From 346b3edd14178474be87f032428d28fbcda20754 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 9 Sep 2024 18:31:55 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-9442-gm4v-r222.json | 10 +++- .../GHSA-24cp-26gx-3pp4.json | 2 +- .../GHSA-fqmx-726h-7gqj.json | 6 +- .../GHSA-f5w9-q8fj-h9jj.json | 1 + .../GHSA-q8rm-wvjp-6qf3.json | 3 +- .../GHSA-r64q-rcp8-3m38.json | 3 +- .../GHSA-q7g5-xr2p-fg3x.json | 6 +- .../GHSA-rh3f-hr59-rp4x.json | 10 +++- .../GHSA-4mfw-p7jh-v87q.json | 6 +- .../GHSA-gxv5-57fj-mhw8.json | 6 +- .../GHSA-mhpp-qp2h-82p4.json | 6 +- .../GHSA-v3rg-qw8m-86w2.json | 6 +- .../GHSA-vq62-g7qj-xg4r.json | 6 +- .../GHSA-w8gw-mmv6-g6v6.json | 6 +- .../GHSA-28x5-qjqx-j9fr.json | 3 +- .../GHSA-2cj3-6xfh-2wmc.json | 11 ++-- .../GHSA-2g6w-xwmj-mfw7.json | 11 ++-- .../GHSA-52j9-mgvj-v9gh.json | 11 ++-- .../GHSA-56x4-xcpf-4jmq.json | 11 ++-- .../GHSA-66mx-vw67-wmq9.json | 11 ++-- .../GHSA-6pg5-rgpc-92pf.json | 9 ++- .../GHSA-crw5-qp92-p6m7.json | 11 ++-- .../GHSA-f6m9-qfp4-rphw.json | 11 ++-- .../GHSA-fm8x-479m-f33c.json | 11 ++-- .../GHSA-g7g4-7563-37xc.json | 11 ++-- .../GHSA-r49f-c964-6w6w.json | 11 ++-- .../GHSA-r7xw-j6rq-f93p.json | 11 ++-- .../GHSA-wjwm-hw3c-78ch.json | 9 ++- .../GHSA-289h-8w4r-w2wx.json | 39 +++++++++++++ .../GHSA-2g39-9g29-w79c.json | 2 +- .../GHSA-35xg-724r-fcfx.json | 11 ++-- .../GHSA-3683-hgvx-mjx6.json | 2 +- .../GHSA-385q-2f2c-f3c9.json | 2 +- .../GHSA-5pj7-xh4x-q82m.json | 2 +- .../GHSA-6c48-fh55-hjmq.json | 11 ++-- .../GHSA-726x-rvqx-m6j6.json | 39 +++++++++++++ .../GHSA-7w4r-xxr6-xrcj.json | 6 +- .../GHSA-92qf-v5hc-8737.json | 39 +++++++++++++ .../GHSA-9xxg-2v8x-4j8c.json | 2 +- .../GHSA-c76v-gjqc-j462.json | 2 +- .../GHSA-cr4f-2vx6-mjcv.json | 2 +- .../GHSA-crqm-pwhx-j97f.json | 9 ++- .../GHSA-gf29-3f4w-753g.json | 54 +++++++++++++++++ .../GHSA-hhqv-m4px-5qwj.json | 58 +++++++++++++++++++ .../GHSA-j2gh-426h-92wp.json | 2 +- .../GHSA-j3hj-xxh9-4p6j.json | 2 +- .../GHSA-mmmq-786f-84xq.json | 35 +++++++++++ .../GHSA-phhc-p9jg-cvj3.json | 39 +++++++++++++ .../GHSA-v94f-69x2-68gg.json | 2 +- .../GHSA-xmm6-qh3x-mprv.json | 38 ++++++++++++ 50 files changed, 531 insertions(+), 86 deletions(-) create mode 100644 advisories/unreviewed/2024/09/GHSA-289h-8w4r-w2wx/GHSA-289h-8w4r-w2wx.json create mode 100644 advisories/unreviewed/2024/09/GHSA-726x-rvqx-m6j6/GHSA-726x-rvqx-m6j6.json create mode 100644 advisories/unreviewed/2024/09/GHSA-92qf-v5hc-8737/GHSA-92qf-v5hc-8737.json create mode 100644 advisories/unreviewed/2024/09/GHSA-gf29-3f4w-753g/GHSA-gf29-3f4w-753g.json create mode 100644 advisories/unreviewed/2024/09/GHSA-hhqv-m4px-5qwj/GHSA-hhqv-m4px-5qwj.json create mode 100644 advisories/unreviewed/2024/09/GHSA-mmmq-786f-84xq/GHSA-mmmq-786f-84xq.json create mode 100644 advisories/unreviewed/2024/09/GHSA-phhc-p9jg-cvj3/GHSA-phhc-p9jg-cvj3.json create mode 100644 advisories/unreviewed/2024/09/GHSA-xmm6-qh3x-mprv/GHSA-xmm6-qh3x-mprv.json diff --git a/advisories/github-reviewed/2024/06/GHSA-9442-gm4v-r222/GHSA-9442-gm4v-r222.json b/advisories/github-reviewed/2024/06/GHSA-9442-gm4v-r222/GHSA-9442-gm4v-r222.json index d4af6af7839..b7034b98629 100644 --- a/advisories/github-reviewed/2024/06/GHSA-9442-gm4v-r222/GHSA-9442-gm4v-r222.json +++ b/advisories/github-reviewed/2024/06/GHSA-9442-gm4v-r222/GHSA-9442-gm4v-r222.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9442-gm4v-r222", - "modified": "2024-08-05T16:35:42Z", + "modified": "2024-09-09T18:30:28Z", "published": "2024-06-20T15:31:19Z", "aliases": [ "CVE-2024-6162" @@ -44,6 +44,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6162" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:1194" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:4386" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:4884" diff --git a/advisories/unreviewed/2022/05/GHSA-24cp-26gx-3pp4/GHSA-24cp-26gx-3pp4.json b/advisories/unreviewed/2022/05/GHSA-24cp-26gx-3pp4/GHSA-24cp-26gx-3pp4.json index a3adc5bf1f9..23a2e67cca9 100644 --- a/advisories/unreviewed/2022/05/GHSA-24cp-26gx-3pp4/GHSA-24cp-26gx-3pp4.json +++ b/advisories/unreviewed/2022/05/GHSA-24cp-26gx-3pp4/GHSA-24cp-26gx-3pp4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-24cp-26gx-3pp4", - "modified": "2022-05-14T01:10:36Z", + "modified": "2024-09-09T18:30:28Z", "published": "2022-05-14T01:10:36Z", "aliases": [ "CVE-2016-3714" diff --git a/advisories/unreviewed/2022/05/GHSA-fqmx-726h-7gqj/GHSA-fqmx-726h-7gqj.json b/advisories/unreviewed/2022/05/GHSA-fqmx-726h-7gqj/GHSA-fqmx-726h-7gqj.json index 2b2615e9c8e..4bbf32fd5ca 100644 --- a/advisories/unreviewed/2022/05/GHSA-fqmx-726h-7gqj/GHSA-fqmx-726h-7gqj.json +++ b/advisories/unreviewed/2022/05/GHSA-fqmx-726h-7gqj/GHSA-fqmx-726h-7gqj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fqmx-726h-7gqj", - "modified": "2022-05-13T01:33:08Z", + "modified": "2024-09-09T18:30:27Z", "published": "2022-05-13T01:33:08Z", "aliases": [ "CVE-2018-1546" @@ -28,6 +28,10 @@ { "type": "WEB", "url": "https://www-prd-trops.events.ibm.com/node/715299" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/715299" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-f5w9-q8fj-h9jj/GHSA-f5w9-q8fj-h9jj.json b/advisories/unreviewed/2023/10/GHSA-f5w9-q8fj-h9jj/GHSA-f5w9-q8fj-h9jj.json index 74a0a9992c8..4e0e13ccc95 100644 --- a/advisories/unreviewed/2023/10/GHSA-f5w9-q8fj-h9jj/GHSA-f5w9-q8fj-h9jj.json +++ b/advisories/unreviewed/2023/10/GHSA-f5w9-q8fj-h9jj/GHSA-f5w9-q8fj-h9jj.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-276", "CWE-94" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/10/GHSA-q8rm-wvjp-6qf3/GHSA-q8rm-wvjp-6qf3.json b/advisories/unreviewed/2023/10/GHSA-q8rm-wvjp-6qf3/GHSA-q8rm-wvjp-6qf3.json index c831cfb81c7..19bcbc784db 100644 --- a/advisories/unreviewed/2023/10/GHSA-q8rm-wvjp-6qf3/GHSA-q8rm-wvjp-6qf3.json +++ b/advisories/unreviewed/2023/10/GHSA-q8rm-wvjp-6qf3/GHSA-q8rm-wvjp-6qf3.json @@ -36,7 +36,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-665" + "CWE-665", + "CWE-94" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-r64q-rcp8-3m38/GHSA-r64q-rcp8-3m38.json b/advisories/unreviewed/2023/10/GHSA-r64q-rcp8-3m38/GHSA-r64q-rcp8-3m38.json index 45208aba3e3..1377cae97d1 100644 --- a/advisories/unreviewed/2023/10/GHSA-r64q-rcp8-3m38/GHSA-r64q-rcp8-3m38.json +++ b/advisories/unreviewed/2023/10/GHSA-r64q-rcp8-3m38/GHSA-r64q-rcp8-3m38.json @@ -36,7 +36,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-665" + "CWE-665", + "CWE-94" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-q7g5-xr2p-fg3x/GHSA-q7g5-xr2p-fg3x.json b/advisories/unreviewed/2024/03/GHSA-q7g5-xr2p-fg3x/GHSA-q7g5-xr2p-fg3x.json index 7e36c5f68ea..a7a9e93e005 100644 --- a/advisories/unreviewed/2024/03/GHSA-q7g5-xr2p-fg3x/GHSA-q7g5-xr2p-fg3x.json +++ b/advisories/unreviewed/2024/03/GHSA-q7g5-xr2p-fg3x/GHSA-q7g5-xr2p-fg3x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q7g5-xr2p-fg3x", - "modified": "2024-03-27T00:30:54Z", + "modified": "2024-09-09T18:30:28Z", "published": "2024-03-27T00:30:54Z", "aliases": [ "CVE-2024-2911" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/03/GHSA-rh3f-hr59-rp4x/GHSA-rh3f-hr59-rp4x.json b/advisories/unreviewed/2024/03/GHSA-rh3f-hr59-rp4x/GHSA-rh3f-hr59-rp4x.json index 39558691d29..cf0df380989 100644 --- a/advisories/unreviewed/2024/03/GHSA-rh3f-hr59-rp4x/GHSA-rh3f-hr59-rp4x.json +++ b/advisories/unreviewed/2024/03/GHSA-rh3f-hr59-rp4x/GHSA-rh3f-hr59-rp4x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rh3f-hr59-rp4x", - "modified": "2024-03-27T03:31:16Z", + "modified": "2024-09-09T18:30:28Z", "published": "2024-03-27T03:31:16Z", "aliases": [ "CVE-2024-2935" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ @@ -36,6 +40,10 @@ { "type": "WEB", "url": "https://vuldb.com/?submit.304678" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/06/GHSA-4mfw-p7jh-v87q/GHSA-4mfw-p7jh-v87q.json b/advisories/unreviewed/2024/06/GHSA-4mfw-p7jh-v87q/GHSA-4mfw-p7jh-v87q.json index 7ae086785d9..f95dc12cee2 100644 --- a/advisories/unreviewed/2024/06/GHSA-4mfw-p7jh-v87q/GHSA-4mfw-p7jh-v87q.json +++ b/advisories/unreviewed/2024/06/GHSA-4mfw-p7jh-v87q/GHSA-4mfw-p7jh-v87q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4mfw-p7jh-v87q", - "modified": "2024-06-24T03:30:37Z", + "modified": "2024-09-09T18:30:28Z", "published": "2024-06-24T03:30:37Z", "aliases": [ "CVE-2024-6274" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/06/GHSA-gxv5-57fj-mhw8/GHSA-gxv5-57fj-mhw8.json b/advisories/unreviewed/2024/06/GHSA-gxv5-57fj-mhw8/GHSA-gxv5-57fj-mhw8.json index b46b1ed90f6..2984b232e5e 100644 --- a/advisories/unreviewed/2024/06/GHSA-gxv5-57fj-mhw8/GHSA-gxv5-57fj-mhw8.json +++ b/advisories/unreviewed/2024/06/GHSA-gxv5-57fj-mhw8/GHSA-gxv5-57fj-mhw8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gxv5-57fj-mhw8", - "modified": "2024-06-24T03:30:37Z", + "modified": "2024-09-09T18:30:28Z", "published": "2024-06-24T03:30:37Z", "aliases": [ "CVE-2024-6279" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/06/GHSA-mhpp-qp2h-82p4/GHSA-mhpp-qp2h-82p4.json b/advisories/unreviewed/2024/06/GHSA-mhpp-qp2h-82p4/GHSA-mhpp-qp2h-82p4.json index 22278a206fa..7dcc668e6bd 100644 --- a/advisories/unreviewed/2024/06/GHSA-mhpp-qp2h-82p4/GHSA-mhpp-qp2h-82p4.json +++ b/advisories/unreviewed/2024/06/GHSA-mhpp-qp2h-82p4/GHSA-mhpp-qp2h-82p4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mhpp-qp2h-82p4", - "modified": "2024-06-24T03:30:37Z", + "modified": "2024-09-09T18:30:28Z", "published": "2024-06-24T03:30:37Z", "aliases": [ "CVE-2024-6275" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/06/GHSA-v3rg-qw8m-86w2/GHSA-v3rg-qw8m-86w2.json b/advisories/unreviewed/2024/06/GHSA-v3rg-qw8m-86w2/GHSA-v3rg-qw8m-86w2.json index 0c0737f00cb..fce29e8fb55 100644 --- a/advisories/unreviewed/2024/06/GHSA-v3rg-qw8m-86w2/GHSA-v3rg-qw8m-86w2.json +++ b/advisories/unreviewed/2024/06/GHSA-v3rg-qw8m-86w2/GHSA-v3rg-qw8m-86w2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v3rg-qw8m-86w2", - "modified": "2024-06-24T03:30:37Z", + "modified": "2024-09-09T18:30:28Z", "published": "2024-06-24T03:30:37Z", "aliases": [ "CVE-2024-6276" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/06/GHSA-vq62-g7qj-xg4r/GHSA-vq62-g7qj-xg4r.json b/advisories/unreviewed/2024/06/GHSA-vq62-g7qj-xg4r/GHSA-vq62-g7qj-xg4r.json index 6dbdf66d0da..fd68ae757da 100644 --- a/advisories/unreviewed/2024/06/GHSA-vq62-g7qj-xg4r/GHSA-vq62-g7qj-xg4r.json +++ b/advisories/unreviewed/2024/06/GHSA-vq62-g7qj-xg4r/GHSA-vq62-g7qj-xg4r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vq62-g7qj-xg4r", - "modified": "2024-06-24T03:30:37Z", + "modified": "2024-09-09T18:30:28Z", "published": "2024-06-24T03:30:37Z", "aliases": [ "CVE-2024-6277" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/06/GHSA-w8gw-mmv6-g6v6/GHSA-w8gw-mmv6-g6v6.json b/advisories/unreviewed/2024/06/GHSA-w8gw-mmv6-g6v6/GHSA-w8gw-mmv6-g6v6.json index 9f21ef673a6..4eb78fe4a0d 100644 --- a/advisories/unreviewed/2024/06/GHSA-w8gw-mmv6-g6v6/GHSA-w8gw-mmv6-g6v6.json +++ b/advisories/unreviewed/2024/06/GHSA-w8gw-mmv6-g6v6/GHSA-w8gw-mmv6-g6v6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w8gw-mmv6-g6v6", - "modified": "2024-06-24T03:30:37Z", + "modified": "2024-09-09T18:30:28Z", "published": "2024-06-24T03:30:37Z", "aliases": [ "CVE-2024-6278" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/07/GHSA-28x5-qjqx-j9fr/GHSA-28x5-qjqx-j9fr.json b/advisories/unreviewed/2024/07/GHSA-28x5-qjqx-j9fr/GHSA-28x5-qjqx-j9fr.json index 9f257c546bf..7fd3627b04a 100644 --- a/advisories/unreviewed/2024/07/GHSA-28x5-qjqx-j9fr/GHSA-28x5-qjqx-j9fr.json +++ b/advisories/unreviewed/2024/07/GHSA-28x5-qjqx-j9fr/GHSA-28x5-qjqx-j9fr.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-1389" + "CWE-1389", + "CWE-704" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-2cj3-6xfh-2wmc/GHSA-2cj3-6xfh-2wmc.json b/advisories/unreviewed/2024/07/GHSA-2cj3-6xfh-2wmc/GHSA-2cj3-6xfh-2wmc.json index efe6a25c05e..86a6310bf24 100644 --- a/advisories/unreviewed/2024/07/GHSA-2cj3-6xfh-2wmc/GHSA-2cj3-6xfh-2wmc.json +++ b/advisories/unreviewed/2024/07/GHSA-2cj3-6xfh-2wmc/GHSA-2cj3-6xfh-2wmc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2cj3-6xfh-2wmc", - "modified": "2024-07-12T15:31:29Z", + "modified": "2024-09-09T18:30:29Z", "published": "2024-07-12T15:31:29Z", "aliases": [ "CVE-2024-40982" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nssb: Fix potential NULL pointer dereference in ssb_device_uevent()\n\nThe ssb_device_uevent() function first attempts to convert the 'dev' pointer\nto 'struct ssb_device *'. However, it mistakenly dereferences 'dev' before\nperforming the NULL check, potentially leading to a NULL pointer\ndereference if 'dev' is NULL.\n\nTo fix this issue, move the NULL check before dereferencing the 'dev' pointer,\nensuring that the pointer is valid before attempting to use it.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-12T13:15:19Z" diff --git a/advisories/unreviewed/2024/07/GHSA-2g6w-xwmj-mfw7/GHSA-2g6w-xwmj-mfw7.json b/advisories/unreviewed/2024/07/GHSA-2g6w-xwmj-mfw7/GHSA-2g6w-xwmj-mfw7.json index e32f6ee5d92..08562f2b179 100644 --- a/advisories/unreviewed/2024/07/GHSA-2g6w-xwmj-mfw7/GHSA-2g6w-xwmj-mfw7.json +++ b/advisories/unreviewed/2024/07/GHSA-2g6w-xwmj-mfw7/GHSA-2g6w-xwmj-mfw7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2g6w-xwmj-mfw7", - "modified": "2024-07-12T15:31:29Z", + "modified": "2024-09-09T18:30:29Z", "published": "2024-07-12T15:31:29Z", "aliases": [ "CVE-2024-40980" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrop_monitor: replace spin_lock by raw_spin_lock\n\ntrace_drop_common() is called with preemption disabled, and it acquires\na spin_lock. This is problematic for RT kernels because spin_locks are\nsleeping locks in this configuration, which causes the following splat:\n\nBUG: sleeping function called from invalid context at kernel/locking/spinlock_rt.c:48\nin_atomic(): 1, irqs_disabled(): 1, non_block: 0, pid: 449, name: rcuc/47\npreempt_count: 1, expected: 0\nRCU nest depth: 2, expected: 2\n5 locks held by rcuc/47/449:\n #0: ff1100086ec30a60 ((softirq_ctrl.lock)){+.+.}-{2:2}, at: __local_bh_disable_ip+0x105/0x210\n #1: ffffffffb394a280 (rcu_read_lock){....}-{1:2}, at: rt_spin_lock+0xbf/0x130\n #2: ffffffffb394a280 (rcu_read_lock){....}-{1:2}, at: __local_bh_disable_ip+0x11c/0x210\n #3: ffffffffb394a160 (rcu_callback){....}-{0:0}, at: rcu_do_batch+0x360/0xc70\n #4: ff1100086ee07520 (&data->lock){+.+.}-{2:2}, at: trace_drop_common.constprop.0+0xb5/0x290\nirq event stamp: 139909\nhardirqs last enabled at (139908): [] _raw_spin_unlock_irqrestore+0x63/0x80\nhardirqs last disabled at (139909): [] trace_drop_common.constprop.0+0x26d/0x290\nsoftirqs last enabled at (139892): [] __local_bh_enable_ip+0x103/0x170\nsoftirqs last disabled at (139898): [] rcu_cpu_kthread+0x93/0x1f0\nPreemption disabled at:\n[] rt_mutex_slowunlock+0xab/0x2e0\nCPU: 47 PID: 449 Comm: rcuc/47 Not tainted 6.9.0-rc2-rt1+ #7\nHardware name: Dell Inc. PowerEdge R650/0Y2G81, BIOS 1.6.5 04/15/2022\nCall Trace:\n \n dump_stack_lvl+0x8c/0xd0\n dump_stack+0x14/0x20\n __might_resched+0x21e/0x2f0\n rt_spin_lock+0x5e/0x130\n ? trace_drop_common.constprop.0+0xb5/0x290\n ? skb_queue_purge_reason.part.0+0x1bf/0x230\n trace_drop_common.constprop.0+0xb5/0x290\n ? preempt_count_sub+0x1c/0xd0\n ? _raw_spin_unlock_irqrestore+0x4a/0x80\n ? __pfx_trace_drop_common.constprop.0+0x10/0x10\n ? rt_mutex_slowunlock+0x26a/0x2e0\n ? skb_queue_purge_reason.part.0+0x1bf/0x230\n ? __pfx_rt_mutex_slowunlock+0x10/0x10\n ? skb_queue_purge_reason.part.0+0x1bf/0x230\n trace_kfree_skb_hit+0x15/0x20\n trace_kfree_skb+0xe9/0x150\n kfree_skb_reason+0x7b/0x110\n skb_queue_purge_reason.part.0+0x1bf/0x230\n ? __pfx_skb_queue_purge_reason.part.0+0x10/0x10\n ? mark_lock.part.0+0x8a/0x520\n...\n\ntrace_drop_common() also disables interrupts, but this is a minor issue\nbecause we could easily replace it with a local_lock.\n\nReplace the spin_lock with raw_spin_lock to avoid sleeping in atomic\ncontext.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -49,9 +52,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-667" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-12T13:15:19Z" diff --git a/advisories/unreviewed/2024/07/GHSA-52j9-mgvj-v9gh/GHSA-52j9-mgvj-v9gh.json b/advisories/unreviewed/2024/07/GHSA-52j9-mgvj-v9gh/GHSA-52j9-mgvj-v9gh.json index 82f2f42f35d..11be77c0a7c 100644 --- a/advisories/unreviewed/2024/07/GHSA-52j9-mgvj-v9gh/GHSA-52j9-mgvj-v9gh.json +++ b/advisories/unreviewed/2024/07/GHSA-52j9-mgvj-v9gh/GHSA-52j9-mgvj-v9gh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-52j9-mgvj-v9gh", - "modified": "2024-07-12T15:31:26Z", + "modified": "2024-09-09T18:30:29Z", "published": "2024-07-12T15:31:26Z", "aliases": [ "CVE-2024-39498" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/mst: Fix NULL pointer dereference at drm_dp_add_payload_part2\n\n[Why]\nCommit:\n- commit 5aa1dfcdf0a4 (\"drm/mst: Refactor the flow for payload allocation/removement\")\naccidently overwrite the commit\n- commit 54d217406afe (\"drm: use mgr->dev in drm_dbg_kms in drm_dp_add_payload_part2\")\nwhich cause regression.\n\n[How]\nRecover the original NULL fix and remove the unnecessary input parameter 'state' for\ndrm_dp_add_payload_part2().\n\n(cherry picked from commit 4545614c1d8da603e57b60dd66224d81b6ffc305)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-12T13:15:12Z" diff --git a/advisories/unreviewed/2024/07/GHSA-56x4-xcpf-4jmq/GHSA-56x4-xcpf-4jmq.json b/advisories/unreviewed/2024/07/GHSA-56x4-xcpf-4jmq/GHSA-56x4-xcpf-4jmq.json index 5ac6deaf8ee..4e1a98e7b37 100644 --- a/advisories/unreviewed/2024/07/GHSA-56x4-xcpf-4jmq/GHSA-56x4-xcpf-4jmq.json +++ b/advisories/unreviewed/2024/07/GHSA-56x4-xcpf-4jmq/GHSA-56x4-xcpf-4jmq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-56x4-xcpf-4jmq", - "modified": "2024-07-16T12:30:40Z", + "modified": "2024-09-09T18:30:29Z", "published": "2024-07-16T12:30:40Z", "aliases": [ "CVE-2022-48804" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nvt_ioctl: fix array_index_nospec in vt_setactivate\n\narray_index_nospec ensures that an out-of-bounds value is set to zero\non the transient path. Decreasing the value by one afterwards causes\na transient integer underflow. vsa.console should be decreased first\nand then sanitized with array_index_nospec.\n\nKasper Acknowledgements: Jakob Koschel, Brian Johannesmeyer, Kaveh\nRazavi, Herbert Bos, Cristiano Giuffrida from the VUSec group at VU\nAmsterdam.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-191" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-16T12:15:04Z" diff --git a/advisories/unreviewed/2024/07/GHSA-66mx-vw67-wmq9/GHSA-66mx-vw67-wmq9.json b/advisories/unreviewed/2024/07/GHSA-66mx-vw67-wmq9/GHSA-66mx-vw67-wmq9.json index 1ac518f45e4..babe2fe19e3 100644 --- a/advisories/unreviewed/2024/07/GHSA-66mx-vw67-wmq9/GHSA-66mx-vw67-wmq9.json +++ b/advisories/unreviewed/2024/07/GHSA-66mx-vw67-wmq9/GHSA-66mx-vw67-wmq9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-66mx-vw67-wmq9", - "modified": "2024-07-12T15:31:29Z", + "modified": "2024-09-09T18:30:29Z", "published": "2024-07-12T15:31:29Z", "aliases": [ "CVE-2024-40981" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbatman-adv: bypass empty buckets in batadv_purge_orig_ref()\n\nMany syzbot reports are pointing to soft lockups in\nbatadv_purge_orig_ref() [1]\n\nRoot cause is unknown, but we can avoid spending too much\ntime there and perhaps get more interesting reports.\n\n[1]\n\nwatchdog: BUG: soft lockup - CPU#0 stuck for 27s! [kworker/u4:6:621]\nModules linked in:\nirq event stamp: 6182794\n hardirqs last enabled at (6182793): [] __local_bh_enable_ip+0x224/0x44c kernel/softirq.c:386\n hardirqs last disabled at (6182794): [] __el1_irq arch/arm64/kernel/entry-common.c:533 [inline]\n hardirqs last disabled at (6182794): [] el1_interrupt+0x24/0x68 arch/arm64/kernel/entry-common.c:551\n softirqs last enabled at (6182792): [] spin_unlock_bh include/linux/spinlock.h:396 [inline]\n softirqs last enabled at (6182792): [] batadv_purge_orig_ref+0x114c/0x1228 net/batman-adv/originator.c:1287\n softirqs last disabled at (6182790): [] spin_lock_bh include/linux/spinlock.h:356 [inline]\n softirqs last disabled at (6182790): [] batadv_purge_orig_ref+0x164/0x1228 net/batman-adv/originator.c:1271\nCPU: 0 PID: 621 Comm: kworker/u4:6 Not tainted 6.8.0-rc7-syzkaller-g707081b61156 #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 02/29/2024\nWorkqueue: bat_events batadv_purge_orig\npstate: 80400005 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n pc : should_resched arch/arm64/include/asm/preempt.h:79 [inline]\n pc : __local_bh_enable_ip+0x228/0x44c kernel/softirq.c:388\n lr : __local_bh_enable_ip+0x224/0x44c kernel/softirq.c:386\nsp : ffff800099007970\nx29: ffff800099007980 x28: 1fffe00018fce1bd x27: dfff800000000000\nx26: ffff0000d2620008 x25: ffff0000c7e70de8 x24: 0000000000000001\nx23: 1fffe00018e57781 x22: dfff800000000000 x21: ffff80008aab71c4\nx20: ffff0001b40136c0 x19: ffff0000c72bbc08 x18: 1fffe0001a817bb0\nx17: ffff800125414000 x16: ffff80008032116c x15: 0000000000000001\nx14: 1fffe0001ee9d610 x13: 0000000000000000 x12: 0000000000000003\nx11: 0000000000000000 x10: 0000000000ff0100 x9 : 0000000000000000\nx8 : 00000000005e5789 x7 : ffff80008aab61dc x6 : 0000000000000000\nx5 : 0000000000000000 x4 : 0000000000000001 x3 : 0000000000000000\nx2 : 0000000000000006 x1 : 0000000000000080 x0 : ffff800125414000\nCall trace:\n __daif_local_irq_enable arch/arm64/include/asm/irqflags.h:27 [inline]\n arch_local_irq_enable arch/arm64/include/asm/irqflags.h:49 [inline]\n __local_bh_enable_ip+0x228/0x44c kernel/softirq.c:386\n __raw_spin_unlock_bh include/linux/spinlock_api_smp.h:167 [inline]\n _raw_spin_unlock_bh+0x3c/0x4c kernel/locking/spinlock.c:210\n spin_unlock_bh include/linux/spinlock.h:396 [inline]\n batadv_purge_orig_ref+0x114c/0x1228 net/batman-adv/originator.c:1287\n batadv_purge_orig+0x20/0x70 net/batman-adv/originator.c:1300\n process_one_work+0x694/0x1204 kernel/workqueue.c:2633\n process_scheduled_works kernel/workqueue.c:2706 [inline]\n worker_thread+0x938/0xef4 kernel/workqueue.c:2787\n kthread+0x288/0x310 kernel/kthread.c:388\n ret_from_fork+0x10/0x20 arch/arm64/kernel/entry.S:860\nSending NMI from CPU 0 to CPUs 1:\nNMI backtrace for cpu 1\nCPU: 1 PID: 0 Comm: swapper/1 Not tainted 6.8.0-rc7-syzkaller-g707081b61156 #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 02/29/2024\npstate: 80400005 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n pc : arch_local_irq_enable+0x8/0xc arch/arm64/include/asm/irqflags.h:51\n lr : default_idle_call+0xf8/0x128 kernel/sched/idle.c:103\nsp : ffff800093a17d30\nx29: ffff800093a17d30 x28: dfff800000000000 x27: 1ffff00012742fb4\nx26: ffff80008ec9d000 x25: 0000000000000000 x24: 0000000000000002\nx23: 1ffff00011d93a74 x22: ffff80008ec9d3a0 x21: 0000000000000000\nx20: ffff0000c19dbc00 x19: ffff8000802d0fd8 x18: 1fffe00036804396\nx17: ffff80008ec9d000 x16: ffff8000802d089c x15: 0000000000000001\n---truncated---", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-667" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-12T13:15:19Z" diff --git a/advisories/unreviewed/2024/07/GHSA-6pg5-rgpc-92pf/GHSA-6pg5-rgpc-92pf.json b/advisories/unreviewed/2024/07/GHSA-6pg5-rgpc-92pf/GHSA-6pg5-rgpc-92pf.json index 54f011bd9a8..ebe811433c3 100644 --- a/advisories/unreviewed/2024/07/GHSA-6pg5-rgpc-92pf/GHSA-6pg5-rgpc-92pf.json +++ b/advisories/unreviewed/2024/07/GHSA-6pg5-rgpc-92pf/GHSA-6pg5-rgpc-92pf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6pg5-rgpc-92pf", - "modified": "2024-07-12T15:31:29Z", + "modified": "2024-09-09T18:30:29Z", "published": "2024-07-12T15:31:29Z", "aliases": [ "CVE-2024-40970" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nAvoid hw_desc array overrun in dw-axi-dmac\n\nI have a use case where nr_buffers = 3 and in which each descriptor is composed by 3\nsegments, resulting in the DMA channel descs_allocated to be 9. Since axi_desc_put()\nhandles the hw_desc considering the descs_allocated, this scenario would result in a\nkernel panic (hw_desc array will be overrun).\n\nTo fix this, the proposal is to add a new member to the axi_dma_desc structure,\nwhere we keep the number of allocated hw_descs (axi_desc_alloc()) and use it in\naxi_desc_put() to handle the hw_desc array correctly.\n\nAdditionally I propose to remove the axi_chan_start_first_queued() call after completing\nthe transfer, since it was identified that unbalance can occur (started descriptors can\nbe interrupted and transfer ignored due to DMA channel not being enabled).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -43,7 +46,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-12T13:15:18Z" diff --git a/advisories/unreviewed/2024/07/GHSA-crw5-qp92-p6m7/GHSA-crw5-qp92-p6m7.json b/advisories/unreviewed/2024/07/GHSA-crw5-qp92-p6m7/GHSA-crw5-qp92-p6m7.json index 773d9f15244..6e6d1c4cae4 100644 --- a/advisories/unreviewed/2024/07/GHSA-crw5-qp92-p6m7/GHSA-crw5-qp92-p6m7.json +++ b/advisories/unreviewed/2024/07/GHSA-crw5-qp92-p6m7/GHSA-crw5-qp92-p6m7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-crw5-qp92-p6m7", - "modified": "2024-07-12T15:31:29Z", + "modified": "2024-09-09T18:30:29Z", "published": "2024-07-12T15:31:29Z", "aliases": [ "CVE-2024-40969" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: don't set RO when shutting down f2fs\n\nShutdown does not check the error of thaw_super due to readonly, which\ncauses a deadlock like below.\n\nf2fs_ioc_shutdown(F2FS_GOING_DOWN_FULLSYNC) issue_discard_thread\n - bdev_freeze\n - freeze_super\n - f2fs_stop_checkpoint()\n - f2fs_handle_critical_error - sb_start_write\n - set RO - waiting\n - bdev_thaw\n - thaw_super_locked\n - return -EINVAL, if sb_rdonly()\n - f2fs_stop_discard_thread\n -> wait for kthread_stop(discard_thread);", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-667" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-12T13:15:18Z" diff --git a/advisories/unreviewed/2024/07/GHSA-f6m9-qfp4-rphw/GHSA-f6m9-qfp4-rphw.json b/advisories/unreviewed/2024/07/GHSA-f6m9-qfp4-rphw/GHSA-f6m9-qfp4-rphw.json index 057c5f222be..ca4b1d78af5 100644 --- a/advisories/unreviewed/2024/07/GHSA-f6m9-qfp4-rphw/GHSA-f6m9-qfp4-rphw.json +++ b/advisories/unreviewed/2024/07/GHSA-f6m9-qfp4-rphw/GHSA-f6m9-qfp4-rphw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f6m9-qfp4-rphw", - "modified": "2024-07-12T15:31:28Z", + "modified": "2024-09-09T18:30:29Z", "published": "2024-07-12T15:31:28Z", "aliases": [ "CVE-2024-40967" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nserial: imx: Introduce timeout when waiting on transmitter empty\n\nBy waiting at most 1 second for USR2_TXDC to be set, we avoid a potential\ndeadlock.\n\nIn case of the timeout, there is not much we can do, so we simply ignore\nthe transmitter state and optimistically try to continue.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-667" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-12T13:15:18Z" diff --git a/advisories/unreviewed/2024/07/GHSA-fm8x-479m-f33c/GHSA-fm8x-479m-f33c.json b/advisories/unreviewed/2024/07/GHSA-fm8x-479m-f33c/GHSA-fm8x-479m-f33c.json index 831507777bc..28457bea4ed 100644 --- a/advisories/unreviewed/2024/07/GHSA-fm8x-479m-f33c/GHSA-fm8x-479m-f33c.json +++ b/advisories/unreviewed/2024/07/GHSA-fm8x-479m-f33c/GHSA-fm8x-479m-f33c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fm8x-479m-f33c", - "modified": "2024-07-12T15:31:28Z", + "modified": "2024-09-09T18:30:29Z", "published": "2024-07-12T15:31:28Z", "aliases": [ "CVE-2024-40964" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: hda: cs35l41: Possible null pointer dereference in cs35l41_hda_unbind()\n\nThe cs35l41_hda_unbind() function clears the hda_component entry\nmatching it's index and then dereferences the codec pointer held in the\nfirst element of the hda_component array, this is an issue when the\ndevice index was 0.\n\nInstead use the codec pointer stashed in the cs35l41_hda structure as it\nwill still be valid.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-12T13:15:18Z" diff --git a/advisories/unreviewed/2024/07/GHSA-g7g4-7563-37xc/GHSA-g7g4-7563-37xc.json b/advisories/unreviewed/2024/07/GHSA-g7g4-7563-37xc/GHSA-g7g4-7563-37xc.json index beddcd66cd3..644d0f32d06 100644 --- a/advisories/unreviewed/2024/07/GHSA-g7g4-7563-37xc/GHSA-g7g4-7563-37xc.json +++ b/advisories/unreviewed/2024/07/GHSA-g7g4-7563-37xc/GHSA-g7g4-7563-37xc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g7g4-7563-37xc", - "modified": "2024-07-12T15:31:29Z", + "modified": "2024-09-09T18:30:29Z", "published": "2024-07-12T15:31:29Z", "aliases": [ "CVE-2024-40973" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: mtk-vcodec: potential null pointer deference in SCP\n\nThe return value of devm_kzalloc() needs to be checked to avoid\nNULL pointer deference. This is similar to CVE-2022-3113.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-12T13:15:18Z" diff --git a/advisories/unreviewed/2024/07/GHSA-r49f-c964-6w6w/GHSA-r49f-c964-6w6w.json b/advisories/unreviewed/2024/07/GHSA-r49f-c964-6w6w/GHSA-r49f-c964-6w6w.json index 70b6b4fd6be..60cab265fad 100644 --- a/advisories/unreviewed/2024/07/GHSA-r49f-c964-6w6w/GHSA-r49f-c964-6w6w.json +++ b/advisories/unreviewed/2024/07/GHSA-r49f-c964-6w6w/GHSA-r49f-c964-6w6w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r49f-c964-6w6w", - "modified": "2024-07-12T15:31:28Z", + "modified": "2024-09-09T18:30:29Z", "published": "2024-07-12T15:31:28Z", "aliases": [ "CVE-2024-40965" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ni2c: lpi2c: Avoid calling clk_get_rate during transfer\n\nInstead of repeatedly calling clk_get_rate for each transfer, lock\nthe clock rate and cache the value.\nA deadlock has been observed while adding tlv320aic32x4 audio codec to\nthe system. When this clock provider adds its clock, the clk mutex is\nlocked already, it needs to access i2c, which in return needs the mutex\nfor clk_get_rate as well.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-667" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-12T13:15:18Z" diff --git a/advisories/unreviewed/2024/07/GHSA-r7xw-j6rq-f93p/GHSA-r7xw-j6rq-f93p.json b/advisories/unreviewed/2024/07/GHSA-r7xw-j6rq-f93p/GHSA-r7xw-j6rq-f93p.json index cff176ecd6f..011a197cb6f 100644 --- a/advisories/unreviewed/2024/07/GHSA-r7xw-j6rq-f93p/GHSA-r7xw-j6rq-f93p.json +++ b/advisories/unreviewed/2024/07/GHSA-r7xw-j6rq-f93p/GHSA-r7xw-j6rq-f93p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r7xw-j6rq-f93p", - "modified": "2024-07-12T15:31:29Z", + "modified": "2024-09-09T18:30:29Z", "published": "2024-07-12T15:31:29Z", "aliases": [ "CVE-2024-40977" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: mt7921s: fix potential hung tasks during chip recovery\n\nDuring chip recovery (e.g. chip reset), there is a possible situation that\nkernel worker reset_work is holding the lock and waiting for kernel thread\nstat_worker to be parked, while stat_worker is waiting for the release of\nthe same lock.\nIt causes a deadlock resulting in the dumping of hung tasks messages and\npossible rebooting of the device.\n\nThis patch prevents the execution of stat_worker during the chip recovery.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-667" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-12T13:15:19Z" diff --git a/advisories/unreviewed/2024/07/GHSA-wjwm-hw3c-78ch/GHSA-wjwm-hw3c-78ch.json b/advisories/unreviewed/2024/07/GHSA-wjwm-hw3c-78ch/GHSA-wjwm-hw3c-78ch.json index c59f22f2fd0..72ae493c5c4 100644 --- a/advisories/unreviewed/2024/07/GHSA-wjwm-hw3c-78ch/GHSA-wjwm-hw3c-78ch.json +++ b/advisories/unreviewed/2024/07/GHSA-wjwm-hw3c-78ch/GHSA-wjwm-hw3c-78ch.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wjwm-hw3c-78ch", - "modified": "2024-07-16T12:30:40Z", + "modified": "2024-09-09T18:30:29Z", "published": "2024-07-16T12:30:40Z", "aliases": [ "CVE-2022-48820" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nphy: stm32: fix a refcount leak in stm32_usbphyc_pll_enable()\n\nThis error path needs to decrement \"usbphyc->n_pll_cons.counter\" before\nreturning.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-16T12:15:05Z" diff --git a/advisories/unreviewed/2024/09/GHSA-289h-8w4r-w2wx/GHSA-289h-8w4r-w2wx.json b/advisories/unreviewed/2024/09/GHSA-289h-8w4r-w2wx/GHSA-289h-8w4r-w2wx.json new file mode 100644 index 00000000000..87b2cbf5d83 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-289h-8w4r-w2wx/GHSA-289h-8w4r-w2wx.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-289h-8w4r-w2wx", + "modified": "2024-09-09T18:30:31Z", + "published": "2024-09-09T18:30:31Z", + "aliases": [ + "CVE-2024-44333" + ], + "details": "D-Link DI-7003GV2 v24.04.18D1, DI-7100G+V2 v24.04.18D1, DI-7100GV2 v24.04.18D1, DI-7200GV2 v24.04.18E1, DI-7300G+V2 v24.04.18D1, and DI-7400G+V2 v24.04.18D1 are vulnerable to Remote Command Execution. An attacker can achieve arbitrary command execution by sending a carefully crafted malicious string to the CGI function responsible for handling usb_paswd.asp.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44333" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Swind1er/c8656b32058e28e64f92d100c92ca12c" + }, + { + "type": "WEB", + "url": "https://www.dlink.com/en/security-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-09T17:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-2g39-9g29-w79c/GHSA-2g39-9g29-w79c.json b/advisories/unreviewed/2024/09/GHSA-2g39-9g29-w79c/GHSA-2g39-9g29-w79c.json index 9b550870528..d32c6466306 100644 --- a/advisories/unreviewed/2024/09/GHSA-2g39-9g29-w79c/GHSA-2g39-9g29-w79c.json +++ b/advisories/unreviewed/2024/09/GHSA-2g39-9g29-w79c/GHSA-2g39-9g29-w79c.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-35xg-724r-fcfx/GHSA-35xg-724r-fcfx.json b/advisories/unreviewed/2024/09/GHSA-35xg-724r-fcfx/GHSA-35xg-724r-fcfx.json index f72874fcb7d..5f24d652ca5 100644 --- a/advisories/unreviewed/2024/09/GHSA-35xg-724r-fcfx/GHSA-35xg-724r-fcfx.json +++ b/advisories/unreviewed/2024/09/GHSA-35xg-724r-fcfx/GHSA-35xg-724r-fcfx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-35xg-724r-fcfx", - "modified": "2024-09-07T00:31:29Z", + "modified": "2024-09-09T18:30:29Z", "published": "2024-09-07T00:31:29Z", "aliases": [ "CVE-2024-44839" ], "details": "RapidCMS v1.3.1 was discovered to contain a SQL injection vulnerability via the articleid parameter at /default/article.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-06T22:15:02Z" diff --git a/advisories/unreviewed/2024/09/GHSA-3683-hgvx-mjx6/GHSA-3683-hgvx-mjx6.json b/advisories/unreviewed/2024/09/GHSA-3683-hgvx-mjx6/GHSA-3683-hgvx-mjx6.json index 97e39ecb12e..388bf144692 100644 --- a/advisories/unreviewed/2024/09/GHSA-3683-hgvx-mjx6/GHSA-3683-hgvx-mjx6.json +++ b/advisories/unreviewed/2024/09/GHSA-3683-hgvx-mjx6/GHSA-3683-hgvx-mjx6.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-385q-2f2c-f3c9/GHSA-385q-2f2c-f3c9.json b/advisories/unreviewed/2024/09/GHSA-385q-2f2c-f3c9/GHSA-385q-2f2c-f3c9.json index 76c3b7c3a8e..74e180003f8 100644 --- a/advisories/unreviewed/2024/09/GHSA-385q-2f2c-f3c9/GHSA-385q-2f2c-f3c9.json +++ b/advisories/unreviewed/2024/09/GHSA-385q-2f2c-f3c9/GHSA-385q-2f2c-f3c9.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-5pj7-xh4x-q82m/GHSA-5pj7-xh4x-q82m.json b/advisories/unreviewed/2024/09/GHSA-5pj7-xh4x-q82m/GHSA-5pj7-xh4x-q82m.json index 0859f763993..5b9456a217b 100644 --- a/advisories/unreviewed/2024/09/GHSA-5pj7-xh4x-q82m/GHSA-5pj7-xh4x-q82m.json +++ b/advisories/unreviewed/2024/09/GHSA-5pj7-xh4x-q82m/GHSA-5pj7-xh4x-q82m.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-287" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-6c48-fh55-hjmq/GHSA-6c48-fh55-hjmq.json b/advisories/unreviewed/2024/09/GHSA-6c48-fh55-hjmq/GHSA-6c48-fh55-hjmq.json index bb38c642ec5..803213d8a63 100644 --- a/advisories/unreviewed/2024/09/GHSA-6c48-fh55-hjmq/GHSA-6c48-fh55-hjmq.json +++ b/advisories/unreviewed/2024/09/GHSA-6c48-fh55-hjmq/GHSA-6c48-fh55-hjmq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6c48-fh55-hjmq", - "modified": "2024-09-07T00:31:29Z", + "modified": "2024-09-09T18:30:29Z", "published": "2024-09-07T00:31:29Z", "aliases": [ "CVE-2024-45771" ], "details": "RapidCMS v1.3.1 was discovered to contain a SQL injection vulnerability via the password parameter at /resource/runlogin.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-06T22:15:02Z" diff --git a/advisories/unreviewed/2024/09/GHSA-726x-rvqx-m6j6/GHSA-726x-rvqx-m6j6.json b/advisories/unreviewed/2024/09/GHSA-726x-rvqx-m6j6/GHSA-726x-rvqx-m6j6.json new file mode 100644 index 00000000000..43db20ab51d --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-726x-rvqx-m6j6/GHSA-726x-rvqx-m6j6.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-726x-rvqx-m6j6", + "modified": "2024-09-09T18:30:31Z", + "published": "2024-09-09T18:30:31Z", + "aliases": [ + "CVE-2024-44335" + ], + "details": "D-Link DI-7003G v19.12.24A1, DI-7003GV2 v24.04.18D1, DI-7100G+V2 v24.04.18D1, DI-7100GV2 v24.04.18D1, DI-7200GV2 v24.04.18E1, DI-7300G+V2 v24.04.18D1, and DI-7400G+V2 v24.04.18D1 are vulnerable to Remote Command Execution (RCE) via version_upgrade.asp.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44335" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Swind1er/029fb2a9dab916f926fab40cc059223f" + }, + { + "type": "WEB", + "url": "https://www.dlink.com/en/security-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-09T18:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-7w4r-xxr6-xrcj/GHSA-7w4r-xxr6-xrcj.json b/advisories/unreviewed/2024/09/GHSA-7w4r-xxr6-xrcj/GHSA-7w4r-xxr6-xrcj.json index 0fa96002525..b6a53cf31d2 100644 --- a/advisories/unreviewed/2024/09/GHSA-7w4r-xxr6-xrcj/GHSA-7w4r-xxr6-xrcj.json +++ b/advisories/unreviewed/2024/09/GHSA-7w4r-xxr6-xrcj/GHSA-7w4r-xxr6-xrcj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7w4r-xxr6-xrcj", - "modified": "2024-09-06T18:31:32Z", + "modified": "2024-09-09T18:30:29Z", "published": "2024-09-06T18:31:32Z", "aliases": [ "CVE-2024-8517" @@ -29,6 +29,10 @@ "type": "WEB", "url": "https://thinkloveshare.com/hacking/spip_preauth_rce_2024_part_2_a_big_upload" }, + { + "type": "WEB", + "url": "https://vozec.fr/researchs/spip-preauth-rce-2024-big-upload" + }, { "type": "WEB", "url": "https://vulncheck.com/advisories/spip-upload-rce" diff --git a/advisories/unreviewed/2024/09/GHSA-92qf-v5hc-8737/GHSA-92qf-v5hc-8737.json b/advisories/unreviewed/2024/09/GHSA-92qf-v5hc-8737/GHSA-92qf-v5hc-8737.json new file mode 100644 index 00000000000..40cc169e4eb --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-92qf-v5hc-8737/GHSA-92qf-v5hc-8737.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-92qf-v5hc-8737", + "modified": "2024-09-09T18:30:31Z", + "published": "2024-09-09T18:30:31Z", + "aliases": [ + "CVE-2024-44334" + ], + "details": "D-Link DI-7003GV2 v24.04.18D1, DI-7100G+V2 v24.04.18D1, DI-7100GV2 v24.04.18D1, DI-7200GV2 v24.04.18E1, DI-7300G+V2 v24.04.18D1, and DI-7400G+V2 v24.04.18D1 are vulnerable to Remote Command Execution due to insufficient parameter filtering in the CGI handling function of upgrade_filter.asp.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44334" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Swind1er/563789899a7a4b9c261045a15efea952" + }, + { + "type": "WEB", + "url": "https://www.dlink.com/en/security-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-09T18:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-9xxg-2v8x-4j8c/GHSA-9xxg-2v8x-4j8c.json b/advisories/unreviewed/2024/09/GHSA-9xxg-2v8x-4j8c/GHSA-9xxg-2v8x-4j8c.json index 0acef6206a2..d9d123e6253 100644 --- a/advisories/unreviewed/2024/09/GHSA-9xxg-2v8x-4j8c/GHSA-9xxg-2v8x-4j8c.json +++ b/advisories/unreviewed/2024/09/GHSA-9xxg-2v8x-4j8c/GHSA-9xxg-2v8x-4j8c.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-522" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-c76v-gjqc-j462/GHSA-c76v-gjqc-j462.json b/advisories/unreviewed/2024/09/GHSA-c76v-gjqc-j462/GHSA-c76v-gjqc-j462.json index 0907fdb0287..22ec677f442 100644 --- a/advisories/unreviewed/2024/09/GHSA-c76v-gjqc-j462/GHSA-c76v-gjqc-j462.json +++ b/advisories/unreviewed/2024/09/GHSA-c76v-gjqc-j462/GHSA-c76v-gjqc-j462.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-502" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-cr4f-2vx6-mjcv/GHSA-cr4f-2vx6-mjcv.json b/advisories/unreviewed/2024/09/GHSA-cr4f-2vx6-mjcv/GHSA-cr4f-2vx6-mjcv.json index 1f5afa4e9e1..353a73fb362 100644 --- a/advisories/unreviewed/2024/09/GHSA-cr4f-2vx6-mjcv/GHSA-cr4f-2vx6-mjcv.json +++ b/advisories/unreviewed/2024/09/GHSA-cr4f-2vx6-mjcv/GHSA-cr4f-2vx6-mjcv.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-crqm-pwhx-j97f/GHSA-crqm-pwhx-j97f.json b/advisories/unreviewed/2024/09/GHSA-crqm-pwhx-j97f/GHSA-crqm-pwhx-j97f.json index 1e462400b27..f4db4c509d4 100644 --- a/advisories/unreviewed/2024/09/GHSA-crqm-pwhx-j97f/GHSA-crqm-pwhx-j97f.json +++ b/advisories/unreviewed/2024/09/GHSA-crqm-pwhx-j97f/GHSA-crqm-pwhx-j97f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-crqm-pwhx-j97f", - "modified": "2024-09-06T21:32:28Z", + "modified": "2024-09-09T18:30:29Z", "published": "2024-09-06T21:32:28Z", "aliases": [ "CVE-2024-34156" ], "details": "Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion. This is a follow-up to CVE-2022-30635.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -39,7 +42,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-06T21:15:12Z" diff --git a/advisories/unreviewed/2024/09/GHSA-gf29-3f4w-753g/GHSA-gf29-3f4w-753g.json b/advisories/unreviewed/2024/09/GHSA-gf29-3f4w-753g/GHSA-gf29-3f4w-753g.json new file mode 100644 index 00000000000..5c90f0c9b09 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-gf29-3f4w-753g/GHSA-gf29-3f4w-753g.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gf29-3f4w-753g", + "modified": "2024-09-09T18:30:30Z", + "published": "2024-09-09T18:30:30Z", + "aliases": [ + "CVE-2024-8604" + ], + "details": "A vulnerability classified as problematic has been found in SourceCodester Online Food Ordering System 2.0. This affects an unknown part of the file index.php of the component Create an Account Page. The manipulation of the argument First Name/Last Name leads to cross site scripting. It is possible to initiate the attack remotely.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8604" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.276831" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.276831" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.404660" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-09T16:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-hhqv-m4px-5qwj/GHSA-hhqv-m4px-5qwj.json b/advisories/unreviewed/2024/09/GHSA-hhqv-m4px-5qwj/GHSA-hhqv-m4px-5qwj.json new file mode 100644 index 00000000000..14e3aabd77b --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-hhqv-m4px-5qwj/GHSA-hhqv-m4px-5qwj.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hhqv-m4px-5qwj", + "modified": "2024-09-09T18:30:31Z", + "published": "2024-09-09T18:30:30Z", + "aliases": [ + "CVE-2024-8605" + ], + "details": "A vulnerability classified as problematic was found in code-projects Inventory Management 1.0. This vulnerability affects unknown code of the file /view/registration.php of the component Registration Form. The manipulation with the input leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8605" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/ali0999109/Inventory-management" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.276832" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.276832" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.404711" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-09T16:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-j2gh-426h-92wp/GHSA-j2gh-426h-92wp.json b/advisories/unreviewed/2024/09/GHSA-j2gh-426h-92wp/GHSA-j2gh-426h-92wp.json index 59d4b8c414f..1b3ddded080 100644 --- a/advisories/unreviewed/2024/09/GHSA-j2gh-426h-92wp/GHSA-j2gh-426h-92wp.json +++ b/advisories/unreviewed/2024/09/GHSA-j2gh-426h-92wp/GHSA-j2gh-426h-92wp.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-j3hj-xxh9-4p6j/GHSA-j3hj-xxh9-4p6j.json b/advisories/unreviewed/2024/09/GHSA-j3hj-xxh9-4p6j/GHSA-j3hj-xxh9-4p6j.json index dcd3dc6cba9..a6aeecbd471 100644 --- a/advisories/unreviewed/2024/09/GHSA-j3hj-xxh9-4p6j/GHSA-j3hj-xxh9-4p6j.json +++ b/advisories/unreviewed/2024/09/GHSA-j3hj-xxh9-4p6j/GHSA-j3hj-xxh9-4p6j.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-mmmq-786f-84xq/GHSA-mmmq-786f-84xq.json b/advisories/unreviewed/2024/09/GHSA-mmmq-786f-84xq/GHSA-mmmq-786f-84xq.json new file mode 100644 index 00000000000..3afa34c3361 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-mmmq-786f-84xq/GHSA-mmmq-786f-84xq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mmmq-786f-84xq", + "modified": "2024-09-09T18:30:30Z", + "published": "2024-09-09T18:30:30Z", + "aliases": [ + "CVE-2024-44721" + ], + "details": "SeaCMS v13.1 was discovered to a Server-Side Request Forgery (SSRF) via the url parameter at /admin_reslib.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44721" + }, + { + "type": "WEB", + "url": "https://github.com/seacms-net/CMS/issues/23" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-09T16:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-phhc-p9jg-cvj3/GHSA-phhc-p9jg-cvj3.json b/advisories/unreviewed/2024/09/GHSA-phhc-p9jg-cvj3/GHSA-phhc-p9jg-cvj3.json new file mode 100644 index 00000000000..0fa5cc4604d --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-phhc-p9jg-cvj3/GHSA-phhc-p9jg-cvj3.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-phhc-p9jg-cvj3", + "modified": "2024-09-09T18:30:31Z", + "published": "2024-09-09T18:30:31Z", + "aliases": [ + "CVE-2024-44849" + ], + "details": "Qualitor up to 8.24 is vulnerable to Remote Code Execution (RCE) via Arbitrary File Upload in checkAcesso.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44849" + }, + { + "type": "WEB", + "url": "https://blog.extencil.me/information-security/cves/cve-2024-44849" + }, + { + "type": "WEB", + "url": "https://github.com/extencil/CVE-2024-44849?tab=readme-ov-file" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-09T18:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-v94f-69x2-68gg/GHSA-v94f-69x2-68gg.json b/advisories/unreviewed/2024/09/GHSA-v94f-69x2-68gg/GHSA-v94f-69x2-68gg.json index a5bcb4a50d5..dbd7c8f52fb 100644 --- a/advisories/unreviewed/2024/09/GHSA-v94f-69x2-68gg/GHSA-v94f-69x2-68gg.json +++ b/advisories/unreviewed/2024/09/GHSA-v94f-69x2-68gg/GHSA-v94f-69x2-68gg.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-xmm6-qh3x-mprv/GHSA-xmm6-qh3x-mprv.json b/advisories/unreviewed/2024/09/GHSA-xmm6-qh3x-mprv/GHSA-xmm6-qh3x-mprv.json new file mode 100644 index 00000000000..a7f5727ef86 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-xmm6-qh3x-mprv/GHSA-xmm6-qh3x-mprv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xmm6-qh3x-mprv", + "modified": "2024-09-09T18:30:30Z", + "published": "2024-09-09T18:30:30Z", + "aliases": [ + "CVE-2024-44720" + ], + "details": "SeaCMS v13.1 was discovered to an arbitrary file read vulnerability via the component admin_safe.php.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44720" + }, + { + "type": "WEB", + "url": "https://github.com/seacms-net/CMS/issues/22" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-09T16:15:02Z" + } +} \ No newline at end of file