Publish Advisories

GHSA-frgf-8jr5-j2jv
GHSA-3c2c-v8x8-23vv
GHSA-9qr8-h5jr-2gmw
GHSA-6589-j38p-mm8c
GHSA-2gg2-2h66-3xcr
GHSA-2xpc-6r4r-v2hh
GHSA-4mgj-2pcm-grp4
GHSA-7vf8-rmp2-v23x
GHSA-hw7v-x4gj-9m6p
GHSA-m3mr-93pv-j56f
GHSA-mhqf-p484-rpwx
GHSA-qjvv-485h-mp82
GHSA-qr7v-3hq9-cr46
GHSA-wjmw-g7qq-g6h2
GHSA-wx7j-q638-34vf
This commit is contained in:
advisory-database[bot]
2023-11-09 03:31:34 +00:00
parent be9e46e9ff
commit 32957f83b2
15 changed files with 217 additions and 30 deletions
@@ -75,6 +75,10 @@
{
"type": "WEB",
"url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/rmagick/CVE-2023-5349.yml"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/S3XMQ2KWPYGT447EKPENGXXHKAQ5NUWF/"
}
],
"database_specific": {
@@ -21,6 +21,14 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2014-0883"
},
{
"type": "WEB",
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/91163"
},
{
"type": "WEB",
"url": "https://www.ibm.com/support/pages/security-bulletin-power-hardware-management-console-hmc-cve-2014-0883"
},
{
"type": "WEB",
"url": "http://www-01.ibm.com/support/docview.wss?uid=nas8N1019972"
@@ -25,6 +25,10 @@
"type": "WEB",
"url": "https://security.paloaltonetworks.com/CVE-2023-0001"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2023/11/08/10"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2023/11/08/2"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6589-j38p-mm8c",
"modified": "2023-09-27T15:30:39Z",
"modified": "2023-11-09T03:30:18Z",
"published": "2023-09-27T15:30:39Z",
"aliases": [
"CVE-2023-5157"
@@ -21,6 +21,22 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5157"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2023:5683"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2023:5684"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2023:6821"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2023:6822"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2023-5157"
@@ -32,11 +48,11 @@
],
"database_specific": {
"cwe_ids": [
"CWE-400"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
"nvd_published_at": "2023-09-27T15:19:41Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2gg2-2h66-3xcr",
"modified": "2023-11-02T00:30:32Z",
"modified": "2023-11-09T03:30:19Z",
"published": "2023-11-02T00:30:32Z",
"aliases": [
"CVE-2023-44025"
],
"details": "SQL injection vulnerability in addify Addifyfreegifts v.1.0.2 and before allows a remote attacker to execute arbitrary code via a crafted script to the getrulebyid function in the AddifyfreegiftsModel.php component.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,11 +28,11 @@
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
"nvd_published_at": "2023-11-01T22:15:08Z"
}
}
@@ -33,6 +33,6 @@
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
"nvd_published_at": "2023-11-01T17:15:11Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4mgj-2pcm-grp4",
"modified": "2023-11-02T00:30:32Z",
"modified": "2023-11-09T03:30:19Z",
"published": "2023-11-02T00:30:32Z",
"aliases": [
"CVE-2023-44954"
],
"details": "Cross Site Scripting vulnerability in BigTree CMS v.4.5.7 allows a remote attacker to execute arbitrary code via the ID parameter in the Developer Settings functions.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -29,11 +32,11 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
"nvd_published_at": "2023-11-01T23:15:07Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7vf8-rmp2-v23x",
"modified": "2023-11-09T03:30:19Z",
"published": "2023-11-09T03:30:19Z",
"aliases": [
"CVE-2023-47007"
],
"details": "An issue in ASUS RT-AX57 v.3.0.0.4_386_52041 allows a remote attacker to execute arbitrary code via a crafted request to the lan_ifname field in the sub_391B8 function.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47007"
},
{
"type": "WEB",
"url": "https://github.com/XYIYM/Digging/blob/main/ASUS/RT-AX57/2/1.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-11-09T01:15:07Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hw7v-x4gj-9m6p",
"modified": "2023-11-01T21:30:19Z",
"modified": "2023-11-09T03:30:19Z",
"published": "2023-11-01T21:30:19Z",
"aliases": [
"CVE-2023-46482"
],
"details": "SQL injection vulnerability in wuzhicms v.4.1.0 allows a remote attacker to execute arbitrary code via the Database Backup Functionality in the coreframe/app/database/admin/index.php component.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,11 +28,11 @@
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
"nvd_published_at": "2023-11-01T19:15:45Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m3mr-93pv-j56f",
"modified": "2023-11-09T03:30:19Z",
"published": "2023-11-09T03:30:19Z",
"aliases": [
"CVE-2023-47006"
],
"details": "An issue in ASUS RT-AX57 v.3.0.0.4_386_52041 allows a remote attacker to execute arbitrary code via a crafted request to the lan_ipaddr field in the sub_6FC74 function.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47006"
},
{
"type": "WEB",
"url": "https://github.com/XYIYM/Digging/blob/main/ASUS/RT-AX57/1/1.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-11-09T01:15:07Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mhqf-p484-rpwx",
"modified": "2023-11-09T03:30:19Z",
"published": "2023-11-09T03:30:19Z",
"aliases": [
"CVE-2023-47005"
],
"details": "An issue in ASUS RT-AX57 v.3.0.0.4_386_52041 allows a remote attacker to execute arbitrary code via a crafted request to the lan_ifname field in the sub_ln 2C318 function.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47005"
},
{
"type": "WEB",
"url": "https://github.com/XYIYM/Digging/blob/main/ASUS/RT-AX57/3/1.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-11-09T01:15:07Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qjvv-485h-mp82",
"modified": "2023-11-02T00:30:32Z",
"modified": "2023-11-09T03:30:19Z",
"published": "2023-11-02T00:30:32Z",
"aliases": [
"CVE-2023-45201"
@@ -37,6 +37,6 @@
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
"nvd_published_at": "2023-11-01T22:15:08Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qr7v-3hq9-cr46",
"modified": "2023-11-09T03:30:19Z",
"published": "2023-11-09T03:30:19Z",
"aliases": [
"CVE-2023-47008"
],
"details": "An issue in ASUS RT-AX57 v.3.0.0.4_386_52041 allows a remote attacker to execute arbitrary code via a crafted request to the ifname field in the sub_4CCE4 function.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47008"
},
{
"type": "WEB",
"url": "https://github.com/XYIYM/Digging/blob/main/ASUS/RT-AX57/4/1.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-11-09T01:15:07Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wjmw-g7qq-g6h2",
"modified": "2023-11-01T18:30:33Z",
"modified": "2023-11-09T03:30:19Z",
"published": "2023-11-01T18:30:33Z",
"aliases": [
"CVE-2023-5766"
],
"details": "\n\nA remote code execution vulnerability in Remote Desktop Manager 2023.2.33 and earlier on Windows allows an attacker to remotely execute code from another windows user session on the same host via a specially crafted TCP packet.\n\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -27,9 +30,9 @@
"cwe_ids": [
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
"nvd_published_at": "2023-11-01T18:15:10Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wx7j-q638-34vf",
"modified": "2023-11-01T18:30:33Z",
"modified": "2023-11-09T03:30:19Z",
"published": "2023-11-01T18:30:33Z",
"aliases": [
"CVE-2023-5765"
],
"details": "Improper access control in the password analyzer feature in Devolutions Remote Desktop Manager 2023.2.33 and earlier on Windows allows an attacker to bypass permissions via data source switching.\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -27,9 +30,9 @@
"cwe_ids": [
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
"nvd_published_at": "2023-11-01T18:15:10Z"
}
}