mirror of
https://github.com/netbirdio/advisory-database.git
synced 2026-05-22 18:04:22 -07:00
Publish Advisories
GHSA-frgf-8jr5-j2jv GHSA-3c2c-v8x8-23vv GHSA-9qr8-h5jr-2gmw GHSA-6589-j38p-mm8c GHSA-2gg2-2h66-3xcr GHSA-2xpc-6r4r-v2hh GHSA-4mgj-2pcm-grp4 GHSA-7vf8-rmp2-v23x GHSA-hw7v-x4gj-9m6p GHSA-m3mr-93pv-j56f GHSA-mhqf-p484-rpwx GHSA-qjvv-485h-mp82 GHSA-qr7v-3hq9-cr46 GHSA-wjmw-g7qq-g6h2 GHSA-wx7j-q638-34vf
This commit is contained in:
@@ -75,6 +75,10 @@
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/rmagick/CVE-2023-5349.yml"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/S3XMQ2KWPYGT447EKPENGXXHKAQ5NUWF/"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
|
||||
@@ -21,6 +21,14 @@
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2014-0883"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/91163"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.ibm.com/support/pages/security-bulletin-power-hardware-management-console-hmc-cve-2014-0883"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "http://www-01.ibm.com/support/docview.wss?uid=nas8N1019972"
|
||||
|
||||
@@ -25,6 +25,10 @@
|
||||
"type": "WEB",
|
||||
"url": "https://security.paloaltonetworks.com/CVE-2023-0001"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "http://www.openwall.com/lists/oss-security/2023/11/08/10"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "http://www.openwall.com/lists/oss-security/2023/11/08/2"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-6589-j38p-mm8c",
|
||||
"modified": "2023-09-27T15:30:39Z",
|
||||
"modified": "2023-11-09T03:30:18Z",
|
||||
"published": "2023-09-27T15:30:39Z",
|
||||
"aliases": [
|
||||
"CVE-2023-5157"
|
||||
@@ -21,6 +21,22 @@
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5157"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://access.redhat.com/errata/RHSA-2023:5683"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://access.redhat.com/errata/RHSA-2023:5684"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://access.redhat.com/errata/RHSA-2023:6821"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://access.redhat.com/errata/RHSA-2023:6822"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://access.redhat.com/security/cve/CVE-2023-5157"
|
||||
@@ -32,11 +48,11 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
"CWE-400"
|
||||
],
|
||||
"severity": null,
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": null
|
||||
"nvd_published_at": "2023-09-27T15:19:41Z"
|
||||
}
|
||||
}
|
||||
@@ -1,14 +1,17 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-2gg2-2h66-3xcr",
|
||||
"modified": "2023-11-02T00:30:32Z",
|
||||
"modified": "2023-11-09T03:30:19Z",
|
||||
"published": "2023-11-02T00:30:32Z",
|
||||
"aliases": [
|
||||
"CVE-2023-44025"
|
||||
],
|
||||
"details": "SQL injection vulnerability in addify Addifyfreegifts v.1.0.2 and before allows a remote attacker to execute arbitrary code via a crafted script to the getrulebyid function in the AddifyfreegiftsModel.php component.",
|
||||
"severity": [
|
||||
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
@@ -25,11 +28,11 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
"CWE-89"
|
||||
],
|
||||
"severity": null,
|
||||
"severity": "CRITICAL",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": null
|
||||
"nvd_published_at": "2023-11-01T22:15:08Z"
|
||||
}
|
||||
}
|
||||
@@ -33,6 +33,6 @@
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": null
|
||||
"nvd_published_at": "2023-11-01T17:15:11Z"
|
||||
}
|
||||
}
|
||||
@@ -1,14 +1,17 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-4mgj-2pcm-grp4",
|
||||
"modified": "2023-11-02T00:30:32Z",
|
||||
"modified": "2023-11-09T03:30:19Z",
|
||||
"published": "2023-11-02T00:30:32Z",
|
||||
"aliases": [
|
||||
"CVE-2023-44954"
|
||||
],
|
||||
"details": "Cross Site Scripting vulnerability in BigTree CMS v.4.5.7 allows a remote attacker to execute arbitrary code via the ID parameter in the Developer Settings functions.",
|
||||
"severity": [
|
||||
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
@@ -29,11 +32,11 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
"CWE-79"
|
||||
],
|
||||
"severity": null,
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": null
|
||||
"nvd_published_at": "2023-11-01T23:15:07Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,35 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-7vf8-rmp2-v23x",
|
||||
"modified": "2023-11-09T03:30:19Z",
|
||||
"published": "2023-11-09T03:30:19Z",
|
||||
"aliases": [
|
||||
"CVE-2023-47007"
|
||||
],
|
||||
"details": "An issue in ASUS RT-AX57 v.3.0.0.4_386_52041 allows a remote attacker to execute arbitrary code via a crafted request to the lan_ifname field in the sub_391B8 function.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47007"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/XYIYM/Digging/blob/main/ASUS/RT-AX57/2/1.md"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2023-11-09T01:15:07Z"
|
||||
}
|
||||
}
|
||||
@@ -1,14 +1,17 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-hw7v-x4gj-9m6p",
|
||||
"modified": "2023-11-01T21:30:19Z",
|
||||
"modified": "2023-11-09T03:30:19Z",
|
||||
"published": "2023-11-01T21:30:19Z",
|
||||
"aliases": [
|
||||
"CVE-2023-46482"
|
||||
],
|
||||
"details": "SQL injection vulnerability in wuzhicms v.4.1.0 allows a remote attacker to execute arbitrary code via the Database Backup Functionality in the coreframe/app/database/admin/index.php component.",
|
||||
"severity": [
|
||||
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
@@ -25,11 +28,11 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
"CWE-89"
|
||||
],
|
||||
"severity": null,
|
||||
"severity": "CRITICAL",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": null
|
||||
"nvd_published_at": "2023-11-01T19:15:45Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,35 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-m3mr-93pv-j56f",
|
||||
"modified": "2023-11-09T03:30:19Z",
|
||||
"published": "2023-11-09T03:30:19Z",
|
||||
"aliases": [
|
||||
"CVE-2023-47006"
|
||||
],
|
||||
"details": "An issue in ASUS RT-AX57 v.3.0.0.4_386_52041 allows a remote attacker to execute arbitrary code via a crafted request to the lan_ipaddr field in the sub_6FC74 function.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47006"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/XYIYM/Digging/blob/main/ASUS/RT-AX57/1/1.md"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2023-11-09T01:15:07Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,35 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-mhqf-p484-rpwx",
|
||||
"modified": "2023-11-09T03:30:19Z",
|
||||
"published": "2023-11-09T03:30:19Z",
|
||||
"aliases": [
|
||||
"CVE-2023-47005"
|
||||
],
|
||||
"details": "An issue in ASUS RT-AX57 v.3.0.0.4_386_52041 allows a remote attacker to execute arbitrary code via a crafted request to the lan_ifname field in the sub_ln 2C318 function.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47005"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/XYIYM/Digging/blob/main/ASUS/RT-AX57/3/1.md"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2023-11-09T01:15:07Z"
|
||||
}
|
||||
}
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-qjvv-485h-mp82",
|
||||
"modified": "2023-11-02T00:30:32Z",
|
||||
"modified": "2023-11-09T03:30:19Z",
|
||||
"published": "2023-11-02T00:30:32Z",
|
||||
"aliases": [
|
||||
"CVE-2023-45201"
|
||||
@@ -37,6 +37,6 @@
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": null
|
||||
"nvd_published_at": "2023-11-01T22:15:08Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,35 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-qr7v-3hq9-cr46",
|
||||
"modified": "2023-11-09T03:30:19Z",
|
||||
"published": "2023-11-09T03:30:19Z",
|
||||
"aliases": [
|
||||
"CVE-2023-47008"
|
||||
],
|
||||
"details": "An issue in ASUS RT-AX57 v.3.0.0.4_386_52041 allows a remote attacker to execute arbitrary code via a crafted request to the ifname field in the sub_4CCE4 function.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47008"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/XYIYM/Digging/blob/main/ASUS/RT-AX57/4/1.md"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2023-11-09T01:15:07Z"
|
||||
}
|
||||
}
|
||||
@@ -1,14 +1,17 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-wjmw-g7qq-g6h2",
|
||||
"modified": "2023-11-01T18:30:33Z",
|
||||
"modified": "2023-11-09T03:30:19Z",
|
||||
"published": "2023-11-01T18:30:33Z",
|
||||
"aliases": [
|
||||
"CVE-2023-5766"
|
||||
],
|
||||
"details": "\n\nA remote code execution vulnerability in Remote Desktop Manager 2023.2.33 and earlier on Windows allows an attacker to remotely execute code from another windows user session on the same host via a specially crafted TCP packet.\n\n\n",
|
||||
"severity": [
|
||||
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
@@ -27,9 +30,9 @@
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"severity": "CRITICAL",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": null
|
||||
"nvd_published_at": "2023-11-01T18:15:10Z"
|
||||
}
|
||||
}
|
||||
@@ -1,14 +1,17 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-wx7j-q638-34vf",
|
||||
"modified": "2023-11-01T18:30:33Z",
|
||||
"modified": "2023-11-09T03:30:19Z",
|
||||
"published": "2023-11-01T18:30:33Z",
|
||||
"aliases": [
|
||||
"CVE-2023-5765"
|
||||
],
|
||||
"details": "Improper access control in the password analyzer feature in Devolutions Remote Desktop Manager 2023.2.33 and earlier on Windows allows an attacker to bypass permissions via data source switching.\n",
|
||||
"severity": [
|
||||
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
@@ -27,9 +30,9 @@
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"severity": "CRITICAL",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": null
|
||||
"nvd_published_at": "2023-11-01T18:15:10Z"
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user