From 3e58595082620bb32c1cd79c36d6e502c2230508 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 4 Oct 2024 15:32:39 +0000 Subject: [PATCH] Publish Advisories GHSA-68vv-fjgv-68v7 GHSA-pg7p-9rpp-xjmx GHSA-qhm7-j2q7-2p2f GHSA-4jc7-pp7p-f6px GHSA-f8x4-897j-jj7g GHSA-j5f8-53mj-mghf GHSA-3pc8-hwcr-cqrw GHSA-62pg-77g7-wvwq GHSA-74xr-gj9j-429c GHSA-7prj-hj6w-444f GHSA-7r7x-w2qg-cx77 GHSA-8xx5-ghfp-wg5c GHSA-cr9c-949p-jxvr GHSA-fpg5-7w95-pcwj GHSA-hm4r-q33h-2fw6 GHSA-jjm3-8267-chq9 GHSA-m5vg-qcpp-rq6f GHSA-pq74-689g-fqg7 GHSA-q99v-9gg3-9f8p GHSA-v863-m35q-9hvv GHSA-vhp6-hrqq-rpqj GHSA-vx6r-82hr-hr24 GHSA-xfh8-7hcx-ppfp GHSA-xfxr-3v89-hch2 --- .../GHSA-68vv-fjgv-68v7.json | 7 ++- .../GHSA-pg7p-9rpp-xjmx.json | 2 +- .../GHSA-qhm7-j2q7-2p2f.json | 2 +- .../GHSA-4jc7-pp7p-f6px.json | 11 ++-- .../GHSA-f8x4-897j-jj7g.json | 9 ++- .../GHSA-j5f8-53mj-mghf.json | 3 +- .../GHSA-3pc8-hwcr-cqrw.json | 38 ++++++++++++ .../GHSA-62pg-77g7-wvwq.json | 38 ++++++++++++ .../GHSA-74xr-gj9j-429c.json | 38 ++++++++++++ .../GHSA-7prj-hj6w-444f.json | 58 +++++++++++++++++++ .../GHSA-7r7x-w2qg-cx77.json | 38 ++++++++++++ .../GHSA-8xx5-ghfp-wg5c.json | 38 ++++++++++++ .../GHSA-cr9c-949p-jxvr.json | 6 +- .../GHSA-fpg5-7w95-pcwj.json | 50 ++++++++++++++++ .../GHSA-hm4r-q33h-2fw6.json | 38 ++++++++++++ .../GHSA-jjm3-8267-chq9.json | 38 ++++++++++++ .../GHSA-m5vg-qcpp-rq6f.json | 38 ++++++++++++ .../GHSA-pq74-689g-fqg7.json | 38 ++++++++++++ .../GHSA-q99v-9gg3-9f8p.json | 46 +++++++++++++++ .../GHSA-v863-m35q-9hvv.json | 58 +++++++++++++++++++ .../GHSA-vhp6-hrqq-rpqj.json | 38 ++++++++++++ .../GHSA-vx6r-82hr-hr24.json | 38 ++++++++++++ .../GHSA-xfh8-7hcx-ppfp.json | 38 ++++++++++++ .../GHSA-xfxr-3v89-hch2.json | 38 ++++++++++++ 24 files changed, 733 insertions(+), 13 deletions(-) create mode 100644 advisories/unreviewed/2024/10/GHSA-3pc8-hwcr-cqrw/GHSA-3pc8-hwcr-cqrw.json create mode 100644 advisories/unreviewed/2024/10/GHSA-62pg-77g7-wvwq/GHSA-62pg-77g7-wvwq.json create mode 100644 advisories/unreviewed/2024/10/GHSA-74xr-gj9j-429c/GHSA-74xr-gj9j-429c.json create mode 100644 advisories/unreviewed/2024/10/GHSA-7prj-hj6w-444f/GHSA-7prj-hj6w-444f.json create mode 100644 advisories/unreviewed/2024/10/GHSA-7r7x-w2qg-cx77/GHSA-7r7x-w2qg-cx77.json create mode 100644 advisories/unreviewed/2024/10/GHSA-8xx5-ghfp-wg5c/GHSA-8xx5-ghfp-wg5c.json create mode 100644 advisories/unreviewed/2024/10/GHSA-fpg5-7w95-pcwj/GHSA-fpg5-7w95-pcwj.json create mode 100644 advisories/unreviewed/2024/10/GHSA-hm4r-q33h-2fw6/GHSA-hm4r-q33h-2fw6.json create mode 100644 advisories/unreviewed/2024/10/GHSA-jjm3-8267-chq9/GHSA-jjm3-8267-chq9.json create mode 100644 advisories/unreviewed/2024/10/GHSA-m5vg-qcpp-rq6f/GHSA-m5vg-qcpp-rq6f.json create mode 100644 advisories/unreviewed/2024/10/GHSA-pq74-689g-fqg7/GHSA-pq74-689g-fqg7.json create mode 100644 advisories/unreviewed/2024/10/GHSA-q99v-9gg3-9f8p/GHSA-q99v-9gg3-9f8p.json create mode 100644 advisories/unreviewed/2024/10/GHSA-v863-m35q-9hvv/GHSA-v863-m35q-9hvv.json create mode 100644 advisories/unreviewed/2024/10/GHSA-vhp6-hrqq-rpqj/GHSA-vhp6-hrqq-rpqj.json create mode 100644 advisories/unreviewed/2024/10/GHSA-vx6r-82hr-hr24/GHSA-vx6r-82hr-hr24.json create mode 100644 advisories/unreviewed/2024/10/GHSA-xfh8-7hcx-ppfp/GHSA-xfh8-7hcx-ppfp.json create mode 100644 advisories/unreviewed/2024/10/GHSA-xfxr-3v89-hch2/GHSA-xfxr-3v89-hch2.json diff --git a/advisories/unreviewed/2022/05/GHSA-68vv-fjgv-68v7/GHSA-68vv-fjgv-68v7.json b/advisories/unreviewed/2022/05/GHSA-68vv-fjgv-68v7/GHSA-68vv-fjgv-68v7.json index e3ac5f487a7..e04ba8ceedd 100644 --- a/advisories/unreviewed/2022/05/GHSA-68vv-fjgv-68v7/GHSA-68vv-fjgv-68v7.json +++ b/advisories/unreviewed/2022/05/GHSA-68vv-fjgv-68v7/GHSA-68vv-fjgv-68v7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-68vv-fjgv-68v7", - "modified": "2022-05-24T19:14:19Z", + "modified": "2024-10-04T15:31:12Z", "published": "2022-05-24T19:14:19Z", "aliases": [ "CVE-2021-24523" ], "details": "The Daily Prayer Time WordPress plugin before 2021.08.10 does not sanitise or escape some of its settings before outputting them in the page, leading to Authenticated Stored Cross-Site Scripting issues.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2024/06/GHSA-pg7p-9rpp-xjmx/GHSA-pg7p-9rpp-xjmx.json b/advisories/unreviewed/2024/06/GHSA-pg7p-9rpp-xjmx/GHSA-pg7p-9rpp-xjmx.json index a801a268e50..1492b3275f8 100644 --- a/advisories/unreviewed/2024/06/GHSA-pg7p-9rpp-xjmx/GHSA-pg7p-9rpp-xjmx.json +++ b/advisories/unreviewed/2024/06/GHSA-pg7p-9rpp-xjmx/GHSA-pg7p-9rpp-xjmx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pg7p-9rpp-xjmx", - "modified": "2024-06-11T15:31:15Z", + "modified": "2024-10-04T15:31:12Z", "published": "2024-06-11T15:31:14Z", "aliases": [ "CVE-2024-21754" diff --git a/advisories/unreviewed/2024/08/GHSA-qhm7-j2q7-2p2f/GHSA-qhm7-j2q7-2p2f.json b/advisories/unreviewed/2024/08/GHSA-qhm7-j2q7-2p2f/GHSA-qhm7-j2q7-2p2f.json index 2d8e366d105..138f476eafd 100644 --- a/advisories/unreviewed/2024/08/GHSA-qhm7-j2q7-2p2f/GHSA-qhm7-j2q7-2p2f.json +++ b/advisories/unreviewed/2024/08/GHSA-qhm7-j2q7-2p2f/GHSA-qhm7-j2q7-2p2f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qhm7-j2q7-2p2f", - "modified": "2024-08-29T12:31:05Z", + "modified": "2024-10-04T15:31:12Z", "published": "2024-08-29T12:31:05Z", "aliases": [ "CVE-2024-5857" diff --git a/advisories/unreviewed/2024/09/GHSA-4jc7-pp7p-f6px/GHSA-4jc7-pp7p-f6px.json b/advisories/unreviewed/2024/09/GHSA-4jc7-pp7p-f6px/GHSA-4jc7-pp7p-f6px.json index 35b73766961..995b6b1a9fb 100644 --- a/advisories/unreviewed/2024/09/GHSA-4jc7-pp7p-f6px/GHSA-4jc7-pp7p-f6px.json +++ b/advisories/unreviewed/2024/09/GHSA-4jc7-pp7p-f6px/GHSA-4jc7-pp7p-f6px.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4jc7-pp7p-f6px", - "modified": "2024-09-27T15:30:34Z", + "modified": "2024-10-04T15:31:12Z", "published": "2024-09-27T15:30:34Z", "aliases": [ "CVE-2024-46850" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Avoid race between dcn35_set_drr() and dc_state_destruct()\n\ndc_state_destruct() nulls the resource context of the DC state. The pipe\ncontext passed to dcn35_set_drr() is a member of this resource context.\n\nIf dc_state_destruct() is called parallel to the IRQ processing (which\ncalls dcn35_set_drr() at some point), we can end up using already nulled\nfunction callback fields of struct stream_resource.\n\nThe logic in dcn35_set_drr() already tries to avoid this, by checking tg\nagainst NULL. But if the nulling happens exactly after the NULL check and\nbefore the next access, then we get a race.\n\nAvoid this by copying tg first to a local variable, and then use this\nvariable for all the operations. This should work, as long as nobody\nfrees the resource pool where the timing generators live.\n\n(cherry picked from commit 0607a50c004798a96e62c089a4c34c220179dcb5)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-27T13:15:16Z" diff --git a/advisories/unreviewed/2024/09/GHSA-f8x4-897j-jj7g/GHSA-f8x4-897j-jj7g.json b/advisories/unreviewed/2024/09/GHSA-f8x4-897j-jj7g/GHSA-f8x4-897j-jj7g.json index db77571298f..a74720cf486 100644 --- a/advisories/unreviewed/2024/09/GHSA-f8x4-897j-jj7g/GHSA-f8x4-897j-jj7g.json +++ b/advisories/unreviewed/2024/09/GHSA-f8x4-897j-jj7g/GHSA-f8x4-897j-jj7g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f8x4-897j-jj7g", - "modified": "2024-09-27T15:30:34Z", + "modified": "2024-10-04T15:31:12Z", "published": "2024-09-27T15:30:34Z", "aliases": [ "CVE-2024-46848" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nperf/x86/intel: Limit the period on Haswell\n\nRunning the ltp test cve-2015-3290 concurrently reports the following\nwarnings.\n\nperfevents: irq loop stuck!\n WARNING: CPU: 31 PID: 32438 at arch/x86/events/intel/core.c:3174\n intel_pmu_handle_irq+0x285/0x370\n Call Trace:\n \n ? __warn+0xa4/0x220\n ? intel_pmu_handle_irq+0x285/0x370\n ? __report_bug+0x123/0x130\n ? intel_pmu_handle_irq+0x285/0x370\n ? __report_bug+0x123/0x130\n ? intel_pmu_handle_irq+0x285/0x370\n ? report_bug+0x3e/0xa0\n ? handle_bug+0x3c/0x70\n ? exc_invalid_op+0x18/0x50\n ? asm_exc_invalid_op+0x1a/0x20\n ? irq_work_claim+0x1e/0x40\n ? intel_pmu_handle_irq+0x285/0x370\n perf_event_nmi_handler+0x3d/0x60\n nmi_handle+0x104/0x330\n\nThanks to Thomas Gleixner's analysis, the issue is caused by the low\ninitial period (1) of the frequency estimation algorithm, which triggers\nthe defects of the HW, specifically erratum HSW11 and HSW143. (For the\ndetails, please refer https://lore.kernel.org/lkml/87plq9l5d2.ffs@tglx/)\n\nThe HSW11 requires a period larger than 100 for the INST_RETIRED.ALL\nevent, but the initial period in the freq mode is 1. The erratum is the\nsame as the BDM11, which has been supported in the kernel. A minimum\nperiod of 128 is enforced as well on HSW.\n\nHSW143 is regarding that the fixed counter 1 may overcount 32 with the\nHyper-Threading is enabled. However, based on the test, the hardware\nhas more issues than it tells. Besides the fixed counter 1, the message\n'interrupt took too long' can be observed on any counter which was armed\nwith a period < 32 and two events expired in the same NMI. A minimum\nperiod of 32 is enforced for the rest of the events.\nThe recommended workaround code of the HSW143 is not implemented.\nBecause it only addresses the issue for the fixed counter. It brings\nextra overhead through extra MSR writing. No related overcounting issue\nhas been reported so far.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -39,7 +42,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-27T13:15:16Z" diff --git a/advisories/unreviewed/2024/09/GHSA-j5f8-53mj-mghf/GHSA-j5f8-53mj-mghf.json b/advisories/unreviewed/2024/09/GHSA-j5f8-53mj-mghf/GHSA-j5f8-53mj-mghf.json index f26ce2def46..d92088b3e05 100644 --- a/advisories/unreviewed/2024/09/GHSA-j5f8-53mj-mghf/GHSA-j5f8-53mj-mghf.json +++ b/advisories/unreviewed/2024/09/GHSA-j5f8-53mj-mghf/GHSA-j5f8-53mj-mghf.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-261" + "CWE-261", + "CWE-326" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-3pc8-hwcr-cqrw/GHSA-3pc8-hwcr-cqrw.json b/advisories/unreviewed/2024/10/GHSA-3pc8-hwcr-cqrw/GHSA-3pc8-hwcr-cqrw.json new file mode 100644 index 00000000000..0b14d8f4d40 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-3pc8-hwcr-cqrw/GHSA-3pc8-hwcr-cqrw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3pc8-hwcr-cqrw", + "modified": "2024-10-04T15:31:21Z", + "published": "2024-10-04T15:31:21Z", + "aliases": [ + "CVE-2024-9482" + ], + "details": "An out-of-bounds write in the engine module in AVG/Avast Antivirus signature <24092400 released on 24/Sep/2024 on MacOS allows a malformed Mach-O file to crash the application during file processing.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9482" + }, + { + "type": "WEB", + "url": "https://support.norton.com/sp/static/external/tools/security-advisories.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-04T13:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-62pg-77g7-wvwq/GHSA-62pg-77g7-wvwq.json b/advisories/unreviewed/2024/10/GHSA-62pg-77g7-wvwq/GHSA-62pg-77g7-wvwq.json new file mode 100644 index 00000000000..fac3a046aa5 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-62pg-77g7-wvwq/GHSA-62pg-77g7-wvwq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-62pg-77g7-wvwq", + "modified": "2024-10-04T15:31:21Z", + "published": "2024-10-04T15:31:21Z", + "aliases": [ + "CVE-2024-47656" + ], + "details": "This vulnerability exists in Shilpi Client Dashboard due to missing restrictions for incorrect login attempts on its API based login. A remote attacker could exploit this vulnerability by conducting a brute force attack on password, which could lead to gain unauthorized access to other user accounts.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47656" + }, + { + "type": "WEB", + "url": "https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0313" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-307" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-04T13:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-74xr-gj9j-429c/GHSA-74xr-gj9j-429c.json b/advisories/unreviewed/2024/10/GHSA-74xr-gj9j-429c/GHSA-74xr-gj9j-429c.json new file mode 100644 index 00000000000..dfbb08c6fda --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-74xr-gj9j-429c/GHSA-74xr-gj9j-429c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-74xr-gj9j-429c", + "modified": "2024-10-04T15:31:21Z", + "published": "2024-10-04T15:31:21Z", + "aliases": [ + "CVE-2024-47657" + ], + "details": "This vulnerability exists in the Shilpi Net Back Office due to improper access controls on certain API endpoints. An authenticated remote attacker could exploit this vulnerability by manipulating a parameter dfclientid through API request URLs which could lead to unauthorized access to sensitive information belonging to other users.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47657" + }, + { + "type": "WEB", + "url": "https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0313" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-639" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-04T13:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-7prj-hj6w-444f/GHSA-7prj-hj6w-444f.json b/advisories/unreviewed/2024/10/GHSA-7prj-hj6w-444f/GHSA-7prj-hj6w-444f.json new file mode 100644 index 00000000000..e483ce85fde --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-7prj-hj6w-444f/GHSA-7prj-hj6w-444f.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7prj-hj6w-444f", + "modified": "2024-10-04T15:31:22Z", + "published": "2024-10-04T15:31:22Z", + "aliases": [ + "CVE-2024-9515" + ], + "details": "A vulnerability was found in D-Link DIR-605L 2.13B01 BETA. It has been classified as critical. This affects the function formSetQoS of the file /goform/formSetQoS. The manipulation of the argument curTime leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9515" + }, + { + "type": "WEB", + "url": "https://github.com/noahze01/IoT-vulnerable/blob/main/D-Link/DIR-605L/formSetQoS.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.279213" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.279213" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.413878" + }, + { + "type": "WEB", + "url": "https://www.dlink.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-04T14:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-7r7x-w2qg-cx77/GHSA-7r7x-w2qg-cx77.json b/advisories/unreviewed/2024/10/GHSA-7r7x-w2qg-cx77/GHSA-7r7x-w2qg-cx77.json new file mode 100644 index 00000000000..fd080e48019 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-7r7x-w2qg-cx77/GHSA-7r7x-w2qg-cx77.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7r7x-w2qg-cx77", + "modified": "2024-10-04T15:31:20Z", + "published": "2024-10-04T15:31:20Z", + "aliases": [ + "CVE-2024-47653" + ], + "details": "This vulnerability exists in Shilpi Client Dashboard due to lack of authorization for modification and cancellation requests through certain API endpoints. An authenticated remote attacker could exploit this vulnerability by placing or cancelling requests through API request body leading to unauthorized modification of requests belonging to the other users.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47653" + }, + { + "type": "WEB", + "url": "https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0313" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-04T13:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-8xx5-ghfp-wg5c/GHSA-8xx5-ghfp-wg5c.json b/advisories/unreviewed/2024/10/GHSA-8xx5-ghfp-wg5c/GHSA-8xx5-ghfp-wg5c.json new file mode 100644 index 00000000000..da1c6e35989 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-8xx5-ghfp-wg5c/GHSA-8xx5-ghfp-wg5c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8xx5-ghfp-wg5c", + "modified": "2024-10-04T15:31:20Z", + "published": "2024-10-04T15:31:20Z", + "aliases": [ + "CVE-2024-47654" + ], + "details": "This vulnerability exists in Shilpi Client Dashboard due to lack of rate limiting and Captcha protection for OTP requests in certain API endpoint. An unauthenticated remote attacker could exploit this vulnerability by sending multiple OTP request through vulnerable API endpoints, which could lead to the OTP bombing on the targeted system.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47654" + }, + { + "type": "WEB", + "url": "https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0313" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-799" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-04T13:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-cr9c-949p-jxvr/GHSA-cr9c-949p-jxvr.json b/advisories/unreviewed/2024/10/GHSA-cr9c-949p-jxvr/GHSA-cr9c-949p-jxvr.json index b90a29fcb7f..b334a7e7991 100644 --- a/advisories/unreviewed/2024/10/GHSA-cr9c-949p-jxvr/GHSA-cr9c-949p-jxvr.json +++ b/advisories/unreviewed/2024/10/GHSA-cr9c-949p-jxvr/GHSA-cr9c-949p-jxvr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cr9c-949p-jxvr", - "modified": "2024-10-03T18:30:36Z", + "modified": "2024-10-04T15:31:19Z", "published": "2024-10-03T18:30:36Z", "aliases": [ "CVE-2023-37822" @@ -22,6 +22,10 @@ "type": "WEB", "url": "https://www.usenix.org/conference/woot24/presentation/goeman" }, + { + "type": "WEB", + "url": "https://www.usenix.org/system/files/woot24-goeman.pdf" + }, { "type": "WEB", "url": "http://anker.com" diff --git a/advisories/unreviewed/2024/10/GHSA-fpg5-7w95-pcwj/GHSA-fpg5-7w95-pcwj.json b/advisories/unreviewed/2024/10/GHSA-fpg5-7w95-pcwj/GHSA-fpg5-7w95-pcwj.json new file mode 100644 index 00000000000..5d83ae37748 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-fpg5-7w95-pcwj/GHSA-fpg5-7w95-pcwj.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fpg5-7w95-pcwj", + "modified": "2024-10-04T15:31:22Z", + "published": "2024-10-04T15:31:22Z", + "aliases": [ + "CVE-2024-9513" + ], + "details": "A vulnerability was found in Netadmin Software NetAdmin IAM up to 3.5 and classified as problematic. Affected by this issue is some unknown functionality of the file /controller/api/Answer/ReturnUserQuestionsFilled of the component HTTP POST Request Handler. The manipulation of the argument username leads to information exposure through discrepancy. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9513" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.279212" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.279212" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.413498" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-203" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-04T13:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-hm4r-q33h-2fw6/GHSA-hm4r-q33h-2fw6.json b/advisories/unreviewed/2024/10/GHSA-hm4r-q33h-2fw6/GHSA-hm4r-q33h-2fw6.json new file mode 100644 index 00000000000..8364518aaae --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-hm4r-q33h-2fw6/GHSA-hm4r-q33h-2fw6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hm4r-q33h-2fw6", + "modified": "2024-10-04T15:31:21Z", + "published": "2024-10-04T15:31:21Z", + "aliases": [ + "CVE-2024-9483" + ], + "details": "A null-pointer-dereference in the signature verification module in AVG/Avast Antivirus signature <24092400 released on 24/Sep/2024 on MacOS may allow a malformed xar file to crash the application during processing.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9483" + }, + { + "type": "WEB", + "url": "https://support.norton.com/sp/static/external/tools/security-advisories.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-04T13:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-jjm3-8267-chq9/GHSA-jjm3-8267-chq9.json b/advisories/unreviewed/2024/10/GHSA-jjm3-8267-chq9/GHSA-jjm3-8267-chq9.json new file mode 100644 index 00000000000..4671a314a1c --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-jjm3-8267-chq9/GHSA-jjm3-8267-chq9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jjm3-8267-chq9", + "modified": "2024-10-04T15:31:21Z", + "published": "2024-10-04T15:31:21Z", + "aliases": [ + "CVE-2024-9484" + ], + "details": "An null-pointer-derefrence in the engine module in AVG/Avast Antivirus signature <24092400 released on 24/Sep/2024 on MacOS allows a malformed xar file to crash the application during file processing.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9484" + }, + { + "type": "WEB", + "url": "https://support.norton.com/sp/static/external/tools/security-advisories.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-04T13:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-m5vg-qcpp-rq6f/GHSA-m5vg-qcpp-rq6f.json b/advisories/unreviewed/2024/10/GHSA-m5vg-qcpp-rq6f/GHSA-m5vg-qcpp-rq6f.json new file mode 100644 index 00000000000..8dd8af46191 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-m5vg-qcpp-rq6f/GHSA-m5vg-qcpp-rq6f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m5vg-qcpp-rq6f", + "modified": "2024-10-04T15:31:21Z", + "published": "2024-10-04T15:31:21Z", + "aliases": [ + "CVE-2024-47790" + ], + "details": "** UNSUPPORTED WHEN ASSIGNED ** This vulnerability exists in D3D Security IP Camera due to usage of insecure Real-Time Streaming Protocol (RTSP) version for live video streaming. A remote attacker could exploit this vulnerability by crafting a RTSP packet leading to unauthorized access to live feed of the targeted device. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47790" + }, + { + "type": "WEB", + "url": "https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0314" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-04T13:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-pq74-689g-fqg7/GHSA-pq74-689g-fqg7.json b/advisories/unreviewed/2024/10/GHSA-pq74-689g-fqg7/GHSA-pq74-689g-fqg7.json new file mode 100644 index 00000000000..47bad8d83c3 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-pq74-689g-fqg7/GHSA-pq74-689g-fqg7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pq74-689g-fqg7", + "modified": "2024-10-04T15:31:21Z", + "published": "2024-10-04T15:31:21Z", + "aliases": [ + "CVE-2024-47789" + ], + "details": "** UNSUPPORTED WHEN ASSIGNED ** This vulnerability exists in D3D Security IP Camera due to usage of weak authentication scheme of the HTTP header protocol where authorization tag contain a Base-64 encoded username and password. A remote attacker could exploit this vulnerability by crafting a HTTP packet leading to exposure of user credentials of the targeted device. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47789" + }, + { + "type": "WEB", + "url": "https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0314" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-319" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-04T13:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-q99v-9gg3-9f8p/GHSA-q99v-9gg3-9f8p.json b/advisories/unreviewed/2024/10/GHSA-q99v-9gg3-9f8p/GHSA-q99v-9gg3-9f8p.json new file mode 100644 index 00000000000..b9338f5677b --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-q99v-9gg3-9f8p/GHSA-q99v-9gg3-9f8p.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q99v-9gg3-9f8p", + "modified": "2024-10-04T15:31:21Z", + "published": "2024-10-04T15:31:21Z", + "aliases": [ + "CVE-2024-8499" + ], + "details": "The Checkout Field Editor (Checkout Manager) for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘render_review_request_notice’ function in all versions up to, and including, 2.0.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8499" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/woo-checkout-field-editor-pro/trunk/admin/class-thwcfd-admin.php#L426" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3160299" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/81eb8963-548f-4e94-83bd-266a19c09aab?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-04T13:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-v863-m35q-9hvv/GHSA-v863-m35q-9hvv.json b/advisories/unreviewed/2024/10/GHSA-v863-m35q-9hvv/GHSA-v863-m35q-9hvv.json new file mode 100644 index 00000000000..20df5733ca3 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-v863-m35q-9hvv/GHSA-v863-m35q-9hvv.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v863-m35q-9hvv", + "modified": "2024-10-04T15:31:22Z", + "published": "2024-10-04T15:31:22Z", + "aliases": [ + "CVE-2024-9514" + ], + "details": "A vulnerability was found in D-Link DIR-605L 2.13B01 BETA. It has been declared as critical. This vulnerability affects the function formSetDomainFilter of the file /goform/formSetDomainFilter. The manipulation of the argument curTime leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9514" + }, + { + "type": "WEB", + "url": "https://github.com/noahze01/IoT-vulnerable/blob/main/D-Link/DIR-605L/formSetDomainFilter.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.279214" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.279214" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.413874" + }, + { + "type": "WEB", + "url": "https://www.dlink.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-04T14:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-vhp6-hrqq-rpqj/GHSA-vhp6-hrqq-rpqj.json b/advisories/unreviewed/2024/10/GHSA-vhp6-hrqq-rpqj/GHSA-vhp6-hrqq-rpqj.json new file mode 100644 index 00000000000..6b350288a35 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-vhp6-hrqq-rpqj/GHSA-vhp6-hrqq-rpqj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vhp6-hrqq-rpqj", + "modified": "2024-10-04T15:31:22Z", + "published": "2024-10-04T15:31:22Z", + "aliases": [ + "CVE-2024-9410" + ], + "details": "Ada.cx's Sentry configuration allowed for blind server-side request forgeries (SSRF) through the use of a data scraping endpoint.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9410" + }, + { + "type": "WEB", + "url": "https://www.tenable.com/security/research/tra-2024-41" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-04T14:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-vx6r-82hr-hr24/GHSA-vx6r-82hr-hr24.json b/advisories/unreviewed/2024/10/GHSA-vx6r-82hr-hr24/GHSA-vx6r-82hr-hr24.json new file mode 100644 index 00000000000..6651eb0d035 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-vx6r-82hr-hr24/GHSA-vx6r-82hr-hr24.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vx6r-82hr-hr24", + "modified": "2024-10-04T15:31:20Z", + "published": "2024-10-04T15:31:20Z", + "aliases": [ + "CVE-2024-47652" + ], + "details": "This vulnerability exists in Shilpi Client Dashboard due to implementation of inadequate authentication mechanism in the login module wherein access to any users account is granted with just their corresponding mobile number. A remote attacker could exploit this vulnerability by providing mobile number of targeted user, to obtain complete access to the targeted user account.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47652" + }, + { + "type": "WEB", + "url": "https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0313" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-308" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-04T13:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-xfh8-7hcx-ppfp/GHSA-xfh8-7hcx-ppfp.json b/advisories/unreviewed/2024/10/GHSA-xfh8-7hcx-ppfp/GHSA-xfh8-7hcx-ppfp.json new file mode 100644 index 00000000000..8a137acb1b2 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-xfh8-7hcx-ppfp/GHSA-xfh8-7hcx-ppfp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xfh8-7hcx-ppfp", + "modified": "2024-10-04T15:31:21Z", + "published": "2024-10-04T15:31:21Z", + "aliases": [ + "CVE-2024-47655" + ], + "details": "This vulnerability exists in the Shilpi Client Dashboard due to improper validation of files being uploaded other than the specified extension. An authenticated remote attacker could exploit this vulnerability by uploading malicious file, which could lead to remote code execution on targeted application.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47655" + }, + { + "type": "WEB", + "url": "https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0313" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-04T13:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-xfxr-3v89-hch2/GHSA-xfxr-3v89-hch2.json b/advisories/unreviewed/2024/10/GHSA-xfxr-3v89-hch2/GHSA-xfxr-3v89-hch2.json new file mode 100644 index 00000000000..46573446651 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-xfxr-3v89-hch2/GHSA-xfxr-3v89-hch2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xfxr-3v89-hch2", + "modified": "2024-10-04T15:31:21Z", + "published": "2024-10-04T15:31:21Z", + "aliases": [ + "CVE-2024-9481" + ], + "details": "An out-of-bounds write in the engine module in AVG/Avast Antivirus signature <24092400 released on 24/Sep/2024 on MacOS allows a malformed eml file to crash the application during file processing.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9481" + }, + { + "type": "WEB", + "url": "https://support.norton.com/sp/static/external/tools/security-advisories.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-04T13:15:12Z" + } +} \ No newline at end of file