Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2025-04-11 18:32:30 +00:00
parent 23a5441b7c
commit 3be6f78bae
51 changed files with 924 additions and 73 deletions
@@ -26,6 +26,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-78",
"CWE-787"
],
"severity": "CRITICAL",
@@ -25,7 +25,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-400"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -26,6 +26,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-78",
"CWE-787"
],
"severity": "CRITICAL",
@@ -26,6 +26,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-285",
"CWE-863"
],
"severity": "MODERATE",
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4rqc-6cwc-8fr7",
"modified": "2025-01-28T18:31:20Z",
"modified": "2025-04-11T18:30:27Z",
"published": "2024-02-22T03:30:36Z",
"aliases": [
"CVE-2024-23127"
],
"details": "A maliciously crafted MODEL, SLDPRT or SLDASM file when parsed VCRUNTIME140.dll through Autodesk AutoCAD can be used to cause a Heap-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.\n",
"details": "A maliciously crafted MODEL, SLDPRT or SLDASM file when parsed VCRUNTIME140.dll through Autodesk AutoCAD can be used to cause a Heap-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.",
"severity": [
{
"type": "CVSS_V3",
@@ -34,7 +34,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-122"
"CWE-122",
"CWE-787"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c8pw-6p2w-cpm2",
"modified": "2024-08-01T15:31:27Z",
"modified": "2025-04-11T18:30:25Z",
"published": "2024-02-22T03:30:35Z",
"aliases": [
"CVE-2024-23121"
],
"details": "A maliciously crafted MODEL file when parsed in libodxdll.dll through Autodesk AutoCAD can force an Out-of-Bound Write. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process.\n",
"details": "A maliciously crafted MODEL file when parsed in libodxdll.dll through Autodesk AutoCAD can force an Out-of-Bound Write. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-ch7v-4hfq-6r4x",
"modified": "2024-08-01T15:31:27Z",
"modified": "2025-04-11T18:30:26Z",
"published": "2024-02-22T03:30:35Z",
"aliases": [
"CVE-2024-23124"
],
"details": "A maliciously crafted STP file when parsed in ASMIMPORT228A.dll through Autodesk AutoCAD can force an Out-of-Bound Write. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process.\n",
"details": "A maliciously crafted STP file when parsed in ASMIMPORT228A.dll through Autodesk AutoCAD can force an Out-of-Bound Write. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f9p5-24wv-w5qx",
"modified": "2024-08-01T15:31:27Z",
"modified": "2025-04-11T18:30:25Z",
"published": "2024-02-22T03:30:35Z",
"aliases": [
"CVE-2024-23122"
],
"details": "A maliciously crafted 3DM file when parsed in opennurbs.dll through Autodesk AutoCAD can force an Out-of-Bound Write. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process.\n",
"details": "A maliciously crafted 3DM file when parsed in opennurbs.dll through Autodesk AutoCAD can force an Out-of-Bound Write. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fgcf-ch4w-m3f6",
"modified": "2024-08-01T15:31:27Z",
"modified": "2025-04-11T18:30:25Z",
"published": "2024-02-22T03:30:35Z",
"aliases": [
"CVE-2024-23123"
],
"details": "A maliciously crafted CATPART file when parsed in CC5Dll.dll and ASMBASE228A.dll through Autodesk AutoCAD can force an Out-of-Bound Write. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process.\n",
"details": "A maliciously crafted CATPART file when parsed in CC5Dll.dll and ASMBASE228A.dll through Autodesk AutoCAD can force an Out-of-Bound Write. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mx83-4qpc-6m5h",
"modified": "2024-08-01T15:31:27Z",
"modified": "2025-04-11T18:30:27Z",
"published": "2024-02-22T03:30:35Z",
"aliases": [
"CVE-2024-23126"
],
"details": "A maliciously crafted CATPART file when parsed CC5Dll.dll through Autodesk AutoCAD can be used to cause a Stack-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.\n",
"details": "A maliciously crafted CATPART file when parsed CC5Dll.dll through Autodesk AutoCAD can be used to cause a Stack-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.",
"severity": [
{
"type": "CVSS_V3",
@@ -30,7 +30,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-121"
"CWE-121",
"CWE-787"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q6r9-2g53-c4qf",
"modified": "2024-08-01T15:31:27Z",
"modified": "2025-04-11T18:30:26Z",
"published": "2024-02-22T03:30:35Z",
"aliases": [
"CVE-2024-23125"
],
"details": "A maliciously crafted SLDPRT file when parsed ODXSW_DLL.dll through Autodesk AutoCAD can be used to cause a Stack-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.\n",
"details": "A maliciously crafted SLDPRT file when parsed ODXSW_DLL.dll through Autodesk AutoCAD can be used to cause a Stack-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.",
"severity": [
{
"type": "CVSS_V3",
@@ -26,7 +26,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-121"
"CWE-121",
"CWE-787"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q9rx-4p5p-q33x",
"modified": "2025-02-11T00:31:24Z",
"modified": "2025-04-11T18:30:24Z",
"published": "2024-02-22T00:31:01Z",
"aliases": [
"CVE-2024-0446"
],
"details": "A maliciously crafted STP, CATPART or MODEL file when parsed in ASMKERN228A.dll through Autodesk AutoCAD can force an Out-of-Bound Write. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process. \n",
"details": "A maliciously crafted STP, CATPART or MODEL file when parsed in ASMKERN228A.dll through Autodesk AutoCAD can force an Out-of-Bound Write. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process. ",
"severity": [
{
"type": "CVSS_V3",
@@ -34,7 +34,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-457"
"CWE-457",
"CWE-908"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rqrg-8xc9-5vw3",
"modified": "2024-08-01T15:31:27Z",
"modified": "2025-04-11T18:30:24Z",
"published": "2024-02-22T00:31:02Z",
"aliases": [
"CVE-2024-23120"
],
"details": "A maliciously crafted STP file when parsed in ASMIMPORT228A.dll through Autodesk AutoCAD can force an Out-of-Bound Write. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process.\n",
"details": "A maliciously crafted STP file when parsed in ASMIMPORT228A.dll through Autodesk AutoCAD can force an Out-of-Bound Write. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process.",
"severity": [
{
"type": "CVSS_V3",
@@ -26,7 +26,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-20"
"CWE-20",
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pfh7-q24c-mjwh",
"modified": "2024-04-15T21:30:46Z",
"modified": "2025-04-11T18:30:32Z",
"published": "2024-04-15T21:30:46Z",
"aliases": [
"CVE-2024-23560"
],
"details": "HCL DevOps Deploy / HCL Launch could be vulnerable to incomplete revocation of permissions when deleting a custom security resource type. \n",
"details": "HCL DevOps Deploy / HCL Launch could be vulnerable to incomplete revocation of permissions when deleting a custom security resource type.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c583-9378-q3jc",
"modified": "2024-10-30T00:31:05Z",
"modified": "2025-04-11T18:30:35Z",
"published": "2024-10-30T00:31:04Z",
"aliases": [
"CVE-2024-7991"
@@ -22,6 +22,10 @@
{
"type": "WEB",
"url": "https://autodesk.com/trust/security-advisories/adsk-sa-2024-0021"
},
{
"type": "WEB",
"url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0021"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gjf9-pfmc-2689",
"modified": "2024-10-30T00:31:05Z",
"modified": "2025-04-11T18:30:35Z",
"published": "2024-10-30T00:31:04Z",
"aliases": [
"CVE-2024-7992"
@@ -22,6 +22,10 @@
{
"type": "WEB",
"url": "https://autodesk.com/trust/security-advisories/adsk-sa-2024-0021"
},
{
"type": "WEB",
"url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0021"
}
],
"database_specific": {
@@ -54,7 +54,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-119"
"CWE-119",
"CWE-787"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-phf9-ch44-7c3w",
"modified": "2025-03-27T03:33:36Z",
"modified": "2025-04-11T18:30:39Z",
"published": "2025-03-27T03:33:36Z",
"aliases": [
"CVE-2025-2831"
@@ -42,7 +42,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-74"
"CWE-74",
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,

Some files were not shown because too many files have changed in this diff Show More