Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2024-08-15 15:32:04 +00:00
parent 78ffb2655c
commit 34679994b6
29 changed files with 678 additions and 35 deletions
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-ggx6-v629-c48v",
"modified": "2022-05-24T17:33:20Z",
"modified": "2024-08-15T15:30:52Z",
"published": "2022-05-24T17:33:20Z",
"aliases": [
"CVE-2020-28327"
],
"details": "A res_pjsip_session crash was discovered in Asterisk Open Source 13.x before 13.37.1, 16.x before 16.14.1, 17.x before 17.8.1, and 18.x before 18.0.1. and Certified Asterisk before 16.8-cert5. Upon receiving a new SIP Invite, Asterisk did not return the created dialog locked or referenced. This caused a gap between the creation of the dialog object, and its next use by the thread that created it. Depending on some off-nominal circumstances and timing, it was possible for another thread to free said dialog in this gap. Asterisk could then crash when the dialog object, or any of its dependent objects, were dereferenced or accessed next by the initial-creation thread. Note, however, that this crash can only occur when using a connection-oriented protocol (e.g., TCP or TLS, but not UDP) for SIP transport. Also, the remote client must be authenticated, or Asterisk must be configured for anonymous calling.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q5gr-h5mj-hp63",
"modified": "2022-05-24T17:33:20Z",
"modified": "2024-08-15T15:30:52Z",
"published": "2022-05-24T17:33:20Z",
"aliases": [
"CVE-2020-28242"
@@ -25,6 +25,10 @@
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2022/04/msg00001.html"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QUS54QTQCYKR36EIULYD544GXDA644HB"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QUS54QTQCYKR36EIULYD544GXDA644HB"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g24h-xx4p-jc7j",
"modified": "2024-02-20T15:31:05Z",
"modified": "2024-08-15T15:30:52Z",
"published": "2024-02-20T15:31:05Z",
"aliases": [
"CVE-2024-25196"
],
"details": "Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions were discovered to contain a buffer overflow via the nav2_controller process. This vulnerability is triggerd via sending a crafted .yaml file.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
}
],
"affected": [
@@ -33,9 +36,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-120"
],
"severity": null,
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-20T14:15:09Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h2xm-59gc-23mm",
"modified": "2024-04-08T15:30:32Z",
"modified": "2024-08-15T15:30:52Z",
"published": "2024-04-08T15:30:32Z",
"aliases": [
"CVE-2024-31805"
],
"details": "TOTOLINK EX200 V4.0.3c.7646_B20201211 allows attackers to start the Telnet service without authorization via the telnet_enabled parameter in the setTelnetCfg function.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-284"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-08T13:15:08Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3pr5-7mf5-rc69",
"modified": "2024-07-12T00:30:35Z",
"modified": "2024-08-15T15:30:52Z",
"published": "2024-07-12T00:30:35Z",
"aliases": [
"CVE-2024-6392"
@@ -36,7 +36,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-862"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,13 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cw3q-225p-f4mw",
"modified": "2024-07-31T21:32:39Z",
"modified": "2024-08-15T15:30:53Z",
"published": "2024-07-31T21:32:39Z",
"aliases": [
"CVE-2024-4187"
],
"details": "Stored XSS vulnerability has been discovered in OpenText™ Filr product, affecting versions 24.1.1 and 24.2. The vulnerability could cause users to not be warned when clicking links to external sites.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:N/R:X/V:D/RE:L/U:Green"
@@ -28,7 +32,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-356"
"CWE-356",
"CWE-79"
],
"severity": "LOW",
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f6rc-73vx-29h5",
"modified": "2024-07-31T21:32:39Z",
"modified": "2024-08-15T15:30:53Z",
"published": "2024-07-31T21:32:38Z",
"aliases": [
"CVE-2024-41258"
],
"details": "An issue was discovered in filestash v0.4. The usage of the ssh.InsecureIgnoreHostKey() disables host key verification, possibly allowing attackers to obtain sensitive information via a man-in-the-middle attack.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-347"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-31T21:15:18Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hw78-gpfh-vw3q",
"modified": "2024-07-11T18:31:13Z",
"modified": "2024-08-15T15:30:52Z",
"published": "2024-07-11T18:31:13Z",
"aliases": [
"CVE-2024-39549"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qpgw-j75c-j585",
"modified": "2024-07-31T21:32:38Z",
"modified": "2024-08-15T15:30:52Z",
"published": "2024-07-31T21:32:38Z",
"aliases": [
"CVE-2024-41254"
],
"details": "An issue was discovered in litestream v0.3.13. The usage of the ssh.InsecureIgnoreHostKey() disables host key verification, possibly allowing attackers to obtain sensitive information via a man-in-the-middle attack.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-347"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-31T21:15:17Z"
@@ -0,0 +1,54 @@
{
"schema_version": "1.4.0",
"id": "GHSA-38wc-99fv-jfwv",
"modified": "2024-08-15T15:30:57Z",
"published": "2024-08-15T15:30:57Z",
"aliases": [
"CVE-2024-7831"
],
"details": "** UNSUPPORTED WHEN ASSIGNED ** A vulnerability has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240814 and classified as critical. Affected by this vulnerability is the function cgi_get_cooliris of the file /cgi-bin/photocenter_mgr.cgi. The manipulation of the argument path leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed that the product is end-of-life. It should be retired and replaced.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7831"
},
{
"type": "WEB",
"url": "https://github.com/BuaaIOTTeam/Iot_Dlink_NAS/blob/main/DNS_cgi_get_cooliris.md"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.274729"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.274729"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.390119"
}
],
"database_specific": {
"cwe_ids": [
"CWE-120"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-15T13:15:15Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-44vq-rpm7-q5q6",
"modified": "2024-08-06T12:30:34Z",
"modified": "2024-08-15T15:30:53Z",
"published": "2024-08-06T12:30:34Z",
"aliases": [
"CVE-2024-33960"
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-53h7-ghj7-7gh9",
"modified": "2024-08-15T15:30:58Z",
"published": "2024-08-15T15:30:58Z",
"aliases": [
"CVE-2024-42677"
],
"details": "An issue in Huizhi enterprise resource management system v.1.0 and before allows a local attacker to obtain sensitive information via the /nssys/common/filehandle. Aspx component",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42677"
},
{
"type": "WEB",
"url": "https://github.com/WarmBrew/web_vul/blob/main/HZ-cve/HZlfi.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-15T14:15:10Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-588q-52qp-c4h8",
"modified": "2024-08-12T15:30:50Z",
"modified": "2024-08-15T15:30:54Z",
"published": "2024-08-12T15:30:50Z",
"aliases": [
"CVE-2024-40473"
],
"details": "A Stored Cross Site Scripting (XSS) vulnerability was found in \"manage_houses.php\" in SourceCodester Best House Rental Management System v1.0. It allows remote attackers to execute arbitrary code via \"House_no\" and \"Description\" parameter fields.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-12T13:38:28Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5v4x-p332-82v3",
"modified": "2024-08-06T12:30:33Z",
"modified": "2024-08-15T15:30:53Z",
"published": "2024-08-06T12:30:33Z",
"aliases": [
"CVE-2024-33981"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7q88-7984-xv4j",
"modified": "2024-08-06T12:30:33Z",
"modified": "2024-08-15T15:30:53Z",
"published": "2024-08-06T12:30:33Z",
"aliases": [
"CVE-2024-33979"
@@ -0,0 +1,54 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c2p2-p654-9c4p",
"modified": "2024-08-15T15:30:57Z",
"published": "2024-08-15T15:30:57Z",
"aliases": [
"CVE-2024-7828"
],
"details": "** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240814. This vulnerability affects the function cgi_set_cover of the file /cgi-bin/photocenter_mgr.cgi. The manipulation of the argument album_name leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed that the product is end-of-life. It should be retired and replaced.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7828"
},
{
"type": "WEB",
"url": "https://github.com/BuaaIOTTeam/Iot_Dlink_NAS/blob/main/DNS_cgi_set_cover.md"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.274726"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.274726"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.390114"
}
],
"database_specific": {
"cwe_ids": [
"CWE-120"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-15T13:15:13Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cxwg-qv44-9w7m",
"modified": "2024-08-06T12:30:33Z",
"modified": "2024-08-15T15:30:53Z",
"published": "2024-08-06T12:30:33Z",
"aliases": [
"CVE-2024-33980"
@@ -0,0 +1,54 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gv8w-244w-5xfq",
"modified": "2024-08-15T15:30:57Z",
"published": "2024-08-15T15:30:57Z",
"aliases": [
"CVE-2024-7830"
],
"details": "** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240814. Affected is the function cgi_move_photo of the file /cgi-bin/photocenter_mgr.cgi. The manipulation of the argument photo_name leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed that the product is end-of-life. It should be retired and replaced.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7830"
},
{
"type": "WEB",
"url": "https://github.com/BuaaIOTTeam/Iot_Dlink_NAS/blob/main/DNS_cgi_move_photo.md"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.274728"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.274728"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.390118"
}
],
"database_specific": {
"cwe_ids": [
"CWE-120"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-15T13:15:14Z"
}
}
@@ -0,0 +1,54 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j2xh-32vh-pwww",
"modified": "2024-08-15T15:30:57Z",
"published": "2024-08-15T15:30:57Z",
"aliases": [
"CVE-2024-7829"
],
"details": "** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240814. This issue affects the function cgi_del_photo of the file /cgi-bin/photocenter_mgr.cgi. The manipulation of the argument current_path leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed that the product is end-of-life. It should be retired and replaced.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7829"
},
{
"type": "WEB",
"url": "https://github.com/BuaaIOTTeam/Iot_Dlink_NAS/blob/main/DNS_cgi_del_photo.md"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.274727"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.274727"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.390117"
}
],
"database_specific": {
"cwe_ids": [
"CWE-120"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-15T13:15:14Z"
}
}
@@ -0,0 +1,54 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mvg4-rgrq-f443",
"modified": "2024-08-15T15:30:58Z",
"published": "2024-08-15T15:30:58Z",
"aliases": [
"CVE-2024-7833"
],
"details": "A vulnerability was found in D-Link DI-8100 16.07. It has been classified as critical. This affects the function upgrade_filter_asp of the file upgrade_filter.asp. The manipulation of the argument path leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7833"
},
{
"type": "WEB",
"url": "https://github.com/aLtEr6/pdf/blob/main/3.pdf"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.274731"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.274731"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.385338"
}
],
"database_specific": {
"cwe_ids": [
"CWE-77"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-15T14:15:14Z"
}
}

Some files were not shown because too many files have changed in this diff Show More