From 2efd058734f2d392fc2f19c299db9f2fe194f4f1 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 20 Nov 2024 18:33:28 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-2pww-2c9q-m4hw.json | 3 +- .../GHSA-7hw4-x97q-5wx2.json | 11 ++-- .../GHSA-5x9p-3r7q-7j42.json | 9 ++-- .../GHSA-f8q5-x5fj-x8wj.json | 11 ++-- .../GHSA-vcq2-59g4-9rm6.json | 9 ++-- .../GHSA-46ff-m72j-q8vp.json | 11 ++-- .../GHSA-96w6-xc3m-h7gp.json | 11 ++-- .../GHSA-f985-cwrv-f4qp.json | 11 ++-- .../GHSA-ffrq-jj39-9cw2.json | 11 ++-- .../GHSA-fq8p-83c5-pghx.json | 9 ++-- .../GHSA-2955-j2mm-qvcq.json | 11 ++-- .../GHSA-57w2-rvhr-q6hq.json | 11 ++-- .../GHSA-64f6-885c-52vw.json | 11 ++-- .../GHSA-g39c-xg27-wmff.json | 11 ++-- .../GHSA-6q4v-q7vf-h7fh.json | 11 ++-- .../GHSA-mrg8-h43c-3q4j.json | 2 +- .../GHSA-4mjg-849g-c6rf.json | 9 ++-- .../GHSA-6qfm-4c78-cfqr.json | 11 ++-- .../GHSA-73cx-rxj3-qqfq.json | 9 ++-- .../GHSA-82f5-7m6p-jqwq.json | 9 ++-- .../GHSA-924c-rx43-2mjr.json | 9 ++-- .../GHSA-9h7h-jp4j-h743.json | 9 ++-- .../GHSA-cfpv-586j-2mfm.json | 9 ++-- .../GHSA-fgrc-hf8c-f3vr.json | 9 ++-- .../GHSA-fxcf-gm2j-7vh5.json | 9 ++-- .../GHSA-g75v-mhrr-qmm9.json | 9 ++-- .../GHSA-jr43-7cf9-8vqm.json | 9 ++-- .../GHSA-jxg7-j4mp-g3q9.json | 9 ++-- .../GHSA-mm2v-m6vc-rhf4.json | 11 ++-- .../GHSA-q5xg-cgpw-7479.json | 11 ++-- .../GHSA-r8fr-h8q4-2f98.json | 9 ++-- .../GHSA-rxvg-52xh-5pv7.json | 11 ++-- .../GHSA-x443-5gjr-4gr5.json | 11 ++-- .../GHSA-xmx8-5v8v-4mhj.json | 9 ++-- .../GHSA-8r4r-8c3p-6r95.json | 11 ++-- .../GHSA-233g-c3hw-rh55.json | 11 ++-- .../GHSA-27gp-h89j-594r.json | 11 ++-- .../GHSA-3vj4-j93w-77x3.json | 35 ++++++++++++ .../GHSA-3w8x-p539-469j.json | 35 ++++++++++++ .../GHSA-45c5-w4j9-w656.json | 35 ++++++++++++ .../GHSA-47g9-6fvg-823p.json | 11 ++-- .../GHSA-4g42-h44f-r666.json | 35 ++++++++++++ .../GHSA-4xv5-h636-p47w.json | 39 ++++++++++++++ .../GHSA-54hc-gq3w-c935.json | 11 ++-- .../GHSA-5qh7-385v-fmqf.json | 11 ++-- .../GHSA-5rg2-32x4-8gcx.json | 35 ++++++++++++ .../GHSA-627r-gc28-6645.json | 39 ++++++++++++++ .../GHSA-69r9-55p9-j6ww.json | 35 ++++++++++++ .../GHSA-6wpw-4vr3-6744.json | 9 ++-- .../GHSA-6x32-2mjm-x4r9.json | 11 ++-- .../GHSA-76ph-jc9g-v47h.json | 35 ++++++++++++ .../GHSA-7mm3-wc4f-j5fh.json | 50 +++++++++++++++++ .../GHSA-7rmf-rfc4-c6r2.json | 50 +++++++++++++++++ .../GHSA-849w-8f8x-v945.json | 11 ++-- .../GHSA-8735-9wmp-4wx2.json | 11 ++-- .../GHSA-8mmp-cwxx-jp88.json | 11 ++-- .../GHSA-95hg-vx6x-rj95.json | 50 +++++++++++++++++ .../GHSA-97h5-gfw2-p92x.json | 11 ++-- .../GHSA-c9v7-fv5h-vr5j.json | 11 ++-- .../GHSA-ch8j-7gjj-5qxq.json | 35 ++++++++++++ .../GHSA-cp57-7c6j-pxfg.json | 11 ++-- .../GHSA-f927-34r4-vxxw.json | 9 ++-- .../GHSA-fg4f-v7hp-cc45.json | 39 ++++++++++++++ .../GHSA-fwpv-rgxh-fj74.json | 35 ++++++++++++ .../GHSA-gc7r-mr2h-cg8h.json | 11 ++-- .../GHSA-gfmp-fjx4-3grr.json | 50 +++++++++++++++++ .../GHSA-gp8c-83qw-c833.json | 11 ++-- .../GHSA-h4c9-8j9c-xf43.json | 39 ++++++++++++++ .../GHSA-h559-wf3x-8rqj.json | 54 +++++++++++++++++++ .../GHSA-h7jr-f9m2-rr37.json | 9 ++-- .../GHSA-hmmh-8x85-6jmh.json | 3 +- .../GHSA-hpv6-625j-5g5j.json | 35 ++++++++++++ .../GHSA-hr5c-w8m8-mfqx.json | 11 ++-- .../GHSA-hx2q-32g5-49fm.json | 50 +++++++++++++++++ .../GHSA-j5fv-4rwc-jmx5.json | 35 ++++++++++++ .../GHSA-jrrp-pvfv-xjh3.json | 50 +++++++++++++++++ .../GHSA-jw3w-mjq9-m7wp.json | 35 ++++++++++++ .../GHSA-jxr7-f3g8-36rm.json | 11 ++-- .../GHSA-mq9r-w66p-33m3.json | 50 +++++++++++++++++ .../GHSA-mqmc-3v72-6q9f.json | 11 ++-- .../GHSA-mr8h-x3p6-5r8q.json | 35 ++++++++++++ .../GHSA-p35q-vvhx-5rq6.json | 11 ++-- .../GHSA-p6hm-frqp-586g.json | 50 +++++++++++++++++ .../GHSA-p9rx-45f8-3vvp.json | 50 +++++++++++++++++ .../GHSA-pmcm-f4m7-v52m.json | 35 ++++++++++++ .../GHSA-pmgw-894q-7f55.json | 35 ++++++++++++ .../GHSA-pq4w-jf35-7pmx.json | 9 +++- .../GHSA-pqf7-5pw8-wxvr.json | 35 ++++++++++++ .../GHSA-pxvr-wp2h-6jcm.json | 35 ++++++++++++ .../GHSA-q8j2-m6jw-5583.json | 11 ++-- .../GHSA-qhv3-2cgf-c955.json | 39 ++++++++++++++ .../GHSA-rc9f-q3jv-fx7r.json | 2 +- .../GHSA-rf7m-w6xx-cv97.json | 9 ++-- .../GHSA-rhj5-4qqq-64c2.json | 11 ++-- .../GHSA-rmc4-mqv6-cmwx.json | 35 ++++++++++++ .../GHSA-rpq5-v9pq-9j39.json | 11 ++-- .../GHSA-v38r-cmm6-v8c3.json | 11 ++-- .../GHSA-vmmq-p5r9-qm38.json | 3 +- .../GHSA-wjgf-x45f-9vgf.json | 39 ++++++++++++++ .../GHSA-x386-xj3c-xjx5.json | 11 ++-- .../GHSA-xc54-5cvr-93hc.json | 11 ++-- .../GHSA-xc7x-w33q-rvw9.json | 35 ++++++++++++ .../GHSA-xx8w-4q6h-66xg.json | 39 ++++++++++++++ 103 files changed, 1864 insertions(+), 231 deletions(-) create mode 100644 advisories/unreviewed/2024/11/GHSA-3vj4-j93w-77x3/GHSA-3vj4-j93w-77x3.json create mode 100644 advisories/unreviewed/2024/11/GHSA-3w8x-p539-469j/GHSA-3w8x-p539-469j.json create mode 100644 advisories/unreviewed/2024/11/GHSA-45c5-w4j9-w656/GHSA-45c5-w4j9-w656.json create mode 100644 advisories/unreviewed/2024/11/GHSA-4g42-h44f-r666/GHSA-4g42-h44f-r666.json create mode 100644 advisories/unreviewed/2024/11/GHSA-4xv5-h636-p47w/GHSA-4xv5-h636-p47w.json create mode 100644 advisories/unreviewed/2024/11/GHSA-5rg2-32x4-8gcx/GHSA-5rg2-32x4-8gcx.json create mode 100644 advisories/unreviewed/2024/11/GHSA-627r-gc28-6645/GHSA-627r-gc28-6645.json create mode 100644 advisories/unreviewed/2024/11/GHSA-69r9-55p9-j6ww/GHSA-69r9-55p9-j6ww.json create mode 100644 advisories/unreviewed/2024/11/GHSA-76ph-jc9g-v47h/GHSA-76ph-jc9g-v47h.json create mode 100644 advisories/unreviewed/2024/11/GHSA-7mm3-wc4f-j5fh/GHSA-7mm3-wc4f-j5fh.json create mode 100644 advisories/unreviewed/2024/11/GHSA-7rmf-rfc4-c6r2/GHSA-7rmf-rfc4-c6r2.json create mode 100644 advisories/unreviewed/2024/11/GHSA-95hg-vx6x-rj95/GHSA-95hg-vx6x-rj95.json create mode 100644 advisories/unreviewed/2024/11/GHSA-ch8j-7gjj-5qxq/GHSA-ch8j-7gjj-5qxq.json create mode 100644 advisories/unreviewed/2024/11/GHSA-fg4f-v7hp-cc45/GHSA-fg4f-v7hp-cc45.json create mode 100644 advisories/unreviewed/2024/11/GHSA-fwpv-rgxh-fj74/GHSA-fwpv-rgxh-fj74.json create mode 100644 advisories/unreviewed/2024/11/GHSA-gfmp-fjx4-3grr/GHSA-gfmp-fjx4-3grr.json create mode 100644 advisories/unreviewed/2024/11/GHSA-h4c9-8j9c-xf43/GHSA-h4c9-8j9c-xf43.json create mode 100644 advisories/unreviewed/2024/11/GHSA-h559-wf3x-8rqj/GHSA-h559-wf3x-8rqj.json create mode 100644 advisories/unreviewed/2024/11/GHSA-hpv6-625j-5g5j/GHSA-hpv6-625j-5g5j.json create mode 100644 advisories/unreviewed/2024/11/GHSA-hx2q-32g5-49fm/GHSA-hx2q-32g5-49fm.json create mode 100644 advisories/unreviewed/2024/11/GHSA-j5fv-4rwc-jmx5/GHSA-j5fv-4rwc-jmx5.json create mode 100644 advisories/unreviewed/2024/11/GHSA-jrrp-pvfv-xjh3/GHSA-jrrp-pvfv-xjh3.json create mode 100644 advisories/unreviewed/2024/11/GHSA-jw3w-mjq9-m7wp/GHSA-jw3w-mjq9-m7wp.json create mode 100644 advisories/unreviewed/2024/11/GHSA-mq9r-w66p-33m3/GHSA-mq9r-w66p-33m3.json create mode 100644 advisories/unreviewed/2024/11/GHSA-mr8h-x3p6-5r8q/GHSA-mr8h-x3p6-5r8q.json create mode 100644 advisories/unreviewed/2024/11/GHSA-p6hm-frqp-586g/GHSA-p6hm-frqp-586g.json create mode 100644 advisories/unreviewed/2024/11/GHSA-p9rx-45f8-3vvp/GHSA-p9rx-45f8-3vvp.json create mode 100644 advisories/unreviewed/2024/11/GHSA-pmcm-f4m7-v52m/GHSA-pmcm-f4m7-v52m.json create mode 100644 advisories/unreviewed/2024/11/GHSA-pmgw-894q-7f55/GHSA-pmgw-894q-7f55.json create mode 100644 advisories/unreviewed/2024/11/GHSA-pqf7-5pw8-wxvr/GHSA-pqf7-5pw8-wxvr.json create mode 100644 advisories/unreviewed/2024/11/GHSA-pxvr-wp2h-6jcm/GHSA-pxvr-wp2h-6jcm.json create mode 100644 advisories/unreviewed/2024/11/GHSA-qhv3-2cgf-c955/GHSA-qhv3-2cgf-c955.json create mode 100644 advisories/unreviewed/2024/11/GHSA-rmc4-mqv6-cmwx/GHSA-rmc4-mqv6-cmwx.json create mode 100644 advisories/unreviewed/2024/11/GHSA-wjgf-x45f-9vgf/GHSA-wjgf-x45f-9vgf.json create mode 100644 advisories/unreviewed/2024/11/GHSA-xc7x-w33q-rvw9/GHSA-xc7x-w33q-rvw9.json create mode 100644 advisories/unreviewed/2024/11/GHSA-xx8w-4q6h-66xg/GHSA-xx8w-4q6h-66xg.json diff --git a/advisories/unreviewed/2023/06/GHSA-2pww-2c9q-m4hw/GHSA-2pww-2c9q-m4hw.json b/advisories/unreviewed/2023/06/GHSA-2pww-2c9q-m4hw/GHSA-2pww-2c9q-m4hw.json index 32152348990..ddfd15ed371 100644 --- a/advisories/unreviewed/2023/06/GHSA-2pww-2c9q-m4hw/GHSA-2pww-2c9q-m4hw.json +++ b/advisories/unreviewed/2023/06/GHSA-2pww-2c9q-m4hw/GHSA-2pww-2c9q-m4hw.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-125" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-7hw4-x97q-5wx2/GHSA-7hw4-x97q-5wx2.json b/advisories/unreviewed/2024/02/GHSA-7hw4-x97q-5wx2/GHSA-7hw4-x97q-5wx2.json index 02a28959f9e..7dc0b34bff1 100644 --- a/advisories/unreviewed/2024/02/GHSA-7hw4-x97q-5wx2/GHSA-7hw4-x97q-5wx2.json +++ b/advisories/unreviewed/2024/02/GHSA-7hw4-x97q-5wx2/GHSA-7hw4-x97q-5wx2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7hw4-x97q-5wx2", - "modified": "2024-02-22T15:30:39Z", + "modified": "2024-11-20T18:32:14Z", "published": "2024-02-22T15:30:39Z", "aliases": [ "CVE-2024-26281" ], "details": "Upon scanning a JavaScript URI with the QR code scanner, an attacker could have executed unauthorized scripts on the current top origin sites in the URL bar. This vulnerability affects Firefox for iOS < 123.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-22T15:15:08Z" diff --git a/advisories/unreviewed/2024/03/GHSA-5x9p-3r7q-7j42/GHSA-5x9p-3r7q-7j42.json b/advisories/unreviewed/2024/03/GHSA-5x9p-3r7q-7j42/GHSA-5x9p-3r7q-7j42.json index ccb184b31d6..fc646c29b59 100644 --- a/advisories/unreviewed/2024/03/GHSA-5x9p-3r7q-7j42/GHSA-5x9p-3r7q-7j42.json +++ b/advisories/unreviewed/2024/03/GHSA-5x9p-3r7q-7j42/GHSA-5x9p-3r7q-7j42.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5x9p-3r7q-7j42", - "modified": "2024-03-13T21:31:02Z", + "modified": "2024-11-20T18:32:14Z", "published": "2024-03-08T03:31:25Z", "aliases": [ "CVE-2024-23279" ], "details": "A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sonoma 14.4. An app may be able to access user-sensitive data.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-08T02:15:49Z" diff --git a/advisories/unreviewed/2024/03/GHSA-f8q5-x5fj-x8wj/GHSA-f8q5-x5fj-x8wj.json b/advisories/unreviewed/2024/03/GHSA-f8q5-x5fj-x8wj/GHSA-f8q5-x5fj-x8wj.json index b079bc56abb..c1d0caad132 100644 --- a/advisories/unreviewed/2024/03/GHSA-f8q5-x5fj-x8wj/GHSA-f8q5-x5fj-x8wj.json +++ b/advisories/unreviewed/2024/03/GHSA-f8q5-x5fj-x8wj/GHSA-f8q5-x5fj-x8wj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f8q5-x5fj-x8wj", - "modified": "2024-03-13T21:31:01Z", + "modified": "2024-11-20T18:32:14Z", "published": "2024-03-08T03:31:24Z", "aliases": [ "CVE-2024-23205" ], "details": "A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sonoma 14.4, iOS 17.4 and iPadOS 17.4. An app may be able to access sensitive user data.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-922" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-08T02:15:47Z" diff --git a/advisories/unreviewed/2024/03/GHSA-vcq2-59g4-9rm6/GHSA-vcq2-59g4-9rm6.json b/advisories/unreviewed/2024/03/GHSA-vcq2-59g4-9rm6/GHSA-vcq2-59g4-9rm6.json index 7a4729d2c79..411ff6fa0fd 100644 --- a/advisories/unreviewed/2024/03/GHSA-vcq2-59g4-9rm6/GHSA-vcq2-59g4-9rm6.json +++ b/advisories/unreviewed/2024/03/GHSA-vcq2-59g4-9rm6/GHSA-vcq2-59g4-9rm6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vcq2-59g4-9rm6", - "modified": "2024-05-01T18:30:37Z", + "modified": "2024-11-20T18:32:14Z", "published": "2024-03-27T03:31:17Z", "aliases": [ "CVE-2024-25394" ], "details": "A buffer overflow occurs in utilities/ymodem/ry_sy.c in RT-Thread through 5.0.2 because of an incorrect sprintf call or a missing '\\0' character.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -43,7 +46,7 @@ "cwe_ids": [ "CWE-120" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-27T03:15:11Z" diff --git a/advisories/unreviewed/2024/04/GHSA-46ff-m72j-q8vp/GHSA-46ff-m72j-q8vp.json b/advisories/unreviewed/2024/04/GHSA-46ff-m72j-q8vp/GHSA-46ff-m72j-q8vp.json index de3a932cbae..6fd27098cd1 100644 --- a/advisories/unreviewed/2024/04/GHSA-46ff-m72j-q8vp/GHSA-46ff-m72j-q8vp.json +++ b/advisories/unreviewed/2024/04/GHSA-46ff-m72j-q8vp/GHSA-46ff-m72j-q8vp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-46ff-m72j-q8vp", - "modified": "2024-04-26T03:30:29Z", + "modified": "2024-11-20T18:32:14Z", "published": "2024-04-26T03:30:29Z", "aliases": [ "CVE-2023-47252" ], "details": "An issue was discovered in PnpSmm in Insyde InsydeH2O with kernel 5.0 through 5.6. There is a possible out-of-bounds access in the SMM communication buffer, leading to tampering. The PNP-related SMI sub-functions do not verify data size before getting it from the communication buffer, which could lead to possible circumstances where the data immediately following the command buffer could be destroyed with a fixed value. This is fixed in kernel 5.2 v05.28.45, kernel 5.3 v05.37.45, kernel 5.4 v05.45.45, kernel 5.5 v05.53.45, and kernel 5.6 v05.60.45.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-26T03:15:06Z" diff --git a/advisories/unreviewed/2024/04/GHSA-96w6-xc3m-h7gp/GHSA-96w6-xc3m-h7gp.json b/advisories/unreviewed/2024/04/GHSA-96w6-xc3m-h7gp/GHSA-96w6-xc3m-h7gp.json index 470510370c5..69ac4e14994 100644 --- a/advisories/unreviewed/2024/04/GHSA-96w6-xc3m-h7gp/GHSA-96w6-xc3m-h7gp.json +++ b/advisories/unreviewed/2024/04/GHSA-96w6-xc3m-h7gp/GHSA-96w6-xc3m-h7gp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-96w6-xc3m-h7gp", - "modified": "2024-04-30T21:30:32Z", + "modified": "2024-11-20T18:32:14Z", "published": "2024-04-30T21:30:32Z", "aliases": [ "CVE-2024-34088" ], "details": "In FRRouting (FRR) through 9.1, it is possible for the get_edge() function in ospf_te.c in the OSPF daemon to return a NULL pointer. In cases where calling functions do not handle the returned NULL value, the OSPF daemon crashes, leading to denial of service.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-30T19:15:23Z" diff --git a/advisories/unreviewed/2024/04/GHSA-f985-cwrv-f4qp/GHSA-f985-cwrv-f4qp.json b/advisories/unreviewed/2024/04/GHSA-f985-cwrv-f4qp/GHSA-f985-cwrv-f4qp.json index b4034cfe403..bc7dd0828c7 100644 --- a/advisories/unreviewed/2024/04/GHSA-f985-cwrv-f4qp/GHSA-f985-cwrv-f4qp.json +++ b/advisories/unreviewed/2024/04/GHSA-f985-cwrv-f4qp/GHSA-f985-cwrv-f4qp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f985-cwrv-f4qp", - "modified": "2024-04-16T18:31:35Z", + "modified": "2024-11-20T18:32:14Z", "published": "2024-04-16T18:31:35Z", "aliases": [ "CVE-2024-3860" ], "details": "An out-of-memory condition during object initialization could result in an empty shape list. If the JIT subsequently traced the object it would crash. This vulnerability affects Firefox < 125.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-401" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-16T16:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-ffrq-jj39-9cw2/GHSA-ffrq-jj39-9cw2.json b/advisories/unreviewed/2024/04/GHSA-ffrq-jj39-9cw2/GHSA-ffrq-jj39-9cw2.json index bce7a737998..e3ab58c1429 100644 --- a/advisories/unreviewed/2024/04/GHSA-ffrq-jj39-9cw2/GHSA-ffrq-jj39-9cw2.json +++ b/advisories/unreviewed/2024/04/GHSA-ffrq-jj39-9cw2/GHSA-ffrq-jj39-9cw2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-ffrq-jj39-9cw2", - "modified": "2024-04-30T00:30:34Z", + "modified": "2024-11-20T18:32:14Z", "published": "2024-04-30T00:30:34Z", "aliases": [ "CVE-2023-50432" ], "details": "simple-dhcp-server through ec976d2 allows remote attackers to cause a denial of service (daemon crash) by sending a DHCP packet without any option fields, which causes free_packet in dhcp_packet.c to dereference a NULL pointer.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-29T22:15:06Z" diff --git a/advisories/unreviewed/2024/04/GHSA-fq8p-83c5-pghx/GHSA-fq8p-83c5-pghx.json b/advisories/unreviewed/2024/04/GHSA-fq8p-83c5-pghx/GHSA-fq8p-83c5-pghx.json index 1c48e8bb1bf..99004faae65 100644 --- a/advisories/unreviewed/2024/04/GHSA-fq8p-83c5-pghx/GHSA-fq8p-83c5-pghx.json +++ b/advisories/unreviewed/2024/04/GHSA-fq8p-83c5-pghx/GHSA-fq8p-83c5-pghx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fq8p-83c5-pghx", - "modified": "2024-04-28T15:30:29Z", + "modified": "2024-11-20T18:32:14Z", "published": "2024-04-28T15:30:29Z", "aliases": [ "CVE-2022-48646" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsfc/siena: fix null pointer dereference in efx_hard_start_xmit\n\nLike in previous patch for sfc, prevent potential (but unlikely) NULL\npointer dereference.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-28T13:15:07Z" diff --git a/advisories/unreviewed/2024/05/GHSA-2955-j2mm-qvcq/GHSA-2955-j2mm-qvcq.json b/advisories/unreviewed/2024/05/GHSA-2955-j2mm-qvcq/GHSA-2955-j2mm-qvcq.json index c137af04c22..f48bc4c73c9 100644 --- a/advisories/unreviewed/2024/05/GHSA-2955-j2mm-qvcq/GHSA-2955-j2mm-qvcq.json +++ b/advisories/unreviewed/2024/05/GHSA-2955-j2mm-qvcq/GHSA-2955-j2mm-qvcq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2955-j2mm-qvcq", - "modified": "2024-05-03T18:30:36Z", + "modified": "2024-11-20T18:32:15Z", "published": "2024-05-03T18:30:36Z", "aliases": [ "CVE-2022-48696" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nregmap: spi: Reserve space for register address/padding\n\nCurrently the max_raw_read and max_raw_write limits in regmap_spi struct\ndo not take into account the additional size of the transmitted register\naddress and padding. This may result in exceeding the maximum permitted\nSPI message size, which could cause undefined behaviour, e.g. data\ncorruption.\n\nFix regmap_get_spi_bus() to properly adjust the above mentioned limits\nby reserving space for the register address/padding as set in the regmap\nconfiguration.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-03T16:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-57w2-rvhr-q6hq/GHSA-57w2-rvhr-q6hq.json b/advisories/unreviewed/2024/05/GHSA-57w2-rvhr-q6hq/GHSA-57w2-rvhr-q6hq.json index 1b94d050846..438d8e0ce62 100644 --- a/advisories/unreviewed/2024/05/GHSA-57w2-rvhr-q6hq/GHSA-57w2-rvhr-q6hq.json +++ b/advisories/unreviewed/2024/05/GHSA-57w2-rvhr-q6hq/GHSA-57w2-rvhr-q6hq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-57w2-rvhr-q6hq", - "modified": "2024-05-23T18:30:55Z", + "modified": "2024-11-20T18:32:15Z", "published": "2024-05-23T18:30:55Z", "aliases": [ "CVE-2024-34932" ], "details": "A SQL injection vulnerability in /model/update_exam.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the name parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-23T17:15:30Z" diff --git a/advisories/unreviewed/2024/05/GHSA-64f6-885c-52vw/GHSA-64f6-885c-52vw.json b/advisories/unreviewed/2024/05/GHSA-64f6-885c-52vw/GHSA-64f6-885c-52vw.json index 06233399efa..0cd15c702dc 100644 --- a/advisories/unreviewed/2024/05/GHSA-64f6-885c-52vw/GHSA-64f6-885c-52vw.json +++ b/advisories/unreviewed/2024/05/GHSA-64f6-885c-52vw/GHSA-64f6-885c-52vw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-64f6-885c-52vw", - "modified": "2024-05-14T18:31:05Z", + "modified": "2024-11-20T18:32:15Z", "published": "2024-05-14T18:31:05Z", "aliases": [ "CVE-2024-4772" ], "details": "An HTTP digest authentication nonce value was generated using `rand()` which could lead to predictable values. This vulnerability affects Firefox < 126.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-338" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T18:15:15Z" diff --git a/advisories/unreviewed/2024/06/GHSA-g39c-xg27-wmff/GHSA-g39c-xg27-wmff.json b/advisories/unreviewed/2024/06/GHSA-g39c-xg27-wmff/GHSA-g39c-xg27-wmff.json index 04cca1e4dd9..ee842c7d7ec 100644 --- a/advisories/unreviewed/2024/06/GHSA-g39c-xg27-wmff/GHSA-g39c-xg27-wmff.json +++ b/advisories/unreviewed/2024/06/GHSA-g39c-xg27-wmff/GHSA-g39c-xg27-wmff.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g39c-xg27-wmff", - "modified": "2024-06-04T15:30:58Z", + "modified": "2024-11-20T18:32:15Z", "published": "2024-06-04T15:30:58Z", "aliases": [ "CVE-2024-36801" ], "details": "A SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via the lgid parameter in Download.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-04T13:15:52Z" diff --git a/advisories/unreviewed/2024/07/GHSA-6q4v-q7vf-h7fh/GHSA-6q4v-q7vf-h7fh.json b/advisories/unreviewed/2024/07/GHSA-6q4v-q7vf-h7fh/GHSA-6q4v-q7vf-h7fh.json index f3d2c81a8fa..fe6d45aa36d 100644 --- a/advisories/unreviewed/2024/07/GHSA-6q4v-q7vf-h7fh/GHSA-6q4v-q7vf-h7fh.json +++ b/advisories/unreviewed/2024/07/GHSA-6q4v-q7vf-h7fh/GHSA-6q4v-q7vf-h7fh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6q4v-q7vf-h7fh", - "modified": "2024-07-09T21:30:39Z", + "modified": "2024-11-20T18:32:15Z", "published": "2024-07-09T21:30:39Z", "aliases": [ "CVE-2024-39181" ], "details": "Shenzhen Libituo Technology Co., Ltd LBT-T300-T400 v3.2 was discovered to contain a buffer overflow via the ApCliSsid parameter in thegenerate_conf_router() function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-09T21:15:15Z" diff --git a/advisories/unreviewed/2024/07/GHSA-mrg8-h43c-3q4j/GHSA-mrg8-h43c-3q4j.json b/advisories/unreviewed/2024/07/GHSA-mrg8-h43c-3q4j/GHSA-mrg8-h43c-3q4j.json index 893ea5279d7..642ad82b364 100644 --- a/advisories/unreviewed/2024/07/GHSA-mrg8-h43c-3q4j/GHSA-mrg8-h43c-3q4j.json +++ b/advisories/unreviewed/2024/07/GHSA-mrg8-h43c-3q4j/GHSA-mrg8-h43c-3q4j.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-4mjg-849g-c6rf/GHSA-4mjg-849g-c6rf.json b/advisories/unreviewed/2024/09/GHSA-4mjg-849g-c6rf/GHSA-4mjg-849g-c6rf.json index 63deaa43efa..59a18ee4221 100644 --- a/advisories/unreviewed/2024/09/GHSA-4mjg-849g-c6rf/GHSA-4mjg-849g-c6rf.json +++ b/advisories/unreviewed/2024/09/GHSA-4mjg-849g-c6rf/GHSA-4mjg-849g-c6rf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4mjg-849g-c6rf", - "modified": "2024-09-27T15:30:33Z", + "modified": "2024-11-20T18:32:15Z", "published": "2024-09-27T15:30:33Z", "aliases": [ "CVE-2024-46825" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: iwlwifi: mvm: use IWL_FW_CHECK for link ID check\n\nThe lookup function iwl_mvm_rcu_fw_link_id_to_link_conf() is\nnormally called with input from the firmware, so it should use\nIWL_FW_CHECK() instead of WARN_ON().", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-27T13:15:15Z" diff --git a/advisories/unreviewed/2024/09/GHSA-6qfm-4c78-cfqr/GHSA-6qfm-4c78-cfqr.json b/advisories/unreviewed/2024/09/GHSA-6qfm-4c78-cfqr/GHSA-6qfm-4c78-cfqr.json index dc8bef612d4..daefcb8df04 100644 --- a/advisories/unreviewed/2024/09/GHSA-6qfm-4c78-cfqr/GHSA-6qfm-4c78-cfqr.json +++ b/advisories/unreviewed/2024/09/GHSA-6qfm-4c78-cfqr/GHSA-6qfm-4c78-cfqr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6qfm-4c78-cfqr", - "modified": "2024-09-18T09:30:37Z", + "modified": "2024-11-20T18:32:15Z", "published": "2024-09-18T09:30:37Z", "aliases": [ "CVE-2024-46774" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\npowerpc/rtas: Prevent Spectre v1 gadget construction in sys_rtas()\n\nSmatch warns:\n\n arch/powerpc/kernel/rtas.c:1932 __do_sys_rtas() warn: potential\n spectre issue 'args.args' [r] (local cap)\n\nThe 'nargs' and 'nret' locals come directly from a user-supplied\nbuffer and are used as indexes into a small stack-based array and as\ninputs to copy_to_user() after they are subject to bounds checks.\n\nUse array_index_nospec() after the bounds checks to clamp these values\nfor speculative execution.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T08:15:05Z" diff --git a/advisories/unreviewed/2024/09/GHSA-73cx-rxj3-qqfq/GHSA-73cx-rxj3-qqfq.json b/advisories/unreviewed/2024/09/GHSA-73cx-rxj3-qqfq/GHSA-73cx-rxj3-qqfq.json index 4fbbb80245d..ca01ad593c2 100644 --- a/advisories/unreviewed/2024/09/GHSA-73cx-rxj3-qqfq/GHSA-73cx-rxj3-qqfq.json +++ b/advisories/unreviewed/2024/09/GHSA-73cx-rxj3-qqfq/GHSA-73cx-rxj3-qqfq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-73cx-rxj3-qqfq", - "modified": "2024-09-27T15:30:34Z", + "modified": "2024-11-20T18:32:15Z", "published": "2024-09-27T15:30:33Z", "aliases": [ "CVE-2024-46817" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Stop amdgpu_dm initialize when stream nums greater than 6\n\n[Why]\nCoverity reports OVERRUN warning. Should abort amdgpu_dm\ninitialize.\n\n[How]\nReturn failure to amdgpu_dm_init.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -51,7 +54,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-27T13:15:14Z" diff --git a/advisories/unreviewed/2024/09/GHSA-82f5-7m6p-jqwq/GHSA-82f5-7m6p-jqwq.json b/advisories/unreviewed/2024/09/GHSA-82f5-7m6p-jqwq/GHSA-82f5-7m6p-jqwq.json index d34d1ea8b73..64f71fecf93 100644 --- a/advisories/unreviewed/2024/09/GHSA-82f5-7m6p-jqwq/GHSA-82f5-7m6p-jqwq.json +++ b/advisories/unreviewed/2024/09/GHSA-82f5-7m6p-jqwq/GHSA-82f5-7m6p-jqwq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-82f5-7m6p-jqwq", - "modified": "2024-09-18T09:30:37Z", + "modified": "2024-11-20T18:32:15Z", "published": "2024-09-18T09:30:37Z", "aliases": [ "CVE-2024-46771" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: bcm: Remove proc entry when dev is unregistered.\n\nsyzkaller reported a warning in bcm_connect() below. [0]\n\nThe repro calls connect() to vxcan1, removes vxcan1, and calls\nconnect() with ifindex == 0.\n\nCalling connect() for a BCM socket allocates a proc entry.\nThen, bcm_sk(sk)->bound is set to 1 to prevent further connect().\n\nHowever, removing the bound device resets bcm_sk(sk)->bound to 0\nin bcm_notify().\n\nThe 2nd connect() tries to allocate a proc entry with the same\nname and sets NULL to bcm_sk(sk)->bcm_proc_read, leaking the\noriginal proc entry.\n\nSince the proc entry is available only for connect()ed sockets,\nlet's clean up the entry when the bound netdev is unregistered.\n\n[0]:\nproc_dir_entry 'can-bcm/2456' already registered\nWARNING: CPU: 1 PID: 394 at fs/proc/generic.c:376 proc_register+0x645/0x8f0 fs/proc/generic.c:375\nModules linked in:\nCPU: 1 PID: 394 Comm: syz-executor403 Not tainted 6.10.0-rc7-g852e42cc2dd4\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014\nRIP: 0010:proc_register+0x645/0x8f0 fs/proc/generic.c:375\nCode: 00 00 00 00 00 48 85 ed 0f 85 97 02 00 00 4d 85 f6 0f 85 9f 02 00 00 48 c7 c7 9b cb cf 87 48 89 de 4c 89 fa e8 1c 6f eb fe 90 <0f> 0b 90 90 48 c7 c7 98 37 99 89 e8 cb 7e 22 05 bb 00 00 00 10 48\nRSP: 0018:ffa0000000cd7c30 EFLAGS: 00010246\nRAX: 9e129be1950f0200 RBX: ff1100011b51582c RCX: ff1100011857cd80\nRDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000002\nRBP: 0000000000000000 R08: ffd400000000000f R09: ff1100013e78cac0\nR10: ffac800000cd7980 R11: ff1100013e12b1f0 R12: 0000000000000000\nR13: 0000000000000000 R14: 0000000000000000 R15: ff1100011a99a2ec\nFS: 00007fbd7086f740(0000) GS:ff1100013fd00000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00000000200071c0 CR3: 0000000118556004 CR4: 0000000000771ef0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe07f0 DR7: 0000000000000400\nPKRU: 55555554\nCall Trace:\n \n proc_create_net_single+0x144/0x210 fs/proc/proc_net.c:220\n bcm_connect+0x472/0x840 net/can/bcm.c:1673\n __sys_connect_file net/socket.c:2049 [inline]\n __sys_connect+0x5d2/0x690 net/socket.c:2066\n __do_sys_connect net/socket.c:2076 [inline]\n __se_sys_connect net/socket.c:2073 [inline]\n __x64_sys_connect+0x8f/0x100 net/socket.c:2073\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xd9/0x1c0 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x4b/0x53\nRIP: 0033:0x7fbd708b0e5d\nCode: ff c3 66 2e 0f 1f 84 00 00 00 00 00 90 f3 0f 1e fa 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 8b 0d 73 9f 1b 00 f7 d8 64 89 01 48\nRSP: 002b:00007fff8cd33f08 EFLAGS: 00000246 ORIG_RAX: 000000000000002a\nRAX: ffffffffffffffda RBX: 0000000000000003 RCX: 00007fbd708b0e5d\nRDX: 0000000000000010 RSI: 0000000020000040 RDI: 0000000000000003\nRBP: 0000000000000000 R08: 0000000000000040 R09: 0000000000000040\nR10: 0000000000000040 R11: 0000000000000246 R12: 00007fff8cd34098\nR13: 0000000000401280 R14: 0000000000406de8 R15: 00007fbd70ab9000\n \nremove_proc_entry: removing non-empty directory 'net/can-bcm', leaking at least '2456'", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -55,7 +58,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T08:15:05Z" diff --git a/advisories/unreviewed/2024/09/GHSA-924c-rx43-2mjr/GHSA-924c-rx43-2mjr.json b/advisories/unreviewed/2024/09/GHSA-924c-rx43-2mjr/GHSA-924c-rx43-2mjr.json index 55ed7a04ac7..6ad113f79a8 100644 --- a/advisories/unreviewed/2024/09/GHSA-924c-rx43-2mjr/GHSA-924c-rx43-2mjr.json +++ b/advisories/unreviewed/2024/09/GHSA-924c-rx43-2mjr/GHSA-924c-rx43-2mjr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-924c-rx43-2mjr", - "modified": "2024-09-27T15:30:33Z", + "modified": "2024-11-20T18:32:15Z", "published": "2024-09-27T15:30:33Z", "aliases": [ "CVE-2024-46816" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Stop amdgpu_dm initialize when link nums greater than max_links\n\n[Why]\nCoverity report OVERRUN warning. There are\nonly max_links elements within dc->links. link\ncount could up to AMDGPU_DM_MAX_DISPLAY_INDEX 31.\n\n[How]\nMake sure link count less than max_links.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-27T13:15:14Z" diff --git a/advisories/unreviewed/2024/09/GHSA-9h7h-jp4j-h743/GHSA-9h7h-jp4j-h743.json b/advisories/unreviewed/2024/09/GHSA-9h7h-jp4j-h743/GHSA-9h7h-jp4j-h743.json index 71ef2cf056e..d4bace0cc16 100644 --- a/advisories/unreviewed/2024/09/GHSA-9h7h-jp4j-h743/GHSA-9h7h-jp4j-h743.json +++ b/advisories/unreviewed/2024/09/GHSA-9h7h-jp4j-h743/GHSA-9h7h-jp4j-h743.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9h7h-jp4j-h743", - "modified": "2024-09-27T15:30:33Z", + "modified": "2024-11-20T18:32:15Z", "published": "2024-09-27T15:30:33Z", "aliases": [ "CVE-2024-46820" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/vcn: remove irq disabling in vcn 5 suspend\n\nWe do not directly enable/disable VCN IRQ in vcn 5.0.0.\nAnd we do not handle the IRQ state as well. So the calls to\ndisable IRQ and set state are removed. This effectively gets\nrid of the warining of\n \"WARN_ON(!amdgpu_irq_enabled(adev, src, type))\"\nin amdgpu_irq_put().", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-27T13:15:14Z" diff --git a/advisories/unreviewed/2024/09/GHSA-cfpv-586j-2mfm/GHSA-cfpv-586j-2mfm.json b/advisories/unreviewed/2024/09/GHSA-cfpv-586j-2mfm/GHSA-cfpv-586j-2mfm.json index ce6d526d95a..1b7599e8348 100644 --- a/advisories/unreviewed/2024/09/GHSA-cfpv-586j-2mfm/GHSA-cfpv-586j-2mfm.json +++ b/advisories/unreviewed/2024/09/GHSA-cfpv-586j-2mfm/GHSA-cfpv-586j-2mfm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cfpv-586j-2mfm", - "modified": "2024-09-18T09:30:37Z", + "modified": "2024-11-20T18:32:15Z", "published": "2024-09-18T09:30:37Z", "aliases": [ "CVE-2024-46780" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: protect references to superblock parameters exposed in sysfs\n\nThe superblock buffers of nilfs2 can not only be overwritten at runtime\nfor modifications/repairs, but they are also regularly swapped, replaced\nduring resizing, and even abandoned when degrading to one side due to\nbacking device issues. So, accessing them requires mutual exclusion using\nthe reader/writer semaphore \"nilfs->ns_sem\".\n\nSome sysfs attribute show methods read this superblock buffer without the\nnecessary mutual exclusion, which can cause problems with pointer\ndereferencing and memory access, so fix it.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -55,7 +58,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T08:15:05Z" diff --git a/advisories/unreviewed/2024/09/GHSA-fgrc-hf8c-f3vr/GHSA-fgrc-hf8c-f3vr.json b/advisories/unreviewed/2024/09/GHSA-fgrc-hf8c-f3vr/GHSA-fgrc-hf8c-f3vr.json index 98d8469a7a2..4408e0e85b8 100644 --- a/advisories/unreviewed/2024/09/GHSA-fgrc-hf8c-f3vr/GHSA-fgrc-hf8c-f3vr.json +++ b/advisories/unreviewed/2024/09/GHSA-fgrc-hf8c-f3vr/GHSA-fgrc-hf8c-f3vr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fgrc-hf8c-f3vr", - "modified": "2024-09-18T09:30:37Z", + "modified": "2024-11-20T18:32:15Z", "published": "2024-09-18T09:30:37Z", "aliases": [ "CVE-2024-46775" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Validate function returns\n\n[WHAT & HOW]\nFunction return values must be checked before data can be used\nin subsequent functions.\n\nThis fixes 4 CHECKED_RETURN issues reported by Coverity.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T08:15:05Z" diff --git a/advisories/unreviewed/2024/09/GHSA-fxcf-gm2j-7vh5/GHSA-fxcf-gm2j-7vh5.json b/advisories/unreviewed/2024/09/GHSA-fxcf-gm2j-7vh5/GHSA-fxcf-gm2j-7vh5.json index 558094cca7c..372da31fda9 100644 --- a/advisories/unreviewed/2024/09/GHSA-fxcf-gm2j-7vh5/GHSA-fxcf-gm2j-7vh5.json +++ b/advisories/unreviewed/2024/09/GHSA-fxcf-gm2j-7vh5/GHSA-fxcf-gm2j-7vh5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fxcf-gm2j-7vh5", - "modified": "2024-09-27T15:30:33Z", + "modified": "2024-11-20T18:32:15Z", "published": "2024-09-27T15:30:33Z", "aliases": [ "CVE-2024-46815" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Check num_valid_sets before accessing reader_wm_sets[]\n\n[WHY & HOW]\nnum_valid_sets needs to be checked to avoid a negative index when\naccessing reader_wm_sets[num_valid_sets - 1].\n\nThis fixes an OVERRUN issue reported by Coverity.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -51,7 +54,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-27T13:15:14Z" diff --git a/advisories/unreviewed/2024/09/GHSA-g75v-mhrr-qmm9/GHSA-g75v-mhrr-qmm9.json b/advisories/unreviewed/2024/09/GHSA-g75v-mhrr-qmm9/GHSA-g75v-mhrr-qmm9.json index eab43652d7e..9f9cb4bc2df 100644 --- a/advisories/unreviewed/2024/09/GHSA-g75v-mhrr-qmm9/GHSA-g75v-mhrr-qmm9.json +++ b/advisories/unreviewed/2024/09/GHSA-g75v-mhrr-qmm9/GHSA-g75v-mhrr-qmm9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g75v-mhrr-qmm9", - "modified": "2024-09-18T09:30:37Z", + "modified": "2024-11-20T18:32:15Z", "published": "2024-09-18T09:30:37Z", "aliases": [ "CVE-2024-46783" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntcp_bpf: fix return value of tcp_bpf_sendmsg()\n\nWhen we cork messages in psock->cork, the last message triggers the\nflushing will result in sending a sk_msg larger than the current\nmessage size. In this case, in tcp_bpf_send_verdict(), 'copied' becomes\nnegative at least in the following case:\n\n468 case __SK_DROP:\n469 default:\n470 sk_msg_free_partial(sk, msg, tosend);\n471 sk_msg_apply_bytes(psock, tosend);\n472 *copied -= (tosend + delta); // <==== HERE\n473 return -EACCES;\n\nTherefore, it could lead to the following BUG with a proper value of\n'copied' (thanks to syzbot). We should not use negative 'copied' as a\nreturn value here.\n\n ------------[ cut here ]------------\n kernel BUG at net/socket.c:733!\n Internal error: Oops - BUG: 00000000f2000800 [#1] PREEMPT SMP\n Modules linked in:\n CPU: 0 UID: 0 PID: 3265 Comm: syz-executor510 Not tainted 6.11.0-rc3-syzkaller-00060-gd07b43284ab3 #0\n Hardware name: linux,dummy-virt (DT)\n pstate: 61400009 (nZCv daif +PAN -UAO -TCO +DIT -SSBS BTYPE=--)\n pc : sock_sendmsg_nosec net/socket.c:733 [inline]\n pc : sock_sendmsg_nosec net/socket.c:728 [inline]\n pc : __sock_sendmsg+0x5c/0x60 net/socket.c:745\n lr : sock_sendmsg_nosec net/socket.c:730 [inline]\n lr : __sock_sendmsg+0x54/0x60 net/socket.c:745\n sp : ffff800088ea3b30\n x29: ffff800088ea3b30 x28: fbf00000062bc900 x27: 0000000000000000\n x26: ffff800088ea3bc0 x25: ffff800088ea3bc0 x24: 0000000000000000\n x23: f9f00000048dc000 x22: 0000000000000000 x21: ffff800088ea3d90\n x20: f9f00000048dc000 x19: ffff800088ea3d90 x18: 0000000000000001\n x17: 0000000000000000 x16: 0000000000000000 x15: 000000002002ffaf\n x14: 0000000000000000 x13: 0000000000000000 x12: 0000000000000000\n x11: 0000000000000000 x10: ffff8000815849c0 x9 : ffff8000815b49c0\n x8 : 0000000000000000 x7 : 000000000000003f x6 : 0000000000000000\n x5 : 00000000000007e0 x4 : fff07ffffd239000 x3 : fbf00000062bc900\n x2 : 0000000000000000 x1 : 0000000000000000 x0 : 00000000fffffdef\n Call trace:\n sock_sendmsg_nosec net/socket.c:733 [inline]\n __sock_sendmsg+0x5c/0x60 net/socket.c:745\n ____sys_sendmsg+0x274/0x2ac net/socket.c:2597\n ___sys_sendmsg+0xac/0x100 net/socket.c:2651\n __sys_sendmsg+0x84/0xe0 net/socket.c:2680\n __do_sys_sendmsg net/socket.c:2689 [inline]\n __se_sys_sendmsg net/socket.c:2687 [inline]\n __arm64_sys_sendmsg+0x24/0x30 net/socket.c:2687\n __invoke_syscall arch/arm64/kernel/syscall.c:35 [inline]\n invoke_syscall+0x48/0x110 arch/arm64/kernel/syscall.c:49\n el0_svc_common.constprop.0+0x40/0xe0 arch/arm64/kernel/syscall.c:132\n do_el0_svc+0x1c/0x28 arch/arm64/kernel/syscall.c:151\n el0_svc+0x34/0xec arch/arm64/kernel/entry-common.c:712\n el0t_64_sync_handler+0x100/0x12c arch/arm64/kernel/entry-common.c:730\n el0t_64_sync+0x19c/0x1a0 arch/arm64/kernel/entry.S:598\n Code: f9404463 d63f0060 3108441f 54fffe81 (d4210000)\n ---[ end trace 0000000000000000 ]---", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -51,7 +54,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T08:15:05Z" diff --git a/advisories/unreviewed/2024/09/GHSA-jr43-7cf9-8vqm/GHSA-jr43-7cf9-8vqm.json b/advisories/unreviewed/2024/09/GHSA-jr43-7cf9-8vqm/GHSA-jr43-7cf9-8vqm.json index 510668b83f3..7f7adc666f5 100644 --- a/advisories/unreviewed/2024/09/GHSA-jr43-7cf9-8vqm/GHSA-jr43-7cf9-8vqm.json +++ b/advisories/unreviewed/2024/09/GHSA-jr43-7cf9-8vqm/GHSA-jr43-7cf9-8vqm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jr43-7cf9-8vqm", - "modified": "2024-09-27T15:30:34Z", + "modified": "2024-11-20T18:32:15Z", "published": "2024-09-27T15:30:33Z", "aliases": [ "CVE-2024-46826" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nELF: fix kernel.randomize_va_space double read\n\nELF loader uses \"randomize_va_space\" twice. It is sysctl and can change\nat any moment, so 2 loads could see 2 different values in theory with\nunpredictable consequences.\n\nIssue exactly one load for consistent value across one exec.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -39,7 +42,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-27T13:15:15Z" diff --git a/advisories/unreviewed/2024/09/GHSA-jxg7-j4mp-g3q9/GHSA-jxg7-j4mp-g3q9.json b/advisories/unreviewed/2024/09/GHSA-jxg7-j4mp-g3q9/GHSA-jxg7-j4mp-g3q9.json index 9861259e541..5c2ab943f07 100644 --- a/advisories/unreviewed/2024/09/GHSA-jxg7-j4mp-g3q9/GHSA-jxg7-j4mp-g3q9.json +++ b/advisories/unreviewed/2024/09/GHSA-jxg7-j4mp-g3q9/GHSA-jxg7-j4mp-g3q9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jxg7-j4mp-g3q9", - "modified": "2024-09-18T09:30:37Z", + "modified": "2024-11-20T18:32:15Z", "published": "2024-09-18T09:30:37Z", "aliases": [ "CVE-2024-46777" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nudf: Avoid excessive partition lengths\n\nAvoid mounting filesystems where the partition would overflow the\n32-bits used for block number. Also refuse to mount filesystems where\nthe partition length is so large we cannot safely index bits in a\nblock bitmap.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -55,7 +58,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T08:15:05Z" diff --git a/advisories/unreviewed/2024/09/GHSA-mm2v-m6vc-rhf4/GHSA-mm2v-m6vc-rhf4.json b/advisories/unreviewed/2024/09/GHSA-mm2v-m6vc-rhf4/GHSA-mm2v-m6vc-rhf4.json index 8596f42494f..e34d8fe4ea7 100644 --- a/advisories/unreviewed/2024/09/GHSA-mm2v-m6vc-rhf4/GHSA-mm2v-m6vc-rhf4.json +++ b/advisories/unreviewed/2024/09/GHSA-mm2v-m6vc-rhf4/GHSA-mm2v-m6vc-rhf4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mm2v-m6vc-rhf4", - "modified": "2024-09-18T09:30:37Z", + "modified": "2024-11-20T18:32:15Z", "published": "2024-09-18T09:30:37Z", "aliases": [ "CVE-2024-46768" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (hp-wmi-sensors) Check if WMI event data exists\n\nThe BIOS can choose to return no event data in response to a\nWMI event, so the ACPI object passed to the WMI notify handler\ncan be NULL.\n\nCheck for such a situation and ignore the event in such a case.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T08:15:04Z" diff --git a/advisories/unreviewed/2024/09/GHSA-q5xg-cgpw-7479/GHSA-q5xg-cgpw-7479.json b/advisories/unreviewed/2024/09/GHSA-q5xg-cgpw-7479/GHSA-q5xg-cgpw-7479.json index 0ad64239ca8..f35a46d5b3c 100644 --- a/advisories/unreviewed/2024/09/GHSA-q5xg-cgpw-7479/GHSA-q5xg-cgpw-7479.json +++ b/advisories/unreviewed/2024/09/GHSA-q5xg-cgpw-7479/GHSA-q5xg-cgpw-7479.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q5xg-cgpw-7479", - "modified": "2024-09-18T09:30:37Z", + "modified": "2024-11-20T18:32:15Z", "published": "2024-09-18T09:30:37Z", "aliases": [ "CVE-2024-46778" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Check UnboundedRequestEnabled's value\n\nCalculateSwathAndDETConfiguration_params_st's UnboundedRequestEnabled\nis a pointer (i.e. dml_bool_t *UnboundedRequestEnabled), and thus\nif (p->UnboundedRequestEnabled) checks its address, not bool value.\n\nThis fixes 1 REVERSE_INULL issue reported by Coverity.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T08:15:05Z" diff --git a/advisories/unreviewed/2024/09/GHSA-r8fr-h8q4-2f98/GHSA-r8fr-h8q4-2f98.json b/advisories/unreviewed/2024/09/GHSA-r8fr-h8q4-2f98/GHSA-r8fr-h8q4-2f98.json index fbbe13de0b2..88489e7b20b 100644 --- a/advisories/unreviewed/2024/09/GHSA-r8fr-h8q4-2f98/GHSA-r8fr-h8q4-2f98.json +++ b/advisories/unreviewed/2024/09/GHSA-r8fr-h8q4-2f98/GHSA-r8fr-h8q4-2f98.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r8fr-h8q4-2f98", - "modified": "2024-09-18T09:30:37Z", + "modified": "2024-11-20T18:32:15Z", "published": "2024-09-18T09:30:37Z", "aliases": [ "CVE-2024-46787" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nuserfaultfd: fix checks for huge PMDs\n\nPatch series \"userfaultfd: fix races around pmd_trans_huge() check\", v2.\n\nThe pmd_trans_huge() code in mfill_atomic() is wrong in three different\nways depending on kernel version:\n\n1. The pmd_trans_huge() check is racy and can lead to a BUG_ON() (if you hit\n the right two race windows) - I've tested this in a kernel build with\n some extra mdelay() calls. See the commit message for a description\n of the race scenario.\n On older kernels (before 6.5), I think the same bug can even\n theoretically lead to accessing transhuge page contents as a page table\n if you hit the right 5 narrow race windows (I haven't tested this case).\n2. As pointed out by Qi Zheng, pmd_trans_huge() is not sufficient for\n detecting PMDs that don't point to page tables.\n On older kernels (before 6.5), you'd just have to win a single fairly\n wide race to hit this.\n I've tested this on 6.1 stable by racing migration (with a mdelay()\n patched into try_to_migrate()) against UFFDIO_ZEROPAGE - on my x86\n VM, that causes a kernel oops in ptlock_ptr().\n3. On newer kernels (>=6.5), for shmem mappings, khugepaged is allowed\n to yank page tables out from under us (though I haven't tested that),\n so I think the BUG_ON() checks in mfill_atomic() are just wrong.\n\nI decided to write two separate fixes for these (one fix for bugs 1+2, one\nfix for bug 3), so that the first fix can be backported to kernels\naffected by bugs 1+2.\n\n\nThis patch (of 2):\n\nThis fixes two issues.\n\nI discovered that the following race can occur:\n\n mfill_atomic other thread\n ============ ============\n \n pmdp_get_lockless() [reads none pmd]\n \n \n \n __pte_alloc [no-op]\n \n \n BUG_ON(pmd_none(*dst_pmd))\n\nI have experimentally verified this in a kernel with extra mdelay() calls;\nthe BUG_ON(pmd_none(*dst_pmd)) triggers.\n\nOn kernels newer than commit 0d940a9b270b (\"mm/pgtable: allow\npte_offset_map[_lock]() to fail\"), this can't lead to anything worse than\na BUG_ON(), since the page table access helpers are actually designed to\ndeal with page tables concurrently disappearing; but on older kernels\n(<=6.4), I think we could probably theoretically race past the two\nBUG_ON() checks and end up treating a hugepage as a page table.\n\nThe second issue is that, as Qi Zheng pointed out, there are other types\nof huge PMDs that pmd_trans_huge() can't catch: devmap PMDs and swap PMDs\n(in particular, migration PMDs).\n\nOn <=6.4, this is worse than the first issue: If mfill_atomic() runs on a\nPMD that contains a migration entry (which just requires winning a single,\nfairly wide race), it will pass the PMD to pte_offset_map_lock(), which\nassumes that the PMD points to a page table.\n\nBreakage follows: First, the kernel tries to take the PTE lock (which will\ncrash or maybe worse if there is no \"struct page\" for the address bits in\nthe migration entry PMD - I think at least on X86 there usually is no\ncorresponding \"struct page\" thanks to the PTE inversion mitigation, amd64\nlooks different).\n\nIf that didn't crash, the kernel would next try to write a PTE into what\nit wrongly thinks is a page table.\n\nAs part of fixing these issues, get rid of the check for pmd_trans_huge()\nbefore __pte_alloc() - that's redundant, we're going to have to check for\nthat after the __pte_alloc() anyway.\n\nBackport note: pmdp_get_lockless() is pmd_read_atomic() in older kernels.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T08:15:05Z" diff --git a/advisories/unreviewed/2024/09/GHSA-rxvg-52xh-5pv7/GHSA-rxvg-52xh-5pv7.json b/advisories/unreviewed/2024/09/GHSA-rxvg-52xh-5pv7/GHSA-rxvg-52xh-5pv7.json index e225cf5ef2c..d08c10fb834 100644 --- a/advisories/unreviewed/2024/09/GHSA-rxvg-52xh-5pv7/GHSA-rxvg-52xh-5pv7.json +++ b/advisories/unreviewed/2024/09/GHSA-rxvg-52xh-5pv7/GHSA-rxvg-52xh-5pv7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rxvg-52xh-5pv7", - "modified": "2024-09-18T09:30:37Z", + "modified": "2024-11-20T18:32:15Z", "published": "2024-09-18T09:30:37Z", "aliases": [ "CVE-2024-46776" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Run DC_LOG_DC after checking link->link_enc\n\n[WHAT]\nThe DC_LOG_DC should be run after link->link_enc is checked, not before.\n\nThis fixes 1 REVERSE_INULL issue reported by Coverity.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T08:15:05Z" diff --git a/advisories/unreviewed/2024/09/GHSA-x443-5gjr-4gr5/GHSA-x443-5gjr-4gr5.json b/advisories/unreviewed/2024/09/GHSA-x443-5gjr-4gr5/GHSA-x443-5gjr-4gr5.json index 1032563f962..358a9456163 100644 --- a/advisories/unreviewed/2024/09/GHSA-x443-5gjr-4gr5/GHSA-x443-5gjr-4gr5.json +++ b/advisories/unreviewed/2024/09/GHSA-x443-5gjr-4gr5/GHSA-x443-5gjr-4gr5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x443-5gjr-4gr5", - "modified": "2024-09-18T09:30:37Z", + "modified": "2024-11-20T18:32:15Z", "published": "2024-09-18T09:30:37Z", "aliases": [ "CVE-2024-46785" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\neventfs: Use list_del_rcu() for SRCU protected list variable\n\nChi Zhiling reported:\n\n We found a null pointer accessing in tracefs[1], the reason is that the\n variable 'ei_child' is set to LIST_POISON1, that means the list was\n removed in eventfs_remove_rec. so when access the ei_child->is_freed, the\n panic triggered.\n\n by the way, the following script can reproduce this panic\n\n loop1 (){\n while true\n do\n echo \"p:kp submit_bio\" > /sys/kernel/debug/tracing/kprobe_events\n echo \"\" > /sys/kernel/debug/tracing/kprobe_events\n done\n }\n loop2 (){\n while true\n do\n tree /sys/kernel/debug/tracing/events/kprobes/\n done\n }\n loop1 &\n loop2\n\n [1]:\n [ 1147.959632][T17331] Unable to handle kernel paging request at virtual address dead000000000150\n [ 1147.968239][T17331] Mem abort info:\n [ 1147.971739][T17331] ESR = 0x0000000096000004\n [ 1147.976172][T17331] EC = 0x25: DABT (current EL), IL = 32 bits\n [ 1147.982171][T17331] SET = 0, FnV = 0\n [ 1147.985906][T17331] EA = 0, S1PTW = 0\n [ 1147.989734][T17331] FSC = 0x04: level 0 translation fault\n [ 1147.995292][T17331] Data abort info:\n [ 1147.998858][T17331] ISV = 0, ISS = 0x00000004, ISS2 = 0x00000000\n [ 1148.005023][T17331] CM = 0, WnR = 0, TnD = 0, TagAccess = 0\n [ 1148.010759][T17331] GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0\n [ 1148.016752][T17331] [dead000000000150] address between user and kernel address ranges\n [ 1148.024571][T17331] Internal error: Oops: 0000000096000004 [#1] SMP\n [ 1148.030825][T17331] Modules linked in: team_mode_loadbalance team nlmon act_gact cls_flower sch_ingress bonding tls macvlan dummy ib_core bridge stp llc veth amdgpu amdxcp mfd_core gpu_sched drm_exec drm_buddy radeon crct10dif_ce video drm_suballoc_helper ghash_ce drm_ttm_helper sha2_ce ttm sha256_arm64 i2c_algo_bit sha1_ce sbsa_gwdt cp210x drm_display_helper cec sr_mod cdrom drm_kms_helper binfmt_misc sg loop fuse drm dm_mod nfnetlink ip_tables autofs4 [last unloaded: tls]\n [ 1148.072808][T17331] CPU: 3 PID: 17331 Comm: ls Tainted: G W ------- ---- 6.6.43 #2\n [ 1148.081751][T17331] Source Version: 21b3b386e948bedd29369af66f3e98ab01b1c650\n [ 1148.088783][T17331] Hardware name: Greatwall GW-001M1A-FTF/GW-001M1A-FTF, BIOS KunLun BIOS V4.0 07/16/2020\n [ 1148.098419][T17331] pstate: 20000005 (nzCv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n [ 1148.106060][T17331] pc : eventfs_iterate+0x2c0/0x398\n [ 1148.111017][T17331] lr : eventfs_iterate+0x2fc/0x398\n [ 1148.115969][T17331] sp : ffff80008d56bbd0\n [ 1148.119964][T17331] x29: ffff80008d56bbf0 x28: ffff001ff5be2600 x27: 0000000000000000\n [ 1148.127781][T17331] x26: ffff001ff52ca4e0 x25: 0000000000009977 x24: dead000000000100\n [ 1148.135598][T17331] x23: 0000000000000000 x22: 000000000000000b x21: ffff800082645f10\n [ 1148.143415][T17331] x20: ffff001fddf87c70 x19: ffff80008d56bc90 x18: 0000000000000000\n [ 1148.151231][T17331] x17: 0000000000000000 x16: 0000000000000000 x15: ffff001ff52ca4e0\n [ 1148.159048][T17331] x14: 0000000000000000 x13: 0000000000000000 x12: 0000000000000000\n [ 1148.166864][T17331] x11: 0000000000000000 x10: 0000000000000000 x9 : ffff8000804391d0\n [ 1148.174680][T17331] x8 : 0000000180000000 x7 : 0000000000000018 x6 : 0000aaab04b92862\n [ 1148.182498][T17331] x5 : 0000aaab04b92862 x4 : 0000000080000000 x3 : 0000000000000068\n [ 1148.190314][T17331] x2 : 000000000000000f x1 : 0000000000007ea8 x0 : 0000000000000001\n [ 1148.198131][T17331] Call trace:\n [ 1148.201259][T17331] eventfs_iterate+0x2c0/0x398\n [ 1148.205864][T17331] iterate_dir+0x98/0x188\n [ 1148.210036][T17331] __arm64_sys_getdents64+0x78/0x160\n [ 1148.215161][T17331] invoke_syscall+0x78/0x108\n [ 1148.219593][T17331] el0_svc_common.constprop.0+0x48/0xf0\n [ 1148.224977][T17331] do_el0_svc+0x24/0x38\n [ 1148.228974][T17331] el0_svc+0x40/0x168\n [ 1148.232798][T17\n---truncated---", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T08:15:05Z" diff --git a/advisories/unreviewed/2024/09/GHSA-xmx8-5v8v-4mhj/GHSA-xmx8-5v8v-4mhj.json b/advisories/unreviewed/2024/09/GHSA-xmx8-5v8v-4mhj/GHSA-xmx8-5v8v-4mhj.json index 23fb8507f2d..da3a78554e9 100644 --- a/advisories/unreviewed/2024/09/GHSA-xmx8-5v8v-4mhj/GHSA-xmx8-5v8v-4mhj.json +++ b/advisories/unreviewed/2024/09/GHSA-xmx8-5v8v-4mhj/GHSA-xmx8-5v8v-4mhj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xmx8-5v8v-4mhj", - "modified": "2024-09-18T09:30:37Z", + "modified": "2024-11-20T18:32:15Z", "published": "2024-09-18T09:30:37Z", "aliases": [ "CVE-2024-46789" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/slub: add check for s->flags in the alloc_tagging_slab_free_hook\n\nWhen enable CONFIG_MEMCG & CONFIG_KFENCE & CONFIG_KMEMLEAK, the following\nwarning always occurs,This is because the following call stack occurred:\nmem_pool_alloc\n kmem_cache_alloc_noprof\n slab_alloc_node\n kfence_alloc\n\nOnce the kfence allocation is successful,slab->obj_exts will not be empty,\nbecause it has already been assigned a value in kfence_init_pool.\n\nSince in the prepare_slab_obj_exts_hook function,we perform a check for\ns->flags & (SLAB_NO_OBJ_EXT | SLAB_NOLEAKTRACE),the alloc_tag_add function\nwill not be called as a result.Therefore,ref->ct remains NULL.\n\nHowever,when we call mem_pool_free,since obj_ext is not empty, it\neventually leads to the alloc_tag_sub scenario being invoked. This is\nwhere the warning occurs.\n\nSo we should add corresponding checks in the alloc_tagging_slab_free_hook.\nFor __GFP_NO_OBJ_EXT case,I didn't see the specific case where it's using\nkfence,so I won't add the corresponding check in\nalloc_tagging_slab_free_hook for now.\n\n[ 3.734349] ------------[ cut here ]------------\n[ 3.734807] alloc_tag was not set\n[ 3.735129] WARNING: CPU: 4 PID: 40 at ./include/linux/alloc_tag.h:130 kmem_cache_free+0x444/0x574\n[ 3.735866] Modules linked in: autofs4\n[ 3.736211] CPU: 4 UID: 0 PID: 40 Comm: ksoftirqd/4 Tainted: G W 6.11.0-rc3-dirty #1\n[ 3.736969] Tainted: [W]=WARN\n[ 3.737258] Hardware name: QEMU KVM Virtual Machine, BIOS unknown 2/2/2022\n[ 3.737875] pstate: 60400005 (nZCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n[ 3.738501] pc : kmem_cache_free+0x444/0x574\n[ 3.738951] lr : kmem_cache_free+0x444/0x574\n[ 3.739361] sp : ffff80008357bb60\n[ 3.739693] x29: ffff80008357bb70 x28: 0000000000000000 x27: 0000000000000000\n[ 3.740338] x26: ffff80008207f000 x25: ffff000b2eb2fd60 x24: ffff0000c0005700\n[ 3.740982] x23: ffff8000804229e4 x22: ffff800082080000 x21: ffff800081756000\n[ 3.741630] x20: fffffd7ff8253360 x19: 00000000000000a8 x18: ffffffffffffffff\n[ 3.742274] x17: ffff800ab327f000 x16: ffff800083398000 x15: ffff800081756df0\n[ 3.742919] x14: 0000000000000000 x13: 205d344320202020 x12: 5b5d373038343337\n[ 3.743560] x11: ffff80008357b650 x10: 000000000000005d x9 : 00000000ffffffd0\n[ 3.744231] x8 : 7f7f7f7f7f7f7f7f x7 : ffff80008237bad0 x6 : c0000000ffff7fff\n[ 3.744907] x5 : ffff80008237ba78 x4 : ffff8000820bbad0 x3 : 0000000000000001\n[ 3.745580] x2 : 68d66547c09f7800 x1 : 68d66547c09f7800 x0 : 0000000000000000\n[ 3.746255] Call trace:\n[ 3.746530] kmem_cache_free+0x444/0x574\n[ 3.746931] mem_pool_free+0x44/0xf4\n[ 3.747306] free_object_rcu+0xc8/0xdc\n[ 3.747693] rcu_do_batch+0x234/0x8a4\n[ 3.748075] rcu_core+0x230/0x3e4\n[ 3.748424] rcu_core_si+0x14/0x1c\n[ 3.748780] handle_softirqs+0x134/0x378\n[ 3.749189] run_ksoftirqd+0x70/0x9c\n[ 3.749560] smpboot_thread_fn+0x148/0x22c\n[ 3.749978] kthread+0x10c/0x118\n[ 3.750323] ret_from_fork+0x10/0x20\n[ 3.750696] ---[ end trace 0000000000000000 ]---", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T08:15:05Z" diff --git a/advisories/unreviewed/2024/10/GHSA-8r4r-8c3p-6r95/GHSA-8r4r-8c3p-6r95.json b/advisories/unreviewed/2024/10/GHSA-8r4r-8c3p-6r95/GHSA-8r4r-8c3p-6r95.json index ec5c5377671..1d27255ea04 100644 --- a/advisories/unreviewed/2024/10/GHSA-8r4r-8c3p-6r95/GHSA-8r4r-8c3p-6r95.json +++ b/advisories/unreviewed/2024/10/GHSA-8r4r-8c3p-6r95/GHSA-8r4r-8c3p-6r95.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8r4r-8c3p-6r95", - "modified": "2024-10-21T18:30:56Z", + "modified": "2024-11-20T18:32:15Z", "published": "2024-10-21T18:30:56Z", "aliases": [ "CVE-2024-49866" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntracing/timerlat: Fix a race during cpuhp processing\n\nThere is another found exception that the \"timerlat/1\" thread was\nscheduled on CPU0, and lead to timer corruption finally:\n\n```\nODEBUG: init active (active state 0) object: ffff888237c2e108 object type: hrtimer hint: timerlat_irq+0x0/0x220\nWARNING: CPU: 0 PID: 426 at lib/debugobjects.c:518 debug_print_object+0x7d/0xb0\nModules linked in:\nCPU: 0 UID: 0 PID: 426 Comm: timerlat/1 Not tainted 6.11.0-rc7+ #45\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.13.0-1ubuntu1.1 04/01/2014\nRIP: 0010:debug_print_object+0x7d/0xb0\n...\nCall Trace:\n \n ? __warn+0x7c/0x110\n ? debug_print_object+0x7d/0xb0\n ? report_bug+0xf1/0x1d0\n ? prb_read_valid+0x17/0x20\n ? handle_bug+0x3f/0x70\n ? exc_invalid_op+0x13/0x60\n ? asm_exc_invalid_op+0x16/0x20\n ? debug_print_object+0x7d/0xb0\n ? debug_print_object+0x7d/0xb0\n ? __pfx_timerlat_irq+0x10/0x10\n __debug_object_init+0x110/0x150\n hrtimer_init+0x1d/0x60\n timerlat_main+0xab/0x2d0\n ? __pfx_timerlat_main+0x10/0x10\n kthread+0xb7/0xe0\n ? __pfx_kthread+0x10/0x10\n ret_from_fork+0x2d/0x40\n ? __pfx_kthread+0x10/0x10\n ret_from_fork_asm+0x1a/0x30\n \n```\n\nAfter tracing the scheduling event, it was discovered that the migration\nof the \"timerlat/1\" thread was performed during thread creation. Further\nanalysis confirmed that it is because the CPU online processing for\nosnoise is implemented through workers, which is asynchronous with the\noffline processing. When the worker was scheduled to create a thread, the\nCPU may has already been removed from the cpu_online_mask during the offline\nprocess, resulting in the inability to select the right CPU:\n\nT1 | T2\n[CPUHP_ONLINE] | cpu_device_down()\nosnoise_hotplug_workfn() |\n | cpus_write_lock()\n | takedown_cpu(1)\n | cpus_write_unlock()\n[CPUHP_OFFLINE] |\n cpus_read_lock() |\n start_kthread(1) |\n cpus_read_unlock() |\n\nTo fix this, skip online processing if the CPU is already offline.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-362" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T18:15:06Z" diff --git a/advisories/unreviewed/2024/11/GHSA-233g-c3hw-rh55/GHSA-233g-c3hw-rh55.json b/advisories/unreviewed/2024/11/GHSA-233g-c3hw-rh55/GHSA-233g-c3hw-rh55.json index 864cd122f0c..1ff47ace0cb 100644 --- a/advisories/unreviewed/2024/11/GHSA-233g-c3hw-rh55/GHSA-233g-c3hw-rh55.json +++ b/advisories/unreviewed/2024/11/GHSA-233g-c3hw-rh55/GHSA-233g-c3hw-rh55.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-233g-c3hw-rh55", - "modified": "2024-11-20T00:32:15Z", + "modified": "2024-11-20T18:32:16Z", "published": "2024-11-20T00:32:15Z", "aliases": [ "CVE-2018-9466" ], "details": "In the xmlSnprintfElementContent function of valid.c, there is a possible out of bounds write. This could lead to remote escalation of privilege in an unprivileged app with no additional execution privileges needed. User interaction is needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-19T23:15:04Z" diff --git a/advisories/unreviewed/2024/11/GHSA-27gp-h89j-594r/GHSA-27gp-h89j-594r.json b/advisories/unreviewed/2024/11/GHSA-27gp-h89j-594r/GHSA-27gp-h89j-594r.json index c616734fb65..e501a8652d7 100644 --- a/advisories/unreviewed/2024/11/GHSA-27gp-h89j-594r/GHSA-27gp-h89j-594r.json +++ b/advisories/unreviewed/2024/11/GHSA-27gp-h89j-594r/GHSA-27gp-h89j-594r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-27gp-h89j-594r", - "modified": "2024-11-20T00:32:14Z", + "modified": "2024-11-20T18:32:16Z", "published": "2024-11-20T00:32:14Z", "aliases": [ "CVE-2018-9419" ], "details": "In l2cble_process_sig_cmd of l2c_ble.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-19T22:15:18Z" diff --git a/advisories/unreviewed/2024/11/GHSA-3vj4-j93w-77x3/GHSA-3vj4-j93w-77x3.json b/advisories/unreviewed/2024/11/GHSA-3vj4-j93w-77x3/GHSA-3vj4-j93w-77x3.json new file mode 100644 index 00000000000..2329b22aa3b --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-3vj4-j93w-77x3/GHSA-3vj4-j93w-77x3.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3vj4-j93w-77x3", + "modified": "2024-11-20T18:32:17Z", + "published": "2024-11-20T18:32:17Z", + "aliases": [ + "CVE-2018-9480" + ], + "details": "In bta_hd_get_report_act of bta_hd_act.cc, there is a possible out-of-bounds read due to improper input validation. This could lead to remote information disclosure in the Bluetooth service with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9480" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2018-09-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T18:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-3w8x-p539-469j/GHSA-3w8x-p539-469j.json b/advisories/unreviewed/2024/11/GHSA-3w8x-p539-469j/GHSA-3w8x-p539-469j.json new file mode 100644 index 00000000000..400cef72c9c --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-3w8x-p539-469j/GHSA-3w8x-p539-469j.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3w8x-p539-469j", + "modified": "2024-11-20T18:32:17Z", + "published": "2024-11-20T18:32:17Z", + "aliases": [ + "CVE-2018-9468" + ], + "details": "In query of DownloadManager.java, there is a possible read/write of arbitrary files due to a permissions bypass. This could lead to local information disclosure and file rewriting with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9468" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2018-09-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-45c5-w4j9-w656/GHSA-45c5-w4j9-w656.json b/advisories/unreviewed/2024/11/GHSA-45c5-w4j9-w656/GHSA-45c5-w4j9-w656.json new file mode 100644 index 00000000000..e6432ed1160 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-45c5-w4j9-w656/GHSA-45c5-w4j9-w656.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-45c5-w4j9-w656", + "modified": "2024-11-20T18:32:17Z", + "published": "2024-11-20T18:32:17Z", + "aliases": [ + "CVE-2018-9471" + ], + "details": "In the deserialization constructor of NanoAppFilter.java, there is a possible loss of data due to type confusion. This could lead to local escalation of privilege in the system server with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9471" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2018-09-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T18:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-47g9-6fvg-823p/GHSA-47g9-6fvg-823p.json b/advisories/unreviewed/2024/11/GHSA-47g9-6fvg-823p/GHSA-47g9-6fvg-823p.json index 23de96499e4..637183d3c08 100644 --- a/advisories/unreviewed/2024/11/GHSA-47g9-6fvg-823p/GHSA-47g9-6fvg-823p.json +++ b/advisories/unreviewed/2024/11/GHSA-47g9-6fvg-823p/GHSA-47g9-6fvg-823p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-47g9-6fvg-823p", - "modified": "2024-11-19T21:31:32Z", + "modified": "2024-11-20T18:32:16Z", "published": "2024-11-19T21:31:32Z", "aliases": [ "CVE-2018-9366" ], "details": "In IMSA_Recv_Thread and VT_IMCB_Thread of ImsaClient.cpp and VideoTelephony.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-19T20:15:27Z" diff --git a/advisories/unreviewed/2024/11/GHSA-4g42-h44f-r666/GHSA-4g42-h44f-r666.json b/advisories/unreviewed/2024/11/GHSA-4g42-h44f-r666/GHSA-4g42-h44f-r666.json new file mode 100644 index 00000000000..93316f4ace9 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-4g42-h44f-r666/GHSA-4g42-h44f-r666.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4g42-h44f-r666", + "modified": "2024-11-20T18:32:17Z", + "published": "2024-11-20T18:32:17Z", + "aliases": [ + "CVE-2018-9470" + ], + "details": "In bff_Scanner_addOutPos of Scanner.c, there is a possible out-of-bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege in an unprivileged app with no additional execution privileges needed. User interaction is needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9470" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2018-09-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T18:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-4xv5-h636-p47w/GHSA-4xv5-h636-p47w.json b/advisories/unreviewed/2024/11/GHSA-4xv5-h636-p47w/GHSA-4xv5-h636-p47w.json new file mode 100644 index 00000000000..173c9792247 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-4xv5-h636-p47w/GHSA-4xv5-h636-p47w.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4xv5-h636-p47w", + "modified": "2024-11-20T18:32:18Z", + "published": "2024-11-20T18:32:18Z", + "aliases": [ + "CVE-2024-29292" + ], + "details": "Multiple OS Command Injection vulnerabilities affecting Kasda KW6512 router software version KW6512_Linux_V1.0 enable an authenticated remote attacker to execute arbitrary OS commands via Quick Setup and Internet page parameters passed to internet.cgi.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29292" + }, + { + "type": "WEB", + "url": "https://gist.github.com/QuartzDust/debfd7ddf934a9f5609d7f1a8cd71154" + }, + { + "type": "WEB", + "url": "https://www.kasdanet.com/ENHCSZ/pro_view-120.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T18:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-54hc-gq3w-c935/GHSA-54hc-gq3w-c935.json b/advisories/unreviewed/2024/11/GHSA-54hc-gq3w-c935/GHSA-54hc-gq3w-c935.json index 901b0e3a9b8..15179ceb280 100644 --- a/advisories/unreviewed/2024/11/GHSA-54hc-gq3w-c935/GHSA-54hc-gq3w-c935.json +++ b/advisories/unreviewed/2024/11/GHSA-54hc-gq3w-c935/GHSA-54hc-gq3w-c935.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-54hc-gq3w-c935", - "modified": "2024-11-19T18:31:06Z", + "modified": "2024-11-20T18:32:16Z", "published": "2024-11-19T18:31:06Z", "aliases": [ "CVE-2024-53050" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/i915/hdcp: Add encoder check in hdcp2_get_capability\n\nAdd encoder check in intel_hdcp2_get_capability to avoid\nnull pointer error.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-19T18:15:25Z" diff --git a/advisories/unreviewed/2024/11/GHSA-5qh7-385v-fmqf/GHSA-5qh7-385v-fmqf.json b/advisories/unreviewed/2024/11/GHSA-5qh7-385v-fmqf/GHSA-5qh7-385v-fmqf.json index 7fea651e181..115ba77ca00 100644 --- a/advisories/unreviewed/2024/11/GHSA-5qh7-385v-fmqf/GHSA-5qh7-385v-fmqf.json +++ b/advisories/unreviewed/2024/11/GHSA-5qh7-385v-fmqf/GHSA-5qh7-385v-fmqf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5qh7-385v-fmqf", - "modified": "2024-11-19T21:31:32Z", + "modified": "2024-11-20T18:32:16Z", "published": "2024-11-19T21:31:32Z", "aliases": [ "CVE-2018-9348" ], "details": "In SMF_ParseMetaEvent of eas_smf.c, there is a possible integer overflow. This could lead to remote denial of service due to resource exhaustion with no additional execution privileges needed. User interaction is needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-190" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-19T20:15:27Z" diff --git a/advisories/unreviewed/2024/11/GHSA-5rg2-32x4-8gcx/GHSA-5rg2-32x4-8gcx.json b/advisories/unreviewed/2024/11/GHSA-5rg2-32x4-8gcx/GHSA-5rg2-32x4-8gcx.json new file mode 100644 index 00000000000..480abb62d02 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-5rg2-32x4-8gcx/GHSA-5rg2-32x4-8gcx.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5rg2-32x4-8gcx", + "modified": "2024-11-20T18:32:17Z", + "published": "2024-11-20T18:32:17Z", + "aliases": [ + "CVE-2018-9477" + ], + "details": "In the development options section of the Settings app, there is a possible authentication bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9477" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2018-09-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T18:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-627r-gc28-6645/GHSA-627r-gc28-6645.json b/advisories/unreviewed/2024/11/GHSA-627r-gc28-6645/GHSA-627r-gc28-6645.json new file mode 100644 index 00000000000..833cfd65682 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-627r-gc28-6645/GHSA-627r-gc28-6645.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-627r-gc28-6645", + "modified": "2024-11-20T18:32:17Z", + "published": "2024-11-20T18:32:17Z", + "aliases": [ + "CVE-2024-52770" + ], + "details": "An arbitrary file upload vulnerability in the component /admin/file_manage_control of DedeBIZ v6.3.0 allows attackers to execute arbitrary code via uploading a crafted file.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52770" + }, + { + "type": "WEB", + "url": "https://co-a1natas.feishu.cn/docx/Zsd9dnGUvoBW6tx0G5fcVx6vnBb" + }, + { + "type": "WEB", + "url": "https://github.com/DedeBIZ/DedeV6" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T17:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-69r9-55p9-j6ww/GHSA-69r9-55p9-j6ww.json b/advisories/unreviewed/2024/11/GHSA-69r9-55p9-j6ww/GHSA-69r9-55p9-j6ww.json new file mode 100644 index 00000000000..eb4db79f633 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-69r9-55p9-j6ww/GHSA-69r9-55p9-j6ww.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-69r9-55p9-j6ww", + "modified": "2024-11-20T18:32:17Z", + "published": "2024-11-20T18:32:17Z", + "aliases": [ + "CVE-2018-9485" + ], + "details": "In l2cble_process_sig_cmd of l2c_ble.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure over bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9485" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2018-09-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T18:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-6wpw-4vr3-6744/GHSA-6wpw-4vr3-6744.json b/advisories/unreviewed/2024/11/GHSA-6wpw-4vr3-6744/GHSA-6wpw-4vr3-6744.json index 957cb1b302e..328f103482a 100644 --- a/advisories/unreviewed/2024/11/GHSA-6wpw-4vr3-6744/GHSA-6wpw-4vr3-6744.json +++ b/advisories/unreviewed/2024/11/GHSA-6wpw-4vr3-6744/GHSA-6wpw-4vr3-6744.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6wpw-4vr3-6744", - "modified": "2024-11-20T00:32:15Z", + "modified": "2024-11-20T18:32:16Z", "published": "2024-11-20T00:32:15Z", "aliases": [ "CVE-2024-44308" ], "details": "The issue was addressed with improved checks. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, macOS Sequoia 15.1.1, iOS 18.1.1 and iPadOS 18.1.1, visionOS 2.1.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited on Intel-based Mac systems.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -43,7 +46,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-20T00:15:17Z" diff --git a/advisories/unreviewed/2024/11/GHSA-6x32-2mjm-x4r9/GHSA-6x32-2mjm-x4r9.json b/advisories/unreviewed/2024/11/GHSA-6x32-2mjm-x4r9/GHSA-6x32-2mjm-x4r9.json index 19de3e5526c..2f213e9c231 100644 --- a/advisories/unreviewed/2024/11/GHSA-6x32-2mjm-x4r9/GHSA-6x32-2mjm-x4r9.json +++ b/advisories/unreviewed/2024/11/GHSA-6x32-2mjm-x4r9/GHSA-6x32-2mjm-x4r9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6x32-2mjm-x4r9", - "modified": "2024-11-20T00:32:14Z", + "modified": "2024-11-20T18:32:16Z", "published": "2024-11-20T00:32:14Z", "aliases": [ "CVE-2018-9432" ], "details": "In createPhonebookDialogView and createMapDialogView of BluetoothPermissionActivity.java, there is a possible permissions bypass. This could lead to local escalation of privilege due to hiding and bypassing the user's ability to disable access to contacts, with no additional execution privileges needed. User interaction is needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-276" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-19T22:15:19Z" diff --git a/advisories/unreviewed/2024/11/GHSA-76ph-jc9g-v47h/GHSA-76ph-jc9g-v47h.json b/advisories/unreviewed/2024/11/GHSA-76ph-jc9g-v47h/GHSA-76ph-jc9g-v47h.json new file mode 100644 index 00000000000..8d28b6bd18f --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-76ph-jc9g-v47h/GHSA-76ph-jc9g-v47h.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-76ph-jc9g-v47h", + "modified": "2024-11-20T18:32:17Z", + "published": "2024-11-20T18:32:17Z", + "aliases": [ + "CVE-2024-51163" + ], + "details": "Local File Inclusion vulnerability in Vegam Solutions Vegam 4i v.6.3.47.0 and earlier allows a remote attacker to obtain sensitive information via the print labelling function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51163" + }, + { + "type": "WEB", + "url": "https://github.com/rahulkadavil/CVEs/tree/main/CVE-2024-51163" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T17:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-7mm3-wc4f-j5fh/GHSA-7mm3-wc4f-j5fh.json b/advisories/unreviewed/2024/11/GHSA-7mm3-wc4f-j5fh/GHSA-7mm3-wc4f-j5fh.json new file mode 100644 index 00000000000..bcb9f1d72f3 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-7mm3-wc4f-j5fh/GHSA-7mm3-wc4f-j5fh.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7mm3-wc4f-j5fh", + "modified": "2024-11-20T18:32:17Z", + "published": "2024-11-20T18:32:17Z", + "aliases": [ + "CVE-2024-11491" + ], + "details": "A vulnerability was found in 115cms up to 20240807. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /index.php/admin/web/useradmin.html. The manipulation of the argument ks leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11491" + }, + { + "type": "WEB", + "url": "https://github.com/Hebing123/cve/issues/70" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.285506" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.285506" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T17:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-7rmf-rfc4-c6r2/GHSA-7rmf-rfc4-c6r2.json b/advisories/unreviewed/2024/11/GHSA-7rmf-rfc4-c6r2/GHSA-7rmf-rfc4-c6r2.json new file mode 100644 index 00000000000..59e5131b6cd --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-7rmf-rfc4-c6r2/GHSA-7rmf-rfc4-c6r2.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7rmf-rfc4-c6r2", + "modified": "2024-11-20T18:32:18Z", + "published": "2024-11-20T18:32:18Z", + "aliases": [ + "CVE-2024-11492" + ], + "details": "A vulnerability classified as problematic has been found in 115cms up to 20240807. This affects an unknown part of the file /index.php/admin/web/appurladd.html. The manipulation of the argument tid leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11492" + }, + { + "type": "WEB", + "url": "https://github.com/Hebing123/cve/issues/70" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.285507" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.285507" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T18:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-849w-8f8x-v945/GHSA-849w-8f8x-v945.json b/advisories/unreviewed/2024/11/GHSA-849w-8f8x-v945/GHSA-849w-8f8x-v945.json index 1fcaefc2574..521779c4ecd 100644 --- a/advisories/unreviewed/2024/11/GHSA-849w-8f8x-v945/GHSA-849w-8f8x-v945.json +++ b/advisories/unreviewed/2024/11/GHSA-849w-8f8x-v945/GHSA-849w-8f8x-v945.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-849w-8f8x-v945", - "modified": "2024-11-19T21:31:32Z", + "modified": "2024-11-20T18:32:16Z", "published": "2024-11-19T21:31:32Z", "aliases": [ "CVE-2018-9341" ], "details": "In impeg2d_mc_fullx_fully of impeg2d_mc.c there is a possible out of bound write due to missing bounds check. This could lead to remote arbitrary code execution with no additional execution privileges needed. User interaction is needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-19T19:15:05Z" diff --git a/advisories/unreviewed/2024/11/GHSA-8735-9wmp-4wx2/GHSA-8735-9wmp-4wx2.json b/advisories/unreviewed/2024/11/GHSA-8735-9wmp-4wx2/GHSA-8735-9wmp-4wx2.json index fce9e98cc3d..efadf52b4fd 100644 --- a/advisories/unreviewed/2024/11/GHSA-8735-9wmp-4wx2/GHSA-8735-9wmp-4wx2.json +++ b/advisories/unreviewed/2024/11/GHSA-8735-9wmp-4wx2/GHSA-8735-9wmp-4wx2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8735-9wmp-4wx2", - "modified": "2024-11-20T00:32:14Z", + "modified": "2024-11-20T18:32:16Z", "published": "2024-11-20T00:32:14Z", "aliases": [ "CVE-2024-44306" ], "details": "A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.6. An app may be able to execute arbitrary code with kernel privileges.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-20T00:15:16Z" diff --git a/advisories/unreviewed/2024/11/GHSA-8mmp-cwxx-jp88/GHSA-8mmp-cwxx-jp88.json b/advisories/unreviewed/2024/11/GHSA-8mmp-cwxx-jp88/GHSA-8mmp-cwxx-jp88.json index 052c25eedad..4019d351bda 100644 --- a/advisories/unreviewed/2024/11/GHSA-8mmp-cwxx-jp88/GHSA-8mmp-cwxx-jp88.json +++ b/advisories/unreviewed/2024/11/GHSA-8mmp-cwxx-jp88/GHSA-8mmp-cwxx-jp88.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8mmp-cwxx-jp88", - "modified": "2024-11-20T00:32:14Z", + "modified": "2024-11-20T18:32:16Z", "published": "2024-11-20T00:32:14Z", "aliases": [ "CVE-2018-9424" ], "details": "In CryptoPlugin::decrypt of CryptoPlugin.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-19T22:15:19Z" diff --git a/advisories/unreviewed/2024/11/GHSA-95hg-vx6x-rj95/GHSA-95hg-vx6x-rj95.json b/advisories/unreviewed/2024/11/GHSA-95hg-vx6x-rj95/GHSA-95hg-vx6x-rj95.json new file mode 100644 index 00000000000..9715516cffd --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-95hg-vx6x-rj95/GHSA-95hg-vx6x-rj95.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-95hg-vx6x-rj95", + "modified": "2024-11-20T18:32:17Z", + "published": "2024-11-20T18:32:17Z", + "aliases": [ + "CVE-2024-11489" + ], + "details": "A vulnerability was found in 115cms up to 20240807. It has been classified as problematic. Affected is an unknown function of the file /index.php/admin/web/file.html. The manipulation of the argument ks leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11489" + }, + { + "type": "WEB", + "url": "https://github.com/Hebing123/cve/issues/70" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.285504" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.285504" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T17:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-97h5-gfw2-p92x/GHSA-97h5-gfw2-p92x.json b/advisories/unreviewed/2024/11/GHSA-97h5-gfw2-p92x/GHSA-97h5-gfw2-p92x.json index 97899d08e76..4aa9001e25c 100644 --- a/advisories/unreviewed/2024/11/GHSA-97h5-gfw2-p92x/GHSA-97h5-gfw2-p92x.json +++ b/advisories/unreviewed/2024/11/GHSA-97h5-gfw2-p92x/GHSA-97h5-gfw2-p92x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-97h5-gfw2-p92x", - "modified": "2024-11-19T18:31:06Z", + "modified": "2024-11-20T18:32:16Z", "published": "2024-11-19T18:31:06Z", "aliases": [ "CVE-2017-13315" ], "details": "In writeToParcel and createFromParcel of DcParamObject.java, there is a permission bypass due to a write size mismatch. This could lead to an elevation of privileges where the user can start an activity with system privileges, with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-131" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-19T18:15:18Z" diff --git a/advisories/unreviewed/2024/11/GHSA-c9v7-fv5h-vr5j/GHSA-c9v7-fv5h-vr5j.json b/advisories/unreviewed/2024/11/GHSA-c9v7-fv5h-vr5j/GHSA-c9v7-fv5h-vr5j.json index f2ff59e4817..f4a20436b98 100644 --- a/advisories/unreviewed/2024/11/GHSA-c9v7-fv5h-vr5j/GHSA-c9v7-fv5h-vr5j.json +++ b/advisories/unreviewed/2024/11/GHSA-c9v7-fv5h-vr5j/GHSA-c9v7-fv5h-vr5j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c9v7-fv5h-vr5j", - "modified": "2024-11-19T21:31:32Z", + "modified": "2024-11-20T18:32:16Z", "published": "2024-11-19T21:31:32Z", "aliases": [ "CVE-2018-9344" ], "details": "In several functions of DescramblerImpl.cpp, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-19T19:15:05Z" diff --git a/advisories/unreviewed/2024/11/GHSA-ch8j-7gjj-5qxq/GHSA-ch8j-7gjj-5qxq.json b/advisories/unreviewed/2024/11/GHSA-ch8j-7gjj-5qxq/GHSA-ch8j-7gjj-5qxq.json new file mode 100644 index 00000000000..27666bf24d1 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-ch8j-7gjj-5qxq/GHSA-ch8j-7gjj-5qxq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ch8j-7gjj-5qxq", + "modified": "2024-11-20T18:32:17Z", + "published": "2024-11-20T18:32:17Z", + "aliases": [ + "CVE-2018-9486" + ], + "details": "In hidh_l2cif_data_ind of hidh_conn.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure over bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9486" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2018-09-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T18:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-cp57-7c6j-pxfg/GHSA-cp57-7c6j-pxfg.json b/advisories/unreviewed/2024/11/GHSA-cp57-7c6j-pxfg/GHSA-cp57-7c6j-pxfg.json index 7132909f6e1..edff1767172 100644 --- a/advisories/unreviewed/2024/11/GHSA-cp57-7c6j-pxfg/GHSA-cp57-7c6j-pxfg.json +++ b/advisories/unreviewed/2024/11/GHSA-cp57-7c6j-pxfg/GHSA-cp57-7c6j-pxfg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cp57-7c6j-pxfg", - "modified": "2024-11-19T18:31:06Z", + "modified": "2024-11-20T18:32:16Z", "published": "2024-11-19T18:31:06Z", "aliases": [ "CVE-2023-21270" ], "details": "In restorePermissionState of PermissionManagerServiceImpl.java, there is a possible way for an app to keep permissions that should be revoked due to incorrect permission flags cleared during an update. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-276" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-19T18:15:19Z" diff --git a/advisories/unreviewed/2024/11/GHSA-f927-34r4-vxxw/GHSA-f927-34r4-vxxw.json b/advisories/unreviewed/2024/11/GHSA-f927-34r4-vxxw/GHSA-f927-34r4-vxxw.json index c9a2b71808b..e9b21e243d2 100644 --- a/advisories/unreviewed/2024/11/GHSA-f927-34r4-vxxw/GHSA-f927-34r4-vxxw.json +++ b/advisories/unreviewed/2024/11/GHSA-f927-34r4-vxxw/GHSA-f927-34r4-vxxw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f927-34r4-vxxw", - "modified": "2024-11-15T18:30:51Z", + "modified": "2024-11-20T18:32:16Z", "published": "2024-11-15T18:30:51Z", "aliases": [ "CVE-2024-50653" ], "details": "CRMEB <=5.4.0 is vulnerable to Incorrect Access Control. Users can bypass the front-end restriction of only being able to claim coupons once by capturing packets and sending a large number of data packets for coupon collection, achieving unlimited coupon collection.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-15T17:15:20Z" diff --git a/advisories/unreviewed/2024/11/GHSA-fg4f-v7hp-cc45/GHSA-fg4f-v7hp-cc45.json b/advisories/unreviewed/2024/11/GHSA-fg4f-v7hp-cc45/GHSA-fg4f-v7hp-cc45.json new file mode 100644 index 00000000000..3651ef4a826 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-fg4f-v7hp-cc45/GHSA-fg4f-v7hp-cc45.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fg4f-v7hp-cc45", + "modified": "2024-11-20T18:32:17Z", + "published": "2024-11-20T18:32:17Z", + "aliases": [ + "CVE-2024-52725" + ], + "details": "SemCms v4.8 was discovered to contain a SQL injection vulnerability. This allows an attacker to execute arbitrary code via the ldgid parameter in the SEMCMS_SeoAndTag.php component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52725" + }, + { + "type": "WEB", + "url": "https://github.com/Megrez0423/Seecms" + }, + { + "type": "WEB", + "url": "http://semcms.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T17:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-fwpv-rgxh-fj74/GHSA-fwpv-rgxh-fj74.json b/advisories/unreviewed/2024/11/GHSA-fwpv-rgxh-fj74/GHSA-fwpv-rgxh-fj74.json new file mode 100644 index 00000000000..8cbc59643f1 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-fwpv-rgxh-fj74/GHSA-fwpv-rgxh-fj74.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fwpv-rgxh-fj74", + "modified": "2024-11-20T18:32:17Z", + "published": "2024-11-20T18:32:17Z", + "aliases": [ + "CVE-2018-9475" + ], + "details": "In HeadsetInterface::ClccResponse of btif_hf.cc, there is a possible out of bounds stack write due to a missing bounds check. This could lead to remote escalation of privilege via Bluetooth, if the recipient has enabled SIP calls with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9475" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2018-09-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T18:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-gc7r-mr2h-cg8h/GHSA-gc7r-mr2h-cg8h.json b/advisories/unreviewed/2024/11/GHSA-gc7r-mr2h-cg8h/GHSA-gc7r-mr2h-cg8h.json index 8dae4022d4e..1b51a8fd762 100644 --- a/advisories/unreviewed/2024/11/GHSA-gc7r-mr2h-cg8h/GHSA-gc7r-mr2h-cg8h.json +++ b/advisories/unreviewed/2024/11/GHSA-gc7r-mr2h-cg8h/GHSA-gc7r-mr2h-cg8h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gc7r-mr2h-cg8h", - "modified": "2024-11-19T21:31:32Z", + "modified": "2024-11-20T18:32:16Z", "published": "2024-11-19T21:31:32Z", "aliases": [ "CVE-2018-9364" ], "details": "In the LG LAF component, there is a special command that allowed modification of certain partitions. This could lead to bypass of secure boot. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-203" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-19T20:15:27Z" diff --git a/advisories/unreviewed/2024/11/GHSA-gfmp-fjx4-3grr/GHSA-gfmp-fjx4-3grr.json b/advisories/unreviewed/2024/11/GHSA-gfmp-fjx4-3grr/GHSA-gfmp-fjx4-3grr.json new file mode 100644 index 00000000000..82eb38692d4 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-gfmp-fjx4-3grr/GHSA-gfmp-fjx4-3grr.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gfmp-fjx4-3grr", + "modified": "2024-11-20T18:32:17Z", + "published": "2024-11-20T18:32:17Z", + "aliases": [ + "CVE-2024-11486" + ], + "details": "A vulnerability, which was classified as problematic, was found in Code4Berry Decoration Management System 1.0. This affects an unknown part of the file /decoration/admin/user_permission.php of the component User Permission Handler. The manipulation leads to permission issues. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11486" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.285501" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.285501" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.441916" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T16:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-gp8c-83qw-c833/GHSA-gp8c-83qw-c833.json b/advisories/unreviewed/2024/11/GHSA-gp8c-83qw-c833/GHSA-gp8c-83qw-c833.json index 2544025e88c..9cf5cb96e3e 100644 --- a/advisories/unreviewed/2024/11/GHSA-gp8c-83qw-c833/GHSA-gp8c-83qw-c833.json +++ b/advisories/unreviewed/2024/11/GHSA-gp8c-83qw-c833/GHSA-gp8c-83qw-c833.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gp8c-83qw-c833", - "modified": "2024-11-19T21:31:32Z", + "modified": "2024-11-20T18:32:16Z", "published": "2024-11-19T21:31:32Z", "aliases": [ "CVE-2018-9345" ], "details": "In BnAudioPolicyService::onTransact of AudioPolicyService.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-908" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-19T19:15:05Z" diff --git a/advisories/unreviewed/2024/11/GHSA-h4c9-8j9c-xf43/GHSA-h4c9-8j9c-xf43.json b/advisories/unreviewed/2024/11/GHSA-h4c9-8j9c-xf43/GHSA-h4c9-8j9c-xf43.json new file mode 100644 index 00000000000..36d2e7d2132 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-h4c9-8j9c-xf43/GHSA-h4c9-8j9c-xf43.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h4c9-8j9c-xf43", + "modified": "2024-11-20T18:32:17Z", + "published": "2024-11-20T18:32:17Z", + "aliases": [ + "CVE-2024-52769" + ], + "details": "An arbitrary file upload vulnerability in the component /admin/friendlink_edit of DedeBIZ v6.3.0 allows attackers to execute arbitrary code via uploading a crafted file.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52769" + }, + { + "type": "WEB", + "url": "https://co-a1natas.feishu.cn/docx/Zsd9dnGUvoBW6tx0G5fcVx6vnBb" + }, + { + "type": "WEB", + "url": "https://github.com/DedeBIZ/DedeV6" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T17:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-h559-wf3x-8rqj/GHSA-h559-wf3x-8rqj.json b/advisories/unreviewed/2024/11/GHSA-h559-wf3x-8rqj/GHSA-h559-wf3x-8rqj.json new file mode 100644 index 00000000000..4d0d62ed2dd --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-h559-wf3x-8rqj/GHSA-h559-wf3x-8rqj.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h559-wf3x-8rqj", + "modified": "2024-11-20T18:32:18Z", + "published": "2024-11-20T18:32:18Z", + "aliases": [ + "CVE-2024-11493" + ], + "details": "A vulnerability classified as problematic was found in 115cms up to 20240807. This vulnerability affects unknown code of the file /index.php/setpage/admin/pageAE.html. The manipulation of the argument tid leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11493" + }, + { + "type": "WEB", + "url": "https://github.com/Hebing123/cve/issues/70" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.285508" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.285508" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.442037" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T18:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-h7jr-f9m2-rr37/GHSA-h7jr-f9m2-rr37.json b/advisories/unreviewed/2024/11/GHSA-h7jr-f9m2-rr37/GHSA-h7jr-f9m2-rr37.json index 79b1ccf8c29..0dcc49808f1 100644 --- a/advisories/unreviewed/2024/11/GHSA-h7jr-f9m2-rr37/GHSA-h7jr-f9m2-rr37.json +++ b/advisories/unreviewed/2024/11/GHSA-h7jr-f9m2-rr37/GHSA-h7jr-f9m2-rr37.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h7jr-f9m2-rr37", - "modified": "2024-11-19T18:31:06Z", + "modified": "2024-11-20T18:32:16Z", "published": "2024-11-19T18:31:06Z", "aliases": [ "CVE-2024-53051" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/i915/hdcp: Add encoder check in intel_hdcp_get_capability\n\nSometimes during hotplug scenario or suspend/resume scenario encoder is\nnot always initialized when intel_hdcp_get_capability add\na check to avoid kernel null pointer dereference.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-19T18:15:25Z" diff --git a/advisories/unreviewed/2024/11/GHSA-hmmh-8x85-6jmh/GHSA-hmmh-8x85-6jmh.json b/advisories/unreviewed/2024/11/GHSA-hmmh-8x85-6jmh/GHSA-hmmh-8x85-6jmh.json index 6c6bedfee8d..ad713b860c7 100644 --- a/advisories/unreviewed/2024/11/GHSA-hmmh-8x85-6jmh/GHSA-hmmh-8x85-6jmh.json +++ b/advisories/unreviewed/2024/11/GHSA-hmmh-8x85-6jmh/GHSA-hmmh-8x85-6jmh.json @@ -48,7 +48,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-hpv6-625j-5g5j/GHSA-hpv6-625j-5g5j.json b/advisories/unreviewed/2024/11/GHSA-hpv6-625j-5g5j/GHSA-hpv6-625j-5g5j.json new file mode 100644 index 00000000000..735be52f082 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-hpv6-625j-5g5j/GHSA-hpv6-625j-5g5j.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hpv6-625j-5g5j", + "modified": "2024-11-20T18:32:17Z", + "published": "2024-11-20T18:32:17Z", + "aliases": [ + "CVE-2018-9483" + ], + "details": "In bta_dm_remove_sec_dev_entry of bta_dm_act.cc, there is a possible out of bounds read due to a use after free. This could lead to remote information disclosure over bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9483" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2018-09-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T18:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-hr5c-w8m8-mfqx/GHSA-hr5c-w8m8-mfqx.json b/advisories/unreviewed/2024/11/GHSA-hr5c-w8m8-mfqx/GHSA-hr5c-w8m8-mfqx.json index 8ed6a7128d7..802782058c8 100644 --- a/advisories/unreviewed/2024/11/GHSA-hr5c-w8m8-mfqx/GHSA-hr5c-w8m8-mfqx.json +++ b/advisories/unreviewed/2024/11/GHSA-hr5c-w8m8-mfqx/GHSA-hr5c-w8m8-mfqx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hr5c-w8m8-mfqx", - "modified": "2024-11-20T00:32:14Z", + "modified": "2024-11-20T18:32:16Z", "published": "2024-11-20T00:32:14Z", "aliases": [ "CVE-2018-9417" ], "details": "In f_hidg_read and hidg_disable of f_hid.c, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-19T22:15:18Z" diff --git a/advisories/unreviewed/2024/11/GHSA-hx2q-32g5-49fm/GHSA-hx2q-32g5-49fm.json b/advisories/unreviewed/2024/11/GHSA-hx2q-32g5-49fm/GHSA-hx2q-32g5-49fm.json new file mode 100644 index 00000000000..ace7789702d --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-hx2q-32g5-49fm/GHSA-hx2q-32g5-49fm.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hx2q-32g5-49fm", + "modified": "2024-11-20T18:32:17Z", + "published": "2024-11-20T18:32:17Z", + "aliases": [ + "CVE-2024-11484" + ], + "details": "A vulnerability classified as critical was found in Code4Berry Decoration Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /decoration/admin/update_image.php of the component User Image Handler. The manipulation of the argument productimage1 leads to improper access controls. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11484" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.285499" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.285499" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.441913" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T16:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-j5fv-4rwc-jmx5/GHSA-j5fv-4rwc-jmx5.json b/advisories/unreviewed/2024/11/GHSA-j5fv-4rwc-jmx5/GHSA-j5fv-4rwc-jmx5.json new file mode 100644 index 00000000000..c73c7d34450 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-j5fv-4rwc-jmx5/GHSA-j5fv-4rwc-jmx5.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j5fv-4rwc-jmx5", + "modified": "2024-11-20T18:32:17Z", + "published": "2024-11-20T18:32:17Z", + "aliases": [ + "CVE-2018-9484" + ], + "details": "In l2cu_send_peer_config_rej of l2c_utils.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9484" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2018-09-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T18:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-jrrp-pvfv-xjh3/GHSA-jrrp-pvfv-xjh3.json b/advisories/unreviewed/2024/11/GHSA-jrrp-pvfv-xjh3/GHSA-jrrp-pvfv-xjh3.json new file mode 100644 index 00000000000..13d50f87b80 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-jrrp-pvfv-xjh3/GHSA-jrrp-pvfv-xjh3.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jrrp-pvfv-xjh3", + "modified": "2024-11-20T18:32:17Z", + "published": "2024-11-20T18:32:17Z", + "aliases": [ + "CVE-2024-11487" + ], + "details": "A vulnerability has been found in Code4Berry Decoration Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /decoration/admin/btndates_report.php of the component Between Dates Reports. The manipulation of the argument fromdate/todate leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11487" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.285502" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.285502" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.441917" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T16:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-jw3w-mjq9-m7wp/GHSA-jw3w-mjq9-m7wp.json b/advisories/unreviewed/2024/11/GHSA-jw3w-mjq9-m7wp/GHSA-jw3w-mjq9-m7wp.json new file mode 100644 index 00000000000..d70d04c17e7 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-jw3w-mjq9-m7wp/GHSA-jw3w-mjq9-m7wp.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jw3w-mjq9-m7wp", + "modified": "2024-11-20T18:32:17Z", + "published": "2024-11-20T18:32:17Z", + "aliases": [ + "CVE-2018-9479" + ], + "details": "In process_service_attr_req and process_service_search_attr_req of sdp_server.cc, there is an out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed.  User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9479" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2018-09-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T18:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-jxr7-f3g8-36rm/GHSA-jxr7-f3g8-36rm.json b/advisories/unreviewed/2024/11/GHSA-jxr7-f3g8-36rm/GHSA-jxr7-f3g8-36rm.json index e6f3a98208b..197aaf590bf 100644 --- a/advisories/unreviewed/2024/11/GHSA-jxr7-f3g8-36rm/GHSA-jxr7-f3g8-36rm.json +++ b/advisories/unreviewed/2024/11/GHSA-jxr7-f3g8-36rm/GHSA-jxr7-f3g8-36rm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jxr7-f3g8-36rm", - "modified": "2024-11-07T12:30:35Z", + "modified": "2024-11-20T18:32:15Z", "published": "2024-11-07T12:30:35Z", "aliases": [ "CVE-2024-50149" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe: Don't free job in TDR\n\nFreeing job in TDR is not safe as TDR can pass the run_job thread\nresulting in UAF. It is only safe for free job to naturally be called by\nthe scheduler. Rather free job in TDR, add to pending list.\n\n(cherry picked from commit ea2f6a77d0c40d97f4a4dc93fee4afe15d94926d)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-07T10:15:06Z" diff --git a/advisories/unreviewed/2024/11/GHSA-mq9r-w66p-33m3/GHSA-mq9r-w66p-33m3.json b/advisories/unreviewed/2024/11/GHSA-mq9r-w66p-33m3/GHSA-mq9r-w66p-33m3.json new file mode 100644 index 00000000000..e5dba0ce9b2 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-mq9r-w66p-33m3/GHSA-mq9r-w66p-33m3.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mq9r-w66p-33m3", + "modified": "2024-11-20T18:32:17Z", + "published": "2024-11-20T18:32:17Z", + "aliases": [ + "CVE-2024-11485" + ], + "details": "A vulnerability, which was classified as critical, has been found in Code4Berry Decoration Management System 1.0. Affected by this issue is some unknown functionality of the file /decoration/admin/userregister.php of the component User Handler. The manipulation leads to permission issues. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11485" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.285500" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.285500" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.441914" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T16:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-mqmc-3v72-6q9f/GHSA-mqmc-3v72-6q9f.json b/advisories/unreviewed/2024/11/GHSA-mqmc-3v72-6q9f/GHSA-mqmc-3v72-6q9f.json index 473f9d36458..07185dc0b2b 100644 --- a/advisories/unreviewed/2024/11/GHSA-mqmc-3v72-6q9f/GHSA-mqmc-3v72-6q9f.json +++ b/advisories/unreviewed/2024/11/GHSA-mqmc-3v72-6q9f/GHSA-mqmc-3v72-6q9f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mqmc-3v72-6q9f", - "modified": "2024-11-20T00:32:14Z", + "modified": "2024-11-20T18:32:16Z", "published": "2024-11-20T00:32:14Z", "aliases": [ "CVE-2018-9421" ], "details": "In writeInplace of Parcel.cpp, there is a possible information leak across processes, using Binder, due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-908" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-19T22:15:19Z" diff --git a/advisories/unreviewed/2024/11/GHSA-mr8h-x3p6-5r8q/GHSA-mr8h-x3p6-5r8q.json b/advisories/unreviewed/2024/11/GHSA-mr8h-x3p6-5r8q/GHSA-mr8h-x3p6-5r8q.json new file mode 100644 index 00000000000..c0215d7f43f --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-mr8h-x3p6-5r8q/GHSA-mr8h-x3p6-5r8q.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mr8h-x3p6-5r8q", + "modified": "2024-11-20T18:32:17Z", + "published": "2024-11-20T18:32:17Z", + "aliases": [ + "CVE-2018-9472" + ], + "details": "In xmlMemStrdupLoc of xmlmemory.c, there is a possible out-of-bounds write due to an integer overflow. This could lead to remote code execution in an unprivileged process with no additional execution privileges needed. User interaction is needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9472" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2018-09-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T18:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-p35q-vvhx-5rq6/GHSA-p35q-vvhx-5rq6.json b/advisories/unreviewed/2024/11/GHSA-p35q-vvhx-5rq6/GHSA-p35q-vvhx-5rq6.json index a885e434466..45fc63128ff 100644 --- a/advisories/unreviewed/2024/11/GHSA-p35q-vvhx-5rq6/GHSA-p35q-vvhx-5rq6.json +++ b/advisories/unreviewed/2024/11/GHSA-p35q-vvhx-5rq6/GHSA-p35q-vvhx-5rq6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p35q-vvhx-5rq6", - "modified": "2024-11-20T00:32:14Z", + "modified": "2024-11-20T18:32:16Z", "published": "2024-11-20T00:32:14Z", "aliases": [ "CVE-2018-9428" ], "details": "In startDevice of AAudioServiceStreamBase.cpp there is a possible out of bounds write due to a use after free. This could lead to local arbitrary code execution with no additional execution privileges needed. User interaction is needed for exploitation. https://source.android.com/security/bulletin/2018-07-01", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-19T22:15:19Z" diff --git a/advisories/unreviewed/2024/11/GHSA-p6hm-frqp-586g/GHSA-p6hm-frqp-586g.json b/advisories/unreviewed/2024/11/GHSA-p6hm-frqp-586g/GHSA-p6hm-frqp-586g.json new file mode 100644 index 00000000000..9bd5bf7ee44 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-p6hm-frqp-586g/GHSA-p6hm-frqp-586g.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p6hm-frqp-586g", + "modified": "2024-11-20T18:32:17Z", + "published": "2024-11-20T18:32:17Z", + "aliases": [ + "CVE-2024-11490" + ], + "details": "A vulnerability was found in 115cms up to 20240807. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /index.php/admin/web/set.html. The manipulation of the argument type leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11490" + }, + { + "type": "WEB", + "url": "https://github.com/Hebing123/cve/issues/70" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.285505" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.285505" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T17:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-p9rx-45f8-3vvp/GHSA-p9rx-45f8-3vvp.json b/advisories/unreviewed/2024/11/GHSA-p9rx-45f8-3vvp/GHSA-p9rx-45f8-3vvp.json new file mode 100644 index 00000000000..5a2bc8205dd --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-p9rx-45f8-3vvp/GHSA-p9rx-45f8-3vvp.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p9rx-45f8-3vvp", + "modified": "2024-11-20T18:32:17Z", + "published": "2024-11-20T18:32:17Z", + "aliases": [ + "CVE-2024-11488" + ], + "details": "A vulnerability was found in 115cms up to 20240807 and classified as problematic. This issue affects some unknown processing of the file /app/admin/view/web_user.html. The manipulation of the argument ks leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11488" + }, + { + "type": "WEB", + "url": "https://github.com/Hebing123/cve/issues/70" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.285503" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.285503" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T17:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-pmcm-f4m7-v52m/GHSA-pmcm-f4m7-v52m.json b/advisories/unreviewed/2024/11/GHSA-pmcm-f4m7-v52m/GHSA-pmcm-f4m7-v52m.json new file mode 100644 index 00000000000..e26c40406e4 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-pmcm-f4m7-v52m/GHSA-pmcm-f4m7-v52m.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pmcm-f4m7-v52m", + "modified": "2024-11-20T18:32:17Z", + "published": "2024-11-20T18:32:17Z", + "aliases": [ + "CVE-2018-9469" + ], + "details": "In multiple functions of ShortcutService.java, there is a possible creation of a spoofed shortcut due to a missing permission check. This could lead to local escalation of privilege in a privileged app with no additional execution privileges needed. User interaction is needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9469" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2018-09-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-pmgw-894q-7f55/GHSA-pmgw-894q-7f55.json b/advisories/unreviewed/2024/11/GHSA-pmgw-894q-7f55/GHSA-pmgw-894q-7f55.json new file mode 100644 index 00000000000..0566232ca11 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-pmgw-894q-7f55/GHSA-pmgw-894q-7f55.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pmgw-894q-7f55", + "modified": "2024-11-20T18:32:17Z", + "published": "2024-11-20T18:32:17Z", + "aliases": [ + "CVE-2018-9482" + ], + "details": "In intr_data_copy_cb of btif_hd.cc, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure in the Bluetooth service with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9482" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2018-09-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T18:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-pq4w-jf35-7pmx/GHSA-pq4w-jf35-7pmx.json b/advisories/unreviewed/2024/11/GHSA-pq4w-jf35-7pmx/GHSA-pq4w-jf35-7pmx.json index 07b4d7eb476..2be3233f79b 100644 --- a/advisories/unreviewed/2024/11/GHSA-pq4w-jf35-7pmx/GHSA-pq4w-jf35-7pmx.json +++ b/advisories/unreviewed/2024/11/GHSA-pq4w-jf35-7pmx/GHSA-pq4w-jf35-7pmx.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pq4w-jf35-7pmx", - "modified": "2024-11-20T12:30:35Z", + "modified": "2024-11-20T18:32:17Z", "published": "2024-11-20T12:30:35Z", "aliases": [ "CVE-2024-10382" ], "details": "There exists a code execution vulnerability in the Car App Android Jetpack Library. In the CarAppService desrialization logic is used that allows for arbitrary java classes to be constructed. In combination with other gadgets, this can lead to arbitrary code execution. An attacker needs to have an app on a victims Android device that uses the CarAppService Class and the victim would need to install a malicious app alongside it. We recommend upgrading the library past version 1.7.0-beta02", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:U/V:C/RE:M/U:Amber" @@ -28,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-502" + "CWE-502", + "CWE-94" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-pqf7-5pw8-wxvr/GHSA-pqf7-5pw8-wxvr.json b/advisories/unreviewed/2024/11/GHSA-pqf7-5pw8-wxvr/GHSA-pqf7-5pw8-wxvr.json new file mode 100644 index 00000000000..b196fb8232a --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-pqf7-5pw8-wxvr/GHSA-pqf7-5pw8-wxvr.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pqf7-5pw8-wxvr", + "modified": "2024-11-20T18:32:17Z", + "published": "2024-11-20T18:32:17Z", + "aliases": [ + "CVE-2018-9474" + ], + "details": "In writeToParcel of MediaPlayer.java, there is a possible serialization/deserialization mismatch due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9474" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2018-09-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T18:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-pxvr-wp2h-6jcm/GHSA-pxvr-wp2h-6jcm.json b/advisories/unreviewed/2024/11/GHSA-pxvr-wp2h-6jcm/GHSA-pxvr-wp2h-6jcm.json new file mode 100644 index 00000000000..8715ee82c1c --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-pxvr-wp2h-6jcm/GHSA-pxvr-wp2h-6jcm.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pxvr-wp2h-6jcm", + "modified": "2024-11-20T18:32:17Z", + "published": "2024-11-20T18:32:17Z", + "aliases": [ + "CVE-2018-9487" + ], + "details": "In setVpnForcedLocked of Vpn.java, there is a possible blocking of internet traffic through vpn due to a bad uid check. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9487" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2018-09-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T18:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-q8j2-m6jw-5583/GHSA-q8j2-m6jw-5583.json b/advisories/unreviewed/2024/11/GHSA-q8j2-m6jw-5583/GHSA-q8j2-m6jw-5583.json index 94474e8b1f4..5fda9e44f85 100644 --- a/advisories/unreviewed/2024/11/GHSA-q8j2-m6jw-5583/GHSA-q8j2-m6jw-5583.json +++ b/advisories/unreviewed/2024/11/GHSA-q8j2-m6jw-5583/GHSA-q8j2-m6jw-5583.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q8j2-m6jw-5583", - "modified": "2024-11-19T21:31:32Z", + "modified": "2024-11-20T18:32:16Z", "published": "2024-11-19T21:31:32Z", "aliases": [ "CVE-2018-9346" ], "details": "In BnAudioPolicyService::onTransact of AudioPolicyService.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-908" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-19T19:15:06Z" diff --git a/advisories/unreviewed/2024/11/GHSA-qhv3-2cgf-c955/GHSA-qhv3-2cgf-c955.json b/advisories/unreviewed/2024/11/GHSA-qhv3-2cgf-c955/GHSA-qhv3-2cgf-c955.json new file mode 100644 index 00000000000..22b3dedc015 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-qhv3-2cgf-c955/GHSA-qhv3-2cgf-c955.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qhv3-2cgf-c955", + "modified": "2024-11-20T18:32:17Z", + "published": "2024-11-20T18:32:17Z", + "aliases": [ + "CVE-2024-51162" + ], + "details": "An issue in Audimex EE v.15.1.20 and before allows a remote attacker to escalate privileges.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51162" + }, + { + "type": "WEB", + "url": "https://en.web-audimex.com/ee-auditmanagement" + }, + { + "type": "WEB", + "url": "https://github.com/Cameleon037/CVEs/blob/main/CVE-2024-51162/README.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T17:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-rc9f-q3jv-fx7r/GHSA-rc9f-q3jv-fx7r.json b/advisories/unreviewed/2024/11/GHSA-rc9f-q3jv-fx7r/GHSA-rc9f-q3jv-fx7r.json index a7ee5b975de..8def39b3427 100644 --- a/advisories/unreviewed/2024/11/GHSA-rc9f-q3jv-fx7r/GHSA-rc9f-q3jv-fx7r.json +++ b/advisories/unreviewed/2024/11/GHSA-rc9f-q3jv-fx7r/GHSA-rc9f-q3jv-fx7r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rc9f-q3jv-fx7r", - "modified": "2024-11-18T09:31:13Z", + "modified": "2024-11-20T18:32:16Z", "published": "2024-11-18T09:31:13Z", "aliases": [ "CVE-2024-49574" diff --git a/advisories/unreviewed/2024/11/GHSA-rf7m-w6xx-cv97/GHSA-rf7m-w6xx-cv97.json b/advisories/unreviewed/2024/11/GHSA-rf7m-w6xx-cv97/GHSA-rf7m-w6xx-cv97.json index b1c8389b5da..040a84a619a 100644 --- a/advisories/unreviewed/2024/11/GHSA-rf7m-w6xx-cv97/GHSA-rf7m-w6xx-cv97.json +++ b/advisories/unreviewed/2024/11/GHSA-rf7m-w6xx-cv97/GHSA-rf7m-w6xx-cv97.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rf7m-w6xx-cv97", - "modified": "2024-11-20T06:30:32Z", + "modified": "2024-11-20T18:32:16Z", "published": "2024-11-20T06:30:32Z", "aliases": [ "CVE-2024-10515" ], "details": "In the process of testing the SEO Plugin by Squirrly SEO WordPress plugin before 12.3.21, a vulnerability was found that allows you to implement Stored XSS on behalf of the editor by embedding malicious script, which entails account takeover backdoor", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-20T06:15:15Z" diff --git a/advisories/unreviewed/2024/11/GHSA-rhj5-4qqq-64c2/GHSA-rhj5-4qqq-64c2.json b/advisories/unreviewed/2024/11/GHSA-rhj5-4qqq-64c2/GHSA-rhj5-4qqq-64c2.json index ebafd46e7f7..4b3a881f87e 100644 --- a/advisories/unreviewed/2024/11/GHSA-rhj5-4qqq-64c2/GHSA-rhj5-4qqq-64c2.json +++ b/advisories/unreviewed/2024/11/GHSA-rhj5-4qqq-64c2/GHSA-rhj5-4qqq-64c2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rhj5-4qqq-64c2", - "modified": "2024-11-20T00:32:14Z", + "modified": "2024-11-20T18:32:16Z", "published": "2024-11-20T00:32:14Z", "aliases": [ "CVE-2018-9420" ], "details": "In BnCameraService::onTransact of CameraService.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-908" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-19T22:15:19Z" diff --git a/advisories/unreviewed/2024/11/GHSA-rmc4-mqv6-cmwx/GHSA-rmc4-mqv6-cmwx.json b/advisories/unreviewed/2024/11/GHSA-rmc4-mqv6-cmwx/GHSA-rmc4-mqv6-cmwx.json new file mode 100644 index 00000000000..2150d9718a0 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-rmc4-mqv6-cmwx/GHSA-rmc4-mqv6-cmwx.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rmc4-mqv6-cmwx", + "modified": "2024-11-20T18:32:17Z", + "published": "2024-11-20T18:32:17Z", + "aliases": [ + "CVE-2018-9478" + ], + "details": "In process_service_attr_req and process_service_search_attr_req of sdp_server.cc, there is an out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed.  User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9478" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2018-09-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T18:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-rpq5-v9pq-9j39/GHSA-rpq5-v9pq-9j39.json b/advisories/unreviewed/2024/11/GHSA-rpq5-v9pq-9j39/GHSA-rpq5-v9pq-9j39.json index 751a0164de1..8f53216fc93 100644 --- a/advisories/unreviewed/2024/11/GHSA-rpq5-v9pq-9j39/GHSA-rpq5-v9pq-9j39.json +++ b/advisories/unreviewed/2024/11/GHSA-rpq5-v9pq-9j39/GHSA-rpq5-v9pq-9j39.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rpq5-v9pq-9j39", - "modified": "2024-11-20T00:32:14Z", + "modified": "2024-11-20T18:32:16Z", "published": "2024-11-20T00:32:14Z", "aliases": [ "CVE-2018-9411" ], "details": "In decrypt of ClearKeyCasPlugin.cpp there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote arbitrary code execution with no additional execution privileges needed. User interaction is needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-19T22:15:18Z" diff --git a/advisories/unreviewed/2024/11/GHSA-v38r-cmm6-v8c3/GHSA-v38r-cmm6-v8c3.json b/advisories/unreviewed/2024/11/GHSA-v38r-cmm6-v8c3/GHSA-v38r-cmm6-v8c3.json index da717da4462..926ca3e0544 100644 --- a/advisories/unreviewed/2024/11/GHSA-v38r-cmm6-v8c3/GHSA-v38r-cmm6-v8c3.json +++ b/advisories/unreviewed/2024/11/GHSA-v38r-cmm6-v8c3/GHSA-v38r-cmm6-v8c3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v38r-cmm6-v8c3", - "modified": "2024-11-19T21:31:32Z", + "modified": "2024-11-20T18:32:16Z", "published": "2024-11-19T21:31:32Z", "aliases": [ "CVE-2018-9339" ], "details": "In writeTypedArrayList and readTypedArrayList of Parcel.java, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-704" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-19T19:15:05Z" diff --git a/advisories/unreviewed/2024/11/GHSA-vmmq-p5r9-qm38/GHSA-vmmq-p5r9-qm38.json b/advisories/unreviewed/2024/11/GHSA-vmmq-p5r9-qm38/GHSA-vmmq-p5r9-qm38.json index fdd5a48856e..a2a797b646e 100644 --- a/advisories/unreviewed/2024/11/GHSA-vmmq-p5r9-qm38/GHSA-vmmq-p5r9-qm38.json +++ b/advisories/unreviewed/2024/11/GHSA-vmmq-p5r9-qm38/GHSA-vmmq-p5r9-qm38.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-1336" + "CWE-1336", + "CWE-94" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-wjgf-x45f-9vgf/GHSA-wjgf-x45f-9vgf.json b/advisories/unreviewed/2024/11/GHSA-wjgf-x45f-9vgf/GHSA-wjgf-x45f-9vgf.json new file mode 100644 index 00000000000..e64a82002d5 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-wjgf-x45f-9vgf/GHSA-wjgf-x45f-9vgf.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wjgf-x45f-9vgf", + "modified": "2024-11-20T18:32:18Z", + "published": "2024-11-20T18:32:18Z", + "aliases": [ + "CVE-2024-52739" + ], + "details": "D-LINK DI-8400 v16.07.26A1 was discovered to contain multiple remote command execution (RCE) vulnerabilities in the msp_info_htm function via the flag and cmd parameters.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52739" + }, + { + "type": "WEB", + "url": "https://github.com/faqiadegege/IoTVuln/blob/main/DI_8400_msp_info_htm_rce/detail.md" + }, + { + "type": "WEB", + "url": "https://www.dlink.com/en/security-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T18:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-x386-xj3c-xjx5/GHSA-x386-xj3c-xjx5.json b/advisories/unreviewed/2024/11/GHSA-x386-xj3c-xjx5/GHSA-x386-xj3c-xjx5.json index dc91d9a2934..e199d781e6f 100644 --- a/advisories/unreviewed/2024/11/GHSA-x386-xj3c-xjx5/GHSA-x386-xj3c-xjx5.json +++ b/advisories/unreviewed/2024/11/GHSA-x386-xj3c-xjx5/GHSA-x386-xj3c-xjx5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x386-xj3c-xjx5", - "modified": "2024-11-19T21:31:32Z", + "modified": "2024-11-20T18:32:16Z", "published": "2024-11-19T21:31:32Z", "aliases": [ "CVE-2018-9340" ], "details": "In ResStringPool::setTo of ResourceTypes.cpp, it's possible for an attacker to control the value of mStringPoolSize to be out of bounds, causing information disclosure.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-19T19:15:05Z" diff --git a/advisories/unreviewed/2024/11/GHSA-xc54-5cvr-93hc/GHSA-xc54-5cvr-93hc.json b/advisories/unreviewed/2024/11/GHSA-xc54-5cvr-93hc/GHSA-xc54-5cvr-93hc.json index 2e863c83b64..d326cc0bfc2 100644 --- a/advisories/unreviewed/2024/11/GHSA-xc54-5cvr-93hc/GHSA-xc54-5cvr-93hc.json +++ b/advisories/unreviewed/2024/11/GHSA-xc54-5cvr-93hc/GHSA-xc54-5cvr-93hc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xc54-5cvr-93hc", - "modified": "2024-11-20T00:32:14Z", + "modified": "2024-11-20T18:32:16Z", "published": "2024-11-20T00:32:14Z", "aliases": [ "CVE-2024-44307" ], "details": "A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.6. An app may be able to execute arbitrary code with kernel privileges.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-20T00:15:17Z" diff --git a/advisories/unreviewed/2024/11/GHSA-xc7x-w33q-rvw9/GHSA-xc7x-w33q-rvw9.json b/advisories/unreviewed/2024/11/GHSA-xc7x-w33q-rvw9/GHSA-xc7x-w33q-rvw9.json new file mode 100644 index 00000000000..1897c2040f4 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-xc7x-w33q-rvw9/GHSA-xc7x-w33q-rvw9.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xc7x-w33q-rvw9", + "modified": "2024-11-20T18:32:17Z", + "published": "2024-11-20T18:32:17Z", + "aliases": [ + "CVE-2018-9481" + ], + "details": "In bta_hd_set_report_act of bta_hd_act.cc, there is a possible out-of-bounds read due to an integer overflow. This could lead to remote information disclosure in the Bluetooth service with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9481" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2018-09-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T18:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-xx8w-4q6h-66xg/GHSA-xx8w-4q6h-66xg.json b/advisories/unreviewed/2024/11/GHSA-xx8w-4q6h-66xg/GHSA-xx8w-4q6h-66xg.json new file mode 100644 index 00000000000..acb243fe8d4 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-xx8w-4q6h-66xg/GHSA-xx8w-4q6h-66xg.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xx8w-4q6h-66xg", + "modified": "2024-11-20T18:32:17Z", + "published": "2024-11-20T18:32:17Z", + "aliases": [ + "CVE-2024-52771" + ], + "details": "DedeBIZ v6.3.0 was discovered to contain an arbitrary file deletion vulnerability via the component /admin/file_manage_view.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52771" + }, + { + "type": "WEB", + "url": "https://co-a1natas.feishu.cn/docx/Zsd9dnGUvoBW6tx0G5fcVx6vnBb" + }, + { + "type": "WEB", + "url": "https://github.com/DedeBIZ/DedeV6" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T17:15:20Z" + } +} \ No newline at end of file