diff --git a/advisories/unreviewed/2023/01/GHSA-3j7g-922g-j6r3/GHSA-3j7g-922g-j6r3.json b/advisories/unreviewed/2023/01/GHSA-3j7g-922g-j6r3/GHSA-3j7g-922g-j6r3.json index 37026466764..41d183e7688 100644 --- a/advisories/unreviewed/2023/01/GHSA-3j7g-922g-j6r3/GHSA-3j7g-922g-j6r3.json +++ b/advisories/unreviewed/2023/01/GHSA-3j7g-922g-j6r3/GHSA-3j7g-922g-j6r3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3j7g-922g-j6r3", - "modified": "2024-04-19T15:30:45Z", + "modified": "2024-12-12T03:32:57Z", "published": "2023-01-12T21:30:30Z", "aliases": [ "CVE-2023-23456" @@ -31,6 +31,10 @@ "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2160381" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/12/msg00013.html" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EL3BVKIGG3SH6I3KPOYQAWCBD4UMPOPI" diff --git a/advisories/unreviewed/2023/06/GHSA-j63h-wp7g-gv2g/GHSA-j63h-wp7g-gv2g.json b/advisories/unreviewed/2023/06/GHSA-j63h-wp7g-gv2g/GHSA-j63h-wp7g-gv2g.json index 2f9b9869343..8c475ece9dd 100644 --- a/advisories/unreviewed/2023/06/GHSA-j63h-wp7g-gv2g/GHSA-j63h-wp7g-gv2g.json +++ b/advisories/unreviewed/2023/06/GHSA-j63h-wp7g-gv2g/GHSA-j63h-wp7g-gv2g.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-78" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-rp64-mpmj-44xf/GHSA-rp64-mpmj-44xf.json b/advisories/unreviewed/2023/06/GHSA-rp64-mpmj-44xf/GHSA-rp64-mpmj-44xf.json index 15e55c96a02..f094be71bbb 100644 --- a/advisories/unreviewed/2023/06/GHSA-rp64-mpmj-44xf/GHSA-rp64-mpmj-44xf.json +++ b/advisories/unreviewed/2023/06/GHSA-rp64-mpmj-44xf/GHSA-rp64-mpmj-44xf.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-400" + "CWE-400", + "CWE-770" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-244w-39h6-2f5r/GHSA-244w-39h6-2f5r.json b/advisories/unreviewed/2023/10/GHSA-244w-39h6-2f5r/GHSA-244w-39h6-2f5r.json index 199095cce76..03ee94c41f9 100644 --- a/advisories/unreviewed/2023/10/GHSA-244w-39h6-2f5r/GHSA-244w-39h6-2f5r.json +++ b/advisories/unreviewed/2023/10/GHSA-244w-39h6-2f5r/GHSA-244w-39h6-2f5r.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-126" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/10/GHSA-4gqw-x6ww-pxrr/GHSA-4gqw-x6ww-pxrr.json b/advisories/unreviewed/2023/10/GHSA-4gqw-x6ww-pxrr/GHSA-4gqw-x6ww-pxrr.json index a21ca4eed98..a59c02d7964 100644 --- a/advisories/unreviewed/2023/10/GHSA-4gqw-x6ww-pxrr/GHSA-4gqw-x6ww-pxrr.json +++ b/advisories/unreviewed/2023/10/GHSA-4gqw-x6ww-pxrr/GHSA-4gqw-x6ww-pxrr.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/10/GHSA-wh38-jq3r-39hr/GHSA-wh38-jq3r-39hr.json b/advisories/unreviewed/2023/10/GHSA-wh38-jq3r-39hr/GHSA-wh38-jq3r-39hr.json index 6eed5c323e6..39d52f4205c 100644 --- a/advisories/unreviewed/2023/10/GHSA-wh38-jq3r-39hr/GHSA-wh38-jq3r-39hr.json +++ b/advisories/unreviewed/2023/10/GHSA-wh38-jq3r-39hr/GHSA-wh38-jq3r-39hr.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/10/GHSA-wh6f-p9hp-fpwj/GHSA-wh6f-p9hp-fpwj.json b/advisories/unreviewed/2023/10/GHSA-wh6f-p9hp-fpwj/GHSA-wh6f-p9hp-fpwj.json index 533bc90c75a..d63506f95a3 100644 --- a/advisories/unreviewed/2023/10/GHSA-wh6f-p9hp-fpwj/GHSA-wh6f-p9hp-fpwj.json +++ b/advisories/unreviewed/2023/10/GHSA-wh6f-p9hp-fpwj/GHSA-wh6f-p9hp-fpwj.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/12/GHSA-2cf6-2fcj-fh7h/GHSA-2cf6-2fcj-fh7h.json b/advisories/unreviewed/2024/12/GHSA-2cf6-2fcj-fh7h/GHSA-2cf6-2fcj-fh7h.json new file mode 100644 index 00000000000..4b19c2cf621 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-2cf6-2fcj-fh7h/GHSA-2cf6-2fcj-fh7h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2cf6-2fcj-fh7h", + "modified": "2024-12-12T03:33:04Z", + "published": "2024-12-12T03:33:04Z", + "aliases": [ + "CVE-2024-49062" + ], + "details": "Microsoft SharePoint Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49062" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49062" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-23" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:04:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-2cwj-7vfc-5vfh/GHSA-2cwj-7vfc-5vfh.json b/advisories/unreviewed/2024/12/GHSA-2cwj-7vfc-5vfh/GHSA-2cwj-7vfc-5vfh.json new file mode 100644 index 00000000000..98745ffa996 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-2cwj-7vfc-5vfh/GHSA-2cwj-7vfc-5vfh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2cwj-7vfc-5vfh", + "modified": "2024-12-12T03:33:04Z", + "published": "2024-12-12T03:33:04Z", + "aliases": [ + "CVE-2024-49065" + ], + "details": "Microsoft Office Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49065" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49065" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:04:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-2g7f-fm5g-52cj/GHSA-2g7f-fm5g-52cj.json b/advisories/unreviewed/2024/12/GHSA-2g7f-fm5g-52cj/GHSA-2g7f-fm5g-52cj.json new file mode 100644 index 00000000000..62a06826cee --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-2g7f-fm5g-52cj/GHSA-2g7f-fm5g-52cj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2g7f-fm5g-52cj", + "modified": "2024-12-12T03:33:04Z", + "published": "2024-12-12T03:33:04Z", + "aliases": [ + "CVE-2024-49085" + ], + "details": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49085" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49085" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:04:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-2gwv-p3pp-2hvm/GHSA-2gwv-p3pp-2hvm.json b/advisories/unreviewed/2024/12/GHSA-2gwv-p3pp-2hvm/GHSA-2gwv-p3pp-2hvm.json new file mode 100644 index 00000000000..cf60e8f143a --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-2gwv-p3pp-2hvm/GHSA-2gwv-p3pp-2hvm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2gwv-p3pp-2hvm", + "modified": "2024-12-12T03:33:04Z", + "published": "2024-12-12T03:33:04Z", + "aliases": [ + "CVE-2024-49064" + ], + "details": "Microsoft SharePoint Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49064" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49064" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-611" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:04:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-372f-8jhc-h6mp/GHSA-372f-8jhc-h6mp.json b/advisories/unreviewed/2024/12/GHSA-372f-8jhc-h6mp/GHSA-372f-8jhc-h6mp.json new file mode 100644 index 00000000000..04f751b50e3 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-372f-8jhc-h6mp/GHSA-372f-8jhc-h6mp.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-372f-8jhc-h6mp", + "modified": "2024-12-12T03:33:06Z", + "published": "2024-12-12T03:33:06Z", + "aliases": [ + "CVE-2024-54501" + ], + "details": "The issue was addressed with improved checks. This issue is fixed in iPadOS 17.7.3, watchOS 11.2, visionOS 2.2, tvOS 18.2, macOS Sequoia 15.2, iOS 18.2 and iPadOS 18.2, macOS Ventura 13.7.2, macOS Sonoma 14.7.2. Processing a maliciously crafted file may lead to a denial of service.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54501" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121837" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121838" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121839" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121840" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121842" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121843" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121844" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121845" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-396q-83g8-947v/GHSA-396q-83g8-947v.json b/advisories/unreviewed/2024/12/GHSA-396q-83g8-947v/GHSA-396q-83g8-947v.json new file mode 100644 index 00000000000..de7e0a3e53f --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-396q-83g8-947v/GHSA-396q-83g8-947v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-396q-83g8-947v", + "modified": "2024-12-12T03:33:05Z", + "published": "2024-12-12T03:33:05Z", + "aliases": [ + "CVE-2024-49114" + ], + "details": "Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49114" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49114" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-820" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:04:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-3gh8-3438-mqwv/GHSA-3gh8-3438-mqwv.json b/advisories/unreviewed/2024/12/GHSA-3gh8-3438-mqwv/GHSA-3gh8-3438-mqwv.json index fb109410d10..60e9fdcf308 100644 --- a/advisories/unreviewed/2024/12/GHSA-3gh8-3438-mqwv/GHSA-3gh8-3438-mqwv.json +++ b/advisories/unreviewed/2024/12/GHSA-3gh8-3438-mqwv/GHSA-3gh8-3438-mqwv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3gh8-3438-mqwv", - "modified": "2024-12-07T00:31:03Z", + "modified": "2024-12-12T03:33:00Z", "published": "2024-12-07T00:31:03Z", "aliases": [ "CVE-2024-41649" ], "details": "Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the executor_thread_.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-281" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-06T22:15:21Z" diff --git a/advisories/unreviewed/2024/12/GHSA-3hpg-wc2r-h2qx/GHSA-3hpg-wc2r-h2qx.json b/advisories/unreviewed/2024/12/GHSA-3hpg-wc2r-h2qx/GHSA-3hpg-wc2r-h2qx.json new file mode 100644 index 00000000000..8c7ca1170e2 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-3hpg-wc2r-h2qx/GHSA-3hpg-wc2r-h2qx.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3hpg-wc2r-h2qx", + "modified": "2024-12-12T03:33:03Z", + "published": "2024-12-12T03:33:03Z", + "aliases": [ + "CVE-2024-37377" + ], + "details": "A heap-based buffer overflow in IPsec of Ivanti Connect Secure before version 22.7R2.3 allows a remote unauthenticated attacker to cause a denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37377" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/December-2024-Security-Advisory-Ivanti-Connect-Secure-ICS-and-Ivanti-Policy-Secure-IPS-Multiple-CVEs" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T01:55:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-3jgx-j97r-g3gv/GHSA-3jgx-j97r-g3gv.json b/advisories/unreviewed/2024/12/GHSA-3jgx-j97r-g3gv/GHSA-3jgx-j97r-g3gv.json new file mode 100644 index 00000000000..be3b482b2a4 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-3jgx-j97r-g3gv/GHSA-3jgx-j97r-g3gv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3jgx-j97r-g3gv", + "modified": "2024-12-12T03:33:04Z", + "published": "2024-12-12T03:33:04Z", + "aliases": [ + "CVE-2024-49063" + ], + "details": "Microsoft/Muzic Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49063" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49063" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:04:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-3m98-m7jj-v78v/GHSA-3m98-m7jj-v78v.json b/advisories/unreviewed/2024/12/GHSA-3m98-m7jj-v78v/GHSA-3m98-m7jj-v78v.json new file mode 100644 index 00000000000..e56c8150b90 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-3m98-m7jj-v78v/GHSA-3m98-m7jj-v78v.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3m98-m7jj-v78v", + "modified": "2024-12-12T03:33:06Z", + "published": "2024-12-12T03:33:06Z", + "aliases": [ + "CVE-2024-54489" + ], + "details": "A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.2, macOS Ventura 13.7.2, macOS Sonoma 14.7.2. Running a mount command may unexpectedly execute arbitrary code.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54489" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121839" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121840" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121842" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-3rr6-v7fv-2xh2/GHSA-3rr6-v7fv-2xh2.json b/advisories/unreviewed/2024/12/GHSA-3rr6-v7fv-2xh2/GHSA-3rr6-v7fv-2xh2.json new file mode 100644 index 00000000000..b939d379a85 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-3rr6-v7fv-2xh2/GHSA-3rr6-v7fv-2xh2.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3rr6-v7fv-2xh2", + "modified": "2024-12-12T03:33:03Z", + "published": "2024-12-12T03:33:03Z", + "aliases": [ + "CVE-2024-12489" + ], + "details": "A vulnerability was found in code-projects Online Class and Exam Scheduling System 1.0. It has been classified as critical. This affects an unknown part of the file /pages/term.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12489" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/bjtyyy/CVE/blob/main/Online%20Class%20and%20Exam%20Scheduling%20System_term_php%20.docx" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.287871" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.287871" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.459113" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T01:40:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-42mv-mp72-h3gp/GHSA-42mv-mp72-h3gp.json b/advisories/unreviewed/2024/12/GHSA-42mv-mp72-h3gp/GHSA-42mv-mp72-h3gp.json new file mode 100644 index 00000000000..1bfc84f7992 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-42mv-mp72-h3gp/GHSA-42mv-mp72-h3gp.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-42mv-mp72-h3gp", + "modified": "2024-12-12T03:33:03Z", + "published": "2024-12-12T03:33:03Z", + "aliases": [ + "CVE-2024-12486" + ], + "details": "A vulnerability, which was classified as critical, was found in code-projects Online Class and Exam Scheduling System 1.0. Affected is an unknown function of the file /pages/rank_update.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12486" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/bjtyyy/CVE/blob/main/Online%20Class%20and%20Exam%20Scheduling%20System_rank_update_php.docx" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.287868" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.287868" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.459081" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T01:40:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-453g-5mrh-qccr/GHSA-453g-5mrh-qccr.json b/advisories/unreviewed/2024/12/GHSA-453g-5mrh-qccr/GHSA-453g-5mrh-qccr.json new file mode 100644 index 00000000000..5e4fbca9fd2 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-453g-5mrh-qccr/GHSA-453g-5mrh-qccr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-453g-5mrh-qccr", + "modified": "2024-12-12T03:33:05Z", + "published": "2024-12-12T03:33:05Z", + "aliases": [ + "CVE-2024-49126" + ], + "details": "Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49126" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49126" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:04:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-4588-xx8p-ch9q/GHSA-4588-xx8p-ch9q.json b/advisories/unreviewed/2024/12/GHSA-4588-xx8p-ch9q/GHSA-4588-xx8p-ch9q.json new file mode 100644 index 00000000000..f0a37500935 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-4588-xx8p-ch9q/GHSA-4588-xx8p-ch9q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4588-xx8p-ch9q", + "modified": "2024-12-12T03:33:06Z", + "published": "2024-12-12T03:33:06Z", + "aliases": [ + "CVE-2024-41146" + ], + "details": "Use of Multiple Resources with Duplicate Identifier (CWE-694) in the Controller 6000 and Controller 7000 Platforms could allow an attacker with physical access to HBUS communication cabling to perform a Denial-of-Service attack against HBUS connected devices, require a device reboot to resolve. \n\nThis issue affects: Controller 6000 and Controller 7000 firmware versions 9.10 prior to vCR9.10.241108a (distributed in 9.10.2149 (MR4)), 9.00 prior to vCR9.00.241108a (distributed in 9.00.2374 (MR5)), 8.90 prior to vCR8.90.241107a (distributed in 8.90.2356 (MR6)), all versions of 8.80 and prior.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41146" + }, + { + "type": "WEB", + "url": "https://security.gallagher.com/en-NZ/Security-Advisories/CVE-2024-41146" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-694" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-4gff-x4ff-9qq7/GHSA-4gff-x4ff-9qq7.json b/advisories/unreviewed/2024/12/GHSA-4gff-x4ff-9qq7/GHSA-4gff-x4ff-9qq7.json index 8025ae5d9e6..61588aa3c27 100644 --- a/advisories/unreviewed/2024/12/GHSA-4gff-x4ff-9qq7/GHSA-4gff-x4ff-9qq7.json +++ b/advisories/unreviewed/2024/12/GHSA-4gff-x4ff-9qq7/GHSA-4gff-x4ff-9qq7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4gff-x4ff-9qq7", - "modified": "2024-12-11T15:31:16Z", + "modified": "2024-12-12T03:33:01Z", "published": "2024-12-11T15:31:16Z", "aliases": [ "CVE-2024-50585" ], "details": "Users who click on a malicious link or visit a website under the control of an attacker can be infected with arbitrary JavaScript which is running in the context of the \"Numerix License Server Administration System Login\" (nlslogin.jsp) page. The vulnerability can be triggered by sending a specially crafted HTTP POST request. \n\n\n\nThe vendor was unresponsive during multiple attempts to contact them via various channels, hence there is no solution available. In case you are using this software, be sure to restrict access and monitor logs. Try to reach out to your contact person for this vendor and request a patch.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-11T15:15:14Z" diff --git a/advisories/unreviewed/2024/12/GHSA-4gjx-h244-c8vq/GHSA-4gjx-h244-c8vq.json b/advisories/unreviewed/2024/12/GHSA-4gjx-h244-c8vq/GHSA-4gjx-h244-c8vq.json index 89e4a9bf02e..a6fa5795f78 100644 --- a/advisories/unreviewed/2024/12/GHSA-4gjx-h244-c8vq/GHSA-4gjx-h244-c8vq.json +++ b/advisories/unreviewed/2024/12/GHSA-4gjx-h244-c8vq/GHSA-4gjx-h244-c8vq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4gjx-h244-c8vq", - "modified": "2024-12-07T00:31:04Z", + "modified": "2024-12-12T03:33:00Z", "published": "2024-12-07T00:31:04Z", "aliases": [ "CVE-2024-44852" ], "details": "Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a segmentation violation via the component theta_star::ThetaStar::isUnsafeToPlan().", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-763" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-06T22:15:21Z" diff --git a/advisories/unreviewed/2024/12/GHSA-4m3c-vp5f-8qxg/GHSA-4m3c-vp5f-8qxg.json b/advisories/unreviewed/2024/12/GHSA-4m3c-vp5f-8qxg/GHSA-4m3c-vp5f-8qxg.json new file mode 100644 index 00000000000..f5f08d5b714 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-4m3c-vp5f-8qxg/GHSA-4m3c-vp5f-8qxg.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4m3c-vp5f-8qxg", + "modified": "2024-12-12T03:33:03Z", + "published": "2024-12-12T03:33:03Z", + "aliases": [ + "CVE-2024-12480" + ], + "details": "A vulnerability was found in cjbi wetech-cms 1.0/1.1/1.2. It has been classified as critical. Affected is the function searchTopic of the file wetech-cms-master\\wetech-core\\src\\main\\java\\tech\\wetech\\cms\\dao\\TopicDao.java. The manipulation of the argument con leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12480" + }, + { + "type": "WEB", + "url": "https://github.com/hadagaga/vuln/blob/master/wetech-cms/sql-2/SQL_injection_vulnerability.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.287862" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.287862" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.458851" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T01:40:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-54w6-f3f8-54q2/GHSA-54w6-f3f8-54q2.json b/advisories/unreviewed/2024/12/GHSA-54w6-f3f8-54q2/GHSA-54w6-f3f8-54q2.json new file mode 100644 index 00000000000..1e9d9d10c6c --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-54w6-f3f8-54q2/GHSA-54w6-f3f8-54q2.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-54w6-f3f8-54q2", + "modified": "2024-12-12T03:33:06Z", + "published": "2024-12-12T03:33:06Z", + "aliases": [ + "CVE-2024-54498" + ], + "details": "A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.2, macOS Ventura 13.7.2, macOS Sonoma 14.7.2. An app may be able to break out of its sandbox.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54498" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121839" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121840" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121842" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-58f5-8jq5-r8p2/GHSA-58f5-8jq5-r8p2.json b/advisories/unreviewed/2024/12/GHSA-58f5-8jq5-r8p2/GHSA-58f5-8jq5-r8p2.json new file mode 100644 index 00000000000..de9ac02a685 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-58f5-8jq5-r8p2/GHSA-58f5-8jq5-r8p2.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-58f5-8jq5-r8p2", + "modified": "2024-12-12T03:33:06Z", + "published": "2024-12-12T03:33:06Z", + "aliases": [ + "CVE-2024-54510" + ], + "details": "A race condition was addressed with improved locking. This issue is fixed in iPadOS 17.7.3, watchOS 11.2, tvOS 18.2, macOS Sequoia 15.2, iOS 18.2 and iPadOS 18.2, macOS Ventura 13.7.2, macOS Sonoma 14.7.2. An app may be able to leak sensitive kernel state.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54510" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121837" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121838" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121839" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121840" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121842" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121843" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121844" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-5ggf-wr65-v75x/GHSA-5ggf-wr65-v75x.json b/advisories/unreviewed/2024/12/GHSA-5ggf-wr65-v75x/GHSA-5ggf-wr65-v75x.json new file mode 100644 index 00000000000..0b5fb4cce28 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-5ggf-wr65-v75x/GHSA-5ggf-wr65-v75x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5ggf-wr65-v75x", + "modified": "2024-12-12T03:33:04Z", + "published": "2024-12-12T03:33:04Z", + "aliases": [ + "CVE-2024-43600" + ], + "details": "Microsoft Office Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43600" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43600" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:00:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-5j9p-7q54-gvh7/GHSA-5j9p-7q54-gvh7.json b/advisories/unreviewed/2024/12/GHSA-5j9p-7q54-gvh7/GHSA-5j9p-7q54-gvh7.json index c241a4ee215..612fbadd15c 100644 --- a/advisories/unreviewed/2024/12/GHSA-5j9p-7q54-gvh7/GHSA-5j9p-7q54-gvh7.json +++ b/advisories/unreviewed/2024/12/GHSA-5j9p-7q54-gvh7/GHSA-5j9p-7q54-gvh7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5j9p-7q54-gvh7", - "modified": "2024-12-10T21:30:52Z", + "modified": "2024-12-12T03:33:01Z", "published": "2024-12-10T21:30:52Z", "aliases": [ "CVE-2024-50924" ], "details": "Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to cause disrupt communications between the controller and the device itself via repeatedly sending crafted packets to the controller.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-281" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-10T19:15:30Z" diff --git a/advisories/unreviewed/2024/12/GHSA-5pqw-jjjw-gf67/GHSA-5pqw-jjjw-gf67.json b/advisories/unreviewed/2024/12/GHSA-5pqw-jjjw-gf67/GHSA-5pqw-jjjw-gf67.json new file mode 100644 index 00000000000..c784d4083a8 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-5pqw-jjjw-gf67/GHSA-5pqw-jjjw-gf67.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5pqw-jjjw-gf67", + "modified": "2024-12-12T03:33:05Z", + "published": "2024-12-12T03:33:05Z", + "aliases": [ + "CVE-2024-49120" + ], + "details": "Windows Remote Desktop Services Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49120" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49120" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-453" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:04:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-622c-pfxh-44wx/GHSA-622c-pfxh-44wx.json b/advisories/unreviewed/2024/12/GHSA-622c-pfxh-44wx/GHSA-622c-pfxh-44wx.json new file mode 100644 index 00000000000..b8b7aa2197b --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-622c-pfxh-44wx/GHSA-622c-pfxh-44wx.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-622c-pfxh-44wx", + "modified": "2024-12-12T03:33:06Z", + "published": "2024-12-12T03:33:06Z", + "aliases": [ + "CVE-2024-12492" + ], + "details": "A vulnerability was found in code-projects Farmacia 1.0. It has been rated as critical. This issue affects some unknown processing of the file /visualizar-usuario.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12492" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/A1ph4D3v1l/cve/blob/main/sql-x.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.287873" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.287873" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.459115" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-67jv-gxg5-rmq6/GHSA-67jv-gxg5-rmq6.json b/advisories/unreviewed/2024/12/GHSA-67jv-gxg5-rmq6/GHSA-67jv-gxg5-rmq6.json new file mode 100644 index 00000000000..214bb124655 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-67jv-gxg5-rmq6/GHSA-67jv-gxg5-rmq6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-67jv-gxg5-rmq6", + "modified": "2024-12-12T03:33:04Z", + "published": "2024-12-12T03:33:04Z", + "aliases": [ + "CVE-2024-49082" + ], + "details": "Windows File Explorer Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49082" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49082" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:04:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-67jx-fcjg-p4rh/GHSA-67jx-fcjg-p4rh.json b/advisories/unreviewed/2024/12/GHSA-67jx-fcjg-p4rh/GHSA-67jx-fcjg-p4rh.json new file mode 100644 index 00000000000..543c0ef288f --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-67jx-fcjg-p4rh/GHSA-67jx-fcjg-p4rh.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-67jx-fcjg-p4rh", + "modified": "2024-12-12T03:33:06Z", + "published": "2024-12-12T03:33:06Z", + "aliases": [ + "CVE-2024-44245" + ], + "details": "The issue was addressed with improved memory handling. This issue is fixed in iPadOS 17.7.3, visionOS 2.2, macOS Sequoia 15.2, iOS 18.2 and iPadOS 18.2, macOS Sonoma 14.7.2. An app may be able to cause unexpected system termination or corrupt kernel memory.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44245" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121837" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121838" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121839" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121840" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121845" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-67x6-x9j4-cm73/GHSA-67x6-x9j4-cm73.json b/advisories/unreviewed/2024/12/GHSA-67x6-x9j4-cm73/GHSA-67x6-x9j4-cm73.json new file mode 100644 index 00000000000..3fc5c03da5c --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-67x6-x9j4-cm73/GHSA-67x6-x9j4-cm73.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-67x6-x9j4-cm73", + "modified": "2024-12-12T03:33:06Z", + "published": "2024-12-12T03:33:06Z", + "aliases": [ + "CVE-2024-12497" + ], + "details": "A vulnerability classified as critical has been found in 1000 Projects Attendance Tracking Management System 1.0. Affected is an unknown function of the file /admin/check_admin_login.php. The manipulation of the argument admin_user_name leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12497" + }, + { + "type": "WEB", + "url": "https://github.com/Ta0k1a/CVE/issues/1" + }, + { + "type": "WEB", + "url": "https://1000projects.org" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.287874" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.287874" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.459239" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-6cx8-q77v-f378/GHSA-6cx8-q77v-f378.json b/advisories/unreviewed/2024/12/GHSA-6cx8-q77v-f378/GHSA-6cx8-q77v-f378.json new file mode 100644 index 00000000000..706a59a7c15 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-6cx8-q77v-f378/GHSA-6cx8-q77v-f378.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6cx8-q77v-f378", + "modified": "2024-12-12T03:33:05Z", + "published": "2024-12-12T03:33:05Z", + "aliases": [ + "CVE-2024-49107" + ], + "details": "WmsRepair Service Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49107" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49107" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:04:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-6gh5-wv8v-cf34/GHSA-6gh5-wv8v-cf34.json b/advisories/unreviewed/2024/12/GHSA-6gh5-wv8v-cf34/GHSA-6gh5-wv8v-cf34.json new file mode 100644 index 00000000000..f0473c8e28d --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-6gh5-wv8v-cf34/GHSA-6gh5-wv8v-cf34.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6gh5-wv8v-cf34", + "modified": "2024-12-12T03:33:04Z", + "published": "2024-12-12T03:33:04Z", + "aliases": [ + "CVE-2024-49081" + ], + "details": "Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49081" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49081" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:04:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-6p96-58pg-p58h/GHSA-6p96-58pg-p58h.json b/advisories/unreviewed/2024/12/GHSA-6p96-58pg-p58h/GHSA-6p96-58pg-p58h.json new file mode 100644 index 00000000000..a1123ee9208 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-6p96-58pg-p58h/GHSA-6p96-58pg-p58h.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6p96-58pg-p58h", + "modified": "2024-12-12T03:33:06Z", + "published": "2024-12-12T03:33:06Z", + "aliases": [ + "CVE-2024-44224" + ], + "details": "A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.2, macOS Ventura 13.7.2, macOS Sonoma 14.7.2. A malicious app may be able to gain root privileges.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44224" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121839" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121840" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121842" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-6vmf-4hpw-fgcm/GHSA-6vmf-4hpw-fgcm.json b/advisories/unreviewed/2024/12/GHSA-6vmf-4hpw-fgcm/GHSA-6vmf-4hpw-fgcm.json new file mode 100644 index 00000000000..c6d62e11df4 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-6vmf-4hpw-fgcm/GHSA-6vmf-4hpw-fgcm.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6vmf-4hpw-fgcm", + "modified": "2024-12-12T03:33:06Z", + "published": "2024-12-12T03:33:06Z", + "aliases": [ + "CVE-2024-44201" + ], + "details": "The issue was addressed with improved memory handling. This issue is fixed in iPadOS 17.7.3, macOS Ventura 13.7.2, iOS 18.1 and iPadOS 18.1, macOS Sonoma 14.7.2. Processing a malicious crafted file may lead to a denial-of-service.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44201" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121563" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121838" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121840" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121842" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-6wcv-fq4v-cvv9/GHSA-6wcv-fq4v-cvv9.json b/advisories/unreviewed/2024/12/GHSA-6wcv-fq4v-cvv9/GHSA-6wcv-fq4v-cvv9.json new file mode 100644 index 00000000000..6e2c8646934 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-6wcv-fq4v-cvv9/GHSA-6wcv-fq4v-cvv9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6wcv-fq4v-cvv9", + "modified": "2024-12-12T03:33:05Z", + "published": "2024-12-12T03:33:05Z", + "aliases": [ + "CVE-2024-49105" + ], + "details": "Remote Desktop Client Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49105" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49105" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:04:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-6xm9-4v9w-hpvh/GHSA-6xm9-4v9w-hpvh.json b/advisories/unreviewed/2024/12/GHSA-6xm9-4v9w-hpvh/GHSA-6xm9-4v9w-hpvh.json new file mode 100644 index 00000000000..44c07609f33 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-6xm9-4v9w-hpvh/GHSA-6xm9-4v9w-hpvh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6xm9-4v9w-hpvh", + "modified": "2024-12-12T03:33:05Z", + "published": "2024-12-12T03:33:05Z", + "aliases": [ + "CVE-2024-49102" + ], + "details": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49102" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49102" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:04:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-75mx-hw5q-pvx3/GHSA-75mx-hw5q-pvx3.json b/advisories/unreviewed/2024/12/GHSA-75mx-hw5q-pvx3/GHSA-75mx-hw5q-pvx3.json new file mode 100644 index 00000000000..4457a2749b1 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-75mx-hw5q-pvx3/GHSA-75mx-hw5q-pvx3.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-75mx-hw5q-pvx3", + "modified": "2024-12-12T03:33:05Z", + "published": "2024-12-12T03:33:05Z", + "aliases": [ + "CVE-2024-55587" + ], + "details": "python-libarchive through 4.2.1 allows directory traversal (to create files) in extract in zip.py for ZipFile.extractall and ZipFile.extract.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55587" + }, + { + "type": "WEB", + "url": "https://github.com/smartfile/python-libarchive/issues/42" + }, + { + "type": "WEB", + "url": "https://github.com/smartfile/python-libarchive/pull/41" + }, + { + "type": "WEB", + "url": "https://github.com/smartfile/python-libarchive/blob/c7677411bfc4ab5701d343bc6ebd9e35c990e80e/libarchive/zip.py#L107" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:08:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-76wg-3c38-9p89/GHSA-76wg-3c38-9p89.json b/advisories/unreviewed/2024/12/GHSA-76wg-3c38-9p89/GHSA-76wg-3c38-9p89.json new file mode 100644 index 00000000000..4f25ddcae69 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-76wg-3c38-9p89/GHSA-76wg-3c38-9p89.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-76wg-3c38-9p89", + "modified": "2024-12-12T03:33:04Z", + "published": "2024-12-12T03:33:04Z", + "aliases": [ + "CVE-2024-49073" + ], + "details": "Windows Mobile Broadband Driver Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49073" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49073" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:04:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-77pc-23q5-7vg9/GHSA-77pc-23q5-7vg9.json b/advisories/unreviewed/2024/12/GHSA-77pc-23q5-7vg9/GHSA-77pc-23q5-7vg9.json new file mode 100644 index 00000000000..20096a3471b --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-77pc-23q5-7vg9/GHSA-77pc-23q5-7vg9.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-77pc-23q5-7vg9", + "modified": "2024-12-12T03:33:06Z", + "published": "2024-12-12T03:33:06Z", + "aliases": [ + "CVE-2024-54466" + ], + "details": "An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.2, macOS Ventura 13.7.2, macOS Sonoma 14.7.2. An encrypted volume may be accessed by a different user without prompting for the password.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54466" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121839" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121840" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121842" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-78q2-767q-6x6v/GHSA-78q2-767q-6x6v.json b/advisories/unreviewed/2024/12/GHSA-78q2-767q-6x6v/GHSA-78q2-767q-6x6v.json new file mode 100644 index 00000000000..6e7447e5ebc --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-78q2-767q-6x6v/GHSA-78q2-767q-6x6v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-78q2-767q-6x6v", + "modified": "2024-12-12T03:33:05Z", + "published": "2024-12-12T03:33:05Z", + "aliases": [ + "CVE-2024-49124" + ], + "details": "Lightweight Directory Access Protocol (LDAP) Client Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49124" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49124" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-362" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:04:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-7h39-783j-9952/GHSA-7h39-783j-9952.json b/advisories/unreviewed/2024/12/GHSA-7h39-783j-9952/GHSA-7h39-783j-9952.json new file mode 100644 index 00000000000..591e4dba91e --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-7h39-783j-9952/GHSA-7h39-783j-9952.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7h39-783j-9952", + "modified": "2024-12-12T03:33:05Z", + "published": "2024-12-12T03:33:05Z", + "aliases": [ + "CVE-2024-49103" + ], + "details": "Windows Wireless Wide Area Network Service (WwanSvc) Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49103" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49103" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:04:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-7j7p-8xpw-v444/GHSA-7j7p-8xpw-v444.json b/advisories/unreviewed/2024/12/GHSA-7j7p-8xpw-v444/GHSA-7j7p-8xpw-v444.json new file mode 100644 index 00000000000..76939741fb7 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-7j7p-8xpw-v444/GHSA-7j7p-8xpw-v444.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7j7p-8xpw-v444", + "modified": "2024-12-12T03:33:05Z", + "published": "2024-12-12T03:33:05Z", + "aliases": [ + "CVE-2024-49118" + ], + "details": "Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49118" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49118" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:04:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-7r2p-cp9x-c68f/GHSA-7r2p-cp9x-c68f.json b/advisories/unreviewed/2024/12/GHSA-7r2p-cp9x-c68f/GHSA-7r2p-cp9x-c68f.json new file mode 100644 index 00000000000..3bd4e08aa0f --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-7r2p-cp9x-c68f/GHSA-7r2p-cp9x-c68f.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7r2p-cp9x-c68f", + "modified": "2024-12-12T03:33:06Z", + "published": "2024-12-12T03:33:06Z", + "aliases": [ + "CVE-2024-54506" + ], + "details": "An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.2. An attacker may be able to cause unexpected system termination or arbitrary code execution in DCP firmware.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54506" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121839" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-7rqg-87vg-jf87/GHSA-7rqg-87vg-jf87.json b/advisories/unreviewed/2024/12/GHSA-7rqg-87vg-jf87/GHSA-7rqg-87vg-jf87.json new file mode 100644 index 00000000000..703b7ffae30 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-7rqg-87vg-jf87/GHSA-7rqg-87vg-jf87.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7rqg-87vg-jf87", + "modified": "2024-12-12T03:33:03Z", + "published": "2024-12-12T03:33:03Z", + "aliases": [ + "CVE-2024-43594" + ], + "details": "System Center Operations Manager Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43594" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43594" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:00:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-7wvc-54wp-pv8x/GHSA-7wvc-54wp-pv8x.json b/advisories/unreviewed/2024/12/GHSA-7wvc-54wp-pv8x/GHSA-7wvc-54wp-pv8x.json new file mode 100644 index 00000000000..8e3c7ff693b --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-7wvc-54wp-pv8x/GHSA-7wvc-54wp-pv8x.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7wvc-54wp-pv8x", + "modified": "2024-12-12T03:33:06Z", + "published": "2024-12-12T03:33:06Z", + "aliases": [ + "CVE-2024-54477" + ], + "details": "The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2, macOS Ventura 13.7.2, macOS Sonoma 14.7.2. An app may be able to access user-sensitive data.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54477" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121839" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121840" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121842" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-83g6-wm8c-3hx9/GHSA-83g6-wm8c-3hx9.json b/advisories/unreviewed/2024/12/GHSA-83g6-wm8c-3hx9/GHSA-83g6-wm8c-3hx9.json new file mode 100644 index 00000000000..e9fe7e56eb0 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-83g6-wm8c-3hx9/GHSA-83g6-wm8c-3hx9.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-83g6-wm8c-3hx9", + "modified": "2024-12-12T03:33:07Z", + "published": "2024-12-12T03:33:07Z", + "aliases": [ + "CVE-2024-54534" + ], + "details": "The issue was addressed with improved memory handling. This issue is fixed in watchOS 11.2, visionOS 2.2, tvOS 18.2, macOS Sequoia 15.2, Safari 18.2, iOS 18.2 and iPadOS 18.2. Processing maliciously crafted web content may lead to memory corruption.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54534" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121837" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121839" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121843" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121844" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121845" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121846" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-868q-j7qx-m3gf/GHSA-868q-j7qx-m3gf.json b/advisories/unreviewed/2024/12/GHSA-868q-j7qx-m3gf/GHSA-868q-j7qx-m3gf.json new file mode 100644 index 00000000000..49aaab94cff --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-868q-j7qx-m3gf/GHSA-868q-j7qx-m3gf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-868q-j7qx-m3gf", + "modified": "2024-12-12T03:33:05Z", + "published": "2024-12-12T03:33:05Z", + "aliases": [ + "CVE-2024-49108" + ], + "details": "Windows Remote Desktop Services Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49108" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49108" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:04:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-873c-cc79-4g4q/GHSA-873c-cc79-4g4q.json b/advisories/unreviewed/2024/12/GHSA-873c-cc79-4g4q/GHSA-873c-cc79-4g4q.json new file mode 100644 index 00000000000..7a5e42e7008 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-873c-cc79-4g4q/GHSA-873c-cc79-4g4q.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-873c-cc79-4g4q", + "modified": "2024-12-12T03:33:06Z", + "published": "2024-12-12T03:33:06Z", + "aliases": [ + "CVE-2024-44212" + ], + "details": "A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18.1, visionOS 2.1, tvOS 18.1, iOS 18.1 and iPadOS 18.1, watchOS 11.1. Cookies belonging to one origin may be sent to another origin.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44212" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121563" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121565" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121566" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121569" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121571" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-887q-rm9x-7wg9/GHSA-887q-rm9x-7wg9.json b/advisories/unreviewed/2024/12/GHSA-887q-rm9x-7wg9/GHSA-887q-rm9x-7wg9.json new file mode 100644 index 00000000000..09a17f26e4c --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-887q-rm9x-7wg9/GHSA-887q-rm9x-7wg9.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-887q-rm9x-7wg9", + "modified": "2024-12-12T03:33:06Z", + "published": "2024-12-12T03:33:06Z", + "aliases": [ + "CVE-2024-54465" + ], + "details": "A logic issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.2. An app may be able to elevate privileges.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54465" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121839" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-8fqw-xqvx-7f2j/GHSA-8fqw-xqvx-7f2j.json b/advisories/unreviewed/2024/12/GHSA-8fqw-xqvx-7f2j/GHSA-8fqw-xqvx-7f2j.json new file mode 100644 index 00000000000..bbb2986c782 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-8fqw-xqvx-7f2j/GHSA-8fqw-xqvx-7f2j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8fqw-xqvx-7f2j", + "modified": "2024-12-12T03:33:06Z", + "published": "2024-12-12T03:33:05Z", + "aliases": [ + "CVE-2024-42407" + ], + "details": "Insertion of Sensitive Information into Log File (CWE-532) in the Gallagher Command Centre Alarm Transmitter feature could allow an authenticated Operator to view some security sensitive information to which they have not been granted access. \n\nThis issue affects: Command Centre Server 9.10 prior to 9.10.2149 (MR4), 9.00 prior to 9.00.2374 (MR5), 8.90 prior to 8.90.2356 (MR6), all versions of 8.80 and prior.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42407" + }, + { + "type": "WEB", + "url": "https://security.gallagher.com/en-NZ/Security-Advisories/CVE-2024-42407" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-8ghc-464q-f7vj/GHSA-8ghc-464q-f7vj.json b/advisories/unreviewed/2024/12/GHSA-8ghc-464q-f7vj/GHSA-8ghc-464q-f7vj.json new file mode 100644 index 00000000000..b2ebbfb162b --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-8ghc-464q-f7vj/GHSA-8ghc-464q-f7vj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8ghc-464q-f7vj", + "modified": "2024-12-12T03:33:04Z", + "published": "2024-12-12T03:33:04Z", + "aliases": [ + "CVE-2024-49074" + ], + "details": "Windows Kernel-Mode Driver Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49074" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49074" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:04:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-8pxx-x275-69h8/GHSA-8pxx-x275-69h8.json b/advisories/unreviewed/2024/12/GHSA-8pxx-x275-69h8/GHSA-8pxx-x275-69h8.json new file mode 100644 index 00000000000..fc090dd13cd --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-8pxx-x275-69h8/GHSA-8pxx-x275-69h8.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8pxx-x275-69h8", + "modified": "2024-12-12T03:33:03Z", + "published": "2024-12-12T03:33:03Z", + "aliases": [ + "CVE-2024-12487" + ], + "details": "A vulnerability has been found in code-projects Online Class and Exam Scheduling System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /pages/room_update.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12487" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/bjtyyy/CVE/blob/main/Online%20Class%20and%20Exam%20Scheduling%20System_room_update_php.docx" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.287869" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.287869" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.459083" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T01:40:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-93h5-h222-mg95/GHSA-93h5-h222-mg95.json b/advisories/unreviewed/2024/12/GHSA-93h5-h222-mg95/GHSA-93h5-h222-mg95.json new file mode 100644 index 00000000000..25ebe0dcca8 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-93h5-h222-mg95/GHSA-93h5-h222-mg95.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-93h5-h222-mg95", + "modified": "2024-12-12T03:33:05Z", + "published": "2024-12-12T03:33:05Z", + "aliases": [ + "CVE-2024-49142" + ], + "details": "Microsoft Access Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49142" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49142" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:04:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-97qm-2h4w-qghq/GHSA-97qm-2h4w-qghq.json b/advisories/unreviewed/2024/12/GHSA-97qm-2h4w-qghq/GHSA-97qm-2h4w-qghq.json new file mode 100644 index 00000000000..4cde9a234ce --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-97qm-2h4w-qghq/GHSA-97qm-2h4w-qghq.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-97qm-2h4w-qghq", + "modified": "2024-12-12T03:33:06Z", + "published": "2024-12-12T03:33:06Z", + "aliases": [ + "CVE-2024-54484" + ], + "details": "The issue was resolved by sanitizing logging. This issue is fixed in macOS Sequoia 15.2. An app may be able to access user-sensitive data.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54484" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121839" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-986v-gc7p-69fc/GHSA-986v-gc7p-69fc.json b/advisories/unreviewed/2024/12/GHSA-986v-gc7p-69fc/GHSA-986v-gc7p-69fc.json new file mode 100644 index 00000000000..2e5de1a9557 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-986v-gc7p-69fc/GHSA-986v-gc7p-69fc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-986v-gc7p-69fc", + "modified": "2024-12-12T03:33:04Z", + "published": "2024-12-12T03:33:04Z", + "aliases": [ + "CVE-2024-49088" + ], + "details": "Windows Common Log File System Driver Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49088" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49088" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-126" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:04:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-9gpp-mwr2-q4r3/GHSA-9gpp-mwr2-q4r3.json b/advisories/unreviewed/2024/12/GHSA-9gpp-mwr2-q4r3/GHSA-9gpp-mwr2-q4r3.json new file mode 100644 index 00000000000..a5dc7473321 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-9gpp-mwr2-q4r3/GHSA-9gpp-mwr2-q4r3.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9gpp-mwr2-q4r3", + "modified": "2024-12-12T03:33:03Z", + "published": "2024-12-12T03:33:03Z", + "aliases": [ + "CVE-2024-37401" + ], + "details": "An out-of-bounds read in IPsec of Ivanti Connect Secure before version 22.7R2.1 allows a remote unauthenticated attacker to cause a denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37401" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/December-2024-Security-Advisory-Ivanti-Connect-Secure-ICS-and-Ivanti-Policy-Secure-IPS-Multiple-CVEs" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T01:55:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-9j95-8xv9-jv6r/GHSA-9j95-8xv9-jv6r.json b/advisories/unreviewed/2024/12/GHSA-9j95-8xv9-jv6r/GHSA-9j95-8xv9-jv6r.json new file mode 100644 index 00000000000..a2dcaac9b94 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-9j95-8xv9-jv6r/GHSA-9j95-8xv9-jv6r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9j95-8xv9-jv6r", + "modified": "2024-12-12T03:33:05Z", + "published": "2024-12-12T03:33:05Z", + "aliases": [ + "CVE-2024-49096" + ], + "details": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49096" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49096" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:04:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-9mxx-gqvm-r9mc/GHSA-9mxx-gqvm-r9mc.json b/advisories/unreviewed/2024/12/GHSA-9mxx-gqvm-r9mc/GHSA-9mxx-gqvm-r9mc.json new file mode 100644 index 00000000000..7b4c86f1ef2 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-9mxx-gqvm-r9mc/GHSA-9mxx-gqvm-r9mc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9mxx-gqvm-r9mc", + "modified": "2024-12-12T03:33:05Z", + "published": "2024-12-12T03:33:05Z", + "aliases": [ + "CVE-2024-49094" + ], + "details": "Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49094" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49094" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:04:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-9q8j-gxp4-4c9j/GHSA-9q8j-gxp4-4c9j.json b/advisories/unreviewed/2024/12/GHSA-9q8j-gxp4-4c9j/GHSA-9q8j-gxp4-4c9j.json new file mode 100644 index 00000000000..8378d77a782 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-9q8j-gxp4-4c9j/GHSA-9q8j-gxp4-4c9j.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9q8j-gxp4-4c9j", + "modified": "2024-12-12T03:33:03Z", + "published": "2024-12-12T03:33:03Z", + "aliases": [ + "CVE-2024-12485" + ], + "details": "A vulnerability, which was classified as critical, has been found in code-projects Online Class and Exam Scheduling System 1.0. This issue affects some unknown processing of the file /pages/department.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12485" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/bjtyyy/CVE/blob/main/Online%20Class%20and%20Exam%20Scheduling%20System_department_php.docx" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.287867" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.287867" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.459077" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T01:40:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-9rxr-xfqc-4rq9/GHSA-9rxr-xfqc-4rq9.json b/advisories/unreviewed/2024/12/GHSA-9rxr-xfqc-4rq9/GHSA-9rxr-xfqc-4rq9.json new file mode 100644 index 00000000000..382a91ca9e9 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-9rxr-xfqc-4rq9/GHSA-9rxr-xfqc-4rq9.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9rxr-xfqc-4rq9", + "modified": "2024-12-12T03:33:03Z", + "published": "2024-12-12T03:33:03Z", + "aliases": [ + "CVE-2024-12479" + ], + "details": "A vulnerability was found in cjbi wetech-cms 1.0/1.1/1.2 and classified as critical. This issue affects the function searchTopicByKeyword of the file wetech-cms-master\\wetech-core\\src\\main\\java\\tech\\wetech\\cms\\dao\\TopicDao.java. The manipulation of the argument keyword leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12479" + }, + { + "type": "WEB", + "url": "https://github.com/hadagaga/vuln/blob/master/wetech-cms/sql-1/SQL_injection_vulnerability.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.287861" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.287861" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.458849" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T01:40:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-9wm3-v99j-79rf/GHSA-9wm3-v99j-79rf.json b/advisories/unreviewed/2024/12/GHSA-9wm3-v99j-79rf/GHSA-9wm3-v99j-79rf.json new file mode 100644 index 00000000000..d23f826732a --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-9wm3-v99j-79rf/GHSA-9wm3-v99j-79rf.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9wm3-v99j-79rf", + "modified": "2024-12-12T03:33:06Z", + "published": "2024-12-12T03:33:06Z", + "aliases": [ + "CVE-2024-44225" + ], + "details": "A logic issue was addressed with improved checks. This issue is fixed in iPadOS 17.7.3, watchOS 11.2, tvOS 18.2, macOS Sequoia 15.2, iOS 18.2 and iPadOS 18.2, macOS Ventura 13.7.2, macOS Sonoma 14.7.2. An app may be able to gain elevated privileges.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44225" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121837" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121838" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121839" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121840" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121842" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121843" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121844" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-c382-wfjm-cr9h/GHSA-c382-wfjm-cr9h.json b/advisories/unreviewed/2024/12/GHSA-c382-wfjm-cr9h/GHSA-c382-wfjm-cr9h.json new file mode 100644 index 00000000000..0e092a6e609 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-c382-wfjm-cr9h/GHSA-c382-wfjm-cr9h.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c382-wfjm-cr9h", + "modified": "2024-12-12T03:33:05Z", + "published": "2024-12-12T03:33:05Z", + "aliases": [ + "CVE-2024-12490" + ], + "details": "A vulnerability was found in code-projects Online Class and Exam Scheduling System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /pages/teacher_save.php. The manipulation of the argument salut leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12490" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/bjtyyy/CVE/blob/main/Online%20Class%20and%20Exam%20Scheduling%20System_teacher_save_php.docx" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.287872" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.287872" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.459116" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-c3f2-9wv2-2gxf/GHSA-c3f2-9wv2-2gxf.json b/advisories/unreviewed/2024/12/GHSA-c3f2-9wv2-2gxf/GHSA-c3f2-9wv2-2gxf.json new file mode 100644 index 00000000000..abbda805ae0 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-c3f2-9wv2-2gxf/GHSA-c3f2-9wv2-2gxf.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c3f2-9wv2-2gxf", + "modified": "2024-12-12T03:33:07Z", + "published": "2024-12-12T03:33:07Z", + "aliases": [ + "CVE-2024-54526" + ], + "details": "The issue was addressed with improved checks. This issue is fixed in watchOS 11.2, tvOS 18.2, macOS Sequoia 15.2, iOS 18.2 and iPadOS 18.2, macOS Ventura 13.7.2, macOS Sonoma 14.7.2. A malicious app may be able to access private information.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54526" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121837" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121839" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121840" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121842" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121843" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121844" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-c4cm-m6vc-3xvq/GHSA-c4cm-m6vc-3xvq.json b/advisories/unreviewed/2024/12/GHSA-c4cm-m6vc-3xvq/GHSA-c4cm-m6vc-3xvq.json new file mode 100644 index 00000000000..74db63f8858 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-c4cm-m6vc-3xvq/GHSA-c4cm-m6vc-3xvq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c4cm-m6vc-3xvq", + "modified": "2024-12-12T03:33:05Z", + "published": "2024-12-12T03:33:05Z", + "aliases": [ + "CVE-2024-49116" + ], + "details": "Windows Remote Desktop Services Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49116" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49116" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:04:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-c6wq-gv79-3q94/GHSA-c6wq-gv79-3q94.json b/advisories/unreviewed/2024/12/GHSA-c6wq-gv79-3q94/GHSA-c6wq-gv79-3q94.json index 1a333644d37..f6ad3f30aac 100644 --- a/advisories/unreviewed/2024/12/GHSA-c6wq-gv79-3q94/GHSA-c6wq-gv79-3q94.json +++ b/advisories/unreviewed/2024/12/GHSA-c6wq-gv79-3q94/GHSA-c6wq-gv79-3q94.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c6wq-gv79-3q94", - "modified": "2024-12-07T00:31:03Z", + "modified": "2024-12-12T03:32:59Z", "published": "2024-12-07T00:31:03Z", "aliases": [ "CVE-2024-38927" ], "details": "Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered via remotely sending a request to change the value of dynamic-parameter `/amcl do_beamskip`.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-06T22:15:20Z" diff --git a/advisories/unreviewed/2024/12/GHSA-c8c9-xcrw-6rgj/GHSA-c8c9-xcrw-6rgj.json b/advisories/unreviewed/2024/12/GHSA-c8c9-xcrw-6rgj/GHSA-c8c9-xcrw-6rgj.json new file mode 100644 index 00000000000..9dc749286a3 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-c8c9-xcrw-6rgj/GHSA-c8c9-xcrw-6rgj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c8c9-xcrw-6rgj", + "modified": "2024-12-12T03:33:04Z", + "published": "2024-12-12T03:33:04Z", + "aliases": [ + "CVE-2024-49080" + ], + "details": "Windows IP Routing Management Snapin Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49080" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49080" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:04:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-c957-vcxp-6qqg/GHSA-c957-vcxp-6qqg.json b/advisories/unreviewed/2024/12/GHSA-c957-vcxp-6qqg/GHSA-c957-vcxp-6qqg.json index 40bcbe23ac2..ae1ae214076 100644 --- a/advisories/unreviewed/2024/12/GHSA-c957-vcxp-6qqg/GHSA-c957-vcxp-6qqg.json +++ b/advisories/unreviewed/2024/12/GHSA-c957-vcxp-6qqg/GHSA-c957-vcxp-6qqg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c957-vcxp-6qqg", - "modified": "2024-12-10T00:31:26Z", + "modified": "2024-12-12T03:33:01Z", "published": "2024-12-10T00:31:26Z", "aliases": [ "CVE-2024-50625" ], "details": "An issue was discovered in Digi ConnectPort LTS before 1.4.12. A vulnerability in the file upload handling of a web application allows manipulation of file paths via POST requests. This can lead to arbitrary file uploads within specific directories, potentially enabling privilege escalation when combined with other vulnerabilities.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-434" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-09T22:15:22Z" diff --git a/advisories/unreviewed/2024/12/GHSA-c9mr-7r2v-xjc9/GHSA-c9mr-7r2v-xjc9.json b/advisories/unreviewed/2024/12/GHSA-c9mr-7r2v-xjc9/GHSA-c9mr-7r2v-xjc9.json new file mode 100644 index 00000000000..2dcad4595cd --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-c9mr-7r2v-xjc9/GHSA-c9mr-7r2v-xjc9.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c9mr-7r2v-xjc9", + "modified": "2024-12-12T03:33:06Z", + "published": "2024-12-12T03:33:06Z", + "aliases": [ + "CVE-2024-44246" + ], + "details": "The issue was addressed with improved routing of Safari-originated requests. This issue is fixed in macOS Sequoia 15.2, iOS 18.2 and iPadOS 18.2, Safari 18.2, iPadOS 17.7.3. On a device with Private Relay enabled, adding a website to the Safari Reading List may reveal the originating IP address to the website.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44246" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121837" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121838" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121839" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121846" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-chq8-x439-4whp/GHSA-chq8-x439-4whp.json b/advisories/unreviewed/2024/12/GHSA-chq8-x439-4whp/GHSA-chq8-x439-4whp.json new file mode 100644 index 00000000000..9f8a93965e2 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-chq8-x439-4whp/GHSA-chq8-x439-4whp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-chq8-x439-4whp", + "modified": "2024-12-12T03:33:04Z", + "published": "2024-12-12T03:33:04Z", + "aliases": [ + "CVE-2024-49070" + ], + "details": "Microsoft SharePoint Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49070" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49070" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:04:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-crvx-jm2p-jmwp/GHSA-crvx-jm2p-jmwp.json b/advisories/unreviewed/2024/12/GHSA-crvx-jm2p-jmwp/GHSA-crvx-jm2p-jmwp.json new file mode 100644 index 00000000000..7d2a2238150 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-crvx-jm2p-jmwp/GHSA-crvx-jm2p-jmwp.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-crvx-jm2p-jmwp", + "modified": "2024-12-12T03:33:06Z", + "published": "2024-12-12T03:33:05Z", + "aliases": [ + "CVE-2024-44241" + ], + "details": "The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.1 and iPadOS 18.1. An attacker may be able to cause unexpected system termination or arbitrary code execution in DCP firmware.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44241" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121563" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-cvp4-7hm2-fv9m/GHSA-cvp4-7hm2-fv9m.json b/advisories/unreviewed/2024/12/GHSA-cvp4-7hm2-fv9m/GHSA-cvp4-7hm2-fv9m.json new file mode 100644 index 00000000000..7d89e31ddd1 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-cvp4-7hm2-fv9m/GHSA-cvp4-7hm2-fv9m.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cvp4-7hm2-fv9m", + "modified": "2024-12-12T03:33:05Z", + "published": "2024-12-12T03:33:05Z", + "aliases": [ + "CVE-2024-55884" + ], + "details": "In the Mullvad VPN client 2024.6 (Desktop), 2024.8 (iOS), and 2024.8-beta1 (Android), the exception-handling alternate stack can be exhausted, leading to heap-based out-of-bounds writes in enable() in exception_logging/unix.rs, aka MLLVD-CR-24-01. NOTE: achieving code execution is considered non-trivial.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55884" + }, + { + "type": "WEB", + "url": "https://github.com/mullvad/mullvadvpn-app/commit/ef6c862071b26023802b00d6e1dc6ca53d1ab3e6" + }, + { + "type": "WEB", + "url": "https://news.ycombinator.com/item?id=42390768" + }, + { + "type": "WEB", + "url": "https://x41-dsec.de/news/2024/12/11/mullvad" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:08:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-cwjq-ghx4-v7j3/GHSA-cwjq-ghx4-v7j3.json b/advisories/unreviewed/2024/12/GHSA-cwjq-ghx4-v7j3/GHSA-cwjq-ghx4-v7j3.json index 1c668658311..60f9c266c26 100644 --- a/advisories/unreviewed/2024/12/GHSA-cwjq-ghx4-v7j3/GHSA-cwjq-ghx4-v7j3.json +++ b/advisories/unreviewed/2024/12/GHSA-cwjq-ghx4-v7j3/GHSA-cwjq-ghx4-v7j3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cwjq-ghx4-v7j3", - "modified": "2024-12-07T00:31:03Z", + "modified": "2024-12-12T03:32:59Z", "published": "2024-12-07T00:31:03Z", "aliases": [ "CVE-2024-38925" ], "details": "Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered via remotely sending a request for change the value of dynamic-parameter`/amcl z_max` .", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-06T22:15:20Z" diff --git a/advisories/unreviewed/2024/12/GHSA-f353-6hqm-57r9/GHSA-f353-6hqm-57r9.json b/advisories/unreviewed/2024/12/GHSA-f353-6hqm-57r9/GHSA-f353-6hqm-57r9.json new file mode 100644 index 00000000000..bc97482be88 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-f353-6hqm-57r9/GHSA-f353-6hqm-57r9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f353-6hqm-57r9", + "modified": "2024-12-12T03:33:04Z", + "published": "2024-12-12T03:33:04Z", + "aliases": [ + "CVE-2024-49076" + ], + "details": "Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49076" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49076" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:04:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-f482-9qmq-phw9/GHSA-f482-9qmq-phw9.json b/advisories/unreviewed/2024/12/GHSA-f482-9qmq-phw9/GHSA-f482-9qmq-phw9.json new file mode 100644 index 00000000000..fe15929f12c --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-f482-9qmq-phw9/GHSA-f482-9qmq-phw9.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f482-9qmq-phw9", + "modified": "2024-12-12T03:33:07Z", + "published": "2024-12-12T03:33:07Z", + "aliases": [ + "CVE-2024-54531" + ], + "details": "The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.2. An app may be able to bypass kASLR.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54531" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121839" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-f7g9-gqxr-pmv7/GHSA-f7g9-gqxr-pmv7.json b/advisories/unreviewed/2024/12/GHSA-f7g9-gqxr-pmv7/GHSA-f7g9-gqxr-pmv7.json new file mode 100644 index 00000000000..02df6b3fe89 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-f7g9-gqxr-pmv7/GHSA-f7g9-gqxr-pmv7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f7g9-gqxr-pmv7", + "modified": "2024-12-12T03:33:02Z", + "published": "2024-12-12T03:33:01Z", + "aliases": [ + "CVE-2024-11947" + ], + "details": "GFI Archiver Core Service Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GFI Archiver. Authentication is required to exploit this vulnerability.\n\nThe specific flaw exists within the Core Service, which listens on TCP port 8017 by default. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-24029.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11947" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1670" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T01:40:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-ffx5-3pxp-6q4w/GHSA-ffx5-3pxp-6q4w.json b/advisories/unreviewed/2024/12/GHSA-ffx5-3pxp-6q4w/GHSA-ffx5-3pxp-6q4w.json new file mode 100644 index 00000000000..ed423bd5ecf --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-ffx5-3pxp-6q4w/GHSA-ffx5-3pxp-6q4w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ffx5-3pxp-6q4w", + "modified": "2024-12-12T03:33:05Z", + "published": "2024-12-12T03:33:05Z", + "aliases": [ + "CVE-2024-49112" + ], + "details": "Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49112" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49112" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-190" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:04:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-fpq5-9jg6-fqq7/GHSA-fpq5-9jg6-fqq7.json b/advisories/unreviewed/2024/12/GHSA-fpq5-9jg6-fqq7/GHSA-fpq5-9jg6-fqq7.json new file mode 100644 index 00000000000..9c19058a54c --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-fpq5-9jg6-fqq7/GHSA-fpq5-9jg6-fqq7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fpq5-9jg6-fqq7", + "modified": "2024-12-12T03:33:04Z", + "published": "2024-12-12T03:33:04Z", + "aliases": [ + "CVE-2024-49079" + ], + "details": "Input Method Editor (IME) Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49079" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49079" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:04:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-fw24-x4v5-9x55/GHSA-fw24-x4v5-9x55.json b/advisories/unreviewed/2024/12/GHSA-fw24-x4v5-9x55/GHSA-fw24-x4v5-9x55.json new file mode 100644 index 00000000000..0e734c37c87 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-fw24-x4v5-9x55/GHSA-fw24-x4v5-9x55.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fw24-x4v5-9x55", + "modified": "2024-12-12T03:33:06Z", + "published": "2024-12-12T03:33:06Z", + "aliases": [ + "CVE-2024-54513" + ], + "details": "A permissions issue was addressed with additional restrictions. This issue is fixed in watchOS 11.2, visionOS 2.2, tvOS 18.2, macOS Sequoia 15.2, iOS 18.2 and iPadOS 18.2. An app may be able to access sensitive user data.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54513" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121837" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121839" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121843" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121844" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121845" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-g4ph-37mq-hvxw/GHSA-g4ph-37mq-hvxw.json b/advisories/unreviewed/2024/12/GHSA-g4ph-37mq-hvxw/GHSA-g4ph-37mq-hvxw.json index 9062dfa46ca..3caceb978b5 100644 --- a/advisories/unreviewed/2024/12/GHSA-g4ph-37mq-hvxw/GHSA-g4ph-37mq-hvxw.json +++ b/advisories/unreviewed/2024/12/GHSA-g4ph-37mq-hvxw/GHSA-g4ph-37mq-hvxw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-g4ph-37mq-hvxw", - "modified": "2024-12-07T00:31:03Z", + "modified": "2024-12-12T03:32:59Z", "published": "2024-12-07T00:31:03Z", "aliases": [ "CVE-2024-38921" ], "details": "Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered via remotely sending a request for change the value of dynamic-parameter`/amcl z_rand ` .", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-06T22:15:19Z" diff --git a/advisories/unreviewed/2024/12/GHSA-g59h-6mcf-fp78/GHSA-g59h-6mcf-fp78.json b/advisories/unreviewed/2024/12/GHSA-g59h-6mcf-fp78/GHSA-g59h-6mcf-fp78.json index 565c6eee95c..d716c6a54c3 100644 --- a/advisories/unreviewed/2024/12/GHSA-g59h-6mcf-fp78/GHSA-g59h-6mcf-fp78.json +++ b/advisories/unreviewed/2024/12/GHSA-g59h-6mcf-fp78/GHSA-g59h-6mcf-fp78.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-g59h-6mcf-fp78", - "modified": "2024-12-07T00:31:03Z", + "modified": "2024-12-12T03:32:59Z", "published": "2024-12-07T00:31:03Z", "aliases": [ "CVE-2024-38924" ], "details": "Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered via remotely sending a request to change the value of dynamic-parameter`/amcl laser_model_type` .", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-06T22:15:19Z" diff --git a/advisories/unreviewed/2024/12/GHSA-g66r-7w88-p6cv/GHSA-g66r-7w88-p6cv.json b/advisories/unreviewed/2024/12/GHSA-g66r-7w88-p6cv/GHSA-g66r-7w88-p6cv.json new file mode 100644 index 00000000000..76c9ff55d9d --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-g66r-7w88-p6cv/GHSA-g66r-7w88-p6cv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g66r-7w88-p6cv", + "modified": "2024-12-12T03:33:05Z", + "published": "2024-12-12T03:33:05Z", + "aliases": [ + "CVE-2024-49109" + ], + "details": "Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49109" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49109" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:04:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-gg96-2qm6-wg5x/GHSA-gg96-2qm6-wg5x.json b/advisories/unreviewed/2024/12/GHSA-gg96-2qm6-wg5x/GHSA-gg96-2qm6-wg5x.json new file mode 100644 index 00000000000..7fc890c851a --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-gg96-2qm6-wg5x/GHSA-gg96-2qm6-wg5x.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gg96-2qm6-wg5x", + "modified": "2024-12-12T03:33:06Z", + "published": "2024-12-12T03:33:06Z", + "aliases": [ + "CVE-2024-54503" + ], + "details": "An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 18.2 and iPadOS 18.2. Muting a call while ringing may not result in mute being enabled.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54503" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121837" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-ggfx-5h4r-jhq3/GHSA-ggfx-5h4r-jhq3.json b/advisories/unreviewed/2024/12/GHSA-ggfx-5h4r-jhq3/GHSA-ggfx-5h4r-jhq3.json new file mode 100644 index 00000000000..d19007e19b8 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-ggfx-5h4r-jhq3/GHSA-ggfx-5h4r-jhq3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ggfx-5h4r-jhq3", + "modified": "2024-12-12T03:33:04Z", + "published": "2024-12-12T03:33:04Z", + "aliases": [ + "CVE-2024-49069" + ], + "details": "Microsoft Excel Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49069" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49069" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:04:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-gqgf-rxrp-grhx/GHSA-gqgf-rxrp-grhx.json b/advisories/unreviewed/2024/12/GHSA-gqgf-rxrp-grhx/GHSA-gqgf-rxrp-grhx.json new file mode 100644 index 00000000000..188b3f0dea1 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-gqgf-rxrp-grhx/GHSA-gqgf-rxrp-grhx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gqgf-rxrp-grhx", + "modified": "2024-12-12T03:33:05Z", + "published": "2024-12-12T03:33:05Z", + "aliases": [ + "CVE-2024-49121" + ], + "details": "Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49121" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49121" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:04:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-gqhm-prc4-8m4c/GHSA-gqhm-prc4-8m4c.json b/advisories/unreviewed/2024/12/GHSA-gqhm-prc4-8m4c/GHSA-gqhm-prc4-8m4c.json new file mode 100644 index 00000000000..8dd2f43b9f2 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-gqhm-prc4-8m4c/GHSA-gqhm-prc4-8m4c.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gqhm-prc4-8m4c", + "modified": "2024-12-12T03:33:06Z", + "published": "2024-12-12T03:33:06Z", + "aliases": [ + "CVE-2024-54515" + ], + "details": "A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.2. A malicious app may be able to gain root privileges.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54515" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121839" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-grq3-9m83-rgpr/GHSA-grq3-9m83-rgpr.json b/advisories/unreviewed/2024/12/GHSA-grq3-9m83-rgpr/GHSA-grq3-9m83-rgpr.json new file mode 100644 index 00000000000..d41518f435e --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-grq3-9m83-rgpr/GHSA-grq3-9m83-rgpr.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-grq3-9m83-rgpr", + "modified": "2024-12-12T03:33:06Z", + "published": "2024-12-12T03:33:06Z", + "aliases": [ + "CVE-2024-44200" + ], + "details": "This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.1 and iPadOS 18.1. An app may be able to read sensitive location information.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44200" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121563" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-h37q-rxj6-83hg/GHSA-h37q-rxj6-83hg.json b/advisories/unreviewed/2024/12/GHSA-h37q-rxj6-83hg/GHSA-h37q-rxj6-83hg.json new file mode 100644 index 00000000000..d6ab247e79e --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-h37q-rxj6-83hg/GHSA-h37q-rxj6-83hg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h37q-rxj6-83hg", + "modified": "2024-12-12T03:33:04Z", + "published": "2024-12-12T03:33:04Z", + "aliases": [ + "CVE-2024-49072" + ], + "details": "Windows Task Scheduler Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49072" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49072" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:04:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-h49r-vq54-f89j/GHSA-h49r-vq54-f89j.json b/advisories/unreviewed/2024/12/GHSA-h49r-vq54-f89j/GHSA-h49r-vq54-f89j.json new file mode 100644 index 00000000000..f16222033a8 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-h49r-vq54-f89j/GHSA-h49r-vq54-f89j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h49r-vq54-f89j", + "modified": "2024-12-12T03:33:05Z", + "published": "2024-12-12T03:33:05Z", + "aliases": [ + "CVE-2024-49128" + ], + "details": "Windows Remote Desktop Services Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49128" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49128" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:04:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-h4hx-5g7m-p3hc/GHSA-h4hx-5g7m-p3hc.json b/advisories/unreviewed/2024/12/GHSA-h4hx-5g7m-p3hc/GHSA-h4hx-5g7m-p3hc.json new file mode 100644 index 00000000000..d1f74b6debe --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-h4hx-5g7m-p3hc/GHSA-h4hx-5g7m-p3hc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h4hx-5g7m-p3hc", + "modified": "2024-12-12T03:33:05Z", + "published": "2024-12-12T03:33:05Z", + "aliases": [ + "CVE-2024-49138" + ], + "details": "Windows Common Log File System Driver Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49138" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49138" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:04:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-h5qr-r3m8-3g2v/GHSA-h5qr-r3m8-3g2v.json b/advisories/unreviewed/2024/12/GHSA-h5qr-r3m8-3g2v/GHSA-h5qr-r3m8-3g2v.json new file mode 100644 index 00000000000..69a8ce44d8e --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-h5qr-r3m8-3g2v/GHSA-h5qr-r3m8-3g2v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h5qr-r3m8-3g2v", + "modified": "2024-12-12T03:33:05Z", + "published": "2024-12-12T03:33:05Z", + "aliases": [ + "CVE-2024-49093" + ], + "details": "Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49093" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49093" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-681" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:04:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-h6fx-m56r-mvw2/GHSA-h6fx-m56r-mvw2.json b/advisories/unreviewed/2024/12/GHSA-h6fx-m56r-mvw2/GHSA-h6fx-m56r-mvw2.json new file mode 100644 index 00000000000..a64ba1daf9a --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-h6fx-m56r-mvw2/GHSA-h6fx-m56r-mvw2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h6fx-m56r-mvw2", + "modified": "2024-12-12T03:33:05Z", + "published": "2024-12-12T03:33:05Z", + "aliases": [ + "CVE-2024-49104" + ], + "details": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49104" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49104" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:04:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-hf45-h325-58j2/GHSA-hf45-h325-58j2.json b/advisories/unreviewed/2024/12/GHSA-hf45-h325-58j2/GHSA-hf45-h325-58j2.json new file mode 100644 index 00000000000..21c2cdd5cc2 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-hf45-h325-58j2/GHSA-hf45-h325-58j2.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hf45-h325-58j2", + "modified": "2024-12-12T03:33:07Z", + "published": "2024-12-12T03:33:07Z", + "aliases": [ + "CVE-2024-54524" + ], + "details": "A logic issue was addressed with improved file handling. This issue is fixed in macOS Sequoia 15.2. A malicious app may be able to access arbitrary files.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54524" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121839" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-hg75-j4c9-fv98/GHSA-hg75-j4c9-fv98.json b/advisories/unreviewed/2024/12/GHSA-hg75-j4c9-fv98/GHSA-hg75-j4c9-fv98.json index d9ce25ec7c9..f128de27368 100644 --- a/advisories/unreviewed/2024/12/GHSA-hg75-j4c9-fv98/GHSA-hg75-j4c9-fv98.json +++ b/advisories/unreviewed/2024/12/GHSA-hg75-j4c9-fv98/GHSA-hg75-j4c9-fv98.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hg75-j4c9-fv98", - "modified": "2024-12-07T00:31:03Z", + "modified": "2024-12-12T03:32:59Z", "published": "2024-12-07T00:31:03Z", "aliases": [ "CVE-2024-41645" ], "details": "Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2__amcl.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-281" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-06T22:15:20Z" diff --git a/advisories/unreviewed/2024/12/GHSA-hjmx-m9c7-h485/GHSA-hjmx-m9c7-h485.json b/advisories/unreviewed/2024/12/GHSA-hjmx-m9c7-h485/GHSA-hjmx-m9c7-h485.json new file mode 100644 index 00000000000..94b2ca13592 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-hjmx-m9c7-h485/GHSA-hjmx-m9c7-h485.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hjmx-m9c7-h485", + "modified": "2024-12-12T03:33:06Z", + "published": "2024-12-12T03:33:06Z", + "aliases": [ + "CVE-2024-54471" + ], + "details": "This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sonoma 14.7.1, macOS Ventura 13.7.1. A malicious application may be able to leak a user's credentials.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54471" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121568" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121570" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-hp58-68h4-82p8/GHSA-hp58-68h4-82p8.json b/advisories/unreviewed/2024/12/GHSA-hp58-68h4-82p8/GHSA-hp58-68h4-82p8.json new file mode 100644 index 00000000000..8b6c349a337 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-hp58-68h4-82p8/GHSA-hp58-68h4-82p8.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hp58-68h4-82p8", + "modified": "2024-12-12T03:33:06Z", + "published": "2024-12-12T03:33:06Z", + "aliases": [ + "CVE-2024-54479" + ], + "details": "The issue was addressed with improved checks. This issue is fixed in iPadOS 17.7.3, watchOS 11.2, visionOS 2.2, tvOS 18.2, macOS Sequoia 15.2, Safari 18.2, iOS 18.2 and iPadOS 18.2. Processing maliciously crafted web content may lead to an unexpected process crash.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54479" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121837" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121838" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121839" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121843" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121844" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121845" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121846" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-hq8w-cr85-pwqw/GHSA-hq8w-cr85-pwqw.json b/advisories/unreviewed/2024/12/GHSA-hq8w-cr85-pwqw/GHSA-hq8w-cr85-pwqw.json new file mode 100644 index 00000000000..1b43150de43 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-hq8w-cr85-pwqw/GHSA-hq8w-cr85-pwqw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hq8w-cr85-pwqw", + "modified": "2024-12-12T03:33:05Z", + "published": "2024-12-12T03:33:05Z", + "aliases": [ + "CVE-2024-49113" + ], + "details": "Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49113" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49113" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:04:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-hv87-379m-crrp/GHSA-hv87-379m-crrp.json b/advisories/unreviewed/2024/12/GHSA-hv87-379m-crrp/GHSA-hv87-379m-crrp.json index 21a67c0aeb3..8eb004f3122 100644 --- a/advisories/unreviewed/2024/12/GHSA-hv87-379m-crrp/GHSA-hv87-379m-crrp.json +++ b/advisories/unreviewed/2024/12/GHSA-hv87-379m-crrp/GHSA-hv87-379m-crrp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hv87-379m-crrp", - "modified": "2024-12-07T00:31:04Z", + "modified": "2024-12-12T03:33:00Z", "published": "2024-12-07T00:31:04Z", "aliases": [ "CVE-2024-44856" ], "details": "Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a NULL pointer dereference via the component nav2_smac_planner().", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-06T22:15:21Z" diff --git a/advisories/unreviewed/2024/12/GHSA-hvg6-qchw-pmph/GHSA-hvg6-qchw-pmph.json b/advisories/unreviewed/2024/12/GHSA-hvg6-qchw-pmph/GHSA-hvg6-qchw-pmph.json new file mode 100644 index 00000000000..c16b6c8bf82 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-hvg6-qchw-pmph/GHSA-hvg6-qchw-pmph.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hvg6-qchw-pmph", + "modified": "2024-12-12T03:33:05Z", + "published": "2024-12-12T03:33:05Z", + "aliases": [ + "CVE-2024-49091" + ], + "details": "Windows Domain Name Service Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49091" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49091" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-591" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:04:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-hw5x-h98r-cfjc/GHSA-hw5x-h98r-cfjc.json b/advisories/unreviewed/2024/12/GHSA-hw5x-h98r-cfjc/GHSA-hw5x-h98r-cfjc.json new file mode 100644 index 00000000000..67d4879f243 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-hw5x-h98r-cfjc/GHSA-hw5x-h98r-cfjc.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hw5x-h98r-cfjc", + "modified": "2024-12-12T03:33:06Z", + "published": "2024-12-12T03:33:06Z", + "aliases": [ + "CVE-2024-54493" + ], + "details": "This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.2. Privacy indicators for microphone access may be attributed incorrectly.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54493" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121839" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-hwmm-rqf4-5hqh/GHSA-hwmm-rqf4-5hqh.json b/advisories/unreviewed/2024/12/GHSA-hwmm-rqf4-5hqh/GHSA-hwmm-rqf4-5hqh.json new file mode 100644 index 00000000000..f15908e951b --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-hwmm-rqf4-5hqh/GHSA-hwmm-rqf4-5hqh.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hwmm-rqf4-5hqh", + "modified": "2024-12-12T03:33:06Z", + "published": "2024-12-12T03:33:06Z", + "aliases": [ + "CVE-2024-44248" + ], + "details": "This issue was addressed through improved state management. This issue is fixed in macOS Ventura 13.7.2, macOS Sonoma 14.7.2. A user with screen sharing access may be able to view another user's screen.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44248" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121840" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121842" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-j3cp-346p-h999/GHSA-j3cp-346p-h999.json b/advisories/unreviewed/2024/12/GHSA-j3cp-346p-h999/GHSA-j3cp-346p-h999.json new file mode 100644 index 00000000000..346983ccbb2 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-j3cp-346p-h999/GHSA-j3cp-346p-h999.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j3cp-346p-h999", + "modified": "2024-12-12T03:33:06Z", + "published": "2024-12-12T03:33:05Z", + "aliases": [ + "CVE-2024-44243" + ], + "details": "A configuration issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.2. An app may be able to modify protected parts of the file system.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44243" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121839" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-j42v-x5w3-cgxg/GHSA-j42v-x5w3-cgxg.json b/advisories/unreviewed/2024/12/GHSA-j42v-x5w3-cgxg/GHSA-j42v-x5w3-cgxg.json new file mode 100644 index 00000000000..affcc6ce746 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-j42v-x5w3-cgxg/GHSA-j42v-x5w3-cgxg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j42v-x5w3-cgxg", + "modified": "2024-12-12T03:33:04Z", + "published": "2024-12-12T03:33:04Z", + "aliases": [ + "CVE-2024-49068" + ], + "details": "Microsoft SharePoint Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49068" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49068" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:04:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-j4h9-xpvr-4pqq/GHSA-j4h9-xpvr-4pqq.json b/advisories/unreviewed/2024/12/GHSA-j4h9-xpvr-4pqq/GHSA-j4h9-xpvr-4pqq.json new file mode 100644 index 00000000000..fe3dcf1dce9 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-j4h9-xpvr-4pqq/GHSA-j4h9-xpvr-4pqq.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j4h9-xpvr-4pqq", + "modified": "2024-12-12T03:33:07Z", + "published": "2024-12-12T03:33:07Z", + "aliases": [ + "CVE-2024-54529" + ], + "details": "A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2, macOS Ventura 13.7.2, macOS Sonoma 14.7.2. An app may be able to execute arbitrary code with kernel privileges.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54529" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121839" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121840" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121842" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-j6r2-q88x-5m39/GHSA-j6r2-q88x-5m39.json b/advisories/unreviewed/2024/12/GHSA-j6r2-q88x-5m39/GHSA-j6r2-q88x-5m39.json new file mode 100644 index 00000000000..353a9329db9 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-j6r2-q88x-5m39/GHSA-j6r2-q88x-5m39.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j6r2-q88x-5m39", + "modified": "2024-12-12T03:33:05Z", + "published": "2024-12-12T03:33:05Z", + "aliases": [ + "CVE-2024-49132" + ], + "details": "Windows Remote Desktop Services Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49132" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49132" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:04:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-j7xp-4wpv-jwg6/GHSA-j7xp-4wpv-jwg6.json b/advisories/unreviewed/2024/12/GHSA-j7xp-4wpv-jwg6/GHSA-j7xp-4wpv-jwg6.json new file mode 100644 index 00000000000..f615ce98e82 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-j7xp-4wpv-jwg6/GHSA-j7xp-4wpv-jwg6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j7xp-4wpv-jwg6", + "modified": "2024-12-12T03:33:04Z", + "published": "2024-12-12T03:33:04Z", + "aliases": [ + "CVE-2024-49078" + ], + "details": "Windows Mobile Broadband Driver Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49078" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49078" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:04:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-j885-4693-cqgh/GHSA-j885-4693-cqgh.json b/advisories/unreviewed/2024/12/GHSA-j885-4693-cqgh/GHSA-j885-4693-cqgh.json new file mode 100644 index 00000000000..73c027c4a98 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-j885-4693-cqgh/GHSA-j885-4693-cqgh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j885-4693-cqgh", + "modified": "2024-12-12T03:33:05Z", + "published": "2024-12-12T03:33:05Z", + "aliases": [ + "CVE-2024-49117" + ], + "details": "Windows Hyper-V Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49117" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49117" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-393" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:04:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-j9q2-q6gv-w438/GHSA-j9q2-q6gv-w438.json b/advisories/unreviewed/2024/12/GHSA-j9q2-q6gv-w438/GHSA-j9q2-q6gv-w438.json index bf045223ca8..03cf40d2b1b 100644 --- a/advisories/unreviewed/2024/12/GHSA-j9q2-q6gv-w438/GHSA-j9q2-q6gv-w438.json +++ b/advisories/unreviewed/2024/12/GHSA-j9q2-q6gv-w438/GHSA-j9q2-q6gv-w438.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-j9q2-q6gv-w438", - "modified": "2024-12-10T00:31:26Z", + "modified": "2024-12-12T03:33:01Z", "published": "2024-12-10T00:31:26Z", "aliases": [ "CVE-2024-50626" ], "details": "An issue was discovered in Digi ConnectPort LTS before 1.4.12. A Directory Traversal vulnerability exists in WebFS. This allows an attacker on the local area network to manipulate URLs to include traversal sequences, potentially leading to unauthorized access to data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-09T22:15:22Z" diff --git a/advisories/unreviewed/2024/12/GHSA-jf72-28rf-27vg/GHSA-jf72-28rf-27vg.json b/advisories/unreviewed/2024/12/GHSA-jf72-28rf-27vg/GHSA-jf72-28rf-27vg.json new file mode 100644 index 00000000000..1d4ab4add82 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-jf72-28rf-27vg/GHSA-jf72-28rf-27vg.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jf72-28rf-27vg", + "modified": "2024-12-12T03:33:06Z", + "published": "2024-12-12T03:33:06Z", + "aliases": [ + "CVE-2024-54504" + ], + "details": "A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.2. An app may be able to access user-sensitive data.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54504" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121839" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-jgrc-ph6q-54v7/GHSA-jgrc-ph6q-54v7.json b/advisories/unreviewed/2024/12/GHSA-jgrc-ph6q-54v7/GHSA-jgrc-ph6q-54v7.json new file mode 100644 index 00000000000..4a120f44050 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-jgrc-ph6q-54v7/GHSA-jgrc-ph6q-54v7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jgrc-ph6q-54v7", + "modified": "2024-12-12T03:33:04Z", + "published": "2024-12-12T03:33:04Z", + "aliases": [ + "CVE-2024-49083" + ], + "details": "Windows Mobile Broadband Driver Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49083" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49083" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:04:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-jq63-f9q2-ph96/GHSA-jq63-f9q2-ph96.json b/advisories/unreviewed/2024/12/GHSA-jq63-f9q2-ph96/GHSA-jq63-f9q2-ph96.json index 8e6ca0a1ac8..d99877fb485 100644 --- a/advisories/unreviewed/2024/12/GHSA-jq63-f9q2-ph96/GHSA-jq63-f9q2-ph96.json +++ b/advisories/unreviewed/2024/12/GHSA-jq63-f9q2-ph96/GHSA-jq63-f9q2-ph96.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jq63-f9q2-ph96", - "modified": "2024-12-11T18:30:42Z", + "modified": "2024-12-12T03:33:01Z", "published": "2024-12-11T18:30:42Z", "aliases": [ "CVE-2024-28140" ], "details": "The scanner device boots into a kiosk mode by default and opens the Scan2Net interface in a browser window. This browser is run with the permissions of the root user. There are also several other applications running as root user. This can be confirmed by running \"ps aux\" as the root user and observing the output.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -27,7 +32,7 @@ "cwe_ids": [ "CWE-250" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-11T16:15:10Z" diff --git a/advisories/unreviewed/2024/12/GHSA-jqhv-wqfx-p2mf/GHSA-jqhv-wqfx-p2mf.json b/advisories/unreviewed/2024/12/GHSA-jqhv-wqfx-p2mf/GHSA-jqhv-wqfx-p2mf.json new file mode 100644 index 00000000000..3538421824c --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-jqhv-wqfx-p2mf/GHSA-jqhv-wqfx-p2mf.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jqhv-wqfx-p2mf", + "modified": "2024-12-12T03:33:03Z", + "published": "2024-12-12T03:33:03Z", + "aliases": [ + "CVE-2024-12481" + ], + "details": "A vulnerability was found in cjbi wetech-cms 1.0/1.1/1.2. It has been declared as critical. Affected by this vulnerability is the function findUser of the file wetech-cms-master\\wetech-core\\src\\main\\java\\tech\\wetech\\cms\\dao\\UserDao.java. The manipulation of the argument searchValue/gId/rId leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12481" + }, + { + "type": "WEB", + "url": "https://github.com/hadagaga/vuln/blob/master/wetech-cms/sql-3/SQL_injection_vulnerability.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.287863" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.287863" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.458852" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T01:40:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-jr5x-w373-qc62/GHSA-jr5x-w373-qc62.json b/advisories/unreviewed/2024/12/GHSA-jr5x-w373-qc62/GHSA-jr5x-w373-qc62.json new file mode 100644 index 00000000000..564307e744f --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-jr5x-w373-qc62/GHSA-jr5x-w373-qc62.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jr5x-w373-qc62", + "modified": "2024-12-12T03:33:05Z", + "published": "2024-12-12T03:33:04Z", + "aliases": [ + "CVE-2024-49090" + ], + "details": "Windows Common Log File System Driver Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49090" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49090" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-822" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:04:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-jw8x-5w8f-9hrm/GHSA-jw8x-5w8f-9hrm.json b/advisories/unreviewed/2024/12/GHSA-jw8x-5w8f-9hrm/GHSA-jw8x-5w8f-9hrm.json new file mode 100644 index 00000000000..cb172995b22 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-jw8x-5w8f-9hrm/GHSA-jw8x-5w8f-9hrm.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jw8x-5w8f-9hrm", + "modified": "2024-12-12T03:33:06Z", + "published": "2024-12-12T03:33:06Z", + "aliases": [ + "CVE-2024-54492" + ], + "details": "This issue was addressed by using HTTPS when sending information over the network. This issue is fixed in macOS Sequoia 15.2, iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, visionOS 2.2. An attacker in a privileged network position may be able to alter network traffic.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54492" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121837" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121838" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121839" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121845" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-m5hx-8765-fjpm/GHSA-m5hx-8765-fjpm.json b/advisories/unreviewed/2024/12/GHSA-m5hx-8765-fjpm/GHSA-m5hx-8765-fjpm.json index d53334c9dfe..cd2d4a0050a 100644 --- a/advisories/unreviewed/2024/12/GHSA-m5hx-8765-fjpm/GHSA-m5hx-8765-fjpm.json +++ b/advisories/unreviewed/2024/12/GHSA-m5hx-8765-fjpm/GHSA-m5hx-8765-fjpm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-m5hx-8765-fjpm", - "modified": "2024-12-08T00:31:20Z", + "modified": "2024-12-12T03:33:00Z", "published": "2024-12-08T00:31:20Z", "aliases": [ "CVE-2024-53473" ], "details": "WeGIA 3.2.0 before 3998672 does not verify permission to change a password.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-07T23:15:34Z" diff --git a/advisories/unreviewed/2024/12/GHSA-m5qq-j8mm-vp66/GHSA-m5qq-j8mm-vp66.json b/advisories/unreviewed/2024/12/GHSA-m5qq-j8mm-vp66/GHSA-m5qq-j8mm-vp66.json new file mode 100644 index 00000000000..7b6badf4ad9 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-m5qq-j8mm-vp66/GHSA-m5qq-j8mm-vp66.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m5qq-j8mm-vp66", + "modified": "2024-12-12T03:33:04Z", + "published": "2024-12-12T03:33:04Z", + "aliases": [ + "CVE-2024-49077" + ], + "details": "Windows Mobile Broadband Driver Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49077" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49077" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:04:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-m66h-xc6v-38j2/GHSA-m66h-xc6v-38j2.json b/advisories/unreviewed/2024/12/GHSA-m66h-xc6v-38j2/GHSA-m66h-xc6v-38j2.json new file mode 100644 index 00000000000..ae3f32eec96 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-m66h-xc6v-38j2/GHSA-m66h-xc6v-38j2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m66h-xc6v-38j2", + "modified": "2024-12-12T03:33:05Z", + "published": "2024-12-12T03:33:05Z", + "aliases": [ + "CVE-2024-49122" + ], + "details": "Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49122" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49122" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:04:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-m73x-6gvh-9839/GHSA-m73x-6gvh-9839.json b/advisories/unreviewed/2024/12/GHSA-m73x-6gvh-9839/GHSA-m73x-6gvh-9839.json index 62c2e445e2f..e24f3ea2a73 100644 --- a/advisories/unreviewed/2024/12/GHSA-m73x-6gvh-9839/GHSA-m73x-6gvh-9839.json +++ b/advisories/unreviewed/2024/12/GHSA-m73x-6gvh-9839/GHSA-m73x-6gvh-9839.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-m73x-6gvh-9839", - "modified": "2024-12-07T00:31:04Z", + "modified": "2024-12-12T03:33:00Z", "published": "2024-12-07T00:31:04Z", "aliases": [ "CVE-2024-44855" ], "details": "Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a NULL pointer dereference via the component nav2_navfn_planner().", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-06T22:15:21Z" diff --git a/advisories/unreviewed/2024/12/GHSA-mf5g-58v5-r995/GHSA-mf5g-58v5-r995.json b/advisories/unreviewed/2024/12/GHSA-mf5g-58v5-r995/GHSA-mf5g-58v5-r995.json new file mode 100644 index 00000000000..4df21da05ce --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-mf5g-58v5-r995/GHSA-mf5g-58v5-r995.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mf5g-58v5-r995", + "modified": "2024-12-12T03:33:06Z", + "published": "2024-12-12T03:33:06Z", + "aliases": [ + "CVE-2024-44290" + ], + "details": "This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.1 and iPadOS 18.1, watchOS 11.1. An app may be able to determine a user’s current location.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44290" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121563" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121565" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-mhch-rj8x-4v2p/GHSA-mhch-rj8x-4v2p.json b/advisories/unreviewed/2024/12/GHSA-mhch-rj8x-4v2p/GHSA-mhch-rj8x-4v2p.json new file mode 100644 index 00000000000..7ce257f3c73 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-mhch-rj8x-4v2p/GHSA-mhch-rj8x-4v2p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mhch-rj8x-4v2p", + "modified": "2024-12-12T03:33:05Z", + "published": "2024-12-12T03:33:05Z", + "aliases": [ + "CVE-2024-49129" + ], + "details": "Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49129" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49129" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:04:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-mjq7-g735-3qwr/GHSA-mjq7-g735-3qwr.json b/advisories/unreviewed/2024/12/GHSA-mjq7-g735-3qwr/GHSA-mjq7-g735-3qwr.json new file mode 100644 index 00000000000..753f08b311e --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-mjq7-g735-3qwr/GHSA-mjq7-g735-3qwr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mjq7-g735-3qwr", + "modified": "2024-12-12T03:33:05Z", + "published": "2024-12-12T03:33:04Z", + "aliases": [ + "CVE-2024-49087" + ], + "details": "Windows Mobile Broadband Driver Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49087" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49087" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:04:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-mr3h-f548-mcv9/GHSA-mr3h-f548-mcv9.json b/advisories/unreviewed/2024/12/GHSA-mr3h-f548-mcv9/GHSA-mr3h-f548-mcv9.json new file mode 100644 index 00000000000..97edb7a39f6 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-mr3h-f548-mcv9/GHSA-mr3h-f548-mcv9.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mr3h-f548-mcv9", + "modified": "2024-12-12T03:33:02Z", + "published": "2024-12-12T03:33:02Z", + "aliases": [ + "CVE-2024-11948" + ], + "details": "GFI Archiver Telerik Web UI Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GFI Archiver. Authentication is not required to exploit this vulnerability.\n\nThe specific flaw exists within the product installer. The issue results from the use of a vulnerable version of Telerik Web UI. An attacker can leverage this vulnerability to execute code in the context of NETWORK SERVICE. Was ZDI-CAN-24041.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11948" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1671" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T01:40:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-mxcm-6447-457q/GHSA-mxcm-6447-457q.json b/advisories/unreviewed/2024/12/GHSA-mxcm-6447-457q/GHSA-mxcm-6447-457q.json new file mode 100644 index 00000000000..e448628be23 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-mxcm-6447-457q/GHSA-mxcm-6447-457q.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mxcm-6447-457q", + "modified": "2024-12-12T03:33:01Z", + "published": "2024-12-12T03:33:01Z", + "aliases": [ + "CVE-2024-11872" + ], + "details": "Epic Games Launcher Incorrect Default Permissions Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Epic Games Launcher. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.\n\nThe specific flaw exists within the product installer. The product applies incorrect default permissions to a sensitive folder. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-24329.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11872" + }, + { + "type": "WEB", + "url": "https://trello.com/c/tcS6Jcfy/578-epic-games-launcher-1720" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1646" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-276" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T01:40:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-mxx8-w72q-6w75/GHSA-mxx8-w72q-6w75.json b/advisories/unreviewed/2024/12/GHSA-mxx8-w72q-6w75/GHSA-mxx8-w72q-6w75.json new file mode 100644 index 00000000000..34801ce4c8b --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-mxx8-w72q-6w75/GHSA-mxx8-w72q-6w75.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mxx8-w72q-6w75", + "modified": "2024-12-12T03:33:06Z", + "published": "2024-12-12T03:33:06Z", + "aliases": [ + "CVE-2024-44242" + ], + "details": "The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.1 and iPadOS 18.1. An attacker may be able to cause unexpected system termination or arbitrary code execution in DCP firmware.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44242" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121563" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-p224-82hj-42w3/GHSA-p224-82hj-42w3.json b/advisories/unreviewed/2024/12/GHSA-p224-82hj-42w3/GHSA-p224-82hj-42w3.json new file mode 100644 index 00000000000..cc23569cdf9 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-p224-82hj-42w3/GHSA-p224-82hj-42w3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p224-82hj-42w3", + "modified": "2024-12-12T03:33:04Z", + "published": "2024-12-12T03:33:04Z", + "aliases": [ + "CVE-2024-49075" + ], + "details": "Windows Remote Desktop Services Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49075" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49075" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:04:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-p2gm-hcx7-mr3w/GHSA-p2gm-hcx7-mr3w.json b/advisories/unreviewed/2024/12/GHSA-p2gm-hcx7-mr3w/GHSA-p2gm-hcx7-mr3w.json new file mode 100644 index 00000000000..eb05736f921 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-p2gm-hcx7-mr3w/GHSA-p2gm-hcx7-mr3w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p2gm-hcx7-mr3w", + "modified": "2024-12-12T03:33:02Z", + "published": "2024-12-12T03:33:02Z", + "aliases": [ + "CVE-2024-11949" + ], + "details": "GFI Archiver Store Service Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GFI Archiver. Authentication is required to exploit this vulnerability.\n\nThe specific flaw exists within the Store Service, which listens on TCP port 8018 by default. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-24331.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11949" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1672" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T01:40:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-p342-xvqv-vrrr/GHSA-p342-xvqv-vrrr.json b/advisories/unreviewed/2024/12/GHSA-p342-xvqv-vrrr/GHSA-p342-xvqv-vrrr.json new file mode 100644 index 00000000000..dd0ad9c5f3c --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-p342-xvqv-vrrr/GHSA-p342-xvqv-vrrr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p342-xvqv-vrrr", + "modified": "2024-12-12T03:33:05Z", + "published": "2024-12-12T03:33:05Z", + "aliases": [ + "CVE-2024-49101" + ], + "details": "Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49101" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49101" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:04:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-p5wj-x33c-f49r/GHSA-p5wj-x33c-f49r.json b/advisories/unreviewed/2024/12/GHSA-p5wj-x33c-f49r/GHSA-p5wj-x33c-f49r.json index ec18f0e2f7b..d7fd8a4e5df 100644 --- a/advisories/unreviewed/2024/12/GHSA-p5wj-x33c-f49r/GHSA-p5wj-x33c-f49r.json +++ b/advisories/unreviewed/2024/12/GHSA-p5wj-x33c-f49r/GHSA-p5wj-x33c-f49r.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p5wj-x33c-f49r", - "modified": "2024-12-07T00:31:03Z", + "modified": "2024-12-12T03:32:59Z", "published": "2024-12-07T00:31:03Z", "aliases": [ "CVE-2024-38926" ], "details": "Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered via remotely sending a request for change the value of dynamic-parameter `/amcl z_short`.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-06T22:15:20Z" diff --git a/advisories/unreviewed/2024/12/GHSA-p6qw-9qh6-cc5x/GHSA-p6qw-9qh6-cc5x.json b/advisories/unreviewed/2024/12/GHSA-p6qw-9qh6-cc5x/GHSA-p6qw-9qh6-cc5x.json new file mode 100644 index 00000000000..0cbbbb923b2 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-p6qw-9qh6-cc5x/GHSA-p6qw-9qh6-cc5x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p6qw-9qh6-cc5x", + "modified": "2024-12-12T03:33:05Z", + "published": "2024-12-12T03:33:05Z", + "aliases": [ + "CVE-2024-49119" + ], + "details": "Windows Remote Desktop Services Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49119" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49119" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-843" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:04:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-p964-4w2r-7927/GHSA-p964-4w2r-7927.json b/advisories/unreviewed/2024/12/GHSA-p964-4w2r-7927/GHSA-p964-4w2r-7927.json new file mode 100644 index 00000000000..cdeff62c746 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-p964-4w2r-7927/GHSA-p964-4w2r-7927.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p964-4w2r-7927", + "modified": "2024-12-12T03:33:06Z", + "published": "2024-12-12T03:33:06Z", + "aliases": [ + "CVE-2024-12503" + ], + "details": "A vulnerability classified as problematic was found in ClassCMS 4.8. Affected by this vulnerability is an unknown functionality of the file /index.php/admin of the component Model Management Page. The manipulation of the argument URL leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12503" + }, + { + "type": "WEB", + "url": "https://github.com/Jack-Black-13/blob/blob/main/classCMS_v4.8_model_xss.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.287875" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.287875" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.461085" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-p98j-34x2-jg46/GHSA-p98j-34x2-jg46.json b/advisories/unreviewed/2024/12/GHSA-p98j-34x2-jg46/GHSA-p98j-34x2-jg46.json new file mode 100644 index 00000000000..dc268cb1c52 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-p98j-34x2-jg46/GHSA-p98j-34x2-jg46.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p98j-34x2-jg46", + "modified": "2024-12-12T03:33:06Z", + "published": "2024-12-12T03:33:06Z", + "aliases": [ + "CVE-2024-44299" + ], + "details": "The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.1 and iPadOS 18.1. An attacker may be able to cause unexpected system termination or arbitrary code execution in DCP firmware.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44299" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121563" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-pp8g-vm2j-rjp3/GHSA-pp8g-vm2j-rjp3.json b/advisories/unreviewed/2024/12/GHSA-pp8g-vm2j-rjp3/GHSA-pp8g-vm2j-rjp3.json new file mode 100644 index 00000000000..49ec682583e --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-pp8g-vm2j-rjp3/GHSA-pp8g-vm2j-rjp3.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pp8g-vm2j-rjp3", + "modified": "2024-12-12T03:33:03Z", + "published": "2024-12-12T03:33:03Z", + "aliases": [ + "CVE-2024-12382" + ], + "details": "Use after free in Translate in Google Chrome prior to 131.0.6778.139 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12382" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/12/stable-channel-update-for-desktop_10.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/379516109" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T01:40:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-prcg-7jgp-2h92/GHSA-prcg-7jgp-2h92.json b/advisories/unreviewed/2024/12/GHSA-prcg-7jgp-2h92/GHSA-prcg-7jgp-2h92.json new file mode 100644 index 00000000000..aa48f4b89bb --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-prcg-7jgp-2h92/GHSA-prcg-7jgp-2h92.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-prcg-7jgp-2h92", + "modified": "2024-12-12T03:33:05Z", + "published": "2024-12-12T03:33:05Z", + "aliases": [ + "CVE-2024-49098" + ], + "details": "Windows Wireless Wide Area Network Service (WwanSvc) Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49098" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49098" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:04:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-prrv-2g69-29hw/GHSA-prrv-2g69-29hw.json b/advisories/unreviewed/2024/12/GHSA-prrv-2g69-29hw/GHSA-prrv-2g69-29hw.json new file mode 100644 index 00000000000..ebbc497c758 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-prrv-2g69-29hw/GHSA-prrv-2g69-29hw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-prrv-2g69-29hw", + "modified": "2024-12-12T03:33:05Z", + "published": "2024-12-12T03:33:05Z", + "aliases": [ + "CVE-2024-49125" + ], + "details": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49125" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49125" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:04:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-pvhv-2w8w-pf3x/GHSA-pvhv-2w8w-pf3x.json b/advisories/unreviewed/2024/12/GHSA-pvhv-2w8w-pf3x/GHSA-pvhv-2w8w-pf3x.json new file mode 100644 index 00000000000..45e7ed5c6c3 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-pvhv-2w8w-pf3x/GHSA-pvhv-2w8w-pf3x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pvhv-2w8w-pf3x", + "modified": "2024-12-12T03:33:05Z", + "published": "2024-12-12T03:33:05Z", + "aliases": [ + "CVE-2024-49106" + ], + "details": "Windows Remote Desktop Services Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49106" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49106" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:04:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-px3q-m266-8w5r/GHSA-px3q-m266-8w5r.json b/advisories/unreviewed/2024/12/GHSA-px3q-m266-8w5r/GHSA-px3q-m266-8w5r.json index 5f920ca58f9..a531a065147 100644 --- a/advisories/unreviewed/2024/12/GHSA-px3q-m266-8w5r/GHSA-px3q-m266-8w5r.json +++ b/advisories/unreviewed/2024/12/GHSA-px3q-m266-8w5r/GHSA-px3q-m266-8w5r.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-px3q-m266-8w5r", - "modified": "2024-12-09T18:31:19Z", + "modified": "2024-12-12T03:33:00Z", "published": "2024-12-09T18:31:19Z", "aliases": [ "CVE-2023-43962" ], "details": "Cross Site Scripting vulnerability in Xunrui CMS Public Edition v.4.6.1 allows a remote attacker to execute arbitrary code via the project name function in the project settings tab.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-09T17:15:06Z" diff --git a/advisories/unreviewed/2024/12/GHSA-px56-8cj3-6h4p/GHSA-px56-8cj3-6h4p.json b/advisories/unreviewed/2024/12/GHSA-px56-8cj3-6h4p/GHSA-px56-8cj3-6h4p.json index 77e14e5ad1a..ae271f17701 100644 --- a/advisories/unreviewed/2024/12/GHSA-px56-8cj3-6h4p/GHSA-px56-8cj3-6h4p.json +++ b/advisories/unreviewed/2024/12/GHSA-px56-8cj3-6h4p/GHSA-px56-8cj3-6h4p.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-px56-8cj3-6h4p", - "modified": "2024-12-07T00:31:03Z", + "modified": "2024-12-12T03:32:59Z", "published": "2024-12-07T00:31:03Z", "aliases": [ "CVE-2024-38922" ], "details": "Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble version was discovered to contain a heap overflow in the nav2_amcl process. This vulnerability is triggered via sending a crafted message to the component /initialpose.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-06T22:15:19Z" diff --git a/advisories/unreviewed/2024/12/GHSA-pxqf-jg9m-j88f/GHSA-pxqf-jg9m-j88f.json b/advisories/unreviewed/2024/12/GHSA-pxqf-jg9m-j88f/GHSA-pxqf-jg9m-j88f.json index 2ea1af5f255..a8e19af2b51 100644 --- a/advisories/unreviewed/2024/12/GHSA-pxqf-jg9m-j88f/GHSA-pxqf-jg9m-j88f.json +++ b/advisories/unreviewed/2024/12/GHSA-pxqf-jg9m-j88f/GHSA-pxqf-jg9m-j88f.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pxqf-jg9m-j88f", - "modified": "2024-12-07T00:31:03Z", + "modified": "2024-12-12T03:32:59Z", "published": "2024-12-07T00:31:03Z", "aliases": [ "CVE-2024-41644" ], "details": "Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via the dyn_param_handler_ component.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-281" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-06T22:15:20Z" diff --git a/advisories/unreviewed/2024/12/GHSA-pxw4-6qw4-jp6w/GHSA-pxw4-6qw4-jp6w.json b/advisories/unreviewed/2024/12/GHSA-pxw4-6qw4-jp6w/GHSA-pxw4-6qw4-jp6w.json new file mode 100644 index 00000000000..bf4cb3674d6 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-pxw4-6qw4-jp6w/GHSA-pxw4-6qw4-jp6w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pxw4-6qw4-jp6w", + "modified": "2024-12-12T03:33:05Z", + "published": "2024-12-12T03:33:05Z", + "aliases": [ + "CVE-2024-49095" + ], + "details": "Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49095" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49095" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-415" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:04:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-q28c-38vj-q7m2/GHSA-q28c-38vj-q7m2.json b/advisories/unreviewed/2024/12/GHSA-q28c-38vj-q7m2/GHSA-q28c-38vj-q7m2.json index 80bbb61adbe..a34b99674ce 100644 --- a/advisories/unreviewed/2024/12/GHSA-q28c-38vj-q7m2/GHSA-q28c-38vj-q7m2.json +++ b/advisories/unreviewed/2024/12/GHSA-q28c-38vj-q7m2/GHSA-q28c-38vj-q7m2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-q28c-38vj-q7m2", - "modified": "2024-12-07T00:31:04Z", + "modified": "2024-12-12T03:33:00Z", "published": "2024-12-07T00:31:04Z", "aliases": [ "CVE-2024-44854" ], "details": "Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a NULL pointer dereference via the component smoothPlan().", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-06T22:15:21Z" diff --git a/advisories/unreviewed/2024/12/GHSA-q39m-4pxm-4x89/GHSA-q39m-4pxm-4x89.json b/advisories/unreviewed/2024/12/GHSA-q39m-4pxm-4x89/GHSA-q39m-4pxm-4x89.json new file mode 100644 index 00000000000..27c472a438f --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-q39m-4pxm-4x89/GHSA-q39m-4pxm-4x89.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q39m-4pxm-4x89", + "modified": "2024-12-12T03:33:05Z", + "published": "2024-12-12T03:33:05Z", + "aliases": [ + "CVE-2024-49111" + ], + "details": "Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49111" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49111" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:04:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-q5hq-6qcp-phr8/GHSA-q5hq-6qcp-phr8.json b/advisories/unreviewed/2024/12/GHSA-q5hq-6qcp-phr8/GHSA-q5hq-6qcp-phr8.json new file mode 100644 index 00000000000..6716d2ada99 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-q5hq-6qcp-phr8/GHSA-q5hq-6qcp-phr8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q5hq-6qcp-phr8", + "modified": "2024-12-12T03:33:05Z", + "published": "2024-12-12T03:33:05Z", + "aliases": [ + "CVE-2024-49123" + ], + "details": "Windows Remote Desktop Services Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49123" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49123" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-591" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:04:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-q7qj-rx6w-8pxw/GHSA-q7qj-rx6w-8pxw.json b/advisories/unreviewed/2024/12/GHSA-q7qj-rx6w-8pxw/GHSA-q7qj-rx6w-8pxw.json new file mode 100644 index 00000000000..4fcee78abbc --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-q7qj-rx6w-8pxw/GHSA-q7qj-rx6w-8pxw.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q7qj-rx6w-8pxw", + "modified": "2024-12-12T03:33:06Z", + "published": "2024-12-12T03:33:06Z", + "aliases": [ + "CVE-2024-54494" + ], + "details": "A race condition was addressed with additional validation. This issue is fixed in iPadOS 17.7.3, watchOS 11.2, visionOS 2.2, tvOS 18.2, macOS Sequoia 15.2, iOS 18.2 and iPadOS 18.2, macOS Ventura 13.7.2, macOS Sonoma 14.7.2. An attacker may be able to create a read-only memory mapping that can be written to.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54494" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121837" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121838" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121839" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121840" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121842" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121843" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121844" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121845" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-qc6f-gvhw-rjrj/GHSA-qc6f-gvhw-rjrj.json b/advisories/unreviewed/2024/12/GHSA-qc6f-gvhw-rjrj/GHSA-qc6f-gvhw-rjrj.json new file mode 100644 index 00000000000..f94da012816 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-qc6f-gvhw-rjrj/GHSA-qc6f-gvhw-rjrj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qc6f-gvhw-rjrj", + "modified": "2024-12-12T03:33:04Z", + "published": "2024-12-12T03:33:04Z", + "aliases": [ + "CVE-2024-49057" + ], + "details": "Microsoft Defender for Endpoint on Android Spoofing Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49057" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49057" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:04:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-qfp8-pvg8-2xph/GHSA-qfp8-pvg8-2xph.json b/advisories/unreviewed/2024/12/GHSA-qfp8-pvg8-2xph/GHSA-qfp8-pvg8-2xph.json new file mode 100644 index 00000000000..d9c0946c81c --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-qfp8-pvg8-2xph/GHSA-qfp8-pvg8-2xph.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qfp8-pvg8-2xph", + "modified": "2024-12-12T03:33:06Z", + "published": "2024-12-12T03:33:06Z", + "aliases": [ + "CVE-2024-54505" + ], + "details": "A type confusion issue was addressed with improved memory handling. This issue is fixed in iPadOS 17.7.3, watchOS 11.2, visionOS 2.2, tvOS 18.2, macOS Sequoia 15.2, Safari 18.2, iOS 18.2 and iPadOS 18.2. Processing maliciously crafted web content may lead to memory corruption.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54505" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121837" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121838" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121839" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121843" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121844" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121845" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121846" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-qgrj-p6f4-pxj8/GHSA-qgrj-p6f4-pxj8.json b/advisories/unreviewed/2024/12/GHSA-qgrj-p6f4-pxj8/GHSA-qgrj-p6f4-pxj8.json new file mode 100644 index 00000000000..e4f8bb59317 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-qgrj-p6f4-pxj8/GHSA-qgrj-p6f4-pxj8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qgrj-p6f4-pxj8", + "modified": "2024-12-12T03:33:05Z", + "published": "2024-12-12T03:33:05Z", + "aliases": [ + "CVE-2024-49127" + ], + "details": "Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49127" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49127" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:04:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-qwqw-c822-4wr8/GHSA-qwqw-c822-4wr8.json b/advisories/unreviewed/2024/12/GHSA-qwqw-c822-4wr8/GHSA-qwqw-c822-4wr8.json new file mode 100644 index 00000000000..539bbac3ebf --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-qwqw-c822-4wr8/GHSA-qwqw-c822-4wr8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qwqw-c822-4wr8", + "modified": "2024-12-12T03:33:05Z", + "published": "2024-12-12T03:33:05Z", + "aliases": [ + "CVE-2024-49099" + ], + "details": "Windows Wireless Wide Area Network Service (WwanSvc) Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49099" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49099" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:04:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-r3pw-h574-jpr4/GHSA-r3pw-h574-jpr4.json b/advisories/unreviewed/2024/12/GHSA-r3pw-h574-jpr4/GHSA-r3pw-h574-jpr4.json new file mode 100644 index 00000000000..1d4b0fc334a --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-r3pw-h574-jpr4/GHSA-r3pw-h574-jpr4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r3pw-h574-jpr4", + "modified": "2024-12-12T03:33:05Z", + "published": "2024-12-12T03:33:04Z", + "aliases": [ + "CVE-2024-49092" + ], + "details": "Windows Mobile Broadband Driver Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49092" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49092" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:04:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-rcvw-67j5-hc25/GHSA-rcvw-67j5-hc25.json b/advisories/unreviewed/2024/12/GHSA-rcvw-67j5-hc25/GHSA-rcvw-67j5-hc25.json index 70252beb9be..a235ec6bf51 100644 --- a/advisories/unreviewed/2024/12/GHSA-rcvw-67j5-hc25/GHSA-rcvw-67j5-hc25.json +++ b/advisories/unreviewed/2024/12/GHSA-rcvw-67j5-hc25/GHSA-rcvw-67j5-hc25.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rcvw-67j5-hc25", - "modified": "2024-12-07T00:31:03Z", + "modified": "2024-12-12T03:33:00Z", "published": "2024-12-07T00:31:03Z", "aliases": [ "CVE-2024-41646" ], "details": "Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2_dwb_controller.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-281" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-06T22:15:20Z" diff --git a/advisories/unreviewed/2024/12/GHSA-rf45-5qvx-8pc5/GHSA-rf45-5qvx-8pc5.json b/advisories/unreviewed/2024/12/GHSA-rf45-5qvx-8pc5/GHSA-rf45-5qvx-8pc5.json new file mode 100644 index 00000000000..e1bcde09506 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-rf45-5qvx-8pc5/GHSA-rf45-5qvx-8pc5.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rf45-5qvx-8pc5", + "modified": "2024-12-12T03:33:03Z", + "published": "2024-12-12T03:33:03Z", + "aliases": [ + "CVE-2024-12482" + ], + "details": "A vulnerability was found in cjbi wetech-cms 1.0/1.1/1.2. It has been rated as problematic. Affected by this issue is the function backup of the file wetech-cms-master\\wetech-basic-common\\src\\main\\java\\tech\\wetech\\basic\\util\\BackupFileUtil.java of the component Database Backup Handler. The manipulation of the argument name leads to path traversal: '../filedir'. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12482" + }, + { + "type": "WEB", + "url": "https://github.com/hadagaga/vuln/blob/master/wetech-cms/Catalog_penetration/Catalog_penetration.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.287864" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.287864" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.458853" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-23" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T01:40:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-rj73-rm78-8mx4/GHSA-rj73-rm78-8mx4.json b/advisories/unreviewed/2024/12/GHSA-rj73-rm78-8mx4/GHSA-rj73-rm78-8mx4.json index bce63f3bc39..ea8733210e8 100644 --- a/advisories/unreviewed/2024/12/GHSA-rj73-rm78-8mx4/GHSA-rj73-rm78-8mx4.json +++ b/advisories/unreviewed/2024/12/GHSA-rj73-rm78-8mx4/GHSA-rj73-rm78-8mx4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rj73-rm78-8mx4", - "modified": "2024-12-07T00:31:03Z", + "modified": "2024-12-12T03:33:00Z", "published": "2024-12-07T00:31:03Z", "aliases": [ "CVE-2024-41650" ], "details": "Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2_costmap_2d.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-281" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-06T22:15:21Z" diff --git a/advisories/unreviewed/2024/12/GHSA-rmh8-223g-x64m/GHSA-rmh8-223g-x64m.json b/advisories/unreviewed/2024/12/GHSA-rmh8-223g-x64m/GHSA-rmh8-223g-x64m.json new file mode 100644 index 00000000000..056bb394c29 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-rmh8-223g-x64m/GHSA-rmh8-223g-x64m.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rmh8-223g-x64m", + "modified": "2024-12-12T03:33:06Z", + "published": "2024-12-12T03:33:06Z", + "aliases": [ + "CVE-2024-54500" + ], + "details": "The issue was addressed with improved checks. This issue is fixed in iPadOS 17.7.3, watchOS 11.2, visionOS 2.2, tvOS 18.2, macOS Sequoia 15.2, iOS 18.2 and iPadOS 18.2, macOS Ventura 13.7.2, macOS Sonoma 14.7.2. Processing a maliciously crafted image may result in disclosure of process memory.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54500" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121837" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121838" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121839" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121840" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121842" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121843" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121844" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121845" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-rq2m-fjrh-fqx7/GHSA-rq2m-fjrh-fqx7.json b/advisories/unreviewed/2024/12/GHSA-rq2m-fjrh-fqx7/GHSA-rq2m-fjrh-fqx7.json new file mode 100644 index 00000000000..86d389163fd --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-rq2m-fjrh-fqx7/GHSA-rq2m-fjrh-fqx7.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rq2m-fjrh-fqx7", + "modified": "2024-12-12T03:33:06Z", + "published": "2024-12-12T03:33:06Z", + "aliases": [ + "CVE-2024-54508" + ], + "details": "The issue was addressed with improved memory handling. This issue is fixed in watchOS 11.2, visionOS 2.2, tvOS 18.2, macOS Sequoia 15.2, Safari 18.2, iOS 18.2 and iPadOS 18.2. Processing maliciously crafted web content may lead to an unexpected process crash.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54508" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121837" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121839" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121843" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121844" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121845" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121846" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-v2gg-jq7f-8425/GHSA-v2gg-jq7f-8425.json b/advisories/unreviewed/2024/12/GHSA-v2gg-jq7f-8425/GHSA-v2gg-jq7f-8425.json new file mode 100644 index 00000000000..36af96c007d --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-v2gg-jq7f-8425/GHSA-v2gg-jq7f-8425.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v2gg-jq7f-8425", + "modified": "2024-12-12T03:33:06Z", + "published": "2024-12-12T03:33:06Z", + "aliases": [ + "CVE-2024-44300" + ], + "details": "A logic issue was addressed with improved file handling. This issue is fixed in macOS Sequoia 15.2, macOS Ventura 13.7.2, macOS Sonoma 14.7.2. An app may be able to access protected user data.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44300" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121839" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121840" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121842" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-v3v5-mr33-c4hg/GHSA-v3v5-mr33-c4hg.json b/advisories/unreviewed/2024/12/GHSA-v3v5-mr33-c4hg/GHSA-v3v5-mr33-c4hg.json index 0c1de8e771d..aea530e44e4 100644 --- a/advisories/unreviewed/2024/12/GHSA-v3v5-mr33-c4hg/GHSA-v3v5-mr33-c4hg.json +++ b/advisories/unreviewed/2024/12/GHSA-v3v5-mr33-c4hg/GHSA-v3v5-mr33-c4hg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-v3v5-mr33-c4hg", - "modified": "2024-12-10T21:30:52Z", + "modified": "2024-12-12T03:33:01Z", "published": "2024-12-10T21:30:52Z", "aliases": [ "CVE-2024-50921" ], "details": "Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to cause a Denial of Service (DoS) via repeatedly sending crafted packets to the controller.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-281" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-10T19:15:30Z" diff --git a/advisories/unreviewed/2024/12/GHSA-v5p3-66g2-2879/GHSA-v5p3-66g2-2879.json b/advisories/unreviewed/2024/12/GHSA-v5p3-66g2-2879/GHSA-v5p3-66g2-2879.json new file mode 100644 index 00000000000..62460fcf2d8 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-v5p3-66g2-2879/GHSA-v5p3-66g2-2879.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v5p3-66g2-2879", + "modified": "2024-12-12T03:33:04Z", + "published": "2024-12-12T03:33:04Z", + "aliases": [ + "CVE-2024-49084" + ], + "details": "Windows Kernel Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49084" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49084" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-362" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:04:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-v8gj-rjxc-h27w/GHSA-v8gj-rjxc-h27w.json b/advisories/unreviewed/2024/12/GHSA-v8gj-rjxc-h27w/GHSA-v8gj-rjxc-h27w.json new file mode 100644 index 00000000000..23f138974bf --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-v8gj-rjxc-h27w/GHSA-v8gj-rjxc-h27w.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v8gj-rjxc-h27w", + "modified": "2024-12-12T03:33:03Z", + "published": "2024-12-12T03:33:03Z", + "aliases": [ + "CVE-2024-12483" + ], + "details": "A vulnerability classified as problematic has been found in Dromara UJCMS up to 9.6.3. This affects an unknown part of the file /users/id of the component User ID Handler. The manipulation leads to authorization bypass. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12483" + }, + { + "type": "WEB", + "url": "https://github.com/cydtseng/Vulnerability-Research/blob/main/ujcms/IDOR-UsernameEnumeration.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.287865" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.287865" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.458895" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-285" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T01:40:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-v8xr-q4f3-9wmf/GHSA-v8xr-q4f3-9wmf.json b/advisories/unreviewed/2024/12/GHSA-v8xr-q4f3-9wmf/GHSA-v8xr-q4f3-9wmf.json new file mode 100644 index 00000000000..e0b2f25fc2f --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-v8xr-q4f3-9wmf/GHSA-v8xr-q4f3-9wmf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v8xr-q4f3-9wmf", + "modified": "2024-12-12T03:33:05Z", + "published": "2024-12-12T03:33:05Z", + "aliases": [ + "CVE-2024-49110" + ], + "details": "Windows Mobile Broadband Driver Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49110" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49110" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:04:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-v9c2-w942-7r95/GHSA-v9c2-w942-7r95.json b/advisories/unreviewed/2024/12/GHSA-v9c2-w942-7r95/GHSA-v9c2-w942-7r95.json new file mode 100644 index 00000000000..6bca853a5c4 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-v9c2-w942-7r95/GHSA-v9c2-w942-7r95.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v9c2-w942-7r95", + "modified": "2024-12-12T03:33:06Z", + "published": "2024-12-12T03:33:06Z", + "aliases": [ + "CVE-2024-54490" + ], + "details": "This issue was addressed by enabling hardened runtime. This issue is fixed in macOS Sequoia 15.2. A local attacker may gain access to user's Keychain items.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54490" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121839" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-vc4g-w5wr-85hv/GHSA-vc4g-w5wr-85hv.json b/advisories/unreviewed/2024/12/GHSA-vc4g-w5wr-85hv/GHSA-vc4g-w5wr-85hv.json new file mode 100644 index 00000000000..603141fc2c3 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-vc4g-w5wr-85hv/GHSA-vc4g-w5wr-85hv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vc4g-w5wr-85hv", + "modified": "2024-12-12T03:33:04Z", + "published": "2024-12-12T03:33:04Z", + "aliases": [ + "CVE-2024-49086" + ], + "details": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49086" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49086" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:04:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-vgp8-265x-9xj2/GHSA-vgp8-265x-9xj2.json b/advisories/unreviewed/2024/12/GHSA-vgp8-265x-9xj2/GHSA-vgp8-265x-9xj2.json new file mode 100644 index 00000000000..c0869bf0d06 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-vgp8-265x-9xj2/GHSA-vgp8-265x-9xj2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vgp8-265x-9xj2", + "modified": "2024-12-12T03:33:05Z", + "published": "2024-12-12T03:33:05Z", + "aliases": [ + "CVE-2024-49115" + ], + "details": "Windows Remote Desktop Services Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49115" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49115" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:04:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-vpj9-v2pp-24wp/GHSA-vpj9-v2pp-24wp.json b/advisories/unreviewed/2024/12/GHSA-vpj9-v2pp-24wp/GHSA-vpj9-v2pp-24wp.json new file mode 100644 index 00000000000..33fc3dc4757 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-vpj9-v2pp-24wp/GHSA-vpj9-v2pp-24wp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vpj9-v2pp-24wp", + "modified": "2024-12-12T03:33:05Z", + "published": "2024-12-12T03:33:05Z", + "aliases": [ + "CVE-2024-49097" + ], + "details": "Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49097" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49097" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:04:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-vr29-w5cg-q4xv/GHSA-vr29-w5cg-q4xv.json b/advisories/unreviewed/2024/12/GHSA-vr29-w5cg-q4xv/GHSA-vr29-w5cg-q4xv.json index 6ebc7924fe6..f358f95062c 100644 --- a/advisories/unreviewed/2024/12/GHSA-vr29-w5cg-q4xv/GHSA-vr29-w5cg-q4xv.json +++ b/advisories/unreviewed/2024/12/GHSA-vr29-w5cg-q4xv/GHSA-vr29-w5cg-q4xv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vr29-w5cg-q4xv", - "modified": "2024-12-07T00:31:04Z", + "modified": "2024-12-12T03:33:00Z", "published": "2024-12-07T00:31:04Z", "aliases": [ "CVE-2024-44853" ], "details": "Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a NULL pointer dereference via the component computeControl().", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-06T22:15:21Z" diff --git a/advisories/unreviewed/2024/12/GHSA-w4gc-9x8j-9hjv/GHSA-w4gc-9x8j-9hjv.json b/advisories/unreviewed/2024/12/GHSA-w4gc-9x8j-9hjv/GHSA-w4gc-9x8j-9hjv.json new file mode 100644 index 00000000000..6469c666928 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-w4gc-9x8j-9hjv/GHSA-w4gc-9x8j-9hjv.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w4gc-9x8j-9hjv", + "modified": "2024-12-12T03:33:03Z", + "published": "2024-12-12T03:33:03Z", + "aliases": [ + "CVE-2024-42448" + ], + "details": "From the VSPC management agent machine, under condition that the management agent is authorized on the server, it is possible to perform Remote Code Execution (RCE) on the VSPC server machine.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42448" + }, + { + "type": "WEB", + "url": "https://www.veeam.com/kb4679" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T01:59:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-w5q3-762f-g235/GHSA-w5q3-762f-g235.json b/advisories/unreviewed/2024/12/GHSA-w5q3-762f-g235/GHSA-w5q3-762f-g235.json new file mode 100644 index 00000000000..8f2bab88399 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-w5q3-762f-g235/GHSA-w5q3-762f-g235.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w5q3-762f-g235", + "modified": "2024-12-12T03:33:06Z", + "published": "2024-12-12T03:33:06Z", + "aliases": [ + "CVE-2024-54476" + ], + "details": "The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2, macOS Ventura 13.7.2, macOS Sonoma 14.7.2. An app may be able to access user-sensitive data.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54476" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121839" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121840" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121842" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-w64q-ccr3-358g/GHSA-w64q-ccr3-358g.json b/advisories/unreviewed/2024/12/GHSA-w64q-ccr3-358g/GHSA-w64q-ccr3-358g.json new file mode 100644 index 00000000000..d26dc4308ab --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-w64q-ccr3-358g/GHSA-w64q-ccr3-358g.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w64q-ccr3-358g", + "modified": "2024-12-12T03:33:06Z", + "published": "2024-12-12T03:33:06Z", + "aliases": [ + "CVE-2024-54502" + ], + "details": "The issue was addressed with improved checks. This issue is fixed in watchOS 11.2, visionOS 2.2, tvOS 18.2, macOS Sequoia 15.2, Safari 18.2, iOS 18.2 and iPadOS 18.2. Processing maliciously crafted web content may lead to an unexpected process crash.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54502" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121837" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121839" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121843" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121844" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121845" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121846" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-w784-x6v6-q82v/GHSA-w784-x6v6-q82v.json b/advisories/unreviewed/2024/12/GHSA-w784-x6v6-q82v/GHSA-w784-x6v6-q82v.json new file mode 100644 index 00000000000..60609d7adfc --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-w784-x6v6-q82v/GHSA-w784-x6v6-q82v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w784-x6v6-q82v", + "modified": "2024-12-12T03:33:05Z", + "published": "2024-12-12T03:33:05Z", + "aliases": [ + "CVE-2024-49089" + ], + "details": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49089" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49089" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:04:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-w7rc-39gw-qjww/GHSA-w7rc-39gw-qjww.json b/advisories/unreviewed/2024/12/GHSA-w7rc-39gw-qjww/GHSA-w7rc-39gw-qjww.json new file mode 100644 index 00000000000..daf8dca98a7 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-w7rc-39gw-qjww/GHSA-w7rc-39gw-qjww.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w7rc-39gw-qjww", + "modified": "2024-12-12T03:33:06Z", + "published": "2024-12-12T03:33:06Z", + "aliases": [ + "CVE-2024-54485" + ], + "details": "The issue was addressed by adding additional logic. This issue is fixed in iPadOS 17.7.3, iOS 18.2 and iPadOS 18.2. An attacker with physical access to an iOS device may be able to view notification content from the lock screen.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54485" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121837" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121838" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-w7xj-7rf9-cg4x/GHSA-w7xj-7rf9-cg4x.json b/advisories/unreviewed/2024/12/GHSA-w7xj-7rf9-cg4x/GHSA-w7xj-7rf9-cg4x.json index dc1fc7b17ad..5b3b3bca077 100644 --- a/advisories/unreviewed/2024/12/GHSA-w7xj-7rf9-cg4x/GHSA-w7xj-7rf9-cg4x.json +++ b/advisories/unreviewed/2024/12/GHSA-w7xj-7rf9-cg4x/GHSA-w7xj-7rf9-cg4x.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-w7xj-7rf9-cg4x", - "modified": "2024-12-04T18:32:37Z", + "modified": "2024-12-12T03:32:59Z", "published": "2024-12-04T18:32:37Z", "aliases": [ "CVE-2024-48453" ], "details": "An issue in INOVANCE AM401_CPU1608TPTN allows a remote attacker to execute arbitrary code via the ExecuteUserProgramUpgrade function", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-04T18:15:14Z" diff --git a/advisories/unreviewed/2024/12/GHSA-wc8w-wrjj-mvq9/GHSA-wc8w-wrjj-mvq9.json b/advisories/unreviewed/2024/12/GHSA-wc8w-wrjj-mvq9/GHSA-wc8w-wrjj-mvq9.json index caad8f7725b..dfc50e972ca 100644 --- a/advisories/unreviewed/2024/12/GHSA-wc8w-wrjj-mvq9/GHSA-wc8w-wrjj-mvq9.json +++ b/advisories/unreviewed/2024/12/GHSA-wc8w-wrjj-mvq9/GHSA-wc8w-wrjj-mvq9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wc8w-wrjj-mvq9", - "modified": "2024-12-10T21:30:52Z", + "modified": "2024-12-12T03:33:01Z", "published": "2024-12-10T21:30:52Z", "aliases": [ "CVE-2024-50930" ], "details": "An issue in Silicon Labs Z-Wave Series 500 v6.84.0 allows attackers to execute arbitrary code.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-281" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-10T19:15:30Z" diff --git a/advisories/unreviewed/2024/12/GHSA-wcqr-6gj6-96wc/GHSA-wcqr-6gj6-96wc.json b/advisories/unreviewed/2024/12/GHSA-wcqr-6gj6-96wc/GHSA-wcqr-6gj6-96wc.json new file mode 100644 index 00000000000..98e81436323 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-wcqr-6gj6-96wc/GHSA-wcqr-6gj6-96wc.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wcqr-6gj6-96wc", + "modified": "2024-12-12T03:33:06Z", + "published": "2024-12-12T03:33:06Z", + "aliases": [ + "CVE-2024-54495" + ], + "details": "The issue was addressed with improved permissions logic. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2. An app may be able to modify protected parts of the file system.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54495" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121839" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121840" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-wj3x-pcf8-r7qm/GHSA-wj3x-pcf8-r7qm.json b/advisories/unreviewed/2024/12/GHSA-wj3x-pcf8-r7qm/GHSA-wj3x-pcf8-r7qm.json new file mode 100644 index 00000000000..8d0160e6d3e --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-wj3x-pcf8-r7qm/GHSA-wj3x-pcf8-r7qm.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wj3x-pcf8-r7qm", + "modified": "2024-12-12T03:33:06Z", + "published": "2024-12-12T03:33:06Z", + "aliases": [ + "CVE-2024-54486" + ], + "details": "The issue was addressed with improved checks. This issue is fixed in iPadOS 17.7.3, watchOS 11.2, visionOS 2.2, tvOS 18.2, macOS Sequoia 15.2, iOS 18.2 and iPadOS 18.2, macOS Ventura 13.7.2, macOS Sonoma 14.7.2. Processing a maliciously crafted font may result in the disclosure of process memory.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54486" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121837" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121838" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121839" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121840" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121842" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121843" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121844" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121845" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-wj49-p585-9263/GHSA-wj49-p585-9263.json b/advisories/unreviewed/2024/12/GHSA-wj49-p585-9263/GHSA-wj49-p585-9263.json new file mode 100644 index 00000000000..37dee1ec886 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-wj49-p585-9263/GHSA-wj49-p585-9263.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wj49-p585-9263", + "modified": "2024-12-12T03:33:06Z", + "published": "2024-12-12T03:33:06Z", + "aliases": [ + "CVE-2024-44220" + ], + "details": "The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2. Parsing a maliciously crafted video file may lead to unexpected system termination.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44220" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121839" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121840" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-wjm9-xj64-xhp8/GHSA-wjm9-xj64-xhp8.json b/advisories/unreviewed/2024/12/GHSA-wjm9-xj64-xhp8/GHSA-wjm9-xj64-xhp8.json new file mode 100644 index 00000000000..af972c33639 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-wjm9-xj64-xhp8/GHSA-wjm9-xj64-xhp8.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wjm9-xj64-xhp8", + "modified": "2024-12-12T03:33:03Z", + "published": "2024-12-12T03:33:03Z", + "aliases": [ + "CVE-2024-12484" + ], + "details": "A vulnerability classified as critical was found in Codezips Technical Discussion Forum 1.0. This vulnerability affects unknown code of the file /signuppost.php. The manipulation of the argument Username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12484" + }, + { + "type": "WEB", + "url": "https://github.com/LiChaser/CVE" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.287866" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.287866" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.459076" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T01:40:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-wm24-225r-44gm/GHSA-wm24-225r-44gm.json b/advisories/unreviewed/2024/12/GHSA-wm24-225r-44gm/GHSA-wm24-225r-44gm.json new file mode 100644 index 00000000000..d0aac57a990 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-wm24-225r-44gm/GHSA-wm24-225r-44gm.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wm24-225r-44gm", + "modified": "2024-12-12T03:33:07Z", + "published": "2024-12-12T03:33:06Z", + "aliases": [ + "CVE-2024-54514" + ], + "details": "The issue was addressed with improved checks. This issue is fixed in watchOS 11.2, tvOS 18.2, macOS Sequoia 15.2, iOS 18.2 and iPadOS 18.2, macOS Ventura 13.7.2, macOS Sonoma 14.7.2. An app may be able to break out of its sandbox.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54514" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121837" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121839" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121840" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121842" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121843" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121844" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-wmx6-8gph-wm9j/GHSA-wmx6-8gph-wm9j.json b/advisories/unreviewed/2024/12/GHSA-wmx6-8gph-wm9j/GHSA-wmx6-8gph-wm9j.json new file mode 100644 index 00000000000..04e2f067b54 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-wmx6-8gph-wm9j/GHSA-wmx6-8gph-wm9j.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wmx6-8gph-wm9j", + "modified": "2024-12-12T03:33:06Z", + "published": "2024-12-12T03:33:06Z", + "aliases": [ + "CVE-2024-54491" + ], + "details": "The issue was resolved by sanitizing logging This issue is fixed in macOS Sequoia 15.2. A malicious application may be able to determine a user's current location.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54491" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121839" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-wr54-9gc5-3m4h/GHSA-wr54-9gc5-3m4h.json b/advisories/unreviewed/2024/12/GHSA-wr54-9gc5-3m4h/GHSA-wr54-9gc5-3m4h.json index b383e5c3156..0a137d6b3cc 100644 --- a/advisories/unreviewed/2024/12/GHSA-wr54-9gc5-3m4h/GHSA-wr54-9gc5-3m4h.json +++ b/advisories/unreviewed/2024/12/GHSA-wr54-9gc5-3m4h/GHSA-wr54-9gc5-3m4h.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wr54-9gc5-3m4h", - "modified": "2024-12-07T00:31:03Z", + "modified": "2024-12-12T03:32:59Z", "published": "2024-12-07T00:31:03Z", "aliases": [ "CVE-2024-38923" ], "details": "Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered via remotely sending a request to change the value of dynamic-parameter`/amcl odom_frame_id` .", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-06T22:15:19Z" diff --git a/advisories/unreviewed/2024/12/GHSA-wrvq-q9qh-872j/GHSA-wrvq-q9qh-872j.json b/advisories/unreviewed/2024/12/GHSA-wrvq-q9qh-872j/GHSA-wrvq-q9qh-872j.json index 7a08c73b98d..00b42f15331 100644 --- a/advisories/unreviewed/2024/12/GHSA-wrvq-q9qh-872j/GHSA-wrvq-q9qh-872j.json +++ b/advisories/unreviewed/2024/12/GHSA-wrvq-q9qh-872j/GHSA-wrvq-q9qh-872j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wrvq-q9qh-872j", - "modified": "2024-12-04T18:32:36Z", + "modified": "2024-12-12T03:32:59Z", "published": "2024-12-04T18:32:36Z", "aliases": [ "CVE-2024-37574" ], "details": "The GriceMobile com.grice.call application 4.5.2 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.iui.mobile.presentation.MobileActivity.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-732" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-04T16:15:24Z" diff --git a/advisories/unreviewed/2024/12/GHSA-wvcq-qqvh-c77p/GHSA-wvcq-qqvh-c77p.json b/advisories/unreviewed/2024/12/GHSA-wvcq-qqvh-c77p/GHSA-wvcq-qqvh-c77p.json new file mode 100644 index 00000000000..eb47658b328 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-wvcq-qqvh-c77p/GHSA-wvcq-qqvh-c77p.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wvcq-qqvh-c77p", + "modified": "2024-12-12T03:33:03Z", + "published": "2024-12-12T03:33:03Z", + "aliases": [ + "CVE-2024-12488" + ], + "details": "A vulnerability was found in code-projects Online Class and Exam Scheduling System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /pages/subject_update.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12488" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/bjtyyy/CVE/blob/main/Online%20Class%20and%20Exam%20Scheduling%20System_subject_update_php%20.docx" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.287870" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.287870" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.459097" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T01:40:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-wwr9-w57c-2f9m/GHSA-wwr9-w57c-2f9m.json b/advisories/unreviewed/2024/12/GHSA-wwr9-w57c-2f9m/GHSA-wwr9-w57c-2f9m.json new file mode 100644 index 00000000000..642f28513d1 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-wwr9-w57c-2f9m/GHSA-wwr9-w57c-2f9m.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wwr9-w57c-2f9m", + "modified": "2024-12-12T03:33:06Z", + "published": "2024-12-12T03:33:06Z", + "aliases": [ + "CVE-2024-44291" + ], + "details": "A logic issue was addressed with improved file handling. This issue is fixed in macOS Sequoia 15.2, macOS Ventura 13.7.2, macOS Sonoma 14.7.2. A malicious app may be able to gain root privileges.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44291" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121839" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121840" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121842" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-x2fx-x8xv-9qm3/GHSA-x2fx-x8xv-9qm3.json b/advisories/unreviewed/2024/12/GHSA-x2fx-x8xv-9qm3/GHSA-x2fx-x8xv-9qm3.json new file mode 100644 index 00000000000..52ca6bd6120 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-x2fx-x8xv-9qm3/GHSA-x2fx-x8xv-9qm3.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x2fx-x8xv-9qm3", + "modified": "2024-12-12T03:33:06Z", + "published": "2024-12-12T03:33:06Z", + "aliases": [ + "CVE-2024-12536" + ], + "details": "A vulnerability, which was classified as problematic, has been found in SourceCodester Kortex Lite Advocate Office Management System 1.0. Affected by this issue is some unknown functionality of the file /control/client_data.php. The manipulation of the argument id leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12536" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.287912" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.287912" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.461130" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-x37p-5rxc-rc3h/GHSA-x37p-5rxc-rc3h.json b/advisories/unreviewed/2024/12/GHSA-x37p-5rxc-rc3h/GHSA-x37p-5rxc-rc3h.json new file mode 100644 index 00000000000..0c289cdf1b9 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-x37p-5rxc-rc3h/GHSA-x37p-5rxc-rc3h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x37p-5rxc-rc3h", + "modified": "2024-12-12T03:33:02Z", + "published": "2024-12-12T03:33:02Z", + "aliases": [ + "CVE-2024-11950" + ], + "details": "XnSoft XnView Classic RWZ File Parsing Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of XnSoft XnView Classic. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\n\nThe specific flaw exists within the parsing of RWZ files. The issue results from the lack of proper validation of user-supplied data, which can result in an integer underflow before writing to memory. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-22913.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11950" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1640" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-191" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T01:40:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-x9j9-ww89-ppfx/GHSA-x9j9-ww89-ppfx.json b/advisories/unreviewed/2024/12/GHSA-x9j9-ww89-ppfx/GHSA-x9j9-ww89-ppfx.json index 94b401c61a6..33c19da733d 100644 --- a/advisories/unreviewed/2024/12/GHSA-x9j9-ww89-ppfx/GHSA-x9j9-ww89-ppfx.json +++ b/advisories/unreviewed/2024/12/GHSA-x9j9-ww89-ppfx/GHSA-x9j9-ww89-ppfx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-x9j9-ww89-ppfx", - "modified": "2024-12-10T21:30:52Z", + "modified": "2024-12-12T03:33:01Z", "published": "2024-12-10T21:30:52Z", "aliases": [ "CVE-2024-50928" ], "details": "Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to change the wakeup interval of end devices in controller memory, disrupting the device's communications with the controller.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-281" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-10T19:15:30Z" diff --git a/advisories/unreviewed/2024/12/GHSA-x9mq-h652-rw6x/GHSA-x9mq-h652-rw6x.json b/advisories/unreviewed/2024/12/GHSA-x9mq-h652-rw6x/GHSA-x9mq-h652-rw6x.json new file mode 100644 index 00000000000..172b863e7cd --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-x9mq-h652-rw6x/GHSA-x9mq-h652-rw6x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x9mq-h652-rw6x", + "modified": "2024-12-12T03:33:04Z", + "published": "2024-12-12T03:33:04Z", + "aliases": [ + "CVE-2024-49059" + ], + "details": "Microsoft Office Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49059" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49059" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:04:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-xcmh-fgq9-r6jc/GHSA-xcmh-fgq9-r6jc.json b/advisories/unreviewed/2024/12/GHSA-xcmh-fgq9-r6jc/GHSA-xcmh-fgq9-r6jc.json new file mode 100644 index 00000000000..94145b2a4cf --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-xcmh-fgq9-r6jc/GHSA-xcmh-fgq9-r6jc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xcmh-fgq9-r6jc", + "modified": "2024-12-12T03:33:03Z", + "published": "2024-12-12T03:33:03Z", + "aliases": [ + "CVE-2024-12381" + ], + "details": "Type Confusion in V8 in Google Chrome prior to 131.0.6778.139 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12381" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/12/stable-channel-update-for-desktop_10.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/381696874" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-843" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T01:40:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-xgmf-7r4h-7jjp/GHSA-xgmf-7r4h-7jjp.json b/advisories/unreviewed/2024/12/GHSA-xgmf-7r4h-7jjp/GHSA-xgmf-7r4h-7jjp.json new file mode 100644 index 00000000000..e73a00c3799 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-xgmf-7r4h-7jjp/GHSA-xgmf-7r4h-7jjp.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xgmf-7r4h-7jjp", + "modified": "2024-12-12T03:33:06Z", + "published": "2024-12-12T03:33:06Z", + "aliases": [ + "CVE-2024-54474" + ], + "details": "The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2, macOS Ventura 13.7.2, macOS Sonoma 14.7.2. An app may be able to access user-sensitive data.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54474" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121839" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121840" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121842" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-xjr5-22cj-7cfp/GHSA-xjr5-22cj-7cfp.json b/advisories/unreviewed/2024/12/GHSA-xjr5-22cj-7cfp/GHSA-xjr5-22cj-7cfp.json new file mode 100644 index 00000000000..3237a9e0003 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-xjr5-22cj-7cfp/GHSA-xjr5-22cj-7cfp.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xjr5-22cj-7cfp", + "modified": "2024-12-12T03:33:07Z", + "published": "2024-12-12T03:33:07Z", + "aliases": [ + "CVE-2024-54527" + ], + "details": "This issue was addressed with improved checks. This issue is fixed in watchOS 11.2, tvOS 18.2, macOS Sequoia 15.2, iOS 18.2 and iPadOS 18.2, macOS Ventura 13.7.2, macOS Sonoma 14.7.2. An app may be able to access sensitive user data.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54527" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121837" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121839" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121840" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121842" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121843" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121844" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-xpm2-f32f-q35f/GHSA-xpm2-f32f-q35f.json b/advisories/unreviewed/2024/12/GHSA-xpm2-f32f-q35f/GHSA-xpm2-f32f-q35f.json index 88a8187530e..6255d9ea187 100644 --- a/advisories/unreviewed/2024/12/GHSA-xpm2-f32f-q35f/GHSA-xpm2-f32f-q35f.json +++ b/advisories/unreviewed/2024/12/GHSA-xpm2-f32f-q35f/GHSA-xpm2-f32f-q35f.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xpm2-f32f-q35f", - "modified": "2024-12-07T00:31:03Z", + "modified": "2024-12-12T03:33:00Z", "published": "2024-12-07T00:31:03Z", "aliases": [ "CVE-2024-41648" ], "details": "Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2_regulated_pure_pursuit_controller.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-281" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-06T22:15:20Z" diff --git a/advisories/unreviewed/2024/12/GHSA-xprr-92x5-gfg6/GHSA-xprr-92x5-gfg6.json b/advisories/unreviewed/2024/12/GHSA-xprr-92x5-gfg6/GHSA-xprr-92x5-gfg6.json index ac2e8d6b4ba..82290556528 100644 --- a/advisories/unreviewed/2024/12/GHSA-xprr-92x5-gfg6/GHSA-xprr-92x5-gfg6.json +++ b/advisories/unreviewed/2024/12/GHSA-xprr-92x5-gfg6/GHSA-xprr-92x5-gfg6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xprr-92x5-gfg6", - "modified": "2024-12-06T18:30:46Z", + "modified": "2024-12-12T03:32:59Z", "published": "2024-12-06T18:30:46Z", "aliases": [ "CVE-2024-54749" ], "details": "Ubiquiti U7-Pro 7.0.35 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-798" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-06T17:15:12Z" diff --git a/advisories/unreviewed/2024/12/GHSA-xw58-64fr-3323/GHSA-xw58-64fr-3323.json b/advisories/unreviewed/2024/12/GHSA-xw58-64fr-3323/GHSA-xw58-64fr-3323.json new file mode 100644 index 00000000000..ec66da85095 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-xw58-64fr-3323/GHSA-xw58-64fr-3323.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xw58-64fr-3323", + "modified": "2024-12-12T03:33:07Z", + "published": "2024-12-12T03:33:07Z", + "aliases": [ + "CVE-2024-54528" + ], + "details": "A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.2, macOS Ventura 13.7.2, macOS Sonoma 14.7.2. An app may be able to overwrite arbitrary files.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54528" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121839" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121840" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121842" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T02:15:32Z" + } +} \ No newline at end of file