From 40f32b74e99e31cfe8404860d2ba995ed1c3bdd6 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 9 Sep 2024 15:32:10 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-cphr-j5f7-39x9.json | 4 +- .../GHSA-gfr4-c37g-mm3v.json | 10 ++++- .../GHSA-238v-q38r-8xqp.json | 11 +++-- .../GHSA-27fg-vf5m-qmjj.json | 11 +++-- .../GHSA-66hj-w2gx-rg6c.json | 11 +++-- .../GHSA-692g-7998-j2vj.json | 11 +++-- .../GHSA-6x25-7hx6-jxf2.json | 11 +++-- .../GHSA-84x6-2366-7jjm.json | 11 +++-- .../GHSA-9pwr-528x-xv6m.json | 2 +- .../GHSA-c8q9-3mqw-64x8.json | 2 +- .../GHSA-fjgx-ff76-7ggv.json | 11 +++-- .../GHSA-fjjq-g95w-h3w9.json | 2 +- .../GHSA-gwmf-748f-8j3c.json | 11 +++-- .../GHSA-m6hp-rq22-2f6w.json | 2 +- .../GHSA-mpxh-cqc3-vxpw.json | 11 +++-- .../GHSA-mqvj-4p4w-f87c.json | 11 +++-- .../GHSA-pwf7-jc5h-rr33.json | 11 +++-- .../GHSA-w952-23jq-pvh9.json | 11 +++-- .../GHSA-4w89-vx8c-pfjq.json | 6 ++- .../GHSA-3rxw-2675-c3j9.json | 11 +++-- .../GHSA-49hg-gf5g-95cj.json | 11 +++-- .../GHSA-4rmw-g454-gq8g.json | 2 +- .../GHSA-58p4-j3v2-9gh4.json | 2 +- .../GHSA-83j5-q3hp-9jjc.json | 2 +- .../GHSA-fm87-mh9v-3658.json | 9 ++-- .../GHSA-h2w7-w434-9vmm.json | 39 +++++++++++++++++ .../GHSA-j7vj-rw65-4v26.json | 11 +++-- .../GHSA-m9gf-397r-hwpg.json | 42 +++++++++++++++++++ .../GHSA-m9m9-9hm4-wvwq.json | 2 +- .../GHSA-mqm9-c95h-x2p6.json | 42 +++++++++++++++++++ .../GHSA-qx8c-7fq5-7j7x.json | 11 +++-- .../GHSA-rjwq-j7vv-9hw7.json | 2 +- .../GHSA-rwxw-p86h-g9q6.json | 6 ++- .../GHSA-w4pv-qv3j-89ww.json | 38 +++++++++++++++++ .../GHSA-whxv-xf4j-48r5.json | 11 +++-- .../GHSA-wq3j-qfpm-h36f.json | 11 +++-- .../GHSA-wvqf-qcwj-mjxr.json | 2 +- .../GHSA-xjcw-q83g-v2h5.json | 38 +++++++++++++++++ 38 files changed, 362 insertions(+), 90 deletions(-) create mode 100644 advisories/unreviewed/2024/09/GHSA-h2w7-w434-9vmm/GHSA-h2w7-w434-9vmm.json create mode 100644 advisories/unreviewed/2024/09/GHSA-m9gf-397r-hwpg/GHSA-m9gf-397r-hwpg.json create mode 100644 advisories/unreviewed/2024/09/GHSA-mqm9-c95h-x2p6/GHSA-mqm9-c95h-x2p6.json create mode 100644 advisories/unreviewed/2024/09/GHSA-w4pv-qv3j-89ww/GHSA-w4pv-qv3j-89ww.json create mode 100644 advisories/unreviewed/2024/09/GHSA-xjcw-q83g-v2h5/GHSA-xjcw-q83g-v2h5.json diff --git a/advisories/unreviewed/2022/05/GHSA-cphr-j5f7-39x9/GHSA-cphr-j5f7-39x9.json b/advisories/unreviewed/2022/05/GHSA-cphr-j5f7-39x9/GHSA-cphr-j5f7-39x9.json index 0ed4fe16fa1..1b7f4cc88fe 100644 --- a/advisories/unreviewed/2022/05/GHSA-cphr-j5f7-39x9/GHSA-cphr-j5f7-39x9.json +++ b/advisories/unreviewed/2022/05/GHSA-cphr-j5f7-39x9/GHSA-cphr-j5f7-39x9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cphr-j5f7-39x9", - "modified": "2022-05-14T03:15:48Z", + "modified": "2024-09-09T15:30:36Z", "published": "2022-05-14T03:15:48Z", "aliases": [ "CVE-2016-9388" @@ -52,7 +52,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-617" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-gfr4-c37g-mm3v/GHSA-gfr4-c37g-mm3v.json b/advisories/unreviewed/2022/05/GHSA-gfr4-c37g-mm3v/GHSA-gfr4-c37g-mm3v.json index bb73e3de5be..d452e23847e 100644 --- a/advisories/unreviewed/2022/05/GHSA-gfr4-c37g-mm3v/GHSA-gfr4-c37g-mm3v.json +++ b/advisories/unreviewed/2022/05/GHSA-gfr4-c37g-mm3v/GHSA-gfr4-c37g-mm3v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gfr4-c37g-mm3v", - "modified": "2023-01-24T03:30:18Z", + "modified": "2024-09-09T15:30:37Z", "published": "2022-05-24T17:26:02Z", "aliases": [ "CVE-2020-24370" @@ -33,6 +33,14 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2023/06/msg00031.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E6KONNG6UEI3FMEOY67NDZC32NBGBI44" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QXYMCIUNGK26VHAYHGP5LPW56G2KWOHQ" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/E6KONNG6UEI3FMEOY67NDZC32NBGBI44" diff --git a/advisories/unreviewed/2024/06/GHSA-238v-q38r-8xqp/GHSA-238v-q38r-8xqp.json b/advisories/unreviewed/2024/06/GHSA-238v-q38r-8xqp/GHSA-238v-q38r-8xqp.json index ceb53582b8d..5ce0a413aef 100644 --- a/advisories/unreviewed/2024/06/GHSA-238v-q38r-8xqp/GHSA-238v-q38r-8xqp.json +++ b/advisories/unreviewed/2024/06/GHSA-238v-q38r-8xqp/GHSA-238v-q38r-8xqp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-238v-q38r-8xqp", - "modified": "2024-06-27T15:30:40Z", + "modified": "2024-09-09T15:30:37Z", "published": "2024-06-21T12:31:20Z", "aliases": [ "CVE-2024-38381" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: nci: Fix uninit-value in nci_rx_work\n\nsyzbot reported the following uninit-value access issue [1]\n\nnci_rx_work() parses received packet from ndev->rx_q. It should be\nvalidated header size, payload size and total packet size before\nprocessing the packet. If an invalid packet is detected, it should be\nsilently discarded.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } ], "affected": [ @@ -57,9 +60,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-908" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-21T11:15:10Z" diff --git a/advisories/unreviewed/2024/06/GHSA-27fg-vf5m-qmjj/GHSA-27fg-vf5m-qmjj.json b/advisories/unreviewed/2024/06/GHSA-27fg-vf5m-qmjj/GHSA-27fg-vf5m-qmjj.json index e0b42d80560..1879d267561 100644 --- a/advisories/unreviewed/2024/06/GHSA-27fg-vf5m-qmjj/GHSA-27fg-vf5m-qmjj.json +++ b/advisories/unreviewed/2024/06/GHSA-27fg-vf5m-qmjj/GHSA-27fg-vf5m-qmjj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-27fg-vf5m-qmjj", - "modified": "2024-06-21T12:31:21Z", + "modified": "2024-09-09T15:30:37Z", "published": "2024-06-21T12:31:21Z", "aliases": [ "CVE-2024-38632" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nvfio/pci: fix potential memory leak in vfio_intx_enable()\n\nIf vfio_irq_ctx_alloc() failed will lead to 'name' memory leak.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-401" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-21T11:15:11Z" diff --git a/advisories/unreviewed/2024/06/GHSA-66hj-w2gx-rg6c/GHSA-66hj-w2gx-rg6c.json b/advisories/unreviewed/2024/06/GHSA-66hj-w2gx-rg6c/GHSA-66hj-w2gx-rg6c.json index ea2fdbfcfe4..24a2fc7e96b 100644 --- a/advisories/unreviewed/2024/06/GHSA-66hj-w2gx-rg6c/GHSA-66hj-w2gx-rg6c.json +++ b/advisories/unreviewed/2024/06/GHSA-66hj-w2gx-rg6c/GHSA-66hj-w2gx-rg6c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-66hj-w2gx-rg6c", - "modified": "2024-06-21T12:31:20Z", + "modified": "2024-09-09T15:30:37Z", "published": "2024-06-21T12:31:20Z", "aliases": [ "CVE-2024-36478" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnull_blk: fix null-ptr-dereference while configuring 'power' and 'submit_queues'\n\nWriting 'power' and 'submit_queues' concurrently will trigger kernel\npanic:\n\nTest script:\n\nmodprobe null_blk nr_devices=0\nmkdir -p /sys/kernel/config/nullb/nullb0\nwhile true; do echo 1 > submit_queues; echo 4 > submit_queues; done &\nwhile true; do echo 1 > power; echo 0 > power; done\n\nTest result:\n\nBUG: kernel NULL pointer dereference, address: 0000000000000148\nOops: 0000 [#1] PREEMPT SMP\nRIP: 0010:__lock_acquire+0x41d/0x28f0\nCall Trace:\n \n lock_acquire+0x121/0x450\n down_write+0x5f/0x1d0\n simple_recursive_removal+0x12f/0x5c0\n blk_mq_debugfs_unregister_hctxs+0x7c/0x100\n blk_mq_update_nr_hw_queues+0x4a3/0x720\n nullb_update_nr_hw_queues+0x71/0xf0 [null_blk]\n nullb_device_submit_queues_store+0x79/0xf0 [null_blk]\n configfs_write_iter+0x119/0x1e0\n vfs_write+0x326/0x730\n ksys_write+0x74/0x150\n\nThis is because del_gendisk() can concurrent with\nblk_mq_update_nr_hw_queues():\n\nnullb_device_power_store\tnullb_apply_submit_queues\n null_del_dev\n del_gendisk\n\t\t\t\t nullb_update_nr_hw_queues\n\t\t\t\t if (!dev->nullb)\n\t\t\t\t // still set while gendisk is deleted\n\t\t\t\t return 0\n\t\t\t\t blk_mq_update_nr_hw_queues\n dev->nullb = NULL\n\nFix this problem by resuing the global mutex to protect\nnullb_device_power_store() and nullb_update_nr_hw_queues() from configfs.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-21T11:15:10Z" diff --git a/advisories/unreviewed/2024/06/GHSA-692g-7998-j2vj/GHSA-692g-7998-j2vj.json b/advisories/unreviewed/2024/06/GHSA-692g-7998-j2vj/GHSA-692g-7998-j2vj.json index 832012bc0fd..64f2abca144 100644 --- a/advisories/unreviewed/2024/06/GHSA-692g-7998-j2vj/GHSA-692g-7998-j2vj.json +++ b/advisories/unreviewed/2024/06/GHSA-692g-7998-j2vj/GHSA-692g-7998-j2vj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-692g-7998-j2vj", - "modified": "2024-06-21T12:31:20Z", + "modified": "2024-09-09T15:30:37Z", "published": "2024-06-21T12:31:20Z", "aliases": [ "CVE-2024-36489" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntls: fix missing memory barrier in tls_init\n\nIn tls_init(), a write memory barrier is missing, and store-store\nreordering may cause NULL dereference in tls_{setsockopt,getsockopt}.\n\nCPU0 CPU1\n----- -----\n// In tls_init()\n// In tls_ctx_create()\nctx = kzalloc()\nctx->sk_proto = READ_ONCE(sk->sk_prot) -(1)\n\n// In update_sk_prot()\nWRITE_ONCE(sk->sk_prot, tls_prots) -(2)\n\n // In sock_common_setsockopt()\n READ_ONCE(sk->sk_prot)->setsockopt()\n\n // In tls_{setsockopt,getsockopt}()\n ctx->sk_proto->setsockopt() -(3)\n\nIn the above scenario, when (1) and (2) are reordered, (3) can observe\nthe NULL value of ctx->sk_proto, causing NULL dereference.\n\nTo fix it, we rely on rcu_assign_pointer() which implies the release\nbarrier semantic. By moving rcu_assign_pointer() after ctx->sk_proto is\ninitialized, we can ensure that ctx->sk_proto are visible when\nchanging sk->sk_prot.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-21T11:15:10Z" diff --git a/advisories/unreviewed/2024/06/GHSA-6x25-7hx6-jxf2/GHSA-6x25-7hx6-jxf2.json b/advisories/unreviewed/2024/06/GHSA-6x25-7hx6-jxf2/GHSA-6x25-7hx6-jxf2.json index ccf155a021a..28f9cd9d199 100644 --- a/advisories/unreviewed/2024/06/GHSA-6x25-7hx6-jxf2/GHSA-6x25-7hx6-jxf2.json +++ b/advisories/unreviewed/2024/06/GHSA-6x25-7hx6-jxf2/GHSA-6x25-7hx6-jxf2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6x25-7hx6-jxf2", - "modified": "2024-06-21T12:31:20Z", + "modified": "2024-09-09T15:30:37Z", "published": "2024-06-21T12:31:20Z", "aliases": [ "CVE-2024-36281" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5: Use mlx5_ipsec_rx_status_destroy to correctly delete status rules\n\nrx_create no longer allocates a modify_hdr instance that needs to be\ncleaned up. The mlx5_modify_header_dealloc call will lead to a NULL pointer\ndereference. A leak in the rules also previously occurred since there are\nnow two rules populated related to status.\n\n BUG: kernel NULL pointer dereference, address: 0000000000000000\n #PF: supervisor read access in kernel mode\n #PF: error_code(0x0000) - not-present page\n PGD 109907067 P4D 109907067 PUD 116890067 PMD 0\n Oops: 0000 [#1] SMP\n CPU: 1 PID: 484 Comm: ip Not tainted 6.9.0-rc2-rrameshbabu+ #254\n Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS Arch Linux 1.16.3-1-1 04/01/2014\n RIP: 0010:mlx5_modify_header_dealloc+0xd/0x70\n \n Call Trace:\n \n ? show_regs+0x60/0x70\n ? __die+0x24/0x70\n ? page_fault_oops+0x15f/0x430\n ? free_to_partial_list.constprop.0+0x79/0x150\n ? do_user_addr_fault+0x2c9/0x5c0\n ? exc_page_fault+0x63/0x110\n ? asm_exc_page_fault+0x27/0x30\n ? mlx5_modify_header_dealloc+0xd/0x70\n rx_create+0x374/0x590\n rx_add_rule+0x3ad/0x500\n ? rx_add_rule+0x3ad/0x500\n ? mlx5_cmd_exec+0x2c/0x40\n ? mlx5_create_ipsec_obj+0xd6/0x200\n mlx5e_accel_ipsec_fs_add_rule+0x31/0xf0\n mlx5e_xfrm_add_state+0x426/0xc00\n ", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-21T11:15:10Z" diff --git a/advisories/unreviewed/2024/06/GHSA-84x6-2366-7jjm/GHSA-84x6-2366-7jjm.json b/advisories/unreviewed/2024/06/GHSA-84x6-2366-7jjm/GHSA-84x6-2366-7jjm.json index 662754f32e2..ed5d6d4f64b 100644 --- a/advisories/unreviewed/2024/06/GHSA-84x6-2366-7jjm/GHSA-84x6-2366-7jjm.json +++ b/advisories/unreviewed/2024/06/GHSA-84x6-2366-7jjm/GHSA-84x6-2366-7jjm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-84x6-2366-7jjm", - "modified": "2024-06-27T12:30:48Z", + "modified": "2024-09-09T15:30:37Z", "published": "2024-06-21T12:31:20Z", "aliases": [ "CVE-2024-38627" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nstm class: Fix a double free in stm_register_device()\n\nThe put_device(&stm->dev) call will trigger stm_device_release() which\nfrees \"stm\" so the vfree(stm) on the next line is a double free.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -57,9 +60,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-415" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-21T11:15:11Z" diff --git a/advisories/unreviewed/2024/06/GHSA-9pwr-528x-xv6m/GHSA-9pwr-528x-xv6m.json b/advisories/unreviewed/2024/06/GHSA-9pwr-528x-xv6m/GHSA-9pwr-528x-xv6m.json index c8eebd7db8b..11257218baf 100644 --- a/advisories/unreviewed/2024/06/GHSA-9pwr-528x-xv6m/GHSA-9pwr-528x-xv6m.json +++ b/advisories/unreviewed/2024/06/GHSA-9pwr-528x-xv6m/GHSA-9pwr-528x-xv6m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9pwr-528x-xv6m", - "modified": "2024-06-20T18:34:09Z", + "modified": "2024-09-09T15:30:37Z", "published": "2024-06-20T18:34:09Z", "aliases": [ "CVE-2024-37352" diff --git a/advisories/unreviewed/2024/06/GHSA-c8q9-3mqw-64x8/GHSA-c8q9-3mqw-64x8.json b/advisories/unreviewed/2024/06/GHSA-c8q9-3mqw-64x8/GHSA-c8q9-3mqw-64x8.json index db45ffbeeab..04287881348 100644 --- a/advisories/unreviewed/2024/06/GHSA-c8q9-3mqw-64x8/GHSA-c8q9-3mqw-64x8.json +++ b/advisories/unreviewed/2024/06/GHSA-c8q9-3mqw-64x8/GHSA-c8q9-3mqw-64x8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c8q9-3mqw-64x8", - "modified": "2024-06-20T18:34:09Z", + "modified": "2024-09-09T15:30:37Z", "published": "2024-06-20T18:34:09Z", "aliases": [ "CVE-2024-37349" diff --git a/advisories/unreviewed/2024/06/GHSA-fjgx-ff76-7ggv/GHSA-fjgx-ff76-7ggv.json b/advisories/unreviewed/2024/06/GHSA-fjgx-ff76-7ggv/GHSA-fjgx-ff76-7ggv.json index 4c30dbe5eb7..419effe1dfc 100644 --- a/advisories/unreviewed/2024/06/GHSA-fjgx-ff76-7ggv/GHSA-fjgx-ff76-7ggv.json +++ b/advisories/unreviewed/2024/06/GHSA-fjgx-ff76-7ggv/GHSA-fjgx-ff76-7ggv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fjgx-ff76-7ggv", - "modified": "2024-07-15T09:36:12Z", + "modified": "2024-09-09T15:30:37Z", "published": "2024-06-21T12:31:21Z", "aliases": [ "CVE-2024-38633" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nserial: max3100: Update uart_driver_registered on driver removal\n\nThe removal of the last MAX3100 device triggers the removal of\nthe driver. However, code doesn't update the respective global\nvariable and after insmod — rmmod — insmod cycle the kernel\noopses:\n\n max3100 spi-PRP0001:01: max3100_probe: adding port 0\n BUG: kernel NULL pointer dereference, address: 0000000000000408\n ...\n RIP: 0010:serial_core_register_port+0xa0/0x840\n ...\n max3100_probe+0x1b6/0x280 [max3100]\n spi_probe+0x8d/0xb0\n\nUpdate the actual state so next time UART driver will be registered\nagain.\n\nHugo also noticed, that the error path in the probe also affected\nby having the variable set, and not cleared. Instead of clearing it\nmove the assignment after the successfull uart_register_driver() call.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -57,9 +60,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-21T11:15:12Z" diff --git a/advisories/unreviewed/2024/06/GHSA-fjjq-g95w-h3w9/GHSA-fjjq-g95w-h3w9.json b/advisories/unreviewed/2024/06/GHSA-fjjq-g95w-h3w9/GHSA-fjjq-g95w-h3w9.json index 31f2ed8891e..11c4e923ad0 100644 --- a/advisories/unreviewed/2024/06/GHSA-fjjq-g95w-h3w9/GHSA-fjjq-g95w-h3w9.json +++ b/advisories/unreviewed/2024/06/GHSA-fjjq-g95w-h3w9/GHSA-fjjq-g95w-h3w9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fjjq-g95w-h3w9", - "modified": "2024-06-20T18:34:09Z", + "modified": "2024-09-09T15:30:37Z", "published": "2024-06-20T18:34:09Z", "aliases": [ "CVE-2024-37351" diff --git a/advisories/unreviewed/2024/06/GHSA-gwmf-748f-8j3c/GHSA-gwmf-748f-8j3c.json b/advisories/unreviewed/2024/06/GHSA-gwmf-748f-8j3c/GHSA-gwmf-748f-8j3c.json index 595eab07344..33287154464 100644 --- a/advisories/unreviewed/2024/06/GHSA-gwmf-748f-8j3c/GHSA-gwmf-748f-8j3c.json +++ b/advisories/unreviewed/2024/06/GHSA-gwmf-748f-8j3c/GHSA-gwmf-748f-8j3c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gwmf-748f-8j3c", - "modified": "2024-06-21T12:31:20Z", + "modified": "2024-09-09T15:30:37Z", "published": "2024-06-21T12:31:19Z", "aliases": [ "CVE-2024-36270" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: tproxy: bail out if IP has been disabled on the device\n\nsyzbot reports:\ngeneral protection fault, probably for non-canonical address 0xdffffc0000000003: 0000 [#1] PREEMPT SMP KASAN PTI\nKASAN: null-ptr-deref in range [0x0000000000000018-0x000000000000001f]\n[..]\nRIP: 0010:nf_tproxy_laddr4+0xb7/0x340 net/ipv4/netfilter/nf_tproxy_ipv4.c:62\nCall Trace:\n nft_tproxy_eval_v4 net/netfilter/nft_tproxy.c:56 [inline]\n nft_tproxy_eval+0xa9a/0x1a00 net/netfilter/nft_tproxy.c:168\n\n__in_dev_get_rcu() can return NULL, so check for this.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -49,9 +52,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-21T11:15:10Z" diff --git a/advisories/unreviewed/2024/06/GHSA-m6hp-rq22-2f6w/GHSA-m6hp-rq22-2f6w.json b/advisories/unreviewed/2024/06/GHSA-m6hp-rq22-2f6w/GHSA-m6hp-rq22-2f6w.json index bf735d4fb32..b97b6265b63 100644 --- a/advisories/unreviewed/2024/06/GHSA-m6hp-rq22-2f6w/GHSA-m6hp-rq22-2f6w.json +++ b/advisories/unreviewed/2024/06/GHSA-m6hp-rq22-2f6w/GHSA-m6hp-rq22-2f6w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m6hp-rq22-2f6w", - "modified": "2024-06-20T18:34:09Z", + "modified": "2024-09-09T15:30:37Z", "published": "2024-06-20T18:34:09Z", "aliases": [ "CVE-2024-37350" diff --git a/advisories/unreviewed/2024/06/GHSA-mpxh-cqc3-vxpw/GHSA-mpxh-cqc3-vxpw.json b/advisories/unreviewed/2024/06/GHSA-mpxh-cqc3-vxpw/GHSA-mpxh-cqc3-vxpw.json index 87acde202cb..763caea8dbe 100644 --- a/advisories/unreviewed/2024/06/GHSA-mpxh-cqc3-vxpw/GHSA-mpxh-cqc3-vxpw.json +++ b/advisories/unreviewed/2024/06/GHSA-mpxh-cqc3-vxpw/GHSA-mpxh-cqc3-vxpw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mpxh-cqc3-vxpw", - "modified": "2024-06-21T12:31:20Z", + "modified": "2024-09-09T15:30:37Z", "published": "2024-06-21T12:31:20Z", "aliases": [ "CVE-2024-38390" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/msm/a6xx: Avoid a nullptr dereference when speedbin setting fails\n\nCalling a6xx_destroy() before adreno_gpu_init() leads to a null pointer\ndereference on:\n\nmsm_gpu_cleanup() : platform_set_drvdata(gpu->pdev, NULL);\n\nas gpu->pdev is only assigned in:\n\na6xx_gpu_init()\n|_ adreno_gpu_init\n |_ msm_gpu_init()\n\nInstead of relying on handwavy null checks down the cleanup chain,\nexplicitly de-allocate the LLC data and free a6xx_gpu instead.\n\nPatchwork: https://patchwork.freedesktop.org/patch/588919/", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-21T11:15:10Z" diff --git a/advisories/unreviewed/2024/06/GHSA-mqvj-4p4w-f87c/GHSA-mqvj-4p4w-f87c.json b/advisories/unreviewed/2024/06/GHSA-mqvj-4p4w-f87c/GHSA-mqvj-4p4w-f87c.json index b5c74bf373b..54d9bbdedc5 100644 --- a/advisories/unreviewed/2024/06/GHSA-mqvj-4p4w-f87c/GHSA-mqvj-4p4w-f87c.json +++ b/advisories/unreviewed/2024/06/GHSA-mqvj-4p4w-f87c/GHSA-mqvj-4p4w-f87c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mqvj-4p4w-f87c", - "modified": "2024-06-21T12:31:20Z", + "modified": "2024-09-09T15:30:37Z", "published": "2024-06-21T12:31:20Z", "aliases": [ "CVE-2024-38631" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\niio: adc: PAC1934: fix accessing out of bounds array index\n\nFix accessing out of bounds array index for average\ncurrent and voltage measurements. The device itself has\nonly 4 channels, but in sysfs there are \"fake\"\nchannels for the average voltages and currents too.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-129" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-21T11:15:11Z" diff --git a/advisories/unreviewed/2024/06/GHSA-pwf7-jc5h-rr33/GHSA-pwf7-jc5h-rr33.json b/advisories/unreviewed/2024/06/GHSA-pwf7-jc5h-rr33/GHSA-pwf7-jc5h-rr33.json index 2c3b0afe57e..eee096b124f 100644 --- a/advisories/unreviewed/2024/06/GHSA-pwf7-jc5h-rr33/GHSA-pwf7-jc5h-rr33.json +++ b/advisories/unreviewed/2024/06/GHSA-pwf7-jc5h-rr33/GHSA-pwf7-jc5h-rr33.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pwf7-jc5h-rr33", - "modified": "2024-06-20T12:31:22Z", + "modified": "2024-09-09T15:30:37Z", "published": "2024-06-20T12:31:22Z", "aliases": [ "CVE-2022-48768" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntracing/histogram: Fix a potential memory leak for kstrdup()\n\nkfree() is missing on an error path to free the memory allocated by\nkstrdup():\n\n p = param = kstrdup(data->params[i], GFP_KERNEL);\n\nSo it is better to free it via kfree(p).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-401" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-20T12:15:14Z" diff --git a/advisories/unreviewed/2024/06/GHSA-w952-23jq-pvh9/GHSA-w952-23jq-pvh9.json b/advisories/unreviewed/2024/06/GHSA-w952-23jq-pvh9/GHSA-w952-23jq-pvh9.json index 18d373075ac..8461c25eb97 100644 --- a/advisories/unreviewed/2024/06/GHSA-w952-23jq-pvh9/GHSA-w952-23jq-pvh9.json +++ b/advisories/unreviewed/2024/06/GHSA-w952-23jq-pvh9/GHSA-w952-23jq-pvh9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w952-23jq-pvh9", - "modified": "2024-06-21T12:31:20Z", + "modified": "2024-09-09T15:30:37Z", "published": "2024-06-21T12:31:20Z", "aliases": [ "CVE-2024-38630" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwatchdog: cpu5wdt.c: Fix use-after-free bug caused by cpu5wdt_trigger\n\nWhen the cpu5wdt module is removing, the origin code uses del_timer() to\nde-activate the timer. If the timer handler is running, del_timer() could\nnot stop it and will return directly. If the port region is released by\nrelease_region() and then the timer handler cpu5wdt_trigger() calls outb()\nto write into the region that is released, the use-after-free bug will\nhappen.\n\nChange del_timer() to timer_shutdown_sync() in order that the timer handler\ncould be finished before the port region is released.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-21T11:15:11Z" diff --git a/advisories/unreviewed/2024/08/GHSA-4w89-vx8c-pfjq/GHSA-4w89-vx8c-pfjq.json b/advisories/unreviewed/2024/08/GHSA-4w89-vx8c-pfjq/GHSA-4w89-vx8c-pfjq.json index 8d7b75c8746..f8a8ef730a8 100644 --- a/advisories/unreviewed/2024/08/GHSA-4w89-vx8c-pfjq/GHSA-4w89-vx8c-pfjq.json +++ b/advisories/unreviewed/2024/08/GHSA-4w89-vx8c-pfjq/GHSA-4w89-vx8c-pfjq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4w89-vx8c-pfjq", - "modified": "2024-08-12T15:30:53Z", + "modified": "2024-09-09T15:30:37Z", "published": "2024-08-12T15:30:52Z", "aliases": [ "CVE-2024-7644" @@ -40,6 +40,10 @@ { "type": "WEB", "url": "https://vuldb.com/?submit.387345" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/09/GHSA-3rxw-2675-c3j9/GHSA-3rxw-2675-c3j9.json b/advisories/unreviewed/2024/09/GHSA-3rxw-2675-c3j9/GHSA-3rxw-2675-c3j9.json index 45e8afb9187..4d887963e57 100644 --- a/advisories/unreviewed/2024/09/GHSA-3rxw-2675-c3j9/GHSA-3rxw-2675-c3j9.json +++ b/advisories/unreviewed/2024/09/GHSA-3rxw-2675-c3j9/GHSA-3rxw-2675-c3j9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3rxw-2675-c3j9", - "modified": "2024-09-09T06:30:45Z", + "modified": "2024-09-09T15:30:40Z", "published": "2024-09-09T06:30:45Z", "aliases": [ "CVE-2024-7688" ], "details": "The AZIndex WordPress plugin through 0.8.1 does not have CSRF checks in some places, which could allow attackers to make logged in admin delete arbitrary indexes via a CSRF attack", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-09T06:15:02Z" diff --git a/advisories/unreviewed/2024/09/GHSA-49hg-gf5g-95cj/GHSA-49hg-gf5g-95cj.json b/advisories/unreviewed/2024/09/GHSA-49hg-gf5g-95cj/GHSA-49hg-gf5g-95cj.json index c26e826dddf..12ee32b7a6a 100644 --- a/advisories/unreviewed/2024/09/GHSA-49hg-gf5g-95cj/GHSA-49hg-gf5g-95cj.json +++ b/advisories/unreviewed/2024/09/GHSA-49hg-gf5g-95cj/GHSA-49hg-gf5g-95cj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-49hg-gf5g-95cj", - "modified": "2024-09-09T06:30:45Z", + "modified": "2024-09-09T15:30:40Z", "published": "2024-09-09T06:30:45Z", "aliases": [ "CVE-2024-7918" ], "details": "The Pocket Widget WordPress plugin through 0.1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-09T06:15:02Z" diff --git a/advisories/unreviewed/2024/09/GHSA-4rmw-g454-gq8g/GHSA-4rmw-g454-gq8g.json b/advisories/unreviewed/2024/09/GHSA-4rmw-g454-gq8g/GHSA-4rmw-g454-gq8g.json index 86c7f944de7..ebe044a4e08 100644 --- a/advisories/unreviewed/2024/09/GHSA-4rmw-g454-gq8g/GHSA-4rmw-g454-gq8g.json +++ b/advisories/unreviewed/2024/09/GHSA-4rmw-g454-gq8g/GHSA-4rmw-g454-gq8g.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-58p4-j3v2-9gh4/GHSA-58p4-j3v2-9gh4.json b/advisories/unreviewed/2024/09/GHSA-58p4-j3v2-9gh4/GHSA-58p4-j3v2-9gh4.json index e06d0663734..ee858568e14 100644 --- a/advisories/unreviewed/2024/09/GHSA-58p4-j3v2-9gh4/GHSA-58p4-j3v2-9gh4.json +++ b/advisories/unreviewed/2024/09/GHSA-58p4-j3v2-9gh4/GHSA-58p4-j3v2-9gh4.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-250" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-83j5-q3hp-9jjc/GHSA-83j5-q3hp-9jjc.json b/advisories/unreviewed/2024/09/GHSA-83j5-q3hp-9jjc/GHSA-83j5-q3hp-9jjc.json index b2c518b6850..f79fac79a5d 100644 --- a/advisories/unreviewed/2024/09/GHSA-83j5-q3hp-9jjc/GHSA-83j5-q3hp-9jjc.json +++ b/advisories/unreviewed/2024/09/GHSA-83j5-q3hp-9jjc/GHSA-83j5-q3hp-9jjc.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-fm87-mh9v-3658/GHSA-fm87-mh9v-3658.json b/advisories/unreviewed/2024/09/GHSA-fm87-mh9v-3658/GHSA-fm87-mh9v-3658.json index 037171ffb0f..455efb6f3af 100644 --- a/advisories/unreviewed/2024/09/GHSA-fm87-mh9v-3658/GHSA-fm87-mh9v-3658.json +++ b/advisories/unreviewed/2024/09/GHSA-fm87-mh9v-3658/GHSA-fm87-mh9v-3658.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fm87-mh9v-3658", - "modified": "2024-09-09T06:30:45Z", + "modified": "2024-09-09T15:30:40Z", "published": "2024-09-09T06:30:45Z", "aliases": [ "CVE-2024-7689" ], "details": "The Snapshot Backup WordPress plugin through 2.1.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-09T06:15:02Z" diff --git a/advisories/unreviewed/2024/09/GHSA-h2w7-w434-9vmm/GHSA-h2w7-w434-9vmm.json b/advisories/unreviewed/2024/09/GHSA-h2w7-w434-9vmm/GHSA-h2w7-w434-9vmm.json new file mode 100644 index 00000000000..68900568194 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-h2w7-w434-9vmm/GHSA-h2w7-w434-9vmm.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h2w7-w434-9vmm", + "modified": "2024-09-09T15:30:41Z", + "published": "2024-09-09T15:30:41Z", + "aliases": [ + "CVE-2024-44375" + ], + "details": "D-Link DI-8100 v16.07.26A1 has a stack overflow vulnerability in the dbsrv_asp function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44375" + }, + { + "type": "WEB", + "url": "https://github.com/Nop3z/CVE/blob/main/dlink/DI-8100/Dlink-di8100-dbsrv_asp-overflow.md" + }, + { + "type": "WEB", + "url": "https://www.dlink.com/en/security-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-09T14:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-j7vj-rw65-4v26/GHSA-j7vj-rw65-4v26.json b/advisories/unreviewed/2024/09/GHSA-j7vj-rw65-4v26/GHSA-j7vj-rw65-4v26.json index b5ffb617d4e..077e0cd16a7 100644 --- a/advisories/unreviewed/2024/09/GHSA-j7vj-rw65-4v26/GHSA-j7vj-rw65-4v26.json +++ b/advisories/unreviewed/2024/09/GHSA-j7vj-rw65-4v26/GHSA-j7vj-rw65-4v26.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j7vj-rw65-4v26", - "modified": "2024-09-06T21:32:28Z", + "modified": "2024-09-09T15:30:38Z", "published": "2024-09-06T21:32:28Z", "aliases": [ "CVE-2024-34158" ], "details": "Calling Parse on a \"// +build\" build tag line with deeply nested expressions can cause a panic due to stack exhaustion.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-674" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-06T21:15:12Z" diff --git a/advisories/unreviewed/2024/09/GHSA-m9gf-397r-hwpg/GHSA-m9gf-397r-hwpg.json b/advisories/unreviewed/2024/09/GHSA-m9gf-397r-hwpg/GHSA-m9gf-397r-hwpg.json new file mode 100644 index 00000000000..4401fd51c2c --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-m9gf-397r-hwpg/GHSA-m9gf-397r-hwpg.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m9gf-397r-hwpg", + "modified": "2024-09-09T15:30:41Z", + "published": "2024-09-09T15:30:41Z", + "aliases": [ + "CVE-2024-8372" + ], + "details": "Improper sanitization of the value of the '[srcset]' attribute in AngularJS allows attackers to bypass common image source restrictions, which can also lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing .\n\nThis issue affects AngularJS versions 1.3.0-rc.4 and greater.\n\nNote:\nThe AngularJS project is End-of-Life and will not receive any updates to address this issue. For more information see here https://docs.angularjs.org/misc/version-support-status .", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8372" + }, + { + "type": "WEB", + "url": "https://codepen.io/herodevs/full/xxoQRNL/0072e627abe03e9cda373bc75b4c1017" + }, + { + "type": "WEB", + "url": "https://www.herodevs.com/vulnerability-directory/cve-2024-8372" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1289" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-09T15:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-m9m9-9hm4-wvwq/GHSA-m9m9-9hm4-wvwq.json b/advisories/unreviewed/2024/09/GHSA-m9m9-9hm4-wvwq/GHSA-m9m9-9hm4-wvwq.json index a3c0d777512..5853159a2b4 100644 --- a/advisories/unreviewed/2024/09/GHSA-m9m9-9hm4-wvwq/GHSA-m9m9-9hm4-wvwq.json +++ b/advisories/unreviewed/2024/09/GHSA-m9m9-9hm4-wvwq/GHSA-m9m9-9hm4-wvwq.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-mqm9-c95h-x2p6/GHSA-mqm9-c95h-x2p6.json b/advisories/unreviewed/2024/09/GHSA-mqm9-c95h-x2p6/GHSA-mqm9-c95h-x2p6.json new file mode 100644 index 00000000000..565ebfd280e --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-mqm9-c95h-x2p6/GHSA-mqm9-c95h-x2p6.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mqm9-c95h-x2p6", + "modified": "2024-09-09T15:30:41Z", + "published": "2024-09-09T15:30:41Z", + "aliases": [ + "CVE-2024-8373" + ], + "details": "Improper sanitization of the value of the '[srcset]' attribute in '' HTML elements in AngularJS allows attackers to bypass common image source restrictions, which can also lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing .\n\nThis issue affects all versions of AngularJS.\n\nNote:\nThe AngularJS project is End-of-Life and will not receive any updates to address this issue. For more information see here https://docs.angularjs.org/misc/version-support-status .", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8373" + }, + { + "type": "WEB", + "url": "https://codepen.io/herodevs/full/bGPQgMp/8da9ce87e99403ee13a295c305ebfa0b" + }, + { + "type": "WEB", + "url": "https://www.herodevs.com/vulnerability-directory/cve-2024-8373" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-791" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-09T15:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-qx8c-7fq5-7j7x/GHSA-qx8c-7fq5-7j7x.json b/advisories/unreviewed/2024/09/GHSA-qx8c-7fq5-7j7x/GHSA-qx8c-7fq5-7j7x.json index fe4645aa113..a452b2c4ae8 100644 --- a/advisories/unreviewed/2024/09/GHSA-qx8c-7fq5-7j7x/GHSA-qx8c-7fq5-7j7x.json +++ b/advisories/unreviewed/2024/09/GHSA-qx8c-7fq5-7j7x/GHSA-qx8c-7fq5-7j7x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qx8c-7fq5-7j7x", - "modified": "2024-09-07T00:31:29Z", + "modified": "2024-09-09T15:30:38Z", "published": "2024-09-07T00:31:29Z", "aliases": [ "CVE-2024-44838" ], "details": "RapidCMS v1.3.1 was discovered to contain a SQL injection vulnerability via the username parameter at /resource/runlogin.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-06T22:15:02Z" diff --git a/advisories/unreviewed/2024/09/GHSA-rjwq-j7vv-9hw7/GHSA-rjwq-j7vv-9hw7.json b/advisories/unreviewed/2024/09/GHSA-rjwq-j7vv-9hw7/GHSA-rjwq-j7vv-9hw7.json index 69ae8c5d056..cd60fb64053 100644 --- a/advisories/unreviewed/2024/09/GHSA-rjwq-j7vv-9hw7/GHSA-rjwq-j7vv-9hw7.json +++ b/advisories/unreviewed/2024/09/GHSA-rjwq-j7vv-9hw7/GHSA-rjwq-j7vv-9hw7.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-295" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-rwxw-p86h-g9q6/GHSA-rwxw-p86h-g9q6.json b/advisories/unreviewed/2024/09/GHSA-rwxw-p86h-g9q6/GHSA-rwxw-p86h-g9q6.json index 033ccd2c8e4..dadca1b2d2c 100644 --- a/advisories/unreviewed/2024/09/GHSA-rwxw-p86h-g9q6/GHSA-rwxw-p86h-g9q6.json +++ b/advisories/unreviewed/2024/09/GHSA-rwxw-p86h-g9q6/GHSA-rwxw-p86h-g9q6.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rwxw-p86h-g9q6", - "modified": "2024-09-09T12:31:57Z", + "modified": "2024-09-09T15:30:40Z", "published": "2024-09-09T12:31:57Z", "aliases": [ "CVE-2024-6572" ], "details": "Improper host key checking in active check 'Check SFTP Service' and special agent 'VNX quotas and filesystem' in Checkmk before Checkmk 2.3.0p15, 2.2.0p33, 2.1.0p48 and 2.0.0 (EOL) allows man-in-the-middle attackers to intercept traffic", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/09/GHSA-w4pv-qv3j-89ww/GHSA-w4pv-qv3j-89ww.json b/advisories/unreviewed/2024/09/GHSA-w4pv-qv3j-89ww/GHSA-w4pv-qv3j-89ww.json new file mode 100644 index 00000000000..13b4e971e57 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-w4pv-qv3j-89ww/GHSA-w4pv-qv3j-89ww.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w4pv-qv3j-89ww", + "modified": "2024-09-09T15:30:41Z", + "published": "2024-09-09T15:30:41Z", + "aliases": [ + "CVE-2024-7015" + ], + "details": "Improper Authentication, Missing Authentication for Critical Function, Improper Authorization vulnerability in Profelis Informatics and Consulting PassBox allows Authentication Abuse.This issue affects PassBox: before v1.2.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7015" + }, + { + "type": "WEB", + "url": "https://https://www.usom.gov.tr/bildirim/tr-24-1418" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-285" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-09T14:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-whxv-xf4j-48r5/GHSA-whxv-xf4j-48r5.json b/advisories/unreviewed/2024/09/GHSA-whxv-xf4j-48r5/GHSA-whxv-xf4j-48r5.json index 71854477811..5b9fd871c55 100644 --- a/advisories/unreviewed/2024/09/GHSA-whxv-xf4j-48r5/GHSA-whxv-xf4j-48r5.json +++ b/advisories/unreviewed/2024/09/GHSA-whxv-xf4j-48r5/GHSA-whxv-xf4j-48r5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-whxv-xf4j-48r5", - "modified": "2024-09-09T06:30:45Z", + "modified": "2024-09-09T15:30:40Z", "published": "2024-09-09T06:30:45Z", "aliases": [ "CVE-2024-7687" ], "details": "The AZIndex WordPress plugin through 0.8.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-09T06:15:02Z" diff --git a/advisories/unreviewed/2024/09/GHSA-wq3j-qfpm-h36f/GHSA-wq3j-qfpm-h36f.json b/advisories/unreviewed/2024/09/GHSA-wq3j-qfpm-h36f/GHSA-wq3j-qfpm-h36f.json index 00d5c8e26a1..defcfee425c 100644 --- a/advisories/unreviewed/2024/09/GHSA-wq3j-qfpm-h36f/GHSA-wq3j-qfpm-h36f.json +++ b/advisories/unreviewed/2024/09/GHSA-wq3j-qfpm-h36f/GHSA-wq3j-qfpm-h36f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wq3j-qfpm-h36f", - "modified": "2024-09-09T06:30:45Z", + "modified": "2024-09-09T15:30:40Z", "published": "2024-09-09T06:30:45Z", "aliases": [ "CVE-2024-6910" ], "details": "The EventON WordPress plugin before 2.2.17 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-09T06:15:02Z" diff --git a/advisories/unreviewed/2024/09/GHSA-wvqf-qcwj-mjxr/GHSA-wvqf-qcwj-mjxr.json b/advisories/unreviewed/2024/09/GHSA-wvqf-qcwj-mjxr/GHSA-wvqf-qcwj-mjxr.json index 959272f61c2..51feaa8885b 100644 --- a/advisories/unreviewed/2024/09/GHSA-wvqf-qcwj-mjxr/GHSA-wvqf-qcwj-mjxr.json +++ b/advisories/unreviewed/2024/09/GHSA-wvqf-qcwj-mjxr/GHSA-wvqf-qcwj-mjxr.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-918" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-xjcw-q83g-v2h5/GHSA-xjcw-q83g-v2h5.json b/advisories/unreviewed/2024/09/GHSA-xjcw-q83g-v2h5/GHSA-xjcw-q83g-v2h5.json new file mode 100644 index 00000000000..9f58a025cff --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-xjcw-q83g-v2h5/GHSA-xjcw-q83g-v2h5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xjcw-q83g-v2h5", + "modified": "2024-09-09T15:30:41Z", + "published": "2024-09-09T15:30:41Z", + "aliases": [ + "CVE-2024-8042" + ], + "details": "Rapid7 Insight Platform versions between November 2019 and August 14, 2024 suffer from missing authorization issues whereby an attacker can intercept local requests to set the name and description of a new user group. This could potentially lead to an empty user group being added to the incorrect customer. This vulnerability is remediated as of August 14, 2024.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:C/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8042" + }, + { + "type": "WEB", + "url": "https://cwe.mitre.org/data/definitions/862.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-09T15:15:12Z" + } +} \ No newline at end of file