mirror of
https://github.com/netbirdio/advisory-database.git
synced 2026-05-22 18:04:22 -07:00
Publish Advisories
GHSA-29ww-cjvv-3x39 GHSA-36r6-mm7x-rqmm GHSA-4wv9-rjh2-6fhw GHSA-5h8h-fq9x-xjw5 GHSA-629m-cwhq-hcx4 GHSA-9vv9-vx4p-wx8p GHSA-ccrw-rwvf-gh8w GHSA-cpgg-rjvm-32fx GHSA-fc7x-6gvp-3rvc GHSA-gwcj-j6gp-p955 GHSA-j23x-w7m9-8c47 GHSA-j4q3-cq76-4p2r GHSA-jwhc-74h7-9587 GHSA-r9vr-4rjx-2pxv GHSA-rxv4-3q25-g562 GHSA-wq24-fr27-25xc
This commit is contained in:
@@ -1,14 +1,17 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-29ww-cjvv-3x39",
|
||||
"modified": "2023-05-08T21:31:08Z",
|
||||
"modified": "2023-05-13T03:30:15Z",
|
||||
"published": "2023-05-08T21:31:08Z",
|
||||
"aliases": [
|
||||
"CVE-2023-28181"
|
||||
],
|
||||
"details": "The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3, tvOS 16.4, watchOS 9.4, iOS 16.4 and iPadOS 16.4. An app may be able to execute arbitrary code with kernel privileges",
|
||||
"severity": [
|
||||
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
|
||||
@@ -1,14 +1,17 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-36r6-mm7x-rqmm",
|
||||
"modified": "2023-05-08T21:31:08Z",
|
||||
"modified": "2023-05-13T03:30:15Z",
|
||||
"published": "2023-05-08T21:31:08Z",
|
||||
"aliases": [
|
||||
"CVE-2023-28200"
|
||||
],
|
||||
"details": "A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, iOS 15.7.4 and iPadOS 15.7.4, macOS Big Sur 11.7.5. An app may be able to disclose kernel memory",
|
||||
"severity": [
|
||||
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
@@ -37,7 +40,7 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
"CWE-20"
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
|
||||
@@ -1,14 +1,17 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-4wv9-rjh2-6fhw",
|
||||
"modified": "2023-05-08T21:31:07Z",
|
||||
"modified": "2023-05-13T03:30:15Z",
|
||||
"published": "2023-05-08T21:31:07Z",
|
||||
"aliases": [
|
||||
"CVE-2023-27946"
|
||||
],
|
||||
"details": "An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, iOS 15.7.4 and iPadOS 15.7.4, macOS Big Sur 11.7.5. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution",
|
||||
"severity": [
|
||||
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
@@ -37,7 +40,7 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
"CWE-125"
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
|
||||
@@ -1,14 +1,17 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-5h8h-fq9x-xjw5",
|
||||
"modified": "2023-05-08T21:31:07Z",
|
||||
"modified": "2023-05-13T03:30:15Z",
|
||||
"published": "2023-05-08T21:31:07Z",
|
||||
"aliases": [
|
||||
"CVE-2023-27945"
|
||||
],
|
||||
"details": "This issue was addressed with improved entitlements. This issue is fixed in Xcode 14.3. A sandboxed app may be able to collect system logs",
|
||||
"severity": [
|
||||
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
|
||||
@@ -1,14 +1,17 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-629m-cwhq-hcx4",
|
||||
"modified": "2023-05-08T21:31:08Z",
|
||||
"modified": "2023-05-13T03:30:15Z",
|
||||
"published": "2023-05-08T21:31:08Z",
|
||||
"aliases": [
|
||||
"CVE-2023-28190"
|
||||
],
|
||||
"details": "A privacy issue was addressed by moving sensitive data to a more secure location. This issue is fixed in macOS Ventura 13.3. An app may be able to access user-sensitive data",
|
||||
"severity": [
|
||||
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
|
||||
@@ -1,14 +1,17 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-9vv9-vx4p-wx8p",
|
||||
"modified": "2023-05-08T21:31:08Z",
|
||||
"modified": "2023-05-13T03:30:15Z",
|
||||
"published": "2023-05-08T21:31:08Z",
|
||||
"aliases": [
|
||||
"CVE-2023-28189"
|
||||
],
|
||||
"details": "The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.3. An app may be able to view sensitive information",
|
||||
"severity": [
|
||||
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
|
||||
@@ -1,14 +1,17 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-ccrw-rwvf-gh8w",
|
||||
"modified": "2023-05-08T21:31:08Z",
|
||||
"modified": "2023-05-13T03:30:15Z",
|
||||
"published": "2023-05-08T21:31:08Z",
|
||||
"aliases": [
|
||||
"CVE-2023-28180"
|
||||
],
|
||||
"details": "A denial-of-service issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. A user in a privileged network position may be able to cause a denial-of-service",
|
||||
"severity": [
|
||||
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
|
||||
@@ -1,14 +1,17 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-cpgg-rjvm-32fx",
|
||||
"modified": "2023-05-08T21:31:07Z",
|
||||
"modified": "2023-05-13T03:30:15Z",
|
||||
"published": "2023-05-08T21:31:07Z",
|
||||
"aliases": [
|
||||
"CVE-2023-27961"
|
||||
],
|
||||
"details": "Multiple validation issues were addressed with improved input sanitization. This issue is fixed in macOS Ventura 13.3, macOS Big Sur 11.7.5, macOS Monterey 12.6.4, watchOS 9.4, iOS 15.7.4 and iPadOS 15.7.4, iOS 16.4 and iPadOS 16.4. Importing a maliciously crafted calendar invitation may exfiltrate user information",
|
||||
"severity": [
|
||||
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
@@ -45,7 +48,7 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
"CWE-20"
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
|
||||
@@ -1,14 +1,17 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-fc7x-6gvp-3rvc",
|
||||
"modified": "2023-05-08T21:31:07Z",
|
||||
"modified": "2023-05-13T03:30:15Z",
|
||||
"published": "2023-05-08T21:31:07Z",
|
||||
"aliases": [
|
||||
"CVE-2023-27952"
|
||||
],
|
||||
"details": "A race condition was addressed with improved locking. This issue is fixed in macOS Ventura 13.3. An app may bypass Gatekeeper checks",
|
||||
"severity": [
|
||||
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
@@ -25,7 +28,7 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
"CWE-362"
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
|
||||
@@ -1,14 +1,17 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-gwcj-j6gp-p955",
|
||||
"modified": "2023-05-08T21:31:08Z",
|
||||
"modified": "2023-05-13T03:30:15Z",
|
||||
"published": "2023-05-08T21:31:08Z",
|
||||
"aliases": [
|
||||
"CVE-2023-28192"
|
||||
],
|
||||
"details": "A permissions issue was addressed with improved validation. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, macOS Big Sur 11.7.5. An app may be able to read sensitive location information",
|
||||
"severity": [
|
||||
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
@@ -33,7 +36,7 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
"CWE-276"
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
|
||||
@@ -1,14 +1,17 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-j23x-w7m9-8c47",
|
||||
"modified": "2023-05-08T21:31:07Z",
|
||||
"modified": "2023-05-13T03:30:15Z",
|
||||
"published": "2023-05-08T21:31:07Z",
|
||||
"aliases": [
|
||||
"CVE-2023-27958"
|
||||
],
|
||||
"details": "The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, macOS Big Sur 11.7.5. A remote user may be able to cause unexpected system termination or corrupt kernel memory",
|
||||
"severity": [
|
||||
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
|
||||
@@ -1,14 +1,17 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-j4q3-cq76-4p2r",
|
||||
"modified": "2023-05-08T21:31:06Z",
|
||||
"modified": "2023-05-13T03:30:15Z",
|
||||
"published": "2023-05-08T21:31:06Z",
|
||||
"aliases": [
|
||||
"CVE-2023-27932"
|
||||
],
|
||||
"details": "This issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.3, watchOS 9.4, tvOS 16.4, Safari 16.4, iOS 16.4 and iPadOS 16.4. Processing maliciously crafted web content may bypass Same Origin Policy",
|
||||
"severity": [
|
||||
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
|
||||
@@ -1,14 +1,17 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-jwhc-74h7-9587",
|
||||
"modified": "2023-05-08T21:31:07Z",
|
||||
"modified": "2023-05-13T03:30:15Z",
|
||||
"published": "2023-05-08T21:31:07Z",
|
||||
"aliases": [
|
||||
"CVE-2023-27949"
|
||||
],
|
||||
"details": "An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, iOS 15.7.4 and iPadOS 15.7.4. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution",
|
||||
"severity": [
|
||||
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
@@ -33,7 +36,7 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
"CWE-125"
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
|
||||
@@ -1,14 +1,17 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-r9vr-4rjx-2pxv",
|
||||
"modified": "2023-05-08T21:31:07Z",
|
||||
"modified": "2023-05-13T03:30:15Z",
|
||||
"published": "2023-05-08T21:31:07Z",
|
||||
"aliases": [
|
||||
"CVE-2023-27951"
|
||||
],
|
||||
"details": "The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, macOS Big Sur 11.7.5. An archive may be able to bypass Gatekeeper",
|
||||
"severity": [
|
||||
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
|
||||
@@ -1,14 +1,17 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-rxv4-3q25-g562",
|
||||
"modified": "2023-05-08T21:31:07Z",
|
||||
"modified": "2023-05-13T03:30:15Z",
|
||||
"published": "2023-05-08T21:31:07Z",
|
||||
"aliases": [
|
||||
"CVE-2023-27944"
|
||||
],
|
||||
"details": "This issue was addressed with a new entitlement. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, macOS Big Sur 11.7.5. An app may be able to break out of its sandbox",
|
||||
"severity": [
|
||||
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
|
||||
@@ -1,14 +1,17 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-wq24-fr27-25xc",
|
||||
"modified": "2023-05-08T21:31:06Z",
|
||||
"modified": "2023-05-13T03:30:15Z",
|
||||
"published": "2023-05-08T21:31:06Z",
|
||||
"aliases": [
|
||||
"CVE-2023-27933"
|
||||
],
|
||||
"details": "The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, watchOS 9.4, tvOS 16.4, iOS 16.4 and iPadOS 16.4. An app with root privileges may be able to execute arbitrary code with kernel privileges",
|
||||
"severity": [
|
||||
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
|
||||
Reference in New Issue
Block a user