases": [ + "CVE-2019-25219" + ], + "details": "Asio C++ Library before 1.13.0 lacks a fallback error code in the case of SSL_ERROR_SYSCALL with no associated error information from the SSL library being used.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-25219" + }, + { + "type": "WEB", + "url": "https://github.com/chriskohlhoff/asio/commit/93337cba7b013150f5aa6194393e1d94be2853ec" + }, + { + "type": "WEB", + "url": "https://github.com/chriskohlhoff/asio/compare/asio-1-12-2...asio-1-13-0" + }, + { + "type": "WEB", + "url": "https://think-async.com/Asio" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-29T17:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-cx83-mmj7-4ghv/GHSA-cx83-mmj7-4ghv.json b/advisories/unreviewed/2024/10/GHSA-cx83-mmj7-4ghv/GHSA-cx83-mmj7-4ghv.json index 2c9c2fb31b4..71232c2ae2d 100644 --- a/advisories/unreviewed/2024/10/GHSA-cx83-mmj7-4ghv/GHSA-cx83-mmj7-4ghv.json +++ b/advisories/unreviewed/2024/10/GHSA-cx83-mmj7-4ghv/GHSA-cx83-mmj7-4ghv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cx83-mmj7-4ghv", - "modified": "2024-10-28T21:30:35Z", + "modified": "2024-10-29T18:30:36Z", "published": "2024-10-28T21:30:35Z", "aliases": [ "CVE-2024-44137" ], "details": "The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.1, macOS Sequoia 15, macOS Sonoma 14.7.1. An attacker with physical access may be able to share items from the lock screen.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-28T21:15:05Z" diff --git a/advisories/unreviewed/2024/10/GHSA-cx8w-r23v-jmjv/GHSA-cx8w-r23v-jmjv.json b/advisories/unreviewed/2024/10/GHSA-cx8w-r23v-jmjv/GHSA-cx8w-r23v-jmjv.json new file mode 100644 index 00000000000..5ed3dcb7ea0 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-cx8w-r23v-jmjv/GHSA-cx8w-r23v-jmjv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cx8w-r23v-jmjv", + "modified": "2024-10-29T18:30:33Z", + "published": "2024-10-29T18:30:33Z", + "aliases": [ + "CVE-2023-26586" + ], + "details": "Uncaught exception for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via adjacent access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26586" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00947.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-248" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-14T14:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-hc2m-pgvg-pf5x/GHSA-hc2m-pgvg-pf5x.json b/advisories/unreviewed/2024/10/GHSA-hc2m-pgvg-pf5x/GHSA-hc2m-pgvg-pf5x.json new file mode 100644 index 00000000000..9ace592987c --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-hc2m-pgvg-pf5x/GHSA-hc2m-pgvg-pf5x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hc2m-pgvg-pf5x", + "modified": "2024-10-29T18:30:34Z", + "published": "2024-10-29T18:30:34Z", + "aliases": [ + "CVE-2023-34983" + ], + "details": "Improper input validation for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via adjacent access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-34983" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00947.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-14T14:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-hmfh-w3mx-w6j4/GHSA-hmfh-w3mx-w6j4.json b/advisories/unreviewed/2024/10/GHSA-hmfh-w3mx-w6j4/GHSA-hmfh-w3mx-w6j4.json new file mode 100644 index 00000000000..d96055d6994 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-hmfh-w3mx-w6j4/GHSA-hmfh-w3mx-w6j4.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hmfh-w3mx-w6j4", + "modified": "2024-10-29T18:30:37Z", + "published": "2024-10-29T18:30:37Z", + "aliases": [ + "CVE-2024-9989" + ], + "details": "The Crypto plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.15. This is due a to limited arbitrary method call to 'crypto_connect_ajax_process::log_in' function in the 'crypto_connect_ajax_process' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the username.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9989" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/crypto/tags/2.10/includes/class-crypto_connect_ajax_register.php#L138" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/crypto/tags/2.10/includes/class-crypto_connect_ajax_register.php#L33" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/e21bd924-1d96-4371-972a-5c99d67261cc?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-288" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-29T17:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-hvf3-fq2g-9gmg/GHSA-hvf3-fq2g-9gmg.json b/advisories/unreviewed/2024/10/GHSA-hvf3-fq2g-9gmg/GHSA-hvf3-fq2g-9gmg.json index 7adfc2df7b9..82a999bc919 100644 --- a/advisories/unreviewed/2024/10/GHSA-hvf3-fq2g-9gmg/GHSA-hvf3-fq2g-9gmg.json +++ b/advisories/unreviewed/2024/10/GHSA-hvf3-fq2g-9gmg/GHSA-hvf3-fq2g-9gmg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hvf3-fq2g-9gmg", - "modified": "2024-10-21T21:30:50Z", + "modified": "2024-10-29T18:30:35Z", "published": "2024-10-21T21:30:50Z", "aliases": [ "CVE-2022-48948" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: uvc: Prevent buffer overflow in setup handler\n\nSetup function uvc_function_setup permits control transfer\nrequests with up to 64 bytes of payload (UVC_MAX_REQUEST_SIZE),\ndata stage handler for OUT transfer uses memcpy to copy req->actual\nbytes to uvc_event->data.data array of size 60. This may result\nin an overflow of 4 bytes.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -57,9 +60,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T20:15:06Z" diff --git a/advisories/unreviewed/2024/10/GHSA-j4xv-h5fv-6v4m/GHSA-j4xv-h5fv-6v4m.json b/advisories/unreviewed/2024/10/GHSA-j4xv-h5fv-6v4m/GHSA-j4xv-h5fv-6v4m.json index c5e1a9489fe..01ef26d7470 100644 --- a/advisories/unreviewed/2024/10/GHSA-j4xv-h5fv-6v4m/GHSA-j4xv-h5fv-6v4m.json +++ b/advisories/unreviewed/2024/10/GHSA-j4xv-h5fv-6v4m/GHSA-j4xv-h5fv-6v4m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j4xv-h5fv-6v4m", - "modified": "2024-10-21T18:30:59Z", + "modified": "2024-10-29T18:30:35Z", "published": "2024-10-21T18:30:59Z", "aliases": [ "CVE-2024-49979" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: gso: fix tcp fraglist segmentation after pull from frag_list\n\nDetect tcp gso fraglist skbs with corrupted geometry (see below) and\npass these to skb_segment instead of skb_segment_list, as the first\ncan segment them correctly.\n\nValid SKB_GSO_FRAGLIST skbs\n- consist of two or more segments\n- the head_skb holds the protocol headers plus first gso_size\n- one or more frag_list skbs hold exactly one segment\n- all but the last must be gso_size\n\nOptional datapath hooks such as NAT and BPF (bpf_skb_pull_data) can\nmodify these skbs, breaking these invariants.\n\nIn extreme cases they pull all data into skb linear. For TCP, this\ncauses a NULL ptr deref in __tcpv4_gso_segment_list_csum at\ntcp_hdr(seg->next).\n\nDetect invalid geometry due to pull, by checking head_skb size.\nDon't just drop, as this may blackhole a destination. Convert to be\nable to pass to regular skb_segment.\n\nApproach and description based on a patch by Willem de Bruijn.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T18:15:18Z" diff --git a/advisories/unreviewed/2024/10/GHSA-jx2m-9x57-vwr5/GHSA-jx2m-9x57-vwr5.json b/advisories/unreviewed/2024/10/GHSA-jx2m-9x57-vwr5/GHSA-jx2m-9x57-vwr5.json index 51e56a336f5..33682494787 100644 --- a/advisories/unreviewed/2024/10/GHSA-jx2m-9x57-vwr5/GHSA-jx2m-9x57-vwr5.json +++ b/advisories/unreviewed/2024/10/GHSA-jx2m-9x57-vwr5/GHSA-jx2m-9x57-vwr5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jx2m-9x57-vwr5", - "modified": "2024-10-29T15:32:04Z", + "modified": "2024-10-29T18:30:36Z", "published": "2024-10-29T15:32:04Z", "aliases": [ "CVE-2024-10465" ], "details": "A clipboard \"paste\" button could persist across tabs which allowed a spoofing attack. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-290" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-29T13:15:04Z" diff --git a/advisories/unreviewed/2024/10/GHSA-m499-vjfj-6h36/GHSA-m499-vjfj-6h36.json b/advisories/unreviewed/2024/10/GHSA-m499-vjfj-6h36/GHSA-m499-vjfj-6h36.json index d1de09c5e8a..c0c9750897e 100644 --- a/advisories/unreviewed/2024/10/GHSA-m499-vjfj-6h36/GHSA-m499-vjfj-6h36.json +++ b/advisories/unreviewed/2024/10/GHSA-m499-vjfj-6h36/GHSA-m499-vjfj-6h36.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m499-vjfj-6h36", - "modified": "2024-10-28T21:30:34Z", + "modified": "2024-10-29T18:30:36Z", "published": "2024-10-28T21:30:34Z", "aliases": [ "CVE-2024-40792" ], "details": "A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15. A malicious app may be able to change network settings.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-28T21:15:04Z" diff --git a/advisories/unreviewed/2024/10/GHSA-m4fc-wmq3-h3jq/GHSA-m4fc-wmq3-h3jq.json b/advisories/unreviewed/2024/10/GHSA-m4fc-wmq3-h3jq/GHSA-m4fc-wmq3-h3jq.json index ab0387c7d9b..ec4a1379108 100644 --- a/advisories/unreviewed/2024/10/GHSA-m4fc-wmq3-h3jq/GHSA-m4fc-wmq3-h3jq.json +++ b/advisories/unreviewed/2024/10/GHSA-m4fc-wmq3-h3jq/GHSA-m4fc-wmq3-h3jq.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-288" + "CWE-288", + "CWE-306" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-m5h5-93gh-rvhm/GHSA-m5h5-93gh-rvhm.json b/advisories/unreviewed/2024/10/GHSA-m5h5-93gh-rvhm/GHSA-m5h5-93gh-rvhm.json index 75b35c67a77..d3b73fa986e 100644 --- a/advisories/unreviewed/2024/10/GHSA-m5h5-93gh-rvhm/GHSA-m5h5-93gh-rvhm.json +++ b/advisories/unreviewed/2024/10/GHSA-m5h5-93gh-rvhm/GHSA-m5h5-93gh-rvhm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m5h5-93gh-rvhm", - "modified": "2024-10-18T18:30:36Z", + "modified": "2024-10-29T18:30:35Z", "published": "2024-10-18T18:30:36Z", "aliases": [ "CVE-2024-42508" ], "details": "This vulnerability could be exploited, leading to unauthorized disclosure of information to authenticated users.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-200" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-18T16:15:04Z" diff --git a/advisories/unreviewed/2024/10/GHSA-m7jf-xm88-cv45/GHSA-m7jf-xm88-cv45.json b/advisories/unreviewed/2024/10/GHSA-m7jf-xm88-cv45/GHSA-m7jf-xm88-cv45.json index 8bc3ff28094..bd960c9b9c6 100644 --- a/advisories/unreviewed/2024/10/GHSA-m7jf-xm88-cv45/GHSA-m7jf-xm88-cv45.json +++ b/advisories/unreviewed/2024/10/GHSA-m7jf-xm88-cv45/GHSA-m7jf-xm88-cv45.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m7jf-xm88-cv45", - "modified": "2024-10-28T21:30:35Z", + "modified": "2024-10-29T18:30:36Z", "published": "2024-10-28T21:30:35Z", "aliases": [ "CVE-2024-44144" ], "details": "A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, macOS Sequoia 15, macOS Sonoma 14.7.1, tvOS 18, watchOS 11, visionOS 2, iOS 18 and iPadOS 18. Processing a maliciously crafted file may lead to unexpected app termination.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -49,9 +52,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-28T21:15:05Z" diff --git a/advisories/unreviewed/2024/10/GHSA-mcg2-6f5j-3fmv/GHSA-mcg2-6f5j-3fmv.json b/advisories/unreviewed/2024/10/GHSA-mcg2-6f5j-3fmv/GHSA-mcg2-6f5j-3fmv.json new file mode 100644 index 00000000000..8ba306dc5d4 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-mcg2-6f5j-3fmv/GHSA-mcg2-6f5j-3fmv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mcg2-6f5j-3fmv", + "modified": "2024-10-29T18:30:33Z", + "published": "2024-10-29T18:30:33Z", + "aliases": [ + "CVE-2023-25945" + ], + "details": "Protection mechanism failure in some Intel(R) OFU software before version 14.1.31 may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25945" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00927.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-693" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-14T14:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-mcg7-2pf9-m48g/GHSA-mcg7-2pf9-m48g.json b/advisories/unreviewed/2024/10/GHSA-mcg7-2pf9-m48g/GHSA-mcg7-2pf9-m48g.json new file mode 100644 index 00000000000..fa358cd5c53 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-mcg7-2pf9-m48g/GHSA-mcg7-2pf9-m48g.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mcg7-2pf9-m48g", + "modified": "2024-10-29T18:30:37Z", + "published": "2024-10-29T18:30:37Z", + "aliases": [ + "CVE-2024-48955" + ], + "details": "In NetAdmin 4.0.30319, an attacker can steal a valid session cookie and inject it into another device, granting unauthorized access. This type of attack is commonly referred to as session hijacking.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48955" + }, + { + "type": "WEB", + "url": "https://github.com/BrotherOfJhonny/CVE-2024-48955_Overview" + }, + { + "type": "WEB", + "url": "https://netadmin.software/gestao-de-identidade-e-acesso" + }, + { + "type": "WEB", + "url": "https://vulmon.com/vulnerabilitydetails?qid=CVE-2024-48955&sortby=bydate" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-29T18:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-mvwj-4mhx-2qqv/GHSA-mvwj-4mhx-2qqv.json b/advisories/unreviewed/2024/10/GHSA-mvwj-4mhx-2qqv/GHSA-mvwj-4mhx-2qqv.json new file mode 100644 index 00000000000..0ca3a5f6489 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-mvwj-4mhx-2qqv/GHSA-mvwj-4mhx-2qqv.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mvwj-4mhx-2qqv", + "modified": "2024-10-29T18:30:37Z", + "published": "2024-10-29T18:30:37Z", + "aliases": [ + "CVE-2024-9990" + ], + "details": "The Crypto plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.15. This is due to missing nonce validation in the 'crypto_connect_ajax_process::check' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9990" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/crypto/tags/2.10/includes/class-crypto_connect_ajax_register.php#L31" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/crypto/tags/2.10/includes/class-crypto_connect_ajax_register.php#L65" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/cea39157-94aa-4982-983e-9c3e4b1af86d?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-29T17:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-pqvr-wrvc-p23v/GHSA-pqvr-wrvc-p23v.json b/advisories/unreviewed/2024/10/GHSA-pqvr-wrvc-p23v/GHSA-pqvr-wrvc-p23v.json new file mode 100644 index 00000000000..4bb51ed33ce --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-pqvr-wrvc-p23v/GHSA-pqvr-wrvc-p23v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pqvr-wrvc-p23v", + "modified": "2024-10-29T18:30:33Z", + "published": "2024-10-29T18:30:33Z", + "aliases": [ + "CVE-2023-32642" + ], + "details": "Insufficient adherence to expected conventions for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via adjacent access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32642" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00947.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1076" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-14T14:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-qc88-643m-whjm/GHSA-qc88-643m-whjm.json b/advisories/unreviewed/2024/10/GHSA-qc88-643m-whjm/GHSA-qc88-643m-whjm.json index a78411ea4a3..0da49259838 100644 --- a/advisories/unreviewed/2024/10/GHSA-qc88-643m-whjm/GHSA-qc88-643m-whjm.json +++ b/advisories/unreviewed/2024/10/GHSA-qc88-643m-whjm/GHSA-qc88-643m-whjm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qc88-643m-whjm", - "modified": "2024-10-28T21:30:34Z", + "modified": "2024-10-29T18:30:36Z", "published": "2024-10-28T21:30:34Z", "aliases": [ "CVE-2024-40855" ], "details": "The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.1, macOS Sequoia 15, macOS Sonoma 14.7.1. A sandboxed app may be able to access sensitive user data.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-28T21:15:04Z" diff --git a/advisories/unreviewed/2024/10/GHSA-qfpw-9prx-m9g3/GHSA-qfpw-9prx-m9g3.json b/advisories/unreviewed/2024/10/GHSA-qfpw-9prx-m9g3/GHSA-qfpw-9prx-m9g3.json new file mode 100644 index 00000000000..fde18396dae --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-qfpw-9prx-m9g3/GHSA-qfpw-9prx-m9g3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qfpw-9prx-m9g3", + "modified": "2024-10-29T18:30:33Z", + "published": "2024-10-29T18:30:33Z", + "aliases": [ + "CVE-2023-25073" + ], + "details": "Improper access control in some Intel(R) DSA software before version 23.4.33 may allow an authenticated user to potentially enable denial of service via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25073" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00969.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-14T14:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-qjpg-5hx2-g69j/GHSA-qjpg-5hx2-g69j.json b/advisories/unreviewed/2024/10/GHSA-qjpg-5hx2-g69j/GHSA-qjpg-5hx2-g69j.json index ee1f3569180..85d3f9eaedd 100644 --- a/advisories/unreviewed/2024/10/GHSA-qjpg-5hx2-g69j/GHSA-qjpg-5hx2-g69j.json +++ b/advisories/unreviewed/2024/10/GHSA-qjpg-5hx2-g69j/GHSA-qjpg-5hx2-g69j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qjpg-5hx2-g69j", - "modified": "2024-10-21T18:30:59Z", + "modified": "2024-10-29T18:30:35Z", "published": "2024-10-21T18:30:59Z", "aliases": [ "CVE-2024-49984" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/v3d: Prevent out of bounds access in performance query extensions\n\nCheck that the number of perfmons userspace is passing in the copy and\nreset extensions is not greater than the internal kernel storage where\nthe ids will be copied into.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T18:15:18Z" diff --git a/advisories/unreviewed/2024/10/GHSA-qpr4-w3rc-m373/GHSA-qpr4-w3rc-m373.json b/advisories/unreviewed/2024/10/GHSA-qpr4-w3rc-m373/GHSA-qpr4-w3rc-m373.json new file mode 100644 index 00000000000..f8d1dad981e --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-qpr4-w3rc-m373/GHSA-qpr4-w3rc-m373.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qpr4-w3rc-m373", + "modified": "2024-10-29T18:30:36Z", + "published": "2024-10-29T18:30:36Z", + "aliases": [ + "CVE-2024-8923" + ], + "details": "ServiceNow has addressed an input validation vulnerability that was identified in the Now Platform. This vulnerability could enable an unauthenticated user to remotely execute code within the context of the Now Platform. ServiceNow deployed an update to hosted instances and ServiceNow provided the update to our partners and self-hosted customers. Further, the vulnerability is addressed in the listed patches and hot fixes.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8923" + }, + { + "type": "WEB", + "url": "https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB1706070" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-29T16:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-r2v5-q2jv-5cff/GHSA-r2v5-q2jv-5cff.json b/advisories/unreviewed/2024/10/GHSA-r2v5-q2jv-5cff/GHSA-r2v5-q2jv-5cff.json index 1a71817f3b1..4b45f44d189 100644 --- a/advisories/unreviewed/2024/10/GHSA-r2v5-q2jv-5cff/GHSA-r2v5-q2jv-5cff.json +++ b/advisories/unreviewed/2024/10/GHSA-r2v5-q2jv-5cff/GHSA-r2v5-q2jv-5cff.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r2v5-q2jv-5cff", - "modified": "2024-10-29T15:32:04Z", + "modified": "2024-10-29T18:30:36Z", "published": "2024-10-29T15:32:04Z", "aliases": [ "CVE-2024-10464" ], "details": "Repeated writes to history interface attributes could have been used to cause a Denial of Service condition in the browser. This was addressed by introducing rate-limiting to this API. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-29T13:15:04Z" diff --git a/advisories/unreviewed/2024/10/GHSA-r4m7-9275-xfg3/GHSA-r4m7-9275-xfg3.json b/advisories/unreviewed/2024/10/GHSA-r4m7-9275-xfg3/GHSA-r4m7-9275-xfg3.json new file mode 100644 index 00000000000..822a5c3cdcb --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-r4m7-9275-xfg3/GHSA-r4m7-9275-xfg3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r4m7-9275-xfg3", + "modified": "2024-10-29T18:30:34Z", + "published": "2024-10-29T18:30:34Z", + "aliases": [ + "CVE-2023-35062" + ], + "details": "Improper access control in some Intel(R) DSA software before version 23.4.33 may allow a privileged user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35062" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00969.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-14T14:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-r922-52fr-4x9g/GHSA-r922-52fr-4x9g.json b/advisories/unreviewed/2024/10/GHSA-r922-52fr-4x9g/GHSA-r922-52fr-4x9g.json index 13fbac112e5..3710e21d622 100644 --- a/advisories/unreviewed/2024/10/GHSA-r922-52fr-4x9g/GHSA-r922-52fr-4x9g.json +++ b/advisories/unreviewed/2024/10/GHSA-r922-52fr-4x9g/GHSA-r922-52fr-4x9g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r922-52fr-4x9g", - "modified": "2024-10-28T21:30:35Z", + "modified": "2024-10-29T18:30:36Z", "published": "2024-10-28T21:30:35Z", "aliases": [ "CVE-2024-44174" ], "details": "The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15. An attacker may be able to view restricted content from the lock screen.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-754" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-28T21:15:05Z" diff --git a/advisories/unreviewed/2024/10/GHSA-rf58-pp6r-5653/GHSA-rf58-pp6r-5653.json b/advisories/unreviewed/2024/10/GHSA-rf58-pp6r-5653/GHSA-rf58-pp6r-5653.json index d5a40eec856..ab332a07814 100644 --- a/advisories/unreviewed/2024/10/GHSA-rf58-pp6r-5653/GHSA-rf58-pp6r-5653.json +++ b/advisories/unreviewed/2024/10/GHSA-rf58-pp6r-5653/GHSA-rf58-pp6r-5653.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rf58-pp6r-5653", - "modified": "2024-10-21T18:30:59Z", + "modified": "2024-10-29T18:30:35Z", "published": "2024-10-21T18:30:59Z", "aliases": [ "CVE-2024-49978" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ngso: fix udp gso fraglist segmentation after pull from frag_list\n\nDetect gso fraglist skbs with corrupted geometry (see below) and\npass these to skb_segment instead of skb_segment_list, as the first\ncan segment them correctly.\n\nValid SKB_GSO_FRAGLIST skbs\n- consist of two or more segments\n- the head_skb holds the protocol headers plus first gso_size\n- one or more frag_list skbs hold exactly one segment\n- all but the last must be gso_size\n\nOptional datapath hooks such as NAT and BPF (bpf_skb_pull_data) can\nmodify these skbs, breaking these invariants.\n\nIn extreme cases they pull all data into skb linear. For UDP, this\ncauses a NULL ptr deref in __udpv4_gso_segment_list_csum at\nudp_hdr(seg->next)->dest.\n\nDetect invalid geometry due to pull, by checking head_skb size.\nDon't just drop, as this may blackhole a destination. Convert to be\nable to pass to regular skb_segment.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T18:15:18Z" diff --git a/advisories/unreviewed/2024/10/GHSA-v2w9-x3m8-jc6p/GHSA-v2w9-x3m8-jc6p.json b/advisories/unreviewed/2024/10/GHSA-v2w9-x3m8-jc6p/GHSA-v2w9-x3m8-jc6p.json new file mode 100644 index 00000000000..5ee78ae2bce --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-v2w9-x3m8-jc6p/GHSA-v2w9-x3m8-jc6p.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v2w9-x3m8-jc6p", + "modified": "2024-10-29T18:30:36Z", + "published": "2024-10-29T18:30:36Z", + "aliases": [ + "CVE-2024-7985" + ], + "details": "The FileOrganizer – Manage WordPress and Website Files plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the \"fileorganizer_ajax_handler\" function in all versions up to, and including, 1.0.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, and permissions granted by an administrator, to upload arbitrary files on the affected site's server which may make remote code execution possible. NOTE: The FileOrganizer Pro plugin must be installed and active to allow Subscriber+ users to upload files.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7985" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/fileorganizer/trunk/main/ajax.php#L13" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3149878" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/f79164c2-be3b-496d-b747-3e4b60b7fc2b?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-29T16:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-v69q-9h68-p7hx/GHSA-v69q-9h68-p7hx.json b/advisories/unreviewed/2024/10/GHSA-v69q-9h68-p7hx/GHSA-v69q-9h68-p7hx.json index 6d23048ef5c..e25fb9e26ba 100644 --- a/advisories/unreviewed/2024/10/GHSA-v69q-9h68-p7hx/GHSA-v69q-9h68-p7hx.json +++ b/advisories/unreviewed/2024/10/GHSA-v69q-9h68-p7hx/GHSA-v69q-9h68-p7hx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v69q-9h68-p7hx", - "modified": "2024-10-28T21:30:35Z", + "modified": "2024-10-29T18:30:36Z", "published": "2024-10-28T21:30:35Z", "aliases": [ "CVE-2024-44155" ], "details": "A custom URL scheme handling issue was addressed with improved input validation. This issue is fixed in Safari 18, iOS 17.7.1 and iPadOS 17.7.1, macOS Sequoia 15, watchOS 11, iOS 18 and iPadOS 18. Maliciously crafted web content may violate iframe sandboxing policy.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -43,7 +46,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-28T21:15:05Z" diff --git a/advisories/unreviewed/2024/10/GHSA-w7w7-6353-385q/GHSA-w7w7-6353-385q.json b/advisories/unreviewed/2024/10/GHSA-w7w7-6353-385q/GHSA-w7w7-6353-385q.json index 2e9ae306394..f66ca642ae5 100644 --- a/advisories/unreviewed/2024/10/GHSA-w7w7-6353-385q/GHSA-w7w7-6353-385q.json +++ b/advisories/unreviewed/2024/10/GHSA-w7w7-6353-385q/GHSA-w7w7-6353-385q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w7w7-6353-385q", - "modified": "2024-10-21T18:30:59Z", + "modified": "2024-10-29T18:30:35Z", "published": "2024-10-21T18:30:59Z", "aliases": [ "CVE-2024-49970" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Implement bounds check for stream encoder creation in DCN401\n\n'stream_enc_regs' array is an array of dcn10_stream_enc_registers\nstructures. The array is initialized with four elements, corresponding\nto the four calls to stream_enc_regs() in the array initializer. This\nmeans that valid indices for this array are 0, 1, 2, and 3.\n\nThe error message 'stream_enc_regs' 4 <= 5 below, is indicating that\nthere is an attempt to access this array with an index of 5, which is\nout of bounds. This could lead to undefined behavior\n\nHere, eng_id is used as an index to access the stream_enc_regs array. If\neng_id is 5, this would result in an out-of-bounds access on the\nstream_enc_regs array.\n\nThus fixing Buffer overflow error in dcn401_stream_encoder_create\n\nFound by smatch:\ndrivers/gpu/drm/amd/amdgpu/../display/dc/resource/dcn401/dcn401_resource.c:1209 dcn401_stream_encoder_create() error: buffer overflow 'stream_enc_regs' 4 <= 5", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-129" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T18:15:17Z" diff --git a/advisories/unreviewed/2024/10/GHSA-w9vp-f95x-pq8m/GHSA-w9vp-f95x-pq8m.json b/advisories/unreviewed/2024/10/GHSA-w9vp-f95x-pq8m/GHSA-w9vp-f95x-pq8m.json new file mode 100644 index 00000000000..b77b2c3c5db --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-w9vp-f95x-pq8m/GHSA-w9vp-f95x-pq8m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w9vp-f95x-pq8m", + "modified": "2024-10-29T18:30:33Z", + "published": "2024-10-29T18:30:33Z", + "aliases": [ + "CVE-2023-25951" + ], + "details": "Improper input validation for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow a privileged user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25951" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00947.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-14T14:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-wfjj-9rr8-m3rh/GHSA-wfjj-9rr8-m3rh.json b/advisories/unreviewed/2024/10/GHSA-wfjj-9rr8-m3rh/GHSA-wfjj-9rr8-m3rh.json index f8d78eb3d94..1ba2288ac04 100644 --- a/advisories/unreviewed/2024/10/GHSA-wfjj-9rr8-m3rh/GHSA-wfjj-9rr8-m3rh.json +++ b/advisories/unreviewed/2024/10/GHSA-wfjj-9rr8-m3rh/GHSA-wfjj-9rr8-m3rh.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-1188" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-x5jw-x6xm-xcgh/GHSA-x5jw-x6xm-xcgh.json b/advisories/unreviewed/2024/10/GHSA-x5jw-x6xm-xcgh/GHSA-x5jw-x6xm-xcgh.json index 14fb4face6d..aa5c9c4a90a 100644 --- a/advisories/unreviewed/2024/10/GHSA-x5jw-x6xm-xcgh/GHSA-x5jw-x6xm-xcgh.json +++ b/advisories/unreviewed/2024/10/GHSA-x5jw-x6xm-xcgh/GHSA-x5jw-x6xm-xcgh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x5jw-x6xm-xcgh", - "modified": "2024-10-28T21:30:35Z", + "modified": "2024-10-29T18:30:36Z", "published": "2024-10-28T21:30:35Z", "aliases": [ "CVE-2024-44126" ], "details": "The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.1, macOS Sequoia 15, iOS 17.7 and iPadOS 17.7, macOS Sonoma 14.7, visionOS 2, iOS 18 and iPadOS 18. Processing a maliciously crafted file may lead to heap corruption.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-28T21:15:05Z" diff --git a/advisories/unreviewed/2024/10/GHSA-xf6c-qw6x-qr69/GHSA-xf6c-qw6x-qr69.json b/advisories/unreviewed/2024/10/GHSA-xf6c-qw6x-qr69/GHSA-xf6c-qw6x-qr69.json index a2537d7d841..c178e9d8222 100644 --- a/advisories/unreviewed/2024/10/GHSA-xf6c-qw6x-qr69/GHSA-xf6c-qw6x-qr69.json +++ b/advisories/unreviewed/2024/10/GHSA-xf6c-qw6x-qr69/GHSA-xf6c-qw6x-qr69.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xf6c-qw6x-qr69", - "modified": "2024-10-28T21:30:34Z", + "modified": "2024-10-29T18:30:36Z", "published": "2024-10-28T21:30:34Z", "aliases": [ "CVE-2024-40851" ], "details": "This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18.1 and iPadOS 18.1. An attacker with physical access may be able to access contact photos from the lock screen.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-28T21:15:04Z" diff --git a/advisories/unreviewed/2024/10/GHSA-xhw3-h8gq-2w23/GHSA-xhw3-h8gq-2w23.json b/advisories/unreviewed/2024/10/GHSA-xhw3-h8gq-2w23/GHSA-xhw3-h8gq-2w23.json index 31175872841..ca646777cd5 100644 --- a/advisories/unreviewed/2024/10/GHSA-xhw3-h8gq-2w23/GHSA-xhw3-h8gq-2w23.json +++ b/advisories/unreviewed/2024/10/GHSA-xhw3-h8gq-2w23/GHSA-xhw3-h8gq-2w23.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xhw3-h8gq-2w23", - "modified": "2024-10-29T15:32:04Z", + "modified": "2024-10-29T18:30:36Z", "published": "2024-10-29T15:32:04Z", "aliases": [ "CVE-2024-10468" ], "details": "Potential race conditions in IndexedDB could have caused memory corruption, leading to a potentially exploitable crash. This vulnerability affects Firefox < 132 and Thunderbird < 132.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-770" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-29T13:15:04Z" diff --git a/advisories/unreviewed/2024/10/GHSA-xrcj-4qfw-rxvm/GHSA-xrcj-4qfw-rxvm.json b/advisories/unreviewed/2024/10/GHSA-xrcj-4qfw-rxvm/GHSA-xrcj-4qfw-rxvm.json new file mode 100644 index 00000000000..204eed0c89e --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-xrcj-4qfw-rxvm/GHSA-xrcj-4qfw-rxvm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xrcj-4qfw-rxvm", + "modified": "2024-10-29T18:30:34Z", + "published": "2024-10-29T18:30:33Z", + "aliases": [ + "CVE-2023-33875" + ], + "details": "Improper access control for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via local access..", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33875" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00947.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-14T14:15:56Z" + } +} \ No newline at end of file