Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2025-01-21 18:31:35 +00:00
parent d85b129314
commit 3cb7bc79b1
61 changed files with 346 additions and 113 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-23qq-p4gq-gc2g",
"modified": "2024-11-01T21:41:21Z",
"modified": "2025-01-21T18:28:26Z",
"published": "2024-05-06T00:30:52Z",
"aliases": [
"CVE-2024-34528"
@@ -59,6 +59,10 @@
{
"type": "WEB",
"url": "https://github.com/WordOps/WordOps/blob/ecf20192c7853925e2cb3f8c8378cd0d86ca0d62/wo/cli/plugins/stack_pref.py#L77"
},
{
"type": "WEB",
"url": "https://github.com/pypa/advisory-database/tree/main/vulns/wordops/PYSEC-2024-175.yaml"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qmjf-wc2h-6x3q",
"modified": "2024-05-29T18:40:56Z",
"modified": "2025-01-21T18:30:41Z",
"published": "2024-05-29T18:40:56Z",
"aliases": [
"CVE-2024-36112"
@@ -82,6 +82,10 @@
{
"type": "PACKAGE",
"url": "https://github.com/nautobot/nautobot"
},
{
"type": "WEB",
"url": "https://github.com/pypa/advisory-database/tree/main/vulns/nautobot/PYSEC-2024-166.yaml"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9x88-4jg8-4vf7",
"modified": "2024-06-06T22:21:21Z",
"modified": "2025-01-21T18:29:12Z",
"published": "2024-06-06T21:30:36Z",
"aliases": [
"CVE-2024-2035"
@@ -44,6 +44,10 @@
"type": "WEB",
"url": "https://github.com/zenml-io/zenml/commit/b95f083efffa56831cd41d8ed536aeb0b6038fa3"
},
{
"type": "WEB",
"url": "https://github.com/pypa/advisory-database/tree/main/vulns/zenml/PYSEC-2024-169.yaml"
},
{
"type": "PACKAGE",
"url": "https://github.com/zenml-io/zenml"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cgvx-9447-vcch",
"modified": "2024-08-26T19:13:46Z",
"modified": "2025-01-21T18:28:57Z",
"published": "2024-06-28T00:33:31Z",
"aliases": [
"CVE-2024-39705"
@@ -60,6 +60,10 @@
"type": "PACKAGE",
"url": "https://github.com/nltk/nltk"
},
{
"type": "WEB",
"url": "https://github.com/pypa/advisory-database/tree/main/vulns/nltk/PYSEC-2024-167.yaml"
},
{
"type": "WEB",
"url": "https://www.vicarius.io/vsociety/posts/rce-in-python-nltk-cve-2024-39705-39706"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vwgf-7f9h-h499",
"modified": "2024-10-11T16:30:36Z",
"modified": "2025-01-21T18:29:05Z",
"published": "2024-06-06T21:30:36Z",
"aliases": [
"CVE-2024-2171"
@@ -44,6 +44,10 @@
"type": "WEB",
"url": "https://github.com/zenml-io/zenml/commit/68bcb3ba60cba9729c9713a49c39502d40fb945e"
},
{
"type": "WEB",
"url": "https://github.com/pypa/advisory-database/tree/main/vulns/zenml/PYSEC-2024-170.yaml"
},
{
"type": "PACKAGE",
"url": "https://github.com/zenml-io/zenml"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r3jq-4r5c-j9hp",
"modified": "2024-10-16T19:32:14Z",
"modified": "2025-01-21T18:28:45Z",
"published": "2024-08-27T19:50:59Z",
"aliases": [
"CVE-2024-47833"
@@ -58,6 +58,10 @@
{
"type": "WEB",
"url": "https://github.com/Avaiga/taipy/blob/develop/frontend/taipy-gui/src/components/Taipy/Navigate.tsx#L67"
},
{
"type": "WEB",
"url": "https://github.com/pypa/advisory-database/tree/main/vulns/taipy/PYSEC-2024-168.yaml"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cg87-wmx4-v546",
"modified": "2025-01-17T21:22:57Z",
"modified": "2025-01-21T18:31:02Z",
"published": "2025-01-17T21:22:56Z",
"aliases": [
"CVE-2025-23207"
@@ -43,6 +43,10 @@
"type": "WEB",
"url": "https://github.com/KaTeX/KaTeX/security/advisories/GHSA-cg87-wmx4-v546"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23207"
},
{
"type": "WEB",
"url": "https://github.com/KaTeX/KaTeX/commit/ff289955e81aab89086eef09254cbf88573d415c"
@@ -59,6 +63,6 @@
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2025-01-17T21:22:56Z",
"nvd_published_at": null
"nvd_published_at": "2025-01-17T22:15:29Z"
}
}
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-24fj-8422-2v9w",
"modified": "2022-05-02T03:36:00Z",
"modified": "2025-01-21T18:31:00Z",
"published": "2022-05-02T03:36:00Z",
"aliases": [
"CVE-2009-2516"
],
"details": "The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold and SP1, and Server 2008 Gold does not properly validate data sent from user mode, which allows local users to gain privileges via a crafted PE .exe file that triggers a NULL pointer dereference during chain traversal, aka \"Windows Kernel NULL Pointer Dereference Vulnerability.\"",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
}
],
"affected": [],
"references": [
{
@@ -33,7 +38,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-20"
"CWE-20",
"CWE-476"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-24xr-jc8x-c65v",
"modified": "2022-05-14T01:31:29Z",
"modified": "2025-01-21T18:31:01Z",
"published": "2022-05-14T01:31:29Z",
"aliases": [
"CVE-2010-1883"
],
"details": "Integer overflow in the Embedded OpenType (EOT) Font Engine in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows remote attackers to execute arbitrary code via a crafted table in an embedded font, aka \"Embedded OpenType Font Integer Overflow Vulnerability.\"",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
@@ -28,7 +33,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-190"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2vw2-h5mp-gfhw",
"modified": "2024-02-02T18:30:21Z",
"modified": "2025-01-21T18:31:00Z",
"published": "2022-05-02T03:35:01Z",
"aliases": [
"CVE-2009-2416"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2wgx-r6j7-j62r",
"modified": "2022-05-02T06:13:03Z",
"modified": "2025-01-21T18:31:00Z",
"published": "2022-05-02T06:13:03Z",
"aliases": [
"CVE-2010-0481"
],
"details": "The kernel in Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly translate a registry key's virtual path to its real path, which allows local users to cause a denial of service (reboot) via a crafted application, aka \"Windows Virtual Path Parsing Vulnerability.\"",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [],
"references": [
{
@@ -40,7 +45,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-22"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-33xc-j7q8-qcjm",
"modified": "2022-05-13T01:15:32Z",
"modified": "2025-01-21T18:31:01Z",
"published": "2022-05-13T01:15:32Z",
"aliases": [
"CVE-2011-1887"
],
"details": "win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other CVEs listed in MS11-054, aka \"Win32k Null Pointer De-reference Vulnerability.\"",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
@@ -48,7 +53,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-476"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6fvg-8hhr-r65p",
"modified": "2022-05-02T06:13:05Z",
"modified": "2025-01-21T18:31:01Z",
"published": "2022-05-02T06:13:05Z",
"aliases": [
"CVE-2010-0488"
],
"details": "Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 does not properly handle unspecified \"encoding strings,\" which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site, aka \"Post Encoding Information Disclosure Vulnerability.\"",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
}
],
"affected": [],
"references": [
{
@@ -53,7 +58,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-200"
"CWE-200",
"CWE-732"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-74cx-pw34-jqwr",
"modified": "2022-05-02T03:12:58Z",
"modified": "2025-01-21T18:31:00Z",
"published": "2022-05-02T03:12:58Z",
"aliases": [
"CVE-2009-0130"
],
"details": "** DISPUTED ** lib/crypto/c_src/crypto_drv.c in erlang does not properly check the return value from the OpenSSL DSA_do_verify function, which might allow remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077. NOTE: a package maintainer disputes this issue, reporting that there is a proper check within the only code that uses the applicable part of crypto_drv.c, and thus \"this report is invalid.\"",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
}
],
"affected": [],
"references": [
{
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7967-3g5v-3pfc",
"modified": "2022-05-02T06:09:45Z",
"modified": "2025-01-21T18:31:00Z",
"published": "2022-05-02T06:09:45Z",
"aliases": [
"CVE-2010-0021"
],
"details": "Multiple race conditions in the SMB implementation in the Server service in Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allow remote attackers to cause a denial of service (system hang) via a crafted (1) SMBv1 or (2) SMBv2 Negotiate packet, aka \"SMB Memory Corruption Vulnerability.\"",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [],
"references": [
{
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7w6f-prr7-wp9h",
"modified": "2022-05-14T02:13:17Z",
"modified": "2025-01-21T18:31:01Z",
"published": "2022-05-14T02:13:17Z",
"aliases": [
"CVE-2010-2554"
],
"details": "The Tracing Feature for Services in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 has incorrect ACLs on its registry keys, which allows local users to gain privileges via vectors involving a named pipe and impersonation, aka \"Tracing Registry Key ACL Vulnerability.\"",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8v76-643q-v8h8",
"modified": "2024-03-21T03:33:03Z",
"modified": "2025-01-21T18:31:01Z",
"published": "2022-05-17T05:36:53Z",
"aliases": [
"CVE-2011-0736"
],
"details": "** DISPUTED ** Adobe ColdFusion 9.0.1 CHF1 and earlier, when a web application is configured to use a DBMS, allows remote attackers to obtain potentially sensitive information about the database structure via an id=- query to a .cfm file. NOTE: the vendor disputes the significance of this issue because the Site-wide Error Handler and Debug Output Settings sections of the ColdFusion Lockdown guide explain the requirement for settings that prevent this information disclosure.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
}
],
"affected": [],
"references": [
{
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8vq2-fxxp-56hm",
"modified": "2022-05-02T03:35:59Z",
"modified": "2025-01-21T18:31:00Z",
"published": "2022-05-02T03:35:59Z",
"aliases": [
"CVE-2009-2512"
],
"details": "The Web Services on Devices API (WSDAPI) in Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 does not properly process the headers of WSD messages, which allows remote attackers to execute arbitrary code via a crafted (1) message or (2) response, aka \"Web Services on Devices API Memory Corruption Vulnerability.\"",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9c2j-5jrv-c2w9",
"modified": "2022-05-14T02:36:48Z",
"modified": "2025-01-21T18:31:01Z",
"published": "2022-05-14T02:36:48Z",
"aliases": [
"CVE-2010-1889"
],
"details": "Double free vulnerability in the kernel in Microsoft Windows Vista SP1 and SP2, and Windows Server 2008 Gold and SP2, allows local users to gain privileges via a crafted application, related to object initialization during error handling, aka \"Windows Kernel Double Free Vulnerability.\"",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c63x-h9v9-hmcr",
"modified": "2022-05-13T01:15:25Z",
"modified": "2025-01-21T18:31:01Z",
"published": "2022-05-13T01:15:25Z",
"aliases": [
"CVE-2011-0663"
],
"details": "Multiple integer overflows in the Microsoft (1) JScript 5.6 through 5.8 and (2) VBScript 5.6 through 5.8 scripting engines allow remote attackers to execute arbitrary code via a crafted web page, aka \"Scripting Memory Reallocation Vulnerability.\"",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
@@ -48,7 +53,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-190"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,

Some files were not shown because too many files have changed in this diff Show More