diff --git a/advisories/unreviewed/2022/05/GHSA-ggx6-v629-c48v/GHSA-ggx6-v629-c48v.json b/advisories/unreviewed/2022/05/GHSA-ggx6-v629-c48v/GHSA-ggx6-v629-c48v.json index cbda97871d2..dd5f9cdd2f7 100644 --- a/advisories/unreviewed/2022/05/GHSA-ggx6-v629-c48v/GHSA-ggx6-v629-c48v.json +++ b/advisories/unreviewed/2022/05/GHSA-ggx6-v629-c48v/GHSA-ggx6-v629-c48v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-ggx6-v629-c48v", - "modified": "2022-05-24T17:33:20Z", + "modified": "2024-08-15T15:30:52Z", "published": "2022-05-24T17:33:20Z", "aliases": [ "CVE-2020-28327" ], "details": "A res_pjsip_session crash was discovered in Asterisk Open Source 13.x before 13.37.1, 16.x before 16.14.1, 17.x before 17.8.1, and 18.x before 18.0.1. and Certified Asterisk before 16.8-cert5. Upon receiving a new SIP Invite, Asterisk did not return the created dialog locked or referenced. This caused a gap between the creation of the dialog object, and its next use by the thread that created it. Depending on some off-nominal circumstances and timing, it was possible for another thread to free said dialog in this gap. Asterisk could then crash when the dialog object, or any of its dependent objects, were dereferenced or accessed next by the initial-creation thread. Note, however, that this crash can only occur when using a connection-oriented protocol (e.g., TCP or TLS, but not UDP) for SIP transport. Also, the remote client must be authenticated, or Asterisk must be configured for anonymous calling.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-q5gr-h5mj-hp63/GHSA-q5gr-h5mj-hp63.json b/advisories/unreviewed/2022/05/GHSA-q5gr-h5mj-hp63/GHSA-q5gr-h5mj-hp63.json index ea0df938a08..e10b645eb92 100644 --- a/advisories/unreviewed/2022/05/GHSA-q5gr-h5mj-hp63/GHSA-q5gr-h5mj-hp63.json +++ b/advisories/unreviewed/2022/05/GHSA-q5gr-h5mj-hp63/GHSA-q5gr-h5mj-hp63.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q5gr-h5mj-hp63", - "modified": "2022-05-24T17:33:20Z", + "modified": "2024-08-15T15:30:52Z", "published": "2022-05-24T17:33:20Z", "aliases": [ "CVE-2020-28242" @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2022/04/msg00001.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QUS54QTQCYKR36EIULYD544GXDA644HB" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QUS54QTQCYKR36EIULYD544GXDA644HB" diff --git a/advisories/unreviewed/2024/02/GHSA-g24h-xx4p-jc7j/GHSA-g24h-xx4p-jc7j.json b/advisories/unreviewed/2024/02/GHSA-g24h-xx4p-jc7j/GHSA-g24h-xx4p-jc7j.json index 9783af1df82..1be6d2e94ee 100644 --- a/advisories/unreviewed/2024/02/GHSA-g24h-xx4p-jc7j/GHSA-g24h-xx4p-jc7j.json +++ b/advisories/unreviewed/2024/02/GHSA-g24h-xx4p-jc7j/GHSA-g24h-xx4p-jc7j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g24h-xx4p-jc7j", - "modified": "2024-02-20T15:31:05Z", + "modified": "2024-08-15T15:30:52Z", "published": "2024-02-20T15:31:05Z", "aliases": [ "CVE-2024-25196" ], "details": "Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions were discovered to contain a buffer overflow via the nav2_controller process. This vulnerability is triggerd via sending a crafted .yaml file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-20T14:15:09Z" diff --git a/advisories/unreviewed/2024/04/GHSA-h2xm-59gc-23mm/GHSA-h2xm-59gc-23mm.json b/advisories/unreviewed/2024/04/GHSA-h2xm-59gc-23mm/GHSA-h2xm-59gc-23mm.json index 72190bf1c15..c4578593dc0 100644 --- a/advisories/unreviewed/2024/04/GHSA-h2xm-59gc-23mm/GHSA-h2xm-59gc-23mm.json +++ b/advisories/unreviewed/2024/04/GHSA-h2xm-59gc-23mm/GHSA-h2xm-59gc-23mm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h2xm-59gc-23mm", - "modified": "2024-04-08T15:30:32Z", + "modified": "2024-08-15T15:30:52Z", "published": "2024-04-08T15:30:32Z", "aliases": [ "CVE-2024-31805" ], "details": "TOTOLINK EX200 V4.0.3c.7646_B20201211 allows attackers to start the Telnet service without authorization via the telnet_enabled parameter in the setTelnetCfg function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-08T13:15:08Z" diff --git a/advisories/unreviewed/2024/07/GHSA-3pr5-7mf5-rc69/GHSA-3pr5-7mf5-rc69.json b/advisories/unreviewed/2024/07/GHSA-3pr5-7mf5-rc69/GHSA-3pr5-7mf5-rc69.json index 493c4895d0a..5cf61c8503f 100644 --- a/advisories/unreviewed/2024/07/GHSA-3pr5-7mf5-rc69/GHSA-3pr5-7mf5-rc69.json +++ b/advisories/unreviewed/2024/07/GHSA-3pr5-7mf5-rc69/GHSA-3pr5-7mf5-rc69.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3pr5-7mf5-rc69", - "modified": "2024-07-12T00:30:35Z", + "modified": "2024-08-15T15:30:52Z", "published": "2024-07-12T00:30:35Z", "aliases": [ "CVE-2024-6392" @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-cw3q-225p-f4mw/GHSA-cw3q-225p-f4mw.json b/advisories/unreviewed/2024/07/GHSA-cw3q-225p-f4mw/GHSA-cw3q-225p-f4mw.json index f03c895d214..f4fa1292f92 100644 --- a/advisories/unreviewed/2024/07/GHSA-cw3q-225p-f4mw/GHSA-cw3q-225p-f4mw.json +++ b/advisories/unreviewed/2024/07/GHSA-cw3q-225p-f4mw/GHSA-cw3q-225p-f4mw.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cw3q-225p-f4mw", - "modified": "2024-07-31T21:32:39Z", + "modified": "2024-08-15T15:30:53Z", "published": "2024-07-31T21:32:39Z", "aliases": [ "CVE-2024-4187" ], "details": "Stored XSS vulnerability has been discovered in OpenTextâ„¢ Filr product, affecting versions 24.1.1 and 24.2. The vulnerability could cause users to not be warned when clicking links to external sites.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:N/R:X/V:D/RE:L/U:Green" @@ -28,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-356" + "CWE-356", + "CWE-79" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-f6rc-73vx-29h5/GHSA-f6rc-73vx-29h5.json b/advisories/unreviewed/2024/07/GHSA-f6rc-73vx-29h5/GHSA-f6rc-73vx-29h5.json index ea3dcefdccb..f0734b08b23 100644 --- a/advisories/unreviewed/2024/07/GHSA-f6rc-73vx-29h5/GHSA-f6rc-73vx-29h5.json +++ b/advisories/unreviewed/2024/07/GHSA-f6rc-73vx-29h5/GHSA-f6rc-73vx-29h5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f6rc-73vx-29h5", - "modified": "2024-07-31T21:32:39Z", + "modified": "2024-08-15T15:30:53Z", "published": "2024-07-31T21:32:38Z", "aliases": [ "CVE-2024-41258" ], "details": "An issue was discovered in filestash v0.4. The usage of the ssh.InsecureIgnoreHostKey() disables host key verification, possibly allowing attackers to obtain sensitive information via a man-in-the-middle attack.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-347" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-31T21:15:18Z" diff --git a/advisories/unreviewed/2024/07/GHSA-hw78-gpfh-vw3q/GHSA-hw78-gpfh-vw3q.json b/advisories/unreviewed/2024/07/GHSA-hw78-gpfh-vw3q/GHSA-hw78-gpfh-vw3q.json index f5fedbc12d0..67ab9a0ccbc 100644 --- a/advisories/unreviewed/2024/07/GHSA-hw78-gpfh-vw3q/GHSA-hw78-gpfh-vw3q.json +++ b/advisories/unreviewed/2024/07/GHSA-hw78-gpfh-vw3q/GHSA-hw78-gpfh-vw3q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hw78-gpfh-vw3q", - "modified": "2024-07-11T18:31:13Z", + "modified": "2024-08-15T15:30:52Z", "published": "2024-07-11T18:31:13Z", "aliases": [ "CVE-2024-39549" diff --git a/advisories/unreviewed/2024/07/GHSA-qpgw-j75c-j585/GHSA-qpgw-j75c-j585.json b/advisories/unreviewed/2024/07/GHSA-qpgw-j75c-j585/GHSA-qpgw-j75c-j585.json index 32d572152d8..49efd0755e6 100644 --- a/advisories/unreviewed/2024/07/GHSA-qpgw-j75c-j585/GHSA-qpgw-j75c-j585.json +++ b/advisories/unreviewed/2024/07/GHSA-qpgw-j75c-j585/GHSA-qpgw-j75c-j585.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qpgw-j75c-j585", - "modified": "2024-07-31T21:32:38Z", + "modified": "2024-08-15T15:30:52Z", "published": "2024-07-31T21:32:38Z", "aliases": [ "CVE-2024-41254" ], "details": "An issue was discovered in litestream v0.3.13. The usage of the ssh.InsecureIgnoreHostKey() disables host key verification, possibly allowing attackers to obtain sensitive information via a man-in-the-middle attack.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-347" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-31T21:15:17Z" diff --git a/advisories/unreviewed/2024/08/GHSA-38wc-99fv-jfwv/GHSA-38wc-99fv-jfwv.json b/advisories/unreviewed/2024/08/GHSA-38wc-99fv-jfwv/GHSA-38wc-99fv-jfwv.json new file mode 100644 index 00000000000..0b29a5f03be --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-38wc-99fv-jfwv/GHSA-38wc-99fv-jfwv.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-38wc-99fv-jfwv", + "modified": "2024-08-15T15:30:57Z", + "published": "2024-08-15T15:30:57Z", + "aliases": [ + "CVE-2024-7831" + ], + "details": "** UNSUPPORTED WHEN ASSIGNED ** A vulnerability has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240814 and classified as critical. Affected by this vulnerability is the function cgi_get_cooliris of the file /cgi-bin/photocenter_mgr.cgi. The manipulation of the argument path leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed that the product is end-of-life. It should be retired and replaced.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7831" + }, + { + "type": "WEB", + "url": "https://github.com/BuaaIOTTeam/Iot_Dlink_NAS/blob/main/DNS_cgi_get_cooliris.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.274729" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.274729" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.390119" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T13:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-44vq-rpm7-q5q6/GHSA-44vq-rpm7-q5q6.json b/advisories/unreviewed/2024/08/GHSA-44vq-rpm7-q5q6/GHSA-44vq-rpm7-q5q6.json index 5c948f71054..73319711eb1 100644 --- a/advisories/unreviewed/2024/08/GHSA-44vq-rpm7-q5q6/GHSA-44vq-rpm7-q5q6.json +++ b/advisories/unreviewed/2024/08/GHSA-44vq-rpm7-q5q6/GHSA-44vq-rpm7-q5q6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-44vq-rpm7-q5q6", - "modified": "2024-08-06T12:30:34Z", + "modified": "2024-08-15T15:30:53Z", "published": "2024-08-06T12:30:34Z", "aliases": [ "CVE-2024-33960" diff --git a/advisories/unreviewed/2024/08/GHSA-53h7-ghj7-7gh9/GHSA-53h7-ghj7-7gh9.json b/advisories/unreviewed/2024/08/GHSA-53h7-ghj7-7gh9/GHSA-53h7-ghj7-7gh9.json new file mode 100644 index 00000000000..29eca8546e0 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-53h7-ghj7-7gh9/GHSA-53h7-ghj7-7gh9.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-53h7-ghj7-7gh9", + "modified": "2024-08-15T15:30:58Z", + "published": "2024-08-15T15:30:58Z", + "aliases": [ + "CVE-2024-42677" + ], + "details": "An issue in Huizhi enterprise resource management system v.1.0 and before allows a local attacker to obtain sensitive information via the /nssys/common/filehandle. Aspx component", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42677" + }, + { + "type": "WEB", + "url": "https://github.com/WarmBrew/web_vul/blob/main/HZ-cve/HZlfi.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T14:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-588q-52qp-c4h8/GHSA-588q-52qp-c4h8.json b/advisories/unreviewed/2024/08/GHSA-588q-52qp-c4h8/GHSA-588q-52qp-c4h8.json index 00920578106..9c4914b8cc1 100644 --- a/advisories/unreviewed/2024/08/GHSA-588q-52qp-c4h8/GHSA-588q-52qp-c4h8.json +++ b/advisories/unreviewed/2024/08/GHSA-588q-52qp-c4h8/GHSA-588q-52qp-c4h8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-588q-52qp-c4h8", - "modified": "2024-08-12T15:30:50Z", + "modified": "2024-08-15T15:30:54Z", "published": "2024-08-12T15:30:50Z", "aliases": [ "CVE-2024-40473" ], "details": "A Stored Cross Site Scripting (XSS) vulnerability was found in \"manage_houses.php\" in SourceCodester Best House Rental Management System v1.0. It allows remote attackers to execute arbitrary code via \"House_no\" and \"Description\" parameter fields.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-12T13:38:28Z" diff --git a/advisories/unreviewed/2024/08/GHSA-5v4x-p332-82v3/GHSA-5v4x-p332-82v3.json b/advisories/unreviewed/2024/08/GHSA-5v4x-p332-82v3/GHSA-5v4x-p332-82v3.json index 6ddb42462df..27b442b12f6 100644 --- a/advisories/unreviewed/2024/08/GHSA-5v4x-p332-82v3/GHSA-5v4x-p332-82v3.json +++ b/advisories/unreviewed/2024/08/GHSA-5v4x-p332-82v3/GHSA-5v4x-p332-82v3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5v4x-p332-82v3", - "modified": "2024-08-06T12:30:33Z", + "modified": "2024-08-15T15:30:53Z", "published": "2024-08-06T12:30:33Z", "aliases": [ "CVE-2024-33981" diff --git a/advisories/unreviewed/2024/08/GHSA-7q88-7984-xv4j/GHSA-7q88-7984-xv4j.json b/advisories/unreviewed/2024/08/GHSA-7q88-7984-xv4j/GHSA-7q88-7984-xv4j.json index 73d67dcf5f5..5abacb2a451 100644 --- a/advisories/unreviewed/2024/08/GHSA-7q88-7984-xv4j/GHSA-7q88-7984-xv4j.json +++ b/advisories/unreviewed/2024/08/GHSA-7q88-7984-xv4j/GHSA-7q88-7984-xv4j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7q88-7984-xv4j", - "modified": "2024-08-06T12:30:33Z", + "modified": "2024-08-15T15:30:53Z", "published": "2024-08-06T12:30:33Z", "aliases": [ "CVE-2024-33979" diff --git a/advisories/unreviewed/2024/08/GHSA-c2p2-p654-9c4p/GHSA-c2p2-p654-9c4p.json b/advisories/unreviewed/2024/08/GHSA-c2p2-p654-9c4p/GHSA-c2p2-p654-9c4p.json new file mode 100644 index 00000000000..8ddccaf04a7 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-c2p2-p654-9c4p/GHSA-c2p2-p654-9c4p.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c2p2-p654-9c4p", + "modified": "2024-08-15T15:30:57Z", + "published": "2024-08-15T15:30:57Z", + "aliases": [ + "CVE-2024-7828" + ], + "details": "** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240814. This vulnerability affects the function cgi_set_cover of the file /cgi-bin/photocenter_mgr.cgi. The manipulation of the argument album_name leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed that the product is end-of-life. It should be retired and replaced.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7828" + }, + { + "type": "WEB", + "url": "https://github.com/BuaaIOTTeam/Iot_Dlink_NAS/blob/main/DNS_cgi_set_cover.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.274726" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.274726" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.390114" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T13:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-cxwg-qv44-9w7m/GHSA-cxwg-qv44-9w7m.json b/advisories/unreviewed/2024/08/GHSA-cxwg-qv44-9w7m/GHSA-cxwg-qv44-9w7m.json index f38ccc417d0..0101aedd316 100644 --- a/advisories/unreviewed/2024/08/GHSA-cxwg-qv44-9w7m/GHSA-cxwg-qv44-9w7m.json +++ b/advisories/unreviewed/2024/08/GHSA-cxwg-qv44-9w7m/GHSA-cxwg-qv44-9w7m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cxwg-qv44-9w7m", - "modified": "2024-08-06T12:30:33Z", + "modified": "2024-08-15T15:30:53Z", "published": "2024-08-06T12:30:33Z", "aliases": [ "CVE-2024-33980" diff --git a/advisories/unreviewed/2024/08/GHSA-gv8w-244w-5xfq/GHSA-gv8w-244w-5xfq.json b/advisories/unreviewed/2024/08/GHSA-gv8w-244w-5xfq/GHSA-gv8w-244w-5xfq.json new file mode 100644 index 00000000000..b119ff7f723 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-gv8w-244w-5xfq/GHSA-gv8w-244w-5xfq.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gv8w-244w-5xfq", + "modified": "2024-08-15T15:30:57Z", + "published": "2024-08-15T15:30:57Z", + "aliases": [ + "CVE-2024-7830" + ], + "details": "** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240814. Affected is the function cgi_move_photo of the file /cgi-bin/photocenter_mgr.cgi. The manipulation of the argument photo_name leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed that the product is end-of-life. It should be retired and replaced.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7830" + }, + { + "type": "WEB", + "url": "https://github.com/BuaaIOTTeam/Iot_Dlink_NAS/blob/main/DNS_cgi_move_photo.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.274728" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.274728" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.390118" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T13:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-j2xh-32vh-pwww/GHSA-j2xh-32vh-pwww.json b/advisories/unreviewed/2024/08/GHSA-j2xh-32vh-pwww/GHSA-j2xh-32vh-pwww.json new file mode 100644 index 00000000000..4530c55e12c --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-j2xh-32vh-pwww/GHSA-j2xh-32vh-pwww.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j2xh-32vh-pwww", + "modified": "2024-08-15T15:30:57Z", + "published": "2024-08-15T15:30:57Z", + "aliases": [ + "CVE-2024-7829" + ], + "details": "** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240814. This issue affects the function cgi_del_photo of the file /cgi-bin/photocenter_mgr.cgi. The manipulation of the argument current_path leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed that the product is end-of-life. It should be retired and replaced.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7829" + }, + { + "type": "WEB", + "url": "https://github.com/BuaaIOTTeam/Iot_Dlink_NAS/blob/main/DNS_cgi_del_photo.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.274727" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.274727" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.390117" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T13:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-mvg4-rgrq-f443/GHSA-mvg4-rgrq-f443.json b/advisories/unreviewed/2024/08/GHSA-mvg4-rgrq-f443/GHSA-mvg4-rgrq-f443.json new file mode 100644 index 00000000000..2eabe1e60df --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-mvg4-rgrq-f443/GHSA-mvg4-rgrq-f443.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mvg4-rgrq-f443", + "modified": "2024-08-15T15:30:58Z", + "published": "2024-08-15T15:30:58Z", + "aliases": [ + "CVE-2024-7833" + ], + "details": "A vulnerability was found in D-Link DI-8100 16.07. It has been classified as critical. This affects the function upgrade_filter_asp of the file upgrade_filter.asp. The manipulation of the argument path leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7833" + }, + { + "type": "WEB", + "url": "https://github.com/aLtEr6/pdf/blob/main/3.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.274731" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.274731" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.385338" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T14:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-mxxm-vx4c-x8w7/GHSA-mxxm-vx4c-x8w7.json b/advisories/unreviewed/2024/08/GHSA-mxxm-vx4c-x8w7/GHSA-mxxm-vx4c-x8w7.json new file mode 100644 index 00000000000..7bf3b352ccd --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-mxxm-vx4c-x8w7/GHSA-mxxm-vx4c-x8w7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mxxm-vx4c-x8w7", + "modified": "2024-08-15T15:30:58Z", + "published": "2024-08-15T15:30:58Z", + "aliases": [ + "CVE-2024-42676" + ], + "details": "File Upload vulnerability in Huizhi enterprise resource management system v.1.0 and before allows a remote attacker to execute arbitrary code via the /nssys/common/Upload. Aspx? Action=DNPageAjaxPostBack component", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42676" + }, + { + "type": "WEB", + "url": "https://github.com/WarmBrew/web_vul/blob/main/HZ-cve/HZupload.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T14:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-p736-fp6q-qr5j/GHSA-p736-fp6q-qr5j.json b/advisories/unreviewed/2024/08/GHSA-p736-fp6q-qr5j/GHSA-p736-fp6q-qr5j.json new file mode 100644 index 00000000000..40c3fc74a3c --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-p736-fp6q-qr5j/GHSA-p736-fp6q-qr5j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p736-fp6q-qr5j", + "modified": "2024-08-15T15:30:58Z", + "published": "2024-08-15T15:30:58Z", + "aliases": [ + "CVE-2024-7262" + ], + "details": "Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.13489 on Windows allows an attacker to load an arbitrary Windows library.\nUsing the MHTML format allows an attacker to automatically deliver a malicious library on opening the document and a single user click on a crafted hyperlink leads to the execution of the library.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:X/RE:L/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7262" + }, + { + "type": "WEB", + "url": "https://www.wps.com/whatsnew/pc/20240422" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T15:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-pcmw-xjj4-jxjp/GHSA-pcmw-xjj4-jxjp.json b/advisories/unreviewed/2024/08/GHSA-pcmw-xjj4-jxjp/GHSA-pcmw-xjj4-jxjp.json new file mode 100644 index 00000000000..e9509e7b9c4 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-pcmw-xjj4-jxjp/GHSA-pcmw-xjj4-jxjp.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pcmw-xjj4-jxjp", + "modified": "2024-08-15T15:30:58Z", + "published": "2024-08-15T15:30:58Z", + "aliases": [ + "CVE-2024-42678" + ], + "details": "Cross Site Scripting vulnerability in Super easy enterprise management system v.1.0.0 and before allows a local attacker to execute arbitrary code via a crafted script to the /WebSet/DlgGridSet.html component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42678" + }, + { + "type": "WEB", + "url": "https://github.com/WarmBrew/web_vul/blob/main/CYGLXT/CYxss.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T14:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-qm84-v26j-7pch/GHSA-qm84-v26j-7pch.json b/advisories/unreviewed/2024/08/GHSA-qm84-v26j-7pch/GHSA-qm84-v26j-7pch.json new file mode 100644 index 00000000000..1d53e4dc986 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-qm84-v26j-7pch/GHSA-qm84-v26j-7pch.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qm84-v26j-7pch", + "modified": "2024-08-15T15:30:58Z", + "published": "2024-08-15T15:30:58Z", + "aliases": [ + "CVE-2024-6347" + ], + "details": "* Unprotected privileged mode access through UDS session in the Blind Spot Detection Sensor ECU firmware in Nissan Altima (2022) allows attackers to trigger denial-of-service (DoS) by unauthorized access to the ECU's programming session.\n * No preconditions implemented for ECU management functionality through UDS session in the Blind Spot Detection Sensor ECU in Nissan Altima (2022) allows attackers to disrupt normal ECU operations by triggering a control command without authentication.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:D/RE:H/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6347" + }, + { + "type": "WEB", + "url": "https://asrg.io/security-advisories/CVE-2024-6347" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-285" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T15:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-rmh7-px2g-m7q9/GHSA-rmh7-px2g-m7q9.json b/advisories/unreviewed/2024/08/GHSA-rmh7-px2g-m7q9/GHSA-rmh7-px2g-m7q9.json index 27c524002a3..9bd27e948a7 100644 --- a/advisories/unreviewed/2024/08/GHSA-rmh7-px2g-m7q9/GHSA-rmh7-px2g-m7q9.json +++ b/advisories/unreviewed/2024/08/GHSA-rmh7-px2g-m7q9/GHSA-rmh7-px2g-m7q9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rmh7-px2g-m7q9", - "modified": "2024-08-12T15:30:50Z", + "modified": "2024-08-15T15:30:54Z", "published": "2024-08-12T15:30:50Z", "aliases": [ "CVE-2024-40480" ], "details": "A Broken Access Control vulnerability was found in /admin/update.php and /admin/dashboard.php in Kashipara Online Exam System v1.0, which allows remote unauthenticated attackers to view administrator dashboard and delete valid user accounts via the direct URL access.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-12T13:38:29Z" diff --git a/advisories/unreviewed/2024/08/GHSA-w7jw-hpw6-gm22/GHSA-w7jw-hpw6-gm22.json b/advisories/unreviewed/2024/08/GHSA-w7jw-hpw6-gm22/GHSA-w7jw-hpw6-gm22.json new file mode 100644 index 00000000000..11fa149af69 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-w7jw-hpw6-gm22/GHSA-w7jw-hpw6-gm22.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w7jw-hpw6-gm22", + "modified": "2024-08-15T15:30:58Z", + "published": "2024-08-15T15:30:58Z", + "aliases": [ + "CVE-2024-42679" + ], + "details": "SQL Injection vulnerability in Super easy enterprise management system v.1.0.0 and before allows a local attacker to execute arbitrary code via a crafted script to the/ajax/Login.ashx component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42679" + }, + { + "type": "WEB", + "url": "https://github.com/WarmBrew/web_vul/blob/main/CYGLXT/CYsqli.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T14:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-wcjv-6xqv-vm87/GHSA-wcjv-6xqv-vm87.json b/advisories/unreviewed/2024/08/GHSA-wcjv-6xqv-vm87/GHSA-wcjv-6xqv-vm87.json new file mode 100644 index 00000000000..88fb05ee754 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-wcjv-6xqv-vm87/GHSA-wcjv-6xqv-vm87.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wcjv-6xqv-vm87", + "modified": "2024-08-15T15:30:58Z", + "published": "2024-08-15T15:30:58Z", + "aliases": [ + "CVE-2024-7832" + ], + "details": "** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240814 and classified as critical. Affected by this issue is the function cgi_get_fullscreen_photos of the file /cgi-bin/photocenter_mgr.cgi. The manipulation of the argument user leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed that the product is end-of-life. It should be retired and replaced.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7832" + }, + { + "type": "WEB", + "url": "https://github.com/BuaaIOTTeam/Iot_Dlink_NAS/blob/main/DNS_cgi_get_fullscreen_photos.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.274730" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.274730" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.390120" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T14:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-wj37-798j-hmqr/GHSA-wj37-798j-hmqr.json b/advisories/unreviewed/2024/08/GHSA-wj37-798j-hmqr/GHSA-wj37-798j-hmqr.json new file mode 100644 index 00000000000..b961908ff79 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-wj37-798j-hmqr/GHSA-wj37-798j-hmqr.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wj37-798j-hmqr", + "modified": "2024-08-15T15:30:58Z", + "published": "2024-08-15T15:30:58Z", + "aliases": [ + "CVE-2024-42680" + ], + "details": "An issue in Super easy enterprise management system v.1.0.0 and before allows a local attacker to obtain the server absolute path by entering a single quotation mark.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42680" + }, + { + "type": "WEB", + "url": "https://github.com/WarmBrew/web_vul/blob/main/CYGLXT/CYinfo.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T14:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-xx3f-44rh-4g76/GHSA-xx3f-44rh-4g76.json b/advisories/unreviewed/2024/08/GHSA-xx3f-44rh-4g76/GHSA-xx3f-44rh-4g76.json new file mode 100644 index 00000000000..07202f95e27 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-xx3f-44rh-4g76/GHSA-xx3f-44rh-4g76.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xx3f-44rh-4g76", + "modified": "2024-08-15T15:30:59Z", + "published": "2024-08-15T15:30:58Z", + "aliases": [ + "CVE-2024-7263" + ], + "details": "Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.13489 on Windows allows an attacker to load an arbitrary Windows library.\nThe patch released in version 12.2.0.16909 to mitigate CVE-2024-7262 was not restrictive enough. Another hyperlink parameter was not properly sanitized which leads to the execution of an arbitrary Windows library.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7263" + }, + { + "type": "WEB", + "url": "https://www.wps.com/whatsnew/pc/20240422" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T15:15:22Z" + } +} \ No newline at end of file