diff --git a/advisories/unreviewed/2024/11/GHSA-38jp-8r92-cqg4/GHSA-38jp-8r92-cqg4.json b/advisories/unreviewed/2024/11/GHSA-38jp-8r92-cqg4/GHSA-38jp-8r92-cqg4.json new file mode 100644 index 00000000000..33751ca345b --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-38jp-8r92-cqg4/GHSA-38jp-8r92-cqg4.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-38jp-8r92-cqg4", + "modified": "2024-11-10T21:30:44Z", + "published": "2024-11-10T21:30:44Z", + "aliases": [ + "CVE-2024-46951" + ], + "details": "An issue was discovered in psi/zcolor.c in Artifex Ghostscript before 10.04.0. An unchecked Implementation pointer in Pattern color space could lead to arbitrary code execution.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46951" + }, + { + "type": "WEB", + "url": "https://bugs.ghostscript.com/show_bug.cgi?id=707991" + }, + { + "type": "WEB", + "url": "https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/commit/?id=f49812186baa7d1362880673408a6fbe8719b4f8" + }, + { + "type": "WEB", + "url": "https://github.com/ArtifexSoftware/ghostpdl/blob/master/doc/News.html" + }, + { + "type": "WEB", + "url": "https://www.suse.com/support/update/announcement/2024/suse-su-20243942-1" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-10T21:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-q743-h9vw-38hv/GHSA-q743-h9vw-38hv.json b/advisories/unreviewed/2024/11/GHSA-q743-h9vw-38hv/GHSA-q743-h9vw-38hv.json new file mode 100644 index 00000000000..16c31319631 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-q743-h9vw-38hv/GHSA-q743-h9vw-38hv.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q743-h9vw-38hv", + "modified": "2024-11-10T21:30:44Z", + "published": "2024-11-10T21:30:44Z", + "aliases": [ + "CVE-2024-46613" + ], + "details": "WeeChat before 4.4.2 has an integer overflow and resultant buffer overflow at core/core-string.c when there are more than two billion items in a list. This affects string_free_split_shared , string_free_split, string_free_split_command, and string_free_split_tags.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46613" + }, + { + "type": "WEB", + "url": "https://github.com/weechat/weechat/issues/2178" + }, + { + "type": "WEB", + "url": "https://weechat.org/doc/weechat/security/WSA-2024-1" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-10T21:15:14Z" + } +} \ No newline at end of file