diff --git a/advisories/unreviewed/2022/03/GHSA-843j-8fp3-h6f6/GHSA-843j-8fp3-h6f6.json b/advisories/unreviewed/2022/03/GHSA-843j-8fp3-h6f6/GHSA-843j-8fp3-h6f6.json index f82dfcb04f5..bedd390b97b 100644 --- a/advisories/unreviewed/2022/03/GHSA-843j-8fp3-h6f6/GHSA-843j-8fp3-h6f6.json +++ b/advisories/unreviewed/2022/03/GHSA-843j-8fp3-h6f6/GHSA-843j-8fp3-h6f6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-843j-8fp3-h6f6", - "modified": "2023-02-12T00:30:24Z", + "modified": "2024-09-16T18:31:17Z", "published": "2022-03-19T00:00:59Z", "aliases": [ "CVE-2021-23150" diff --git a/advisories/unreviewed/2022/04/GHSA-x568-473g-qj6x/GHSA-x568-473g-qj6x.json b/advisories/unreviewed/2022/04/GHSA-x568-473g-qj6x/GHSA-x568-473g-qj6x.json index 9c06553daac..174a14947b4 100644 --- a/advisories/unreviewed/2022/04/GHSA-x568-473g-qj6x/GHSA-x568-473g-qj6x.json +++ b/advisories/unreviewed/2022/04/GHSA-x568-473g-qj6x/GHSA-x568-473g-qj6x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x568-473g-qj6x", - "modified": "2022-05-07T00:01:00Z", + "modified": "2024-09-16T18:31:17Z", "published": "2022-04-28T00:00:29Z", "aliases": [ "CVE-2022-22521" diff --git a/advisories/unreviewed/2022/05/GHSA-5m5r-69xr-2fx8/GHSA-5m5r-69xr-2fx8.json b/advisories/unreviewed/2022/05/GHSA-5m5r-69xr-2fx8/GHSA-5m5r-69xr-2fx8.json index 5a90198b5cd..1a206442727 100644 --- a/advisories/unreviewed/2022/05/GHSA-5m5r-69xr-2fx8/GHSA-5m5r-69xr-2fx8.json +++ b/advisories/unreviewed/2022/05/GHSA-5m5r-69xr-2fx8/GHSA-5m5r-69xr-2fx8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5m5r-69xr-2fx8", - "modified": "2022-05-02T03:51:53Z", + "modified": "2024-09-16T18:31:17Z", "published": "2022-05-02T03:51:53Z", "aliases": [ "CVE-2009-4117" @@ -18,6 +18,18 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2009-4117" }, + { + "type": "WEB", + "url": "https://bugs.ghostscript.com/show_bug.cgi?id=708030" + }, + { + "type": "WEB", + "url": "https://cgit.ghostscript.com/cgi-bin/cgit.cgi/mupdf.git/commit/?id=a21cc1548993c392e474817bb3d656eb3730d88f" + }, + { + "type": "WEB", + "url": "https://cgit.ghostscript.com/cgi-bin/cgit.cgi/mupdf.git/commit/?id=cf6860c3d70a2f7a63cdb621cc3b58c891915deb" + }, { "type": "WEB", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/54441" diff --git a/advisories/unreviewed/2022/05/GHSA-6ggq-gv3v-v28c/GHSA-6ggq-gv3v-v28c.json b/advisories/unreviewed/2022/05/GHSA-6ggq-gv3v-v28c/GHSA-6ggq-gv3v-v28c.json index a811f58c177..f9ff9d443b0 100644 --- a/advisories/unreviewed/2022/05/GHSA-6ggq-gv3v-v28c/GHSA-6ggq-gv3v-v28c.json +++ b/advisories/unreviewed/2022/05/GHSA-6ggq-gv3v-v28c/GHSA-6ggq-gv3v-v28c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6ggq-gv3v-v28c", - "modified": "2023-03-17T06:30:34Z", + "modified": "2024-09-16T18:31:17Z", "published": "2022-05-24T22:28:18Z", "aliases": [ "CVE-2020-5367" diff --git a/advisories/unreviewed/2022/05/GHSA-9v5c-3867-7h2w/GHSA-9v5c-3867-7h2w.json b/advisories/unreviewed/2022/05/GHSA-9v5c-3867-7h2w/GHSA-9v5c-3867-7h2w.json index 0689a39ef7a..6caecc0b1de 100644 --- a/advisories/unreviewed/2022/05/GHSA-9v5c-3867-7h2w/GHSA-9v5c-3867-7h2w.json +++ b/advisories/unreviewed/2022/05/GHSA-9v5c-3867-7h2w/GHSA-9v5c-3867-7h2w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9v5c-3867-7h2w", - "modified": "2024-09-12T18:31:38Z", + "modified": "2024-09-16T18:31:17Z", "published": "2022-05-14T01:00:37Z", "aliases": [ "CVE-2018-19881" @@ -25,10 +25,18 @@ "type": "WEB", "url": "https://bugs.ghostscript.com/show_bug.cgi?id=700342" }, + { + "type": "WEB", + "url": "https://bugs.ghostscript.com/show_bug.cgi?id=700442" + }, { "type": "WEB", "url": "https://cgit.ghostscript.com/cgi-bin/cgit.cgi/mupdf.git/commit/?id=a7f7d91cdff8d303c11d458fa8b802776f73c8cc" }, + { + "type": "WEB", + "url": "https://cgit.ghostscript.com/cgi-bin/cgit.cgi/mupdf.git/commit/?id=c8f7e48ff74720a5e984ae19d978a5ab4d5dde5b" + }, { "type": "WEB", "url": "https://github.com/TeamSeri0us/pocs/tree/master/mupdf/20181203" diff --git a/advisories/unreviewed/2022/05/GHSA-wg6r-fv2h-h7xm/GHSA-wg6r-fv2h-h7xm.json b/advisories/unreviewed/2022/05/GHSA-wg6r-fv2h-h7xm/GHSA-wg6r-fv2h-h7xm.json index 533362bd31e..af0cbdad0b6 100644 --- a/advisories/unreviewed/2022/05/GHSA-wg6r-fv2h-h7xm/GHSA-wg6r-fv2h-h7xm.json +++ b/advisories/unreviewed/2022/05/GHSA-wg6r-fv2h-h7xm/GHSA-wg6r-fv2h-h7xm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wg6r-fv2h-h7xm", - "modified": "2022-05-24T19:03:03Z", + "modified": "2024-09-16T18:31:17Z", "published": "2022-05-24T19:03:03Z", "aliases": [ "CVE-2021-3485" diff --git a/advisories/unreviewed/2022/11/GHSA-c83p-m9mw-q96q/GHSA-c83p-m9mw-q96q.json b/advisories/unreviewed/2022/11/GHSA-c83p-m9mw-q96q/GHSA-c83p-m9mw-q96q.json index c1d89da26f0..ee85135fa5a 100644 --- a/advisories/unreviewed/2022/11/GHSA-c83p-m9mw-q96q/GHSA-c83p-m9mw-q96q.json +++ b/advisories/unreviewed/2022/11/GHSA-c83p-m9mw-q96q/GHSA-c83p-m9mw-q96q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c83p-m9mw-q96q", - "modified": "2022-12-02T00:30:25Z", + "modified": "2024-09-16T18:31:17Z", "published": "2022-11-28T18:30:17Z", "aliases": [ "CVE-2021-45036" diff --git a/advisories/unreviewed/2023/01/GHSA-v7hq-gmm8-4vwh/GHSA-v7hq-gmm8-4vwh.json b/advisories/unreviewed/2023/01/GHSA-v7hq-gmm8-4vwh/GHSA-v7hq-gmm8-4vwh.json index 3ec19151c93..40da50482bb 100644 --- a/advisories/unreviewed/2023/01/GHSA-v7hq-gmm8-4vwh/GHSA-v7hq-gmm8-4vwh.json +++ b/advisories/unreviewed/2023/01/GHSA-v7hq-gmm8-4vwh/GHSA-v7hq-gmm8-4vwh.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-306" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/04/GHSA-3x7j-9p25-v8r6/GHSA-3x7j-9p25-v8r6.json b/advisories/unreviewed/2023/04/GHSA-3x7j-9p25-v8r6/GHSA-3x7j-9p25-v8r6.json index b2c447de033..03a12de74d8 100644 --- a/advisories/unreviewed/2023/04/GHSA-3x7j-9p25-v8r6/GHSA-3x7j-9p25-v8r6.json +++ b/advisories/unreviewed/2023/04/GHSA-3x7j-9p25-v8r6/GHSA-3x7j-9p25-v8r6.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/04/GHSA-4297-gpxg-66rx/GHSA-4297-gpxg-66rx.json b/advisories/unreviewed/2023/04/GHSA-4297-gpxg-66rx/GHSA-4297-gpxg-66rx.json index 9fdacb0e662..36326f7a4a2 100644 --- a/advisories/unreviewed/2023/04/GHSA-4297-gpxg-66rx/GHSA-4297-gpxg-66rx.json +++ b/advisories/unreviewed/2023/04/GHSA-4297-gpxg-66rx/GHSA-4297-gpxg-66rx.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/04/GHSA-59pc-fqhf-v493/GHSA-59pc-fqhf-v493.json b/advisories/unreviewed/2023/04/GHSA-59pc-fqhf-v493/GHSA-59pc-fqhf-v493.json index 5a3a3ce07ac..87f108ca87c 100644 --- a/advisories/unreviewed/2023/04/GHSA-59pc-fqhf-v493/GHSA-59pc-fqhf-v493.json +++ b/advisories/unreviewed/2023/04/GHSA-59pc-fqhf-v493/GHSA-59pc-fqhf-v493.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-306" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/04/GHSA-c492-fr35-c3wf/GHSA-c492-fr35-c3wf.json b/advisories/unreviewed/2023/04/GHSA-c492-fr35-c3wf/GHSA-c492-fr35-c3wf.json index 5b91d18d28f..b286f988b7c 100644 --- a/advisories/unreviewed/2023/04/GHSA-c492-fr35-c3wf/GHSA-c492-fr35-c3wf.json +++ b/advisories/unreviewed/2023/04/GHSA-c492-fr35-c3wf/GHSA-c492-fr35-c3wf.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-400" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/04/GHSA-fw34-gjff-gr9g/GHSA-fw34-gjff-gr9g.json b/advisories/unreviewed/2023/04/GHSA-fw34-gjff-gr9g/GHSA-fw34-gjff-gr9g.json index 0bac38926bb..879f8718642 100644 --- a/advisories/unreviewed/2023/04/GHSA-fw34-gjff-gr9g/GHSA-fw34-gjff-gr9g.json +++ b/advisories/unreviewed/2023/04/GHSA-fw34-gjff-gr9g/GHSA-fw34-gjff-gr9g.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-400" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/04/GHSA-gq4c-x6cg-qppv/GHSA-gq4c-x6cg-qppv.json b/advisories/unreviewed/2023/04/GHSA-gq4c-x6cg-qppv/GHSA-gq4c-x6cg-qppv.json index 52c7867c527..169769e7b9a 100644 --- a/advisories/unreviewed/2023/04/GHSA-gq4c-x6cg-qppv/GHSA-gq4c-x6cg-qppv.json +++ b/advisories/unreviewed/2023/04/GHSA-gq4c-x6cg-qppv/GHSA-gq4c-x6cg-qppv.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/04/GHSA-grrp-hf9w-3vjm/GHSA-grrp-hf9w-3vjm.json b/advisories/unreviewed/2023/04/GHSA-grrp-hf9w-3vjm/GHSA-grrp-hf9w-3vjm.json index 8b762e4253a..a5e79bc9c9e 100644 --- a/advisories/unreviewed/2023/04/GHSA-grrp-hf9w-3vjm/GHSA-grrp-hf9w-3vjm.json +++ b/advisories/unreviewed/2023/04/GHSA-grrp-hf9w-3vjm/GHSA-grrp-hf9w-3vjm.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/04/GHSA-m9rj-w763-3x3j/GHSA-m9rj-w763-3x3j.json b/advisories/unreviewed/2023/04/GHSA-m9rj-w763-3x3j/GHSA-m9rj-w763-3x3j.json index 9898ed0c18b..cd000601747 100644 --- a/advisories/unreviewed/2023/04/GHSA-m9rj-w763-3x3j/GHSA-m9rj-w763-3x3j.json +++ b/advisories/unreviewed/2023/04/GHSA-m9rj-w763-3x3j/GHSA-m9rj-w763-3x3j.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-w25v-58xw-9xcx/GHSA-w25v-58xw-9xcx.json b/advisories/unreviewed/2023/10/GHSA-w25v-58xw-9xcx/GHSA-w25v-58xw-9xcx.json index 7559a34d691..4539f54dd37 100644 --- a/advisories/unreviewed/2023/10/GHSA-w25v-58xw-9xcx/GHSA-w25v-58xw-9xcx.json +++ b/advisories/unreviewed/2023/10/GHSA-w25v-58xw-9xcx/GHSA-w25v-58xw-9xcx.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-34" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/11/GHSA-2c2j-2pgv-gfgc/GHSA-2c2j-2pgv-gfgc.json b/advisories/unreviewed/2023/11/GHSA-2c2j-2pgv-gfgc/GHSA-2c2j-2pgv-gfgc.json index 72f9ed8c931..9857451379f 100644 --- a/advisories/unreviewed/2023/11/GHSA-2c2j-2pgv-gfgc/GHSA-2c2j-2pgv-gfgc.json +++ b/advisories/unreviewed/2023/11/GHSA-2c2j-2pgv-gfgc/GHSA-2c2j-2pgv-gfgc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2c2j-2pgv-gfgc", - "modified": "2023-11-06T18:30:19Z", + "modified": "2024-09-16T18:31:18Z", "published": "2023-11-06T18:30:19Z", "aliases": [ "CVE-2023-40661" diff --git a/advisories/unreviewed/2023/11/GHSA-7635-x5f9-5458/GHSA-7635-x5f9-5458.json b/advisories/unreviewed/2023/11/GHSA-7635-x5f9-5458/GHSA-7635-x5f9-5458.json index 916da258049..3d5fa83ad96 100644 --- a/advisories/unreviewed/2023/11/GHSA-7635-x5f9-5458/GHSA-7635-x5f9-5458.json +++ b/advisories/unreviewed/2023/11/GHSA-7635-x5f9-5458/GHSA-7635-x5f9-5458.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7635-x5f9-5458", - "modified": "2023-11-06T18:30:19Z", + "modified": "2024-09-16T18:31:18Z", "published": "2023-11-06T18:30:19Z", "aliases": [ "CVE-2023-40660" diff --git a/advisories/unreviewed/2023/12/GHSA-9vh7-c87x-8q9v/GHSA-9vh7-c87x-8q9v.json b/advisories/unreviewed/2023/12/GHSA-9vh7-c87x-8q9v/GHSA-9vh7-c87x-8q9v.json index bea6d480d8b..3d326e6a451 100644 --- a/advisories/unreviewed/2023/12/GHSA-9vh7-c87x-8q9v/GHSA-9vh7-c87x-8q9v.json +++ b/advisories/unreviewed/2023/12/GHSA-9vh7-c87x-8q9v/GHSA-9vh7-c87x-8q9v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9vh7-c87x-8q9v", - "modified": "2023-12-11T21:30:21Z", + "modified": "2024-09-16T18:31:18Z", "published": "2023-12-11T21:30:21Z", "aliases": [ "CVE-2023-6679" diff --git a/advisories/unreviewed/2023/12/GHSA-gg57-587f-h5v6/GHSA-gg57-587f-h5v6.json b/advisories/unreviewed/2023/12/GHSA-gg57-587f-h5v6/GHSA-gg57-587f-h5v6.json index 1254647f716..0e4a0ebd61e 100644 --- a/advisories/unreviewed/2023/12/GHSA-gg57-587f-h5v6/GHSA-gg57-587f-h5v6.json +++ b/advisories/unreviewed/2023/12/GHSA-gg57-587f-h5v6/GHSA-gg57-587f-h5v6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gg57-587f-h5v6", - "modified": "2023-12-28T18:30:32Z", + "modified": "2024-09-16T18:31:18Z", "published": "2023-12-28T18:30:32Z", "aliases": [ "CVE-2023-5384" diff --git a/advisories/unreviewed/2024/01/GHSA-45hh-rj6v-548f/GHSA-45hh-rj6v-548f.json b/advisories/unreviewed/2024/01/GHSA-45hh-rj6v-548f/GHSA-45hh-rj6v-548f.json index 6346b947f99..797e542cdd4 100644 --- a/advisories/unreviewed/2024/01/GHSA-45hh-rj6v-548f/GHSA-45hh-rj6v-548f.json +++ b/advisories/unreviewed/2024/01/GHSA-45hh-rj6v-548f/GHSA-45hh-rj6v-548f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-45hh-rj6v-548f", - "modified": "2024-02-20T21:30:20Z", + "modified": "2024-09-16T18:31:19Z", "published": "2024-01-10T15:30:19Z", "aliases": [ "CVE-2023-5455" diff --git a/advisories/unreviewed/2024/08/GHSA-rj56-mm47-cqp3/GHSA-rj56-mm47-cqp3.json b/advisories/unreviewed/2024/08/GHSA-rj56-mm47-cqp3/GHSA-rj56-mm47-cqp3.json index 73d5bd79014..00250ebe216 100644 --- a/advisories/unreviewed/2024/08/GHSA-rj56-mm47-cqp3/GHSA-rj56-mm47-cqp3.json +++ b/advisories/unreviewed/2024/08/GHSA-rj56-mm47-cqp3/GHSA-rj56-mm47-cqp3.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-434", "CWE-89" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2024/09/GHSA-34h3-77mg-mfgh/GHSA-34h3-77mg-mfgh.json b/advisories/unreviewed/2024/09/GHSA-34h3-77mg-mfgh/GHSA-34h3-77mg-mfgh.json new file mode 100644 index 00000000000..de9d7d279f9 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-34h3-77mg-mfgh/GHSA-34h3-77mg-mfgh.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-34h3-77mg-mfgh", + "modified": "2024-09-16T18:31:21Z", + "published": "2024-09-16T18:31:21Z", + "aliases": [ + "CVE-2024-21871" + ], + "details": "Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21871" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01071.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-16T17:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-3frm-3q2w-pp83/GHSA-3frm-3q2w-pp83.json b/advisories/unreviewed/2024/09/GHSA-3frm-3q2w-pp83/GHSA-3frm-3q2w-pp83.json new file mode 100644 index 00000000000..5dacf6a57d8 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-3frm-3q2w-pp83/GHSA-3frm-3q2w-pp83.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3frm-3q2w-pp83", + "modified": "2024-09-16T18:31:21Z", + "published": "2024-09-16T18:31:21Z", + "aliases": [ + "CVE-2023-25546" + ], + "details": "Out-of-bounds read in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable denial of service via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25546" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01071.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-16T17:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-3x4g-4374-v83h/GHSA-3x4g-4374-v83h.json b/advisories/unreviewed/2024/09/GHSA-3x4g-4374-v83h/GHSA-3x4g-4374-v83h.json index 0154d9d07b5..e7a8929b7fe 100644 --- a/advisories/unreviewed/2024/09/GHSA-3x4g-4374-v83h/GHSA-3x4g-4374-v83h.json +++ b/advisories/unreviewed/2024/09/GHSA-3x4g-4374-v83h/GHSA-3x4g-4374-v83h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3x4g-4374-v83h", - "modified": "2024-09-13T21:31:22Z", + "modified": "2024-09-16T18:31:21Z", "published": "2024-09-13T21:31:22Z", "aliases": [ "CVE-2024-44096" ], "details": "there is a possible arbitrary read due to an insecure default value. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-453" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-13T21:15:10Z" diff --git a/advisories/unreviewed/2024/09/GHSA-5wmr-r266-pc3m/GHSA-5wmr-r266-pc3m.json b/advisories/unreviewed/2024/09/GHSA-5wmr-r266-pc3m/GHSA-5wmr-r266-pc3m.json new file mode 100644 index 00000000000..dff43188028 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-5wmr-r266-pc3m/GHSA-5wmr-r266-pc3m.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5wmr-r266-pc3m", + "modified": "2024-09-16T18:31:21Z", + "published": "2024-09-16T18:31:21Z", + "aliases": [ + "CVE-2023-43753" + ], + "details": "Improper conditions check in some Intel(R) Processors with Intel(R) SGX may allow a privileged user to potentially enable information disclosure via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-43753" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01071.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-16T17:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-6qq3-v7mp-wx7q/GHSA-6qq3-v7mp-wx7q.json b/advisories/unreviewed/2024/09/GHSA-6qq3-v7mp-wx7q/GHSA-6qq3-v7mp-wx7q.json index fc2a7d16e4f..00befcc6ae1 100644 --- a/advisories/unreviewed/2024/09/GHSA-6qq3-v7mp-wx7q/GHSA-6qq3-v7mp-wx7q.json +++ b/advisories/unreviewed/2024/09/GHSA-6qq3-v7mp-wx7q/GHSA-6qq3-v7mp-wx7q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6qq3-v7mp-wx7q", - "modified": "2024-09-13T21:31:22Z", + "modified": "2024-09-16T18:31:21Z", "published": "2024-09-13T21:31:22Z", "aliases": [ "CVE-2024-44095" ], "details": "In ppmp_protect_mfcfw_buf of code/drm_fw.c, there is a possible corrupt memory due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-783" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-13T21:15:10Z" diff --git a/advisories/unreviewed/2024/09/GHSA-77rm-8jvr-hfgm/GHSA-77rm-8jvr-hfgm.json b/advisories/unreviewed/2024/09/GHSA-77rm-8jvr-hfgm/GHSA-77rm-8jvr-hfgm.json new file mode 100644 index 00000000000..9acd87e3cd8 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-77rm-8jvr-hfgm/GHSA-77rm-8jvr-hfgm.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-77rm-8jvr-hfgm", + "modified": "2024-09-16T18:31:21Z", + "published": "2024-09-16T18:31:21Z", + "aliases": [ + "CVE-2023-41833" + ], + "details": "A race condition in UEFI firmware for some Intel(R) processors may allow a privileged user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-41833" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01071.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-362" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-16T17:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-7c78-g5wc-hcch/GHSA-7c78-g5wc-hcch.json b/advisories/unreviewed/2024/09/GHSA-7c78-g5wc-hcch/GHSA-7c78-g5wc-hcch.json new file mode 100644 index 00000000000..77621217151 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-7c78-g5wc-hcch/GHSA-7c78-g5wc-hcch.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7c78-g5wc-hcch", + "modified": "2024-09-16T18:31:21Z", + "published": "2024-09-16T18:31:21Z", + "aliases": [ + "CVE-2024-8752" + ], + "details": "The Windows version of WebIQ 2.15.9 is affected by a directory traversal vulnerability that allows remote attackers to read any file on the system.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8752" + }, + { + "type": "WEB", + "url": "https://www.tenable.com/security/research/tra-2024-38" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-16T16:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-7whw-68xg-fr5c/GHSA-7whw-68xg-fr5c.json b/advisories/unreviewed/2024/09/GHSA-7whw-68xg-fr5c/GHSA-7whw-68xg-fr5c.json new file mode 100644 index 00000000000..590382dbc8c --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-7whw-68xg-fr5c/GHSA-7whw-68xg-fr5c.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7whw-68xg-fr5c", + "modified": "2024-09-16T18:31:21Z", + "published": "2024-09-16T18:31:21Z", + "aliases": [ + "CVE-2024-44623" + ], + "details": "An issue in TuomoKu SPx-GC v.1.3.0 and before allows a remote attacker to execute arbitrary code via the child_process.js function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44623" + }, + { + "type": "WEB", + "url": "https://github.com/TuomoKu/SPX-GC" + }, + { + "type": "WEB", + "url": "https://github.com/TuomoKu/SPX-GC/blob/v.1.3.0/routes/routes-api.js#L39" + }, + { + "type": "WEB", + "url": "https://github.com/merbinr/CVE-2024-44623" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-16T16:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-899w-w5qq-hg5v/GHSA-899w-w5qq-hg5v.json b/advisories/unreviewed/2024/09/GHSA-899w-w5qq-hg5v/GHSA-899w-w5qq-hg5v.json new file mode 100644 index 00000000000..707b11684fd --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-899w-w5qq-hg5v/GHSA-899w-w5qq-hg5v.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-899w-w5qq-hg5v", + "modified": "2024-09-16T18:31:21Z", + "published": "2024-09-16T18:31:21Z", + "aliases": [ + "CVE-2023-42772" + ], + "details": "Untrusted pointer dereference in UEFI firmware for some Intel(R) reference processors may allow a privileged user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-42772" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01071.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-822" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-16T17:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-8q6q-j6wg-846f/GHSA-8q6q-j6wg-846f.json b/advisories/unreviewed/2024/09/GHSA-8q6q-j6wg-846f/GHSA-8q6q-j6wg-846f.json new file mode 100644 index 00000000000..cf3db5adc51 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-8q6q-j6wg-846f/GHSA-8q6q-j6wg-846f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8q6q-j6wg-846f", + "modified": "2024-09-16T18:31:22Z", + "published": "2024-09-16T18:31:22Z", + "aliases": [ + "CVE-2024-34545" + ], + "details": "Improper input validation in some Intel(R) RAID Web Console software all versions may allow an authenticated user to potentially enable information disclosure via adjacent access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34545" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00926.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-16T17:16:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-9g66-w5hj-vhx4/GHSA-9g66-w5hj-vhx4.json b/advisories/unreviewed/2024/09/GHSA-9g66-w5hj-vhx4/GHSA-9g66-w5hj-vhx4.json index 335f63fe7d7..43a684d912c 100644 --- a/advisories/unreviewed/2024/09/GHSA-9g66-w5hj-vhx4/GHSA-9g66-w5hj-vhx4.json +++ b/advisories/unreviewed/2024/09/GHSA-9g66-w5hj-vhx4/GHSA-9g66-w5hj-vhx4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9g66-w5hj-vhx4", - "modified": "2024-09-13T21:31:22Z", + "modified": "2024-09-16T18:31:20Z", "published": "2024-09-13T21:31:22Z", "aliases": [ "CVE-2024-44092" ], "details": "In TBD of TBD, there is a possible LCS signing enforcement missing due to test/debugging code left in a production build. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-489" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-13T21:15:10Z" diff --git a/advisories/unreviewed/2024/09/GHSA-9v23-3rf5-vx8j/GHSA-9v23-3rf5-vx8j.json b/advisories/unreviewed/2024/09/GHSA-9v23-3rf5-vx8j/GHSA-9v23-3rf5-vx8j.json new file mode 100644 index 00000000000..ee37bf073af --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-9v23-3rf5-vx8j/GHSA-9v23-3rf5-vx8j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9v23-3rf5-vx8j", + "modified": "2024-09-16T18:31:22Z", + "published": "2024-09-16T18:31:22Z", + "aliases": [ + "CVE-2024-34543" + ], + "details": "Improper access control in Intel(R) RAID Web Console software for all versions may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34543" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00926.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-16T17:16:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-c7c7-8frm-jcmp/GHSA-c7c7-8frm-jcmp.json b/advisories/unreviewed/2024/09/GHSA-c7c7-8frm-jcmp/GHSA-c7c7-8frm-jcmp.json new file mode 100644 index 00000000000..57659c7dbef --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-c7c7-8frm-jcmp/GHSA-c7c7-8frm-jcmp.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c7c7-8frm-jcmp", + "modified": "2024-09-16T18:31:21Z", + "published": "2024-09-16T18:31:21Z", + "aliases": [ + "CVE-2023-23904" + ], + "details": "NULL pointer dereference in the UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23904" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01071.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-395" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-16T17:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-gjx4-p4f2-33wq/GHSA-gjx4-p4f2-33wq.json b/advisories/unreviewed/2024/09/GHSA-gjx4-p4f2-33wq/GHSA-gjx4-p4f2-33wq.json new file mode 100644 index 00000000000..c7d681f76ea --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-gjx4-p4f2-33wq/GHSA-gjx4-p4f2-33wq.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gjx4-p4f2-33wq", + "modified": "2024-09-16T18:31:21Z", + "published": "2024-09-16T18:31:21Z", + "aliases": [ + "CVE-2023-22351" + ], + "details": "Out-of-bounds write in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22351" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01071.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-16T17:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-gpvf-6hpf-4f9h/GHSA-gpvf-6hpf-4f9h.json b/advisories/unreviewed/2024/09/GHSA-gpvf-6hpf-4f9h/GHSA-gpvf-6hpf-4f9h.json index 1416aa4ee28..dcc5c36b786 100644 --- a/advisories/unreviewed/2024/09/GHSA-gpvf-6hpf-4f9h/GHSA-gpvf-6hpf-4f9h.json +++ b/advisories/unreviewed/2024/09/GHSA-gpvf-6hpf-4f9h/GHSA-gpvf-6hpf-4f9h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gpvf-6hpf-4f9h", - "modified": "2024-09-02T21:30:30Z", + "modified": "2024-09-16T18:31:20Z", "published": "2024-09-02T21:30:30Z", "aliases": [ "CVE-2024-45621" ], "details": "The Electron desktop application of Rocket.Chat through 6.3.4 allows stored XSS via links in an uploaded file, related to failure to use a separate browser upon encountering third-party external actions from PDF documents.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-02T19:15:13Z" diff --git a/advisories/unreviewed/2024/09/GHSA-gw2j-g839-3547/GHSA-gw2j-g839-3547.json b/advisories/unreviewed/2024/09/GHSA-gw2j-g839-3547/GHSA-gw2j-g839-3547.json new file mode 100644 index 00000000000..c2be99b3a23 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-gw2j-g839-3547/GHSA-gw2j-g839-3547.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gw2j-g839-3547", + "modified": "2024-09-16T18:31:22Z", + "published": "2024-09-16T18:31:22Z", + "aliases": [ + "CVE-2024-34153" + ], + "details": "Uncontrolled search path element in Intel(R) RAID Web Console software for all versions may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34153" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00926.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-16T17:16:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-h2w5-3v43-j5c8/GHSA-h2w5-3v43-j5c8.json b/advisories/unreviewed/2024/09/GHSA-h2w5-3v43-j5c8/GHSA-h2w5-3v43-j5c8.json new file mode 100644 index 00000000000..0c911717dd2 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-h2w5-3v43-j5c8/GHSA-h2w5-3v43-j5c8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h2w5-3v43-j5c8", + "modified": "2024-09-16T18:31:21Z", + "published": "2024-09-16T18:31:21Z", + "aliases": [ + "CVE-2024-28170" + ], + "details": "Improper access control in Intel(R) RAID Web Console all versions may allow an authenticated user to potentially enable information disclosure via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28170" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00926.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-16T17:16:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-j7q4-4r7g-3jf4/GHSA-j7q4-4r7g-3jf4.json b/advisories/unreviewed/2024/09/GHSA-j7q4-4r7g-3jf4/GHSA-j7q4-4r7g-3jf4.json index 2dc953e4f73..8343fa61d7b 100644 --- a/advisories/unreviewed/2024/09/GHSA-j7q4-4r7g-3jf4/GHSA-j7q4-4r7g-3jf4.json +++ b/advisories/unreviewed/2024/09/GHSA-j7q4-4r7g-3jf4/GHSA-j7q4-4r7g-3jf4.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j7q4-4r7g-3jf4", - "modified": "2024-09-16T14:37:28Z", + "modified": "2024-09-16T18:31:21Z", "published": "2024-09-16T14:37:28Z", "aliases": [ "CVE-2024-1578" ], "details": "The MiCard PLUS Ci and MiCard PLUS BLE reader products developed by rf IDEAS and rebranded by NT-ware have a firmware fault that may result in characters randomly being dropped from some ID card reads, which would result in the wrong ID card number being assigned during ID card self-registration and might result in failed login attempts for end-users. Random characters being dropped from ID card numbers compromises the uniqueness of ID cards that can, therefore, result in a security issue if the users are using the ‘ID card self-registration’ function.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:P/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/09/GHSA-jx9q-9xj3-cp3g/GHSA-jx9q-9xj3-cp3g.json b/advisories/unreviewed/2024/09/GHSA-jx9q-9xj3-cp3g/GHSA-jx9q-9xj3-cp3g.json index e089edc2ec4..13b207c0827 100644 --- a/advisories/unreviewed/2024/09/GHSA-jx9q-9xj3-cp3g/GHSA-jx9q-9xj3-cp3g.json +++ b/advisories/unreviewed/2024/09/GHSA-jx9q-9xj3-cp3g/GHSA-jx9q-9xj3-cp3g.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-119", "CWE-788" ], "severity": "LOW", diff --git a/advisories/unreviewed/2024/09/GHSA-m5wh-wcvg-3f5f/GHSA-m5wh-wcvg-3f5f.json b/advisories/unreviewed/2024/09/GHSA-m5wh-wcvg-3f5f/GHSA-m5wh-wcvg-3f5f.json new file mode 100644 index 00000000000..fe77f87bbf8 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-m5wh-wcvg-3f5f/GHSA-m5wh-wcvg-3f5f.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m5wh-wcvg-3f5f", + "modified": "2024-09-16T18:31:21Z", + "published": "2024-09-16T18:31:21Z", + "aliases": [ + "CVE-2024-23984" + ], + "details": "Observable discrepancy in RAPL interface for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23984" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01103.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-203" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-16T17:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-p47w-6xhw-hhxj/GHSA-p47w-6xhw-hhxj.json b/advisories/unreviewed/2024/09/GHSA-p47w-6xhw-hhxj/GHSA-p47w-6xhw-hhxj.json index 062220d8289..9730d444950 100644 --- a/advisories/unreviewed/2024/09/GHSA-p47w-6xhw-hhxj/GHSA-p47w-6xhw-hhxj.json +++ b/advisories/unreviewed/2024/09/GHSA-p47w-6xhw-hhxj/GHSA-p47w-6xhw-hhxj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p47w-6xhw-hhxj", - "modified": "2024-09-13T21:31:22Z", + "modified": "2024-09-16T18:31:21Z", "published": "2024-09-13T21:31:22Z", "aliases": [ "CVE-2024-44094" ], "details": "In ppmp_protect_mfcfw_buf of code/drm_fw.c, there is a possible memory corruption due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-20" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-13T21:15:10Z" diff --git a/advisories/unreviewed/2024/09/GHSA-p4m2-q7r3-j2h5/GHSA-p4m2-q7r3-j2h5.json b/advisories/unreviewed/2024/09/GHSA-p4m2-q7r3-j2h5/GHSA-p4m2-q7r3-j2h5.json new file mode 100644 index 00000000000..337fd41f80c --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-p4m2-q7r3-j2h5/GHSA-p4m2-q7r3-j2h5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p4m2-q7r3-j2h5", + "modified": "2024-09-16T18:31:22Z", + "published": "2024-09-16T18:31:22Z", + "aliases": [ + "CVE-2024-33848" + ], + "details": "Uncaught exception in Intel(R) RAID Web Console software all versions may allow an authenticated user to potentially enable denial of service via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33848" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00926.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-248" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-16T17:16:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-p5c4-rjq3-8654/GHSA-p5c4-rjq3-8654.json b/advisories/unreviewed/2024/09/GHSA-p5c4-rjq3-8654/GHSA-p5c4-rjq3-8654.json new file mode 100644 index 00000000000..4be03c61a88 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-p5c4-rjq3-8654/GHSA-p5c4-rjq3-8654.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p5c4-rjq3-8654", + "modified": "2024-09-16T18:31:22Z", + "published": "2024-09-16T18:31:21Z", + "aliases": [ + "CVE-2024-32666" + ], + "details": "NULL pointer dereference in Intel(R) RAID Web Console software for all versions may allow an authenticated user to potentially enable denial of service via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32666" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00926.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-16T17:16:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-pcx7-83rx-78c2/GHSA-pcx7-83rx-78c2.json b/advisories/unreviewed/2024/09/GHSA-pcx7-83rx-78c2/GHSA-pcx7-83rx-78c2.json new file mode 100644 index 00000000000..bb3943f2a02 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-pcx7-83rx-78c2/GHSA-pcx7-83rx-78c2.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pcx7-83rx-78c2", + "modified": "2024-09-16T18:31:21Z", + "published": "2024-09-16T18:31:21Z", + "aliases": [ + "CVE-2024-21781" + ], + "details": "Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to enable information disclosure or denial of service via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:N/VA:H/SC:H/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21781" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01071.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-16T17:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-pppq-wphf-gg65/GHSA-pppq-wphf-gg65.json b/advisories/unreviewed/2024/09/GHSA-pppq-wphf-gg65/GHSA-pppq-wphf-gg65.json new file mode 100644 index 00000000000..1cffe9afdd1 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-pppq-wphf-gg65/GHSA-pppq-wphf-gg65.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pppq-wphf-gg65", + "modified": "2024-09-16T18:31:22Z", + "published": "2024-09-16T18:31:22Z", + "aliases": [ + "CVE-2024-36261" + ], + "details": "Improper access control in Intel(R) RAID Web Console software all versions may allow an authenticated user to potentially enable denial of service via adjacent access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36261" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00926.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-16T17:16:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-q74x-f8wx-jrgv/GHSA-q74x-f8wx-jrgv.json b/advisories/unreviewed/2024/09/GHSA-q74x-f8wx-jrgv/GHSA-q74x-f8wx-jrgv.json index 88d66a54012..4f67e4b1b08 100644 --- a/advisories/unreviewed/2024/09/GHSA-q74x-f8wx-jrgv/GHSA-q74x-f8wx-jrgv.json +++ b/advisories/unreviewed/2024/09/GHSA-q74x-f8wx-jrgv/GHSA-q74x-f8wx-jrgv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q74x-f8wx-jrgv", - "modified": "2024-09-13T21:31:22Z", + "modified": "2024-09-16T18:31:21Z", "published": "2024-09-13T21:31:22Z", "aliases": [ "CVE-2024-44093" ], "details": "In ppmp_unprotect_buf of drm/code/drm_fw.c, there is a possible memory corruption due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-783" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-13T21:15:10Z" diff --git a/advisories/unreviewed/2024/09/GHSA-r3xc-mh5x-gjfq/GHSA-r3xc-mh5x-gjfq.json b/advisories/unreviewed/2024/09/GHSA-r3xc-mh5x-gjfq/GHSA-r3xc-mh5x-gjfq.json new file mode 100644 index 00000000000..759cb953bfd --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-r3xc-mh5x-gjfq/GHSA-r3xc-mh5x-gjfq.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r3xc-mh5x-gjfq", + "modified": "2024-09-16T18:31:21Z", + "published": "2024-09-16T18:31:21Z", + "aliases": [ + "CVE-2024-24968" + ], + "details": "Improper finite state machines (FSMs) in hardware logic in some Intel(R) Processors may allow an privileged user to potentially enable a denial of service via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24968" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01097.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1245" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-16T17:16:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-rq4p-jrjr-m4mq/GHSA-rq4p-jrjr-m4mq.json b/advisories/unreviewed/2024/09/GHSA-rq4p-jrjr-m4mq/GHSA-rq4p-jrjr-m4mq.json new file mode 100644 index 00000000000..96e12259f53 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-rq4p-jrjr-m4mq/GHSA-rq4p-jrjr-m4mq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rq4p-jrjr-m4mq", + "modified": "2024-09-16T18:31:22Z", + "published": "2024-09-16T18:31:22Z", + "aliases": [ + "CVE-2024-36247" + ], + "details": "Improper access control in Intel(R) RAID Web Console all versions may allow an authenticated user to potentially enable denial of service via adjacent access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36247" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00926.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-16T17:16:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-v3gc-cff3-2vg3/GHSA-v3gc-cff3-2vg3.json b/advisories/unreviewed/2024/09/GHSA-v3gc-cff3-2vg3/GHSA-v3gc-cff3-2vg3.json index 1a3686911bd..8ada3fbd9bc 100644 --- a/advisories/unreviewed/2024/09/GHSA-v3gc-cff3-2vg3/GHSA-v3gc-cff3-2vg3.json +++ b/advisories/unreviewed/2024/09/GHSA-v3gc-cff3-2vg3/GHSA-v3gc-cff3-2vg3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v3gc-cff3-2vg3", - "modified": "2024-09-13T21:31:22Z", + "modified": "2024-09-16T18:31:20Z", "published": "2024-09-13T21:31:22Z", "aliases": [ "CVE-2024-44430" ], "details": "SQL Injection vulnerability in Best Free Law Office Management Software-v1.0 allows an attacker to execute arbitrary code and obtain sensitive information via a crafted payload to the kortex_lite/control/register_case.php interface", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-13T20:15:02Z" diff --git a/advisories/unreviewed/2024/09/GHSA-v63p-x2p8-f754/GHSA-v63p-x2p8-f754.json b/advisories/unreviewed/2024/09/GHSA-v63p-x2p8-f754/GHSA-v63p-x2p8-f754.json new file mode 100644 index 00000000000..2f90d994218 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-v63p-x2p8-f754/GHSA-v63p-x2p8-f754.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v63p-x2p8-f754", + "modified": "2024-09-16T18:31:21Z", + "published": "2024-09-16T18:31:21Z", + "aliases": [ + "CVE-2024-23599" + ], + "details": "Race condition in Seamless Firmware Updates for some Intel(R) reference platforms may allow a privileged user to potentially enable denial of service via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23599" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01071.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-362" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-16T17:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-vpc7-hmh5-3wx6/GHSA-vpc7-hmh5-3wx6.json b/advisories/unreviewed/2024/09/GHSA-vpc7-hmh5-3wx6/GHSA-vpc7-hmh5-3wx6.json new file mode 100644 index 00000000000..2ce9ab40245 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-vpc7-hmh5-3wx6/GHSA-vpc7-hmh5-3wx6.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vpc7-hmh5-3wx6", + "modified": "2024-09-16T18:31:21Z", + "published": "2024-09-16T18:31:21Z", + "aliases": [ + "CVE-2024-21829" + ], + "details": "Improper input validation in UEFI firmware error handler for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21829" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01071.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-16T17:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-vrj2-p3r5-2mq6/GHSA-vrj2-p3r5-2mq6.json b/advisories/unreviewed/2024/09/GHSA-vrj2-p3r5-2mq6/GHSA-vrj2-p3r5-2mq6.json new file mode 100644 index 00000000000..9e2c0045633 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-vrj2-p3r5-2mq6/GHSA-vrj2-p3r5-2mq6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vrj2-p3r5-2mq6", + "modified": "2024-09-16T18:31:22Z", + "published": "2024-09-16T18:31:21Z", + "aliases": [ + "CVE-2024-32940" + ], + "details": "Improper access control in Intel(R) RAID Web Console software for all versions may allow an authenticated user to potentially enable denial of service via adjacent access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32940" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00926.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-16T17:16:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-vw3f-8r5j-7wqm/GHSA-vw3f-8r5j-7wqm.json b/advisories/unreviewed/2024/09/GHSA-vw3f-8r5j-7wqm/GHSA-vw3f-8r5j-7wqm.json new file mode 100644 index 00000000000..fb90d9e1231 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-vw3f-8r5j-7wqm/GHSA-vw3f-8r5j-7wqm.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vw3f-8r5j-7wqm", + "modified": "2024-09-16T18:31:22Z", + "published": "2024-09-16T18:31:22Z", + "aliases": [ + "CVE-2023-45854" + ], + "details": "A Business Logic vulnerability in Shopkit 1.0 allows an attacker to add products with negative quantities to the shopping cart via the qtd parameter in the add-to-cart function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45854" + }, + { + "type": "WEB", + "url": "https://kafka-esc.com/posts/2024/09/cve-2023-45854-interger-overflow-in-shopkit-1.0" + }, + { + "type": "WEB", + "url": "https://shopk.it" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-16T18:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-xjwh-3rm6-w25h/GHSA-xjwh-3rm6-w25h.json b/advisories/unreviewed/2024/09/GHSA-xjwh-3rm6-w25h/GHSA-xjwh-3rm6-w25h.json index ec7f55dca7f..0dfbec37eed 100644 --- a/advisories/unreviewed/2024/09/GHSA-xjwh-3rm6-w25h/GHSA-xjwh-3rm6-w25h.json +++ b/advisories/unreviewed/2024/09/GHSA-xjwh-3rm6-w25h/GHSA-xjwh-3rm6-w25h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xjwh-3rm6-w25h", - "modified": "2024-09-04T12:30:37Z", + "modified": "2024-09-16T18:31:20Z", "published": "2024-09-02T18:31:25Z", "aliases": [ "CVE-2024-44947" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfuse: Initialize beyond-EOF page contents before setting uptodate\n\nfuse_notify_store(), unlike fuse_do_readpage(), does not enable page\nzeroing (because it can be used to change partial page contents).\n\nSo fuse_notify_store() must be more careful to fully initialize page\ncontents (including parts of the page that are beyond end-of-file)\nbefore marking the page uptodate.\n\nThe current code can leave beyond-EOF page contents uninitialized, which\nmakes these uninitialized page contents visible to userspace via mmap().\n\nThis is an information leak, but only affects systems which do not\nenable init-on-alloc (via CONFIG_INIT_ON_ALLOC_DEFAULT_ON=y or the\ncorresponding kernel command line parameter).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-665" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-02T18:15:36Z" diff --git a/advisories/unreviewed/2024/09/GHSA-xmxj-v2q8-8qx6/GHSA-xmxj-v2q8-8qx6.json b/advisories/unreviewed/2024/09/GHSA-xmxj-v2q8-8qx6/GHSA-xmxj-v2q8-8qx6.json new file mode 100644 index 00000000000..38db45998a6 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-xmxj-v2q8-8qx6/GHSA-xmxj-v2q8-8qx6.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xmxj-v2q8-8qx6", + "modified": "2024-09-16T18:31:22Z", + "published": "2024-09-16T18:31:22Z", + "aliases": [ + "CVE-2024-8661" + ], + "details": "Concrete CMS versions 9.0.0 to 9.3.4 and below 8.5.18 are vulnerable to Stored XSS in the \"Next&Previous Nav\" block. A rogue administrator could add a malicious payload by executing it in the browsers of targeted users. The Concrete CMS Security Team gave this vulnerability a CVSS v4 score of 4.6 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N  Since the \"Next&Previous Nav\" block output was not sufficiently sanitized, the malicious payload could be executed in the browsers of targeted users. Thanks, Chu Quoc Khanh for reporting.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8661" + }, + { + "type": "WEB", + "url": "https://github.com/concretecms/concretecms/pull/12204" + }, + { + "type": "WEB", + "url": "https://github.com/concretecms/concretecms/commit/ce5ee2ab83fe8de6fa012dd51c5a1dde05cb0dc4" + }, + { + "type": "WEB", + "url": "https://documentation.concretecms.org/9-x/developers/introduction/version-history/934-release-notes" + }, + { + "type": "WEB", + "url": "https://documentation.concretecms.org/developers/introduction/version-history/8519-release-notes" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-16T18:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-xp7v-r3c8-pp3w/GHSA-xp7v-r3c8-pp3w.json b/advisories/unreviewed/2024/09/GHSA-xp7v-r3c8-pp3w/GHSA-xp7v-r3c8-pp3w.json new file mode 100644 index 00000000000..c4b3fda8378 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-xp7v-r3c8-pp3w/GHSA-xp7v-r3c8-pp3w.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xp7v-r3c8-pp3w", + "modified": "2024-09-16T18:31:21Z", + "published": "2024-09-16T18:31:21Z", + "aliases": [ + "CVE-2023-43626" + ], + "details": "Improper access control in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-43626" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01071.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-16T17:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-xr4c-mmrv-3h6c/GHSA-xr4c-mmrv-3h6c.json b/advisories/unreviewed/2024/09/GHSA-xr4c-mmrv-3h6c/GHSA-xr4c-mmrv-3h6c.json index cdbe01fdcda..18d1392ccc8 100644 --- a/advisories/unreviewed/2024/09/GHSA-xr4c-mmrv-3h6c/GHSA-xr4c-mmrv-3h6c.json +++ b/advisories/unreviewed/2024/09/GHSA-xr4c-mmrv-3h6c/GHSA-xr4c-mmrv-3h6c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xr4c-mmrv-3h6c", - "modified": "2024-09-13T21:31:22Z", + "modified": "2024-09-16T18:31:20Z", "published": "2024-09-13T21:31:22Z", "aliases": [ "CVE-2024-29779" ], "details": "there is a possible escalation of privilege due to an unusual root cause. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-13T21:15:10Z"