From 30964177597eac91a7a7f305430f8fe0b2b8ade2 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 26 Nov 2024 15:32:46 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-h9xw-259p-x86h.json | 9 ++- .../GHSA-p559-89wh-h48w.json | 9 ++- .../GHSA-qp4c-f9fg-vrxf.json | 11 ++-- .../GHSA-296c-8m99-q77p.json | 3 +- .../GHSA-57cg-pmv4-v925.json | 15 +++-- .../GHSA-6cvr-wmr3-636f.json | 1 + .../GHSA-gf7m-c4p9-5gvh.json | 1 + .../GHSA-22pf-6rh7-89gj.json | 38 ++++++++++++ .../GHSA-3r9h-5xmh-8j4q.json | 43 ++++++++++++++ .../GHSA-49gp-6j88-r9j7.json | 38 ++++++++++++ .../GHSA-4c4w-pcg8-6hq9.json | 39 ++++++++++++ .../GHSA-4jp9-q9g7-48gr.json | 51 ++++++++++++++++ .../GHSA-4qc3-fmcj-w66w.json | 6 +- .../GHSA-53mx-8hhc-gmp3.json | 59 +++++++++++++++++++ .../GHSA-77rq-3336-8w4x.json | 38 ++++++++++++ .../GHSA-7gfr-xrcc-jm66.json | 38 ++++++++++++ .../GHSA-7mjq-fcrm-26pg.json | 4 +- .../GHSA-7r4q-q89f-2mcg.json | 43 ++++++++++++++ .../GHSA-845f-27fw-gjw9.json | 43 ++++++++++++++ .../GHSA-8rq4-c5x2-x4g8.json | 43 ++++++++++++++ .../GHSA-8vxw-wxwq-hg38.json | 38 ++++++++++++ .../GHSA-92xm-7m45-93pf.json | 38 ++++++++++++ .../GHSA-966f-2c6j-qj89.json | 6 +- .../GHSA-9g2q-259c-66mq.json | 51 ++++++++++++++++ .../GHSA-cpgg-w28j-jvph.json | 9 ++- .../GHSA-cpxj-fx45-9pgm.json | 51 ++++++++++++++++ .../GHSA-cq6j-fwr2-x2rr.json | 38 ++++++++++++ .../GHSA-f94q-ffqr-x638.json | 6 +- .../GHSA-fvjw-6h28-3r9c.json | 38 ++++++++++++ .../GHSA-fw6g-5qw9-p3mx.json | 6 +- .../GHSA-g5wv-cvf4-2r98.json | 51 ++++++++++++++++ .../GHSA-h43c-gg33-qj9g.json | 43 ++++++++++++++ .../GHSA-h6c3-73mq-5cp9.json | 46 +++++++++++++++ .../GHSA-h8gv-f7pf-7c4p.json | 43 ++++++++++++++ .../GHSA-jxv2-pgjw-vg3v.json | 39 ++++++++++++ .../GHSA-m59j-fmqm-3q93.json | 51 ++++++++++++++++ .../GHSA-mjcw-r3mg-3848.json | 55 +++++++++++++++++ .../GHSA-p9vw-xw86-3f2w.json | 43 ++++++++++++++ .../GHSA-qpv5-9fm8-4hfv.json | 42 +++++++++++++ .../GHSA-qxf6-g9x3-8w74.json | 51 ++++++++++++++++ .../GHSA-rh22-rcv2-42x3.json | 51 ++++++++++++++++ .../GHSA-vmrp-q2j9-gmqr.json | 38 ++++++++++++ .../GHSA-wjq6-6xvc-xr82.json | 39 ++++++++++++ 43 files changed, 1381 insertions(+), 24 deletions(-) create mode 100644 advisories/unreviewed/2024/11/GHSA-22pf-6rh7-89gj/GHSA-22pf-6rh7-89gj.json create mode 100644 advisories/unreviewed/2024/11/GHSA-3r9h-5xmh-8j4q/GHSA-3r9h-5xmh-8j4q.json create mode 100644 advisories/unreviewed/2024/11/GHSA-49gp-6j88-r9j7/GHSA-49gp-6j88-r9j7.json create mode 100644 advisories/unreviewed/2024/11/GHSA-4c4w-pcg8-6hq9/GHSA-4c4w-pcg8-6hq9.json create mode 100644 advisories/unreviewed/2024/11/GHSA-4jp9-q9g7-48gr/GHSA-4jp9-q9g7-48gr.json create mode 100644 advisories/unreviewed/2024/11/GHSA-53mx-8hhc-gmp3/GHSA-53mx-8hhc-gmp3.json create mode 100644 advisories/unreviewed/2024/11/GHSA-77rq-3336-8w4x/GHSA-77rq-3336-8w4x.json create mode 100644 advisories/unreviewed/2024/11/GHSA-7gfr-xrcc-jm66/GHSA-7gfr-xrcc-jm66.json create mode 100644 advisories/unreviewed/2024/11/GHSA-7r4q-q89f-2mcg/GHSA-7r4q-q89f-2mcg.json create mode 100644 advisories/unreviewed/2024/11/GHSA-845f-27fw-gjw9/GHSA-845f-27fw-gjw9.json create mode 100644 advisories/unreviewed/2024/11/GHSA-8rq4-c5x2-x4g8/GHSA-8rq4-c5x2-x4g8.json create mode 100644 advisories/unreviewed/2024/11/GHSA-8vxw-wxwq-hg38/GHSA-8vxw-wxwq-hg38.json create mode 100644 advisories/unreviewed/2024/11/GHSA-92xm-7m45-93pf/GHSA-92xm-7m45-93pf.json create mode 100644 advisories/unreviewed/2024/11/GHSA-9g2q-259c-66mq/GHSA-9g2q-259c-66mq.json create mode 100644 advisories/unreviewed/2024/11/GHSA-cpxj-fx45-9pgm/GHSA-cpxj-fx45-9pgm.json create mode 100644 advisories/unreviewed/2024/11/GHSA-cq6j-fwr2-x2rr/GHSA-cq6j-fwr2-x2rr.json create mode 100644 advisories/unreviewed/2024/11/GHSA-fvjw-6h28-3r9c/GHSA-fvjw-6h28-3r9c.json create mode 100644 advisories/unreviewed/2024/11/GHSA-g5wv-cvf4-2r98/GHSA-g5wv-cvf4-2r98.json create mode 100644 advisories/unreviewed/2024/11/GHSA-h43c-gg33-qj9g/GHSA-h43c-gg33-qj9g.json create mode 100644 advisories/unreviewed/2024/11/GHSA-h6c3-73mq-5cp9/GHSA-h6c3-73mq-5cp9.json create mode 100644 advisories/unreviewed/2024/11/GHSA-h8gv-f7pf-7c4p/GHSA-h8gv-f7pf-7c4p.json create mode 100644 advisories/unreviewed/2024/11/GHSA-jxv2-pgjw-vg3v/GHSA-jxv2-pgjw-vg3v.json create mode 100644 advisories/unreviewed/2024/11/GHSA-m59j-fmqm-3q93/GHSA-m59j-fmqm-3q93.json create mode 100644 advisories/unreviewed/2024/11/GHSA-mjcw-r3mg-3848/GHSA-mjcw-r3mg-3848.json create mode 100644 advisories/unreviewed/2024/11/GHSA-p9vw-xw86-3f2w/GHSA-p9vw-xw86-3f2w.json create mode 100644 advisories/unreviewed/2024/11/GHSA-qpv5-9fm8-4hfv/GHSA-qpv5-9fm8-4hfv.json create mode 100644 advisories/unreviewed/2024/11/GHSA-qxf6-g9x3-8w74/GHSA-qxf6-g9x3-8w74.json create mode 100644 advisories/unreviewed/2024/11/GHSA-rh22-rcv2-42x3/GHSA-rh22-rcv2-42x3.json create mode 100644 advisories/unreviewed/2024/11/GHSA-vmrp-q2j9-gmqr/GHSA-vmrp-q2j9-gmqr.json create mode 100644 advisories/unreviewed/2024/11/GHSA-wjq6-6xvc-xr82/GHSA-wjq6-6xvc-xr82.json diff --git a/advisories/unreviewed/2024/02/GHSA-h9xw-259p-x86h/GHSA-h9xw-259p-x86h.json b/advisories/unreviewed/2024/02/GHSA-h9xw-259p-x86h/GHSA-h9xw-259p-x86h.json index 77cd9ce23c8..4d9beab5a7b 100644 --- a/advisories/unreviewed/2024/02/GHSA-h9xw-259p-x86h/GHSA-h9xw-259p-x86h.json +++ b/advisories/unreviewed/2024/02/GHSA-h9xw-259p-x86h/GHSA-h9xw-259p-x86h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h9xw-259p-x86h", - "modified": "2024-02-16T21:31:31Z", + "modified": "2024-11-26T15:30:59Z", "published": "2024-02-16T21:31:31Z", "aliases": [ "CVE-2024-0019" ], "details": "In setListening of AppOpsControllerImpl.java, there is a possible way to hide the microphone privacy indicator when restarting systemUI due to a missing check for active recordings. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-16T20:15:47Z" diff --git a/advisories/unreviewed/2024/03/GHSA-p559-89wh-h48w/GHSA-p559-89wh-h48w.json b/advisories/unreviewed/2024/03/GHSA-p559-89wh-h48w/GHSA-p559-89wh-h48w.json index b065a03eac6..131f459bcd9 100644 --- a/advisories/unreviewed/2024/03/GHSA-p559-89wh-h48w/GHSA-p559-89wh-h48w.json +++ b/advisories/unreviewed/2024/03/GHSA-p559-89wh-h48w/GHSA-p559-89wh-h48w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p559-89wh-h48w", - "modified": "2024-03-11T18:31:08Z", + "modified": "2024-11-26T15:30:59Z", "published": "2024-03-11T18:31:08Z", "aliases": [ "CVE-2024-0053" ], "details": "In getCustomPrinterIcon of PrintManagerService.java, there is a possible way to view other user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-11T17:15:45Z" diff --git a/advisories/unreviewed/2024/03/GHSA-qp4c-f9fg-vrxf/GHSA-qp4c-f9fg-vrxf.json b/advisories/unreviewed/2024/03/GHSA-qp4c-f9fg-vrxf/GHSA-qp4c-f9fg-vrxf.json index d0b73f33795..2ff4d9bb5a7 100644 --- a/advisories/unreviewed/2024/03/GHSA-qp4c-f9fg-vrxf/GHSA-qp4c-f9fg-vrxf.json +++ b/advisories/unreviewed/2024/03/GHSA-qp4c-f9fg-vrxf/GHSA-qp4c-f9fg-vrxf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qp4c-f9fg-vrxf", - "modified": "2024-03-11T18:31:07Z", + "modified": "2024-11-26T15:30:59Z", "published": "2024-03-11T18:31:07Z", "aliases": [ "CVE-2024-0039" ], "details": "In attp_build_value_cmd of att_protocol.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-11T17:15:45Z" diff --git a/advisories/unreviewed/2024/08/GHSA-296c-8m99-q77p/GHSA-296c-8m99-q77p.json b/advisories/unreviewed/2024/08/GHSA-296c-8m99-q77p/GHSA-296c-8m99-q77p.json index 02366ac8966..0b859f23c11 100644 --- a/advisories/unreviewed/2024/08/GHSA-296c-8m99-q77p/GHSA-296c-8m99-q77p.json +++ b/advisories/unreviewed/2024/08/GHSA-296c-8m99-q77p/GHSA-296c-8m99-q77p.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-57cg-pmv4-v925/GHSA-57cg-pmv4-v925.json b/advisories/unreviewed/2024/08/GHSA-57cg-pmv4-v925/GHSA-57cg-pmv4-v925.json index 3752369aa74..bb967ffe166 100644 --- a/advisories/unreviewed/2024/08/GHSA-57cg-pmv4-v925/GHSA-57cg-pmv4-v925.json +++ b/advisories/unreviewed/2024/08/GHSA-57cg-pmv4-v925/GHSA-57cg-pmv4-v925.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-57cg-pmv4-v925", - "modified": "2024-08-12T15:30:51Z", + "modified": "2024-11-26T15:31:00Z", "published": "2024-08-12T15:30:51Z", "aliases": [ "CVE-2024-6640" ], "details": "In ICMPv6 Neighbor Discovery (ND), the ID is always 0. When pf is configured to allow ND and block incoming Echo Requests, a crafted Echo Request packet after a Neighbor Solicitation (NS) can trigger an Echo Reply. The packet has to come from the same host as the NS and have a zero as identifier to match the state created by the Neighbor Discovery and allow replies to be generated.\n\nICMPv6 packets with identifier value of zero bypass firewall rules written on the assumption that the incoming packets are going to create a state in the state table.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -21,13 +24,17 @@ { "type": "WEB", "url": "https://security.freebsd.org/advisories/FreeBSD-SA-24:05.pf.asc" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240816-0008" } ], "database_specific": { "cwe_ids": [ - + "CWE-276" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-12T13:38:39Z" diff --git a/advisories/unreviewed/2024/08/GHSA-6cvr-wmr3-636f/GHSA-6cvr-wmr3-636f.json b/advisories/unreviewed/2024/08/GHSA-6cvr-wmr3-636f/GHSA-6cvr-wmr3-636f.json index 42c31b493fc..0b064aa47e1 100644 --- a/advisories/unreviewed/2024/08/GHSA-6cvr-wmr3-636f/GHSA-6cvr-wmr3-636f.json +++ b/advisories/unreviewed/2024/08/GHSA-6cvr-wmr3-636f/GHSA-6cvr-wmr3-636f.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-126" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/08/GHSA-gf7m-c4p9-5gvh/GHSA-gf7m-c4p9-5gvh.json b/advisories/unreviewed/2024/08/GHSA-gf7m-c4p9-5gvh/GHSA-gf7m-c4p9-5gvh.json index 146dbfc2916..218b5f23e73 100644 --- a/advisories/unreviewed/2024/08/GHSA-gf7m-c4p9-5gvh/GHSA-gf7m-c4p9-5gvh.json +++ b/advisories/unreviewed/2024/08/GHSA-gf7m-c4p9-5gvh/GHSA-gf7m-c4p9-5gvh.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-126" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/11/GHSA-22pf-6rh7-89gj/GHSA-22pf-6rh7-89gj.json b/advisories/unreviewed/2024/11/GHSA-22pf-6rh7-89gj/GHSA-22pf-6rh7-89gj.json new file mode 100644 index 00000000000..7de1af58904 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-22pf-6rh7-89gj/GHSA-22pf-6rh7-89gj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-22pf-6rh7-89gj", + "modified": "2024-11-26T15:31:03Z", + "published": "2024-11-26T15:31:03Z", + "aliases": [ + "CVE-2024-9928" + ], + "details": "A vulnerability exists in NSD570 login panel that does not restrict excessive authentication attempts. If exploited, this could\ncause account takeover and unauthorized access to the system\nwhen an attacker conducts brute-force attacks against the\nequipment login. Note that the system supports only one concurrent session and implements a delay of more than a second\nbetween failed login attempts making it difficult to automate the\nattacks.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9928" + }, + { + "type": "WEB", + "url": "https://publisher.hitachienergy.com/preview?DocumentID=8DBD000173&LanguageCode=en&DocumentPartId=&Action=launch" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-307" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T14:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-3r9h-5xmh-8j4q/GHSA-3r9h-5xmh-8j4q.json b/advisories/unreviewed/2024/11/GHSA-3r9h-5xmh-8j4q/GHSA-3r9h-5xmh-8j4q.json new file mode 100644 index 00000000000..aab08d96f88 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-3r9h-5xmh-8j4q/GHSA-3r9h-5xmh-8j4q.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3r9h-5xmh-8j4q", + "modified": "2024-11-26T15:31:03Z", + "published": "2024-11-26T15:31:03Z", + "aliases": [ + "CVE-2024-11708" + ], + "details": "Missing thread synchronization primitives could have led to a data race on members of the PlaybackParams structure. This vulnerability affects Firefox < 133 and Thunderbird < 133.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11708" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1922912" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-63" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-67" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T14:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-49gp-6j88-r9j7/GHSA-49gp-6j88-r9j7.json b/advisories/unreviewed/2024/11/GHSA-49gp-6j88-r9j7/GHSA-49gp-6j88-r9j7.json new file mode 100644 index 00000000000..ac8598811e4 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-49gp-6j88-r9j7/GHSA-49gp-6j88-r9j7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-49gp-6j88-r9j7", + "modified": "2024-11-26T15:31:01Z", + "published": "2024-11-26T15:31:01Z", + "aliases": [ + "CVE-2017-18306" + ], + "details": "Information disclosure due to uninitialized variable.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2017-18306" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/may-2018-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T14:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-4c4w-pcg8-6hq9/GHSA-4c4w-pcg8-6hq9.json b/advisories/unreviewed/2024/11/GHSA-4c4w-pcg8-6hq9/GHSA-4c4w-pcg8-6hq9.json new file mode 100644 index 00000000000..8e06a745a00 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-4c4w-pcg8-6hq9/GHSA-4c4w-pcg8-6hq9.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4c4w-pcg8-6hq9", + "modified": "2024-11-26T15:31:03Z", + "published": "2024-11-26T15:31:03Z", + "aliases": [ + "CVE-2024-53976" + ], + "details": "Under certain circumstances, navigating to a webpage would result in the address missing from the location URL bar, making it unclear what the URL was for the loaded webpage. This vulnerability affects Firefox for iOS < 133.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53976" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1905749" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-66" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T14:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-4jp9-q9g7-48gr/GHSA-4jp9-q9g7-48gr.json b/advisories/unreviewed/2024/11/GHSA-4jp9-q9g7-48gr/GHSA-4jp9-q9g7-48gr.json new file mode 100644 index 00000000000..6a46bc8b379 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-4jp9-q9g7-48gr/GHSA-4jp9-q9g7-48gr.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4jp9-q9g7-48gr", + "modified": "2024-11-26T15:31:02Z", + "published": "2024-11-26T15:31:02Z", + "aliases": [ + "CVE-2024-11697" + ], + "details": "When handling keypress events, an attacker may have been able to trick a user into bypassing the \"Open Executable File?\" confirmation dialog. This could have led to malicious code execution. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11697" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1842187" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-63" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-64" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-67" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-68" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T14:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-4qc3-fmcj-w66w/GHSA-4qc3-fmcj-w66w.json b/advisories/unreviewed/2024/11/GHSA-4qc3-fmcj-w66w/GHSA-4qc3-fmcj-w66w.json index 34e979136e3..b6916984ae4 100644 --- a/advisories/unreviewed/2024/11/GHSA-4qc3-fmcj-w66w/GHSA-4qc3-fmcj-w66w.json +++ b/advisories/unreviewed/2024/11/GHSA-4qc3-fmcj-w66w/GHSA-4qc3-fmcj-w66w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4qc3-fmcj-w66w", - "modified": "2024-11-26T12:41:37Z", + "modified": "2024-11-26T15:31:01Z", "published": "2024-11-26T12:41:37Z", "aliases": [ "CVE-2024-47250" @@ -21,6 +21,10 @@ { "type": "WEB", "url": "https://lists.apache.org/thread/zdb50spojlqbn0yxd866mbzqjt2vpt85" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/11/26/4" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/11/GHSA-53mx-8hhc-gmp3/GHSA-53mx-8hhc-gmp3.json b/advisories/unreviewed/2024/11/GHSA-53mx-8hhc-gmp3/GHSA-53mx-8hhc-gmp3.json new file mode 100644 index 00000000000..290c177227f --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-53mx-8hhc-gmp3/GHSA-53mx-8hhc-gmp3.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-53mx-8hhc-gmp3", + "modified": "2024-11-26T15:31:01Z", + "published": "2024-11-26T15:31:01Z", + "aliases": [ + "CVE-2024-11691" + ], + "details": "An attacker could have caused memory corruption due to a flaw in Apple's GPU driver; this can be avoided by working around the flaw. \n*Note: This issue only affected macOS operating systems. Other operating systems are unaffected.* This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Firefox ESR < 115.18, Thunderbird < 133, and Thunderbird < 128.5.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11691" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1914707" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1924184" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-63" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-64" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-65" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-67" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-68" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T14:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-77rq-3336-8w4x/GHSA-77rq-3336-8w4x.json b/advisories/unreviewed/2024/11/GHSA-77rq-3336-8w4x/GHSA-77rq-3336-8w4x.json new file mode 100644 index 00000000000..b494ba11729 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-77rq-3336-8w4x/GHSA-77rq-3336-8w4x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-77rq-3336-8w4x", + "modified": "2024-11-26T15:31:01Z", + "published": "2024-11-26T15:31:01Z", + "aliases": [ + "CVE-2018-5852" + ], + "details": "An unsigned integer underflow vulnerability in IPA driver result into a buffer over-read while reading NAT entry using debugfs command 'cat /sys/kernel/debug/ipa/ip4_nat'", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-5852" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/may-2018-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-126" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T14:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-7gfr-xrcc-jm66/GHSA-7gfr-xrcc-jm66.json b/advisories/unreviewed/2024/11/GHSA-7gfr-xrcc-jm66/GHSA-7gfr-xrcc-jm66.json new file mode 100644 index 00000000000..a5fe8fd68b7 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-7gfr-xrcc-jm66/GHSA-7gfr-xrcc-jm66.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7gfr-xrcc-jm66", + "modified": "2024-11-26T15:31:01Z", + "published": "2024-11-26T15:31:01Z", + "aliases": [ + "CVE-2018-11816" + ], + "details": "Crafted Binder Request Causes Heap UAF in MediaServer", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-11816" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/may-2018-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T14:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-7mjq-fcrm-26pg/GHSA-7mjq-fcrm-26pg.json b/advisories/unreviewed/2024/11/GHSA-7mjq-fcrm-26pg/GHSA-7mjq-fcrm-26pg.json index 85703aeedff..eac3b33205b 100644 --- a/advisories/unreviewed/2024/11/GHSA-7mjq-fcrm-26pg/GHSA-7mjq-fcrm-26pg.json +++ b/advisories/unreviewed/2024/11/GHSA-7mjq-fcrm-26pg/GHSA-7mjq-fcrm-26pg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7mjq-fcrm-26pg", - "modified": "2024-11-26T12:41:37Z", + "modified": "2024-11-26T15:31:01Z", "published": "2024-11-26T12:41:37Z", "aliases": [ "CVE-2024-38831" @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-7r4q-q89f-2mcg/GHSA-7r4q-q89f-2mcg.json b/advisories/unreviewed/2024/11/GHSA-7r4q-q89f-2mcg/GHSA-7r4q-q89f-2mcg.json new file mode 100644 index 00000000000..56f5cac532d --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-7r4q-q89f-2mcg/GHSA-7r4q-q89f-2mcg.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7r4q-q89f-2mcg", + "modified": "2024-11-26T15:31:03Z", + "published": "2024-11-26T15:31:02Z", + "aliases": [ + "CVE-2024-11702" + ], + "details": "Copying sensitive information from Private Browsing tabs on Android, such as passwords, may have inadvertently stored data in the cloud-based clipboard history if enabled. This vulnerability affects Firefox < 133 and Thunderbird < 133.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11702" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1918884" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-63" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-67" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T14:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-845f-27fw-gjw9/GHSA-845f-27fw-gjw9.json b/advisories/unreviewed/2024/11/GHSA-845f-27fw-gjw9/GHSA-845f-27fw-gjw9.json new file mode 100644 index 00000000000..b8e730737ce --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-845f-27fw-gjw9/GHSA-845f-27fw-gjw9.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-845f-27fw-gjw9", + "modified": "2024-11-26T15:31:02Z", + "published": "2024-11-26T15:31:02Z", + "aliases": [ + "CVE-2024-11700" + ], + "details": "Malicious websites may have been able to user intent confirmation through tapjacking. This could have led to users unknowingly approving the launch of external applications, potentially exposing them to underlying vulnerabilities. This vulnerability affects Firefox < 133 and Thunderbird < 133.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11700" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1836921" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-63" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-67" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T14:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-8rq4-c5x2-x4g8/GHSA-8rq4-c5x2-x4g8.json b/advisories/unreviewed/2024/11/GHSA-8rq4-c5x2-x4g8/GHSA-8rq4-c5x2-x4g8.json new file mode 100644 index 00000000000..0a6432358fb --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-8rq4-c5x2-x4g8/GHSA-8rq4-c5x2-x4g8.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8rq4-c5x2-x4g8", + "modified": "2024-11-26T15:31:03Z", + "published": "2024-11-26T15:31:02Z", + "aliases": [ + "CVE-2024-11706" + ], + "details": "A null pointer dereference may have inadvertently occurred in `pk12util`, and specifically in the `SEC_ASN1DecodeItem_Util` function, when handling malformed or improperly formatted input files. This vulnerability affects Firefox < 133 and Thunderbird < 133.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11706" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1923767" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-63" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-67" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T14:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-8vxw-wxwq-hg38/GHSA-8vxw-wxwq-hg38.json b/advisories/unreviewed/2024/11/GHSA-8vxw-wxwq-hg38/GHSA-8vxw-wxwq-hg38.json new file mode 100644 index 00000000000..1f67152ff8a --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-8vxw-wxwq-hg38/GHSA-8vxw-wxwq-hg38.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8vxw-wxwq-hg38", + "modified": "2024-11-26T15:31:03Z", + "published": "2024-11-26T15:31:03Z", + "aliases": [ + "CVE-2024-36463" + ], + "details": "The implementation of atob in \"Zabbix JS\" allows to create a string with arbitrary content and use it to access internal properties of objects.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36463" + }, + { + "type": "WEB", + "url": "https://support.zabbix.com/browse/ZBX-25611" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-767" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T15:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-92xm-7m45-93pf/GHSA-92xm-7m45-93pf.json b/advisories/unreviewed/2024/11/GHSA-92xm-7m45-93pf/GHSA-92xm-7m45-93pf.json new file mode 100644 index 00000000000..e47ae255575 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-92xm-7m45-93pf/GHSA-92xm-7m45-93pf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-92xm-7m45-93pf", + "modified": "2024-11-26T15:31:01Z", + "published": "2024-11-26T15:31:01Z", + "aliases": [ + "CVE-2016-10408" + ], + "details": "QSEE will randomly experience a fatal error during execution due to speculative instruction fetches from device memory. Device memory is not valid executable memory.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2016-10408" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/may-2018-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T14:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-966f-2c6j-qj89/GHSA-966f-2c6j-qj89.json b/advisories/unreviewed/2024/11/GHSA-966f-2c6j-qj89/GHSA-966f-2c6j-qj89.json index 5c993ea3f07..b236ad15bf5 100644 --- a/advisories/unreviewed/2024/11/GHSA-966f-2c6j-qj89/GHSA-966f-2c6j-qj89.json +++ b/advisories/unreviewed/2024/11/GHSA-966f-2c6j-qj89/GHSA-966f-2c6j-qj89.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-966f-2c6j-qj89", - "modified": "2024-11-26T12:41:37Z", + "modified": "2024-11-26T15:31:01Z", "published": "2024-11-26T12:41:37Z", "aliases": [ "CVE-2024-51569" @@ -21,6 +21,10 @@ { "type": "WEB", "url": "https://lists.apache.org/thread/q0vs5rddx1lho30xnpsrvpzgxqmywnhs" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/11/26/5" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/11/GHSA-9g2q-259c-66mq/GHSA-9g2q-259c-66mq.json b/advisories/unreviewed/2024/11/GHSA-9g2q-259c-66mq/GHSA-9g2q-259c-66mq.json new file mode 100644 index 00000000000..1cb5dd77b9f --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-9g2q-259c-66mq/GHSA-9g2q-259c-66mq.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9g2q-259c-66mq", + "modified": "2024-11-26T15:31:02Z", + "published": "2024-11-26T15:31:02Z", + "aliases": [ + "CVE-2024-11699" + ], + "details": "Memory safety bugs present in Firefox 132, Firefox ESR 128.4, and Thunderbird 128.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11699" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/buglist.cgi?bug_id=1880582%2C1929911" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-63" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-64" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-67" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-68" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T14:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-cpgg-w28j-jvph/GHSA-cpgg-w28j-jvph.json b/advisories/unreviewed/2024/11/GHSA-cpgg-w28j-jvph/GHSA-cpgg-w28j-jvph.json index 90f910b9d34..3e57fd36aee 100644 --- a/advisories/unreviewed/2024/11/GHSA-cpgg-w28j-jvph/GHSA-cpgg-w28j-jvph.json +++ b/advisories/unreviewed/2024/11/GHSA-cpgg-w28j-jvph/GHSA-cpgg-w28j-jvph.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cpgg-w28j-jvph", - "modified": "2024-11-26T06:31:03Z", + "modified": "2024-11-26T15:31:01Z", "published": "2024-11-26T06:31:03Z", "aliases": [ "CVE-2024-10471" ], "details": "The Everest Forms WordPress plugin before 3.0.4.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-26T06:15:07Z" diff --git a/advisories/unreviewed/2024/11/GHSA-cpxj-fx45-9pgm/GHSA-cpxj-fx45-9pgm.json b/advisories/unreviewed/2024/11/GHSA-cpxj-fx45-9pgm/GHSA-cpxj-fx45-9pgm.json new file mode 100644 index 00000000000..705015a9b2b --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-cpxj-fx45-9pgm/GHSA-cpxj-fx45-9pgm.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cpxj-fx45-9pgm", + "modified": "2024-11-26T15:31:01Z", + "published": "2024-11-26T15:31:01Z", + "aliases": [ + "CVE-2024-11692" + ], + "details": "An attacker could cause a select dropdown to be shown over another tab; this could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11692" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1909535" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-63" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-64" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-67" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-68" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T14:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-cq6j-fwr2-x2rr/GHSA-cq6j-fwr2-x2rr.json b/advisories/unreviewed/2024/11/GHSA-cq6j-fwr2-x2rr/GHSA-cq6j-fwr2-x2rr.json new file mode 100644 index 00000000000..e3c9869da90 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-cq6j-fwr2-x2rr/GHSA-cq6j-fwr2-x2rr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cq6j-fwr2-x2rr", + "modified": "2024-11-26T15:31:03Z", + "published": "2024-11-26T15:31:03Z", + "aliases": [ + "CVE-2024-9929" + ], + "details": "A vulnerability exists in NSD570 that allows any authenticated\nuser to access all device logs disclosing login information with\ntimestamps.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9929" + }, + { + "type": "WEB", + "url": "https://publisher.hitachienergy.com/preview?DocumentID=8DBD000173&LanguageCode=en&DocumentPartId=&Action=launch" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-497" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T14:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-f94q-ffqr-x638/GHSA-f94q-ffqr-x638.json b/advisories/unreviewed/2024/11/GHSA-f94q-ffqr-x638/GHSA-f94q-ffqr-x638.json index bd1b77c43b5..f820da12d84 100644 --- a/advisories/unreviewed/2024/11/GHSA-f94q-ffqr-x638/GHSA-f94q-ffqr-x638.json +++ b/advisories/unreviewed/2024/11/GHSA-f94q-ffqr-x638/GHSA-f94q-ffqr-x638.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f94q-ffqr-x638", - "modified": "2024-11-26T12:41:37Z", + "modified": "2024-11-26T15:31:01Z", "published": "2024-11-26T12:41:37Z", "aliases": [ "CVE-2024-47248" @@ -21,6 +21,10 @@ { "type": "WEB", "url": "https://lists.apache.org/thread/z8m7jqh54xybf9kz8q2l3tz92zsj7tmz" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/11/26/2" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/11/GHSA-fvjw-6h28-3r9c/GHSA-fvjw-6h28-3r9c.json b/advisories/unreviewed/2024/11/GHSA-fvjw-6h28-3r9c/GHSA-fvjw-6h28-3r9c.json new file mode 100644 index 00000000000..b17a8012b88 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-fvjw-6h28-3r9c/GHSA-fvjw-6h28-3r9c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fvjw-6h28-3r9c", + "modified": "2024-11-26T15:31:01Z", + "published": "2024-11-26T15:31:01Z", + "aliases": [ + "CVE-2017-18307" + ], + "details": "Information disclosure possible while audio playback.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2017-18307" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/may-2018-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T14:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-fw6g-5qw9-p3mx/GHSA-fw6g-5qw9-p3mx.json b/advisories/unreviewed/2024/11/GHSA-fw6g-5qw9-p3mx/GHSA-fw6g-5qw9-p3mx.json index 92d44ef56c5..e97c1027fe8 100644 --- a/advisories/unreviewed/2024/11/GHSA-fw6g-5qw9-p3mx/GHSA-fw6g-5qw9-p3mx.json +++ b/advisories/unreviewed/2024/11/GHSA-fw6g-5qw9-p3mx/GHSA-fw6g-5qw9-p3mx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fw6g-5qw9-p3mx", - "modified": "2024-11-26T12:41:37Z", + "modified": "2024-11-26T15:31:01Z", "published": "2024-11-26T12:41:37Z", "aliases": [ "CVE-2024-47249" @@ -21,6 +21,10 @@ { "type": "WEB", "url": "https://lists.apache.org/thread/7ckxw6481dp68ons627pjcb27c75n0mq" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/11/26/3" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/11/GHSA-g5wv-cvf4-2r98/GHSA-g5wv-cvf4-2r98.json b/advisories/unreviewed/2024/11/GHSA-g5wv-cvf4-2r98/GHSA-g5wv-cvf4-2r98.json new file mode 100644 index 00000000000..762ac3c3082 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-g5wv-cvf4-2r98/GHSA-g5wv-cvf4-2r98.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g5wv-cvf4-2r98", + "modified": "2024-11-26T15:31:02Z", + "published": "2024-11-26T15:31:02Z", + "aliases": [ + "CVE-2024-11696" + ], + "details": "The application failed to account for exceptions thrown by the `loadManifestFromFile` method during add-on signature verification. This flaw, triggered by an invalid or unsupported extension manifest, could have caused runtime errors that disrupted the signature validation process. As a result, the enforcement of signature validation for unrelated add-ons may have been bypassed. Signature validation in this context is used to ensure that third-party applications on the user's computer have not tampered with the user's extensions, limiting the impact of this issue. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11696" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1929600" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-63" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-64" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-67" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-68" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T14:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-h43c-gg33-qj9g/GHSA-h43c-gg33-qj9g.json b/advisories/unreviewed/2024/11/GHSA-h43c-gg33-qj9g/GHSA-h43c-gg33-qj9g.json new file mode 100644 index 00000000000..ee7eecfc6d4 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-h43c-gg33-qj9g/GHSA-h43c-gg33-qj9g.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h43c-gg33-qj9g", + "modified": "2024-11-26T15:31:02Z", + "published": "2024-11-26T15:31:02Z", + "aliases": [ + "CVE-2024-11705" + ], + "details": "`NSC_DeriveKey` inadvertently assumed that the `phKey` parameter is always non-NULL. When it was passed as NULL, a segmentation fault (SEGV) occurred, leading to crashes. This behavior conflicted with the PKCS#11 v3.0 specification, which allows `phKey` to be NULL for certain mechanisms. This vulnerability affects Firefox < 133 and Thunderbird < 133.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11705" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1921768" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-63" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-67" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T14:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-h6c3-73mq-5cp9/GHSA-h6c3-73mq-5cp9.json b/advisories/unreviewed/2024/11/GHSA-h6c3-73mq-5cp9/GHSA-h6c3-73mq-5cp9.json new file mode 100644 index 00000000000..a6a104a4e51 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-h6c3-73mq-5cp9/GHSA-h6c3-73mq-5cp9.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h6c3-73mq-5cp9", + "modified": "2024-11-26T15:31:03Z", + "published": "2024-11-26T15:31:03Z", + "aliases": [ + "CVE-2024-8236" + ], + "details": "The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter of the Icon widget in all versions up to, and including, 3.25.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8236" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/elementor/tags/3.23.4/includes/widgets/icon.php#L489" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3192020" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/b1305be5-8267-475f-b962-62e3930116e1?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T14:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-h8gv-f7pf-7c4p/GHSA-h8gv-f7pf-7c4p.json b/advisories/unreviewed/2024/11/GHSA-h8gv-f7pf-7c4p/GHSA-h8gv-f7pf-7c4p.json new file mode 100644 index 00000000000..e98b3a1afb6 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-h8gv-f7pf-7c4p/GHSA-h8gv-f7pf-7c4p.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h8gv-f7pf-7c4p", + "modified": "2024-11-26T15:31:02Z", + "published": "2024-11-26T15:31:02Z", + "aliases": [ + "CVE-2024-11704" + ], + "details": "A double-free issue could have occurred in `sec_pkcs7_decoder_start_decrypt()` when handling an error path. Under specific conditions, the same symmetric key could have been freed twice, potentially leading to memory corruption. This vulnerability affects Firefox < 133 and Thunderbird < 133.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11704" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1899402" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-63" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-67" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T14:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-jxv2-pgjw-vg3v/GHSA-jxv2-pgjw-vg3v.json b/advisories/unreviewed/2024/11/GHSA-jxv2-pgjw-vg3v/GHSA-jxv2-pgjw-vg3v.json new file mode 100644 index 00000000000..4f215918471 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-jxv2-pgjw-vg3v/GHSA-jxv2-pgjw-vg3v.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jxv2-pgjw-vg3v", + "modified": "2024-11-26T15:31:03Z", + "published": "2024-11-26T15:31:03Z", + "aliases": [ + "CVE-2024-53975" + ], + "details": "Accessing a non-secure HTTP site that uses a non-existent port may cause the SSL padlock icon in the location URL bar to, misleadingly, appear secure. This vulnerability affects Firefox for iOS < 133.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53975" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1843467" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-66" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T14:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-m59j-fmqm-3q93/GHSA-m59j-fmqm-3q93.json b/advisories/unreviewed/2024/11/GHSA-m59j-fmqm-3q93/GHSA-m59j-fmqm-3q93.json new file mode 100644 index 00000000000..2c9071aa5a3 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-m59j-fmqm-3q93/GHSA-m59j-fmqm-3q93.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m59j-fmqm-3q93", + "modified": "2024-11-26T15:31:02Z", + "published": "2024-11-26T15:31:02Z", + "aliases": [ + "CVE-2024-11698" + ], + "details": "A flaw in handling fullscreen transitions may have inadvertently caused the application to become stuck in fullscreen mode when a modal dialog was opened during the transition. This issue left users unable to exit fullscreen mode using standard actions like pressing \"Esc\" or accessing right-click menus, resulting in a disrupted browsing experience until the browser is restarted. \n*This bug only affects the application when running on macOS. Other operating systems are unaffected.* This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11698" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1916152" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-63" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-64" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-67" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-68" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T14:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-mjcw-r3mg-3848/GHSA-mjcw-r3mg-3848.json b/advisories/unreviewed/2024/11/GHSA-mjcw-r3mg-3848/GHSA-mjcw-r3mg-3848.json new file mode 100644 index 00000000000..fc5482d4229 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-mjcw-r3mg-3848/GHSA-mjcw-r3mg-3848.json @@ -0,0 +1,55 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mjcw-r3mg-3848", + "modified": "2024-11-26T15:31:02Z", + "published": "2024-11-26T15:31:02Z", + "aliases": [ + "CVE-2024-11694" + ], + "details": "Enhanced Tracking Protection's Strict mode may have inadvertently allowed a CSP `frame-src` bypass and DOM-based XSS through the Google SafeFrame shim in the Web Compatibility extension. This issue could have exposed users to malicious frames masquerading as legitimate content. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Firefox ESR < 115.18, Thunderbird < 133, and Thunderbird < 128.5.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11694" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1924167" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-63" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-64" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-65" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-67" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-68" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T14:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-p9vw-xw86-3f2w/GHSA-p9vw-xw86-3f2w.json b/advisories/unreviewed/2024/11/GHSA-p9vw-xw86-3f2w/GHSA-p9vw-xw86-3f2w.json new file mode 100644 index 00000000000..bd46e45e61e --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-p9vw-xw86-3f2w/GHSA-p9vw-xw86-3f2w.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p9vw-xw86-3f2w", + "modified": "2024-11-26T15:31:02Z", + "published": "2024-11-26T15:31:02Z", + "aliases": [ + "CVE-2024-11701" + ], + "details": "The incorrect domain may have been displayed in the address bar during an interrupted navigation attempt. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 133 and Thunderbird < 133.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11701" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1914797" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-63" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-67" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T14:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-qpv5-9fm8-4hfv/GHSA-qpv5-9fm8-4hfv.json b/advisories/unreviewed/2024/11/GHSA-qpv5-9fm8-4hfv/GHSA-qpv5-9fm8-4hfv.json new file mode 100644 index 00000000000..9f84bd86a55 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-qpv5-9fm8-4hfv/GHSA-qpv5-9fm8-4hfv.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qpv5-9fm8-4hfv", + "modified": "2024-11-26T15:31:03Z", + "published": "2024-11-26T15:31:03Z", + "aliases": [ + "CVE-2024-9461" + ], + "details": "The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.16.6 via the cron_interval parameter. This is due to missing input validation and sanitization. This makes it possible for authenticated attackers, with Administrator-level access and above, to execute code on the server.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9461" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/boldgrid-backup/tags/1.16.5/admin/class-boldgrid-backup-admin-settings.php#L748" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/804b42a0-1cea-4f68-bd4a-d292a9f23fbe?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T14:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-qxf6-g9x3-8w74/GHSA-qxf6-g9x3-8w74.json b/advisories/unreviewed/2024/11/GHSA-qxf6-g9x3-8w74/GHSA-qxf6-g9x3-8w74.json new file mode 100644 index 00000000000..747e6827ce0 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-qxf6-g9x3-8w74/GHSA-qxf6-g9x3-8w74.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qxf6-g9x3-8w74", + "modified": "2024-11-26T15:31:01Z", + "published": "2024-11-26T15:31:01Z", + "aliases": [ + "CVE-2024-11693" + ], + "details": "The executable file warning was not presented when downloading .library-ms files. \n*Note: This issue only affected Windows operating systems. Other operating systems are unaffected.* This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11693" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1921458" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-63" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-64" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-67" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-68" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T14:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-rh22-rcv2-42x3/GHSA-rh22-rcv2-42x3.json b/advisories/unreviewed/2024/11/GHSA-rh22-rcv2-42x3/GHSA-rh22-rcv2-42x3.json new file mode 100644 index 00000000000..fef580bf64c --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-rh22-rcv2-42x3/GHSA-rh22-rcv2-42x3.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rh22-rcv2-42x3", + "modified": "2024-11-26T15:31:02Z", + "published": "2024-11-26T15:31:02Z", + "aliases": [ + "CVE-2024-11695" + ], + "details": "A crafted URL containing Arabic script and whitespace characters could have hidden the true origin of the page, resulting in a potential spoofing attack. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11695" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1925496" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-63" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-64" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-67" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-68" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T14:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-vmrp-q2j9-gmqr/GHSA-vmrp-q2j9-gmqr.json b/advisories/unreviewed/2024/11/GHSA-vmrp-q2j9-gmqr/GHSA-vmrp-q2j9-gmqr.json new file mode 100644 index 00000000000..ff0fcd3be52 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-vmrp-q2j9-gmqr/GHSA-vmrp-q2j9-gmqr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vmrp-q2j9-gmqr", + "modified": "2024-11-26T15:31:03Z", + "published": "2024-11-26T15:31:03Z", + "aliases": [ + "CVE-2024-22117" + ], + "details": "When a URL is added to the map element, it is recorded in the database with sequential IDs. Upon adding a new URL, the system retrieves the last sysmapelementurlid value and increments it by one. However, an issue arises when a user manually changes the sysmapelementurlid value by adding sysmapelementurlid + 1. This action prevents others from adding URLs to the map element.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22117" + }, + { + "type": "WEB", + "url": "https://support.zabbix.com/browse/ZBX-25610" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T15:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-wjq6-6xvc-xr82/GHSA-wjq6-6xvc-xr82.json b/advisories/unreviewed/2024/11/GHSA-wjq6-6xvc-xr82/GHSA-wjq6-6xvc-xr82.json new file mode 100644 index 00000000000..7cad1dc711a --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-wjq6-6xvc-xr82/GHSA-wjq6-6xvc-xr82.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wjq6-6xvc-xr82", + "modified": "2024-11-26T15:31:02Z", + "published": "2024-11-26T15:31:02Z", + "aliases": [ + "CVE-2024-11703" + ], + "details": "On Android, Firefox may have inadvertently allowed viewing saved passwords without the required device PIN authentication. This vulnerability affects Firefox < 133.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11703" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1928779" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-63" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T14:15:19Z" + } +} \ No newline at end of file