diff --git a/advisories/unreviewed/2021/12/GHSA-m97r-wj82-82xw/GHSA-m97r-wj82-82xw.json b/advisories/unreviewed/2021/12/GHSA-m97r-wj82-82xw/GHSA-m97r-wj82-82xw.json index 42a3cb0c82d..c4e4b76e96a 100644 --- a/advisories/unreviewed/2021/12/GHSA-m97r-wj82-82xw/GHSA-m97r-wj82-82xw.json +++ b/advisories/unreviewed/2021/12/GHSA-m97r-wj82-82xw/GHSA-m97r-wj82-82xw.json @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://www.incibe-cert.es/en/early-warning/security-advisories/parallels-remote-application-server-credentials-management-errors" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/parallels-remote-application-server-credentials-management-errors" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/10/GHSA-8hw4-gj79-m365/GHSA-8hw4-gj79-m365.json b/advisories/unreviewed/2022/10/GHSA-8hw4-gj79-m365/GHSA-8hw4-gj79-m365.json index d9629522bc7..788be7464ea 100644 --- a/advisories/unreviewed/2022/10/GHSA-8hw4-gj79-m365/GHSA-8hw4-gj79-m365.json +++ b/advisories/unreviewed/2022/10/GHSA-8hw4-gj79-m365/GHSA-8hw4-gj79-m365.json @@ -24,11 +24,15 @@ { "type": "WEB", "url": "https://www.incibe-cert.es/en/early-warning/ics-advisories/multiple-vulnerabilities-zgr-tps200-ng" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso-sci/multiple-vulnerabilities-zgr-tps200-ng" } ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/11/GHSA-5gr2-8w66-g9j9/GHSA-5gr2-8w66-g9j9.json b/advisories/unreviewed/2023/11/GHSA-5gr2-8w66-g9j9/GHSA-5gr2-8w66-g9j9.json new file mode 100644 index 00000000000..ea51ecedb77 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-5gr2-8w66-g9j9/GHSA-5gr2-8w66-g9j9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5gr2-8w66-g9j9", + "modified": "2023-11-20T12:30:27Z", + "published": "2023-11-20T12:30:27Z", + "aliases": [ + "CVE-2023-46100" + ], + "details": "in OpenHarmony v3.2.2 and prior versions allow a local attacker get sensitive buffer information through use of uninitialized resource.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46100" + }, + { + "type": "WEB", + "url": "https://gitee.com/openharmony/security/blob/master/zh/security-disclosure/2023/2023-12.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-908" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-20T12:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-66pm-7m3q-gh7c/GHSA-66pm-7m3q-gh7c.json b/advisories/unreviewed/2023/11/GHSA-66pm-7m3q-gh7c/GHSA-66pm-7m3q-gh7c.json new file mode 100644 index 00000000000..1c04e831f51 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-66pm-7m3q-gh7c/GHSA-66pm-7m3q-gh7c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-66pm-7m3q-gh7c", + "modified": "2023-11-20T12:30:27Z", + "published": "2023-11-20T12:30:27Z", + "aliases": [ + "CVE-2023-43612" + ], + "details": "in OpenHarmony v3.2.2 and prior versions allow a local attacker arbitrary file read and write through improper preservation of permissions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-43612" + }, + { + "type": "WEB", + "url": "https://gitee.com/openharmony/security/blob/master/zh/security-disclosure/2023/2023-12.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-281" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-20T12:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-7w4h-76j5-gqgx/GHSA-7w4h-76j5-gqgx.json b/advisories/unreviewed/2023/11/GHSA-7w4h-76j5-gqgx/GHSA-7w4h-76j5-gqgx.json new file mode 100644 index 00000000000..81bfab7c9c8 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-7w4h-76j5-gqgx/GHSA-7w4h-76j5-gqgx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7w4h-76j5-gqgx", + "modified": "2023-11-20T12:30:27Z", + "published": "2023-11-20T12:30:27Z", + "aliases": [ + "CVE-2023-47217" + ], + "details": "in OpenHarmony v3.2.2 and prior versions allow a local attacker cause DOS through buffer overflow.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47217" + }, + { + "type": "WEB", + "url": "https://gitee.com/openharmony/security/blob/master/zh/security-disclosure/2023/2023-12.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-20T12:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-85wf-77c7-2h37/GHSA-85wf-77c7-2h37.json b/advisories/unreviewed/2023/11/GHSA-85wf-77c7-2h37/GHSA-85wf-77c7-2h37.json new file mode 100644 index 00000000000..3446c664317 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-85wf-77c7-2h37/GHSA-85wf-77c7-2h37.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-85wf-77c7-2h37", + "modified": "2023-11-20T12:30:27Z", + "published": "2023-11-20T12:30:27Z", + "aliases": [ + "CVE-2023-5593" + ], + "details": "The out-of-bounds write vulnerability in the Windows-based SecuExtender SSL VPN Client software version 4.0.4.0 could allow an authenticated local user to gain a privilege escalation by sending a crafted CREATE message.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5593" + }, + { + "type": "WEB", + "url": "https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-out-of-bounds-write-vulnerability-in-secuextender-ssl-vpn-client-software" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-20T12:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-cv6h-7p3x-q58x/GHSA-cv6h-7p3x-q58x.json b/advisories/unreviewed/2023/11/GHSA-cv6h-7p3x-q58x/GHSA-cv6h-7p3x-q58x.json new file mode 100644 index 00000000000..fd73a5f95f0 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-cv6h-7p3x-q58x/GHSA-cv6h-7p3x-q58x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cv6h-7p3x-q58x", + "modified": "2023-11-20T12:30:27Z", + "published": "2023-11-20T12:30:27Z", + "aliases": [ + "CVE-2023-6045" + ], + "details": "in OpenHarmony v3.2.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through type confusion.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6045" + }, + { + "type": "WEB", + "url": "https://gitee.com/openharmony/security/blob/master/zh/security-disclosure/2023/2023-12.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-843" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-20T12:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-fjp6-hgv6-f8gw/GHSA-fjp6-hgv6-f8gw.json b/advisories/unreviewed/2023/11/GHSA-fjp6-hgv6-f8gw/GHSA-fjp6-hgv6-f8gw.json new file mode 100644 index 00000000000..100a8750a48 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-fjp6-hgv6-f8gw/GHSA-fjp6-hgv6-f8gw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fjp6-hgv6-f8gw", + "modified": "2023-11-20T12:30:27Z", + "published": "2023-11-20T12:30:27Z", + "aliases": [ + "CVE-2023-42774" + ], + "details": "in OpenHarmony v3.2.2 and prior versions allow a local attacker get confidential information through incorrect default permissions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-42774" + }, + { + "type": "WEB", + "url": "https://gitee.com/openharmony/security/blob/master/zh/security-disclosure/2023/2023-12.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-276" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-20T12:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-jm6v-mv47-p2gv/GHSA-jm6v-mv47-p2gv.json b/advisories/unreviewed/2023/11/GHSA-jm6v-mv47-p2gv/GHSA-jm6v-mv47-p2gv.json new file mode 100644 index 00000000000..e56148da6d4 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-jm6v-mv47-p2gv/GHSA-jm6v-mv47-p2gv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jm6v-mv47-p2gv", + "modified": "2023-11-20T12:30:27Z", + "published": "2023-11-20T12:30:27Z", + "aliases": [ + "CVE-2023-46705" + ], + "details": "in OpenHarmony v3.2.2 and prior versions allow a local attacker causes system information leak through type confusion.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46705" + }, + { + "type": "WEB", + "url": "https://gitee.com/openharmony/security/blob/master/zh/security-disclosure/2023/2023-12.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-843" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-20T12:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-vhc9-98xp-277v/GHSA-vhc9-98xp-277v.json b/advisories/unreviewed/2023/11/GHSA-vhc9-98xp-277v/GHSA-vhc9-98xp-277v.json new file mode 100644 index 00000000000..c7367ab0a40 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-vhc9-98xp-277v/GHSA-vhc9-98xp-277v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vhc9-98xp-277v", + "modified": "2023-11-20T12:30:27Z", + "published": "2023-11-20T12:30:27Z", + "aliases": [ + "CVE-2023-3116" + ], + "details": "in OpenHarmony v3.2.2 and prior versions allow a local attacker get confidential information or rewrite sensitive file through incorrect default permissions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3116" + }, + { + "type": "WEB", + "url": "https://gitee.com/openharmony/security/blob/master/zh/security-disclosure/2023/2023-12.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-276" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-20T12:15:07Z" + } +} \ No newline at end of file