From 2ec055e9127eddef1eff2d3cc4801e6a5883d0b1 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 29 Mar 2023 21:31:31 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-8hg6-g75q-4x9v.json | 9 ++-- .../GHSA-hr98-frg6-wvvr.json | 9 ++-- .../GHSA-j5c8-5345-567f.json | 9 ++-- .../GHSA-x9f6-xw7x-fm76.json | 9 ++-- .../GHSA-24q5-7fw8-5m7f.json | 39 +++++++++++++++ .../GHSA-2523-mx65-hm92.json | 35 ++++++++++++++ .../GHSA-276x-2hgv-3x2j.json | 39 +++++++++++++++ .../GHSA-2797-h4gc-wv56.json | 39 +++++++++++++++ .../GHSA-29cx-mrrh-g7pc.json | 39 +++++++++++++++ .../GHSA-2cpq-6g4r-6726.json | 35 ++++++++++++++ .../GHSA-2jp6-jv62-jw48.json | 39 +++++++++++++++ .../GHSA-2rc8-5vp2-97ch.json | 39 +++++++++++++++ .../GHSA-2rjc-h554-j93w.json | 39 +++++++++++++++ .../GHSA-2v4g-w3qw-prh4.json | 35 ++++++++++++++ .../GHSA-2x7m-w9xq-pcvr.json | 39 +++++++++++++++ .../GHSA-33j8-9xqj-q27p.json | 39 +++++++++++++++ .../GHSA-33jv-5wxr-v6v3.json | 39 +++++++++++++++ .../GHSA-3452-rvwh-rv7h.json | 39 +++++++++++++++ .../GHSA-345m-hwph-xh83.json | 11 +++-- .../GHSA-345r-5qfx-4jpr.json | 35 ++++++++++++++ .../GHSA-366x-2hwp-qq45.json | 39 +++++++++++++++ .../GHSA-3fvg-68xh-vfxq.json | 35 ++++++++++++++ .../GHSA-3m65-86mg-45wp.json | 39 +++++++++++++++ .../GHSA-3rvm-9j83-445h.json | 39 +++++++++++++++ .../GHSA-3wm7-5h33-f92f.json | 35 ++++++++++++++ .../GHSA-43qp-56c9-mg75.json | 39 +++++++++++++++ .../GHSA-446g-ch6r-4m6w.json | 39 +++++++++++++++ .../GHSA-44h9-27pc-757g.json | 35 ++++++++++++++ .../GHSA-48fv-6rrf-3cqx.json | 39 +++++++++++++++ .../GHSA-4f3p-pr3g-6qgf.json | 35 ++++++++++++++ .../GHSA-4fg6-p758-85rf.json | 39 +++++++++++++++ .../GHSA-4fp9-g9rc-jhf3.json | 39 +++++++++++++++ .../GHSA-4fpc-4gp5-rfgp.json | 39 +++++++++++++++ .../GHSA-4gp8-394w-2vcg.json | 35 ++++++++++++++ .../GHSA-4j42-3rxm-869g.json | 39 +++++++++++++++ .../GHSA-4j4g-x85c-8f36.json | 39 +++++++++++++++ .../GHSA-4mfr-5g26-5m2m.json | 39 +++++++++++++++ .../GHSA-4rpc-xhhq-h2cq.json | 35 ++++++++++++++ .../GHSA-4rxf-rcjh-42f3.json | 39 +++++++++++++++ .../GHSA-52w8-9f8q-6r2v.json | 11 +++-- .../GHSA-54c2-w283-x9w8.json | 35 ++++++++++++++ .../GHSA-567x-fp72-xh2g.json | 35 ++++++++++++++ .../GHSA-5hm2-2whx-4749.json | 35 ++++++++++++++ .../GHSA-5pmp-c2mf-mxm4.json | 35 ++++++++++++++ .../GHSA-5v3q-vvmp-5xfx.json | 39 +++++++++++++++ .../GHSA-5w68-r965-r3m3.json | 35 ++++++++++++++ .../GHSA-5xp2-x7qr-wjrx.json | 39 +++++++++++++++ .../GHSA-5xr5-9vfx-374w.json | 35 ++++++++++++++ .../GHSA-64p4-gjjq-76rf.json | 39 +++++++++++++++ .../GHSA-65gj-57wq-hhwj.json | 39 +++++++++++++++ .../GHSA-65qp-9jcx-88ff.json | 39 +++++++++++++++ .../GHSA-6626-mmrw-83qj.json | 39 +++++++++++++++ .../GHSA-6fx6-mv6x-h475.json | 39 +++++++++++++++ .../GHSA-6gg3-r538-67r7.json | 35 ++++++++++++++ .../GHSA-6gpc-qw5q-frjv.json | 35 ++++++++++++++ .../GHSA-6hc2-h64w-g96p.json | 35 ++++++++++++++ .../GHSA-6hpv-3vxv-xp2r.json | 39 +++++++++++++++ .../GHSA-6j74-p6h3-8g44.json | 39 +++++++++++++++ .../GHSA-6pqf-hr2v-2788.json | 11 +++-- .../GHSA-6rww-x4m5-6j62.json | 39 +++++++++++++++ .../GHSA-725m-2qgr-hprx.json | 11 +++-- .../GHSA-743r-m8c7-27h7.json | 39 +++++++++++++++ .../GHSA-7fhj-9wp7-2477.json | 11 +++-- .../GHSA-7h5h-fqwm-4g32.json | 35 ++++++++++++++ .../GHSA-7pr7-x6mw-h647.json | 39 +++++++++++++++ .../GHSA-7vjm-f76c-4jgr.json | 35 ++++++++++++++ .../GHSA-7w2q-74wh-62qq.json | 35 ++++++++++++++ .../GHSA-83cq-237j-2w54.json | 39 +++++++++++++++ .../GHSA-88v9-2vvv-pvwv.json | 39 +++++++++++++++ .../GHSA-88wg-fvch-429c.json | 39 +++++++++++++++ .../GHSA-8c56-mh3f-3268.json | 39 +++++++++++++++ .../GHSA-8cf2-943h-fh5p.json | 35 ++++++++++++++ .../GHSA-93g9-xjvr-89v9.json | 39 +++++++++++++++ .../GHSA-93vf-fhrw-pvpj.json | 39 +++++++++++++++ .../GHSA-94w7-67qp-92gp.json | 39 +++++++++++++++ .../GHSA-95x2-jpfx-6c98.json | 39 +++++++++++++++ .../GHSA-962c-q54j-xg6v.json | 39 +++++++++++++++ .../GHSA-98fh-32qc-74hp.json | 35 ++++++++++++++ .../GHSA-9922-6549-73mx.json | 39 +++++++++++++++ .../GHSA-9cp7-c9w3-64vv.json | 39 +++++++++++++++ .../GHSA-9qp4-g72v-v5g9.json | 11 +++-- .../GHSA-c2jq-8332-fm87.json | 39 +++++++++++++++ .../GHSA-c459-crcf-rfqh.json | 35 ++++++++++++++ .../GHSA-c7f3-g9w9-wqqq.json | 39 +++++++++++++++ .../GHSA-cf44-xc9w-h3q8.json | 39 +++++++++++++++ .../GHSA-cjvg-rm6v-pgjg.json | 39 +++++++++++++++ .../GHSA-cp8x-fmj3-2w9f.json | 39 +++++++++++++++ .../GHSA-cv64-ghcf-rjjj.json | 39 +++++++++++++++ .../GHSA-cvhp-xfvg-rr6v.json | 39 +++++++++++++++ .../GHSA-cxfw-2mm4-92m9.json | 39 +++++++++++++++ .../GHSA-f5hr-hqp7-c2qw.json | 39 +++++++++++++++ .../GHSA-f6pf-7qx7-fg5m.json | 39 +++++++++++++++ .../GHSA-f952-wvmx-6w24.json | 39 +++++++++++++++ .../GHSA-f9v3-rvrm-52r5.json | 35 ++++++++++++++ .../GHSA-f9vp-qm5c-2255.json | 39 +++++++++++++++ .../GHSA-fff6-82fr-q9xp.json | 39 +++++++++++++++ .../GHSA-fh4c-rwgp-mc5v.json | 35 ++++++++++++++ .../GHSA-fjv7-v9cp-p3jq.json | 39 +++++++++++++++ .../GHSA-fq3j-rpjj-667v.json | 39 +++++++++++++++ .../GHSA-frrc-f75h-9j62.json | 35 ++++++++++++++ .../GHSA-fv8v-x6r7-4jm8.json | 39 +++++++++++++++ .../GHSA-fvpr-q9j2-9vq7.json | 39 +++++++++++++++ .../GHSA-fwj9-7qq8-jc93.json | 39 +++++++++++++++ .../GHSA-g594-6376-7c5r.json | 35 ++++++++++++++ .../GHSA-g5fp-qxxg-w295.json | 39 +++++++++++++++ .../GHSA-g995-wpvr-c8gv.json | 39 +++++++++++++++ .../GHSA-gcjr-346m-7x54.json | 35 ++++++++++++++ .../GHSA-gh4v-v2hh-g9m6.json | 39 +++++++++++++++ .../GHSA-ghqp-75mj-j4x8.json | 35 ++++++++++++++ .../GHSA-gm89-j9wr-p8rw.json | 39 +++++++++++++++ .../GHSA-gm9h-jqqh-9434.json | 39 +++++++++++++++ .../GHSA-gm9p-w68v-q8rp.json | 39 +++++++++++++++ .../GHSA-gqv3-mwv7-3fg9.json | 39 +++++++++++++++ .../GHSA-h3mx-pc7w-4qh2.json | 11 +++-- .../GHSA-h75r-g3wx-p3m3.json | 39 +++++++++++++++ .../GHSA-h8wj-xxvx-cv2r.json | 39 +++++++++++++++ .../GHSA-h9h8-v9p8-wfqp.json | 11 +++-- .../GHSA-hg7f-vxww-gm23.json | 39 +++++++++++++++ .../GHSA-hgmf-x9rw-2cf9.json | 39 +++++++++++++++ .../GHSA-hx4j-3826-jwrv.json | 11 +++-- .../GHSA-j6jr-7hqv-4mp7.json | 35 ++++++++++++++ .../GHSA-j6p3-mvwv-6qc2.json | 39 +++++++++++++++ .../GHSA-j9gx-w67p-w37r.json | 39 +++++++++++++++ .../GHSA-jf9h-v46r-899c.json | 39 +++++++++++++++ .../GHSA-jfmw-22wh-9p3p.json | 39 +++++++++++++++ .../GHSA-jhgx-rh52-857w.json | 39 +++++++++++++++ .../GHSA-jhq5-5c6h-9xj2.json | 35 ++++++++++++++ .../GHSA-jmxp-55h2-rg35.json | 35 ++++++++++++++ .../GHSA-jr7h-mp2v-g8f4.json | 39 +++++++++++++++ .../GHSA-jv3h-vgc4-3286.json | 39 +++++++++++++++ .../GHSA-jvgw-wcf7-8qhm.json | 39 +++++++++++++++ .../GHSA-jvxm-jqvh-vw8w.json | 35 ++++++++++++++ .../GHSA-jw63-hmqg-58g3.json | 9 ++-- .../GHSA-m46g-8pc6-m8q7.json | 35 ++++++++++++++ .../GHSA-m5q4-m78h-xjw6.json | 39 +++++++++++++++ .../GHSA-m68p-4w8c-8x3r.json | 39 +++++++++++++++ .../GHSA-m8f7-5xcg-535x.json | 39 +++++++++++++++ .../GHSA-mfh4-7734-777j.json | 39 +++++++++++++++ .../GHSA-mj95-c6pq-6cm4.json | 11 +++-- .../GHSA-mp6x-jhfm-fxfq.json | 39 +++++++++++++++ .../GHSA-mpcg-2wq2-r3hq.json | 39 +++++++++++++++ .../GHSA-mqp9-5m4c-g7f8.json | 39 +++++++++++++++ .../GHSA-mrcj-939x-ph52.json | 39 +++++++++++++++ .../GHSA-mvgg-p48p-h9jc.json | 47 +++++++++++++++++++ .../GHSA-mw6v-8jv9-7qrx.json | 39 +++++++++++++++ .../GHSA-mwjw-gjjg-g95f.json | 35 ++++++++++++++ .../GHSA-p658-968w-vm74.json | 39 +++++++++++++++ .../GHSA-p682-rxp7-r33h.json | 39 +++++++++++++++ .../GHSA-p7pc-qwg6-498g.json | 39 +++++++++++++++ .../GHSA-pc9v-3h75-cp72.json | 39 +++++++++++++++ .../GHSA-pcgm-9vcp-6328.json | 39 +++++++++++++++ .../GHSA-pmq2-7wm2-2j2f.json | 39 +++++++++++++++ .../GHSA-pp2x-h7r9-38wv.json | 11 +++-- .../GHSA-pqjj-qjgj-f2x9.json | 39 +++++++++++++++ .../GHSA-pvmm-fgf7-r833.json | 35 ++++++++++++++ .../GHSA-pwcm-gxw7-h8mv.json | 39 +++++++++++++++ .../GHSA-pwmj-ff87-vjpm.json | 39 +++++++++++++++ .../GHSA-pxwx-g88v-cm98.json | 39 +++++++++++++++ .../GHSA-q3c4-7524-h583.json | 35 ++++++++++++++ .../GHSA-q3j9-7mrh-5qq4.json | 11 +++-- .../GHSA-q653-fx3f-vxx7.json | 39 +++++++++++++++ .../GHSA-q74r-2mgj-gmf6.json | 11 +++-- .../GHSA-qfj3-4fxc-mgvr.json | 39 +++++++++++++++ .../GHSA-qfr3-mfc8-5fjx.json | 11 +++-- .../GHSA-qgxc-q43p-rg2r.json | 35 ++++++++++++++ .../GHSA-qjg8-7gjq-vxf4.json | 39 +++++++++++++++ .../GHSA-qp65-hwv9-52vm.json | 39 +++++++++++++++ .../GHSA-qw23-6j7v-fhg8.json | 39 +++++++++++++++ .../GHSA-qw7p-6f7c-jj4p.json | 39 +++++++++++++++ .../GHSA-r3gj-5f62-vgx7.json | 39 +++++++++++++++ .../GHSA-r4rc-5jf7-j8p4.json | 11 +++-- .../GHSA-r8vp-qh3v-5wfc.json | 35 ++++++++++++++ .../GHSA-r95g-66gf-3xc2.json | 39 +++++++++++++++ .../GHSA-rgfh-fr7j-cfww.json | 39 +++++++++++++++ .../GHSA-rh28-jmpq-2rm5.json | 39 +++++++++++++++ .../GHSA-rh4w-wj5p-5r32.json | 39 +++++++++++++++ .../GHSA-rpfj-c47q-c8m4.json | 39 +++++++++++++++ .../GHSA-rq4q-fjxh-vjg3.json | 39 +++++++++++++++ .../GHSA-rr78-v2mc-p2mp.json | 39 +++++++++++++++ .../GHSA-rrfg-8crh-5vmr.json | 35 ++++++++++++++ .../GHSA-rvc6-cvq7-4g2q.json | 39 +++++++++++++++ .../GHSA-rx2p-774w-85jc.json | 39 +++++++++++++++ .../GHSA-rxmx-w44h-9gvh.json | 39 +++++++++++++++ .../GHSA-v452-7f7v-7m7q.json | 39 +++++++++++++++ .../GHSA-v594-5w2m-322p.json | 39 +++++++++++++++ .../GHSA-vc38-hp22-mh4x.json | 35 ++++++++++++++ .../GHSA-vc68-vpf2-7xq5.json | 39 +++++++++++++++ .../GHSA-vg6v-qwqm-x96m.json | 39 +++++++++++++++ .../GHSA-vhc5-85r7-whv3.json | 39 +++++++++++++++ .../GHSA-vr6q-6f35-6fpc.json | 39 +++++++++++++++ .../GHSA-vrcj-9qv3-hv75.json | 11 +++-- .../GHSA-vrvf-x4g2-cx9g.json | 39 +++++++++++++++ .../GHSA-w2w6-xp88-5cvw.json | 11 +++-- .../GHSA-w472-7q22-qfjx.json | 39 +++++++++++++++ .../GHSA-w7wq-mfjm-crgc.json | 35 ++++++++++++++ .../GHSA-w94x-h737-f6h9.json | 39 +++++++++++++++ .../GHSA-wc7c-x2x3-w322.json | 39 +++++++++++++++ .../GHSA-wccm-69w3-xxcw.json | 39 +++++++++++++++ .../GHSA-wf6j-p2w6-h539.json | 39 +++++++++++++++ .../GHSA-wfpr-8m9q-hrr8.json | 39 +++++++++++++++ .../GHSA-wgqg-7gcr-3hm8.json | 11 +++-- .../GHSA-wj78-xrp7-jrhr.json | 39 +++++++++++++++ .../GHSA-wjw4-2695-6mj3.json | 39 +++++++++++++++ .../GHSA-wvf6-6fcj-rrxv.json | 39 +++++++++++++++ .../GHSA-x255-79xw-5565.json | 11 +++-- .../GHSA-xf7f-g3ff-jjc9.json | 35 ++++++++++++++ .../GHSA-xhfw-qhxr-hjhq.json | 35 ++++++++++++++ .../GHSA-xv6g-6g23-79w2.json | 39 +++++++++++++++ .../GHSA-xw54-w9r2-97q7.json | 35 ++++++++++++++ .../GHSA-xxch-mf4j-qcvj.json | 4 ++ 210 files changed, 7202 insertions(+), 91 deletions(-) create mode 100644 advisories/unreviewed/2023/03/GHSA-24q5-7fw8-5m7f/GHSA-24q5-7fw8-5m7f.json create mode 100644 advisories/unreviewed/2023/03/GHSA-2523-mx65-hm92/GHSA-2523-mx65-hm92.json create mode 100644 advisories/unreviewed/2023/03/GHSA-276x-2hgv-3x2j/GHSA-276x-2hgv-3x2j.json create mode 100644 advisories/unreviewed/2023/03/GHSA-2797-h4gc-wv56/GHSA-2797-h4gc-wv56.json create mode 100644 advisories/unreviewed/2023/03/GHSA-29cx-mrrh-g7pc/GHSA-29cx-mrrh-g7pc.json create mode 100644 advisories/unreviewed/2023/03/GHSA-2cpq-6g4r-6726/GHSA-2cpq-6g4r-6726.json create mode 100644 advisories/unreviewed/2023/03/GHSA-2jp6-jv62-jw48/GHSA-2jp6-jv62-jw48.json create mode 100644 advisories/unreviewed/2023/03/GHSA-2rc8-5vp2-97ch/GHSA-2rc8-5vp2-97ch.json create mode 100644 advisories/unreviewed/2023/03/GHSA-2rjc-h554-j93w/GHSA-2rjc-h554-j93w.json create mode 100644 advisories/unreviewed/2023/03/GHSA-2v4g-w3qw-prh4/GHSA-2v4g-w3qw-prh4.json create mode 100644 advisories/unreviewed/2023/03/GHSA-2x7m-w9xq-pcvr/GHSA-2x7m-w9xq-pcvr.json create mode 100644 advisories/unreviewed/2023/03/GHSA-33j8-9xqj-q27p/GHSA-33j8-9xqj-q27p.json create mode 100644 advisories/unreviewed/2023/03/GHSA-33jv-5wxr-v6v3/GHSA-33jv-5wxr-v6v3.json create mode 100644 advisories/unreviewed/2023/03/GHSA-3452-rvwh-rv7h/GHSA-3452-rvwh-rv7h.json create mode 100644 advisories/unreviewed/2023/03/GHSA-345r-5qfx-4jpr/GHSA-345r-5qfx-4jpr.json create mode 100644 advisories/unreviewed/2023/03/GHSA-366x-2hwp-qq45/GHSA-366x-2hwp-qq45.json create mode 100644 advisories/unreviewed/2023/03/GHSA-3fvg-68xh-vfxq/GHSA-3fvg-68xh-vfxq.json create mode 100644 advisories/unreviewed/2023/03/GHSA-3m65-86mg-45wp/GHSA-3m65-86mg-45wp.json create mode 100644 advisories/unreviewed/2023/03/GHSA-3rvm-9j83-445h/GHSA-3rvm-9j83-445h.json create mode 100644 advisories/unreviewed/2023/03/GHSA-3wm7-5h33-f92f/GHSA-3wm7-5h33-f92f.json create mode 100644 advisories/unreviewed/2023/03/GHSA-43qp-56c9-mg75/GHSA-43qp-56c9-mg75.json create mode 100644 advisories/unreviewed/2023/03/GHSA-446g-ch6r-4m6w/GHSA-446g-ch6r-4m6w.json create mode 100644 advisories/unreviewed/2023/03/GHSA-44h9-27pc-757g/GHSA-44h9-27pc-757g.json create mode 100644 advisories/unreviewed/2023/03/GHSA-48fv-6rrf-3cqx/GHSA-48fv-6rrf-3cqx.json create mode 100644 advisories/unreviewed/2023/03/GHSA-4f3p-pr3g-6qgf/GHSA-4f3p-pr3g-6qgf.json create mode 100644 advisories/unreviewed/2023/03/GHSA-4fg6-p758-85rf/GHSA-4fg6-p758-85rf.json create mode 100644 advisories/unreviewed/2023/03/GHSA-4fp9-g9rc-jhf3/GHSA-4fp9-g9rc-jhf3.json create mode 100644 advisories/unreviewed/2023/03/GHSA-4fpc-4gp5-rfgp/GHSA-4fpc-4gp5-rfgp.json create mode 100644 advisories/unreviewed/2023/03/GHSA-4gp8-394w-2vcg/GHSA-4gp8-394w-2vcg.json create mode 100644 advisories/unreviewed/2023/03/GHSA-4j42-3rxm-869g/GHSA-4j42-3rxm-869g.json create mode 100644 advisories/unreviewed/2023/03/GHSA-4j4g-x85c-8f36/GHSA-4j4g-x85c-8f36.json create mode 100644 advisories/unreviewed/2023/03/GHSA-4mfr-5g26-5m2m/GHSA-4mfr-5g26-5m2m.json create mode 100644 advisories/unreviewed/2023/03/GHSA-4rpc-xhhq-h2cq/GHSA-4rpc-xhhq-h2cq.json create mode 100644 advisories/unreviewed/2023/03/GHSA-4rxf-rcjh-42f3/GHSA-4rxf-rcjh-42f3.json create mode 100644 advisories/unreviewed/2023/03/GHSA-54c2-w283-x9w8/GHSA-54c2-w283-x9w8.json create mode 100644 advisories/unreviewed/2023/03/GHSA-567x-fp72-xh2g/GHSA-567x-fp72-xh2g.json create mode 100644 advisories/unreviewed/2023/03/GHSA-5hm2-2whx-4749/GHSA-5hm2-2whx-4749.json create mode 100644 advisories/unreviewed/2023/03/GHSA-5pmp-c2mf-mxm4/GHSA-5pmp-c2mf-mxm4.json create mode 100644 advisories/unreviewed/2023/03/GHSA-5v3q-vvmp-5xfx/GHSA-5v3q-vvmp-5xfx.json create mode 100644 advisories/unreviewed/2023/03/GHSA-5w68-r965-r3m3/GHSA-5w68-r965-r3m3.json create mode 100644 advisories/unreviewed/2023/03/GHSA-5xp2-x7qr-wjrx/GHSA-5xp2-x7qr-wjrx.json create mode 100644 advisories/unreviewed/2023/03/GHSA-5xr5-9vfx-374w/GHSA-5xr5-9vfx-374w.json create mode 100644 advisories/unreviewed/2023/03/GHSA-64p4-gjjq-76rf/GHSA-64p4-gjjq-76rf.json create mode 100644 advisories/unreviewed/2023/03/GHSA-65gj-57wq-hhwj/GHSA-65gj-57wq-hhwj.json create mode 100644 advisories/unreviewed/2023/03/GHSA-65qp-9jcx-88ff/GHSA-65qp-9jcx-88ff.json create mode 100644 advisories/unreviewed/2023/03/GHSA-6626-mmrw-83qj/GHSA-6626-mmrw-83qj.json create mode 100644 advisories/unreviewed/2023/03/GHSA-6fx6-mv6x-h475/GHSA-6fx6-mv6x-h475.json create mode 100644 advisories/unreviewed/2023/03/GHSA-6gg3-r538-67r7/GHSA-6gg3-r538-67r7.json create mode 100644 advisories/unreviewed/2023/03/GHSA-6gpc-qw5q-frjv/GHSA-6gpc-qw5q-frjv.json create mode 100644 advisories/unreviewed/2023/03/GHSA-6hc2-h64w-g96p/GHSA-6hc2-h64w-g96p.json create mode 100644 advisories/unreviewed/2023/03/GHSA-6hpv-3vxv-xp2r/GHSA-6hpv-3vxv-xp2r.json create mode 100644 advisories/unreviewed/2023/03/GHSA-6j74-p6h3-8g44/GHSA-6j74-p6h3-8g44.json create mode 100644 advisories/unreviewed/2023/03/GHSA-6rww-x4m5-6j62/GHSA-6rww-x4m5-6j62.json create mode 100644 advisories/unreviewed/2023/03/GHSA-743r-m8c7-27h7/GHSA-743r-m8c7-27h7.json create mode 100644 advisories/unreviewed/2023/03/GHSA-7h5h-fqwm-4g32/GHSA-7h5h-fqwm-4g32.json create mode 100644 advisories/unreviewed/2023/03/GHSA-7pr7-x6mw-h647/GHSA-7pr7-x6mw-h647.json create mode 100644 advisories/unreviewed/2023/03/GHSA-7vjm-f76c-4jgr/GHSA-7vjm-f76c-4jgr.json create mode 100644 advisories/unreviewed/2023/03/GHSA-7w2q-74wh-62qq/GHSA-7w2q-74wh-62qq.json create mode 100644 advisories/unreviewed/2023/03/GHSA-83cq-237j-2w54/GHSA-83cq-237j-2w54.json create mode 100644 advisories/unreviewed/2023/03/GHSA-88v9-2vvv-pvwv/GHSA-88v9-2vvv-pvwv.json create mode 100644 advisories/unreviewed/2023/03/GHSA-88wg-fvch-429c/GHSA-88wg-fvch-429c.json create mode 100644 advisories/unreviewed/2023/03/GHSA-8c56-mh3f-3268/GHSA-8c56-mh3f-3268.json create mode 100644 advisories/unreviewed/2023/03/GHSA-8cf2-943h-fh5p/GHSA-8cf2-943h-fh5p.json create mode 100644 advisories/unreviewed/2023/03/GHSA-93g9-xjvr-89v9/GHSA-93g9-xjvr-89v9.json create mode 100644 advisories/unreviewed/2023/03/GHSA-93vf-fhrw-pvpj/GHSA-93vf-fhrw-pvpj.json create mode 100644 advisories/unreviewed/2023/03/GHSA-94w7-67qp-92gp/GHSA-94w7-67qp-92gp.json create mode 100644 advisories/unreviewed/2023/03/GHSA-95x2-jpfx-6c98/GHSA-95x2-jpfx-6c98.json create mode 100644 advisories/unreviewed/2023/03/GHSA-962c-q54j-xg6v/GHSA-962c-q54j-xg6v.json create mode 100644 advisories/unreviewed/2023/03/GHSA-98fh-32qc-74hp/GHSA-98fh-32qc-74hp.json create mode 100644 advisories/unreviewed/2023/03/GHSA-9922-6549-73mx/GHSA-9922-6549-73mx.json create mode 100644 advisories/unreviewed/2023/03/GHSA-9cp7-c9w3-64vv/GHSA-9cp7-c9w3-64vv.json create mode 100644 advisories/unreviewed/2023/03/GHSA-c2jq-8332-fm87/GHSA-c2jq-8332-fm87.json create mode 100644 advisories/unreviewed/2023/03/GHSA-c459-crcf-rfqh/GHSA-c459-crcf-rfqh.json create mode 100644 advisories/unreviewed/2023/03/GHSA-c7f3-g9w9-wqqq/GHSA-c7f3-g9w9-wqqq.json create mode 100644 advisories/unreviewed/2023/03/GHSA-cf44-xc9w-h3q8/GHSA-cf44-xc9w-h3q8.json create mode 100644 advisories/unreviewed/2023/03/GHSA-cjvg-rm6v-pgjg/GHSA-cjvg-rm6v-pgjg.json create mode 100644 advisories/unreviewed/2023/03/GHSA-cp8x-fmj3-2w9f/GHSA-cp8x-fmj3-2w9f.json create mode 100644 advisories/unreviewed/2023/03/GHSA-cv64-ghcf-rjjj/GHSA-cv64-ghcf-rjjj.json create mode 100644 advisories/unreviewed/2023/03/GHSA-cvhp-xfvg-rr6v/GHSA-cvhp-xfvg-rr6v.json create mode 100644 advisories/unreviewed/2023/03/GHSA-cxfw-2mm4-92m9/GHSA-cxfw-2mm4-92m9.json create mode 100644 advisories/unreviewed/2023/03/GHSA-f5hr-hqp7-c2qw/GHSA-f5hr-hqp7-c2qw.json create mode 100644 advisories/unreviewed/2023/03/GHSA-f6pf-7qx7-fg5m/GHSA-f6pf-7qx7-fg5m.json create mode 100644 advisories/unreviewed/2023/03/GHSA-f952-wvmx-6w24/GHSA-f952-wvmx-6w24.json create mode 100644 advisories/unreviewed/2023/03/GHSA-f9v3-rvrm-52r5/GHSA-f9v3-rvrm-52r5.json create mode 100644 advisories/unreviewed/2023/03/GHSA-f9vp-qm5c-2255/GHSA-f9vp-qm5c-2255.json create mode 100644 advisories/unreviewed/2023/03/GHSA-fff6-82fr-q9xp/GHSA-fff6-82fr-q9xp.json create mode 100644 advisories/unreviewed/2023/03/GHSA-fh4c-rwgp-mc5v/GHSA-fh4c-rwgp-mc5v.json create mode 100644 advisories/unreviewed/2023/03/GHSA-fjv7-v9cp-p3jq/GHSA-fjv7-v9cp-p3jq.json create mode 100644 advisories/unreviewed/2023/03/GHSA-fq3j-rpjj-667v/GHSA-fq3j-rpjj-667v.json create mode 100644 advisories/unreviewed/2023/03/GHSA-frrc-f75h-9j62/GHSA-frrc-f75h-9j62.json create mode 100644 advisories/unreviewed/2023/03/GHSA-fv8v-x6r7-4jm8/GHSA-fv8v-x6r7-4jm8.json create mode 100644 advisories/unreviewed/2023/03/GHSA-fvpr-q9j2-9vq7/GHSA-fvpr-q9j2-9vq7.json create mode 100644 advisories/unreviewed/2023/03/GHSA-fwj9-7qq8-jc93/GHSA-fwj9-7qq8-jc93.json create mode 100644 advisories/unreviewed/2023/03/GHSA-g594-6376-7c5r/GHSA-g594-6376-7c5r.json create mode 100644 advisories/unreviewed/2023/03/GHSA-g5fp-qxxg-w295/GHSA-g5fp-qxxg-w295.json create mode 100644 advisories/unreviewed/2023/03/GHSA-g995-wpvr-c8gv/GHSA-g995-wpvr-c8gv.json create mode 100644 advisories/unreviewed/2023/03/GHSA-gcjr-346m-7x54/GHSA-gcjr-346m-7x54.json create mode 100644 advisories/unreviewed/2023/03/GHSA-gh4v-v2hh-g9m6/GHSA-gh4v-v2hh-g9m6.json create mode 100644 advisories/unreviewed/2023/03/GHSA-ghqp-75mj-j4x8/GHSA-ghqp-75mj-j4x8.json create mode 100644 advisories/unreviewed/2023/03/GHSA-gm89-j9wr-p8rw/GHSA-gm89-j9wr-p8rw.json create mode 100644 advisories/unreviewed/2023/03/GHSA-gm9h-jqqh-9434/GHSA-gm9h-jqqh-9434.json create mode 100644 advisories/unreviewed/2023/03/GHSA-gm9p-w68v-q8rp/GHSA-gm9p-w68v-q8rp.json create mode 100644 advisories/unreviewed/2023/03/GHSA-gqv3-mwv7-3fg9/GHSA-gqv3-mwv7-3fg9.json create mode 100644 advisories/unreviewed/2023/03/GHSA-h75r-g3wx-p3m3/GHSA-h75r-g3wx-p3m3.json create mode 100644 advisories/unreviewed/2023/03/GHSA-h8wj-xxvx-cv2r/GHSA-h8wj-xxvx-cv2r.json create mode 100644 advisories/unreviewed/2023/03/GHSA-hg7f-vxww-gm23/GHSA-hg7f-vxww-gm23.json create mode 100644 advisories/unreviewed/2023/03/GHSA-hgmf-x9rw-2cf9/GHSA-hgmf-x9rw-2cf9.json create mode 100644 advisories/unreviewed/2023/03/GHSA-j6jr-7hqv-4mp7/GHSA-j6jr-7hqv-4mp7.json create mode 100644 advisories/unreviewed/2023/03/GHSA-j6p3-mvwv-6qc2/GHSA-j6p3-mvwv-6qc2.json create mode 100644 advisories/unreviewed/2023/03/GHSA-j9gx-w67p-w37r/GHSA-j9gx-w67p-w37r.json create mode 100644 advisories/unreviewed/2023/03/GHSA-jf9h-v46r-899c/GHSA-jf9h-v46r-899c.json create mode 100644 advisories/unreviewed/2023/03/GHSA-jfmw-22wh-9p3p/GHSA-jfmw-22wh-9p3p.json create mode 100644 advisories/unreviewed/2023/03/GHSA-jhgx-rh52-857w/GHSA-jhgx-rh52-857w.json create mode 100644 advisories/unreviewed/2023/03/GHSA-jhq5-5c6h-9xj2/GHSA-jhq5-5c6h-9xj2.json create mode 100644 advisories/unreviewed/2023/03/GHSA-jmxp-55h2-rg35/GHSA-jmxp-55h2-rg35.json create mode 100644 advisories/unreviewed/2023/03/GHSA-jr7h-mp2v-g8f4/GHSA-jr7h-mp2v-g8f4.json create mode 100644 advisories/unreviewed/2023/03/GHSA-jv3h-vgc4-3286/GHSA-jv3h-vgc4-3286.json create mode 100644 advisories/unreviewed/2023/03/GHSA-jvgw-wcf7-8qhm/GHSA-jvgw-wcf7-8qhm.json create mode 100644 advisories/unreviewed/2023/03/GHSA-jvxm-jqvh-vw8w/GHSA-jvxm-jqvh-vw8w.json create mode 100644 advisories/unreviewed/2023/03/GHSA-m46g-8pc6-m8q7/GHSA-m46g-8pc6-m8q7.json create mode 100644 advisories/unreviewed/2023/03/GHSA-m5q4-m78h-xjw6/GHSA-m5q4-m78h-xjw6.json create mode 100644 advisories/unreviewed/2023/03/GHSA-m68p-4w8c-8x3r/GHSA-m68p-4w8c-8x3r.json create mode 100644 advisories/unreviewed/2023/03/GHSA-m8f7-5xcg-535x/GHSA-m8f7-5xcg-535x.json create mode 100644 advisories/unreviewed/2023/03/GHSA-mfh4-7734-777j/GHSA-mfh4-7734-777j.json create mode 100644 advisories/unreviewed/2023/03/GHSA-mp6x-jhfm-fxfq/GHSA-mp6x-jhfm-fxfq.json create mode 100644 advisories/unreviewed/2023/03/GHSA-mpcg-2wq2-r3hq/GHSA-mpcg-2wq2-r3hq.json create mode 100644 advisories/unreviewed/2023/03/GHSA-mqp9-5m4c-g7f8/GHSA-mqp9-5m4c-g7f8.json create mode 100644 advisories/unreviewed/2023/03/GHSA-mrcj-939x-ph52/GHSA-mrcj-939x-ph52.json create mode 100644 advisories/unreviewed/2023/03/GHSA-mvgg-p48p-h9jc/GHSA-mvgg-p48p-h9jc.json create mode 100644 advisories/unreviewed/2023/03/GHSA-mw6v-8jv9-7qrx/GHSA-mw6v-8jv9-7qrx.json create mode 100644 advisories/unreviewed/2023/03/GHSA-mwjw-gjjg-g95f/GHSA-mwjw-gjjg-g95f.json create mode 100644 advisories/unreviewed/2023/03/GHSA-p658-968w-vm74/GHSA-p658-968w-vm74.json create mode 100644 advisories/unreviewed/2023/03/GHSA-p682-rxp7-r33h/GHSA-p682-rxp7-r33h.json create mode 100644 advisories/unreviewed/2023/03/GHSA-p7pc-qwg6-498g/GHSA-p7pc-qwg6-498g.json create mode 100644 advisories/unreviewed/2023/03/GHSA-pc9v-3h75-cp72/GHSA-pc9v-3h75-cp72.json create mode 100644 advisories/unreviewed/2023/03/GHSA-pcgm-9vcp-6328/GHSA-pcgm-9vcp-6328.json create mode 100644 advisories/unreviewed/2023/03/GHSA-pmq2-7wm2-2j2f/GHSA-pmq2-7wm2-2j2f.json create mode 100644 advisories/unreviewed/2023/03/GHSA-pqjj-qjgj-f2x9/GHSA-pqjj-qjgj-f2x9.json create mode 100644 advisories/unreviewed/2023/03/GHSA-pvmm-fgf7-r833/GHSA-pvmm-fgf7-r833.json create mode 100644 advisories/unreviewed/2023/03/GHSA-pwcm-gxw7-h8mv/GHSA-pwcm-gxw7-h8mv.json create mode 100644 advisories/unreviewed/2023/03/GHSA-pwmj-ff87-vjpm/GHSA-pwmj-ff87-vjpm.json create mode 100644 advisories/unreviewed/2023/03/GHSA-pxwx-g88v-cm98/GHSA-pxwx-g88v-cm98.json create mode 100644 advisories/unreviewed/2023/03/GHSA-q3c4-7524-h583/GHSA-q3c4-7524-h583.json create mode 100644 advisories/unreviewed/2023/03/GHSA-q653-fx3f-vxx7/GHSA-q653-fx3f-vxx7.json create mode 100644 advisories/unreviewed/2023/03/GHSA-qfj3-4fxc-mgvr/GHSA-qfj3-4fxc-mgvr.json create mode 100644 advisories/unreviewed/2023/03/GHSA-qgxc-q43p-rg2r/GHSA-qgxc-q43p-rg2r.json create mode 100644 advisories/unreviewed/2023/03/GHSA-qjg8-7gjq-vxf4/GHSA-qjg8-7gjq-vxf4.json create mode 100644 advisories/unreviewed/2023/03/GHSA-qp65-hwv9-52vm/GHSA-qp65-hwv9-52vm.json create mode 100644 advisories/unreviewed/2023/03/GHSA-qw23-6j7v-fhg8/GHSA-qw23-6j7v-fhg8.json create mode 100644 advisories/unreviewed/2023/03/GHSA-qw7p-6f7c-jj4p/GHSA-qw7p-6f7c-jj4p.json create mode 100644 advisories/unreviewed/2023/03/GHSA-r3gj-5f62-vgx7/GHSA-r3gj-5f62-vgx7.json create mode 100644 advisories/unreviewed/2023/03/GHSA-r8vp-qh3v-5wfc/GHSA-r8vp-qh3v-5wfc.json create mode 100644 advisories/unreviewed/2023/03/GHSA-r95g-66gf-3xc2/GHSA-r95g-66gf-3xc2.json create mode 100644 advisories/unreviewed/2023/03/GHSA-rgfh-fr7j-cfww/GHSA-rgfh-fr7j-cfww.json create mode 100644 advisories/unreviewed/2023/03/GHSA-rh28-jmpq-2rm5/GHSA-rh28-jmpq-2rm5.json create mode 100644 advisories/unreviewed/2023/03/GHSA-rh4w-wj5p-5r32/GHSA-rh4w-wj5p-5r32.json create mode 100644 advisories/unreviewed/2023/03/GHSA-rpfj-c47q-c8m4/GHSA-rpfj-c47q-c8m4.json create mode 100644 advisories/unreviewed/2023/03/GHSA-rq4q-fjxh-vjg3/GHSA-rq4q-fjxh-vjg3.json create mode 100644 advisories/unreviewed/2023/03/GHSA-rr78-v2mc-p2mp/GHSA-rr78-v2mc-p2mp.json create mode 100644 advisories/unreviewed/2023/03/GHSA-rrfg-8crh-5vmr/GHSA-rrfg-8crh-5vmr.json create mode 100644 advisories/unreviewed/2023/03/GHSA-rvc6-cvq7-4g2q/GHSA-rvc6-cvq7-4g2q.json create mode 100644 advisories/unreviewed/2023/03/GHSA-rx2p-774w-85jc/GHSA-rx2p-774w-85jc.json create mode 100644 advisories/unreviewed/2023/03/GHSA-rxmx-w44h-9gvh/GHSA-rxmx-w44h-9gvh.json create mode 100644 advisories/unreviewed/2023/03/GHSA-v452-7f7v-7m7q/GHSA-v452-7f7v-7m7q.json create mode 100644 advisories/unreviewed/2023/03/GHSA-v594-5w2m-322p/GHSA-v594-5w2m-322p.json create mode 100644 advisories/unreviewed/2023/03/GHSA-vc38-hp22-mh4x/GHSA-vc38-hp22-mh4x.json create mode 100644 advisories/unreviewed/2023/03/GHSA-vc68-vpf2-7xq5/GHSA-vc68-vpf2-7xq5.json create mode 100644 advisories/unreviewed/2023/03/GHSA-vg6v-qwqm-x96m/GHSA-vg6v-qwqm-x96m.json create mode 100644 advisories/unreviewed/2023/03/GHSA-vhc5-85r7-whv3/GHSA-vhc5-85r7-whv3.json create mode 100644 advisories/unreviewed/2023/03/GHSA-vr6q-6f35-6fpc/GHSA-vr6q-6f35-6fpc.json create mode 100644 advisories/unreviewed/2023/03/GHSA-vrvf-x4g2-cx9g/GHSA-vrvf-x4g2-cx9g.json create mode 100644 advisories/unreviewed/2023/03/GHSA-w472-7q22-qfjx/GHSA-w472-7q22-qfjx.json create mode 100644 advisories/unreviewed/2023/03/GHSA-w7wq-mfjm-crgc/GHSA-w7wq-mfjm-crgc.json create mode 100644 advisories/unreviewed/2023/03/GHSA-w94x-h737-f6h9/GHSA-w94x-h737-f6h9.json create mode 100644 advisories/unreviewed/2023/03/GHSA-wc7c-x2x3-w322/GHSA-wc7c-x2x3-w322.json create mode 100644 advisories/unreviewed/2023/03/GHSA-wccm-69w3-xxcw/GHSA-wccm-69w3-xxcw.json create mode 100644 advisories/unreviewed/2023/03/GHSA-wf6j-p2w6-h539/GHSA-wf6j-p2w6-h539.json create mode 100644 advisories/unreviewed/2023/03/GHSA-wfpr-8m9q-hrr8/GHSA-wfpr-8m9q-hrr8.json create mode 100644 advisories/unreviewed/2023/03/GHSA-wj78-xrp7-jrhr/GHSA-wj78-xrp7-jrhr.json create mode 100644 advisories/unreviewed/2023/03/GHSA-wjw4-2695-6mj3/GHSA-wjw4-2695-6mj3.json create mode 100644 advisories/unreviewed/2023/03/GHSA-wvf6-6fcj-rrxv/GHSA-wvf6-6fcj-rrxv.json create mode 100644 advisories/unreviewed/2023/03/GHSA-xf7f-g3ff-jjc9/GHSA-xf7f-g3ff-jjc9.json create mode 100644 advisories/unreviewed/2023/03/GHSA-xhfw-qhxr-hjhq/GHSA-xhfw-qhxr-hjhq.json create mode 100644 advisories/unreviewed/2023/03/GHSA-xv6g-6g23-79w2/GHSA-xv6g-6g23-79w2.json create mode 100644 advisories/unreviewed/2023/03/GHSA-xw54-w9r2-97q7/GHSA-xw54-w9r2-97q7.json diff --git a/advisories/unreviewed/2022/05/GHSA-8hg6-g75q-4x9v/GHSA-8hg6-g75q-4x9v.json b/advisories/unreviewed/2022/05/GHSA-8hg6-g75q-4x9v/GHSA-8hg6-g75q-4x9v.json index 356fc031595..7e08f517d85 100644 --- a/advisories/unreviewed/2022/05/GHSA-8hg6-g75q-4x9v/GHSA-8hg6-g75q-4x9v.json +++ b/advisories/unreviewed/2022/05/GHSA-8hg6-g75q-4x9v/GHSA-8hg6-g75q-4x9v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8hg6-g75q-4x9v", - "modified": "2022-05-24T22:00:37Z", + "modified": "2023-03-29T21:30:22Z", "published": "2022-05-24T22:00:37Z", "aliases": [ "CVE-2019-9008" ], "details": "An issue was discovered in 3S-Smart CODESYS V3 through 3.5.12.30. A user with low privileges can take full control over the runtime.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-732" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-hr98-frg6-wvvr/GHSA-hr98-frg6-wvvr.json b/advisories/unreviewed/2022/05/GHSA-hr98-frg6-wvvr/GHSA-hr98-frg6-wvvr.json index c4b37209005..6f3acc0a443 100644 --- a/advisories/unreviewed/2022/05/GHSA-hr98-frg6-wvvr/GHSA-hr98-frg6-wvvr.json +++ b/advisories/unreviewed/2022/05/GHSA-hr98-frg6-wvvr/GHSA-hr98-frg6-wvvr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hr98-frg6-wvvr", - "modified": "2022-05-24T22:00:36Z", + "modified": "2023-03-29T21:30:22Z", "published": "2022-05-24T22:00:36Z", "aliases": [ "CVE-2019-5481" ], "details": "Double-free vulnerability in the FTP-kerberos code in cURL 7.52.0 to 7.65.3.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -73,7 +76,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-415" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-j5c8-5345-567f/GHSA-j5c8-5345-567f.json b/advisories/unreviewed/2022/05/GHSA-j5c8-5345-567f/GHSA-j5c8-5345-567f.json index 335478d8a2d..bdbec49ed5f 100644 --- a/advisories/unreviewed/2022/05/GHSA-j5c8-5345-567f/GHSA-j5c8-5345-567f.json +++ b/advisories/unreviewed/2022/05/GHSA-j5c8-5345-567f/GHSA-j5c8-5345-567f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j5c8-5345-567f", - "modified": "2022-05-24T16:56:22Z", + "modified": "2023-03-29T21:30:22Z", "published": "2022-05-24T16:56:22Z", "aliases": [ "CVE-2019-16239" ], "details": "process_http_response in OpenConnect before 8.05 has a Buffer Overflow when a malicious server uses HTTP chunked encoding with crafted chunk sizes.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -65,7 +68,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-x9f6-xw7x-fm76/GHSA-x9f6-xw7x-fm76.json b/advisories/unreviewed/2022/05/GHSA-x9f6-xw7x-fm76/GHSA-x9f6-xw7x-fm76.json index e269878fb8b..1867b4b8901 100644 --- a/advisories/unreviewed/2022/05/GHSA-x9f6-xw7x-fm76/GHSA-x9f6-xw7x-fm76.json +++ b/advisories/unreviewed/2022/05/GHSA-x9f6-xw7x-fm76/GHSA-x9f6-xw7x-fm76.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x9f6-xw7x-fm76", - "modified": "2022-05-24T16:56:22Z", + "modified": "2023-03-29T21:30:22Z", "published": "2022-05-24T16:56:22Z", "aliases": [ "CVE-2019-16378" ], "details": "OpenDMARC through 1.3.2 and 1.4.x through 1.4.0-Beta1 is prone to a signature-bypass vulnerability with multiple From: addresses, which might affect applications that consider a domain name to be relevant to the origin of an e-mail message.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -61,7 +64,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-290" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/03/GHSA-24q5-7fw8-5m7f/GHSA-24q5-7fw8-5m7f.json b/advisories/unreviewed/2023/03/GHSA-24q5-7fw8-5m7f/GHSA-24q5-7fw8-5m7f.json new file mode 100644 index 00000000000..2af112968e3 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-24q5-7fw8-5m7f/GHSA-24q5-7fw8-5m7f.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-24q5-7fw8-5m7f", + "modified": "2023-03-29T21:30:19Z", + "published": "2023-03-29T21:30:19Z", + "aliases": [ + "CVE-2022-43621" + ], + "details": "This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-1935 1.03 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of HNAP login requests. The issue results from an incorrectly implemented comparison. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-16152.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43621" + }, + { + "type": "WEB", + "url": "https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10310" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1503/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-697" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-2523-mx65-hm92/GHSA-2523-mx65-hm92.json b/advisories/unreviewed/2023/03/GHSA-2523-mx65-hm92/GHSA-2523-mx65-hm92.json new file mode 100644 index 00000000000..013c20210e3 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-2523-mx65-hm92/GHSA-2523-mx65-hm92.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2523-mx65-hm92", + "modified": "2023-03-29T21:30:16Z", + "published": "2023-03-29T21:30:16Z", + "aliases": [ + "CVE-2022-44369" + ], + "details": "NASM 2.16 (development) is vulnerable to 476: Null Pointer Dereference via output/outaout.c.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-44369" + }, + { + "type": "WEB", + "url": "https://bugzilla.nasm.us/show_bug.cgi?id=3392819" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-276x-2hgv-3x2j/GHSA-276x-2hgv-3x2j.json b/advisories/unreviewed/2023/03/GHSA-276x-2hgv-3x2j/GHSA-276x-2hgv-3x2j.json new file mode 100644 index 00000000000..bf75486d7fe --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-276x-2hgv-3x2j/GHSA-276x-2hgv-3x2j.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-276x-2hgv-3x2j", + "modified": "2023-03-29T21:30:20Z", + "published": "2023-03-29T21:30:20Z", + "aliases": [ + "CVE-2022-37375" + ], + "details": "This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JPC files. Crafted data in a JPC file can trigger a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-18069.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-37375" + }, + { + "type": "WEB", + "url": "https://www.tracker-software.com/product/pdf-xchange-editor/history" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1103/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-2797-h4gc-wv56/GHSA-2797-h4gc-wv56.json b/advisories/unreviewed/2023/03/GHSA-2797-h4gc-wv56/GHSA-2797-h4gc-wv56.json new file mode 100644 index 00000000000..589f78430c3 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-2797-h4gc-wv56/GHSA-2797-h4gc-wv56.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2797-h4gc-wv56", + "modified": "2023-03-29T21:30:21Z", + "published": "2023-03-29T21:30:21Z", + "aliases": [ + "CVE-2022-28311" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.02.034. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of DXF files. Crafted data in a DXF file can trigger a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16341.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-28311" + }, + { + "type": "WEB", + "url": "https://www.bentley.com/en/common-vulnerability-exposure/be-2022-0005" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-601/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-29cx-mrrh-g7pc/GHSA-29cx-mrrh-g7pc.json b/advisories/unreviewed/2023/03/GHSA-29cx-mrrh-g7pc/GHSA-29cx-mrrh-g7pc.json new file mode 100644 index 00000000000..3fa787854cc --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-29cx-mrrh-g7pc/GHSA-29cx-mrrh-g7pc.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-29cx-mrrh-g7pc", + "modified": "2023-03-29T21:30:20Z", + "published": "2023-03-29T21:30:20Z", + "aliases": [ + "CVE-2022-36980" + ], + "details": "This vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche 6.3.2.3490. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the EnterpriseServer service. The issue results from the lack of proper locking when performing operations during authentication. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-15528.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36980" + }, + { + "type": "WEB", + "url": "https://download.wavelink.com/Files/avalanche_v6.3.4_release_notes.txt" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-785/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-367" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-2cpq-6g4r-6726/GHSA-2cpq-6g4r-6726.json b/advisories/unreviewed/2023/03/GHSA-2cpq-6g4r-6726/GHSA-2cpq-6g4r-6726.json new file mode 100644 index 00000000000..defeb71137f --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-2cpq-6g4r-6726/GHSA-2cpq-6g4r-6726.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2cpq-6g4r-6726", + "modified": "2023-03-29T21:30:19Z", + "published": "2023-03-29T21:30:19Z", + "aliases": [ + "CVE-2022-43617" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Corel CorelDRAW Graphics Suite 23.5.0.506. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PCX files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16372.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43617" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1475/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-2jp6-jv62-jw48/GHSA-2jp6-jv62-jw48.json b/advisories/unreviewed/2023/03/GHSA-2jp6-jv62-jw48/GHSA-2jp6-jv62-jw48.json new file mode 100644 index 00000000000..73e4c12e633 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-2jp6-jv62-jw48/GHSA-2jp6-jv62-jw48.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2jp6-jv62-jw48", + "modified": "2023-03-29T21:30:20Z", + "published": "2023-03-29T21:30:20Z", + "aliases": [ + "CVE-2022-37367" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of AcroForms. Crafted data in an AcroForm can trigger a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-17726.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-37367" + }, + { + "type": "WEB", + "url": "https://www.tracker-software.com/product/pdf-xchange-editor/history" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1095/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-2rc8-5vp2-97ch/GHSA-2rc8-5vp2-97ch.json b/advisories/unreviewed/2023/03/GHSA-2rc8-5vp2-97ch/GHSA-2rc8-5vp2-97ch.json new file mode 100644 index 00000000000..234e22c6010 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-2rc8-5vp2-97ch/GHSA-2rc8-5vp2-97ch.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2rc8-5vp2-97ch", + "modified": "2023-03-29T21:30:20Z", + "published": "2023-03-29T21:30:20Z", + "aliases": [ + "CVE-2022-37356" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JPG files. Crafted data in a JPG file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-17630.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-37356" + }, + { + "type": "WEB", + "url": "https://www.tracker-software.com/product/pdf-xchange-editor/history" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1084/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-2rjc-h554-j93w/GHSA-2rjc-h554-j93w.json b/advisories/unreviewed/2023/03/GHSA-2rjc-h554-j93w/GHSA-2rjc-h554-j93w.json new file mode 100644 index 00000000000..ee30860c8ec --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-2rjc-h554-j93w/GHSA-2rjc-h554-j93w.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2rjc-h554-j93w", + "modified": "2023-03-29T21:30:21Z", + "published": "2023-03-29T21:30:21Z", + "aliases": [ + "CVE-2022-36977" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Avalanche 6.3.2.3490. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the Certificate Management Server service. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-15449.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36977" + }, + { + "type": "WEB", + "url": "https://download.wavelink.com/Files/avalanche_v6.3.4_release_notes.txt" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-782/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-2v4g-w3qw-prh4/GHSA-2v4g-w3qw-prh4.json b/advisories/unreviewed/2023/03/GHSA-2v4g-w3qw-prh4/GHSA-2v4g-w3qw-prh4.json new file mode 100644 index 00000000000..61c8e843b5e --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-2v4g-w3qw-prh4/GHSA-2v4g-w3qw-prh4.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2v4g-w3qw-prh4", + "modified": "2023-03-29T21:30:17Z", + "published": "2023-03-29T21:30:17Z", + "aliases": [ + "CVE-2022-47607" + ], + "details": "Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Usersnap plugin <= 4.16 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-47607" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/usersnap/wordpress-usersnap-plugin-4-16-cross-site-scripting-xss?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-2x7m-w9xq-pcvr/GHSA-2x7m-w9xq-pcvr.json b/advisories/unreviewed/2023/03/GHSA-2x7m-w9xq-pcvr/GHSA-2x7m-w9xq-pcvr.json new file mode 100644 index 00000000000..ae70b0227ae --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-2x7m-w9xq-pcvr/GHSA-2x7m-w9xq-pcvr.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2x7m-w9xq-pcvr", + "modified": "2023-03-29T21:30:21Z", + "published": "2023-03-29T21:30:21Z", + "aliases": [ + "CVE-2022-28688" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 2020 SP2 Patch 0(4201.2111.1802.0000). User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of APP files. The process loads a library from an unsecured location. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-17201.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-28688" + }, + { + "type": "WEB", + "url": "https://www.aveva.com/content/dam/aveva/documents/support/cyber-security-updates/SecurityBulletin_AVEVA-2022-005.pdf" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1127/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-33j8-9xqj-q27p/GHSA-33j8-9xqj-q27p.json b/advisories/unreviewed/2023/03/GHSA-33j8-9xqj-q27p/GHSA-33j8-9xqj-q27p.json new file mode 100644 index 00000000000..48381f74568 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-33j8-9xqj-q27p/GHSA-33j8-9xqj-q27p.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-33j8-9xqj-q27p", + "modified": "2023-03-29T21:30:21Z", + "published": "2023-03-29T21:30:21Z", + "aliases": [ + "CVE-2022-36972" + ], + "details": "This vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche 6.3.2.3490. The specific flaw exists within the ProfileDaoImpl class. A crafted request can trigger execution of SQL queries composed from a user-supplied string. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-15328.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36972" + }, + { + "type": "WEB", + "url": "https://download.wavelink.com/Files/avalanche_v6.3.4_release_notes.txt" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-777/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-33jv-5wxr-v6v3/GHSA-33jv-5wxr-v6v3.json b/advisories/unreviewed/2023/03/GHSA-33jv-5wxr-v6v3/GHSA-33jv-5wxr-v6v3.json new file mode 100644 index 00000000000..664636d2b5d --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-33jv-5wxr-v6v3/GHSA-33jv-5wxr-v6v3.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-33jv-5wxr-v6v3", + "modified": "2023-03-29T21:30:20Z", + "published": "2023-03-29T21:30:20Z", + "aliases": [ + "CVE-2022-37364" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of EMF files. Crafted data in an EMF file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-17634.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-37364" + }, + { + "type": "WEB", + "url": "https://www.tracker-software.com/product/pdf-xchange-editor/history" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1092/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-3452-rvwh-rv7h/GHSA-3452-rvwh-rv7h.json b/advisories/unreviewed/2023/03/GHSA-3452-rvwh-rv7h/GHSA-3452-rvwh-rv7h.json new file mode 100644 index 00000000000..a3a003c064e --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-3452-rvwh-rv7h/GHSA-3452-rvwh-rv7h.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3452-rvwh-rv7h", + "modified": "2023-03-29T21:30:16Z", + "published": "2023-03-29T21:30:16Z", + "aliases": [ + "CVE-2023-1656" + ], + "details": "Cleartext Transmission of Sensitive Information vulnerability in ForgeRock Inc. OpenIDM and Java Remote Connector Server (RCS) LDAP Connector on Windows, MacOS, Linux allows Remote Services with Stolen Credentials.This issue affects OpenIDM and Java Remote Connector Server (RCS): from 1.5.20.9 through 1.5.20.13.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1656" + }, + { + "type": "WEB", + "url": "https://backstage.forgerock.com/downloads/browse/idm/all/productId:idm-connectors/subProductId:ldap/minorVersion:1.5/version:1.5.20.14" + }, + { + "type": "WEB", + "url": "https://backstage.forgerock.com/knowledge/kb/article/a14149722" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-345m-hwph-xh83/GHSA-345m-hwph-xh83.json b/advisories/unreviewed/2023/03/GHSA-345m-hwph-xh83/GHSA-345m-hwph-xh83.json index c22e4c7c7ee..ba332d02801 100644 --- a/advisories/unreviewed/2023/03/GHSA-345m-hwph-xh83/GHSA-345m-hwph-xh83.json +++ b/advisories/unreviewed/2023/03/GHSA-345m-hwph-xh83/GHSA-345m-hwph-xh83.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-345m-hwph-xh83", - "modified": "2023-03-24T21:30:52Z", + "modified": "2023-03-29T21:30:22Z", "published": "2023-03-24T21:30:52Z", "aliases": [ "CVE-2023-21047" ], "details": "In ConvertToHalMetadata of aidl_utils.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-256166866References: N/A", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-119" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-24T20:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-345r-5qfx-4jpr/GHSA-345r-5qfx-4jpr.json b/advisories/unreviewed/2023/03/GHSA-345r-5qfx-4jpr/GHSA-345r-5qfx-4jpr.json new file mode 100644 index 00000000000..6ec7181ff2f --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-345r-5qfx-4jpr/GHSA-345r-5qfx-4jpr.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-345r-5qfx-4jpr", + "modified": "2023-03-29T21:30:15Z", + "published": "2023-03-29T21:30:15Z", + "aliases": [ + "CVE-2023-28509" + ], + "details": "Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 use weak encryption for packet-level security and passwords transferred on the wire.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28509" + }, + { + "type": "WEB", + "url": "https://www.rapid7.com/blog/post/2023/03/29/multiple-vulnerabilities-in-rocket-software-unirpc-server-fixed/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T21:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-366x-2hwp-qq45/GHSA-366x-2hwp-qq45.json b/advisories/unreviewed/2023/03/GHSA-366x-2hwp-qq45/GHSA-366x-2hwp-qq45.json new file mode 100644 index 00000000000..b5be4068b23 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-366x-2hwp-qq45/GHSA-366x-2hwp-qq45.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-366x-2hwp-qq45", + "modified": "2023-03-29T21:30:20Z", + "published": "2023-03-29T21:30:20Z", + "aliases": [ + "CVE-2022-37381" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the AFSpecial_KeystrokeEx method. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-17110.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-37381" + }, + { + "type": "WEB", + "url": "https://www.foxit.com/support/security-bulletins.html" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1053/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-3fvg-68xh-vfxq/GHSA-3fvg-68xh-vfxq.json b/advisories/unreviewed/2023/03/GHSA-3fvg-68xh-vfxq/GHSA-3fvg-68xh-vfxq.json new file mode 100644 index 00000000000..ff06a5dbaf1 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-3fvg-68xh-vfxq/GHSA-3fvg-68xh-vfxq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3fvg-68xh-vfxq", + "modified": "2023-03-29T21:30:18Z", + "published": "2023-03-29T21:30:18Z", + "aliases": [ + "CVE-2022-43636" + ], + "details": "This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of TP-Link TL-WR940N 6_211111 3.20.1(US) routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the httpd service, which listens on TCP port 80 by default. The issue results from the lack of sufficient randomness in the sequnce numbers used for session managment. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-18334.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43636" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1614/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-330" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-3m65-86mg-45wp/GHSA-3m65-86mg-45wp.json b/advisories/unreviewed/2023/03/GHSA-3m65-86mg-45wp/GHSA-3m65-86mg-45wp.json new file mode 100644 index 00000000000..f4ac375d6a9 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-3m65-86mg-45wp/GHSA-3m65-86mg-45wp.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3m65-86mg-45wp", + "modified": "2023-03-29T21:30:22Z", + "published": "2023-03-29T21:30:22Z", + "aliases": [ + "CVE-2022-28304" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.02.034. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of OBJ files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16171.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-28304" + }, + { + "type": "WEB", + "url": "https://www.bentley.com/en/common-vulnerability-exposure/be-2022-0008" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-594/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-3rvm-9j83-445h/GHSA-3rvm-9j83-445h.json b/advisories/unreviewed/2023/03/GHSA-3rvm-9j83-445h/GHSA-3rvm-9j83-445h.json new file mode 100644 index 00000000000..95049d092be --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-3rvm-9j83-445h/GHSA-3rvm-9j83-445h.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3rvm-9j83-445h", + "modified": "2023-03-29T21:30:19Z", + "published": "2023-03-29T21:30:19Z", + "aliases": [ + "CVE-2022-43625" + ], + "details": "This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the handling of SetStaticRouteIPv4Settings requests to the web management portal. When parsing the NetMask element, the process does not properly validate the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-16144.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43625" + }, + { + "type": "WEB", + "url": "https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10310" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1495/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-3wm7-5h33-f92f/GHSA-3wm7-5h33-f92f.json b/advisories/unreviewed/2023/03/GHSA-3wm7-5h33-f92f/GHSA-3wm7-5h33-f92f.json new file mode 100644 index 00000000000..3dc6617e6f7 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-3wm7-5h33-f92f/GHSA-3wm7-5h33-f92f.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3wm7-5h33-f92f", + "modified": "2023-03-29T21:30:15Z", + "published": "2023-03-29T21:30:15Z", + "aliases": [ + "CVE-2023-28505" + ], + "details": "Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a buffer overflow in an API function, where a string is copied into a caller-provided buffer without checking the length. This requires a valid login to exploit.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28505" + }, + { + "type": "WEB", + "url": "https://www.rapid7.com/blog/post/2023/03/29/multiple-vulnerabilities-in-rocket-software-unirpc-server-fixed/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T21:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-43qp-56c9-mg75/GHSA-43qp-56c9-mg75.json b/advisories/unreviewed/2023/03/GHSA-43qp-56c9-mg75/GHSA-43qp-56c9-mg75.json new file mode 100644 index 00000000000..fa2b22385b0 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-43qp-56c9-mg75/GHSA-43qp-56c9-mg75.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-43qp-56c9-mg75", + "modified": "2023-03-29T21:30:19Z", + "published": "2023-03-29T21:30:19Z", + "aliases": [ + "CVE-2022-37383" + ], + "details": "This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Doc objects. By performing actions in JavaScript, an attacker can trigger a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-17111.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-37383" + }, + { + "type": "WEB", + "url": "https://www.foxit.com/support/security-bulletins.html" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1055/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-446g-ch6r-4m6w/GHSA-446g-ch6r-4m6w.json b/advisories/unreviewed/2023/03/GHSA-446g-ch6r-4m6w/GHSA-446g-ch6r-4m6w.json new file mode 100644 index 00000000000..aff6c367843 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-446g-ch6r-4m6w/GHSA-446g-ch6r-4m6w.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-446g-ch6r-4m6w", + "modified": "2023-03-29T21:30:20Z", + "published": "2023-03-29T21:30:20Z", + "aliases": [ + "CVE-2022-37352" + ], + "details": "This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of WMF files. Crafted data in a WMF file can trigger a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-17638.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-37352" + }, + { + "type": "WEB", + "url": "https://www.tracker-software.com/product/pdf-xchange-editor/history" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1080/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-44h9-27pc-757g/GHSA-44h9-27pc-757g.json b/advisories/unreviewed/2023/03/GHSA-44h9-27pc-757g/GHSA-44h9-27pc-757g.json new file mode 100644 index 00000000000..8c1d13c79c8 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-44h9-27pc-757g/GHSA-44h9-27pc-757g.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-44h9-27pc-757g", + "modified": "2023-03-29T21:30:18Z", + "published": "2023-03-29T21:30:18Z", + "aliases": [ + "CVE-2022-43635" + ], + "details": "This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link TL-WR940N 6_211111 3.20.1(US) routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the httpd service, which listens on TCP port 80 by default. The issue results from the incorrect implementation of the authentication algorithm. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-17332.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43635" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1615/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-303" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-48fv-6rrf-3cqx/GHSA-48fv-6rrf-3cqx.json b/advisories/unreviewed/2023/03/GHSA-48fv-6rrf-3cqx/GHSA-48fv-6rrf-3cqx.json new file mode 100644 index 00000000000..bab44ab2cf7 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-48fv-6rrf-3cqx/GHSA-48fv-6rrf-3cqx.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-48fv-6rrf-3cqx", + "modified": "2023-03-29T21:30:22Z", + "published": "2023-03-29T21:30:22Z", + "aliases": [ + "CVE-2022-27641" + ], + "details": "This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the NetUSB module. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before allocating a buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-15806.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-27641" + }, + { + "type": "WEB", + "url": "https://kb.netgear.com/000064437/Security-Advisory-for-Pre-Authentication-Buffer-Overflow-on-Multiple-Products-PSV-2021-0278" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-544/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-190" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-4f3p-pr3g-6qgf/GHSA-4f3p-pr3g-6qgf.json b/advisories/unreviewed/2023/03/GHSA-4f3p-pr3g-6qgf/GHSA-4f3p-pr3g-6qgf.json new file mode 100644 index 00000000000..9ba13038d07 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-4f3p-pr3g-6qgf/GHSA-4f3p-pr3g-6qgf.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4f3p-pr3g-6qgf", + "modified": "2023-03-29T21:30:19Z", + "published": "2023-03-29T21:30:19Z", + "aliases": [ + "CVE-2022-42430" + ], + "details": "This vulnerability allows local attackers to escalate privileges on affected Tesla vehicles. An attacker must first obtain the ability to execute privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handling of the wowlan_config data structure. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of root. Was ZDI-CAN-17543.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-42430" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1406/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-4fg6-p758-85rf/GHSA-4fg6-p758-85rf.json b/advisories/unreviewed/2023/03/GHSA-4fg6-p758-85rf/GHSA-4fg6-p758-85rf.json new file mode 100644 index 00000000000..03d770357c9 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-4fg6-p758-85rf/GHSA-4fg6-p758-85rf.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4fg6-p758-85rf", + "modified": "2023-03-29T21:30:20Z", + "published": "2023-03-29T21:30:20Z", + "aliases": [ + "CVE-2022-37378" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Editor 11.1.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the optimization of JavaScript functions. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16867.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-37378" + }, + { + "type": "WEB", + "url": "https://www.foxit.com/support/security-bulletins.html" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1050/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-4fp9-g9rc-jhf3/GHSA-4fp9-g9rc-jhf3.json b/advisories/unreviewed/2023/03/GHSA-4fp9-g9rc-jhf3/GHSA-4fp9-g9rc-jhf3.json new file mode 100644 index 00000000000..cffbf6457fd --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-4fp9-g9rc-jhf3/GHSA-4fp9-g9rc-jhf3.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4fp9-g9rc-jhf3", + "modified": "2023-03-29T21:30:21Z", + "published": "2023-03-29T21:30:21Z", + "aliases": [ + "CVE-2022-28306" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.02.034. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of OBJ files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this to execute code in the context of the current process. Was ZDI-CAN-16174.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-28306" + }, + { + "type": "WEB", + "url": "https://www.bentley.com/en/common-vulnerability-exposure/be-2022-0008" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-595/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-4fpc-4gp5-rfgp/GHSA-4fpc-4gp5-rfgp.json b/advisories/unreviewed/2023/03/GHSA-4fpc-4gp5-rfgp/GHSA-4fpc-4gp5-rfgp.json new file mode 100644 index 00000000000..954ecb33d48 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-4fpc-4gp5-rfgp/GHSA-4fpc-4gp5-rfgp.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4fpc-4gp5-rfgp", + "modified": "2023-03-29T21:30:20Z", + "published": "2023-03-29T21:30:20Z", + "aliases": [ + "CVE-2022-36974" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Avalanche 6.3.2.3490. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the Web File Server service. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-15330.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36974" + }, + { + "type": "WEB", + "url": "https://download.wavelink.com/Files/avalanche_v6.3.4_release_notes.txt" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-779/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-4gp8-394w-2vcg/GHSA-4gp8-394w-2vcg.json b/advisories/unreviewed/2023/03/GHSA-4gp8-394w-2vcg/GHSA-4gp8-394w-2vcg.json new file mode 100644 index 00000000000..0378cb68b5e --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-4gp8-394w-2vcg/GHSA-4gp8-394w-2vcg.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4gp8-394w-2vcg", + "modified": "2023-03-29T21:30:16Z", + "published": "2023-03-29T21:30:16Z", + "aliases": [ + "CVE-2022-47602" + ], + "details": "Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in JoomUnited WP Table Manager plugin <= 3.5.2 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-47602" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-table-manager/wordpress-wp-table-manager-plugin-3-5-2-cross-site-scripting-xss?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-4j42-3rxm-869g/GHSA-4j42-3rxm-869g.json b/advisories/unreviewed/2023/03/GHSA-4j42-3rxm-869g/GHSA-4j42-3rxm-869g.json new file mode 100644 index 00000000000..0a2a87284e1 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-4j42-3rxm-869g/GHSA-4j42-3rxm-869g.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4j42-3rxm-869g", + "modified": "2023-03-29T21:30:19Z", + "published": "2023-03-29T21:30:19Z", + "aliases": [ + "CVE-2022-3210" + ], + "details": "This vulnerability allows network-adjacent attackers to execute arbitrary commands on affected installations of D-Link DIR-2150 4.0.1 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the xupnpd service, which listens on TCP port 4044 by default. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-15905.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-3210" + }, + { + "type": "WEB", + "url": "https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10304" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1222/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-4j4g-x85c-8f36/GHSA-4j4g-x85c-8f36.json b/advisories/unreviewed/2023/03/GHSA-4j4g-x85c-8f36/GHSA-4j4g-x85c-8f36.json new file mode 100644 index 00000000000..a6b7f92e68e --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-4j4g-x85c-8f36/GHSA-4j4g-x85c-8f36.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4j4g-x85c-8f36", + "modified": "2023-03-29T21:30:18Z", + "published": "2023-03-29T21:30:18Z", + "aliases": [ + "CVE-2022-43631" + ], + "details": "This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the handling of SetVirtualServerSettings requests to the web management portal. When parsing subelements within the VirtualServerInfo element, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-16151.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43631" + }, + { + "type": "WEB", + "url": "https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10310" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1502/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-4mfr-5g26-5m2m/GHSA-4mfr-5g26-5m2m.json b/advisories/unreviewed/2023/03/GHSA-4mfr-5g26-5m2m/GHSA-4mfr-5g26-5m2m.json new file mode 100644 index 00000000000..408043f9dc4 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-4mfr-5g26-5m2m/GHSA-4mfr-5g26-5m2m.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4mfr-5g26-5m2m", + "modified": "2023-03-29T21:30:20Z", + "published": "2023-03-29T21:30:20Z", + "aliases": [ + "CVE-2022-37377" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Editor 11.1.1.53537;. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within JavaScript optimizations. The issue results from an improper optimization, which can result in a type confusion condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16733.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-37377" + }, + { + "type": "WEB", + "url": "https://www.foxit.com/support/security-bulletins.html" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1049/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-843" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-4rpc-xhhq-h2cq/GHSA-4rpc-xhhq-h2cq.json b/advisories/unreviewed/2023/03/GHSA-4rpc-xhhq-h2cq/GHSA-4rpc-xhhq-h2cq.json new file mode 100644 index 00000000000..922e86f629f --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-4rpc-xhhq-h2cq/GHSA-4rpc-xhhq-h2cq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4rpc-xhhq-h2cq", + "modified": "2023-03-29T21:30:19Z", + "published": "2023-03-29T21:30:19Z", + "aliases": [ + "CVE-2022-43609" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of IronCAD. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of STP files. When parsing the VECTOR element, the process does not properly initialize a pointer prior to accessing it. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-17672.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43609" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1467/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-824" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-4rxf-rcjh-42f3/GHSA-4rxf-rcjh-42f3.json b/advisories/unreviewed/2023/03/GHSA-4rxf-rcjh-42f3/GHSA-4rxf-rcjh-42f3.json new file mode 100644 index 00000000000..e688f0f69ca --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-4rxf-rcjh-42f3/GHSA-4rxf-rcjh-42f3.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4rxf-rcjh-42f3", + "modified": "2023-03-29T21:30:19Z", + "published": "2023-03-29T21:30:19Z", + "aliases": [ + "CVE-2022-37390" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.2.2.53575. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of AcroForms. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-17551.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-37390" + }, + { + "type": "WEB", + "url": "https://www.foxit.com/support/security-bulletins.html" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1062/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-52w8-9f8q-6r2v/GHSA-52w8-9f8q-6r2v.json b/advisories/unreviewed/2023/03/GHSA-52w8-9f8q-6r2v/GHSA-52w8-9f8q-6r2v.json index 910f0883dcc..7275425f802 100644 --- a/advisories/unreviewed/2023/03/GHSA-52w8-9f8q-6r2v/GHSA-52w8-9f8q-6r2v.json +++ b/advisories/unreviewed/2023/03/GHSA-52w8-9f8q-6r2v/GHSA-52w8-9f8q-6r2v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-52w8-9f8q-6r2v", - "modified": "2023-03-24T21:30:52Z", + "modified": "2023-03-29T21:30:22Z", "published": "2023-03-24T21:30:52Z", "aliases": [ "CVE-2023-21049" ], "details": "In append_camera_metadata of camera_metadata.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-236688120References: N/A", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-24T20:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-54c2-w283-x9w8/GHSA-54c2-w283-x9w8.json b/advisories/unreviewed/2023/03/GHSA-54c2-w283-x9w8/GHSA-54c2-w283-x9w8.json new file mode 100644 index 00000000000..cc548de9632 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-54c2-w283-x9w8/GHSA-54c2-w283-x9w8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-54c2-w283-x9w8", + "modified": "2023-03-29T21:30:19Z", + "published": "2023-03-29T21:30:19Z", + "aliases": [ + "CVE-2022-42428" + ], + "details": "This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of requests to modify poller broker configuration. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to escalate privileges to the level of an administrator. Was ZDI-CAN-18410.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-42428" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1399/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-567x-fp72-xh2g/GHSA-567x-fp72-xh2g.json b/advisories/unreviewed/2023/03/GHSA-567x-fp72-xh2g/GHSA-567x-fp72-xh2g.json new file mode 100644 index 00000000000..790d3ea36ee --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-567x-fp72-xh2g/GHSA-567x-fp72-xh2g.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-567x-fp72-xh2g", + "modified": "2023-03-29T21:30:19Z", + "published": "2023-03-29T21:30:19Z", + "aliases": [ + "CVE-2022-42426" + ], + "details": "This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of requests to modify poller broker configuration. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to escalate privileges to the level of an administrator. Was ZDI-CAN-18554.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-42426" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1397/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-5hm2-2whx-4749/GHSA-5hm2-2whx-4749.json b/advisories/unreviewed/2023/03/GHSA-5hm2-2whx-4749/GHSA-5hm2-2whx-4749.json new file mode 100644 index 00000000000..cae32bdf417 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-5hm2-2whx-4749/GHSA-5hm2-2whx-4749.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5hm2-2whx-4749", + "modified": "2023-03-29T21:30:16Z", + "published": "2023-03-29T21:30:16Z", + "aliases": [ + "CVE-2022-44370" + ], + "details": "NASM v2.16 was discovered to contain a heap buffer overflow in the component quote_for_pmake() asm/nasm.c:856", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-44370" + }, + { + "type": "WEB", + "url": "https://bugzilla.nasm.us/show_bug.cgi?id=3392815" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-5pmp-c2mf-mxm4/GHSA-5pmp-c2mf-mxm4.json b/advisories/unreviewed/2023/03/GHSA-5pmp-c2mf-mxm4/GHSA-5pmp-c2mf-mxm4.json new file mode 100644 index 00000000000..edc3e43476e --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-5pmp-c2mf-mxm4/GHSA-5pmp-c2mf-mxm4.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5pmp-c2mf-mxm4", + "modified": "2023-03-29T21:30:19Z", + "published": "2023-03-29T21:30:19Z", + "aliases": [ + "CVE-2022-43610" + ], + "details": "This vulnerability allows remote attackers to disclose sensitive information on affected installations of Corel CorelDRAW Graphics Suite 23.5.0.506. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of GIF images. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-16350.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43610" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1468/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-5v3q-vvmp-5xfx/GHSA-5v3q-vvmp-5xfx.json b/advisories/unreviewed/2023/03/GHSA-5v3q-vvmp-5xfx/GHSA-5v3q-vvmp-5xfx.json new file mode 100644 index 00000000000..7a1a524667d --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-5v3q-vvmp-5xfx/GHSA-5v3q-vvmp-5xfx.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5v3q-vvmp-5xfx", + "modified": "2023-03-29T21:30:20Z", + "published": "2023-03-29T21:30:20Z", + "aliases": [ + "CVE-2022-37349" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the submitForm method. By performing actions in JavaScript, an attacker can trigger a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-17142.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-37349" + }, + { + "type": "WEB", + "url": "https://www.tracker-software.com/product/pdf-xchange-editor/history" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1076/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-5w68-r965-r3m3/GHSA-5w68-r965-r3m3.json b/advisories/unreviewed/2023/03/GHSA-5w68-r965-r3m3/GHSA-5w68-r965-r3m3.json new file mode 100644 index 00000000000..914d1b8367d --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-5w68-r965-r3m3/GHSA-5w68-r965-r3m3.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5w68-r965-r3m3", + "modified": "2023-03-29T21:30:17Z", + "published": "2023-03-29T21:30:17Z", + "aliases": [ + "CVE-2022-44368" + ], + "details": "NASM v2.16 was discovered to contain a null pointer deference in the NASM component", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-44368" + }, + { + "type": "WEB", + "url": "https://bugzilla.nasm.us/show_bug.cgi?id=3392820" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-5xp2-x7qr-wjrx/GHSA-5xp2-x7qr-wjrx.json b/advisories/unreviewed/2023/03/GHSA-5xp2-x7qr-wjrx/GHSA-5xp2-x7qr-wjrx.json new file mode 100644 index 00000000000..910e6871f19 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-5xp2-x7qr-wjrx/GHSA-5xp2-x7qr-wjrx.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5xp2-x7qr-wjrx", + "modified": "2023-03-29T21:30:20Z", + "published": "2023-03-29T21:30:20Z", + "aliases": [ + "CVE-2022-37012" + ], + "details": "This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Unified Automation OPC UA C++ Demo Server 1.7.6-537. Authentication is not required to exploit this vulnerability. The specific flaw exists within the OpcUa_SecureListener_ProcessSessionCallRequest method. A crafted OPC UA message can force the server to incorrectly update a reference count. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-16927.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-37012" + }, + { + "type": "WEB", + "url": "https://documentation.unified-automation.com/uasdkcpp/1.7.7/CHANGELOG.txt" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1030/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-911" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-5xr5-9vfx-374w/GHSA-5xr5-9vfx-374w.json b/advisories/unreviewed/2023/03/GHSA-5xr5-9vfx-374w/GHSA-5xr5-9vfx-374w.json new file mode 100644 index 00000000000..880bd395d63 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-5xr5-9vfx-374w/GHSA-5xr5-9vfx-374w.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5xr5-9vfx-374w", + "modified": "2023-03-29T21:30:21Z", + "published": "2023-03-29T21:30:21Z", + "aliases": [ + "CVE-2022-2560" + ], + "details": "This vulnerability allows remote attackers to delete arbitrary files on affected installations of EnterpriseDT CompleteFTP CompleteFTP Server v22.1.0 Server. Authentication is not required to exploit this vulnerability. The specific flaw exists within the HttpFile class. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to delete files in the context of SYSTEM. Was ZDI-CAN-17481.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-2560" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1032/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-64p4-gjjq-76rf/GHSA-64p4-gjjq-76rf.json b/advisories/unreviewed/2023/03/GHSA-64p4-gjjq-76rf/GHSA-64p4-gjjq-76rf.json new file mode 100644 index 00000000000..200c04d8588 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-64p4-gjjq-76rf/GHSA-64p4-gjjq-76rf.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-64p4-gjjq-76rf", + "modified": "2023-03-29T21:30:21Z", + "published": "2023-03-29T21:30:21Z", + "aliases": [ + "CVE-2022-28314" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.02.34. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of IFC files. Crafted data in an IFC file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16332.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-28314" + }, + { + "type": "WEB", + "url": "https://www.bentley.com/en/common-vulnerability-exposure/be-2022-0006" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-605/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-65gj-57wq-hhwj/GHSA-65gj-57wq-hhwj.json b/advisories/unreviewed/2023/03/GHSA-65gj-57wq-hhwj/GHSA-65gj-57wq-hhwj.json new file mode 100644 index 00000000000..4efd3f503c6 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-65gj-57wq-hhwj/GHSA-65gj-57wq-hhwj.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-65gj-57wq-hhwj", + "modified": "2023-03-29T21:30:22Z", + "published": "2023-03-29T21:30:22Z", + "aliases": [ + "CVE-2022-28303" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.16.02.022. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of SKP files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16280.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-28303" + }, + { + "type": "WEB", + "url": "https://www.bentley.com/en/common-vulnerability-exposure/be-2022-0009" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-596/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-65qp-9jcx-88ff/GHSA-65qp-9jcx-88ff.json b/advisories/unreviewed/2023/03/GHSA-65qp-9jcx-88ff/GHSA-65qp-9jcx-88ff.json new file mode 100644 index 00000000000..b67ea6ed61b --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-65qp-9jcx-88ff/GHSA-65qp-9jcx-88ff.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-65qp-9jcx-88ff", + "modified": "2023-03-29T21:30:20Z", + "published": "2023-03-29T21:30:20Z", + "aliases": [ + "CVE-2022-37363" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of EMF files. Crafted data in an EMF file can trigger a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-17673.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-37363" + }, + { + "type": "WEB", + "url": "https://www.tracker-software.com/product/pdf-xchange-editor/history" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1091/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-6626-mmrw-83qj/GHSA-6626-mmrw-83qj.json b/advisories/unreviewed/2023/03/GHSA-6626-mmrw-83qj/GHSA-6626-mmrw-83qj.json new file mode 100644 index 00000000000..5ffa688a809 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-6626-mmrw-83qj/GHSA-6626-mmrw-83qj.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6626-mmrw-83qj", + "modified": "2023-03-29T21:30:18Z", + "published": "2023-03-29T21:30:18Z", + "aliases": [ + "CVE-2022-43647" + ], + "details": "This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-825 1.0.9/EE routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the xupnpd service, which listens on TCP port 4044. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the admin user. Was ZDI-CAN-19464.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43647" + }, + { + "type": "WEB", + "url": "https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10319" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1706/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-6fx6-mv6x-h475/GHSA-6fx6-mv6x-h475.json b/advisories/unreviewed/2023/03/GHSA-6fx6-mv6x-h475/GHSA-6fx6-mv6x-h475.json new file mode 100644 index 00000000000..0ef855e9d27 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-6fx6-mv6x-h475/GHSA-6fx6-mv6x-h475.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6fx6-mv6x-h475", + "modified": "2023-03-29T21:30:19Z", + "published": "2023-03-29T21:30:19Z", + "aliases": [ + "CVE-2022-42432" + ], + "details": "This vulnerability allows local attackers to disclose sensitive information on affected installations of the Linux Kernel 6.0-rc2. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the nft_osf_eval function. The issue results from the lack of proper initialization of memory prior to accessing it. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the kernel. Was ZDI-CAN-18540.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-42432" + }, + { + "type": "WEB", + "url": "https://patchwork.ozlabs.org/project/netfilter-devel/patch/20220907082618.1193201-1-pablo@netfilter.org/" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1457/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-457" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-6gg3-r538-67r7/GHSA-6gg3-r538-67r7.json b/advisories/unreviewed/2023/03/GHSA-6gg3-r538-67r7/GHSA-6gg3-r538-67r7.json new file mode 100644 index 00000000000..f0b9cf0a5b7 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-6gg3-r538-67r7/GHSA-6gg3-r538-67r7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6gg3-r538-67r7", + "modified": "2023-03-29T21:30:18Z", + "published": "2023-03-29T21:30:18Z", + "aliases": [ + "CVE-2022-45355" + ], + "details": "Auth. (admin+) SQL Injection (SQLi) vulnerability in ThimPress WP Pipes plugin <= 1.33 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45355" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-pipes/wordpress-wp-pipes-plugin-1-33-auth-sql-injection-sqli-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-6gpc-qw5q-frjv/GHSA-6gpc-qw5q-frjv.json b/advisories/unreviewed/2023/03/GHSA-6gpc-qw5q-frjv/GHSA-6gpc-qw5q-frjv.json new file mode 100644 index 00000000000..b4fd02c8fac --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-6gpc-qw5q-frjv/GHSA-6gpc-qw5q-frjv.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6gpc-qw5q-frjv", + "modified": "2023-03-29T21:30:16Z", + "published": "2023-03-29T21:30:16Z", + "aliases": [ + "CVE-2019-8963" + ], + "details": "A Denial of Service (DoS) vulnerability was discovered in FlexNet Publisher's lmadmin 11.16.5, when doing a crafted POST request on lmadmin using the web-based tool.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-8963" + }, + { + "type": "WEB", + "url": "https://community.flexera.com/t5/FlexNet-Publisher-Knowledge-Base/CVE-2019-8963-Remediated-in-FlexNet-Publisher/ta-p/148768" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T21:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-6hc2-h64w-g96p/GHSA-6hc2-h64w-g96p.json b/advisories/unreviewed/2023/03/GHSA-6hc2-h64w-g96p/GHSA-6hc2-h64w-g96p.json new file mode 100644 index 00000000000..c5a3debf4bb --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-6hc2-h64w-g96p/GHSA-6hc2-h64w-g96p.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6hc2-h64w-g96p", + "modified": "2023-03-29T21:30:19Z", + "published": "2023-03-29T21:30:19Z", + "aliases": [ + "CVE-2022-43614" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Corel CorelDRAW Graphics Suite 23.5.0.506. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of GIF images. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16357.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43614" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1472/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-6hpv-3vxv-xp2r/GHSA-6hpv-3vxv-xp2r.json b/advisories/unreviewed/2023/03/GHSA-6hpv-3vxv-xp2r/GHSA-6hpv-3vxv-xp2r.json new file mode 100644 index 00000000000..c09ee7867de --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-6hpv-3vxv-xp2r/GHSA-6hpv-3vxv-xp2r.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6hpv-3vxv-xp2r", + "modified": "2023-03-29T21:30:18Z", + "published": "2023-03-29T21:30:18Z", + "aliases": [ + "CVE-2022-43632" + ], + "details": "This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the handling of SetQoSSettings requests to the web management portal. When parsing subelements within the QoSInfo element, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-16153.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43632" + }, + { + "type": "WEB", + "url": "https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10310" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1504/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-6j74-p6h3-8g44/GHSA-6j74-p6h3-8g44.json b/advisories/unreviewed/2023/03/GHSA-6j74-p6h3-8g44/GHSA-6j74-p6h3-8g44.json new file mode 100644 index 00000000000..3a5c2e5be75 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-6j74-p6h3-8g44/GHSA-6j74-p6h3-8g44.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6j74-p6h3-8g44", + "modified": "2023-03-29T21:30:21Z", + "published": "2023-03-29T21:30:21Z", + "aliases": [ + "CVE-2022-28646" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.2.034. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of IFC files. Crafted data in an IFC file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16570.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-28646" + }, + { + "type": "WEB", + "url": "https://www.bentley.com/en/common-vulnerability-exposure/be-2022-0006" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-616/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-6pqf-hr2v-2788/GHSA-6pqf-hr2v-2788.json b/advisories/unreviewed/2023/03/GHSA-6pqf-hr2v-2788/GHSA-6pqf-hr2v-2788.json index 3d7e919d6ed..3db5d56ec90 100644 --- a/advisories/unreviewed/2023/03/GHSA-6pqf-hr2v-2788/GHSA-6pqf-hr2v-2788.json +++ b/advisories/unreviewed/2023/03/GHSA-6pqf-hr2v-2788/GHSA-6pqf-hr2v-2788.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6pqf-hr2v-2788", - "modified": "2023-03-24T21:30:52Z", + "modified": "2023-03-29T21:30:17Z", "published": "2023-03-24T21:30:52Z", "aliases": [ "CVE-2023-21052" ], "details": "In setToExternal of ril_external_client.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-259063189References: N/A", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-24T20:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-6rww-x4m5-6j62/GHSA-6rww-x4m5-6j62.json b/advisories/unreviewed/2023/03/GHSA-6rww-x4m5-6j62/GHSA-6rww-x4m5-6j62.json new file mode 100644 index 00000000000..36b01d29854 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-6rww-x4m5-6j62/GHSA-6rww-x4m5-6j62.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6rww-x4m5-6j62", + "modified": "2023-03-29T21:30:21Z", + "published": "2023-03-29T21:30:21Z", + "aliases": [ + "CVE-2022-2825" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX V6.11.718.0. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of text encoding conversions. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-18411.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-2825" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-22-242-10" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1455/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-725m-2qgr-hprx/GHSA-725m-2qgr-hprx.json b/advisories/unreviewed/2023/03/GHSA-725m-2qgr-hprx/GHSA-725m-2qgr-hprx.json index d95f6047ae8..2744734ea19 100644 --- a/advisories/unreviewed/2023/03/GHSA-725m-2qgr-hprx/GHSA-725m-2qgr-hprx.json +++ b/advisories/unreviewed/2023/03/GHSA-725m-2qgr-hprx/GHSA-725m-2qgr-hprx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-725m-2qgr-hprx", - "modified": "2023-03-24T21:30:52Z", + "modified": "2023-03-29T21:30:22Z", "published": "2023-03-24T21:30:52Z", "aliases": [ "CVE-2023-21048" ], "details": "In handleEvent of nan.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-259304053References: N/A", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-24T20:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-743r-m8c7-27h7/GHSA-743r-m8c7-27h7.json b/advisories/unreviewed/2023/03/GHSA-743r-m8c7-27h7/GHSA-743r-m8c7-27h7.json new file mode 100644 index 00000000000..21a8ed1bfd9 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-743r-m8c7-27h7/GHSA-743r-m8c7-27h7.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-743r-m8c7-27h7", + "modified": "2023-03-29T21:30:18Z", + "published": "2023-03-29T21:30:18Z", + "aliases": [ + "CVE-2022-43637" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 12.0.1.12430. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-18626.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43637" + }, + { + "type": "WEB", + "url": "https://www.foxit.com/support/security-bulletins.html" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1657/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-7fhj-9wp7-2477/GHSA-7fhj-9wp7-2477.json b/advisories/unreviewed/2023/03/GHSA-7fhj-9wp7-2477/GHSA-7fhj-9wp7-2477.json index 659118a5384..fb1bb5255bd 100644 --- a/advisories/unreviewed/2023/03/GHSA-7fhj-9wp7-2477/GHSA-7fhj-9wp7-2477.json +++ b/advisories/unreviewed/2023/03/GHSA-7fhj-9wp7-2477/GHSA-7fhj-9wp7-2477.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7fhj-9wp7-2477", - "modified": "2023-03-24T21:30:52Z", + "modified": "2023-03-29T21:30:22Z", "published": "2023-03-24T21:30:52Z", "aliases": [ "CVE-2023-21045" ], "details": "When cpif handles probe failures, there is a possible out of bounds read due to a use after free. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-259323725References: N/A", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-24T20:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-7h5h-fqwm-4g32/GHSA-7h5h-fqwm-4g32.json b/advisories/unreviewed/2023/03/GHSA-7h5h-fqwm-4g32/GHSA-7h5h-fqwm-4g32.json new file mode 100644 index 00000000000..56b381ccab1 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-7h5h-fqwm-4g32/GHSA-7h5h-fqwm-4g32.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7h5h-fqwm-4g32", + "modified": "2023-03-29T21:30:17Z", + "published": "2023-03-29T21:30:17Z", + "aliases": [ + "CVE-2020-14140" + ], + "details": "When Xiaomi router firmware is updated in 2020, there is an unauthenticated API that can reveal WIFI password vulnerability. This vulnerability is caused by the lack of access control policies on some API interfaces. Attackers can exploit this vulnerability to enter the background and execute background command injection.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-14140" + }, + { + "type": "WEB", + "url": "https://trust.mi.com/zh-CN/misrc/bulletins/advisory?cveId=506" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-7pr7-x6mw-h647/GHSA-7pr7-x6mw-h647.json b/advisories/unreviewed/2023/03/GHSA-7pr7-x6mw-h647/GHSA-7pr7-x6mw-h647.json new file mode 100644 index 00000000000..069d4ed7830 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-7pr7-x6mw-h647/GHSA-7pr7-x6mw-h647.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7pr7-x6mw-h647", + "modified": "2023-03-29T21:30:22Z", + "published": "2023-03-29T21:30:22Z", + "aliases": [ + "CVE-2022-27647" + ], + "details": "This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the handling of the name or email field provided to libreadycloud.so. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-15874.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-27647" + }, + { + "type": "WEB", + "url": "https://kb.netgear.com/000064723/Security-Advisory-for-Multiple-Vulnerabilities-on-Multiple-Products-PSV-2021-0327" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-524/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-7vjm-f76c-4jgr/GHSA-7vjm-f76c-4jgr.json b/advisories/unreviewed/2023/03/GHSA-7vjm-f76c-4jgr/GHSA-7vjm-f76c-4jgr.json new file mode 100644 index 00000000000..2d9886bc514 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-7vjm-f76c-4jgr/GHSA-7vjm-f76c-4jgr.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7vjm-f76c-4jgr", + "modified": "2023-03-29T21:30:15Z", + "published": "2023-03-29T21:30:15Z", + "aliases": [ + "CVE-2023-28506" + ], + "details": "Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a stack-based buffer overflow, where a string is copied into a buffer using a memcpy-like function and a user-provided length. This requires a valid login to exploit.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28506" + }, + { + "type": "WEB", + "url": "https://www.rapid7.com/blog/post/2023/03/29/multiple-vulnerabilities-in-rocket-software-unirpc-server-fixed/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T21:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-7w2q-74wh-62qq/GHSA-7w2q-74wh-62qq.json b/advisories/unreviewed/2023/03/GHSA-7w2q-74wh-62qq/GHSA-7w2q-74wh-62qq.json new file mode 100644 index 00000000000..02f17217fc7 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-7w2q-74wh-62qq/GHSA-7w2q-74wh-62qq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7w2q-74wh-62qq", + "modified": "2023-03-29T21:30:19Z", + "published": "2023-03-29T21:30:19Z", + "aliases": [ + "CVE-2022-42433" + ], + "details": "This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link TL-WR841N TL-WR841N(US)_V14_220121 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the ated_tp service. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-17356.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-42433" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1466/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-83cq-237j-2w54/GHSA-83cq-237j-2w54.json b/advisories/unreviewed/2023/03/GHSA-83cq-237j-2w54/GHSA-83cq-237j-2w54.json new file mode 100644 index 00000000000..f80df971061 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-83cq-237j-2w54/GHSA-83cq-237j-2w54.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-83cq-237j-2w54", + "modified": "2023-03-29T21:30:22Z", + "published": "2023-03-29T21:30:22Z", + "aliases": [ + "CVE-2022-27648" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of KOYO Screen Creator 0.1.1.1. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of SCA2 files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-14868.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-27648" + }, + { + "type": "WEB", + "url": "https://www.koyoele.co.jp/en/topics/202203154994/" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-543/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-88v9-2vvv-pvwv/GHSA-88v9-2vvv-pvwv.json b/advisories/unreviewed/2023/03/GHSA-88v9-2vvv-pvwv/GHSA-88v9-2vvv-pvwv.json new file mode 100644 index 00000000000..6281b1dad6e --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-88v9-2vvv-pvwv/GHSA-88v9-2vvv-pvwv.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-88v9-2vvv-pvwv", + "modified": "2023-03-29T21:30:19Z", + "published": "2023-03-29T21:30:19Z", + "aliases": [ + "CVE-2022-37382" + ], + "details": "This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the removeIcon method. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-17383.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-37382" + }, + { + "type": "WEB", + "url": "https://www.foxit.com/support/security-bulletins.html" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1054/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-88wg-fvch-429c/GHSA-88wg-fvch-429c.json b/advisories/unreviewed/2023/03/GHSA-88wg-fvch-429c/GHSA-88wg-fvch-429c.json new file mode 100644 index 00000000000..2f992bd071d --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-88wg-fvch-429c/GHSA-88wg-fvch-429c.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-88wg-fvch-429c", + "modified": "2023-03-29T21:30:21Z", + "published": "2023-03-29T21:30:21Z", + "aliases": [ + "CVE-2022-36976" + ], + "details": "This vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche 6.3.2.3490. The specific flaw exists within the GroupDaoImpl class. A crafted request can trigger execution of SQL queries composed from a user-supplied string. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-15333.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36976" + }, + { + "type": "WEB", + "url": "https://download.wavelink.com/Files/avalanche_v6.3.4_release_notes.txt" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-781/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-8c56-mh3f-3268/GHSA-8c56-mh3f-3268.json b/advisories/unreviewed/2023/03/GHSA-8c56-mh3f-3268/GHSA-8c56-mh3f-3268.json new file mode 100644 index 00000000000..eb46cc5a8b8 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-8c56-mh3f-3268/GHSA-8c56-mh3f-3268.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8c56-mh3f-3268", + "modified": "2023-03-29T21:30:18Z", + "published": "2023-03-29T21:30:18Z", + "aliases": [ + "CVE-2022-43640" + ], + "details": "This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 12.0.1.12430. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF files. Crafted data in a PDF file can trigger a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-18629.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43640" + }, + { + "type": "WEB", + "url": "https://www.foxit.com/support/security-bulletins.html" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1660/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-8cf2-943h-fh5p/GHSA-8cf2-943h-fh5p.json b/advisories/unreviewed/2023/03/GHSA-8cf2-943h-fh5p/GHSA-8cf2-943h-fh5p.json new file mode 100644 index 00000000000..8ee18710080 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-8cf2-943h-fh5p/GHSA-8cf2-943h-fh5p.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8cf2-943h-fh5p", + "modified": "2023-03-29T21:30:16Z", + "published": "2023-03-29T21:30:16Z", + "aliases": [ + "CVE-2023-22705" + ], + "details": "Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Collne Inc. Welcart e-Commerce plugin <= 2.8.10 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22705" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/usc-e-shop/wordpress-welcart-e-commerce-plugin-2-8-10-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-93g9-xjvr-89v9/GHSA-93g9-xjvr-89v9.json b/advisories/unreviewed/2023/03/GHSA-93g9-xjvr-89v9/GHSA-93g9-xjvr-89v9.json new file mode 100644 index 00000000000..fcf291d068d --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-93g9-xjvr-89v9/GHSA-93g9-xjvr-89v9.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-93g9-xjvr-89v9", + "modified": "2023-03-29T21:30:18Z", + "published": "2023-03-29T21:30:18Z", + "aliases": [ + "CVE-2022-43644" + ], + "details": "This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-825 1.0.9/EE routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the Dreambox plugin for the xupnpd service, which listens on TCP port 4044. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the admin user. Was ZDI-CAN-19461.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43644" + }, + { + "type": "WEB", + "url": "https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10319" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1703/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-93vf-fhrw-pvpj/GHSA-93vf-fhrw-pvpj.json b/advisories/unreviewed/2023/03/GHSA-93vf-fhrw-pvpj/GHSA-93vf-fhrw-pvpj.json new file mode 100644 index 00000000000..c87f29ec8e9 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-93vf-fhrw-pvpj/GHSA-93vf-fhrw-pvpj.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-93vf-fhrw-pvpj", + "modified": "2023-03-29T21:30:21Z", + "published": "2023-03-29T21:30:21Z", + "aliases": [ + "CVE-2022-28313" + ], + "details": "This vulnerability allows remote attackers to disclose sensitive information on affected installations of Bentley MicroStation CONNECT 10.16.02.034. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of 3DS files. Crafted data in a 3DS file can trigger a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-16343.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-28313" + }, + { + "type": "WEB", + "url": "https://www.bentley.com/en/common-vulnerability-exposure/be-2022-0003" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-603/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-94w7-67qp-92gp/GHSA-94w7-67qp-92gp.json b/advisories/unreviewed/2023/03/GHSA-94w7-67qp-92gp/GHSA-94w7-67qp-92gp.json new file mode 100644 index 00000000000..c2cbf0abcb2 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-94w7-67qp-92gp/GHSA-94w7-67qp-92gp.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-94w7-67qp-92gp", + "modified": "2023-03-29T21:30:19Z", + "published": "2023-03-29T21:30:19Z", + "aliases": [ + "CVE-2022-43622" + ], + "details": "This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of Login requests to the web management portal. When parsing the HNAP_AUTH header, the process does not properly validate the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-16139.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43622" + }, + { + "type": "WEB", + "url": "https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10310" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1491/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-95x2-jpfx-6c98/GHSA-95x2-jpfx-6c98.json b/advisories/unreviewed/2023/03/GHSA-95x2-jpfx-6c98/GHSA-95x2-jpfx-6c98.json new file mode 100644 index 00000000000..b8c1e034cd5 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-95x2-jpfx-6c98/GHSA-95x2-jpfx-6c98.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-95x2-jpfx-6c98", + "modified": "2023-03-29T21:30:20Z", + "published": "2023-03-29T21:30:20Z", + "aliases": [ + "CVE-2022-37357" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of ICO files. Crafted data in an ICO file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-17631.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-37357" + }, + { + "type": "WEB", + "url": "https://www.tracker-software.com/product/pdf-xchange-editor/history" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1085/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-962c-q54j-xg6v/GHSA-962c-q54j-xg6v.json b/advisories/unreviewed/2023/03/GHSA-962c-q54j-xg6v/GHSA-962c-q54j-xg6v.json new file mode 100644 index 00000000000..ff521854de0 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-962c-q54j-xg6v/GHSA-962c-q54j-xg6v.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-962c-q54j-xg6v", + "modified": "2023-03-29T21:30:19Z", + "published": "2023-03-29T21:30:19Z", + "aliases": [ + "CVE-2022-37391" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.2.2.53575. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of AcroForms. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-17661.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-37391" + }, + { + "type": "WEB", + "url": "https://www.foxit.com/support/security-bulletins.html" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1063/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-98fh-32qc-74hp/GHSA-98fh-32qc-74hp.json b/advisories/unreviewed/2023/03/GHSA-98fh-32qc-74hp/GHSA-98fh-32qc-74hp.json new file mode 100644 index 00000000000..16069eb1398 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-98fh-32qc-74hp/GHSA-98fh-32qc-74hp.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-98fh-32qc-74hp", + "modified": "2023-03-29T21:30:19Z", + "published": "2023-03-29T21:30:19Z", + "aliases": [ + "CVE-2022-43612" + ], + "details": "This vulnerability allows remote attackers to disclose sensitive information on affected installations of Corel CorelDRAW Graphics Suite 23.5.0.506. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JP2 images. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-16355.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43612" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1470/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-9922-6549-73mx/GHSA-9922-6549-73mx.json b/advisories/unreviewed/2023/03/GHSA-9922-6549-73mx/GHSA-9922-6549-73mx.json new file mode 100644 index 00000000000..d6e6f86c900 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-9922-6549-73mx/GHSA-9922-6549-73mx.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9922-6549-73mx", + "modified": "2023-03-29T21:30:19Z", + "published": "2023-03-29T21:30:19Z", + "aliases": [ + "CVE-2022-43608" + ], + "details": "This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Canon imageCLASS MF644Cdw 10.03 printers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the BJNP service. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before allocating a buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-16032.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43608" + }, + { + "type": "WEB", + "url": "https://www.psirt.canon/advisory-information/cve-2022-43608_20221125" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1666/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-190" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-9cp7-c9w3-64vv/GHSA-9cp7-c9w3-64vv.json b/advisories/unreviewed/2023/03/GHSA-9cp7-c9w3-64vv/GHSA-9cp7-c9w3-64vv.json new file mode 100644 index 00000000000..85bc3b536e1 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-9cp7-c9w3-64vv/GHSA-9cp7-c9w3-64vv.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9cp7-c9w3-64vv", + "modified": "2023-03-29T21:30:19Z", + "published": "2023-03-29T21:30:19Z", + "aliases": [ + "CVE-2022-37389" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.2.2.53575. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of AcroForms. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-17545.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-37389" + }, + { + "type": "WEB", + "url": "https://www.foxit.com/support/security-bulletins.html" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1061/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-9qp4-g72v-v5g9/GHSA-9qp4-g72v-v5g9.json b/advisories/unreviewed/2023/03/GHSA-9qp4-g72v-v5g9/GHSA-9qp4-g72v-v5g9.json index 0ff3bd8f2a4..90dba8d3a81 100644 --- a/advisories/unreviewed/2023/03/GHSA-9qp4-g72v-v5g9/GHSA-9qp4-g72v-v5g9.json +++ b/advisories/unreviewed/2023/03/GHSA-9qp4-g72v-v5g9/GHSA-9qp4-g72v-v5g9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9qp4-g72v-v5g9", - "modified": "2023-03-24T21:30:52Z", + "modified": "2023-03-29T21:30:22Z", "published": "2023-03-24T21:30:52Z", "aliases": [ "CVE-2023-21050" ], "details": "In load_png_image of ExynosHWCHelper.cpp, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-244423702References: N/A", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-24T20:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-c2jq-8332-fm87/GHSA-c2jq-8332-fm87.json b/advisories/unreviewed/2023/03/GHSA-c2jq-8332-fm87/GHSA-c2jq-8332-fm87.json new file mode 100644 index 00000000000..7da91cdcc6d --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-c2jq-8332-fm87/GHSA-c2jq-8332-fm87.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c2jq-8332-fm87", + "modified": "2023-03-29T21:30:18Z", + "published": "2023-03-29T21:30:18Z", + "aliases": [ + "CVE-2022-43639" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 12.0.1.12430. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-18628.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43639" + }, + { + "type": "WEB", + "url": "https://www.foxit.com/support/security-bulletins.html" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1659/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-c459-crcf-rfqh/GHSA-c459-crcf-rfqh.json b/advisories/unreviewed/2023/03/GHSA-c459-crcf-rfqh/GHSA-c459-crcf-rfqh.json new file mode 100644 index 00000000000..9cb621b13e9 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-c459-crcf-rfqh/GHSA-c459-crcf-rfqh.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c459-crcf-rfqh", + "modified": "2023-03-29T21:30:19Z", + "published": "2023-03-29T21:30:19Z", + "aliases": [ + "CVE-2022-42425" + ], + "details": "This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of requests to modify poller broker configuration. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to escalate privileges to the level of an administrator. Was ZDI-CAN-18555.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-42425" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1396/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-c7f3-g9w9-wqqq/GHSA-c7f3-g9w9-wqqq.json b/advisories/unreviewed/2023/03/GHSA-c7f3-g9w9-wqqq/GHSA-c7f3-g9w9-wqqq.json new file mode 100644 index 00000000000..767ffa5bd77 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-c7f3-g9w9-wqqq/GHSA-c7f3-g9w9-wqqq.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c7f3-g9w9-wqqq", + "modified": "2023-03-29T21:30:20Z", + "published": "2023-03-29T21:30:20Z", + "aliases": [ + "CVE-2022-37373" + ], + "details": "This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF files. Crafted data in a PDF file can trigger a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-17810.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-37373" + }, + { + "type": "WEB", + "url": "https://www.tracker-software.com/product/pdf-xchange-editor/history" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1101/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-cf44-xc9w-h3q8/GHSA-cf44-xc9w-h3q8.json b/advisories/unreviewed/2023/03/GHSA-cf44-xc9w-h3q8/GHSA-cf44-xc9w-h3q8.json new file mode 100644 index 00000000000..d8de3e2b1c6 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-cf44-xc9w-h3q8/GHSA-cf44-xc9w-h3q8.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cf44-xc9w-h3q8", + "modified": "2023-03-29T21:30:20Z", + "published": "2023-03-29T21:30:20Z", + "aliases": [ + "CVE-2022-37379" + ], + "details": "This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the AFSpecial_KeystrokeEx method. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-17168.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-37379" + }, + { + "type": "WEB", + "url": "https://www.foxit.com/support/security-bulletins.html" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1051/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-cjvg-rm6v-pgjg/GHSA-cjvg-rm6v-pgjg.json b/advisories/unreviewed/2023/03/GHSA-cjvg-rm6v-pgjg/GHSA-cjvg-rm6v-pgjg.json new file mode 100644 index 00000000000..24548d138ca --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-cjvg-rm6v-pgjg/GHSA-cjvg-rm6v-pgjg.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cjvg-rm6v-pgjg", + "modified": "2023-03-29T21:30:20Z", + "published": "2023-03-29T21:30:20Z", + "aliases": [ + "CVE-2022-36978" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Avalanche 6.3.2.3490. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the Notification Server service. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-15448.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36978" + }, + { + "type": "WEB", + "url": "https://download.wavelink.com/Files/avalanche_v6.3.4_release_notes.txt" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-783/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-cp8x-fmj3-2w9f/GHSA-cp8x-fmj3-2w9f.json b/advisories/unreviewed/2023/03/GHSA-cp8x-fmj3-2w9f/GHSA-cp8x-fmj3-2w9f.json new file mode 100644 index 00000000000..7a1748cf066 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-cp8x-fmj3-2w9f/GHSA-cp8x-fmj3-2w9f.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cp8x-fmj3-2w9f", + "modified": "2023-03-29T21:30:21Z", + "published": "2023-03-29T21:30:21Z", + "aliases": [ + "CVE-2022-28320" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.16.02.022. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of 3DM files. The issue results from the lack of proper initialization of memory prior to accessing it. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16282.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-28320" + }, + { + "type": "WEB", + "url": "https://www.bentley.com/en/common-vulnerability-exposure/be-2022-0002" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-597/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-457" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-cv64-ghcf-rjjj/GHSA-cv64-ghcf-rjjj.json b/advisories/unreviewed/2023/03/GHSA-cv64-ghcf-rjjj/GHSA-cv64-ghcf-rjjj.json new file mode 100644 index 00000000000..f8a0b22a730 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-cv64-ghcf-rjjj/GHSA-cv64-ghcf-rjjj.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cv64-ghcf-rjjj", + "modified": "2023-03-29T21:30:20Z", + "published": "2023-03-29T21:30:20Z", + "aliases": [ + "CVE-2022-37361" + ], + "details": "This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JP2 files. Crafted data in a JP2 file can trigger a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-17674.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-37361" + }, + { + "type": "WEB", + "url": "https://www.tracker-software.com/product/pdf-xchange-editor/history" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1089/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-cvhp-xfvg-rr6v/GHSA-cvhp-xfvg-rr6v.json b/advisories/unreviewed/2023/03/GHSA-cvhp-xfvg-rr6v/GHSA-cvhp-xfvg-rr6v.json new file mode 100644 index 00000000000..44a747f580f --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-cvhp-xfvg-rr6v/GHSA-cvhp-xfvg-rr6v.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cvhp-xfvg-rr6v", + "modified": "2023-03-29T21:30:21Z", + "published": "2023-03-29T21:30:21Z", + "aliases": [ + "CVE-2022-28642" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.02.34. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of DGN files. Crafted data in a DGN file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16424.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-28642" + }, + { + "type": "WEB", + "url": "https://www.bentley.com/en/common-vulnerability-exposure/be-2022-0004" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-608/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-cxfw-2mm4-92m9/GHSA-cxfw-2mm4-92m9.json b/advisories/unreviewed/2023/03/GHSA-cxfw-2mm4-92m9/GHSA-cxfw-2mm4-92m9.json new file mode 100644 index 00000000000..51aad9ad428 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-cxfw-2mm4-92m9/GHSA-cxfw-2mm4-92m9.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cxfw-2mm4-92m9", + "modified": "2023-03-29T21:30:21Z", + "published": "2023-03-29T21:30:21Z", + "aliases": [ + "CVE-2022-28309" + ], + "details": "This vulnerability allows remote attackers to disclose sensitive information on affected installations of Bentley View 10.16.02.022. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of 3DS files. Crafted data in a 3DS file can trigger a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-16308.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-28309" + }, + { + "type": "WEB", + "url": "https://www.bentley.com/en/common-vulnerability-exposure/be-2022-0003" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-600/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-f5hr-hqp7-c2qw/GHSA-f5hr-hqp7-c2qw.json b/advisories/unreviewed/2023/03/GHSA-f5hr-hqp7-c2qw/GHSA-f5hr-hqp7-c2qw.json new file mode 100644 index 00000000000..2013882fe41 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-f5hr-hqp7-c2qw/GHSA-f5hr-hqp7-c2qw.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f5hr-hqp7-c2qw", + "modified": "2023-03-29T21:30:19Z", + "published": "2023-03-29T21:30:19Z", + "aliases": [ + "CVE-2022-43620" + ], + "details": "This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-1935 1.03 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of HNAP login requests. The issue results from the lack of proper implementation of the authentication algorithm. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-16142.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43620" + }, + { + "type": "WEB", + "url": "https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10310" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1494/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-f6pf-7qx7-fg5m/GHSA-f6pf-7qx7-fg5m.json b/advisories/unreviewed/2023/03/GHSA-f6pf-7qx7-fg5m/GHSA-f6pf-7qx7-fg5m.json new file mode 100644 index 00000000000..4186eb3753e --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-f6pf-7qx7-fg5m/GHSA-f6pf-7qx7-fg5m.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f6pf-7qx7-fg5m", + "modified": "2023-03-29T21:30:21Z", + "published": "2023-03-29T21:30:21Z", + "aliases": [ + "CVE-2022-28685" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 2020 SP2 Patch 0(4201.2111.1802.0000). User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of APP files. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-17212.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-28685" + }, + { + "type": "WEB", + "url": "https://www.aveva.com/content/dam/aveva/documents/support/cyber-security-updates/SecurityBulletin_AVEVA-2022-005.pdf" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1124/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-f952-wvmx-6w24/GHSA-f952-wvmx-6w24.json b/advisories/unreviewed/2023/03/GHSA-f952-wvmx-6w24/GHSA-f952-wvmx-6w24.json new file mode 100644 index 00000000000..415f175214d --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-f952-wvmx-6w24/GHSA-f952-wvmx-6w24.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f952-wvmx-6w24", + "modified": "2023-03-29T21:30:21Z", + "published": "2023-03-29T21:30:21Z", + "aliases": [ + "CVE-2022-2848" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX V6.11.718.0. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of text encoding conversions. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-16486.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-2848" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-22-242-10" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1454/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-f9v3-rvrm-52r5/GHSA-f9v3-rvrm-52r5.json b/advisories/unreviewed/2023/03/GHSA-f9v3-rvrm-52r5/GHSA-f9v3-rvrm-52r5.json new file mode 100644 index 00000000000..8c57271e503 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-f9v3-rvrm-52r5/GHSA-f9v3-rvrm-52r5.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f9v3-rvrm-52r5", + "modified": "2023-03-29T21:30:15Z", + "published": "2023-03-29T21:30:15Z", + "aliases": [ + "CVE-2023-28508" + ], + "details": "Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a heap-based overflow vulnerability, where certain input can corrupt the heap and crash the forked process.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28508" + }, + { + "type": "WEB", + "url": "https://www.rapid7.com/blog/post/2023/03/29/multiple-vulnerabilities-in-rocket-software-unirpc-server-fixed/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T21:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-f9vp-qm5c-2255/GHSA-f9vp-qm5c-2255.json b/advisories/unreviewed/2023/03/GHSA-f9vp-qm5c-2255/GHSA-f9vp-qm5c-2255.json new file mode 100644 index 00000000000..bf7d423f3fc --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-f9vp-qm5c-2255/GHSA-f9vp-qm5c-2255.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f9vp-qm5c-2255", + "modified": "2023-03-29T21:30:20Z", + "published": "2023-03-29T21:30:20Z", + "aliases": [ + "CVE-2022-37350" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Collab objects. By performing actions in JavaScript, an attacker can trigger a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-17144.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-37350" + }, + { + "type": "WEB", + "url": "https://www.tracker-software.com/product/pdf-xchange-editor/history" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1078/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-fff6-82fr-q9xp/GHSA-fff6-82fr-q9xp.json b/advisories/unreviewed/2023/03/GHSA-fff6-82fr-q9xp/GHSA-fff6-82fr-q9xp.json new file mode 100644 index 00000000000..9c7c9857a51 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-fff6-82fr-q9xp/GHSA-fff6-82fr-q9xp.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fff6-82fr-q9xp", + "modified": "2023-03-29T21:30:18Z", + "published": "2023-03-29T21:30:18Z", + "aliases": [ + "CVE-2022-43650" + ], + "details": "This vulnerability allows remote attackers to disclose sensitive information on affected installations of RARLAB WinRAR 6.11.0.0. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of ZIP files. Crafted data in a ZIP file can trigger a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-19232.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43650" + }, + { + "type": "WEB", + "url": "https://www.win-rar.com/singlenewsview.html?&L=0&tx_ttnews%5Btt_news%5D=216&cHash=983dfbcc83fb1b64a5f792891a281709" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-23-092/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-fh4c-rwgp-mc5v/GHSA-fh4c-rwgp-mc5v.json b/advisories/unreviewed/2023/03/GHSA-fh4c-rwgp-mc5v/GHSA-fh4c-rwgp-mc5v.json new file mode 100644 index 00000000000..e9163bb0f13 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-fh4c-rwgp-mc5v/GHSA-fh4c-rwgp-mc5v.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fh4c-rwgp-mc5v", + "modified": "2023-03-29T21:30:19Z", + "published": "2023-03-29T21:30:19Z", + "aliases": [ + "CVE-2022-42427" + ], + "details": "This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the contact groups configuration page. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to escalate privileges to the level of an administrator. Was ZDI-CAN-18541.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-42427" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1398/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-fjv7-v9cp-p3jq/GHSA-fjv7-v9cp-p3jq.json b/advisories/unreviewed/2023/03/GHSA-fjv7-v9cp-p3jq/GHSA-fjv7-v9cp-p3jq.json new file mode 100644 index 00000000000..42c91cad6bf --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-fjv7-v9cp-p3jq/GHSA-fjv7-v9cp-p3jq.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fjv7-v9cp-p3jq", + "modified": "2023-03-29T21:30:20Z", + "published": "2023-03-29T21:30:20Z", + "aliases": [ + "CVE-2022-37370" + ], + "details": "This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF files. Crafted data in a PDF file can trigger a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-17725.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-37370" + }, + { + "type": "WEB", + "url": "https://www.tracker-software.com/product/pdf-xchange-editor/history" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1098/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-fq3j-rpjj-667v/GHSA-fq3j-rpjj-667v.json b/advisories/unreviewed/2023/03/GHSA-fq3j-rpjj-667v/GHSA-fq3j-rpjj-667v.json new file mode 100644 index 00000000000..a10a6835033 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-fq3j-rpjj-667v/GHSA-fq3j-rpjj-667v.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fq3j-rpjj-667v", + "modified": "2023-03-29T21:30:18Z", + "published": "2023-03-29T21:30:18Z", + "aliases": [ + "CVE-2022-43641" + ], + "details": "This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 12.0.1.12430. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-18894.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43641" + }, + { + "type": "WEB", + "url": "https://www.foxit.com/support/security-bulletins.html" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1661/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-frrc-f75h-9j62/GHSA-frrc-f75h-9j62.json b/advisories/unreviewed/2023/03/GHSA-frrc-f75h-9j62/GHSA-frrc-f75h-9j62.json new file mode 100644 index 00000000000..0ea9046b06f --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-frrc-f75h-9j62/GHSA-frrc-f75h-9j62.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-frrc-f75h-9j62", + "modified": "2023-03-29T21:30:16Z", + "published": "2023-03-29T21:30:16Z", + "aliases": [ + "CVE-2017-6894" + ], + "details": "A vulnerability exists in FlexNet Manager Suite releases 2015 R2 SP3 and earlier (including FlexNet Manager Platform 9.2 and earlier) that affects the inventory gathering components and can be exploited by local users to perform certain actions with elevated privileges on the local system.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2017-6894" + }, + { + "type": "WEB", + "url": "https://community.flexera.com/t5/FlexNet-Manager-Knowledge-Base/A-vulnerability-exists-in-FlexNet-Manager-Suite-release-2015-R2/ta-p/1891" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T21:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-fv8v-x6r7-4jm8/GHSA-fv8v-x6r7-4jm8.json b/advisories/unreviewed/2023/03/GHSA-fv8v-x6r7-4jm8/GHSA-fv8v-x6r7-4jm8.json new file mode 100644 index 00000000000..bdca9226761 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-fv8v-x6r7-4jm8/GHSA-fv8v-x6r7-4jm8.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fv8v-x6r7-4jm8", + "modified": "2023-03-29T21:30:19Z", + "published": "2023-03-29T21:30:19Z", + "aliases": [ + "CVE-2022-43628" + ], + "details": "This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the handling of SetIPv6FirewallSettings requests to the web management portal. When parsing subelements within the IPv6FirewallRule element, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-16148.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43628" + }, + { + "type": "WEB", + "url": "https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10310" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1499/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-fvpr-q9j2-9vq7/GHSA-fvpr-q9j2-9vq7.json b/advisories/unreviewed/2023/03/GHSA-fvpr-q9j2-9vq7/GHSA-fvpr-q9j2-9vq7.json new file mode 100644 index 00000000000..37c1974af4b --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-fvpr-q9j2-9vq7/GHSA-fvpr-q9j2-9vq7.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fvpr-q9j2-9vq7", + "modified": "2023-03-29T21:30:19Z", + "published": "2023-03-29T21:30:19Z", + "aliases": [ + "CVE-2022-37385" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Doc objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-17301.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-37385" + }, + { + "type": "WEB", + "url": "https://www.foxit.com/support/security-bulletins.html" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1057/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-fwj9-7qq8-jc93/GHSA-fwj9-7qq8-jc93.json b/advisories/unreviewed/2023/03/GHSA-fwj9-7qq8-jc93/GHSA-fwj9-7qq8-jc93.json new file mode 100644 index 00000000000..b67412aede7 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-fwj9-7qq8-jc93/GHSA-fwj9-7qq8-jc93.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fwj9-7qq8-jc93", + "modified": "2023-03-29T21:30:18Z", + "published": "2023-03-29T21:30:18Z", + "aliases": [ + "CVE-2022-43634" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the dsi_writeinit function. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-17646.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43634" + }, + { + "type": "WEB", + "url": "https://github.com/Netatalk/Netatalk/pull/186" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-23-094/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-g594-6376-7c5r/GHSA-g594-6376-7c5r.json b/advisories/unreviewed/2023/03/GHSA-g594-6376-7c5r/GHSA-g594-6376-7c5r.json new file mode 100644 index 00000000000..2b10334b40f --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-g594-6376-7c5r/GHSA-g594-6376-7c5r.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g594-6376-7c5r", + "modified": "2023-03-29T21:30:16Z", + "published": "2023-03-29T21:30:16Z", + "aliases": [ + "CVE-2023-28503" + ], + "details": "Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from an authentication bypass vulnerability, where a special username with a deterministic password can be leveraged to bypass authentication checks and execute OS commands as the root user.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28503" + }, + { + "type": "WEB", + "url": "https://www.rapid7.com/blog/post/2023/03/29/multiple-vulnerabilities-in-rocket-software-unirpc-server-fixed/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T21:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-g5fp-qxxg-w295/GHSA-g5fp-qxxg-w295.json b/advisories/unreviewed/2023/03/GHSA-g5fp-qxxg-w295/GHSA-g5fp-qxxg-w295.json new file mode 100644 index 00000000000..8cd214e87ad --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-g5fp-qxxg-w295/GHSA-g5fp-qxxg-w295.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g5fp-qxxg-w295", + "modified": "2023-03-29T21:30:18Z", + "published": "2023-03-29T21:30:18Z", + "aliases": [ + "CVE-2022-43649" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 12.0.2.12465. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-19478.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43649" + }, + { + "type": "WEB", + "url": "https://www.foxit.com/support/security-bulletins.html" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-23-091/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-g995-wpvr-c8gv/GHSA-g995-wpvr-c8gv.json b/advisories/unreviewed/2023/03/GHSA-g995-wpvr-c8gv/GHSA-g995-wpvr-c8gv.json new file mode 100644 index 00000000000..e1b0b6fd335 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-g995-wpvr-c8gv/GHSA-g995-wpvr-c8gv.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g995-wpvr-c8gv", + "modified": "2023-03-29T21:30:20Z", + "published": "2023-03-29T21:30:20Z", + "aliases": [ + "CVE-2022-37366" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Doc objects. By performing actions in JavaScript, an attacker can trigger a read past the end of an allocated object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-17727.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-37366" + }, + { + "type": "WEB", + "url": "https://www.tracker-software.com/product/pdf-xchange-editor/history" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1094/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-gcjr-346m-7x54/GHSA-gcjr-346m-7x54.json b/advisories/unreviewed/2023/03/GHSA-gcjr-346m-7x54/GHSA-gcjr-346m-7x54.json new file mode 100644 index 00000000000..55145d02470 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-gcjr-346m-7x54/GHSA-gcjr-346m-7x54.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gcjr-346m-7x54", + "modified": "2023-03-29T21:30:19Z", + "published": "2023-03-29T21:30:19Z", + "aliases": [ + "CVE-2022-42431" + ], + "details": "This vulnerability allows local attackers to escalate privileges on affected Tesla vehicles. An attacker must first obtain the ability to execute privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the bcmdhd driver. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a buffer. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of root. Was ZDI-CAN-17544.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-42431" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1407/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-gh4v-v2hh-g9m6/GHSA-gh4v-v2hh-g9m6.json b/advisories/unreviewed/2023/03/GHSA-gh4v-v2hh-g9m6/GHSA-gh4v-v2hh-g9m6.json new file mode 100644 index 00000000000..c6ad97d01f4 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-gh4v-v2hh-g9m6/GHSA-gh4v-v2hh-g9m6.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gh4v-v2hh-g9m6", + "modified": "2023-03-29T21:30:20Z", + "published": "2023-03-29T21:30:20Z", + "aliases": [ + "CVE-2022-37013" + ], + "details": "This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Unified Automation OPC UA C++ Demo Server 1.7.6-537 [with vendor rollup]. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of certificates. A crafted certificate can force the server into an infinite loop. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-17203.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-37013" + }, + { + "type": "WEB", + "url": "https://documentation.unified-automation.com/uasdkcpp/1.7.7/CHANGELOG.txt" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1029/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-835" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-ghqp-75mj-j4x8/GHSA-ghqp-75mj-j4x8.json b/advisories/unreviewed/2023/03/GHSA-ghqp-75mj-j4x8/GHSA-ghqp-75mj-j4x8.json new file mode 100644 index 00000000000..781c35c08cd --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-ghqp-75mj-j4x8/GHSA-ghqp-75mj-j4x8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ghqp-75mj-j4x8", + "modified": "2023-03-29T21:30:19Z", + "published": "2023-03-29T21:30:19Z", + "aliases": [ + "CVE-2022-43618" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Corel CorelDRAW Graphics Suite 23.5.0.506. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PCX files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16377.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43618" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1476/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-gm89-j9wr-p8rw/GHSA-gm89-j9wr-p8rw.json b/advisories/unreviewed/2023/03/GHSA-gm89-j9wr-p8rw/GHSA-gm89-j9wr-p8rw.json new file mode 100644 index 00000000000..969dc37d576 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-gm89-j9wr-p8rw/GHSA-gm89-j9wr-p8rw.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gm89-j9wr-p8rw", + "modified": "2023-03-29T21:30:21Z", + "published": "2023-03-29T21:30:21Z", + "aliases": [ + "CVE-2022-28315" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.02.34. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of IFC files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16367.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-28315" + }, + { + "type": "WEB", + "url": "https://www.bentley.com/en/common-vulnerability-exposure/be-2022-0006" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-606/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-gm9h-jqqh-9434/GHSA-gm9h-jqqh-9434.json b/advisories/unreviewed/2023/03/GHSA-gm9h-jqqh-9434/GHSA-gm9h-jqqh-9434.json new file mode 100644 index 00000000000..c667844baf5 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-gm9h-jqqh-9434/GHSA-gm9h-jqqh-9434.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gm9h-jqqh-9434", + "modified": "2023-03-29T21:30:22Z", + "published": "2023-03-29T21:30:22Z", + "aliases": [ + "CVE-2022-28301" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.02.34. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of IFC files. Crafted data in an IFC file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16392.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-28301" + }, + { + "type": "WEB", + "url": "https://www.bentley.com/en/common-vulnerability-exposure/be-2022-0006" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-612/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-gm9p-w68v-q8rp/GHSA-gm9p-w68v-q8rp.json b/advisories/unreviewed/2023/03/GHSA-gm9p-w68v-q8rp/GHSA-gm9p-w68v-q8rp.json new file mode 100644 index 00000000000..80db096f1c9 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-gm9p-w68v-q8rp/GHSA-gm9p-w68v-q8rp.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gm9p-w68v-q8rp", + "modified": "2023-03-29T21:30:21Z", + "published": "2023-03-29T21:30:21Z", + "aliases": [ + "CVE-2022-28318" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.02.34. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of IFC files. Crafted data in an IFC file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16379.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-28318" + }, + { + "type": "WEB", + "url": "https://www.bentley.com/en/common-vulnerability-exposure/be-2022-0006" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-618/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-gqv3-mwv7-3fg9/GHSA-gqv3-mwv7-3fg9.json b/advisories/unreviewed/2023/03/GHSA-gqv3-mwv7-3fg9/GHSA-gqv3-mwv7-3fg9.json new file mode 100644 index 00000000000..8ac10f64e06 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-gqv3-mwv7-3fg9/GHSA-gqv3-mwv7-3fg9.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gqv3-mwv7-3fg9", + "modified": "2023-03-29T21:30:21Z", + "published": "2023-03-29T21:30:21Z", + "aliases": [ + "CVE-2022-36970" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 20.0 Build: 4201.2111.1802.0000 Service Pack 2. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of APP files. Crafted data in a APP file can cause the application to execute arbitrary Visual Basic scripts. The user interface fails to provide sufficient indication of the hazard. An attacker can leverage this vulnerability to execute code in the context of current process. Was ZDI-CAN-17370.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36970" + }, + { + "type": "WEB", + "url": "https://www.aveva.com/content/dam/aveva/documents/support/cyber-security-updates/SecurityBulletin_AVEVA-2022-005.pdf" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1129/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-356" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-h3mx-pc7w-4qh2/GHSA-h3mx-pc7w-4qh2.json b/advisories/unreviewed/2023/03/GHSA-h3mx-pc7w-4qh2/GHSA-h3mx-pc7w-4qh2.json index ac3b3f00b88..6243c7505a0 100644 --- a/advisories/unreviewed/2023/03/GHSA-h3mx-pc7w-4qh2/GHSA-h3mx-pc7w-4qh2.json +++ b/advisories/unreviewed/2023/03/GHSA-h3mx-pc7w-4qh2/GHSA-h3mx-pc7w-4qh2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h3mx-pc7w-4qh2", - "modified": "2023-03-24T21:30:53Z", + "modified": "2023-03-29T21:30:22Z", "published": "2023-03-24T21:30:53Z", "aliases": [ "CVE-2023-21060" ], "details": "In sms_GetTpPiIe of sms_PduCodec.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-253770924References: N/A", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-24T20:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-h75r-g3wx-p3m3/GHSA-h75r-g3wx-p3m3.json b/advisories/unreviewed/2023/03/GHSA-h75r-g3wx-p3m3/GHSA-h75r-g3wx-p3m3.json new file mode 100644 index 00000000000..e31fd5b4fdd --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-h75r-g3wx-p3m3/GHSA-h75r-g3wx-p3m3.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h75r-g3wx-p3m3", + "modified": "2023-03-29T21:30:20Z", + "published": "2023-03-29T21:30:20Z", + "aliases": [ + "CVE-2022-37380" + ], + "details": "This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of ADBC objects. By performing actions in JavaScript, an attacker can trigger a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-17169.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-37380" + }, + { + "type": "WEB", + "url": "https://www.foxit.com/support/security-bulletins.html" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1052/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-h8wj-xxvx-cv2r/GHSA-h8wj-xxvx-cv2r.json b/advisories/unreviewed/2023/03/GHSA-h8wj-xxvx-cv2r/GHSA-h8wj-xxvx-cv2r.json new file mode 100644 index 00000000000..777df33aa6c --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-h8wj-xxvx-cv2r/GHSA-h8wj-xxvx-cv2r.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h8wj-xxvx-cv2r", + "modified": "2023-03-29T21:30:22Z", + "published": "2023-03-29T21:30:22Z", + "aliases": [ + "CVE-2022-27643" + ], + "details": "This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of SOAP requests. When parsing the SOAPAction header, the process does not properly validate the length of user-supplied data prior to copying it to a buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-15692.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-27643" + }, + { + "type": "WEB", + "url": "https://kb.netgear.com/000064720/Security-Advisory-for-Pre-Authentication-Buffer-Overflow-on-Multiple-Products-PSV-2021-0323" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-519/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-h9h8-v9p8-wfqp/GHSA-h9h8-v9p8-wfqp.json b/advisories/unreviewed/2023/03/GHSA-h9h8-v9p8-wfqp/GHSA-h9h8-v9p8-wfqp.json index 87ddcf53e40..1b8be3054c5 100644 --- a/advisories/unreviewed/2023/03/GHSA-h9h8-v9p8-wfqp/GHSA-h9h8-v9p8-wfqp.json +++ b/advisories/unreviewed/2023/03/GHSA-h9h8-v9p8-wfqp/GHSA-h9h8-v9p8-wfqp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h9h8-v9p8-wfqp", - "modified": "2023-03-24T21:30:53Z", + "modified": "2023-03-29T21:30:17Z", "published": "2023-03-24T21:30:53Z", "aliases": [ "CVE-2023-21064" ], "details": "In DoSetPinControl of miscservice.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-243130078References: N/A", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-24T20:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-hg7f-vxww-gm23/GHSA-hg7f-vxww-gm23.json b/advisories/unreviewed/2023/03/GHSA-hg7f-vxww-gm23/GHSA-hg7f-vxww-gm23.json new file mode 100644 index 00000000000..544c5b2c825 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-hg7f-vxww-gm23/GHSA-hg7f-vxww-gm23.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hg7f-vxww-gm23", + "modified": "2023-03-29T21:30:21Z", + "published": "2023-03-29T21:30:21Z", + "aliases": [ + "CVE-2022-28310" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.02.034. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of SKP files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16339.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-28310" + }, + { + "type": "WEB", + "url": "https://www.bentley.com/en/common-vulnerability-exposure/be-2022-0009" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-590/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-hgmf-x9rw-2cf9/GHSA-hgmf-x9rw-2cf9.json b/advisories/unreviewed/2023/03/GHSA-hgmf-x9rw-2cf9/GHSA-hgmf-x9rw-2cf9.json new file mode 100644 index 00000000000..2ebdbc52bfa --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-hgmf-x9rw-2cf9/GHSA-hgmf-x9rw-2cf9.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hgmf-x9rw-2cf9", + "modified": "2023-03-29T21:30:21Z", + "published": "2023-03-29T21:30:21Z", + "aliases": [ + "CVE-2022-28307" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.16.02.022. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of DXF files. Crafted data in a DXF file can trigger a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16306.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-28307" + }, + { + "type": "WEB", + "url": "https://www.bentley.com/en/common-vulnerability-exposure/be-2022-0005" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-598/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-hx4j-3826-jwrv/GHSA-hx4j-3826-jwrv.json b/advisories/unreviewed/2023/03/GHSA-hx4j-3826-jwrv/GHSA-hx4j-3826-jwrv.json index f97e793e8d3..831f2a8609b 100644 --- a/advisories/unreviewed/2023/03/GHSA-hx4j-3826-jwrv/GHSA-hx4j-3826-jwrv.json +++ b/advisories/unreviewed/2023/03/GHSA-hx4j-3826-jwrv/GHSA-hx4j-3826-jwrv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hx4j-3826-jwrv", - "modified": "2023-03-24T21:30:52Z", + "modified": "2023-03-29T21:30:23Z", "published": "2023-03-24T21:30:52Z", "aliases": [ "CVE-2023-21043" ], "details": "In (TBD) of (TBD), there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-239872581References: N/A", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-24T20:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-j6jr-7hqv-4mp7/GHSA-j6jr-7hqv-4mp7.json b/advisories/unreviewed/2023/03/GHSA-j6jr-7hqv-4mp7/GHSA-j6jr-7hqv-4mp7.json new file mode 100644 index 00000000000..53bbfc61091 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-j6jr-7hqv-4mp7/GHSA-j6jr-7hqv-4mp7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j6jr-7hqv-4mp7", + "modified": "2023-03-29T21:30:16Z", + "published": "2023-03-29T21:30:16Z", + "aliases": [ + "CVE-2023-28502" + ], + "details": "Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a stack-based buffer overflow in the \"udadmin\" service that can lead to remote code execution as the root user.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28502" + }, + { + "type": "WEB", + "url": "https://www.rapid7.com/blog/post/2023/03/29/multiple-vulnerabilities-in-rocket-software-unirpc-server-fixed/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T21:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-j6p3-mvwv-6qc2/GHSA-j6p3-mvwv-6qc2.json b/advisories/unreviewed/2023/03/GHSA-j6p3-mvwv-6qc2/GHSA-j6p3-mvwv-6qc2.json new file mode 100644 index 00000000000..1d694d4c426 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-j6p3-mvwv-6qc2/GHSA-j6p3-mvwv-6qc2.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j6p3-mvwv-6qc2", + "modified": "2023-03-29T21:30:20Z", + "published": "2023-03-29T21:30:20Z", + "aliases": [ + "CVE-2022-37376" + ], + "details": "This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Editor 11.1.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of arrays. By performing actions in JavaScript, an attacker can trigger a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-16599.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-37376" + }, + { + "type": "WEB", + "url": "https://www.foxit.com/support/security-bulletins.html" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1048/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-j9gx-w67p-w37r/GHSA-j9gx-w67p-w37r.json b/advisories/unreviewed/2023/03/GHSA-j9gx-w67p-w37r/GHSA-j9gx-w67p-w37r.json new file mode 100644 index 00000000000..cf5a609b4d2 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-j9gx-w67p-w37r/GHSA-j9gx-w67p-w37r.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j9gx-w67p-w37r", + "modified": "2023-03-29T21:30:21Z", + "published": "2023-03-29T21:30:21Z", + "aliases": [ + "CVE-2022-36969" + ], + "details": "This vulnerability allows remote attackers to disclose sensitive information on affected installations of AVEVA Edge 2020 SP2 Patch 0(4201.2111.1802.0000). User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the LoadImportedLibraries method. Due to the improper restriction of XML External Entity (XXE) references, a crafted document specifying a URI causes the XML parser to access the URI and embed the contents back into the XML document for further processing. An attacker can leverage this vulnerability to disclose information in the context of the current process. Was ZDI-CAN-17394.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36969" + }, + { + "type": "WEB", + "url": "https://www.aveva.com/content/dam/aveva/documents/support/cyber-security-updates/SecurityBulletin_AVEVA-2022-005.pdf" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1128/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-611" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-jf9h-v46r-899c/GHSA-jf9h-v46r-899c.json b/advisories/unreviewed/2023/03/GHSA-jf9h-v46r-899c/GHSA-jf9h-v46r-899c.json new file mode 100644 index 00000000000..b7de79b088e --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-jf9h-v46r-899c/GHSA-jf9h-v46r-899c.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jf9h-v46r-899c", + "modified": "2023-03-29T21:30:21Z", + "published": "2023-03-29T21:30:21Z", + "aliases": [ + "CVE-2022-28647" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.2.034. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of IFC files. Crafted data in an IFC file can trigger a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16573.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-28647" + }, + { + "type": "WEB", + "url": "https://www.bentley.com/en/common-vulnerability-exposure/be-2022-0006" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-617/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-jfmw-22wh-9p3p/GHSA-jfmw-22wh-9p3p.json b/advisories/unreviewed/2023/03/GHSA-jfmw-22wh-9p3p/GHSA-jfmw-22wh-9p3p.json new file mode 100644 index 00000000000..4652c979709 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-jfmw-22wh-9p3p/GHSA-jfmw-22wh-9p3p.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jfmw-22wh-9p3p", + "modified": "2023-03-29T21:30:20Z", + "published": "2023-03-29T21:30:20Z", + "aliases": [ + "CVE-2022-37372" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF files. Crafted data in a PDF file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-17809.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-37372" + }, + { + "type": "WEB", + "url": "https://www.tracker-software.com/product/pdf-xchange-editor/history" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1100/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-jhgx-rh52-857w/GHSA-jhgx-rh52-857w.json b/advisories/unreviewed/2023/03/GHSA-jhgx-rh52-857w/GHSA-jhgx-rh52-857w.json new file mode 100644 index 00000000000..2d5bd2e5e31 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-jhgx-rh52-857w/GHSA-jhgx-rh52-857w.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jhgx-rh52-857w", + "modified": "2023-03-29T21:30:20Z", + "published": "2023-03-29T21:30:20Z", + "aliases": [ + "CVE-2022-37360" + ], + "details": "This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of EMF files. Crafted data in an EMF file can trigger a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-17635.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-37360" + }, + { + "type": "WEB", + "url": "https://www.tracker-software.com/product/pdf-xchange-editor/history" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1088/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-jhq5-5c6h-9xj2/GHSA-jhq5-5c6h-9xj2.json b/advisories/unreviewed/2023/03/GHSA-jhq5-5c6h-9xj2/GHSA-jhq5-5c6h-9xj2.json new file mode 100644 index 00000000000..c084fca4b78 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-jhq5-5c6h-9xj2/GHSA-jhq5-5c6h-9xj2.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jhq5-5c6h-9xj2", + "modified": "2023-03-29T21:30:16Z", + "published": "2023-03-29T21:30:16Z", + "aliases": [ + "CVE-2023-28501" + ], + "details": "Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a heap-based buffer overflow in the unirpcd daemon that, if successfully exploited, can lead to remote code execution as the root user.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28501" + }, + { + "type": "WEB", + "url": "https://www.rapid7.com/blog/post/2023/03/29/multiple-vulnerabilities-in-rocket-software-unirpc-server-fixed/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-jmxp-55h2-rg35/GHSA-jmxp-55h2-rg35.json b/advisories/unreviewed/2023/03/GHSA-jmxp-55h2-rg35/GHSA-jmxp-55h2-rg35.json new file mode 100644 index 00000000000..a86802aa0fb --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-jmxp-55h2-rg35/GHSA-jmxp-55h2-rg35.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jmxp-55h2-rg35", + "modified": "2023-03-29T21:30:19Z", + "published": "2023-03-29T21:30:19Z", + "aliases": [ + "CVE-2022-3093" + ], + "details": "This vulnerability allows physical attackers to execute arbitrary code on affected Tesla vehicles. Authentication is not required to exploit this vulnerability. The specific flaw exists within the ice_updater update mechanism. The issue results from the lack of proper validation of user-supplied firmware. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-17463.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-3093" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1188/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-367" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-jr7h-mp2v-g8f4/GHSA-jr7h-mp2v-g8f4.json b/advisories/unreviewed/2023/03/GHSA-jr7h-mp2v-g8f4/GHSA-jr7h-mp2v-g8f4.json new file mode 100644 index 00000000000..b44411b2f9a --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-jr7h-mp2v-g8f4/GHSA-jr7h-mp2v-g8f4.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jr7h-mp2v-g8f4", + "modified": "2023-03-29T21:30:18Z", + "published": "2023-03-29T21:30:18Z", + "aliases": [ + "CVE-2022-43633" + ], + "details": "This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the handling of SetSysLogSettings requests to the web management portal. When parsing the IPAddress element, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-16154.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43633" + }, + { + "type": "WEB", + "url": "https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10310" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1505/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-jv3h-vgc4-3286/GHSA-jv3h-vgc4-3286.json b/advisories/unreviewed/2023/03/GHSA-jv3h-vgc4-3286/GHSA-jv3h-vgc4-3286.json new file mode 100644 index 00000000000..7258ad31d19 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-jv3h-vgc4-3286/GHSA-jv3h-vgc4-3286.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jv3h-vgc4-3286", + "modified": "2023-03-29T21:30:22Z", + "published": "2023-03-29T21:30:22Z", + "aliases": [ + "CVE-2022-27645" + ], + "details": "This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within readycloud_control.cgi. The issue results from incorrect string matching logic when accessing protected pages. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-15762.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-27645" + }, + { + "type": "WEB", + "url": "https://kb.netgear.com/000064722/Security-Advisory-for-Sensitive-Information-Disclosure-on-Some-Routers-and-Fixed-Wireless-Products-PSV-2021-0325" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-522/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-jvgw-wcf7-8qhm/GHSA-jvgw-wcf7-8qhm.json b/advisories/unreviewed/2023/03/GHSA-jvgw-wcf7-8qhm/GHSA-jvgw-wcf7-8qhm.json new file mode 100644 index 00000000000..3d88cecd735 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-jvgw-wcf7-8qhm/GHSA-jvgw-wcf7-8qhm.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jvgw-wcf7-8qhm", + "modified": "2023-03-29T21:30:21Z", + "published": "2023-03-29T21:30:21Z", + "aliases": [ + "CVE-2022-28317" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.02.34. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of IFC files. The issue results from the lack of proper initialization of memory prior to accessing it. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16369.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-28317" + }, + { + "type": "WEB", + "url": "https://www.bentley.com/en/common-vulnerability-exposure/be-2022-0006" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-604/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-457" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-jvxm-jqvh-vw8w/GHSA-jvxm-jqvh-vw8w.json b/advisories/unreviewed/2023/03/GHSA-jvxm-jqvh-vw8w/GHSA-jvxm-jqvh-vw8w.json new file mode 100644 index 00000000000..46ae9bfc526 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-jvxm-jqvh-vw8w/GHSA-jvxm-jqvh-vw8w.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jvxm-jqvh-vw8w", + "modified": "2023-03-29T21:30:19Z", + "published": "2023-03-29T21:30:19Z", + "aliases": [ + "CVE-2022-43613" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Corel CorelDRAW Graphics Suite 23.5.0.506. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of CGM files. When parsing CGM files, the process does not properly validate the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16356.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43613" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1471/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-jw63-hmqg-58g3/GHSA-jw63-hmqg-58g3.json b/advisories/unreviewed/2023/03/GHSA-jw63-hmqg-58g3/GHSA-jw63-hmqg-58g3.json index 40fb27f873f..ea4841c1539 100644 --- a/advisories/unreviewed/2023/03/GHSA-jw63-hmqg-58g3/GHSA-jw63-hmqg-58g3.json +++ b/advisories/unreviewed/2023/03/GHSA-jw63-hmqg-58g3/GHSA-jw63-hmqg-58g3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jw63-hmqg-58g3", - "modified": "2023-03-22T06:30:21Z", + "modified": "2023-03-29T21:30:17Z", "published": "2023-03-22T06:30:21Z", "aliases": [ "CVE-2023-28005" ], "details": "A vulnerability in Trend Micro Endpoint Encryption Full Disk Encryption version 6.0.0.3204 and below could allow an attacker with physical access to an affected device to bypass Microsoft Windows? Secure Boot process in an attempt to execute other attacks to obtain access to the contents of the device. An attacker must first obtain physical access to the target system in order to exploit this vulnerability. It is also important to note that the contents of the drive(s) encrypted with TMEE FDE would still be protected and would NOT be accessible by the attacker by exploitation of this vulnerability alone.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-22T06:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-m46g-8pc6-m8q7/GHSA-m46g-8pc6-m8q7.json b/advisories/unreviewed/2023/03/GHSA-m46g-8pc6-m8q7/GHSA-m46g-8pc6-m8q7.json new file mode 100644 index 00000000000..eb9f8344411 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-m46g-8pc6-m8q7/GHSA-m46g-8pc6-m8q7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m46g-8pc6-m8q7", + "modified": "2023-03-29T21:30:16Z", + "published": "2023-03-29T21:30:16Z", + "aliases": [ + "CVE-2022-3787" + ], + "details": "A vulnerability was found in the device-mapper-multipath. The device-mapper-multipath allows local users to obtain root access, exploited alone or in conjunction with CVE-2022-41973. Local users that are able to write to UNIX domain sockets can bypass access controls and manipulate the multipath setup. This issue occurs because an attacker can repeat a keyword, which is mishandled when arithmetic ADD is used instead of bitwise OR. This could lead to local privilege escalation to root.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-3787" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2138959" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T21:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-m5q4-m78h-xjw6/GHSA-m5q4-m78h-xjw6.json b/advisories/unreviewed/2023/03/GHSA-m5q4-m78h-xjw6/GHSA-m5q4-m78h-xjw6.json new file mode 100644 index 00000000000..fa919339be0 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-m5q4-m78h-xjw6/GHSA-m5q4-m78h-xjw6.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m5q4-m78h-xjw6", + "modified": "2023-03-29T21:30:22Z", + "published": "2023-03-29T21:30:22Z", + "aliases": [ + "CVE-2022-28305" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.02.034. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of OBJ files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16172.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-28305" + }, + { + "type": "WEB", + "url": "https://www.bentley.com/en/common-vulnerability-exposure/be-2022-0008" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-593/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-m68p-4w8c-8x3r/GHSA-m68p-4w8c-8x3r.json b/advisories/unreviewed/2023/03/GHSA-m68p-4w8c-8x3r/GHSA-m68p-4w8c-8x3r.json new file mode 100644 index 00000000000..35b136fe018 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-m68p-4w8c-8x3r/GHSA-m68p-4w8c-8x3r.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m68p-4w8c-8x3r", + "modified": "2023-03-29T21:30:20Z", + "published": "2023-03-29T21:30:20Z", + "aliases": [ + "CVE-2022-36975" + ], + "details": "This vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche 6.3.2.3490. The specific flaw exists within the ProfileDaoImpl class. A crafted request can trigger execution of SQL queries composed from a user-supplied string. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-15332.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36975" + }, + { + "type": "WEB", + "url": "https://download.wavelink.com/Files/avalanche_v6.3.4_release_notes.txt" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-780/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-m8f7-5xcg-535x/GHSA-m8f7-5xcg-535x.json b/advisories/unreviewed/2023/03/GHSA-m8f7-5xcg-535x/GHSA-m8f7-5xcg-535x.json new file mode 100644 index 00000000000..8fa74d3f437 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-m8f7-5xcg-535x/GHSA-m8f7-5xcg-535x.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m8f7-5xcg-535x", + "modified": "2023-03-29T21:30:21Z", + "published": "2023-03-29T21:30:21Z", + "aliases": [ + "CVE-2022-36973" + ], + "details": "This vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche 6.3.2.3490. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the ProfileDaoImpl class. A crafted request can trigger execution of SQL queries composed from a user-supplied string. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-15329.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36973" + }, + { + "type": "WEB", + "url": "https://download.wavelink.com/Files/avalanche_v6.3.4_release_notes.txt" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-778/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-mfh4-7734-777j/GHSA-mfh4-7734-777j.json b/advisories/unreviewed/2023/03/GHSA-mfh4-7734-777j/GHSA-mfh4-7734-777j.json new file mode 100644 index 00000000000..2efa757a835 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-mfh4-7734-777j/GHSA-mfh4-7734-777j.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mfh4-7734-777j", + "modified": "2023-03-29T21:30:20Z", + "published": "2023-03-29T21:30:20Z", + "aliases": [ + "CVE-2022-37354" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of J2K files. Crafted data in a J2K file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-17628.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-37354" + }, + { + "type": "WEB", + "url": "https://www.tracker-software.com/product/pdf-xchange-editor/history" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1082/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-mj95-c6pq-6cm4/GHSA-mj95-c6pq-6cm4.json b/advisories/unreviewed/2023/03/GHSA-mj95-c6pq-6cm4/GHSA-mj95-c6pq-6cm4.json index d5c7eb7ee68..58c044bcabe 100644 --- a/advisories/unreviewed/2023/03/GHSA-mj95-c6pq-6cm4/GHSA-mj95-c6pq-6cm4.json +++ b/advisories/unreviewed/2023/03/GHSA-mj95-c6pq-6cm4/GHSA-mj95-c6pq-6cm4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mj95-c6pq-6cm4", - "modified": "2023-03-24T21:30:53Z", + "modified": "2023-03-29T21:30:17Z", "published": "2023-03-24T21:30:53Z", "aliases": [ "CVE-2023-21063" ], "details": "In ParseWithAuthType of simdata.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-243129862References: N/A", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-24T20:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-mp6x-jhfm-fxfq/GHSA-mp6x-jhfm-fxfq.json b/advisories/unreviewed/2023/03/GHSA-mp6x-jhfm-fxfq/GHSA-mp6x-jhfm-fxfq.json new file mode 100644 index 00000000000..7693342f1d9 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-mp6x-jhfm-fxfq/GHSA-mp6x-jhfm-fxfq.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mp6x-jhfm-fxfq", + "modified": "2023-03-29T21:30:20Z", + "published": "2023-03-29T21:30:20Z", + "aliases": [ + "CVE-2022-37374" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PNG files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-18068.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-37374" + }, + { + "type": "WEB", + "url": "https://www.tracker-software.com/product/pdf-xchange-editor/history" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1102/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-mpcg-2wq2-r3hq/GHSA-mpcg-2wq2-r3hq.json b/advisories/unreviewed/2023/03/GHSA-mpcg-2wq2-r3hq/GHSA-mpcg-2wq2-r3hq.json new file mode 100644 index 00000000000..820ba9e83f1 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-mpcg-2wq2-r3hq/GHSA-mpcg-2wq2-r3hq.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mpcg-2wq2-r3hq", + "modified": "2023-03-29T21:30:19Z", + "published": "2023-03-29T21:30:19Z", + "aliases": [ + "CVE-2022-43623" + ], + "details": "This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the handling of SetWebFilterSetting requests to the web management portal. When parsing the WebFilterURLs element, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-16140.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43623" + }, + { + "type": "WEB", + "url": "https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10310" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1492/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-mqp9-5m4c-g7f8/GHSA-mqp9-5m4c-g7f8.json b/advisories/unreviewed/2023/03/GHSA-mqp9-5m4c-g7f8/GHSA-mqp9-5m4c-g7f8.json new file mode 100644 index 00000000000..99f91dbf2b1 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-mqp9-5m4c-g7f8/GHSA-mqp9-5m4c-g7f8.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mqp9-5m4c-g7f8", + "modified": "2023-03-29T21:30:20Z", + "published": "2023-03-29T21:30:20Z", + "aliases": [ + "CVE-2022-37355" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JPG files. Crafted data in a JPG file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-17629.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-37355" + }, + { + "type": "WEB", + "url": "https://www.tracker-software.com/product/pdf-xchange-editor/history" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1083/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-mrcj-939x-ph52/GHSA-mrcj-939x-ph52.json b/advisories/unreviewed/2023/03/GHSA-mrcj-939x-ph52/GHSA-mrcj-939x-ph52.json new file mode 100644 index 00000000000..3f611832602 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-mrcj-939x-ph52/GHSA-mrcj-939x-ph52.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mrcj-939x-ph52", + "modified": "2023-03-29T21:30:18Z", + "published": "2023-03-29T21:30:18Z", + "aliases": [ + "CVE-2022-43638" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 12.0.1.12430. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-18627.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43638" + }, + { + "type": "WEB", + "url": "https://www.foxit.com/support/security-bulletins.html" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1658/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-mvgg-p48p-h9jc/GHSA-mvgg-p48p-h9jc.json b/advisories/unreviewed/2023/03/GHSA-mvgg-p48p-h9jc/GHSA-mvgg-p48p-h9jc.json new file mode 100644 index 00000000000..37ab240875f --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-mvgg-p48p-h9jc/GHSA-mvgg-p48p-h9jc.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mvgg-p48p-h9jc", + "modified": "2023-03-29T21:30:16Z", + "published": "2023-03-29T21:30:16Z", + "aliases": [ + "CVE-2023-0664" + ], + "details": "A flaw was found in the QEMU Guest Agent service for Windows. A local unprivileged user may be able to manipulate the QEMU Guest Agent's Windows installer via repair custom actions to elevate their privileges on the system.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-0664" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2167423" + }, + { + "type": "WEB", + "url": "https://gitlab.com/qemu-project/qemu/-/commit/07ce178a2b0768eb9e712bb5ad0cf6dc7fcf0158" + }, + { + "type": "WEB", + "url": "https://gitlab.com/qemu-project/qemu/-/commit/88288c2a51faa7c795f053fc8b31b1c16ff804c5" + }, + { + "type": "WEB", + "url": "https://lists.nongnu.org/archive/html/qemu-devel/2023-03/msg01445.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-mw6v-8jv9-7qrx/GHSA-mw6v-8jv9-7qrx.json b/advisories/unreviewed/2023/03/GHSA-mw6v-8jv9-7qrx/GHSA-mw6v-8jv9-7qrx.json new file mode 100644 index 00000000000..a56fe14bb3a --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-mw6v-8jv9-7qrx/GHSA-mw6v-8jv9-7qrx.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mw6v-8jv9-7qrx", + "modified": "2023-03-29T21:30:21Z", + "published": "2023-03-29T21:30:21Z", + "aliases": [ + "CVE-2022-2561" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of OPC Labs QuickOPC 2022.1. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of XML files in Connectivity Explorer. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16596.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-2561" + }, + { + "type": "WEB", + "url": "https://kb.opclabs.com/ZDI-CAN-16596_Connectivity_Explorer_file_vulnerability" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1031/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-mwjw-gjjg-g95f/GHSA-mwjw-gjjg-g95f.json b/advisories/unreviewed/2023/03/GHSA-mwjw-gjjg-g95f/GHSA-mwjw-gjjg-g95f.json new file mode 100644 index 00000000000..3fa62f53d34 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-mwjw-gjjg-g95f/GHSA-mwjw-gjjg-g95f.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mwjw-gjjg-g95f", + "modified": "2023-03-29T21:30:19Z", + "published": "2023-03-29T21:30:19Z", + "aliases": [ + "CVE-2022-42424" + ], + "details": "This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of requests to modify poller broker configuration. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to escalate privileges to the level of an administrator. Was ZDI-CAN-18556.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-42424" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1395/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-p658-968w-vm74/GHSA-p658-968w-vm74.json b/advisories/unreviewed/2023/03/GHSA-p658-968w-vm74/GHSA-p658-968w-vm74.json new file mode 100644 index 00000000000..ff9e707f95d --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-p658-968w-vm74/GHSA-p658-968w-vm74.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p658-968w-vm74", + "modified": "2023-03-29T21:30:21Z", + "published": "2023-03-29T21:30:21Z", + "aliases": [ + "CVE-2022-28687" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 2020 SP2 Patch 0(4201.2111.1802.0000). User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of APP files. The process loads a library from an unsecured location. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16257.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-28687" + }, + { + "type": "WEB", + "url": "https://www.aveva.com/content/dam/aveva/documents/support/cyber-security-updates/SecurityBulletin_AVEVA-2022-005.pdf" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1126/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-p682-rxp7-r33h/GHSA-p682-rxp7-r33h.json b/advisories/unreviewed/2023/03/GHSA-p682-rxp7-r33h/GHSA-p682-rxp7-r33h.json new file mode 100644 index 00000000000..8e75812a471 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-p682-rxp7-r33h/GHSA-p682-rxp7-r33h.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p682-rxp7-r33h", + "modified": "2023-03-29T21:30:18Z", + "published": "2023-03-29T21:30:18Z", + "aliases": [ + "CVE-2022-43648" + ], + "details": "This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-3040 1.20B03 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the MiniDLNA service. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the MiniDLNA service. Was ZDI-CAN-19910.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43648" + }, + { + "type": "WEB", + "url": "https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10322" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-23-052/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-p7pc-qwg6-498g/GHSA-p7pc-qwg6-498g.json b/advisories/unreviewed/2023/03/GHSA-p7pc-qwg6-498g/GHSA-p7pc-qwg6-498g.json new file mode 100644 index 00000000000..54f5c7844be --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-p7pc-qwg6-498g/GHSA-p7pc-qwg6-498g.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p7pc-qwg6-498g", + "modified": "2023-03-29T21:30:21Z", + "published": "2023-03-29T21:30:21Z", + "aliases": [ + "CVE-2022-28308" + ], + "details": "This vulnerability allows remote attackers to disclose sensitive information on affected installations of Bentley View 10.16.02.022. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of 3DS files. Crafted data in a 3DS file can trigger a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-16307.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-28308" + }, + { + "type": "WEB", + "url": "https://www.bentley.com/en/common-vulnerability-exposure/be-2022-0003" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-599/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-pc9v-3h75-cp72/GHSA-pc9v-3h75-cp72.json b/advisories/unreviewed/2023/03/GHSA-pc9v-3h75-cp72/GHSA-pc9v-3h75-cp72.json new file mode 100644 index 00000000000..016d10c28bc --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-pc9v-3h75-cp72/GHSA-pc9v-3h75-cp72.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pc9v-3h75-cp72", + "modified": "2023-03-29T21:30:19Z", + "published": "2023-03-29T21:30:19Z", + "aliases": [ + "CVE-2022-37386" + ], + "details": "This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 11.2.2.53575. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the resetForm method. By performing actions in JavaScript, an attacker can trigger a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-17550.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-37386" + }, + { + "type": "WEB", + "url": "https://www.foxit.com/support/security-bulletins.html" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1058/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-pcgm-9vcp-6328/GHSA-pcgm-9vcp-6328.json b/advisories/unreviewed/2023/03/GHSA-pcgm-9vcp-6328/GHSA-pcgm-9vcp-6328.json new file mode 100644 index 00000000000..4ad748fc5ec --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-pcgm-9vcp-6328/GHSA-pcgm-9vcp-6328.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pcgm-9vcp-6328", + "modified": "2023-03-29T21:30:22Z", + "published": "2023-03-29T21:30:22Z", + "aliases": [ + "CVE-2022-28302" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.02.34. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of IFC files. Crafted data in an IFC file can trigger a read past the end of an allocated buffer. An attacker can leverage this to execute code in the context of the current process. Was ZDI-CAN-16446.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-28302" + }, + { + "type": "WEB", + "url": "https://www.bentley.com/en/common-vulnerability-exposure/be-2022-0006" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-614/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-pmq2-7wm2-2j2f/GHSA-pmq2-7wm2-2j2f.json b/advisories/unreviewed/2023/03/GHSA-pmq2-7wm2-2j2f/GHSA-pmq2-7wm2-2j2f.json new file mode 100644 index 00000000000..1baeeb83713 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-pmq2-7wm2-2j2f/GHSA-pmq2-7wm2-2j2f.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pmq2-7wm2-2j2f", + "modified": "2023-03-29T21:30:22Z", + "published": "2023-03-29T21:30:22Z", + "aliases": [ + "CVE-2022-28300" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation 10.16.02.034 CONNECT. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JP2 images. Crafted data in a JP2 file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16202.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-28300" + }, + { + "type": "WEB", + "url": "https://www.bentley.com/en/common-vulnerability-exposure/be-2022-0007" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-592/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-pp2x-h7r9-38wv/GHSA-pp2x-h7r9-38wv.json b/advisories/unreviewed/2023/03/GHSA-pp2x-h7r9-38wv/GHSA-pp2x-h7r9-38wv.json index 54c48e88697..1370d53a080 100644 --- a/advisories/unreviewed/2023/03/GHSA-pp2x-h7r9-38wv/GHSA-pp2x-h7r9-38wv.json +++ b/advisories/unreviewed/2023/03/GHSA-pp2x-h7r9-38wv/GHSA-pp2x-h7r9-38wv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pp2x-h7r9-38wv", - "modified": "2023-03-24T21:30:52Z", + "modified": "2023-03-29T21:30:22Z", "published": "2023-03-24T21:30:52Z", "aliases": [ "CVE-2023-21051" ], "details": "In dwc3_exynos_clk_get of dwc3-exynos.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege in the kernel with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-259323322References: N/A", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-24T20:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-pqjj-qjgj-f2x9/GHSA-pqjj-qjgj-f2x9.json b/advisories/unreviewed/2023/03/GHSA-pqjj-qjgj-f2x9/GHSA-pqjj-qjgj-f2x9.json new file mode 100644 index 00000000000..13418256ab0 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-pqjj-qjgj-f2x9/GHSA-pqjj-qjgj-f2x9.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pqjj-qjgj-f2x9", + "modified": "2023-03-29T21:30:19Z", + "published": "2023-03-29T21:30:19Z", + "aliases": [ + "CVE-2022-37384" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the delay method. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-17327.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-37384" + }, + { + "type": "WEB", + "url": "https://www.foxit.com/support/security-bulletins.html" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1056/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-pvmm-fgf7-r833/GHSA-pvmm-fgf7-r833.json b/advisories/unreviewed/2023/03/GHSA-pvmm-fgf7-r833/GHSA-pvmm-fgf7-r833.json new file mode 100644 index 00000000000..ec4b16424d3 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-pvmm-fgf7-r833/GHSA-pvmm-fgf7-r833.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pvmm-fgf7-r833", + "modified": "2023-03-29T21:30:15Z", + "published": "2023-03-29T21:30:15Z", + "aliases": [ + "CVE-2023-28507" + ], + "details": "Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a memory-exhaustion issue, where a decompression routine will allocate increasing amounts of memory until all system memory is exhausted and the forked process crashes.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28507" + }, + { + "type": "WEB", + "url": "https://www.rapid7.com/blog/post/2023/03/29/multiple-vulnerabilities-in-rocket-software-unirpc-server-fixed/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T21:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-pwcm-gxw7-h8mv/GHSA-pwcm-gxw7-h8mv.json b/advisories/unreviewed/2023/03/GHSA-pwcm-gxw7-h8mv/GHSA-pwcm-gxw7-h8mv.json new file mode 100644 index 00000000000..c8bca307335 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-pwcm-gxw7-h8mv/GHSA-pwcm-gxw7-h8mv.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pwcm-gxw7-h8mv", + "modified": "2023-03-29T21:30:20Z", + "published": "2023-03-29T21:30:20Z", + "aliases": [ + "CVE-2022-37353" + ], + "details": "This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of EMF files. Crafted data in an EMF file can trigger a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-17637.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-37353" + }, + { + "type": "WEB", + "url": "https://www.tracker-software.com/product/pdf-xchange-editor/history" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1081/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-pwmj-ff87-vjpm/GHSA-pwmj-ff87-vjpm.json b/advisories/unreviewed/2023/03/GHSA-pwmj-ff87-vjpm/GHSA-pwmj-ff87-vjpm.json new file mode 100644 index 00000000000..fee6400535b --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-pwmj-ff87-vjpm/GHSA-pwmj-ff87-vjpm.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pwmj-ff87-vjpm", + "modified": "2023-03-29T21:30:20Z", + "published": "2023-03-29T21:30:20Z", + "aliases": [ + "CVE-2022-37359" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of J2K files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-17633.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-37359" + }, + { + "type": "WEB", + "url": "https://www.tracker-software.com/product/pdf-xchange-editor/history" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1087/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-pxwx-g88v-cm98/GHSA-pxwx-g88v-cm98.json b/advisories/unreviewed/2023/03/GHSA-pxwx-g88v-cm98/GHSA-pxwx-g88v-cm98.json new file mode 100644 index 00000000000..8ecb34812bf --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-pxwx-g88v-cm98/GHSA-pxwx-g88v-cm98.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pxwx-g88v-cm98", + "modified": "2023-03-29T21:30:20Z", + "published": "2023-03-29T21:30:20Z", + "aliases": [ + "CVE-2022-37351" + ], + "details": "This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of J2K files. Crafted data in a J2K file can trigger a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-17636.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-37351" + }, + { + "type": "WEB", + "url": "https://www.tracker-software.com/product/pdf-xchange-editor/history" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1079/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-q3c4-7524-h583/GHSA-q3c4-7524-h583.json b/advisories/unreviewed/2023/03/GHSA-q3c4-7524-h583/GHSA-q3c4-7524-h583.json new file mode 100644 index 00000000000..4c59237168e --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-q3c4-7524-h583/GHSA-q3c4-7524-h583.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q3c4-7524-h583", + "modified": "2023-03-29T21:30:17Z", + "published": "2023-03-29T21:30:17Z", + "aliases": [ + "CVE-2022-47610" + ], + "details": "Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Mr Digital Simple Image Popup plugin <= 1.3.6 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-47610" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/simple-image-popup/wordpress-simple-image-popup-plugin-1-3-6-cross-site-scripting-xss?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-q3j9-7mrh-5qq4/GHSA-q3j9-7mrh-5qq4.json b/advisories/unreviewed/2023/03/GHSA-q3j9-7mrh-5qq4/GHSA-q3j9-7mrh-5qq4.json index 9ea05bec372..a33edd4a709 100644 --- a/advisories/unreviewed/2023/03/GHSA-q3j9-7mrh-5qq4/GHSA-q3j9-7mrh-5qq4.json +++ b/advisories/unreviewed/2023/03/GHSA-q3j9-7mrh-5qq4/GHSA-q3j9-7mrh-5qq4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q3j9-7mrh-5qq4", - "modified": "2023-03-24T21:30:52Z", + "modified": "2023-03-29T21:30:22Z", "published": "2023-03-24T21:30:52Z", "aliases": [ "CVE-2023-21044" ], "details": "In init of VendorGraphicBufferMeta, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-253425086References: N/A", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-119" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-24T20:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-q653-fx3f-vxx7/GHSA-q653-fx3f-vxx7.json b/advisories/unreviewed/2023/03/GHSA-q653-fx3f-vxx7/GHSA-q653-fx3f-vxx7.json new file mode 100644 index 00000000000..4a5465e4538 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-q653-fx3f-vxx7/GHSA-q653-fx3f-vxx7.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q653-fx3f-vxx7", + "modified": "2023-03-29T21:30:19Z", + "published": "2023-03-29T21:30:19Z", + "aliases": [ + "CVE-2022-43624" + ], + "details": "This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the handling of SetStaticRouteIPv6Settings requests to the web management portal. When parsing subelements within the StaticRouteIPv6List element, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-16145.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43624" + }, + { + "type": "WEB", + "url": "https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10310" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1496/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-q74r-2mgj-gmf6/GHSA-q74r-2mgj-gmf6.json b/advisories/unreviewed/2023/03/GHSA-q74r-2mgj-gmf6/GHSA-q74r-2mgj-gmf6.json index d3466c7ef88..45493e4bc7e 100644 --- a/advisories/unreviewed/2023/03/GHSA-q74r-2mgj-gmf6/GHSA-q74r-2mgj-gmf6.json +++ b/advisories/unreviewed/2023/03/GHSA-q74r-2mgj-gmf6/GHSA-q74r-2mgj-gmf6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q74r-2mgj-gmf6", - "modified": "2023-03-24T21:30:52Z", + "modified": "2023-03-29T21:30:22Z", "published": "2023-03-24T21:30:52Z", "aliases": [ "CVE-2023-21059" ], "details": "In EUTRAN_LCS_DecodeFacilityInformationElement of LPP_LcsManagement.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-247564044References: N/A", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-24T20:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-qfj3-4fxc-mgvr/GHSA-qfj3-4fxc-mgvr.json b/advisories/unreviewed/2023/03/GHSA-qfj3-4fxc-mgvr/GHSA-qfj3-4fxc-mgvr.json new file mode 100644 index 00000000000..12b212ab6e3 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-qfj3-4fxc-mgvr/GHSA-qfj3-4fxc-mgvr.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qfj3-4fxc-mgvr", + "modified": "2023-03-29T21:30:20Z", + "published": "2023-03-29T21:30:20Z", + "aliases": [ + "CVE-2022-36981" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Avalanche 6.3.3.101. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the DeviceLogResource class. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-15966.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36981" + }, + { + "type": "WEB", + "url": "https://download.wavelink.com/Files/avalanche_v6.3.4_release_notes.txt" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-786/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-qfr3-mfc8-5fjx/GHSA-qfr3-mfc8-5fjx.json b/advisories/unreviewed/2023/03/GHSA-qfr3-mfc8-5fjx/GHSA-qfr3-mfc8-5fjx.json index 15c39028a50..aabd7e9ec4b 100644 --- a/advisories/unreviewed/2023/03/GHSA-qfr3-mfc8-5fjx/GHSA-qfr3-mfc8-5fjx.json +++ b/advisories/unreviewed/2023/03/GHSA-qfr3-mfc8-5fjx/GHSA-qfr3-mfc8-5fjx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qfr3-mfc8-5fjx", - "modified": "2023-03-24T21:30:53Z", + "modified": "2023-03-29T21:30:22Z", "published": "2023-03-24T21:30:53Z", "aliases": [ "CVE-2023-25350" ], "details": "Faveo Helpdesk 1.0-1.11.1 is vulnerable to SQL Injection. When the user logs in through the login box, he has no judgment on the validity of the user's input data. The parameters passed from the front end to the back end are controllable, which will lead to SQL injection.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-24T20:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-qgxc-q43p-rg2r/GHSA-qgxc-q43p-rg2r.json b/advisories/unreviewed/2023/03/GHSA-qgxc-q43p-rg2r/GHSA-qgxc-q43p-rg2r.json new file mode 100644 index 00000000000..b9707663a32 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-qgxc-q43p-rg2r/GHSA-qgxc-q43p-rg2r.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qgxc-q43p-rg2r", + "modified": "2023-03-29T21:30:19Z", + "published": "2023-03-29T21:30:19Z", + "aliases": [ + "CVE-2022-43611" + ], + "details": "This vulnerability allows remote attackers to disclose sensitive information on affected installations of Corel CorelDRAW Graphics Suite 23.5.0.506. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of BMP images. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-16351.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43611" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1469/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-qjg8-7gjq-vxf4/GHSA-qjg8-7gjq-vxf4.json b/advisories/unreviewed/2023/03/GHSA-qjg8-7gjq-vxf4/GHSA-qjg8-7gjq-vxf4.json new file mode 100644 index 00000000000..9803d64e40e --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-qjg8-7gjq-vxf4/GHSA-qjg8-7gjq-vxf4.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qjg8-7gjq-vxf4", + "modified": "2023-03-29T21:30:22Z", + "published": "2023-03-29T21:30:22Z", + "aliases": [ + "CVE-2022-27646" + ], + "details": "This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the circled daemon. A crafted circleinfo.txt file can trigger an overflow of a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-15879.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-27646" + }, + { + "type": "WEB", + "url": "https://kb.netgear.com/000064721/Security-Advisory-for-Multiple-Vulnerabilities-on-Multiple-Products-PSV-2021-0324" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-523/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-qp65-hwv9-52vm/GHSA-qp65-hwv9-52vm.json b/advisories/unreviewed/2023/03/GHSA-qp65-hwv9-52vm/GHSA-qp65-hwv9-52vm.json new file mode 100644 index 00000000000..532694255b5 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-qp65-hwv9-52vm/GHSA-qp65-hwv9-52vm.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qp65-hwv9-52vm", + "modified": "2023-03-29T21:30:20Z", + "published": "2023-03-29T21:30:20Z", + "aliases": [ + "CVE-2022-37365" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the saveAs method. The application exposes a JavaScript interface that allows the attacker to write arbitrary files. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-17527.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-37365" + }, + { + "type": "WEB", + "url": "https://www.tracker-software.com/product/pdf-xchange-editor/history" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1093/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-749" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-qw23-6j7v-fhg8/GHSA-qw23-6j7v-fhg8.json b/advisories/unreviewed/2023/03/GHSA-qw23-6j7v-fhg8/GHSA-qw23-6j7v-fhg8.json new file mode 100644 index 00000000000..5f27e1b470f --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-qw23-6j7v-fhg8/GHSA-qw23-6j7v-fhg8.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qw23-6j7v-fhg8", + "modified": "2023-03-29T21:30:21Z", + "published": "2023-03-29T21:30:21Z", + "aliases": [ + "CVE-2022-28645" + ], + "details": "This vulnerability allows remote attackers to disclose sensitive information on affected installations of Bentley MicroStation CONNECT 10.16.02.34. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of DGN files. Crafted data in a DGN file can trigger a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-16470.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-28645" + }, + { + "type": "WEB", + "url": "https://www.bentley.com/en/common-vulnerability-exposure/be-2022-0004" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-610/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-qw7p-6f7c-jj4p/GHSA-qw7p-6f7c-jj4p.json b/advisories/unreviewed/2023/03/GHSA-qw7p-6f7c-jj4p/GHSA-qw7p-6f7c-jj4p.json new file mode 100644 index 00000000000..c44a9b59060 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-qw7p-6f7c-jj4p/GHSA-qw7p-6f7c-jj4p.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qw7p-6f7c-jj4p", + "modified": "2023-03-29T21:30:21Z", + "published": "2023-03-29T21:30:21Z", + "aliases": [ + "CVE-2022-28643" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.02.34. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of DGN files. Crafted data in a DGN file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16468.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-28643" + }, + { + "type": "WEB", + "url": "https://www.bentley.com/en/common-vulnerability-exposure/be-2022-0004" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-609/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-r3gj-5f62-vgx7/GHSA-r3gj-5f62-vgx7.json b/advisories/unreviewed/2023/03/GHSA-r3gj-5f62-vgx7/GHSA-r3gj-5f62-vgx7.json new file mode 100644 index 00000000000..e9a68fe8f60 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-r3gj-5f62-vgx7/GHSA-r3gj-5f62-vgx7.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r3gj-5f62-vgx7", + "modified": "2023-03-29T21:30:20Z", + "published": "2023-03-29T21:30:20Z", + "aliases": [ + "CVE-2022-37358" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JPG files. Crafted data in a JPG file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-17632.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-37358" + }, + { + "type": "WEB", + "url": "https://www.tracker-software.com/product/pdf-xchange-editor/history" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1086/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-r4rc-5jf7-j8p4/GHSA-r4rc-5jf7-j8p4.json b/advisories/unreviewed/2023/03/GHSA-r4rc-5jf7-j8p4/GHSA-r4rc-5jf7-j8p4.json index d87249900ef..0d8a63a328b 100644 --- a/advisories/unreviewed/2023/03/GHSA-r4rc-5jf7-j8p4/GHSA-r4rc-5jf7-j8p4.json +++ b/advisories/unreviewed/2023/03/GHSA-r4rc-5jf7-j8p4/GHSA-r4rc-5jf7-j8p4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r4rc-5jf7-j8p4", - "modified": "2023-03-24T21:30:52Z", + "modified": "2023-03-29T21:30:23Z", "published": "2023-03-24T21:30:52Z", "aliases": [ "CVE-2023-21041" ], "details": "In append_to_params of param_util.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-250123688References: N/A", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-24T20:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-r8vp-qh3v-5wfc/GHSA-r8vp-qh3v-5wfc.json b/advisories/unreviewed/2023/03/GHSA-r8vp-qh3v-5wfc/GHSA-r8vp-qh3v-5wfc.json new file mode 100644 index 00000000000..fd6b74a8b1b --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-r8vp-qh3v-5wfc/GHSA-r8vp-qh3v-5wfc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r8vp-qh3v-5wfc", + "modified": "2023-03-29T21:30:19Z", + "published": "2023-03-29T21:30:19Z", + "aliases": [ + "CVE-2022-43616" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Corel CorelDRAW Graphics Suite 23.5.0.506. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of EMF images. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16371.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43616" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1474/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-r95g-66gf-3xc2/GHSA-r95g-66gf-3xc2.json b/advisories/unreviewed/2023/03/GHSA-r95g-66gf-3xc2/GHSA-r95g-66gf-3xc2.json new file mode 100644 index 00000000000..45d8d4c32aa --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-r95g-66gf-3xc2/GHSA-r95g-66gf-3xc2.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r95g-66gf-3xc2", + "modified": "2023-03-29T21:30:20Z", + "published": "2023-03-29T21:30:20Z", + "aliases": [ + "CVE-2022-37362" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PNG files. Crafted data in a PNG file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-17660.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-37362" + }, + { + "type": "WEB", + "url": "https://www.tracker-software.com/product/pdf-xchange-editor/history" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1090/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-rgfh-fr7j-cfww/GHSA-rgfh-fr7j-cfww.json b/advisories/unreviewed/2023/03/GHSA-rgfh-fr7j-cfww/GHSA-rgfh-fr7j-cfww.json new file mode 100644 index 00000000000..6fa6dd50021 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-rgfh-fr7j-cfww/GHSA-rgfh-fr7j-cfww.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rgfh-fr7j-cfww", + "modified": "2023-03-29T21:30:20Z", + "published": "2023-03-29T21:30:20Z", + "aliases": [ + "CVE-2022-36979" + ], + "details": "This vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche 6.3.2.3490. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the AvalancheDaoSupport class. A crafted request can trigger execution of SQL queries composed from a user-supplied string. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-15493.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36979" + }, + { + "type": "WEB", + "url": "https://download.wavelink.com/Files/avalanche_v6.3.4_release_notes.txt" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-784/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-rh28-jmpq-2rm5/GHSA-rh28-jmpq-2rm5.json b/advisories/unreviewed/2023/03/GHSA-rh28-jmpq-2rm5/GHSA-rh28-jmpq-2rm5.json new file mode 100644 index 00000000000..05fd11f3bb0 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-rh28-jmpq-2rm5/GHSA-rh28-jmpq-2rm5.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rh28-jmpq-2rm5", + "modified": "2023-03-29T21:30:18Z", + "published": "2023-03-29T21:30:18Z", + "aliases": [ + "CVE-2022-43642" + ], + "details": "This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-825 1.0.9/EE routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the YouTube plugin for the xupnpd service, which listens on TCP port 4044. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the admin user. Was ZDI-CAN-19222.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43642" + }, + { + "type": "WEB", + "url": "https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10319" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1701/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-rh4w-wj5p-5r32/GHSA-rh4w-wj5p-5r32.json b/advisories/unreviewed/2023/03/GHSA-rh4w-wj5p-5r32/GHSA-rh4w-wj5p-5r32.json new file mode 100644 index 00000000000..fda6c01494f --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-rh4w-wj5p-5r32/GHSA-rh4w-wj5p-5r32.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rh4w-wj5p-5r32", + "modified": "2023-03-29T21:30:21Z", + "published": "2023-03-29T21:30:21Z", + "aliases": [ + "CVE-2022-28686" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 2020 SP2 Patch 0(4201.2111.1802.0000). User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of APP files. The process loads a library from an unsecured location. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-17114.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-28686" + }, + { + "type": "WEB", + "url": "https://www.aveva.com/content/dam/aveva/documents/support/cyber-security-updates/SecurityBulletin_AVEVA-2022-005.pdf" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1125/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-rpfj-c47q-c8m4/GHSA-rpfj-c47q-c8m4.json b/advisories/unreviewed/2023/03/GHSA-rpfj-c47q-c8m4/GHSA-rpfj-c47q-c8m4.json new file mode 100644 index 00000000000..b39d59bbe55 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-rpfj-c47q-c8m4/GHSA-rpfj-c47q-c8m4.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rpfj-c47q-c8m4", + "modified": "2023-03-29T21:30:18Z", + "published": "2023-03-29T21:30:18Z", + "aliases": [ + "CVE-2022-43643" + ], + "details": "This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-825 1.0.9/EE routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the Generic plugin for the xupnpd service, which listens on TCP port 4044. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the admin user. Was ZDI-CAN-19460.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43643" + }, + { + "type": "WEB", + "url": "https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10319" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1702/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-rq4q-fjxh-vjg3/GHSA-rq4q-fjxh-vjg3.json b/advisories/unreviewed/2023/03/GHSA-rq4q-fjxh-vjg3/GHSA-rq4q-fjxh-vjg3.json new file mode 100644 index 00000000000..76e0849ea3e --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-rq4q-fjxh-vjg3/GHSA-rq4q-fjxh-vjg3.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rq4q-fjxh-vjg3", + "modified": "2023-03-29T21:30:21Z", + "published": "2023-03-29T21:30:21Z", + "aliases": [ + "CVE-2022-28319" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.02.034. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of 3DM files. The issue results from the lack of proper initialization of memory prior to accessing it. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16340.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-28319" + }, + { + "type": "WEB", + "url": "https://www.bentley.com/en/common-vulnerability-exposure/be-2022-0002" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-591/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-457" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-rr78-v2mc-p2mp/GHSA-rr78-v2mc-p2mp.json b/advisories/unreviewed/2023/03/GHSA-rr78-v2mc-p2mp/GHSA-rr78-v2mc-p2mp.json new file mode 100644 index 00000000000..6d03c1c5e68 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-rr78-v2mc-p2mp/GHSA-rr78-v2mc-p2mp.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rr78-v2mc-p2mp", + "modified": "2023-03-29T21:30:18Z", + "published": "2023-03-29T21:30:18Z", + "aliases": [ + "CVE-2022-43630" + ], + "details": "This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of http requests to the web management portal. When parsing the SOAPAction header, the process does not properly validate the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-16150.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43630" + }, + { + "type": "WEB", + "url": "https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10310" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1501/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-rrfg-8crh-5vmr/GHSA-rrfg-8crh-5vmr.json b/advisories/unreviewed/2023/03/GHSA-rrfg-8crh-5vmr/GHSA-rrfg-8crh-5vmr.json new file mode 100644 index 00000000000..13e31f75595 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-rrfg-8crh-5vmr/GHSA-rrfg-8crh-5vmr.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rrfg-8crh-5vmr", + "modified": "2023-03-29T21:30:16Z", + "published": "2023-03-29T21:30:16Z", + "aliases": [ + "CVE-2023-1652" + ], + "details": "A use-after-free flaw was found in nfsd4_ssc_setup_dul in fs/nfsd/nfs4proc.c in the NFS filesystem in the Linux Kernel. This issue could allow a local attacker to crash the system or it may lead to a kernel information leak problem.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1652" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/cve-2023-1652" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T21:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-rvc6-cvq7-4g2q/GHSA-rvc6-cvq7-4g2q.json b/advisories/unreviewed/2023/03/GHSA-rvc6-cvq7-4g2q/GHSA-rvc6-cvq7-4g2q.json new file mode 100644 index 00000000000..90e6d004ffa --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-rvc6-cvq7-4g2q/GHSA-rvc6-cvq7-4g2q.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rvc6-cvq7-4g2q", + "modified": "2023-03-29T21:30:22Z", + "published": "2023-03-29T21:30:22Z", + "aliases": [ + "CVE-2022-27644" + ], + "details": "This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the downloading of files via HTTPS. The issue results from the lack of proper validation of the certificate presented by the server. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of root. Was ZDI-CAN-15797.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-27644" + }, + { + "type": "WEB", + "url": "https://kb.netgear.com/000064721/Security-Advisory-for-Multiple-Vulnerabilities-on-Multiple-Products-PSV-2021-0324" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-520/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-295" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-rx2p-774w-85jc/GHSA-rx2p-774w-85jc.json b/advisories/unreviewed/2023/03/GHSA-rx2p-774w-85jc/GHSA-rx2p-774w-85jc.json new file mode 100644 index 00000000000..bc0825530d7 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-rx2p-774w-85jc/GHSA-rx2p-774w-85jc.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rx2p-774w-85jc", + "modified": "2023-03-29T21:30:21Z", + "published": "2023-03-29T21:30:21Z", + "aliases": [ + "CVE-2022-36971" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Avalanche 6.3.2.3490. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the JwtTokenUtility class. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-15301.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36971" + }, + { + "type": "WEB", + "url": "https://download.wavelink.com/Files/avalanche_v6.3.4_release_notes.txt" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-776/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-rxmx-w44h-9gvh/GHSA-rxmx-w44h-9gvh.json b/advisories/unreviewed/2023/03/GHSA-rxmx-w44h-9gvh/GHSA-rxmx-w44h-9gvh.json new file mode 100644 index 00000000000..fda3f970aac --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-rxmx-w44h-9gvh/GHSA-rxmx-w44h-9gvh.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rxmx-w44h-9gvh", + "modified": "2023-03-29T21:30:19Z", + "published": "2023-03-29T21:30:19Z", + "aliases": [ + "CVE-2022-43619" + ], + "details": "This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the handling of ConfigFileUpload requests to the web management portal. The issue results from the lack of proper validation of a user-supplied string before using it as a format specifier. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-16141.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43619" + }, + { + "type": "WEB", + "url": "https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10310" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1493/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-134" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-v452-7f7v-7m7q/GHSA-v452-7f7v-7m7q.json b/advisories/unreviewed/2023/03/GHSA-v452-7f7v-7m7q/GHSA-v452-7f7v-7m7q.json new file mode 100644 index 00000000000..e462cbf4063 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-v452-7f7v-7m7q/GHSA-v452-7f7v-7m7q.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v452-7f7v-7m7q", + "modified": "2023-03-29T21:30:21Z", + "published": "2023-03-29T21:30:21Z", + "aliases": [ + "CVE-2022-28644" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.02.34. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of DGN files. Crafted data in a DGN file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16469.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-28644" + }, + { + "type": "WEB", + "url": "https://www.bentley.com/en/common-vulnerability-exposure/be-2022-0004" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-611/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-v594-5w2m-322p/GHSA-v594-5w2m-322p.json b/advisories/unreviewed/2023/03/GHSA-v594-5w2m-322p/GHSA-v594-5w2m-322p.json new file mode 100644 index 00000000000..fbb9543cb06 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-v594-5w2m-322p/GHSA-v594-5w2m-322p.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v594-5w2m-322p", + "modified": "2023-03-29T21:30:19Z", + "published": "2023-03-29T21:30:19Z", + "aliases": [ + "CVE-2022-37388" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.2.2.53575. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF files. Crafted data in a PDF file can trigger a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-17516.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-37388" + }, + { + "type": "WEB", + "url": "https://www.foxit.com/support/security-bulletins.html" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1060/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-vc38-hp22-mh4x/GHSA-vc38-hp22-mh4x.json b/advisories/unreviewed/2023/03/GHSA-vc38-hp22-mh4x/GHSA-vc38-hp22-mh4x.json new file mode 100644 index 00000000000..5fe8f56a73f --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-vc38-hp22-mh4x/GHSA-vc38-hp22-mh4x.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vc38-hp22-mh4x", + "modified": "2023-03-29T21:30:15Z", + "published": "2023-03-29T21:30:15Z", + "aliases": [ + "CVE-2023-28504" + ], + "details": "Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a stack-based buffer overflow that can lead to remote code execution as the root user.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28504" + }, + { + "type": "WEB", + "url": "https://www.rapid7.com/blog/post/2023/03/29/multiple-vulnerabilities-in-rocket-software-unirpc-server-fixed/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T21:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-vc68-vpf2-7xq5/GHSA-vc68-vpf2-7xq5.json b/advisories/unreviewed/2023/03/GHSA-vc68-vpf2-7xq5/GHSA-vc68-vpf2-7xq5.json new file mode 100644 index 00000000000..7f78c68ec24 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-vc68-vpf2-7xq5/GHSA-vc68-vpf2-7xq5.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vc68-vpf2-7xq5", + "modified": "2023-03-29T21:30:21Z", + "published": "2023-03-29T21:30:21Z", + "aliases": [ + "CVE-2022-28316" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.02.34. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of IFC files. Crafted data in an IFC file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16368.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-28316" + }, + { + "type": "WEB", + "url": "https://www.bentley.com/en/common-vulnerability-exposure/be-2022-0006" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-607/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-vg6v-qwqm-x96m/GHSA-vg6v-qwqm-x96m.json b/advisories/unreviewed/2023/03/GHSA-vg6v-qwqm-x96m/GHSA-vg6v-qwqm-x96m.json new file mode 100644 index 00000000000..1187160884f --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-vg6v-qwqm-x96m/GHSA-vg6v-qwqm-x96m.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vg6v-qwqm-x96m", + "modified": "2023-03-29T21:30:18Z", + "published": "2023-03-29T21:30:18Z", + "aliases": [ + "CVE-2022-43629" + ], + "details": "This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the handling of SetSysEmailSettings requests to the web management portal. When parsing subelements within the SetSysEmailSettings element, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-16149.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43629" + }, + { + "type": "WEB", + "url": "https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10310" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1500/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-vhc5-85r7-whv3/GHSA-vhc5-85r7-whv3.json b/advisories/unreviewed/2023/03/GHSA-vhc5-85r7-whv3/GHSA-vhc5-85r7-whv3.json new file mode 100644 index 00000000000..d7cdf9af469 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-vhc5-85r7-whv3/GHSA-vhc5-85r7-whv3.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vhc5-85r7-whv3", + "modified": "2023-03-29T21:30:19Z", + "published": "2023-03-29T21:30:19Z", + "aliases": [ + "CVE-2022-43627" + ], + "details": "This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the handling of SetStaticRouteIPv4Settings requests to the web management portal. When parsing subelements within the StaticRouteIPv4Data element, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-16147.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43627" + }, + { + "type": "WEB", + "url": "https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10310" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1498/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-vr6q-6f35-6fpc/GHSA-vr6q-6f35-6fpc.json b/advisories/unreviewed/2023/03/GHSA-vr6q-6f35-6fpc/GHSA-vr6q-6f35-6fpc.json new file mode 100644 index 00000000000..ceb472d6320 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-vr6q-6f35-6fpc/GHSA-vr6q-6f35-6fpc.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vr6q-6f35-6fpc", + "modified": "2023-03-29T21:30:21Z", + "published": "2023-03-29T21:30:21Z", + "aliases": [ + "CVE-2022-28641" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.02.34. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of IFC files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16390.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-28641" + }, + { + "type": "WEB", + "url": "https://www.bentley.com/en/common-vulnerability-exposure/be-2022-0006" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-613/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-vrcj-9qv3-hv75/GHSA-vrcj-9qv3-hv75.json b/advisories/unreviewed/2023/03/GHSA-vrcj-9qv3-hv75/GHSA-vrcj-9qv3-hv75.json index 8789d3f5612..005af7c5793 100644 --- a/advisories/unreviewed/2023/03/GHSA-vrcj-9qv3-hv75/GHSA-vrcj-9qv3-hv75.json +++ b/advisories/unreviewed/2023/03/GHSA-vrcj-9qv3-hv75/GHSA-vrcj-9qv3-hv75.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vrcj-9qv3-hv75", - "modified": "2023-03-24T21:30:52Z", + "modified": "2023-03-29T21:30:22Z", "published": "2023-03-24T21:30:52Z", "aliases": [ "CVE-2023-21046" ], "details": "In ConvertToHalMetadata of aidl_utils.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-253424924References: N/A", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-24T20:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-vrvf-x4g2-cx9g/GHSA-vrvf-x4g2-cx9g.json b/advisories/unreviewed/2023/03/GHSA-vrvf-x4g2-cx9g/GHSA-vrvf-x4g2-cx9g.json new file mode 100644 index 00000000000..8f10a65c32d --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-vrvf-x4g2-cx9g/GHSA-vrvf-x4g2-cx9g.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vrvf-x4g2-cx9g", + "modified": "2023-03-29T21:30:20Z", + "published": "2023-03-29T21:30:20Z", + "aliases": [ + "CVE-2022-36982" + ], + "details": "This vulnerability allows remote attackers to read arbitrary files on affected installations of Ivanti Avalanche 6.3.3.101. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the AgentTaskHandler class. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to disclose stored session cookies, leading to further compromise. Was ZDI-CAN-15967.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36982" + }, + { + "type": "WEB", + "url": "https://download.wavelink.com/Files/avalanche_v6.3.4_release_notes.txt" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-787/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-w2w6-xp88-5cvw/GHSA-w2w6-xp88-5cvw.json b/advisories/unreviewed/2023/03/GHSA-w2w6-xp88-5cvw/GHSA-w2w6-xp88-5cvw.json index b6134a9f651..91ffb8d65f0 100644 --- a/advisories/unreviewed/2023/03/GHSA-w2w6-xp88-5cvw/GHSA-w2w6-xp88-5cvw.json +++ b/advisories/unreviewed/2023/03/GHSA-w2w6-xp88-5cvw/GHSA-w2w6-xp88-5cvw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w2w6-xp88-5cvw", - "modified": "2023-03-22T18:30:37Z", + "modified": "2023-03-29T21:30:17Z", "published": "2023-03-22T18:30:37Z", "aliases": [ "CVE-2023-0464" ], "details": "A security vulnerability has been identified in all supported versions of OpenSSL related to the verification of X.509 certificate chains that include policy constraints. Attackers may be able to exploit this vulnerability by creating a malicious certificate chain that triggers exponential use of computational resources, leading to a denial-of-service (DoS) attack on affected systems. Policy processing is disabled by default but can be enabled by passing the `-policy' argument to the command line utilities or by calling the `X509_VERIFY_PARAM_set1_policies()' function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-295" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-22T17:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-w472-7q22-qfjx/GHSA-w472-7q22-qfjx.json b/advisories/unreviewed/2023/03/GHSA-w472-7q22-qfjx/GHSA-w472-7q22-qfjx.json new file mode 100644 index 00000000000..7e29fc7034c --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-w472-7q22-qfjx/GHSA-w472-7q22-qfjx.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w472-7q22-qfjx", + "modified": "2023-03-29T21:30:20Z", + "published": "2023-03-29T21:30:20Z", + "aliases": [ + "CVE-2022-37368" + ], + "details": "This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Doc objects. By performing actions in JavaScript, an attacker can trigger a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-17728.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-37368" + }, + { + "type": "WEB", + "url": "https://www.tracker-software.com/product/pdf-xchange-editor/history" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1096/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-w7wq-mfjm-crgc/GHSA-w7wq-mfjm-crgc.json b/advisories/unreviewed/2023/03/GHSA-w7wq-mfjm-crgc/GHSA-w7wq-mfjm-crgc.json new file mode 100644 index 00000000000..b19a46df913 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-w7wq-mfjm-crgc/GHSA-w7wq-mfjm-crgc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w7wq-mfjm-crgc", + "modified": "2023-03-29T21:30:19Z", + "published": "2023-03-29T21:30:19Z", + "aliases": [ + "CVE-2022-42429" + ], + "details": "This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of requests to modify poller broker configuration. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to escalate privileges to the level of an administrator. Was ZDI-CAN-18557.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-42429" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1394/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-w94x-h737-f6h9/GHSA-w94x-h737-f6h9.json b/advisories/unreviewed/2023/03/GHSA-w94x-h737-f6h9/GHSA-w94x-h737-f6h9.json new file mode 100644 index 00000000000..5f6b630026b --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-w94x-h737-f6h9/GHSA-w94x-h737-f6h9.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w94x-h737-f6h9", + "modified": "2023-03-29T21:30:22Z", + "published": "2023-03-29T21:30:22Z", + "aliases": [ + "CVE-2022-27642" + ], + "details": "This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the httpd service. The issue results from incorrect string matching logic when accessing protected pages. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of root. Was ZDI-CAN-15854.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-27642" + }, + { + "type": "WEB", + "url": "https://kb.netgear.com/000064723/Security-Advisory-for-Multiple-Vulnerabilities-on-Multiple-Products-PSV-2021-0327" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-518/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-wc7c-x2x3-w322/GHSA-wc7c-x2x3-w322.json b/advisories/unreviewed/2023/03/GHSA-wc7c-x2x3-w322/GHSA-wc7c-x2x3-w322.json new file mode 100644 index 00000000000..dd43b95e2cf --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-wc7c-x2x3-w322/GHSA-wc7c-x2x3-w322.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wc7c-x2x3-w322", + "modified": "2023-03-29T21:30:20Z", + "published": "2023-03-29T21:30:20Z", + "aliases": [ + "CVE-2022-37371" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF files. Crafted data in a PDF file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-17772.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-37371" + }, + { + "type": "WEB", + "url": "https://www.tracker-software.com/product/pdf-xchange-editor/history" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1099/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-wccm-69w3-xxcw/GHSA-wccm-69w3-xxcw.json b/advisories/unreviewed/2023/03/GHSA-wccm-69w3-xxcw/GHSA-wccm-69w3-xxcw.json new file mode 100644 index 00000000000..ea28b4eb110 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-wccm-69w3-xxcw/GHSA-wccm-69w3-xxcw.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wccm-69w3-xxcw", + "modified": "2023-03-29T21:30:18Z", + "published": "2023-03-29T21:30:18Z", + "aliases": [ + "CVE-2022-43646" + ], + "details": "This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-825 1.0.9/EE routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the Vimeo plugin for the xupnpd service, which listens on TCP port 4044. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the admin user. Was ZDI-CAN-19463.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43646" + }, + { + "type": "WEB", + "url": "https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10319" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1705/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-wf6j-p2w6-h539/GHSA-wf6j-p2w6-h539.json b/advisories/unreviewed/2023/03/GHSA-wf6j-p2w6-h539/GHSA-wf6j-p2w6-h539.json new file mode 100644 index 00000000000..7852b251d58 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-wf6j-p2w6-h539/GHSA-wf6j-p2w6-h539.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wf6j-p2w6-h539", + "modified": "2023-03-29T21:30:19Z", + "published": "2023-03-29T21:30:19Z", + "aliases": [ + "CVE-2022-37387" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.2.2.53575. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of AcroForms. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-17552.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-37387" + }, + { + "type": "WEB", + "url": "https://www.foxit.com/support/security-bulletins.html" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1059/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-wfpr-8m9q-hrr8/GHSA-wfpr-8m9q-hrr8.json b/advisories/unreviewed/2023/03/GHSA-wfpr-8m9q-hrr8/GHSA-wfpr-8m9q-hrr8.json new file mode 100644 index 00000000000..e838d0a2114 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-wfpr-8m9q-hrr8/GHSA-wfpr-8m9q-hrr8.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wfpr-8m9q-hrr8", + "modified": "2023-03-29T21:30:19Z", + "published": "2023-03-29T21:30:19Z", + "aliases": [ + "CVE-2022-43626" + ], + "details": "This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the handling of SetIPv4FirewallSettings requests to the web management portal. When parsing subelements within the IPv4FirewallRule element, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-16146.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43626" + }, + { + "type": "WEB", + "url": "https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10310" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1497/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-wgqg-7gcr-3hm8/GHSA-wgqg-7gcr-3hm8.json b/advisories/unreviewed/2023/03/GHSA-wgqg-7gcr-3hm8/GHSA-wgqg-7gcr-3hm8.json index a33e95a77e8..51db55712fb 100644 --- a/advisories/unreviewed/2023/03/GHSA-wgqg-7gcr-3hm8/GHSA-wgqg-7gcr-3hm8.json +++ b/advisories/unreviewed/2023/03/GHSA-wgqg-7gcr-3hm8/GHSA-wgqg-7gcr-3hm8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wgqg-7gcr-3hm8", - "modified": "2023-03-24T21:30:52Z", + "modified": "2023-03-29T21:30:23Z", "published": "2023-03-24T21:30:52Z", "aliases": [ "CVE-2023-21042" ], "details": "In (TBD) of (TBD), there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-239873326References: N/A", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-24T20:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-wj78-xrp7-jrhr/GHSA-wj78-xrp7-jrhr.json b/advisories/unreviewed/2023/03/GHSA-wj78-xrp7-jrhr/GHSA-wj78-xrp7-jrhr.json new file mode 100644 index 00000000000..46b9b852ed1 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-wj78-xrp7-jrhr/GHSA-wj78-xrp7-jrhr.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wj78-xrp7-jrhr", + "modified": "2023-03-29T21:30:21Z", + "published": "2023-03-29T21:30:21Z", + "aliases": [ + "CVE-2022-28312" + ], + "details": "This vulnerability allows remote attackers to disclose sensitive information on affected installations of Bentley MicroStation CONNECT 10.16.02.034. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of 3DS files. Crafted data in a 3DS file can trigger a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-16342.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-28312" + }, + { + "type": "WEB", + "url": "https://www.bentley.com/en/common-vulnerability-exposure/be-2022-0003" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-602/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-wjw4-2695-6mj3/GHSA-wjw4-2695-6mj3.json b/advisories/unreviewed/2023/03/GHSA-wjw4-2695-6mj3/GHSA-wjw4-2695-6mj3.json new file mode 100644 index 00000000000..2d908ea2407 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-wjw4-2695-6mj3/GHSA-wjw4-2695-6mj3.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wjw4-2695-6mj3", + "modified": "2023-03-29T21:30:18Z", + "published": "2023-03-29T21:30:18Z", + "aliases": [ + "CVE-2022-43645" + ], + "details": "This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-825 1.0.9/EE routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the IVI plugin for the xupnpd service, which listens on TCP port 4044. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the admin user. Was ZDI-CAN-19462.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43645" + }, + { + "type": "WEB", + "url": "https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10319" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1704/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-wvf6-6fcj-rrxv/GHSA-wvf6-6fcj-rrxv.json b/advisories/unreviewed/2023/03/GHSA-wvf6-6fcj-rrxv/GHSA-wvf6-6fcj-rrxv.json new file mode 100644 index 00000000000..67305a528be --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-wvf6-6fcj-rrxv/GHSA-wvf6-6fcj-rrxv.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wvf6-6fcj-rrxv", + "modified": "2023-03-29T21:30:20Z", + "published": "2023-03-29T21:30:20Z", + "aliases": [ + "CVE-2022-37369" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF files. Crafted data in a PDF file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-17724.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-37369" + }, + { + "type": "WEB", + "url": "https://www.tracker-software.com/product/pdf-xchange-editor/history" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1097/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-x255-79xw-5565/GHSA-x255-79xw-5565.json b/advisories/unreviewed/2023/03/GHSA-x255-79xw-5565/GHSA-x255-79xw-5565.json index 835b812aea9..63e0db7b075 100644 --- a/advisories/unreviewed/2023/03/GHSA-x255-79xw-5565/GHSA-x255-79xw-5565.json +++ b/advisories/unreviewed/2023/03/GHSA-x255-79xw-5565/GHSA-x255-79xw-5565.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x255-79xw-5565", - "modified": "2023-03-24T21:30:52Z", + "modified": "2023-03-29T21:30:17Z", "published": "2023-03-24T21:30:52Z", "aliases": [ "CVE-2023-21054" ], "details": "In EUTRAN_LCS_ConvertLCS_MOLRReq of LPP_CommonUtil.c, there is a possible out of bounds write due to a logic error in the code. This could lead to remote code execution with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-244556535References: N/A", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-24T20:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-xf7f-g3ff-jjc9/GHSA-xf7f-g3ff-jjc9.json b/advisories/unreviewed/2023/03/GHSA-xf7f-g3ff-jjc9/GHSA-xf7f-g3ff-jjc9.json new file mode 100644 index 00000000000..d5401ff7cb0 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-xf7f-g3ff-jjc9/GHSA-xf7f-g3ff-jjc9.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xf7f-g3ff-jjc9", + "modified": "2023-03-29T21:30:17Z", + "published": "2023-03-29T21:30:17Z", + "aliases": [ + "CVE-2022-47613" + ], + "details": "Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in QuantumCloud AI ChatBot plugin <= 4.3.0 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-47613" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/chatbot/wordpress-chatbot-plugin-4-3-0-multiple-cross-site-scripting-xss?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-xhfw-qhxr-hjhq/GHSA-xhfw-qhxr-hjhq.json b/advisories/unreviewed/2023/03/GHSA-xhfw-qhxr-hjhq/GHSA-xhfw-qhxr-hjhq.json new file mode 100644 index 00000000000..0315a35641a --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-xhfw-qhxr-hjhq/GHSA-xhfw-qhxr-hjhq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xhfw-qhxr-hjhq", + "modified": "2023-03-29T21:30:16Z", + "published": "2023-03-29T21:30:16Z", + "aliases": [ + "CVE-2023-0836" + ], + "details": "An information leak vulnerability was discovered in HAProxy 2.1, 2.2 before 2.2.27, 2.3, 2.4 before 2.4.21, 2.5 before 2.5.11, 2.6 before 2.6.8, 2.7 before 2.7.1. There are 5 bytes left uninitialized in the connection buffer when encoding the FCGI_BEGIN_REQUEST record. Sensitive data may be disclosed to configured FastCGI backends in an unexpected way.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-0836" + }, + { + "type": "WEB", + "url": "https://git.haproxy.org/?p=haproxy.git;a=commitdiff;h=2e6bf0a" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T21:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-xv6g-6g23-79w2/GHSA-xv6g-6g23-79w2.json b/advisories/unreviewed/2023/03/GHSA-xv6g-6g23-79w2/GHSA-xv6g-6g23-79w2.json new file mode 100644 index 00000000000..c8e6d0d53e1 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-xv6g-6g23-79w2/GHSA-xv6g-6g23-79w2.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xv6g-6g23-79w2", + "modified": "2023-03-29T21:30:20Z", + "published": "2023-03-29T21:30:20Z", + "aliases": [ + "CVE-2022-36983" + ], + "details": "This vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche 6.3.3.101. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SetSettings class. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-15919.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36983" + }, + { + "type": "WEB", + "url": "https://download.wavelink.com/Files/avalanche_v6.3.4_release_notes.txt" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-788/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-749" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-xw54-w9r2-97q7/GHSA-xw54-w9r2-97q7.json b/advisories/unreviewed/2023/03/GHSA-xw54-w9r2-97q7/GHSA-xw54-w9r2-97q7.json new file mode 100644 index 00000000000..a06ab16e6bf --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-xw54-w9r2-97q7/GHSA-xw54-w9r2-97q7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xw54-w9r2-97q7", + "modified": "2023-03-29T21:30:19Z", + "published": "2023-03-29T21:30:19Z", + "aliases": [ + "CVE-2022-43615" + ], + "details": "This vulnerability allows remote attackers to disclose sensitive information on affected installations of Corel CorelDRAW Graphics Suite 23.5.0.506. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-16370.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43615" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1473/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-xxch-mf4j-qcvj/GHSA-xxch-mf4j-qcvj.json b/advisories/unreviewed/2023/03/GHSA-xxch-mf4j-qcvj/GHSA-xxch-mf4j-qcvj.json index 8473db2fb87..44e20a14960 100644 --- a/advisories/unreviewed/2023/03/GHSA-xxch-mf4j-qcvj/GHSA-xxch-mf4j-qcvj.json +++ b/advisories/unreviewed/2023/03/GHSA-xxch-mf4j-qcvj/GHSA-xxch-mf4j-qcvj.json @@ -21,6 +21,10 @@ { "type": "WEB", "url": "https://dino.im/security/cve-2023-28686/" + }, + { + "type": "WEB", + "url": "https://www.debian.org/security/2023/dsa-5379" } ], "database_specific": {