diff --git a/advisories/unreviewed/2024/06/GHSA-c7vf-6j49-jq2x/GHSA-c7vf-6j49-jq2x.json b/advisories/unreviewed/2024/06/GHSA-c7vf-6j49-jq2x/GHSA-c7vf-6j49-jq2x.json index 4dbc37d3ddd..18ed1d5fe29 100644 --- a/advisories/unreviewed/2024/06/GHSA-c7vf-6j49-jq2x/GHSA-c7vf-6j49-jq2x.json +++ b/advisories/unreviewed/2024/06/GHSA-c7vf-6j49-jq2x/GHSA-c7vf-6j49-jq2x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c7vf-6j49-jq2x", - "modified": "2024-06-06T18:30:57Z", + "modified": "2024-09-18T15:30:47Z", "published": "2024-06-06T18:30:57Z", "aliases": [ "CVE-2024-36745" ], "details": "An issue in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) via inputting a negative value into the oneflow.index_select parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-06T18:15:16Z" diff --git a/advisories/unreviewed/2024/06/GHSA-wjxm-v88j-7gj4/GHSA-wjxm-v88j-7gj4.json b/advisories/unreviewed/2024/06/GHSA-wjxm-v88j-7gj4/GHSA-wjxm-v88j-7gj4.json index 066820ab34b..5c7ea55d05c 100644 --- a/advisories/unreviewed/2024/06/GHSA-wjxm-v88j-7gj4/GHSA-wjxm-v88j-7gj4.json +++ b/advisories/unreviewed/2024/06/GHSA-wjxm-v88j-7gj4/GHSA-wjxm-v88j-7gj4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wjxm-v88j-7gj4", - "modified": "2024-06-06T18:30:57Z", + "modified": "2024-09-18T15:30:47Z", "published": "2024-06-06T18:30:57Z", "aliases": [ "CVE-2024-36736" ], "details": "An issue in the oneflow.permute component of OneFlow-Inc. Oneflow v0.9.1 causes an incorrect calculation when the same dimension operation is performed.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-682" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-06T18:15:16Z" diff --git a/advisories/unreviewed/2024/07/GHSA-4cvc-j8gf-mg3g/GHSA-4cvc-j8gf-mg3g.json b/advisories/unreviewed/2024/07/GHSA-4cvc-j8gf-mg3g/GHSA-4cvc-j8gf-mg3g.json index 95999d9e1eb..550311986a1 100644 --- a/advisories/unreviewed/2024/07/GHSA-4cvc-j8gf-mg3g/GHSA-4cvc-j8gf-mg3g.json +++ b/advisories/unreviewed/2024/07/GHSA-4cvc-j8gf-mg3g/GHSA-4cvc-j8gf-mg3g.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-312", "CWE-316" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/07/GHSA-hwc3-h295-hhg9/GHSA-hwc3-h295-hhg9.json b/advisories/unreviewed/2024/07/GHSA-hwc3-h295-hhg9/GHSA-hwc3-h295-hhg9.json index 10014a71117..5e3cb4189fe 100644 --- a/advisories/unreviewed/2024/07/GHSA-hwc3-h295-hhg9/GHSA-hwc3-h295-hhg9.json +++ b/advisories/unreviewed/2024/07/GHSA-hwc3-h295-hhg9/GHSA-hwc3-h295-hhg9.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-565" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-rf42-gqmw-5vh9/GHSA-rf42-gqmw-5vh9.json b/advisories/unreviewed/2024/07/GHSA-rf42-gqmw-5vh9/GHSA-rf42-gqmw-5vh9.json index df9a444d1bb..267378e47bb 100644 --- a/advisories/unreviewed/2024/07/GHSA-rf42-gqmw-5vh9/GHSA-rf42-gqmw-5vh9.json +++ b/advisories/unreviewed/2024/07/GHSA-rf42-gqmw-5vh9/GHSA-rf42-gqmw-5vh9.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-256" + "CWE-256", + "CWE-522" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-27j9-vfp3-773q/GHSA-27j9-vfp3-773q.json b/advisories/unreviewed/2024/09/GHSA-27j9-vfp3-773q/GHSA-27j9-vfp3-773q.json new file mode 100644 index 00000000000..8390f2b8f80 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-27j9-vfp3-773q/GHSA-27j9-vfp3-773q.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-27j9-vfp3-773q", + "modified": "2024-09-18T15:30:53Z", + "published": "2024-09-18T15:30:53Z", + "aliases": [ + "CVE-2024-46581" + ], + "details": "Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sProfName parameter at v2x00.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46581" + }, + { + "type": "WEB", + "url": "https://ink-desk-28f.notion.site/Draytek-vigor-3910-Analysis-Report-b3b23e150c4f4bab822c3c47fd7b9de9#7c3324f08b21445fb00f1e8eaa26283f" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T15:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-27vc-rww5-64v8/GHSA-27vc-rww5-64v8.json b/advisories/unreviewed/2024/09/GHSA-27vc-rww5-64v8/GHSA-27vc-rww5-64v8.json new file mode 100644 index 00000000000..ba62c097b0e --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-27vc-rww5-64v8/GHSA-27vc-rww5-64v8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-27vc-rww5-64v8", + "modified": "2024-09-18T15:30:52Z", + "published": "2024-09-18T15:30:52Z", + "aliases": [ + "CVE-2024-46557" + ], + "details": "Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sProfileName parameter at v2x00.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46557" + }, + { + "type": "WEB", + "url": "https://ink-desk-28f.notion.site/Draytek-vigor-3910-Analysis-Report-b3b23e150c4f4bab822c3c47fd7b9de9#8817e09b31b04ebebdaa5d6df1415df0" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T15:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-2gmp-x9r7-xp6q/GHSA-2gmp-x9r7-xp6q.json b/advisories/unreviewed/2024/09/GHSA-2gmp-x9r7-xp6q/GHSA-2gmp-x9r7-xp6q.json new file mode 100644 index 00000000000..fc98554cb1c --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-2gmp-x9r7-xp6q/GHSA-2gmp-x9r7-xp6q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2gmp-x9r7-xp6q", + "modified": "2024-09-18T15:30:52Z", + "published": "2024-09-18T15:30:52Z", + "aliases": [ + "CVE-2024-31197" + ], + "details": "Improper Null Termination vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of10::Port:unpack.\n\nThis issue affects libfluid: 0.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31197" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-31197" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-170" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T14:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-2mj4-2m9q-g49h/GHSA-2mj4-2m9q-g49h.json b/advisories/unreviewed/2024/09/GHSA-2mj4-2m9q-g49h/GHSA-2mj4-2m9q-g49h.json new file mode 100644 index 00000000000..ba872b38b83 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-2mj4-2m9q-g49h/GHSA-2mj4-2m9q-g49h.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2mj4-2m9q-g49h", + "modified": "2024-09-18T15:30:53Z", + "published": "2024-09-18T15:30:53Z", + "aliases": [ + "CVE-2024-46582" + ], + "details": "Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sSrvAddr parameter at v2x00.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46582" + }, + { + "type": "WEB", + "url": "https://ink-desk-28f.notion.site/Draytek-vigor-3910-Analysis-Report-b3b23e150c4f4bab822c3c47fd7b9de9#20001f379c5641a1ab4f7ce459ce3db0" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T15:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-2qj2-rq28-64cc/GHSA-2qj2-rq28-64cc.json b/advisories/unreviewed/2024/09/GHSA-2qj2-rq28-64cc/GHSA-2qj2-rq28-64cc.json new file mode 100644 index 00000000000..0caa9b5275a --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-2qj2-rq28-64cc/GHSA-2qj2-rq28-64cc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2qj2-rq28-64cc", + "modified": "2024-09-18T15:30:53Z", + "published": "2024-09-18T15:30:53Z", + "aliases": [ + "CVE-2024-46596" + ], + "details": "Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sAct parameter at v2x00.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46596" + }, + { + "type": "WEB", + "url": "https://ink-desk-28f.notion.site/Draytek-vigor-3910-Analysis-Report-b3b23e150c4f4bab822c3c47fd7b9de9#d049794ac4804e48968cb77589d5ec45" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T15:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-39hm-m9hv-pfcr/GHSA-39hm-m9hv-pfcr.json b/advisories/unreviewed/2024/09/GHSA-39hm-m9hv-pfcr/GHSA-39hm-m9hv-pfcr.json new file mode 100644 index 00000000000..4c57efbc556 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-39hm-m9hv-pfcr/GHSA-39hm-m9hv-pfcr.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-39hm-m9hv-pfcr", + "modified": "2024-09-18T15:30:52Z", + "published": "2024-09-18T15:30:52Z", + "aliases": [ + "CVE-2024-46554" + ], + "details": "Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the profname parameter at v2x00.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46554" + }, + { + "type": "WEB", + "url": "https://ink-desk-28f.notion.site/Draytek-vigor-3910-Analysis-Report-b3b23e150c4f4bab822c3c47fd7b9de9#ee86534f23b84f2cbfa9401ee1d9d179" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T15:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-3cmw-x7g9-558m/GHSA-3cmw-x7g9-558m.json b/advisories/unreviewed/2024/09/GHSA-3cmw-x7g9-558m/GHSA-3cmw-x7g9-558m.json new file mode 100644 index 00000000000..c2a41d5c128 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-3cmw-x7g9-558m/GHSA-3cmw-x7g9-558m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3cmw-x7g9-558m", + "modified": "2024-09-18T15:30:52Z", + "published": "2024-09-18T15:30:52Z", + "aliases": [ + "CVE-2024-39590" + ], + "details": "Multiple invalid pointer dereference vulnerabilities exist in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC_v3 16bf8bac1a36d95b73e7b8722d0edb8b9c5bb56a. A specially crafted EtherNet/IP request can lead to denial of service. An attacker can send a series of EtherNet/IP requests to trigger these vulnerabilities.This instance of the vulnerability occurs within the `Protected_Logical_Write_Reply` function", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39590" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2016" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-704" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T15:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-3jm6-w42x-q7xv/GHSA-3jm6-w42x-q7xv.json b/advisories/unreviewed/2024/09/GHSA-3jm6-w42x-q7xv/GHSA-3jm6-w42x-q7xv.json new file mode 100644 index 00000000000..1966719ba1b --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-3jm6-w42x-q7xv/GHSA-3jm6-w42x-q7xv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3jm6-w42x-q7xv", + "modified": "2024-09-18T15:30:52Z", + "published": "2024-09-18T15:30:52Z", + "aliases": [ + "CVE-2024-31195" + ], + "details": "Out-of-bounds Read vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of13::MultipartReplyTable::unpack.\n\nThis issue affects libfluid: 0.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31195" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-31195" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T14:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-3mxv-x893-5542/GHSA-3mxv-x893-5542.json b/advisories/unreviewed/2024/09/GHSA-3mxv-x893-5542/GHSA-3mxv-x893-5542.json new file mode 100644 index 00000000000..81263c07574 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-3mxv-x893-5542/GHSA-3mxv-x893-5542.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3mxv-x893-5542", + "modified": "2024-09-18T15:30:51Z", + "published": "2024-09-18T15:30:51Z", + "aliases": [ + "CVE-2024-31174" + ], + "details": "Out-of-bounds Read vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of10::FeaturesReply::unpack.\n\nThis issue affects libfluid: 0.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31174" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-31174" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T14:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-3v74-rm67-6782/GHSA-3v74-rm67-6782.json b/advisories/unreviewed/2024/09/GHSA-3v74-rm67-6782/GHSA-3v74-rm67-6782.json new file mode 100644 index 00000000000..a4324a4dc90 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-3v74-rm67-6782/GHSA-3v74-rm67-6782.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3v74-rm67-6782", + "modified": "2024-09-18T15:30:52Z", + "published": "2024-09-18T15:30:52Z", + "aliases": [ + "CVE-2023-28451" + ], + "details": "An issue was discovered in Technitium 11.0.2. There is a vulnerability (called BadDNS) in DNS resolving software, which triggers a resolver to ignore valid responses, thus causing DoS (denial of service) for normal resolution. The effects of an exploit would be widespread and highly impactful, because the attacker could just forge a response targeting the source port of a vulnerable resolver without the need to guess the correct TXID.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28451" + }, + { + "type": "WEB", + "url": "https://gist.github.com/idealeer/89947ca07836fd0f7e9761198ca9a0f3." + }, + { + "type": "WEB", + "url": "https://technitium.com/dns" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T15:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-3w5w-2v95-54r9/GHSA-3w5w-2v95-54r9.json b/advisories/unreviewed/2024/09/GHSA-3w5w-2v95-54r9/GHSA-3w5w-2v95-54r9.json new file mode 100644 index 00000000000..974a7ab7996 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-3w5w-2v95-54r9/GHSA-3w5w-2v95-54r9.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3w5w-2v95-54r9", + "modified": "2024-09-18T15:30:52Z", + "published": "2024-09-18T15:30:52Z", + "aliases": [ + "CVE-2024-46553" + ], + "details": "Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the ipaddrmsk%d parameter at v2x00.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46553" + }, + { + "type": "WEB", + "url": "https://ink-desk-28f.notion.site/Draytek-vigor-3910-Analysis-Report-b3b23e150c4f4bab822c3c47fd7b9de9#1e21ab70186245aa8fb17578863216e2" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T15:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-3x4g-4374-v83h/GHSA-3x4g-4374-v83h.json b/advisories/unreviewed/2024/09/GHSA-3x4g-4374-v83h/GHSA-3x4g-4374-v83h.json index e7a8929b7fe..4e6caa8d719 100644 --- a/advisories/unreviewed/2024/09/GHSA-3x4g-4374-v83h/GHSA-3x4g-4374-v83h.json +++ b/advisories/unreviewed/2024/09/GHSA-3x4g-4374-v83h/GHSA-3x4g-4374-v83h.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-1188", "CWE-453" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/09/GHSA-45fw-7wjh-qgj9/GHSA-45fw-7wjh-qgj9.json b/advisories/unreviewed/2024/09/GHSA-45fw-7wjh-qgj9/GHSA-45fw-7wjh-qgj9.json new file mode 100644 index 00000000000..482296bb117 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-45fw-7wjh-qgj9/GHSA-45fw-7wjh-qgj9.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-45fw-7wjh-qgj9", + "modified": "2024-09-18T15:30:52Z", + "published": "2024-09-18T15:30:52Z", + "aliases": [ + "CVE-2024-46558" + ], + "details": "Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the newProname parameter at v2x00.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46558" + }, + { + "type": "WEB", + "url": "https://ink-desk-28f.notion.site/Draytek-vigor-3910-Analysis-Report-b3b23e150c4f4bab822c3c47fd7b9de9#43e2ae152385466180ebec957696ceaa" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T15:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-45r4-jrvf-27wr/GHSA-45r4-jrvf-27wr.json b/advisories/unreviewed/2024/09/GHSA-45r4-jrvf-27wr/GHSA-45r4-jrvf-27wr.json new file mode 100644 index 00000000000..546b389eac9 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-45r4-jrvf-27wr/GHSA-45r4-jrvf-27wr.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-45r4-jrvf-27wr", + "modified": "2024-09-18T15:30:53Z", + "published": "2024-09-18T15:30:53Z", + "aliases": [ + "CVE-2024-46571" + ], + "details": "Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sPPPSrvNm parameter at fwuser.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46571" + }, + { + "type": "WEB", + "url": "https://ink-desk-28f.notion.site/Draytek-vigor-3910-Analysis-Report-b3b23e150c4f4bab822c3c47fd7b9de9#b325c78d0d4643b6a2e7703a811f1dd5" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T15:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-4pwx-m3xw-8xj9/GHSA-4pwx-m3xw-8xj9.json b/advisories/unreviewed/2024/09/GHSA-4pwx-m3xw-8xj9/GHSA-4pwx-m3xw-8xj9.json new file mode 100644 index 00000000000..580564db021 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-4pwx-m3xw-8xj9/GHSA-4pwx-m3xw-8xj9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4pwx-m3xw-8xj9", + "modified": "2024-09-18T15:30:51Z", + "published": "2024-09-18T15:30:51Z", + "aliases": [ + "CVE-2024-31175" + ], + "details": "Unchecked Return Value to NULL Pointer Dereference vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of13::TablePropertiesList::unpack.\n\nThis issue affects libfluid: 0.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31175" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-31175" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-690" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T14:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-4qrv-8qq4-m334/GHSA-4qrv-8qq4-m334.json b/advisories/unreviewed/2024/09/GHSA-4qrv-8qq4-m334/GHSA-4qrv-8qq4-m334.json new file mode 100644 index 00000000000..a35fe691181 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-4qrv-8qq4-m334/GHSA-4qrv-8qq4-m334.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4qrv-8qq4-m334", + "modified": "2024-09-18T15:30:51Z", + "published": "2024-09-18T15:30:51Z", + "aliases": [ + "CVE-2024-31185" + ], + "details": "Unchecked Return Value to NULL Pointer Dereference vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of13::MeterBandList::unpack.\n\nThis issue affects libfluid: 0.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31185" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-31185" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-690" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T14:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-55hv-grg7-hf97/GHSA-55hv-grg7-hf97.json b/advisories/unreviewed/2024/09/GHSA-55hv-grg7-hf97/GHSA-55hv-grg7-hf97.json new file mode 100644 index 00000000000..9d220aadbbd --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-55hv-grg7-hf97/GHSA-55hv-grg7-hf97.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-55hv-grg7-hf97", + "modified": "2024-09-18T15:30:53Z", + "published": "2024-09-18T15:30:53Z", + "aliases": [ + "CVE-2024-46565" + ], + "details": "Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sSrvName parameter at service.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46565" + }, + { + "type": "WEB", + "url": "https://ink-desk-28f.notion.site/Draytek-vigor-3910-Analysis-Report-b3b23e150c4f4bab822c3c47fd7b9de9#34ffb536a14f400680eec54e565b25f3" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T15:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-576f-8hqc-j5jv/GHSA-576f-8hqc-j5jv.json b/advisories/unreviewed/2024/09/GHSA-576f-8hqc-j5jv/GHSA-576f-8hqc-j5jv.json new file mode 100644 index 00000000000..6c1fcc28b62 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-576f-8hqc-j5jv/GHSA-576f-8hqc-j5jv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-576f-8hqc-j5jv", + "modified": "2024-09-18T15:30:51Z", + "published": "2024-09-18T15:30:51Z", + "aliases": [ + "CVE-2024-31176" + ], + "details": "Out-of-bounds Read vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of13::TableFeaturePropOXM::unpack.\n\nThis issue affects libfluid: 0.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31176" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-31176" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T14:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-65q7-86f4-pxh5/GHSA-65q7-86f4-pxh5.json b/advisories/unreviewed/2024/09/GHSA-65q7-86f4-pxh5/GHSA-65q7-86f4-pxh5.json new file mode 100644 index 00000000000..014359a50a1 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-65q7-86f4-pxh5/GHSA-65q7-86f4-pxh5.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-65q7-86f4-pxh5", + "modified": "2024-09-18T15:30:53Z", + "published": "2024-09-18T15:30:53Z", + "aliases": [ + "CVE-2024-46593" + ], + "details": "Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the trapcomm parameter at cgiswm.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46593" + }, + { + "type": "WEB", + "url": "https://ink-desk-28f.notion.site/Draytek-vigor-3910-Analysis-Report-b3b23e150c4f4bab822c3c47fd7b9de9#f85d41a6875a4853be9a3c457bc81a33" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T15:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-67cr-pq3q-pqwx/GHSA-67cr-pq3q-pqwx.json b/advisories/unreviewed/2024/09/GHSA-67cr-pq3q-pqwx/GHSA-67cr-pq3q-pqwx.json new file mode 100644 index 00000000000..2a56143b80a --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-67cr-pq3q-pqwx/GHSA-67cr-pq3q-pqwx.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-67cr-pq3q-pqwx", + "modified": "2024-09-18T15:30:52Z", + "published": "2024-09-18T15:30:52Z", + "aliases": [ + "CVE-2024-46552" + ], + "details": "Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sStRtMskShow parameter at ipstrt.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46552" + }, + { + "type": "WEB", + "url": "https://ink-desk-28f.notion.site/Draytek-vigor-3910-Analysis-Report-b3b23e150c4f4bab822c3c47fd7b9de9#53ad238cc1af41f7a32b29260f7274ec" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T15:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-67q9-cxjc-p8vg/GHSA-67q9-cxjc-p8vg.json b/advisories/unreviewed/2024/09/GHSA-67q9-cxjc-p8vg/GHSA-67q9-cxjc-p8vg.json new file mode 100644 index 00000000000..ea4b6acf149 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-67q9-cxjc-p8vg/GHSA-67q9-cxjc-p8vg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-67q9-cxjc-p8vg", + "modified": "2024-09-18T15:30:51Z", + "published": "2024-09-18T15:30:51Z", + "aliases": [ + "CVE-2024-31178" + ], + "details": "Out-of-bounds Read vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of13::TableFeaturePropNextTables::unpack.\n\nThis issue affects libfluid: 0.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31178" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-31178" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T14:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-6fv7-9g8h-f3wm/GHSA-6fv7-9g8h-f3wm.json b/advisories/unreviewed/2024/09/GHSA-6fv7-9g8h-f3wm/GHSA-6fv7-9g8h-f3wm.json new file mode 100644 index 00000000000..7cb3442afde --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-6fv7-9g8h-f3wm/GHSA-6fv7-9g8h-f3wm.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6fv7-9g8h-f3wm", + "modified": "2024-09-18T15:30:52Z", + "published": "2024-09-18T15:30:52Z", + "aliases": [ + "CVE-2024-44542" + ], + "details": "SQL Injection vulnerability in todesk v.1.1 allows a remote attacker to execute arbitrary code via the /todesk.com/news.html parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44542" + }, + { + "type": "WEB", + "url": "https://github.com/alphandbelt/CVE-2024-44542/tree/main" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T15:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-6m86-hgfj-mfmr/GHSA-6m86-hgfj-mfmr.json b/advisories/unreviewed/2024/09/GHSA-6m86-hgfj-mfmr/GHSA-6m86-hgfj-mfmr.json new file mode 100644 index 00000000000..ec20568e656 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-6m86-hgfj-mfmr/GHSA-6m86-hgfj-mfmr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6m86-hgfj-mfmr", + "modified": "2024-09-18T15:30:51Z", + "published": "2024-09-18T15:30:51Z", + "aliases": [ + "CVE-2024-31171" + ], + "details": "Out-of-bounds Read vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of10::StatsReplyPort::unpack.\n\nThis issue affects libfluid: 0.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31171" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-31171" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T14:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-6mgp-6qqc-4g38/GHSA-6mgp-6qqc-4g38.json b/advisories/unreviewed/2024/09/GHSA-6mgp-6qqc-4g38/GHSA-6mgp-6qqc-4g38.json new file mode 100644 index 00000000000..4529b1c7d0a --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-6mgp-6qqc-4g38/GHSA-6mgp-6qqc-4g38.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6mgp-6qqc-4g38", + "modified": "2024-09-18T15:30:52Z", + "published": "2024-09-18T15:30:52Z", + "aliases": [ + "CVE-2023-28455" + ], + "details": "An issue was discovered in Technitium through 11.0.2. The forwarding mode enables attackers to create a query loop using Technitium resolvers, launching amplification attacks and causing potential DoS.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28455" + }, + { + "type": "WEB", + "url": "https://gist.github.com/idealeer/89947ca07836fd0f7e9761198ca9a0f3" + }, + { + "type": "WEB", + "url": "https://technitium.com/dns" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T15:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-6p22-8x2w-g3r3/GHSA-6p22-8x2w-g3r3.json b/advisories/unreviewed/2024/09/GHSA-6p22-8x2w-g3r3/GHSA-6p22-8x2w-g3r3.json new file mode 100644 index 00000000000..aa9d771f478 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-6p22-8x2w-g3r3/GHSA-6p22-8x2w-g3r3.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6p22-8x2w-g3r3", + "modified": "2024-09-18T15:30:53Z", + "published": "2024-09-18T15:30:53Z", + "aliases": [ + "CVE-2024-46583" + ], + "details": "Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the extRadSrv2 parameter at cgiapp.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46583" + }, + { + "type": "WEB", + "url": "https://ink-desk-28f.notion.site/Draytek-vigor-3910-Analysis-Report-b3b23e150c4f4bab822c3c47fd7b9de9#0f15f2bf2eb448c381255850e43cf96a" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T15:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-6p25-v7px-gqph/GHSA-6p25-v7px-gqph.json b/advisories/unreviewed/2024/09/GHSA-6p25-v7px-gqph/GHSA-6p25-v7px-gqph.json new file mode 100644 index 00000000000..5c3da95b887 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-6p25-v7px-gqph/GHSA-6p25-v7px-gqph.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6p25-v7px-gqph", + "modified": "2024-09-18T15:30:52Z", + "published": "2024-09-18T15:30:52Z", + "aliases": [ + "CVE-2023-28456" + ], + "details": "An issue was discovered in Technitium through 11.0.2. It enables attackers to launch amplification attacks (3 times more than other \"golden model\" software like BIND) and cause potential DoS.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28456" + }, + { + "type": "WEB", + "url": "https://gist.github.com/idealeer/89947ca07836fd0f7e9761198ca9a0f3" + }, + { + "type": "WEB", + "url": "https://technitium.com/dns" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T15:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-6p4p-f7m9-43rh/GHSA-6p4p-f7m9-43rh.json b/advisories/unreviewed/2024/09/GHSA-6p4p-f7m9-43rh/GHSA-6p4p-f7m9-43rh.json new file mode 100644 index 00000000000..907863107e8 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-6p4p-f7m9-43rh/GHSA-6p4p-f7m9-43rh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6p4p-f7m9-43rh", + "modified": "2024-09-18T15:30:53Z", + "published": "2024-09-18T15:30:53Z", + "aliases": [ + "CVE-2024-5959" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Eliz Software Panel allows Stored XSS.This issue affects Panel: before v2.3.24.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5959" + }, + { + "type": "WEB", + "url": "https://www.usom.gov.tr/bildirim/tr-24-1497" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T15:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-6qq3-v7mp-wx7q/GHSA-6qq3-v7mp-wx7q.json b/advisories/unreviewed/2024/09/GHSA-6qq3-v7mp-wx7q/GHSA-6qq3-v7mp-wx7q.json index 00befcc6ae1..bc317907d6c 100644 --- a/advisories/unreviewed/2024/09/GHSA-6qq3-v7mp-wx7q/GHSA-6qq3-v7mp-wx7q.json +++ b/advisories/unreviewed/2024/09/GHSA-6qq3-v7mp-wx7q/GHSA-6qq3-v7mp-wx7q.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-783" + "CWE-783", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-735f-p4wh-56vp/GHSA-735f-p4wh-56vp.json b/advisories/unreviewed/2024/09/GHSA-735f-p4wh-56vp/GHSA-735f-p4wh-56vp.json new file mode 100644 index 00000000000..7635d7ebee8 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-735f-p4wh-56vp/GHSA-735f-p4wh-56vp.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-735f-p4wh-56vp", + "modified": "2024-09-18T15:30:52Z", + "published": "2024-09-18T15:30:52Z", + "aliases": [ + "CVE-2024-46550" + ], + "details": "Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the CGIbyFieldName parameter at chglog.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46550" + }, + { + "type": "WEB", + "url": "https://ink-desk-28f.notion.site/Draytek-vigor-3910-Analysis-Report-b3b23e150c4f4bab822c3c47fd7b9de9#bffdd8897d944a77834b865d9326a1d7" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T15:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-735p-552j-x6p3/GHSA-735p-552j-x6p3.json b/advisories/unreviewed/2024/09/GHSA-735p-552j-x6p3/GHSA-735p-552j-x6p3.json new file mode 100644 index 00000000000..0e210b57bf8 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-735p-552j-x6p3/GHSA-735p-552j-x6p3.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-735p-552j-x6p3", + "modified": "2024-09-18T15:30:52Z", + "published": "2024-09-18T15:30:52Z", + "aliases": [ + "CVE-2024-46559" + ], + "details": "Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sBPA_UsrNme parameter at inet15.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46559" + }, + { + "type": "WEB", + "url": "https://ink-desk-28f.notion.site/Draytek-vigor-3910-Analysis-Report-b3b23e150c4f4bab822c3c47fd7b9de9#acee48e159494c479aecc1bfa87f0d83" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T15:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-73xr-wr9g-3273/GHSA-73xr-wr9g-3273.json b/advisories/unreviewed/2024/09/GHSA-73xr-wr9g-3273/GHSA-73xr-wr9g-3273.json new file mode 100644 index 00000000000..460c1ed8b4e --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-73xr-wr9g-3273/GHSA-73xr-wr9g-3273.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-73xr-wr9g-3273", + "modified": "2024-09-18T15:30:53Z", + "published": "2024-09-18T15:30:53Z", + "aliases": [ + "CVE-2024-46589" + ], + "details": "Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sIpv6AiccuUser parameter at inetipv6.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46589" + }, + { + "type": "WEB", + "url": "https://ink-desk-28f.notion.site/Draytek-vigor-3910-Analysis-Report-b3b23e150c4f4bab822c3c47fd7b9de9#e170f53316c740488da5d16f57be1b52" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T15:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-7c28-pwp9-54g4/GHSA-7c28-pwp9-54g4.json b/advisories/unreviewed/2024/09/GHSA-7c28-pwp9-54g4/GHSA-7c28-pwp9-54g4.json new file mode 100644 index 00000000000..f377d5909a4 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-7c28-pwp9-54g4/GHSA-7c28-pwp9-54g4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7c28-pwp9-54g4", + "modified": "2024-09-18T15:30:51Z", + "published": "2024-09-18T15:30:51Z", + "aliases": [ + "CVE-2024-31192" + ], + "details": "Out-of-bounds Read vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of13::MultipartReplyGroupDesc::unpack.\n\nThis issue affects libfluid: 0.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31192" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-31192" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T14:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-7c3x-gh76-g622/GHSA-7c3x-gh76-g622.json b/advisories/unreviewed/2024/09/GHSA-7c3x-gh76-g622/GHSA-7c3x-gh76-g622.json new file mode 100644 index 00000000000..2efc35e4b22 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-7c3x-gh76-g622/GHSA-7c3x-gh76-g622.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7c3x-gh76-g622", + "modified": "2024-09-18T15:30:52Z", + "published": "2024-09-18T15:30:52Z", + "aliases": [ + "CVE-2024-46551" + ], + "details": "Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sBPA_Pwd parameter at inet15.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46551" + }, + { + "type": "WEB", + "url": "https://ink-desk-28f.notion.site/Draytek-vigor-3910-Analysis-Report-b3b23e150c4f4bab822c3c47fd7b9de9#aabdeced2a5e407ba3b3c0d318af0a29" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T15:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-7ghv-w4w7-gjc3/GHSA-7ghv-w4w7-gjc3.json b/advisories/unreviewed/2024/09/GHSA-7ghv-w4w7-gjc3/GHSA-7ghv-w4w7-gjc3.json new file mode 100644 index 00000000000..598cd24746f --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-7ghv-w4w7-gjc3/GHSA-7ghv-w4w7-gjc3.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7ghv-w4w7-gjc3", + "modified": "2024-09-18T15:30:53Z", + "published": "2024-09-18T15:30:53Z", + "aliases": [ + "CVE-2024-46586" + ], + "details": "Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sCloudPass parameter at v2x00.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46586" + }, + { + "type": "WEB", + "url": "https://ink-desk-28f.notion.site/Draytek-vigor-3910-Analysis-Report-b3b23e150c4f4bab822c3c47fd7b9de9#3d4d22d30d164ef9b8fb1fe1024ada3a" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T15:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-7jjq-j5wq-j8cv/GHSA-7jjq-j5wq-j8cv.json b/advisories/unreviewed/2024/09/GHSA-7jjq-j5wq-j8cv/GHSA-7jjq-j5wq-j8cv.json new file mode 100644 index 00000000000..dee149ceafb --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-7jjq-j5wq-j8cv/GHSA-7jjq-j5wq-j8cv.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7jjq-j5wq-j8cv", + "modified": "2024-09-18T15:30:53Z", + "published": "2024-09-18T15:30:53Z", + "aliases": [ + "CVE-2024-46585" + ], + "details": "Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sProfileName parameter at usergrp.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46585" + }, + { + "type": "WEB", + "url": "https://ink-desk-28f.notion.site/Draytek-vigor-3910-Analysis-Report-b3b23e150c4f4bab822c3c47fd7b9de9#8defec5c93be4cdfa5a1ea1078cbe7d2" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T15:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-7pvm-8xr9-7v7g/GHSA-7pvm-8xr9-7v7g.json b/advisories/unreviewed/2024/09/GHSA-7pvm-8xr9-7v7g/GHSA-7pvm-8xr9-7v7g.json new file mode 100644 index 00000000000..aff76388edb --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-7pvm-8xr9-7v7g/GHSA-7pvm-8xr9-7v7g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7pvm-8xr9-7v7g", + "modified": "2024-09-18T15:30:51Z", + "published": "2024-09-18T15:30:51Z", + "aliases": [ + "CVE-2024-31189" + ], + "details": "Out-of-bounds Read vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of13::MultipartRequestTableFeatures::unpack.\n\nThis issue affects libfluid: 0.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31189" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-31189" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T14:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-7pw4-6wxj-w4m4/GHSA-7pw4-6wxj-w4m4.json b/advisories/unreviewed/2024/09/GHSA-7pw4-6wxj-w4m4/GHSA-7pw4-6wxj-w4m4.json new file mode 100644 index 00000000000..417d283f16d --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-7pw4-6wxj-w4m4/GHSA-7pw4-6wxj-w4m4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7pw4-6wxj-w4m4", + "modified": "2024-09-18T15:30:51Z", + "published": "2024-09-18T15:30:51Z", + "aliases": [ + "CVE-2024-31194" + ], + "details": "Out-of-bounds Read vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of13::MultipartReplyPortStats::unpack.\n\nThis issue affects libfluid: 0.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31194" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-31194" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T14:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-8jvv-vmjw-rvrv/GHSA-8jvv-vmjw-rvrv.json b/advisories/unreviewed/2024/09/GHSA-8jvv-vmjw-rvrv/GHSA-8jvv-vmjw-rvrv.json new file mode 100644 index 00000000000..34f1024bb8a --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-8jvv-vmjw-rvrv/GHSA-8jvv-vmjw-rvrv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8jvv-vmjw-rvrv", + "modified": "2024-09-18T15:30:51Z", + "published": "2024-09-18T15:30:51Z", + "aliases": [ + "CVE-2024-31170" + ], + "details": "Out-of-bounds Read vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of10::StatsReplyQueue::unpack.\n\nThis issue affects libfluid: 0.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31170" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-31170" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T14:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-8vvc-wfcp-337x/GHSA-8vvc-wfcp-337x.json b/advisories/unreviewed/2024/09/GHSA-8vvc-wfcp-337x/GHSA-8vvc-wfcp-337x.json new file mode 100644 index 00000000000..ad91cb6d6e6 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-8vvc-wfcp-337x/GHSA-8vvc-wfcp-337x.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8vvc-wfcp-337x", + "modified": "2024-09-18T15:30:53Z", + "published": "2024-09-18T15:30:53Z", + "aliases": [ + "CVE-2024-46594" + ], + "details": "Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the saveVPNProfile parameter at v2x00.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46594" + }, + { + "type": "WEB", + "url": "https://ink-desk-28f.notion.site/Draytek-vigor-3910-Analysis-Report-b3b23e150c4f4bab822c3c47fd7b9de9#33c5e76a919e4f04ae8a7bb039e37131" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T15:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-8xwp-62fq-vgg9/GHSA-8xwp-62fq-vgg9.json b/advisories/unreviewed/2024/09/GHSA-8xwp-62fq-vgg9/GHSA-8xwp-62fq-vgg9.json index 438a174d950..2d932cd0d41 100644 --- a/advisories/unreviewed/2024/09/GHSA-8xwp-62fq-vgg9/GHSA-8xwp-62fq-vgg9.json +++ b/advisories/unreviewed/2024/09/GHSA-8xwp-62fq-vgg9/GHSA-8xwp-62fq-vgg9.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-306" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-923m-rgj5-fgjh/GHSA-923m-rgj5-fgjh.json b/advisories/unreviewed/2024/09/GHSA-923m-rgj5-fgjh/GHSA-923m-rgj5-fgjh.json new file mode 100644 index 00000000000..f983f3e513b --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-923m-rgj5-fgjh/GHSA-923m-rgj5-fgjh.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-923m-rgj5-fgjh", + "modified": "2024-09-18T15:30:53Z", + "published": "2024-09-18T15:30:53Z", + "aliases": [ + "CVE-2024-46580" + ], + "details": "Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the fid parameter at v2x00.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46580" + }, + { + "type": "WEB", + "url": "https://ink-desk-28f.notion.site/Draytek-vigor-3910-Analysis-Report-b3b23e150c4f4bab822c3c47fd7b9de9#230c640b5e354e20b5b529a510079eea" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T15:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-92r2-p37j-59f8/GHSA-92r2-p37j-59f8.json b/advisories/unreviewed/2024/09/GHSA-92r2-p37j-59f8/GHSA-92r2-p37j-59f8.json new file mode 100644 index 00000000000..9e1b73a6b16 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-92r2-p37j-59f8/GHSA-92r2-p37j-59f8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-92r2-p37j-59f8", + "modified": "2024-09-18T15:30:51Z", + "published": "2024-09-18T15:30:51Z", + "aliases": [ + "CVE-2024-31191" + ], + "details": "Out-of-bounds Read vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of13::MultipartReplyMeter::unpack.\n\nThis issue affects libfluid: 0.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31191" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-31191" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T14:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-94jw-wm22-7fjx/GHSA-94jw-wm22-7fjx.json b/advisories/unreviewed/2024/09/GHSA-94jw-wm22-7fjx/GHSA-94jw-wm22-7fjx.json new file mode 100644 index 00000000000..9119e7dbf04 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-94jw-wm22-7fjx/GHSA-94jw-wm22-7fjx.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-94jw-wm22-7fjx", + "modified": "2024-09-18T15:30:53Z", + "published": "2024-09-18T15:30:53Z", + "aliases": [ + "CVE-2024-46597" + ], + "details": "Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sPubKey parameter at dialin.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46597" + }, + { + "type": "WEB", + "url": "https://ink-desk-28f.notion.site/Draytek-vigor-3910-Analysis-Report-b3b23e150c4f4bab822c3c47fd7b9de9#11467dddc16f460db85a5e8d3a6665fb" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T15:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-963r-9g4m-v5vm/GHSA-963r-9g4m-v5vm.json b/advisories/unreviewed/2024/09/GHSA-963r-9g4m-v5vm/GHSA-963r-9g4m-v5vm.json new file mode 100644 index 00000000000..87c8a8f178b --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-963r-9g4m-v5vm/GHSA-963r-9g4m-v5vm.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-963r-9g4m-v5vm", + "modified": "2024-09-18T15:30:53Z", + "published": "2024-09-18T15:30:53Z", + "aliases": [ + "CVE-2024-46567" + ], + "details": "Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the iProfileIdx parameter at v2x00.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46567" + }, + { + "type": "WEB", + "url": "https://ink-desk-28f.notion.site/Draytek-vigor-3910-Analysis-Report-b3b23e150c4f4bab822c3c47fd7b9de9#c17358f2569248cea5c2b6c1bfe94306" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T15:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-9c7x-x2xj-mr98/GHSA-9c7x-x2xj-mr98.json b/advisories/unreviewed/2024/09/GHSA-9c7x-x2xj-mr98/GHSA-9c7x-x2xj-mr98.json new file mode 100644 index 00000000000..018f7863905 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-9c7x-x2xj-mr98/GHSA-9c7x-x2xj-mr98.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9c7x-x2xj-mr98", + "modified": "2024-09-18T15:30:51Z", + "published": "2024-09-18T15:30:51Z", + "aliases": [ + "CVE-2024-31184" + ], + "details": "Out-of-bounds Read vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of13::MeterStats::unpack.\n\nThis issue affects libfluid: 0.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31184" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-31184" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T14:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-9fcx-vcgw-ccc6/GHSA-9fcx-vcgw-ccc6.json b/advisories/unreviewed/2024/09/GHSA-9fcx-vcgw-ccc6/GHSA-9fcx-vcgw-ccc6.json new file mode 100644 index 00000000000..ea8225d786e --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-9fcx-vcgw-ccc6/GHSA-9fcx-vcgw-ccc6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9fcx-vcgw-ccc6", + "modified": "2024-09-18T15:30:53Z", + "published": "2024-09-18T15:30:53Z", + "aliases": [ + "CVE-2024-5960" + ], + "details": "Plaintext Storage of a Password vulnerability in Eliz Software Panel allows : Use of Known Domain Credentials.This issue affects Panel: before v2.3.24.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5960" + }, + { + "type": "WEB", + "url": "https://www.usom.gov.tr/bildirim/tr-24-1497" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-256" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T15:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-9rfc-px2m-hwvj/GHSA-9rfc-px2m-hwvj.json b/advisories/unreviewed/2024/09/GHSA-9rfc-px2m-hwvj/GHSA-9rfc-px2m-hwvj.json new file mode 100644 index 00000000000..93fda18b64b --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-9rfc-px2m-hwvj/GHSA-9rfc-px2m-hwvj.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9rfc-px2m-hwvj", + "modified": "2024-09-18T15:30:52Z", + "published": "2024-09-18T15:30:52Z", + "aliases": [ + "CVE-2023-28457" + ], + "details": "An issue was discovered in Technitium through 11.0.3. It enables attackers to conduct a DNS cache poisoning attack and inject fake responses within 1 second, which is impactful.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28457" + }, + { + "type": "WEB", + "url": "https://gist.github.com/idealeer/89947ca07836fd0f7e9761198ca9a0f3" + }, + { + "type": "WEB", + "url": "https://technitium.com/dns" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T15:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-c5c4-5r7q-ccqv/GHSA-c5c4-5r7q-ccqv.json b/advisories/unreviewed/2024/09/GHSA-c5c4-5r7q-ccqv/GHSA-c5c4-5r7q-ccqv.json new file mode 100644 index 00000000000..9fe29d2bfa4 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-c5c4-5r7q-ccqv/GHSA-c5c4-5r7q-ccqv.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c5c4-5r7q-ccqv", + "modified": "2024-09-18T15:30:52Z", + "published": "2024-09-18T15:30:52Z", + "aliases": [ + "CVE-2024-46555" + ], + "details": "Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the pb parameter at v2x00.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46555" + }, + { + "type": "WEB", + "url": "https://ink-desk-28f.notion.site/Draytek-vigor-3910-Analysis-Report-b3b23e150c4f4bab822c3c47fd7b9de9#e15d03bdd4b9441e8eb157fbd09969f4" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T15:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-c7hq-2xxf-6mw2/GHSA-c7hq-2xxf-6mw2.json b/advisories/unreviewed/2024/09/GHSA-c7hq-2xxf-6mw2/GHSA-c7hq-2xxf-6mw2.json new file mode 100644 index 00000000000..b3e0f80d729 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-c7hq-2xxf-6mw2/GHSA-c7hq-2xxf-6mw2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c7hq-2xxf-6mw2", + "modified": "2024-09-18T15:30:51Z", + "published": "2024-09-18T15:30:51Z", + "aliases": [ + "CVE-2024-31177" + ], + "details": "Out-of-bounds Read vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg modules). This vulnerability is associated with program routines fluid_msg::of13::TableFeaturePropActions::unpack.\n\nThis issue affects libfluid: 0.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31177" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-31177" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T14:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-ccw9-q98h-qv5r/GHSA-ccw9-q98h-qv5r.json b/advisories/unreviewed/2024/09/GHSA-ccw9-q98h-qv5r/GHSA-ccw9-q98h-qv5r.json new file mode 100644 index 00000000000..2c3451cce35 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-ccw9-q98h-qv5r/GHSA-ccw9-q98h-qv5r.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ccw9-q98h-qv5r", + "modified": "2024-09-18T15:30:53Z", + "published": "2024-09-18T15:30:53Z", + "aliases": [ + "CVE-2024-46566" + ], + "details": "Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sAppName parameter at sslapp.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46566" + }, + { + "type": "WEB", + "url": "https://ink-desk-28f.notion.site/Draytek-vigor-3910-Analysis-Report-b3b23e150c4f4bab822c3c47fd7b9de9#fed8e44f6b1e44fa9432a8359c36906a" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T15:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-cxhr-64cg-3mjp/GHSA-cxhr-64cg-3mjp.json b/advisories/unreviewed/2024/09/GHSA-cxhr-64cg-3mjp/GHSA-cxhr-64cg-3mjp.json new file mode 100644 index 00000000000..499cacc018a --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-cxhr-64cg-3mjp/GHSA-cxhr-64cg-3mjp.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cxhr-64cg-3mjp", + "modified": "2024-09-18T15:30:53Z", + "published": "2024-09-18T15:30:53Z", + "aliases": [ + "CVE-2024-46591" + ], + "details": "Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sDnsPro parameter at v2x00.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46591" + }, + { + "type": "WEB", + "url": "https://ink-desk-28f.notion.site/Draytek-vigor-3910-Analysis-Report-b3b23e150c4f4bab822c3c47fd7b9de9#336655c8396248a2b0fc7be9da0b64c9" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T15:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-cxw7-46xp-6h7x/GHSA-cxw7-46xp-6h7x.json b/advisories/unreviewed/2024/09/GHSA-cxw7-46xp-6h7x/GHSA-cxw7-46xp-6h7x.json new file mode 100644 index 00000000000..3dc8d474a0d --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-cxw7-46xp-6h7x/GHSA-cxw7-46xp-6h7x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cxw7-46xp-6h7x", + "modified": "2024-09-18T15:30:52Z", + "published": "2024-09-18T15:30:52Z", + "aliases": [ + "CVE-2024-31198" + ], + "details": "Out-of-bounds Read vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of10::Port:unpack.\n\nThis issue affects libfluid: 0.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31198" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-31198" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T14:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-f826-4hr5-hxxx/GHSA-f826-4hr5-hxxx.json b/advisories/unreviewed/2024/09/GHSA-f826-4hr5-hxxx/GHSA-f826-4hr5-hxxx.json new file mode 100644 index 00000000000..5fa14c766ce --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-f826-4hr5-hxxx/GHSA-f826-4hr5-hxxx.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f826-4hr5-hxxx", + "modified": "2024-09-18T15:30:53Z", + "published": "2024-09-18T15:30:53Z", + "aliases": [ + "CVE-2024-46592" + ], + "details": "Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the ssidencrypt_5g%d parameter at v2x00.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46592" + }, + { + "type": "WEB", + "url": "https://ink-desk-28f.notion.site/Draytek-vigor-3910-Analysis-Report-b3b23e150c4f4bab822c3c47fd7b9de9#1fe94a7181d24f5fbe464a5f9417d084" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T15:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-ff5r-mvxr-r3x8/GHSA-ff5r-mvxr-r3x8.json b/advisories/unreviewed/2024/09/GHSA-ff5r-mvxr-r3x8/GHSA-ff5r-mvxr-r3x8.json new file mode 100644 index 00000000000..90b564652e5 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-ff5r-mvxr-r3x8/GHSA-ff5r-mvxr-r3x8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ff5r-mvxr-r3x8", + "modified": "2024-09-18T15:30:51Z", + "published": "2024-09-18T15:30:51Z", + "aliases": [ + "CVE-2024-31183" + ], + "details": "Out-of-bounds Read vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of13::Hello::unpack.\n\nThis issue affects libfluid: 0.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31183" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-31183" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T14:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-ff8r-g78q-g9wh/GHSA-ff8r-g78q-g9wh.json b/advisories/unreviewed/2024/09/GHSA-ff8r-g78q-g9wh/GHSA-ff8r-g78q-g9wh.json new file mode 100644 index 00000000000..08491141363 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-ff8r-g78q-g9wh/GHSA-ff8r-g78q-g9wh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ff8r-g78q-g9wh", + "modified": "2024-09-18T15:30:51Z", + "published": "2024-09-18T15:30:51Z", + "aliases": [ + "CVE-2024-31172" + ], + "details": "Out-of-bounds Read vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of10::StatsReplyTable::unpack.\n\nThis issue affects libfluid: 0.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31172" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-31172" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T14:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-fgx2-m7jc-63xr/GHSA-fgx2-m7jc-63xr.json b/advisories/unreviewed/2024/09/GHSA-fgx2-m7jc-63xr/GHSA-fgx2-m7jc-63xr.json new file mode 100644 index 00000000000..7cf9c45fad3 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-fgx2-m7jc-63xr/GHSA-fgx2-m7jc-63xr.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fgx2-m7jc-63xr", + "modified": "2024-09-18T15:30:53Z", + "published": "2024-09-18T15:30:53Z", + "aliases": [ + "CVE-2024-46564" + ], + "details": "Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sProfileName parameter at fextobj.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46564" + }, + { + "type": "WEB", + "url": "https://ink-desk-28f.notion.site/Draytek-vigor-3910-Analysis-Report-b3b23e150c4f4bab822c3c47fd7b9de9#4ebd20d478124581b01338b89622363a" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T15:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-fpgw-4ghq-mm93/GHSA-fpgw-4ghq-mm93.json b/advisories/unreviewed/2024/09/GHSA-fpgw-4ghq-mm93/GHSA-fpgw-4ghq-mm93.json new file mode 100644 index 00000000000..c6569100d82 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-fpgw-4ghq-mm93/GHSA-fpgw-4ghq-mm93.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fpgw-4ghq-mm93", + "modified": "2024-09-18T15:30:53Z", + "published": "2024-09-18T15:30:53Z", + "aliases": [ + "CVE-2024-46561" + ], + "details": "Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the queryret parameter at v2x00.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46561" + }, + { + "type": "WEB", + "url": "https://ink-desk-28f.notion.site/Draytek-vigor-3910-Analysis-Report-b3b23e150c4f4bab822c3c47fd7b9de9#48ac749c7e444d8398b414f9d1d48c40" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T15:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-fqmh-8xfw-5v84/GHSA-fqmh-8xfw-5v84.json b/advisories/unreviewed/2024/09/GHSA-fqmh-8xfw-5v84/GHSA-fqmh-8xfw-5v84.json new file mode 100644 index 00000000000..e607a715442 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-fqmh-8xfw-5v84/GHSA-fqmh-8xfw-5v84.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fqmh-8xfw-5v84", + "modified": "2024-09-18T15:30:52Z", + "published": "2024-09-18T15:30:52Z", + "aliases": [ + "CVE-2024-46560" + ], + "details": "Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the pub_key parameter at v2x00.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46560" + }, + { + "type": "WEB", + "url": "https://ink-desk-28f.notion.site/Draytek-vigor-3910-Analysis-Report-b3b23e150c4f4bab822c3c47fd7b9de9#2a9a497ab8214aeb991df9b9714b3c25" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T15:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-fqvq-m9ff-5v4w/GHSA-fqvq-m9ff-5v4w.json b/advisories/unreviewed/2024/09/GHSA-fqvq-m9ff-5v4w/GHSA-fqvq-m9ff-5v4w.json new file mode 100644 index 00000000000..2ccd0fc417d --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-fqvq-m9ff-5v4w/GHSA-fqvq-m9ff-5v4w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fqvq-m9ff-5v4w", + "modified": "2024-09-18T15:30:49Z", + "published": "2024-09-18T15:30:49Z", + "aliases": [ + "CVE-2024-23915" + ], + "details": "Unchecked Return Value to NULL Pointer Dereference vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routines fluid_msg::of13::InstructionSet::unpack.\n\nThis issue affects libfluid: 0.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23915" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-23915" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-690" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T14:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-frph-pw87-p4w6/GHSA-frph-pw87-p4w6.json b/advisories/unreviewed/2024/09/GHSA-frph-pw87-p4w6/GHSA-frph-pw87-p4w6.json new file mode 100644 index 00000000000..64cbc156b34 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-frph-pw87-p4w6/GHSA-frph-pw87-p4w6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-frph-pw87-p4w6", + "modified": "2024-09-18T15:30:50Z", + "published": "2024-09-18T15:30:50Z", + "aliases": [ + "CVE-2024-31168" + ], + "details": "Out-of-bounds Read vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::EchoCommon::unpack.\n\nThis issue affects libfluid: 0.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31168" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-31168" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T14:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-fxq3-rjrf-gqq3/GHSA-fxq3-rjrf-gqq3.json b/advisories/unreviewed/2024/09/GHSA-fxq3-rjrf-gqq3/GHSA-fxq3-rjrf-gqq3.json new file mode 100644 index 00000000000..e5545c29405 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-fxq3-rjrf-gqq3/GHSA-fxq3-rjrf-gqq3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fxq3-rjrf-gqq3", + "modified": "2024-09-18T15:30:52Z", + "published": "2024-09-18T15:30:52Z", + "aliases": [ + "CVE-2024-34026" + ], + "details": "A stack-based buffer overflow vulnerability exists in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC _v3 b4702061dc14d1024856f71b4543298d77007b88. A specially crafted EtherNet/IP request can lead to remote code execution. An attacker can send a series of EtherNet/IP requests to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34026" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2005" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T15:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-g38f-j3m7-3p88/GHSA-g38f-j3m7-3p88.json b/advisories/unreviewed/2024/09/GHSA-g38f-j3m7-3p88/GHSA-g38f-j3m7-3p88.json new file mode 100644 index 00000000000..6f9650a7f8b --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-g38f-j3m7-3p88/GHSA-g38f-j3m7-3p88.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g38f-j3m7-3p88", + "modified": "2024-09-18T15:30:52Z", + "published": "2024-09-18T15:30:52Z", + "aliases": [ + "CVE-2024-36980" + ], + "details": "An out-of-bounds read vulnerability exists in the OpenPLC Runtime EtherNet/IP PCCC parser functionality of OpenPLC_v3 b4702061dc14d1024856f71b4543298d77007b88. A specially crafted network request can lead to denial of service. An attacker can send a series of EtherNet/IP requests to trigger this vulnerability.This is the first instance of the incorrect comparison.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36980" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2004" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T15:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-g399-5j3g-vm56/GHSA-g399-5j3g-vm56.json b/advisories/unreviewed/2024/09/GHSA-g399-5j3g-vm56/GHSA-g399-5j3g-vm56.json new file mode 100644 index 00000000000..62fb25e55e9 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-g399-5j3g-vm56/GHSA-g399-5j3g-vm56.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g399-5j3g-vm56", + "modified": "2024-09-18T15:30:52Z", + "published": "2024-09-18T15:30:52Z", + "aliases": [ + "CVE-2024-8891" + ], + "details": "An attacker with no knowledge of the current users in the web application, could build a dictionary of potential users and check the server responses as it indicates whether or not the user is present in CIRCUTOR Q-SMT in its firmware version 1.0.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8891" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso-sci/multiple-vulnerabilities-circutor-products" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-359" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T14:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-g4r7-86gm-pgqc/GHSA-g4r7-86gm-pgqc.json b/advisories/unreviewed/2024/09/GHSA-g4r7-86gm-pgqc/GHSA-g4r7-86gm-pgqc.json new file mode 100644 index 00000000000..654e0f7af39 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-g4r7-86gm-pgqc/GHSA-g4r7-86gm-pgqc.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g4r7-86gm-pgqc", + "modified": "2024-09-18T15:30:52Z", + "published": "2024-09-18T15:30:52Z", + "aliases": [ + "CVE-2024-35515" + ], + "details": "Insecure deserialization in sqlitedict up to v2.1.0 allows attackers to execute arbitrary code.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35515" + }, + { + "type": "WEB", + "url": "https://github.com/piskvorky/sqlitedict" + }, + { + "type": "WEB", + "url": "https://wha13.github.io/2024/06/13/mfcve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T15:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-g7fv-v867-rmwj/GHSA-g7fv-v867-rmwj.json b/advisories/unreviewed/2024/09/GHSA-g7fv-v867-rmwj/GHSA-g7fv-v867-rmwj.json index ce342d66a5c..406da9ca22e 100644 --- a/advisories/unreviewed/2024/09/GHSA-g7fv-v867-rmwj/GHSA-g7fv-v867-rmwj.json +++ b/advisories/unreviewed/2024/09/GHSA-g7fv-v867-rmwj/GHSA-g7fv-v867-rmwj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g7fv-v867-rmwj", - "modified": "2024-09-13T15:31:36Z", + "modified": "2024-09-18T15:30:48Z", "published": "2024-09-13T15:31:36Z", "aliases": [ "CVE-2024-8269" diff --git a/advisories/unreviewed/2024/09/GHSA-gfx6-fv9x-fgpc/GHSA-gfx6-fv9x-fgpc.json b/advisories/unreviewed/2024/09/GHSA-gfx6-fv9x-fgpc/GHSA-gfx6-fv9x-fgpc.json new file mode 100644 index 00000000000..ab5b3cb0ea6 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-gfx6-fv9x-fgpc/GHSA-gfx6-fv9x-fgpc.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gfx6-fv9x-fgpc", + "modified": "2024-09-18T15:30:52Z", + "published": "2024-09-18T15:30:52Z", + "aliases": [ + "CVE-2024-39081" + ], + "details": "An issue in SMART TYRE CAR & BIKE v4.2.0 allows attackers to perform a man-in-the-middle attack via Bluetooth communications.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39081" + }, + { + "type": "WEB", + "url": "https://github.com/Amirasaiyad/BLE-TPMS/blob/main/README.md" + }, + { + "type": "WEB", + "url": "https://github.com/Amirasaiyad/BLE-TPMS/blob/main/Treel_BLE_TPMS_Penetration_Testing_Report.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T14:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-gvgp-m8mg-49xw/GHSA-gvgp-m8mg-49xw.json b/advisories/unreviewed/2024/09/GHSA-gvgp-m8mg-49xw/GHSA-gvgp-m8mg-49xw.json new file mode 100644 index 00000000000..c35d34b7277 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-gvgp-m8mg-49xw/GHSA-gvgp-m8mg-49xw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gvgp-m8mg-49xw", + "modified": "2024-09-18T15:30:49Z", + "published": "2024-09-18T15:30:49Z", + "aliases": [ + "CVE-2024-8890" + ], + "details": "An attacker with access to the network where the CIRCUTOR Q-SMT is located in its firmware version 1.0.4, could obtain legitimate credentials or steal sessions due to the fact that the device only implements the HTTP protocol. This fact prevents a secure communication channel from being established.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8890" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso-sci/multiple-vulnerabilities-circutor-products" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-201" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T13:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-h2pr-ggrm-q7gx/GHSA-h2pr-ggrm-q7gx.json b/advisories/unreviewed/2024/09/GHSA-h2pr-ggrm-q7gx/GHSA-h2pr-ggrm-q7gx.json new file mode 100644 index 00000000000..c8b78752137 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-h2pr-ggrm-q7gx/GHSA-h2pr-ggrm-q7gx.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h2pr-ggrm-q7gx", + "modified": "2024-09-18T15:30:53Z", + "published": "2024-09-18T15:30:53Z", + "aliases": [ + "CVE-2024-46588" + ], + "details": "Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sProfileName parameter at wizfw.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46588" + }, + { + "type": "WEB", + "url": "https://ink-desk-28f.notion.site/Draytek-vigor-3910-Analysis-Report-b3b23e150c4f4bab822c3c47fd7b9de9#7be91fa3afab4c9c978f7f6c1cc4c847" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T15:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-h439-4q4v-53mg/GHSA-h439-4q4v-53mg.json b/advisories/unreviewed/2024/09/GHSA-h439-4q4v-53mg/GHSA-h439-4q4v-53mg.json new file mode 100644 index 00000000000..e591c093406 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-h439-4q4v-53mg/GHSA-h439-4q4v-53mg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h439-4q4v-53mg", + "modified": "2024-09-18T15:30:51Z", + "published": "2024-09-18T15:30:51Z", + "aliases": [ + "CVE-2024-31188" + ], + "details": "Out-of-bounds Read vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of13::MultipartReplyTableFeatures::unpack.\n\nThis issue affects libfluid: 0.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31188" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-31188" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T14:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-h66g-2x3f-vgpp/GHSA-h66g-2x3f-vgpp.json b/advisories/unreviewed/2024/09/GHSA-h66g-2x3f-vgpp/GHSA-h66g-2x3f-vgpp.json new file mode 100644 index 00000000000..cd3ee83fb77 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-h66g-2x3f-vgpp/GHSA-h66g-2x3f-vgpp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h66g-2x3f-vgpp", + "modified": "2024-09-18T15:30:53Z", + "published": "2024-09-18T15:30:53Z", + "aliases": [ + "CVE-2024-5958" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eliz Software Panel allows Command Line Execution through SQL Injection.This issue affects Panel: before v2.3.24.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5958" + }, + { + "type": "WEB", + "url": "https://www.usom.gov.tr/bildirim/tr-24-1497" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T15:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-hfmw-7g3m-gj6q/GHSA-hfmw-7g3m-gj6q.json b/advisories/unreviewed/2024/09/GHSA-hfmw-7g3m-gj6q/GHSA-hfmw-7g3m-gj6q.json new file mode 100644 index 00000000000..54609b40ab7 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-hfmw-7g3m-gj6q/GHSA-hfmw-7g3m-gj6q.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hfmw-7g3m-gj6q", + "modified": "2024-09-18T15:30:52Z", + "published": "2024-09-18T15:30:52Z", + "aliases": [ + "CVE-2023-28452" + ], + "details": "An issue was discovered in CoreDNS through 1.10.1. There is a vulnerability in DNS resolving software, which triggers a resolver to ignore valid responses, thus causing denial of service for normal resolution. In an exploit, the attacker could just forge a response targeting the source port of a vulnerable resolver without the need to guess the correct TXID.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28452" + }, + { + "type": "WEB", + "url": "https://coredns.io" + }, + { + "type": "WEB", + "url": "https://gist.github.com/idealeer/e41c7fb3b661d4262d0b6f21e12168ba" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T15:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-j298-ggff-cvm8/GHSA-j298-ggff-cvm8.json b/advisories/unreviewed/2024/09/GHSA-j298-ggff-cvm8/GHSA-j298-ggff-cvm8.json new file mode 100644 index 00000000000..09d77308643 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-j298-ggff-cvm8/GHSA-j298-ggff-cvm8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j298-ggff-cvm8", + "modified": "2024-09-18T15:30:49Z", + "published": "2024-09-18T15:30:49Z", + "aliases": [ + "CVE-2024-23916" + ], + "details": "Unchecked Return Value to NULL Pointer Dereference vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routines fluid_msg::ActionSet::unpack.\n\nThis issue affects libfluid: 0.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23916" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-23916" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-690" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T14:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-jvw4-8x97-wppq/GHSA-jvw4-8x97-wppq.json b/advisories/unreviewed/2024/09/GHSA-jvw4-8x97-wppq/GHSA-jvw4-8x97-wppq.json new file mode 100644 index 00000000000..a0a858c4673 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-jvw4-8x97-wppq/GHSA-jvw4-8x97-wppq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jvw4-8x97-wppq", + "modified": "2024-09-18T15:30:51Z", + "published": "2024-09-18T15:30:51Z", + "aliases": [ + "CVE-2024-31179" + ], + "details": "Out-of-bounds Read vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of13::TableFeaturePropInstruction::unpack.\n\nThis issue affects libfluid: 0.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31179" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-31179" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T14:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-m38v-7vc8-5x55/GHSA-m38v-7vc8-5x55.json b/advisories/unreviewed/2024/09/GHSA-m38v-7vc8-5x55/GHSA-m38v-7vc8-5x55.json new file mode 100644 index 00000000000..e22ff8b007d --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-m38v-7vc8-5x55/GHSA-m38v-7vc8-5x55.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m38v-7vc8-5x55", + "modified": "2024-09-18T15:30:53Z", + "published": "2024-09-18T15:30:53Z", + "aliases": [ + "CVE-2024-46584" + ], + "details": "Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the AControlIp1 parameter at acontrol.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46584" + }, + { + "type": "WEB", + "url": "https://ink-desk-28f.notion.site/Draytek-vigor-3910-Analysis-Report-b3b23e150c4f4bab822c3c47fd7b9de9#20fb6e1bcec049728e6319d9da46416d" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T15:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-m67j-wqgc-38f3/GHSA-m67j-wqgc-38f3.json b/advisories/unreviewed/2024/09/GHSA-m67j-wqgc-38f3/GHSA-m67j-wqgc-38f3.json new file mode 100644 index 00000000000..7a78d4fc8ad --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-m67j-wqgc-38f3/GHSA-m67j-wqgc-38f3.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m67j-wqgc-38f3", + "modified": "2024-09-18T15:30:53Z", + "published": "2024-09-18T15:30:53Z", + "aliases": [ + "CVE-2024-46568" + ], + "details": "Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sPeerId parameter at vpn.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46568" + }, + { + "type": "WEB", + "url": "https://ink-desk-28f.notion.site/Draytek-vigor-3910-Analysis-Report-b3b23e150c4f4bab822c3c47fd7b9de9#41a3e5586f424ceb858a5a66836a40cb" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T15:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-m92x-f2xf-6w5q/GHSA-m92x-f2xf-6w5q.json b/advisories/unreviewed/2024/09/GHSA-m92x-f2xf-6w5q/GHSA-m92x-f2xf-6w5q.json new file mode 100644 index 00000000000..00a7d0595bf --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-m92x-f2xf-6w5q/GHSA-m92x-f2xf-6w5q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m92x-f2xf-6w5q", + "modified": "2024-09-18T15:30:52Z", + "published": "2024-09-18T15:30:52Z", + "aliases": [ + "CVE-2024-36981" + ], + "details": "An out-of-bounds read vulnerability exists in the OpenPLC Runtime EtherNet/IP PCCC parser functionality of OpenPLC_v3 b4702061dc14d1024856f71b4543298d77007b88. A specially crafted network request can lead to denial of service. An attacker can send a series of EtherNet/IP requests to trigger this vulnerability.This is the final instance of the incorrect comparison.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36981" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2004" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T15:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-m9w6-r7mg-6gqq/GHSA-m9w6-r7mg-6gqq.json b/advisories/unreviewed/2024/09/GHSA-m9w6-r7mg-6gqq/GHSA-m9w6-r7mg-6gqq.json new file mode 100644 index 00000000000..6437717b69f --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-m9w6-r7mg-6gqq/GHSA-m9w6-r7mg-6gqq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m9w6-r7mg-6gqq", + "modified": "2024-09-18T15:30:50Z", + "published": "2024-09-18T15:30:50Z", + "aliases": [ + "CVE-2024-31167" + ], + "details": "Unchecked Return Value to NULL Pointer Dereference vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::QueuePropertyList::unpack13.\n\nThis issue affects libfluid: 0.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31167" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-31167" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-690" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T14:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-mcw8-xx8x-344q/GHSA-mcw8-xx8x-344q.json b/advisories/unreviewed/2024/09/GHSA-mcw8-xx8x-344q/GHSA-mcw8-xx8x-344q.json new file mode 100644 index 00000000000..abde2e8a79f --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-mcw8-xx8x-344q/GHSA-mcw8-xx8x-344q.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mcw8-xx8x-344q", + "modified": "2024-09-18T15:30:53Z", + "published": "2024-09-18T15:30:53Z", + "aliases": [ + "CVE-2024-46590" + ], + "details": "Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the ssidencrypt%d parameter at v2x00.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46590" + }, + { + "type": "WEB", + "url": "https://ink-desk-28f.notion.site/Draytek-vigor-3910-Analysis-Report-b3b23e150c4f4bab822c3c47fd7b9de9#e0a960e24de649b3a67c21a63592d82f" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T15:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-mh89-qc88-2rhh/GHSA-mh89-qc88-2rhh.json b/advisories/unreviewed/2024/09/GHSA-mh89-qc88-2rhh/GHSA-mh89-qc88-2rhh.json new file mode 100644 index 00000000000..1aa086b8c2f --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-mh89-qc88-2rhh/GHSA-mh89-qc88-2rhh.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mh89-qc88-2rhh", + "modified": "2024-09-18T15:30:53Z", + "published": "2024-09-18T15:30:53Z", + "aliases": [ + "CVE-2024-46595" + ], + "details": "Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the saveitem parameter at lan2lan.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46595" + }, + { + "type": "WEB", + "url": "https://ink-desk-28f.notion.site/Draytek-vigor-3910-Analysis-Report-b3b23e150c4f4bab822c3c47fd7b9de9#7f26d2119de54d5fbc25a8d3ebe2b16c" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T15:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-mv2p-f8px-fp4v/GHSA-mv2p-f8px-fp4v.json b/advisories/unreviewed/2024/09/GHSA-mv2p-f8px-fp4v/GHSA-mv2p-f8px-fp4v.json new file mode 100644 index 00000000000..b7d351706bf --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-mv2p-f8px-fp4v/GHSA-mv2p-f8px-fp4v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mv2p-f8px-fp4v", + "modified": "2024-09-18T15:30:51Z", + "published": "2024-09-18T15:30:51Z", + "aliases": [ + "CVE-2024-31187" + ], + "details": "Out-of-bounds Read vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of13::MultipartReplyPortDescription::unpack.\n\nThis issue affects libfluid: 0.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31187" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-31187" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T14:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-p22p-4gp5-hqw7/GHSA-p22p-4gp5-hqw7.json b/advisories/unreviewed/2024/09/GHSA-p22p-4gp5-hqw7/GHSA-p22p-4gp5-hqw7.json new file mode 100644 index 00000000000..87e2302e1a7 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-p22p-4gp5-hqw7/GHSA-p22p-4gp5-hqw7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p22p-4gp5-hqw7", + "modified": "2024-09-18T15:30:49Z", + "published": "2024-09-18T15:30:49Z", + "aliases": [ + "CVE-2024-31164" + ], + "details": "Unchecked Return Value to NULL Pointer Dereference vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routines fluid_msg::ActionList::unpack13.\n\nThis issue affects libfluid: 0.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31164" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-31164" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-690" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T14:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-p47w-6xhw-hhxj/GHSA-p47w-6xhw-hhxj.json b/advisories/unreviewed/2024/09/GHSA-p47w-6xhw-hhxj/GHSA-p47w-6xhw-hhxj.json index 9730d444950..cae3c28c6f6 100644 --- a/advisories/unreviewed/2024/09/GHSA-p47w-6xhw-hhxj/GHSA-p47w-6xhw-hhxj.json +++ b/advisories/unreviewed/2024/09/GHSA-p47w-6xhw-hhxj/GHSA-p47w-6xhw-hhxj.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-pcw9-jcmv-xqqq/GHSA-pcw9-jcmv-xqqq.json b/advisories/unreviewed/2024/09/GHSA-pcw9-jcmv-xqqq/GHSA-pcw9-jcmv-xqqq.json new file mode 100644 index 00000000000..e16b95e9519 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-pcw9-jcmv-xqqq/GHSA-pcw9-jcmv-xqqq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pcw9-jcmv-xqqq", + "modified": "2024-09-18T15:30:51Z", + "published": "2024-09-18T15:30:51Z", + "aliases": [ + "CVE-2024-31182" + ], + "details": "Unchecked Return Value to NULL Pointer Dereference vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::QueuePropertyList::unpack10.\n\nThis issue affects libfluid: 0.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31182" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-31182" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-690" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T14:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-pv49-965m-2m35/GHSA-pv49-965m-2m35.json b/advisories/unreviewed/2024/09/GHSA-pv49-965m-2m35/GHSA-pv49-965m-2m35.json new file mode 100644 index 00000000000..868202f53ac --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-pv49-965m-2m35/GHSA-pv49-965m-2m35.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pv49-965m-2m35", + "modified": "2024-09-18T15:30:51Z", + "published": "2024-09-18T15:30:51Z", + "aliases": [ + "CVE-2024-31181" + ], + "details": "Out-of-bounds Read vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of13::GroupStats::unpack.\n\nThis issue affects libfluid: 0.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31181" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-31181" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T14:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-q247-wj3r-2x97/GHSA-q247-wj3r-2x97.json b/advisories/unreviewed/2024/09/GHSA-q247-wj3r-2x97/GHSA-q247-wj3r-2x97.json new file mode 100644 index 00000000000..f0ce0b39858 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-q247-wj3r-2x97/GHSA-q247-wj3r-2x97.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q247-wj3r-2x97", + "modified": "2024-09-18T15:30:53Z", + "published": "2024-09-18T15:30:53Z", + "aliases": [ + "CVE-2024-6878" + ], + "details": "Files or Directories Accessible to External Parties vulnerability in Eliz Software Panel allows Collect Data from Common Resource Locations.This issue affects Panel: before v2.3.24.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6878" + }, + { + "type": "WEB", + "url": "https://www.usom.gov.tr/bildirim/tr-24-1497" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-552" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T15:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-q74x-f8wx-jrgv/GHSA-q74x-f8wx-jrgv.json b/advisories/unreviewed/2024/09/GHSA-q74x-f8wx-jrgv/GHSA-q74x-f8wx-jrgv.json index 4f67e4b1b08..aa42a4a7895 100644 --- a/advisories/unreviewed/2024/09/GHSA-q74x-f8wx-jrgv/GHSA-q74x-f8wx-jrgv.json +++ b/advisories/unreviewed/2024/09/GHSA-q74x-f8wx-jrgv/GHSA-q74x-f8wx-jrgv.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-783" + "CWE-783", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-q786-f28r-38f4/GHSA-q786-f28r-38f4.json b/advisories/unreviewed/2024/09/GHSA-q786-f28r-38f4/GHSA-q786-f28r-38f4.json new file mode 100644 index 00000000000..a320b4e78a0 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-q786-f28r-38f4/GHSA-q786-f28r-38f4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q786-f28r-38f4", + "modified": "2024-09-18T15:30:51Z", + "published": "2024-09-18T15:30:51Z", + "aliases": [ + "CVE-2024-31173" + ], + "details": "Out-of-bounds Read vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of10::StatsReplyFlow::unpack.\n\nThis issue affects libfluid: 0.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31173" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-31173" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T14:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-qc32-xfvc-33fg/GHSA-qc32-xfvc-33fg.json b/advisories/unreviewed/2024/09/GHSA-qc32-xfvc-33fg/GHSA-qc32-xfvc-33fg.json new file mode 100644 index 00000000000..24aeb67b0d2 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-qc32-xfvc-33fg/GHSA-qc32-xfvc-33fg.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qc32-xfvc-33fg", + "modified": "2024-09-18T15:30:52Z", + "published": "2024-09-18T15:30:52Z", + "aliases": [ + "CVE-2023-49203" + ], + "details": "Technitium 11.5.3 allows remote attackers to cause a denial of service (bandwidth amplification) because the DNSBomb manipulation causes accumulation of low-rate DNS queries such that there is a large-sized response in a burst of traffic.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49203" + }, + { + "type": "WEB", + "url": "https://gist.github.com/idealeer/89947ca07836fd0f7e9761198ca9a0f3." + }, + { + "type": "WEB", + "url": "https://technitium.com/dns" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T15:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-qx8f-4333-p3gq/GHSA-qx8f-4333-p3gq.json b/advisories/unreviewed/2024/09/GHSA-qx8f-4333-p3gq/GHSA-qx8f-4333-p3gq.json new file mode 100644 index 00000000000..95c39063592 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-qx8f-4333-p3gq/GHSA-qx8f-4333-p3gq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qx8f-4333-p3gq", + "modified": "2024-09-18T15:30:51Z", + "published": "2024-09-18T15:30:51Z", + "aliases": [ + "CVE-2024-31186" + ], + "details": "Out-of-bounds Read vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of13::QueueGetConfigReply::unpack.\n\nThis issue affects libfluid: 0.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31186" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-31186" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T14:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-rjg6-j4q2-2v5v/GHSA-rjg6-j4q2-2v5v.json b/advisories/unreviewed/2024/09/GHSA-rjg6-j4q2-2v5v/GHSA-rjg6-j4q2-2v5v.json new file mode 100644 index 00000000000..557efaad70a --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-rjg6-j4q2-2v5v/GHSA-rjg6-j4q2-2v5v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rjg6-j4q2-2v5v", + "modified": "2024-09-18T15:30:52Z", + "published": "2024-09-18T15:30:52Z", + "aliases": [ + "CVE-2024-31196" + ], + "details": "Unchecked Return Value to NULL Pointer Dereference vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::ActionList::unpack10.\n\nThis issue affects libfluid: 0.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31196" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-31196" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-690" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T14:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-rv5g-p7p6-mpxp/GHSA-rv5g-p7p6-mpxp.json b/advisories/unreviewed/2024/09/GHSA-rv5g-p7p6-mpxp/GHSA-rv5g-p7p6-mpxp.json new file mode 100644 index 00000000000..64359e00655 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-rv5g-p7p6-mpxp/GHSA-rv5g-p7p6-mpxp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rv5g-p7p6-mpxp", + "modified": "2024-09-18T15:30:50Z", + "published": "2024-09-18T15:30:50Z", + "aliases": [ + "CVE-2024-31165" + ], + "details": "Unchecked Return Value to NULL Pointer Dereference vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of13::SetFieldAction::unpack.\n\nThis issue affects libfluid: 0.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31165" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-31165" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-690" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T14:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-rwf3-hrxc-h758/GHSA-rwf3-hrxc-h758.json b/advisories/unreviewed/2024/09/GHSA-rwf3-hrxc-h758/GHSA-rwf3-hrxc-h758.json new file mode 100644 index 00000000000..363f171de99 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-rwf3-hrxc-h758/GHSA-rwf3-hrxc-h758.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rwf3-hrxc-h758", + "modified": "2024-09-18T15:30:51Z", + "published": "2024-09-18T15:30:51Z", + "aliases": [ + "CVE-2024-31193" + ], + "details": "Out-of-bounds Read vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of13::MultipartReplyGroup::unpack.\n\nThis issue affects libfluid: 0.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31193" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-31193" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T14:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-vcr3-pvg9-93rg/GHSA-vcr3-pvg9-93rg.json b/advisories/unreviewed/2024/09/GHSA-vcr3-pvg9-93rg/GHSA-vcr3-pvg9-93rg.json new file mode 100644 index 00000000000..eb9ce245110 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-vcr3-pvg9-93rg/GHSA-vcr3-pvg9-93rg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vcr3-pvg9-93rg", + "modified": "2024-09-18T15:30:49Z", + "published": "2024-09-18T15:30:49Z", + "aliases": [ + "CVE-2024-8892" + ], + "details": "Vulnerability in CIRCUTOR TCP2RS+ firmware version 1.3b, which could allow an attacker to modify any configuration value, even if the device has the user/password authentication option enabled, without authentication by sending packets through the UDP protocol and port 2000, deconfiguring the device and thus disabling its use. This equipment is at the end of its useful life cycle.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8892" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso-sci/multiple-vulnerabilities-circutor-products" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T13:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-vg9q-pxh6-vg9v/GHSA-vg9q-pxh6-vg9v.json b/advisories/unreviewed/2024/09/GHSA-vg9q-pxh6-vg9v/GHSA-vg9q-pxh6-vg9v.json new file mode 100644 index 00000000000..7965d464c3a --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-vg9q-pxh6-vg9v/GHSA-vg9q-pxh6-vg9v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vg9q-pxh6-vg9v", + "modified": "2024-09-18T15:30:51Z", + "published": "2024-09-18T15:30:51Z", + "aliases": [ + "CVE-2024-31190" + ], + "details": "Out-of-bounds Read vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of13::MultipartReplyMeterConfig::unpack.\n\nThis issue affects libfluid: 0.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31190" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-31190" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T14:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-vgw3-33x7-h3gh/GHSA-vgw3-33x7-h3gh.json b/advisories/unreviewed/2024/09/GHSA-vgw3-33x7-h3gh/GHSA-vgw3-33x7-h3gh.json new file mode 100644 index 00000000000..62bb117413e --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-vgw3-33x7-h3gh/GHSA-vgw3-33x7-h3gh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vgw3-33x7-h3gh", + "modified": "2024-09-18T15:30:50Z", + "published": "2024-09-18T15:30:50Z", + "aliases": [ + "CVE-2024-31166" + ], + "details": "Out-of-bounds Read vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of13::HelloElemVersionBitmap::unpack.\n\nThis issue affects libfluid: 0.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31166" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-31166" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T14:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-vm47-pw3h-2qgg/GHSA-vm47-pw3h-2qgg.json b/advisories/unreviewed/2024/09/GHSA-vm47-pw3h-2qgg/GHSA-vm47-pw3h-2qgg.json new file mode 100644 index 00000000000..f0f5d014ff0 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-vm47-pw3h-2qgg/GHSA-vm47-pw3h-2qgg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vm47-pw3h-2qgg", + "modified": "2024-09-18T15:30:51Z", + "published": "2024-09-18T15:30:51Z", + "aliases": [ + "CVE-2024-31180" + ], + "details": "Out-of-bounds Read vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of13::GroupDesc::unpack.\n\nThis issue affects libfluid: 0.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31180" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-31180" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T14:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-vvxm-2vxq-rhgq/GHSA-vvxm-2vxq-rhgq.json b/advisories/unreviewed/2024/09/GHSA-vvxm-2vxq-rhgq/GHSA-vvxm-2vxq-rhgq.json index 2b7076c23a9..87611700d19 100644 --- a/advisories/unreviewed/2024/09/GHSA-vvxm-2vxq-rhgq/GHSA-vvxm-2vxq-rhgq.json +++ b/advisories/unreviewed/2024/09/GHSA-vvxm-2vxq-rhgq/GHSA-vvxm-2vxq-rhgq.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vvxm-2vxq-rhgq", - "modified": "2024-09-18T12:31:31Z", + "modified": "2024-09-18T15:30:49Z", "published": "2024-09-18T12:31:31Z", "aliases": [ "CVE-2024-5682" ], "details": "Improper Restriction of Excessive Authentication Attempts vulnerability in Yordam Information Technology Yordam Library Automation System allows Interface Manipulation.This issue affects Yordam Library Automation System: before 20.1.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/09/GHSA-w392-75q8-vr67/GHSA-w392-75q8-vr67.json b/advisories/unreviewed/2024/09/GHSA-w392-75q8-vr67/GHSA-w392-75q8-vr67.json new file mode 100644 index 00000000000..fa203bc7792 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-w392-75q8-vr67/GHSA-w392-75q8-vr67.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w392-75q8-vr67", + "modified": "2024-09-18T15:30:52Z", + "published": "2024-09-18T15:30:52Z", + "aliases": [ + "CVE-2024-45858" + ], + "details": "An arbitrary code execution vulnerability exists in versions 0.2.9 up to 0.5.10 of the Guardrails AI Guardrails framework because of the way it validates XML files. If a victim user loads a maliciously crafted XML file containing Python code, the code will be passed to an eval function, causing it to execute on the user's machine.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45858" + }, + { + "type": "WEB", + "url": "https://hiddenlayer.com/sai-security-advisory/2024-09-guardrails" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-95" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T15:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-w7c2-w23x-h6pm/GHSA-w7c2-w23x-h6pm.json b/advisories/unreviewed/2024/09/GHSA-w7c2-w23x-h6pm/GHSA-w7c2-w23x-h6pm.json new file mode 100644 index 00000000000..6b97521906c --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-w7c2-w23x-h6pm/GHSA-w7c2-w23x-h6pm.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w7c2-w23x-h6pm", + "modified": "2024-09-18T15:30:52Z", + "published": "2024-09-18T15:30:52Z", + "aliases": [ + "CVE-2024-46556" + ], + "details": "Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sInRCSecret0 parameter at v2x00.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46556" + }, + { + "type": "WEB", + "url": "https://ink-desk-28f.notion.site/Draytek-vigor-3910-Analysis-Report-b3b23e150c4f4bab822c3c47fd7b9de9#a26d36d8c8d042299348d8ec7a0260ca" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T15:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-w7pj-cjvc-96cx/GHSA-w7pj-cjvc-96cx.json b/advisories/unreviewed/2024/09/GHSA-w7pj-cjvc-96cx/GHSA-w7pj-cjvc-96cx.json new file mode 100644 index 00000000000..8f6b7bdc369 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-w7pj-cjvc-96cx/GHSA-w7pj-cjvc-96cx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w7pj-cjvc-96cx", + "modified": "2024-09-18T15:30:51Z", + "published": "2024-09-18T15:30:51Z", + "aliases": [ + "CVE-2024-31169" + ], + "details": "Out-of-bounds Read vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of10::QueueGetConfigReply::unpack.\n\nThis issue affects libfluid: 0.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31169" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-31169" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T14:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-w92r-xm6v-f2vj/GHSA-w92r-xm6v-f2vj.json b/advisories/unreviewed/2024/09/GHSA-w92r-xm6v-f2vj/GHSA-w92r-xm6v-f2vj.json new file mode 100644 index 00000000000..6232fffe888 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-w92r-xm6v-f2vj/GHSA-w92r-xm6v-f2vj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w92r-xm6v-f2vj", + "modified": "2024-09-18T15:30:53Z", + "published": "2024-09-18T15:30:53Z", + "aliases": [ + "CVE-2024-6877" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Eliz Software Panel allows Reflected XSS.This issue affects Panel: before v2.3.24.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6877" + }, + { + "type": "WEB", + "url": "https://www.usom.gov.tr/bildirim/tr-24-1497" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T15:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-x6fp-542m-2mr8/GHSA-x6fp-542m-2mr8.json b/advisories/unreviewed/2024/09/GHSA-x6fp-542m-2mr8/GHSA-x6fp-542m-2mr8.json new file mode 100644 index 00000000000..6ea00d8ff0f --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-x6fp-542m-2mr8/GHSA-x6fp-542m-2mr8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x6fp-542m-2mr8", + "modified": "2024-09-18T15:30:52Z", + "published": "2024-09-18T15:30:52Z", + "aliases": [ + "CVE-2024-39589" + ], + "details": "Multiple invalid pointer dereference vulnerabilities exist in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC_v3 16bf8bac1a36d95b73e7b8722d0edb8b9c5bb56a. A specially crafted EtherNet/IP request can lead to denial of service. An attacker can send a series of EtherNet/IP requests to trigger these vulnerabilities.This instance of the vulnerability occurs within the `Protected_Logical_Read_Reply` function", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39589" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2016" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-704" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T15:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-xxmj-qmq4-g4j9/GHSA-xxmj-qmq4-g4j9.json b/advisories/unreviewed/2024/09/GHSA-xxmj-qmq4-g4j9/GHSA-xxmj-qmq4-g4j9.json new file mode 100644 index 00000000000..df43fb238ba --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-xxmj-qmq4-g4j9/GHSA-xxmj-qmq4-g4j9.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xxmj-qmq4-g4j9", + "modified": "2024-09-18T15:30:53Z", + "published": "2024-09-18T15:30:53Z", + "aliases": [ + "CVE-2024-46598" + ], + "details": "Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the iprofileidx parameter at dialin.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46598" + }, + { + "type": "WEB", + "url": "https://ink-desk-28f.notion.site/Draytek-vigor-3910-Analysis-Report-b3b23e150c4f4bab822c3c47fd7b9de9#0875f261ad5c4e1ba59448d49a261a99" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T15:15:18Z" + } +} \ No newline at end of file