diff --git a/advisories/unreviewed/2023/10/GHSA-2q7g-2crp-58pw/GHSA-2q7g-2crp-58pw.json b/advisories/unreviewed/2023/10/GHSA-2q7g-2crp-58pw/GHSA-2q7g-2crp-58pw.json index 7bf13505ea1..14dcc04019d 100644 --- a/advisories/unreviewed/2023/10/GHSA-2q7g-2crp-58pw/GHSA-2q7g-2crp-58pw.json +++ b/advisories/unreviewed/2023/10/GHSA-2q7g-2crp-58pw/GHSA-2q7g-2crp-58pw.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-35gh-9rr7-fw4g/GHSA-35gh-9rr7-fw4g.json b/advisories/unreviewed/2023/10/GHSA-35gh-9rr7-fw4g/GHSA-35gh-9rr7-fw4g.json index 52fa70ebfd8..5af385b2f3e 100644 --- a/advisories/unreviewed/2023/10/GHSA-35gh-9rr7-fw4g/GHSA-35gh-9rr7-fw4g.json +++ b/advisories/unreviewed/2023/10/GHSA-35gh-9rr7-fw4g/GHSA-35gh-9rr7-fw4g.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-400" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-5738-v2hj-j4xc/GHSA-5738-v2hj-j4xc.json b/advisories/unreviewed/2023/10/GHSA-5738-v2hj-j4xc/GHSA-5738-v2hj-j4xc.json index 52f31190e96..e84c120528b 100644 --- a/advisories/unreviewed/2023/10/GHSA-5738-v2hj-j4xc/GHSA-5738-v2hj-j4xc.json +++ b/advisories/unreviewed/2023/10/GHSA-5738-v2hj-j4xc/GHSA-5738-v2hj-j4xc.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-84vp-6362-r6g3/GHSA-84vp-6362-r6g3.json b/advisories/unreviewed/2023/10/GHSA-84vp-6362-r6g3/GHSA-84vp-6362-r6g3.json index cd5566ba839..3f651414a1c 100644 --- a/advisories/unreviewed/2023/10/GHSA-84vp-6362-r6g3/GHSA-84vp-6362-r6g3.json +++ b/advisories/unreviewed/2023/10/GHSA-84vp-6362-r6g3/GHSA-84vp-6362-r6g3.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-9xjj-cwg3-hjc7/GHSA-9xjj-cwg3-hjc7.json b/advisories/unreviewed/2023/10/GHSA-9xjj-cwg3-hjc7/GHSA-9xjj-cwg3-hjc7.json index 5b9a050e14e..b71f1c7ed30 100644 --- a/advisories/unreviewed/2023/10/GHSA-9xjj-cwg3-hjc7/GHSA-9xjj-cwg3-hjc7.json +++ b/advisories/unreviewed/2023/10/GHSA-9xjj-cwg3-hjc7/GHSA-9xjj-cwg3-hjc7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9xjj-cwg3-hjc7", - "modified": "2023-11-08T21:30:34Z", + "modified": "2024-09-06T21:32:26Z", "published": "2023-10-31T21:32:35Z", "aliases": [ "CVE-2023-46484" diff --git a/advisories/unreviewed/2023/10/GHSA-hqwr-xv28-whqf/GHSA-hqwr-xv28-whqf.json b/advisories/unreviewed/2023/10/GHSA-hqwr-xv28-whqf/GHSA-hqwr-xv28-whqf.json index 14747664ffa..0d9c1119268 100644 --- a/advisories/unreviewed/2023/10/GHSA-hqwr-xv28-whqf/GHSA-hqwr-xv28-whqf.json +++ b/advisories/unreviewed/2023/10/GHSA-hqwr-xv28-whqf/GHSA-hqwr-xv28-whqf.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-mfm9-gf89-rmqf/GHSA-mfm9-gf89-rmqf.json b/advisories/unreviewed/2023/10/GHSA-mfm9-gf89-rmqf/GHSA-mfm9-gf89-rmqf.json index 966185e365d..906ebce259c 100644 --- a/advisories/unreviewed/2023/10/GHSA-mfm9-gf89-rmqf/GHSA-mfm9-gf89-rmqf.json +++ b/advisories/unreviewed/2023/10/GHSA-mfm9-gf89-rmqf/GHSA-mfm9-gf89-rmqf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mfm9-gf89-rmqf", - "modified": "2023-11-08T21:30:35Z", + "modified": "2024-09-06T21:32:26Z", "published": "2023-10-31T21:32:36Z", "aliases": [ "CVE-2023-46485" diff --git a/advisories/unreviewed/2023/10/GHSA-v5g2-x587-cc7c/GHSA-v5g2-x587-cc7c.json b/advisories/unreviewed/2023/10/GHSA-v5g2-x587-cc7c/GHSA-v5g2-x587-cc7c.json index 4426debf0f5..1889ab17e3b 100644 --- a/advisories/unreviewed/2023/10/GHSA-v5g2-x587-cc7c/GHSA-v5g2-x587-cc7c.json +++ b/advisories/unreviewed/2023/10/GHSA-v5g2-x587-cc7c/GHSA-v5g2-x587-cc7c.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/11/GHSA-7x3f-23vq-mrxp/GHSA-7x3f-23vq-mrxp.json b/advisories/unreviewed/2023/11/GHSA-7x3f-23vq-mrxp/GHSA-7x3f-23vq-mrxp.json index e17b98da6e0..dc7b0825fd4 100644 --- a/advisories/unreviewed/2023/11/GHSA-7x3f-23vq-mrxp/GHSA-7x3f-23vq-mrxp.json +++ b/advisories/unreviewed/2023/11/GHSA-7x3f-23vq-mrxp/GHSA-7x3f-23vq-mrxp.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/11/GHSA-8v7h-jhgr-2fgc/GHSA-8v7h-jhgr-2fgc.json b/advisories/unreviewed/2023/11/GHSA-8v7h-jhgr-2fgc/GHSA-8v7h-jhgr-2fgc.json index e4365605f37..5b2184c9a4f 100644 --- a/advisories/unreviewed/2023/11/GHSA-8v7h-jhgr-2fgc/GHSA-8v7h-jhgr-2fgc.json +++ b/advisories/unreviewed/2023/11/GHSA-8v7h-jhgr-2fgc/GHSA-8v7h-jhgr-2fgc.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/11/GHSA-grf5-hh55-whxh/GHSA-grf5-hh55-whxh.json b/advisories/unreviewed/2023/11/GHSA-grf5-hh55-whxh/GHSA-grf5-hh55-whxh.json index 60defe15c65..16a9bd06d53 100644 --- a/advisories/unreviewed/2023/11/GHSA-grf5-hh55-whxh/GHSA-grf5-hh55-whxh.json +++ b/advisories/unreviewed/2023/11/GHSA-grf5-hh55-whxh/GHSA-grf5-hh55-whxh.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-121", "CWE-787" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2023/11/GHSA-wjmw-g7qq-g6h2/GHSA-wjmw-g7qq-g6h2.json b/advisories/unreviewed/2023/11/GHSA-wjmw-g7qq-g6h2/GHSA-wjmw-g7qq-g6h2.json index 7f2f06b83ef..704d0a846f0 100644 --- a/advisories/unreviewed/2023/11/GHSA-wjmw-g7qq-g6h2/GHSA-wjmw-g7qq-g6h2.json +++ b/advisories/unreviewed/2023/11/GHSA-wjmw-g7qq-g6h2/GHSA-wjmw-g7qq-g6h2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wjmw-g7qq-g6h2", - "modified": "2023-11-09T03:30:19Z", + "modified": "2024-09-06T21:32:26Z", "published": "2023-11-01T18:30:33Z", "aliases": [ "CVE-2023-5766" diff --git a/advisories/unreviewed/2024/01/GHSA-7hrg-3c44-45cg/GHSA-7hrg-3c44-45cg.json b/advisories/unreviewed/2024/01/GHSA-7hrg-3c44-45cg/GHSA-7hrg-3c44-45cg.json index 8b36ebdfed5..1a7ef12c9dc 100644 --- a/advisories/unreviewed/2024/01/GHSA-7hrg-3c44-45cg/GHSA-7hrg-3c44-45cg.json +++ b/advisories/unreviewed/2024/01/GHSA-7hrg-3c44-45cg/GHSA-7hrg-3c44-45cg.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-20" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-56m7-9pwj-r76p/GHSA-56m7-9pwj-r76p.json b/advisories/unreviewed/2024/04/GHSA-56m7-9pwj-r76p/GHSA-56m7-9pwj-r76p.json index 586359aaa57..ae123546419 100644 --- a/advisories/unreviewed/2024/04/GHSA-56m7-9pwj-r76p/GHSA-56m7-9pwj-r76p.json +++ b/advisories/unreviewed/2024/04/GHSA-56m7-9pwj-r76p/GHSA-56m7-9pwj-r76p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-56m7-9pwj-r76p", - "modified": "2024-04-05T09:30:38Z", + "modified": "2024-09-06T21:32:26Z", "published": "2024-04-05T09:30:38Z", "aliases": [ "CVE-2024-29863" ], "details": "A race condition in the installer executable in Qlik Qlikview before versions May 2022 SR3 (12.70.20300) and May 2023 SR2 (12,80.20200) may allow an existing lower privileged user to cause code to be executed in the context of a Windows Administrator.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-362" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-05T07:15:11Z" diff --git a/advisories/unreviewed/2024/04/GHSA-5hr7-cgh9-28w9/GHSA-5hr7-cgh9-28w9.json b/advisories/unreviewed/2024/04/GHSA-5hr7-cgh9-28w9/GHSA-5hr7-cgh9-28w9.json index 4630d2436dc..6ae143e33de 100644 --- a/advisories/unreviewed/2024/04/GHSA-5hr7-cgh9-28w9/GHSA-5hr7-cgh9-28w9.json +++ b/advisories/unreviewed/2024/04/GHSA-5hr7-cgh9-28w9/GHSA-5hr7-cgh9-28w9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5hr7-cgh9-28w9", - "modified": "2024-04-11T21:30:52Z", + "modified": "2024-09-06T21:32:27Z", "published": "2024-04-11T21:30:52Z", "aliases": [ "CVE-2024-28458" ], "details": "Null Pointer Dereference vulnerability in swfdump in swftools 0.9.2 allows attackers to crash the appliation via the function compileSWFActionCode in action/actioncompiler.c.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-11T21:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-6rqv-5cg7-m4x3/GHSA-6rqv-5cg7-m4x3.json b/advisories/unreviewed/2024/04/GHSA-6rqv-5cg7-m4x3/GHSA-6rqv-5cg7-m4x3.json index c0fedcfd8db..996e2f7856c 100644 --- a/advisories/unreviewed/2024/04/GHSA-6rqv-5cg7-m4x3/GHSA-6rqv-5cg7-m4x3.json +++ b/advisories/unreviewed/2024/04/GHSA-6rqv-5cg7-m4x3/GHSA-6rqv-5cg7-m4x3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6rqv-5cg7-m4x3", - "modified": "2024-04-29T21:30:34Z", + "modified": "2024-09-06T21:32:27Z", "published": "2024-04-29T21:30:34Z", "aliases": [ "CVE-2023-46565" ], "details": "Buffer Overflow vulnerability in osrg gobgp commit 419c50dfac578daa4d11256904d0dc182f1a9b22 allows a remote attacker to cause a denial of service via the handlingError function in pkg/server/fsm.go.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-29T20:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-7v7g-vx57-pg3r/GHSA-7v7g-vx57-pg3r.json b/advisories/unreviewed/2024/04/GHSA-7v7g-vx57-pg3r/GHSA-7v7g-vx57-pg3r.json index e0755bb7008..6d7b982ee6b 100644 --- a/advisories/unreviewed/2024/04/GHSA-7v7g-vx57-pg3r/GHSA-7v7g-vx57-pg3r.json +++ b/advisories/unreviewed/2024/04/GHSA-7v7g-vx57-pg3r/GHSA-7v7g-vx57-pg3r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7v7g-vx57-pg3r", - "modified": "2024-04-30T15:30:37Z", + "modified": "2024-09-06T21:32:27Z", "published": "2024-04-30T15:30:37Z", "aliases": [ "CVE-2024-33274" ], "details": "Directory Traversal vulnerability in FME Modules customfields v.2.2.7 and before allows a remote attacker to obtain sensitive information via the Custom Checkout Fields, Add Custom Fields to Checkout parameter of the ajax.php", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-30T15:15:53Z" diff --git a/advisories/unreviewed/2024/04/GHSA-9w5c-29mx-552c/GHSA-9w5c-29mx-552c.json b/advisories/unreviewed/2024/04/GHSA-9w5c-29mx-552c/GHSA-9w5c-29mx-552c.json index be73123b29b..edc48f2a7de 100644 --- a/advisories/unreviewed/2024/04/GHSA-9w5c-29mx-552c/GHSA-9w5c-29mx-552c.json +++ b/advisories/unreviewed/2024/04/GHSA-9w5c-29mx-552c/GHSA-9w5c-29mx-552c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9w5c-29mx-552c", - "modified": "2024-04-03T03:30:30Z", + "modified": "2024-09-06T21:32:26Z", "published": "2024-04-03T03:30:30Z", "aliases": [ "CVE-2024-28755" ], "details": "An issue was discovered in Mbed TLS 3.5.x before 3.6.0. When an SSL context was reset with the mbedtls_ssl_session_reset() API, the maximum TLS version to be negotiated was not restored to the configured one. An attacker was able to prevent an Mbed TLS server from establishing any TLS 1.3 connection, potentially resulting in a Denial of Service or forced version downgrade from TLS 1.3 to TLS 1.2.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-326" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-03T03:15:10Z" diff --git a/advisories/unreviewed/2024/04/GHSA-cq55-h3qw-j4hc/GHSA-cq55-h3qw-j4hc.json b/advisories/unreviewed/2024/04/GHSA-cq55-h3qw-j4hc/GHSA-cq55-h3qw-j4hc.json index 68384f221b4..929213c8439 100644 --- a/advisories/unreviewed/2024/04/GHSA-cq55-h3qw-j4hc/GHSA-cq55-h3qw-j4hc.json +++ b/advisories/unreviewed/2024/04/GHSA-cq55-h3qw-j4hc/GHSA-cq55-h3qw-j4hc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cq55-h3qw-j4hc", - "modified": "2024-04-26T21:31:11Z", + "modified": "2024-09-06T21:32:27Z", "published": "2024-04-26T21:31:11Z", "aliases": [ "CVE-2022-48611" ], "details": "A logic issue was addressed with improved checks. This issue is fixed in iTunes 12.12.4 for Windows. A local attacker may be able to elevate their privileges.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-693" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-26T20:15:07Z" diff --git a/advisories/unreviewed/2024/04/GHSA-hfv9-qvw2-c8h9/GHSA-hfv9-qvw2-c8h9.json b/advisories/unreviewed/2024/04/GHSA-hfv9-qvw2-c8h9/GHSA-hfv9-qvw2-c8h9.json index 029ea7767b1..a264e55a932 100644 --- a/advisories/unreviewed/2024/04/GHSA-hfv9-qvw2-c8h9/GHSA-hfv9-qvw2-c8h9.json +++ b/advisories/unreviewed/2024/04/GHSA-hfv9-qvw2-c8h9/GHSA-hfv9-qvw2-c8h9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hfv9-qvw2-c8h9", - "modified": "2024-04-17T18:31:36Z", + "modified": "2024-09-06T21:32:27Z", "published": "2024-04-17T18:31:36Z", "aliases": [ "CVE-2024-30980" ], "details": "SQL Injection vulnerability in phpgurukul Cyber Cafe Management System Using PHP & MySQL 1.0 allows attackers to run arbitrary SQL commands via the Computer Location parameter in manage-computer.php page.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T17:15:15Z" diff --git a/advisories/unreviewed/2024/04/GHSA-m57m-663q-6vcv/GHSA-m57m-663q-6vcv.json b/advisories/unreviewed/2024/04/GHSA-m57m-663q-6vcv/GHSA-m57m-663q-6vcv.json index f04089614d8..916304bc3c7 100644 --- a/advisories/unreviewed/2024/04/GHSA-m57m-663q-6vcv/GHSA-m57m-663q-6vcv.json +++ b/advisories/unreviewed/2024/04/GHSA-m57m-663q-6vcv/GHSA-m57m-663q-6vcv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m57m-663q-6vcv", - "modified": "2024-04-29T21:30:34Z", + "modified": "2024-09-06T21:32:27Z", "published": "2024-04-29T21:30:34Z", "aliases": [ "CVE-2024-33266" ], "details": "SQL Injection vulnerability in Helloshop deliveryorderautoupdate v.2.8.1 and before allows an attacker to run arbitrary SQL commands via the DeliveryorderautoupdateOrdersModuleFrontController::initContent function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-29T20:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-j2m8-5vfj-r2jj/GHSA-j2m8-5vfj-r2jj.json b/advisories/unreviewed/2024/05/GHSA-j2m8-5vfj-r2jj/GHSA-j2m8-5vfj-r2jj.json index b735afa21ce..34439c1ce51 100644 --- a/advisories/unreviewed/2024/05/GHSA-j2m8-5vfj-r2jj/GHSA-j2m8-5vfj-r2jj.json +++ b/advisories/unreviewed/2024/05/GHSA-j2m8-5vfj-r2jj/GHSA-j2m8-5vfj-r2jj.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-59" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-m3x3-867j-f35f/GHSA-m3x3-867j-f35f.json b/advisories/unreviewed/2024/05/GHSA-m3x3-867j-f35f/GHSA-m3x3-867j-f35f.json index 127cecfd61a..5e9eac60f08 100644 --- a/advisories/unreviewed/2024/05/GHSA-m3x3-867j-f35f/GHSA-m3x3-867j-f35f.json +++ b/advisories/unreviewed/2024/05/GHSA-m3x3-867j-f35f/GHSA-m3x3-867j-f35f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m3x3-867j-f35f", - "modified": "2024-06-10T18:30:59Z", + "modified": "2024-09-06T21:32:27Z", "published": "2024-05-14T15:32:53Z", "aliases": [ "CVE-2024-27839" ], "details": "A privacy issue was addressed by moving sensitive data to a more secure location. This issue is fixed in iOS 17.5 and iPadOS 17.5. A malicious application may be able to determine a user's current location.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:13:07Z" diff --git a/advisories/unreviewed/2024/05/GHSA-pq6w-8h36-7f4v/GHSA-pq6w-8h36-7f4v.json b/advisories/unreviewed/2024/05/GHSA-pq6w-8h36-7f4v/GHSA-pq6w-8h36-7f4v.json index f3d7ad29676..93df32cf5e8 100644 --- a/advisories/unreviewed/2024/05/GHSA-pq6w-8h36-7f4v/GHSA-pq6w-8h36-7f4v.json +++ b/advisories/unreviewed/2024/05/GHSA-pq6w-8h36-7f4v/GHSA-pq6w-8h36-7f4v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pq6w-8h36-7f4v", - "modified": "2024-05-01T21:30:37Z", + "modified": "2024-09-06T21:32:27Z", "published": "2024-05-01T21:30:37Z", "aliases": [ "CVE-2024-33428" ], "details": "Buffer-Overflow vulnerability at conv.c:68 of stsaz phiola v2.0-rc22 allows a remote attacker to execute arbitrary code via the a crafted .wav file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-122" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-01T19:15:27Z" diff --git a/advisories/unreviewed/2024/06/GHSA-268h-82rc-5x3h/GHSA-268h-82rc-5x3h.json b/advisories/unreviewed/2024/06/GHSA-268h-82rc-5x3h/GHSA-268h-82rc-5x3h.json index 300d3827e39..7d127b61bb2 100644 --- a/advisories/unreviewed/2024/06/GHSA-268h-82rc-5x3h/GHSA-268h-82rc-5x3h.json +++ b/advisories/unreviewed/2024/06/GHSA-268h-82rc-5x3h/GHSA-268h-82rc-5x3h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-268h-82rc-5x3h", - "modified": "2024-06-14T21:30:52Z", + "modified": "2024-09-06T21:32:27Z", "published": "2024-06-08T15:31:18Z", "aliases": [ "CVE-2024-37408" ], "details": "fprintd through 1.94.3 lacks a security attention mechanism, and thus unexpected actions might be authorized by \"auth sufficient pam_fprintd.so\" for Sudo.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-287" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-08T14:15:11Z" diff --git a/advisories/unreviewed/2024/06/GHSA-qqmv-8748-799f/GHSA-qqmv-8748-799f.json b/advisories/unreviewed/2024/06/GHSA-qqmv-8748-799f/GHSA-qqmv-8748-799f.json index cdd7c5f3610..dfbdf741927 100644 --- a/advisories/unreviewed/2024/06/GHSA-qqmv-8748-799f/GHSA-qqmv-8748-799f.json +++ b/advisories/unreviewed/2024/06/GHSA-qqmv-8748-799f/GHSA-qqmv-8748-799f.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-cqgr-5wqv-qc6w/GHSA-cqgr-5wqv-qc6w.json b/advisories/unreviewed/2024/07/GHSA-cqgr-5wqv-qc6w/GHSA-cqgr-5wqv-qc6w.json index 80bc9f26d7b..535f9849443 100644 --- a/advisories/unreviewed/2024/07/GHSA-cqgr-5wqv-qc6w/GHSA-cqgr-5wqv-qc6w.json +++ b/advisories/unreviewed/2024/07/GHSA-cqgr-5wqv-qc6w/GHSA-cqgr-5wqv-qc6w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cqgr-5wqv-qc6w", - "modified": "2024-07-21T09:30:32Z", + "modified": "2024-09-06T21:32:27Z", "published": "2024-07-21T09:30:32Z", "aliases": [ "CVE-2024-37519" diff --git a/advisories/unreviewed/2024/08/GHSA-2gqg-96r8-5h58/GHSA-2gqg-96r8-5h58.json b/advisories/unreviewed/2024/08/GHSA-2gqg-96r8-5h58/GHSA-2gqg-96r8-5h58.json index f5ebb8c34b2..62ed14ec107 100644 --- a/advisories/unreviewed/2024/08/GHSA-2gqg-96r8-5h58/GHSA-2gqg-96r8-5h58.json +++ b/advisories/unreviewed/2024/08/GHSA-2gqg-96r8-5h58/GHSA-2gqg-96r8-5h58.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-128" + "CWE-128", + "CWE-682" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-2pmm-55vx-qrxv/GHSA-2pmm-55vx-qrxv.json b/advisories/unreviewed/2024/09/GHSA-2pmm-55vx-qrxv/GHSA-2pmm-55vx-qrxv.json new file mode 100644 index 00000000000..dc67ac3f0b8 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-2pmm-55vx-qrxv/GHSA-2pmm-55vx-qrxv.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2pmm-55vx-qrxv", + "modified": "2024-09-06T21:32:28Z", + "published": "2024-09-06T21:32:28Z", + "aliases": [ + "CVE-2024-44845" + ], + "details": "DrayTek Vigor3900 v1.5.1.6 was discovered to contain an authenticated command injection vulnerability via the value parameter in the filter_string function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44845" + }, + { + "type": "WEB", + "url": "https://github.com/glkfc/IoT-Vulnerability/blob/main/DaryTek/vigor3900_2.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-06T21:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-8xfx-rj4p-23jm/GHSA-8xfx-rj4p-23jm.json b/advisories/unreviewed/2024/09/GHSA-8xfx-rj4p-23jm/GHSA-8xfx-rj4p-23jm.json new file mode 100644 index 00000000000..ce08adb1aff --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-8xfx-rj4p-23jm/GHSA-8xfx-rj4p-23jm.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8xfx-rj4p-23jm", + "modified": "2024-09-06T21:32:28Z", + "published": "2024-09-06T21:32:28Z", + "aliases": [ + "CVE-2024-34155" + ], + "details": "Calling any of the Parse functions on Go source code which contains deeply nested literals can cause a panic due to stack exhaustion.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34155" + }, + { + "type": "WEB", + "url": "https://go.dev/cl/611238" + }, + { + "type": "WEB", + "url": "https://go.dev/issue/69138" + }, + { + "type": "WEB", + "url": "https://groups.google.com/g/golang-dev/c/S9POB9NCTdk" + }, + { + "type": "WEB", + "url": "https://pkg.go.dev/vuln/GO-2024-3105" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-06T21:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-crg5-c758-hm56/GHSA-crg5-c758-hm56.json b/advisories/unreviewed/2024/09/GHSA-crg5-c758-hm56/GHSA-crg5-c758-hm56.json new file mode 100644 index 00000000000..10fcd9593fb --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-crg5-c758-hm56/GHSA-crg5-c758-hm56.json @@ -0,0 +1,55 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-crg5-c758-hm56", + "modified": "2024-09-06T21:32:28Z", + "published": "2024-09-06T21:32:28Z", + "aliases": [ + "CVE-2024-7652" + ], + "details": "An error in the ECMA-262 specification relating to Async Generators could have resulted in a type confusion, potentially leading to memory corruption and an exploitable crash. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/tc39/ecma262/security/advisories/GHSA-g38c-wh3c-5h9r" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7652" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1901411" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-29" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-30" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-31" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-32" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-06T19:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-crqm-pwhx-j97f/GHSA-crqm-pwhx-j97f.json b/advisories/unreviewed/2024/09/GHSA-crqm-pwhx-j97f/GHSA-crqm-pwhx-j97f.json new file mode 100644 index 00000000000..1e462400b27 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-crqm-pwhx-j97f/GHSA-crqm-pwhx-j97f.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-crqm-pwhx-j97f", + "modified": "2024-09-06T21:32:28Z", + "published": "2024-09-06T21:32:28Z", + "aliases": [ + "CVE-2024-34156" + ], + "details": "Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion. This is a follow-up to CVE-2022-30635.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34156" + }, + { + "type": "WEB", + "url": "https://go.dev/cl/611239" + }, + { + "type": "WEB", + "url": "https://go.dev/issue/69139" + }, + { + "type": "WEB", + "url": "https://groups.google.com/g/golang-dev/c/S9POB9NCTdk" + }, + { + "type": "WEB", + "url": "https://pkg.go.dev/vuln/GO-2024-3106" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-06T21:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-hrmc-jmp7-mpm2/GHSA-hrmc-jmp7-mpm2.json b/advisories/unreviewed/2024/09/GHSA-hrmc-jmp7-mpm2/GHSA-hrmc-jmp7-mpm2.json index f1e17ad8535..d56ff4746cf 100644 --- a/advisories/unreviewed/2024/09/GHSA-hrmc-jmp7-mpm2/GHSA-hrmc-jmp7-mpm2.json +++ b/advisories/unreviewed/2024/09/GHSA-hrmc-jmp7-mpm2/GHSA-hrmc-jmp7-mpm2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hrmc-jmp7-mpm2", - "modified": "2024-09-06T18:31:31Z", + "modified": "2024-09-06T21:32:28Z", "published": "2024-09-06T18:31:31Z", "aliases": [ "CVE-2024-45758" ], "details": "H2O.ai H2O through 3.46.0.4 allows attackers to arbitrarily set the JDBC URL, leading to deserialization attacks, file reads, and command execution. Exploitation can occur when an attacker has access to post to the ImportSQLTable URI with a JSON document containing a connection_url property with any typical JDBC Connection URL attack payload such as one that uses queryInterceptors.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-502" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-06T16:15:03Z" diff --git a/advisories/unreviewed/2024/09/GHSA-hw5v-7r63-g2h6/GHSA-hw5v-7r63-g2h6.json b/advisories/unreviewed/2024/09/GHSA-hw5v-7r63-g2h6/GHSA-hw5v-7r63-g2h6.json index c9fbbd6570b..3ac2f63ef6d 100644 --- a/advisories/unreviewed/2024/09/GHSA-hw5v-7r63-g2h6/GHSA-hw5v-7r63-g2h6.json +++ b/advisories/unreviewed/2024/09/GHSA-hw5v-7r63-g2h6/GHSA-hw5v-7r63-g2h6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hw5v-7r63-g2h6", - "modified": "2024-09-05T21:31:34Z", + "modified": "2024-09-06T21:32:28Z", "published": "2024-09-05T21:31:34Z", "aliases": [ "CVE-2024-45158" ], "details": "An issue was discovered in Mbed TLS 3.6 before 3.6.1. A stack buffer overflow in mbedtls_ecdsa_der_to_raw() and mbedtls_ecdsa_raw_to_der() can occur when the bits parameter is larger than the largest supported curve. In some configurations with PSA disabled, all values of bits are affected. (This never happens in internal library calls, but can affect applications that call these functions directly.)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-05T19:15:13Z" diff --git a/advisories/unreviewed/2024/09/GHSA-j7vj-rw65-4v26/GHSA-j7vj-rw65-4v26.json b/advisories/unreviewed/2024/09/GHSA-j7vj-rw65-4v26/GHSA-j7vj-rw65-4v26.json new file mode 100644 index 00000000000..b5ffb617d4e --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-j7vj-rw65-4v26/GHSA-j7vj-rw65-4v26.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j7vj-rw65-4v26", + "modified": "2024-09-06T21:32:28Z", + "published": "2024-09-06T21:32:28Z", + "aliases": [ + "CVE-2024-34158" + ], + "details": "Calling Parse on a \"// +build\" build tag line with deeply nested expressions can cause a panic due to stack exhaustion.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34158" + }, + { + "type": "WEB", + "url": "https://go.dev/cl/611240" + }, + { + "type": "WEB", + "url": "https://go.dev/issue/69141" + }, + { + "type": "WEB", + "url": "https://groups.google.com/g/golang-dev/c/S9POB9NCTdk" + }, + { + "type": "WEB", + "url": "https://pkg.go.dev/vuln/GO-2024-3107" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-06T21:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-w66f-4c3w-wm2w/GHSA-w66f-4c3w-wm2w.json b/advisories/unreviewed/2024/09/GHSA-w66f-4c3w-wm2w/GHSA-w66f-4c3w-wm2w.json new file mode 100644 index 00000000000..4a5c0abc406 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-w66f-4c3w-wm2w/GHSA-w66f-4c3w-wm2w.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w66f-4c3w-wm2w", + "modified": "2024-09-06T21:32:28Z", + "published": "2024-09-06T21:32:28Z", + "aliases": [ + "CVE-2024-44844" + ], + "details": "DrayTek Vigor3900 v1.5.1.6 was discovered to contain an authenticated command injection vulnerability via the name parameter in the run_command function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44844" + }, + { + "type": "WEB", + "url": "https://github.com/glkfc/IoT-Vulnerability/blob/main/DaryTek/vigor3900_1.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-06T21:15:12Z" + } +} \ No newline at end of file