diff --git a/advisories/unreviewed/2023/03/GHSA-263m-wfpm-g5hx/GHSA-263m-wfpm-g5hx.json b/advisories/unreviewed/2023/03/GHSA-263m-wfpm-g5hx/GHSA-263m-wfpm-g5hx.json new file mode 100644 index 00000000000..cd9c2c9eb8a --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-263m-wfpm-g5hx/GHSA-263m-wfpm-g5hx.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-263m-wfpm-g5hx", + "modified": "2023-03-28T21:30:20Z", + "published": "2023-03-28T21:30:20Z", + "aliases": [ + "CVE-2022-24907" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.1.0.52543. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JP2 images. Crafted data in a JP2 image can trigger a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16186.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-24907" + }, + { + "type": "WEB", + "url": "https://www.foxit.com/support/security-bulletins.html" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-350/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-2gcw-6fxx-2w99/GHSA-2gcw-6fxx-2w99.json b/advisories/unreviewed/2023/03/GHSA-2gcw-6fxx-2w99/GHSA-2gcw-6fxx-2w99.json new file mode 100644 index 00000000000..184d8b3ebb9 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-2gcw-6fxx-2w99/GHSA-2gcw-6fxx-2w99.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2gcw-6fxx-2w99", + "modified": "2023-03-28T21:30:16Z", + "published": "2023-03-28T21:30:16Z", + "aliases": [ + "CVE-2023-1676" + ], + "details": "A vulnerability was found in DriverGenius 9.70.0.346. It has been declared as critical. Affected by this vulnerability is the function 0x9C402088 in the library mydrivers64.sys of the component IOCTL Handler. The manipulation leads to memory corruption. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The identifier VDB-224233 was assigned to this vulnerability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1676" + }, + { + "type": "WEB", + "url": "https://drive.google.com/file/d/1kYCec3kYCzD9s2Vnclp_aW5jLneWqHC_/view" + }, + { + "type": "WEB", + "url": "https://github.com/zeze-zeze/WindowsKernelVuln/tree/master/unassigned27" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.224233" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.224233" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T21:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-2mqm-qfgv-7589/GHSA-2mqm-qfgv-7589.json b/advisories/unreviewed/2023/03/GHSA-2mqm-qfgv-7589/GHSA-2mqm-qfgv-7589.json new file mode 100644 index 00000000000..2ccc07aae92 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-2mqm-qfgv-7589/GHSA-2mqm-qfgv-7589.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2mqm-qfgv-7589", + "modified": "2023-03-28T21:30:18Z", + "published": "2023-03-28T21:30:18Z", + "aliases": [ + "CVE-2023-26342" + ], + "details": "Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26342" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/dimension/apsb23-20.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-382v-24ph-q459/GHSA-382v-24ph-q459.json b/advisories/unreviewed/2023/03/GHSA-382v-24ph-q459/GHSA-382v-24ph-q459.json new file mode 100644 index 00000000000..eccccf189fd --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-382v-24ph-q459/GHSA-382v-24ph-q459.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-382v-24ph-q459", + "modified": "2023-03-28T21:30:18Z", + "published": "2023-03-28T21:30:18Z", + "aliases": [ + "CVE-2023-26340" + ], + "details": "Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26340" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/dimension/apsb23-20.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-399m-4fj8-h7wr/GHSA-399m-4fj8-h7wr.json b/advisories/unreviewed/2023/03/GHSA-399m-4fj8-h7wr/GHSA-399m-4fj8-h7wr.json new file mode 100644 index 00000000000..f05f1209abc --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-399m-4fj8-h7wr/GHSA-399m-4fj8-h7wr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-399m-4fj8-h7wr", + "modified": "2023-03-28T21:30:19Z", + "published": "2023-03-28T21:30:19Z", + "aliases": [ + "CVE-2023-25899" + ], + "details": "Adobe Dimension versions 3.4.7 (and earlier) is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25899" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/dimension/apsb23-20.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-3fm4-2j55-fwvw/GHSA-3fm4-2j55-fwvw.json b/advisories/unreviewed/2023/03/GHSA-3fm4-2j55-fwvw/GHSA-3fm4-2j55-fwvw.json new file mode 100644 index 00000000000..d791af7a9b9 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-3fm4-2j55-fwvw/GHSA-3fm4-2j55-fwvw.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3fm4-2j55-fwvw", + "modified": "2023-03-28T21:30:20Z", + "published": "2023-03-28T21:30:20Z", + "aliases": [ + "CVE-2022-23124" + ], + "details": "This vulnerability allows remote attackers to disclose sensitive information on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the get_finderinfo method. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of root. Was ZDI-CAN-15870.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-23124" + }, + { + "type": "WEB", + "url": "https://netatalk.sourceforge.io/3.1/ReleaseNotes3.1.13.html" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-525/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-42gj-c2xf-3m98/GHSA-42gj-c2xf-3m98.json b/advisories/unreviewed/2023/03/GHSA-42gj-c2xf-3m98/GHSA-42gj-c2xf-3m98.json index 56389be0d4f..97788241d4a 100644 --- a/advisories/unreviewed/2023/03/GHSA-42gj-c2xf-3m98/GHSA-42gj-c2xf-3m98.json +++ b/advisories/unreviewed/2023/03/GHSA-42gj-c2xf-3m98/GHSA-42gj-c2xf-3m98.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-42gj-c2xf-3m98", - "modified": "2023-03-24T00:30:15Z", + "modified": "2023-03-28T21:30:17Z", "published": "2023-03-24T00:30:15Z", "aliases": [ "CVE-2023-24295" ], "details": "A stack overfow in SoftMaker Software GmbH FlexiPDF v3.0.3.0 allows attackers to execute arbitrary code after opening a crafted PDF file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-23T22:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-43jv-rf9m-vfp4/GHSA-43jv-rf9m-vfp4.json b/advisories/unreviewed/2023/03/GHSA-43jv-rf9m-vfp4/GHSA-43jv-rf9m-vfp4.json new file mode 100644 index 00000000000..6baa0b82be7 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-43jv-rf9m-vfp4/GHSA-43jv-rf9m-vfp4.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-43jv-rf9m-vfp4", + "modified": "2023-03-28T21:30:16Z", + "published": "2023-03-28T21:30:16Z", + "aliases": [ + "CVE-2023-28712" + ], + "details": "Osprey Pump Controller version 1.01 contains an unauthenticated command injection vulnerability that could allow system access with www-data permissions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28712" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-23-082-06" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T21:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-48pj-v95r-xh7w/GHSA-48pj-v95r-xh7w.json b/advisories/unreviewed/2023/03/GHSA-48pj-v95r-xh7w/GHSA-48pj-v95r-xh7w.json new file mode 100644 index 00000000000..02502416933 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-48pj-v95r-xh7w/GHSA-48pj-v95r-xh7w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-48pj-v95r-xh7w", + "modified": "2023-03-28T21:30:18Z", + "published": "2023-03-28T21:30:18Z", + "aliases": [ + "CVE-2023-26331" + ], + "details": "Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26331" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/dimension/apsb23-20.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-4g9j-67qh-w827/GHSA-4g9j-67qh-w827.json b/advisories/unreviewed/2023/03/GHSA-4g9j-67qh-w827/GHSA-4g9j-67qh-w827.json new file mode 100644 index 00000000000..125ecbb2fda --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-4g9j-67qh-w827/GHSA-4g9j-67qh-w827.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4g9j-67qh-w827", + "modified": "2023-03-28T21:30:19Z", + "published": "2023-03-28T21:30:19Z", + "aliases": [ + "CVE-2023-25887" + ], + "details": "Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25887" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/dimension/apsb23-20.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-4j6r-65gx-cpfx/GHSA-4j6r-65gx-cpfx.json b/advisories/unreviewed/2023/03/GHSA-4j6r-65gx-cpfx/GHSA-4j6r-65gx-cpfx.json index 92a9f9619c7..a074e6619d6 100644 --- a/advisories/unreviewed/2023/03/GHSA-4j6r-65gx-cpfx/GHSA-4j6r-65gx-cpfx.json +++ b/advisories/unreviewed/2023/03/GHSA-4j6r-65gx-cpfx/GHSA-4j6r-65gx-cpfx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4j6r-65gx-cpfx", - "modified": "2023-03-24T21:30:50Z", + "modified": "2023-03-28T21:30:18Z", "published": "2023-03-24T21:30:50Z", "aliases": [ "CVE-2023-20980" ], "details": "In btu_ble_ll_conn_param_upd_evt of btu_hcif.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure in the Bluetooth server with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-260230274", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-24T20:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-4mpv-9j83-cm3q/GHSA-4mpv-9j83-cm3q.json b/advisories/unreviewed/2023/03/GHSA-4mpv-9j83-cm3q/GHSA-4mpv-9j83-cm3q.json new file mode 100644 index 00000000000..ed5d09aeaa2 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-4mpv-9j83-cm3q/GHSA-4mpv-9j83-cm3q.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4mpv-9j83-cm3q", + "modified": "2023-03-28T21:30:16Z", + "published": "2023-03-28T21:30:16Z", + "aliases": [ + "CVE-2023-28648" + ], + "details": "Osprey Pump Controller version 1.01 inputs passed to a GET parameter are not properly sanitized before being returned to the user. This can be exploited to execute arbitrary HTML/JS code in a user's browser session in context of an affected site.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28648" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-23-082-06" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T21:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-4qr8-cxh4-rc4h/GHSA-4qr8-cxh4-rc4h.json b/advisories/unreviewed/2023/03/GHSA-4qr8-cxh4-rc4h/GHSA-4qr8-cxh4-rc4h.json new file mode 100644 index 00000000000..428a4572269 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-4qr8-cxh4-rc4h/GHSA-4qr8-cxh4-rc4h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4qr8-cxh4-rc4h", + "modified": "2023-03-28T21:30:18Z", + "published": "2023-03-28T21:30:18Z", + "aliases": [ + "CVE-2023-26345" + ], + "details": "Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26345" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/dimension/apsb23-20.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-52gc-5pjh-wc34/GHSA-52gc-5pjh-wc34.json b/advisories/unreviewed/2023/03/GHSA-52gc-5pjh-wc34/GHSA-52gc-5pjh-wc34.json new file mode 100644 index 00000000000..f099790abac --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-52gc-5pjh-wc34/GHSA-52gc-5pjh-wc34.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-52gc-5pjh-wc34", + "modified": "2023-03-28T21:30:20Z", + "published": "2023-03-28T21:30:20Z", + "aliases": [ + "CVE-2022-24353" + ], + "details": "This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link AC1750 1.1.4 Build 20211022 rel.59103(5553) routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the NetUSB.ko module. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the root user. Was ZDI-CAN-15769.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-24353" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-263/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-54cv-wj74-27xr/GHSA-54cv-wj74-27xr.json b/advisories/unreviewed/2023/03/GHSA-54cv-wj74-27xr/GHSA-54cv-wj74-27xr.json new file mode 100644 index 00000000000..bfca4162db1 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-54cv-wj74-27xr/GHSA-54cv-wj74-27xr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-54cv-wj74-27xr", + "modified": "2023-03-28T21:30:18Z", + "published": "2023-03-28T21:30:18Z", + "aliases": [ + "CVE-2023-26335" + ], + "details": "Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26335" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/dimension/apsb23-20.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-556w-jh9r-fpj3/GHSA-556w-jh9r-fpj3.json b/advisories/unreviewed/2023/03/GHSA-556w-jh9r-fpj3/GHSA-556w-jh9r-fpj3.json index b8d33519cb2..392f39cd3e7 100644 --- a/advisories/unreviewed/2023/03/GHSA-556w-jh9r-fpj3/GHSA-556w-jh9r-fpj3.json +++ b/advisories/unreviewed/2023/03/GHSA-556w-jh9r-fpj3/GHSA-556w-jh9r-fpj3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-556w-jh9r-fpj3", - "modified": "2023-03-24T21:30:50Z", + "modified": "2023-03-28T21:30:20Z", "published": "2023-03-24T21:30:50Z", "aliases": [ "CVE-2023-20968" ], "details": "In multiple locations of p2p_iface.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-262235935", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-24T20:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-56f4-gq77-grmv/GHSA-56f4-gq77-grmv.json b/advisories/unreviewed/2023/03/GHSA-56f4-gq77-grmv/GHSA-56f4-gq77-grmv.json index 1cdaef75e6f..aa7cfccda6c 100644 --- a/advisories/unreviewed/2023/03/GHSA-56f4-gq77-grmv/GHSA-56f4-gq77-grmv.json +++ b/advisories/unreviewed/2023/03/GHSA-56f4-gq77-grmv/GHSA-56f4-gq77-grmv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-56f4-gq77-grmv", - "modified": "2023-03-24T21:30:50Z", + "modified": "2023-03-28T21:30:20Z", "published": "2023-03-24T21:30:50Z", "aliases": [ "CVE-2023-20970" ], "details": "In multiple locations of p2p_iface.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-262236005", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-24T20:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-5h4q-7v83-2cp6/GHSA-5h4q-7v83-2cp6.json b/advisories/unreviewed/2023/03/GHSA-5h4q-7v83-2cp6/GHSA-5h4q-7v83-2cp6.json index 64e8abdaf9b..fabbdcdfbd8 100644 --- a/advisories/unreviewed/2023/03/GHSA-5h4q-7v83-2cp6/GHSA-5h4q-7v83-2cp6.json +++ b/advisories/unreviewed/2023/03/GHSA-5h4q-7v83-2cp6/GHSA-5h4q-7v83-2cp6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5h4q-7v83-2cp6", - "modified": "2023-03-22T21:30:16Z", + "modified": "2023-03-28T21:30:21Z", "published": "2023-03-22T21:30:16Z", "aliases": [ "CVE-2023-28659" ], "details": "The Waiting: One-click Countdowns WordPress Plugin, version <= 0.6.2, is affected by an authenticated SQL injection vulnerability in the pbc_down[meta][id] parameter of the pbc_save_downs action.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-22T21:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-5qh8-94r2-76g9/GHSA-5qh8-94r2-76g9.json b/advisories/unreviewed/2023/03/GHSA-5qh8-94r2-76g9/GHSA-5qh8-94r2-76g9.json new file mode 100644 index 00000000000..9f9fda47ed7 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-5qh8-94r2-76g9/GHSA-5qh8-94r2-76g9.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5qh8-94r2-76g9", + "modified": "2023-03-28T21:30:17Z", + "published": "2023-03-28T21:30:17Z", + "aliases": [ + "CVE-2023-1518" + ], + "details": "CP Plus KVMS Pro versions 2.01.0.T.190521 and prior are vulnerable to sensitive credentials being leaked because they are insufficiently protected.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1518" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-23-082-02" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T21:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-5rqc-wqwj-478f/GHSA-5rqc-wqwj-478f.json b/advisories/unreviewed/2023/03/GHSA-5rqc-wqwj-478f/GHSA-5rqc-wqwj-478f.json new file mode 100644 index 00000000000..876fe964f99 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-5rqc-wqwj-478f/GHSA-5rqc-wqwj-478f.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5rqc-wqwj-478f", + "modified": "2023-03-28T21:30:16Z", + "published": "2023-03-28T21:30:16Z", + "aliases": [ + "CVE-2023-20903" + ], + "details": "This disclosure regards a vulnerability related to UAA refresh tokens and external identity providers.Assuming that an external identity provider is linked to the UAA, a refresh token is issued to a client on behalf of a user from that identity provider, the administrator of the UAA deactivates the identity provider from the UAA. It is expected that the UAA would reject a refresh token during a refresh token grant, but it does not (hence the vulnerability). It will continue to issue access tokens to request presenting such refresh tokens, as if the identity provider was still active. As a result, clients with refresh tokens issued through the deactivated identity provider would still have access to Cloud Foundry resources until their refresh token expires (which defaults to 30 days).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-20903" + }, + { + "type": "WEB", + "url": "https://www.cloudfoundry.org/blog/cve-2023-20903-tokens-for-inactivated-idps-are-not-revoked-and-remain-valid-until-expiration/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T21:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-63wp-2cpc-rcwf/GHSA-63wp-2cpc-rcwf.json b/advisories/unreviewed/2023/03/GHSA-63wp-2cpc-rcwf/GHSA-63wp-2cpc-rcwf.json index 2808c8cdbfc..e718b814650 100644 --- a/advisories/unreviewed/2023/03/GHSA-63wp-2cpc-rcwf/GHSA-63wp-2cpc-rcwf.json +++ b/advisories/unreviewed/2023/03/GHSA-63wp-2cpc-rcwf/GHSA-63wp-2cpc-rcwf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-63wp-2cpc-rcwf", - "modified": "2023-03-22T15:30:20Z", + "modified": "2023-03-28T21:30:21Z", "published": "2023-03-22T15:30:20Z", "aliases": [ "CVE-2023-1571" ], "details": "A vulnerability, which was classified as critical, was found in DataGear up to 4.5.0. This affects an unknown part of the file /analysisProject/pagingQueryData. The manipulation of the argument queryOrder leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 4.5.1 is able to address this issue. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-223563.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-22T15:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-66g8-4pj2-65hv/GHSA-66g8-4pj2-65hv.json b/advisories/unreviewed/2023/03/GHSA-66g8-4pj2-65hv/GHSA-66g8-4pj2-65hv.json new file mode 100644 index 00000000000..f266de7f77b --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-66g8-4pj2-65hv/GHSA-66g8-4pj2-65hv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-66g8-4pj2-65hv", + "modified": "2023-03-28T21:30:19Z", + "published": "2023-03-28T21:30:19Z", + "aliases": [ + "CVE-2023-25902" + ], + "details": "Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25902" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/dimension/apsb23-20.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-6rf3-h8vx-h8mv/GHSA-6rf3-h8vx-h8mv.json b/advisories/unreviewed/2023/03/GHSA-6rf3-h8vx-h8mv/GHSA-6rf3-h8vx-h8mv.json new file mode 100644 index 00000000000..eef2418e00d --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-6rf3-h8vx-h8mv/GHSA-6rf3-h8vx-h8mv.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6rf3-h8vx-h8mv", + "modified": "2023-03-28T21:30:20Z", + "published": "2023-03-28T21:30:20Z", + "aliases": [ + "CVE-2022-24908" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.1.0.52543. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JP2 images. Crafted data in a JP2 image can trigger a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16187.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-24908" + }, + { + "type": "WEB", + "url": "https://www.foxit.com/support/security-bulletins.html" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-351/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-6rfx-cr35-r87p/GHSA-6rfx-cr35-r87p.json b/advisories/unreviewed/2023/03/GHSA-6rfx-cr35-r87p/GHSA-6rfx-cr35-r87p.json new file mode 100644 index 00000000000..d876bffb1fd --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-6rfx-cr35-r87p/GHSA-6rfx-cr35-r87p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6rfx-cr35-r87p", + "modified": "2023-03-28T21:30:19Z", + "published": "2023-03-28T21:30:19Z", + "aliases": [ + "CVE-2023-25883" + ], + "details": "Adobe Dimension versions 3.4.7 (and earlier) is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25883" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/dimension/apsb23-20.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-6v85-xmc7-gr5h/GHSA-6v85-xmc7-gr5h.json b/advisories/unreviewed/2023/03/GHSA-6v85-xmc7-gr5h/GHSA-6v85-xmc7-gr5h.json new file mode 100644 index 00000000000..3ab8b456d1e --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-6v85-xmc7-gr5h/GHSA-6v85-xmc7-gr5h.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6v85-xmc7-gr5h", + "modified": "2023-03-28T21:30:16Z", + "published": "2023-03-28T21:30:16Z", + "aliases": [ + "CVE-2023-28654" + ], + "details": "Osprey Pump Controller version 1.01 has a hidden administrative account that has the hardcoded password that allows full access to the web management interface configuration. The user is not visible in Usernames and Passwords menu list of the application and the password cannot be changed through any normal operation of the device.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28654" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-23-082-06" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T21:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-72hp-959x-6xcw/GHSA-72hp-959x-6xcw.json b/advisories/unreviewed/2023/03/GHSA-72hp-959x-6xcw/GHSA-72hp-959x-6xcw.json new file mode 100644 index 00000000000..7c91f252eae --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-72hp-959x-6xcw/GHSA-72hp-959x-6xcw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-72hp-959x-6xcw", + "modified": "2023-03-28T21:30:19Z", + "published": "2023-03-28T21:30:19Z", + "aliases": [ + "CVE-2023-25881" + ], + "details": "Adobe Dimension versions 3.4.7 (and earlier) is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25881" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/dimension/apsb23-20.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-74h5-c7r2-qfwr/GHSA-74h5-c7r2-qfwr.json b/advisories/unreviewed/2023/03/GHSA-74h5-c7r2-qfwr/GHSA-74h5-c7r2-qfwr.json index 28932ddcc05..c84322e34ac 100644 --- a/advisories/unreviewed/2023/03/GHSA-74h5-c7r2-qfwr/GHSA-74h5-c7r2-qfwr.json +++ b/advisories/unreviewed/2023/03/GHSA-74h5-c7r2-qfwr/GHSA-74h5-c7r2-qfwr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-74h5-c7r2-qfwr", - "modified": "2023-03-24T21:30:50Z", + "modified": "2023-03-28T21:30:20Z", "published": "2023-03-24T21:30:50Z", "aliases": [ "CVE-2023-20971" ], "details": "In updatePermissionTreeSourcePackage of PermissionManagerServiceImpl.java, there is a possible way to obtain dangerous permission without the user's consent due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-225880325", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-24T20:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-76hr-hr87-x887/GHSA-76hr-hr87-x887.json b/advisories/unreviewed/2023/03/GHSA-76hr-hr87-x887/GHSA-76hr-hr87-x887.json new file mode 100644 index 00000000000..e486ac5e380 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-76hr-hr87-x887/GHSA-76hr-hr87-x887.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-76hr-hr87-x887", + "modified": "2023-03-28T21:30:20Z", + "published": "2023-03-28T21:30:20Z", + "aliases": [ + "CVE-2022-24972" + ], + "details": "This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link TL-WR940N 3.20.1 Build 200316 Rel.34392n (5553) routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the httpd service, which listens on TCP port 80 by default. The issue results from the lack of proper access control. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-13911.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-24972" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-405/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-78q9-q3h9-qcp9/GHSA-78q9-q3h9-qcp9.json b/advisories/unreviewed/2023/03/GHSA-78q9-q3h9-qcp9/GHSA-78q9-q3h9-qcp9.json index c5aaba963b7..336bbcb0862 100644 --- a/advisories/unreviewed/2023/03/GHSA-78q9-q3h9-qcp9/GHSA-78q9-q3h9-qcp9.json +++ b/advisories/unreviewed/2023/03/GHSA-78q9-q3h9-qcp9/GHSA-78q9-q3h9-qcp9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-78q9-q3h9-qcp9", - "modified": "2023-03-24T21:30:50Z", + "modified": "2023-03-28T21:30:21Z", "published": "2023-03-24T21:30:50Z", "aliases": [ "CVE-2023-20959" ], "details": "In AddSupervisedUserActivity, guest users are not prevented from starting the activity due to missing permissions checks. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-249057848", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-24T20:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-799c-g7rj-xf44/GHSA-799c-g7rj-xf44.json b/advisories/unreviewed/2023/03/GHSA-799c-g7rj-xf44/GHSA-799c-g7rj-xf44.json new file mode 100644 index 00000000000..11170b2ba04 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-799c-g7rj-xf44/GHSA-799c-g7rj-xf44.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-799c-g7rj-xf44", + "modified": "2023-03-28T21:30:17Z", + "published": "2023-03-28T21:30:17Z", + "aliases": [ + "CVE-2023-1516" + ], + "details": "RoboDK versions 5.5.3 and prior contain an insecure permission assignment to critical directories vulnerability, which could allow a local user to escalate privileges and write files to the RoboDK process and achieve code execution.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1516" + }, + { + "type": "WEB", + "url": "https://robodk.com/contact" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-23-082-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T21:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-7jr7-v6gv-m656/GHSA-7jr7-v6gv-m656.json b/advisories/unreviewed/2023/03/GHSA-7jr7-v6gv-m656/GHSA-7jr7-v6gv-m656.json index d2ef1fe2332..2591806abb7 100644 --- a/advisories/unreviewed/2023/03/GHSA-7jr7-v6gv-m656/GHSA-7jr7-v6gv-m656.json +++ b/advisories/unreviewed/2023/03/GHSA-7jr7-v6gv-m656/GHSA-7jr7-v6gv-m656.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7jr7-v6gv-m656", - "modified": "2023-03-24T00:30:15Z", + "modified": "2023-03-28T21:30:17Z", "published": "2023-03-24T00:30:15Z", "aliases": [ "CVE-2023-27034" ], "details": "PrestaShop jmsblog 2.5.5 was discovered to contain a SQL injection vulnerability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-23T22:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-87cj-g83v-hmpg/GHSA-87cj-g83v-hmpg.json b/advisories/unreviewed/2023/03/GHSA-87cj-g83v-hmpg/GHSA-87cj-g83v-hmpg.json new file mode 100644 index 00000000000..26b5ddb5cd7 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-87cj-g83v-hmpg/GHSA-87cj-g83v-hmpg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-87cj-g83v-hmpg", + "modified": "2023-03-28T21:30:19Z", + "published": "2023-03-28T21:30:19Z", + "aliases": [ + "CVE-2023-25886" + ], + "details": "Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25886" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/dimension/apsb23-20.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-8cm2-f4g9-wjfm/GHSA-8cm2-f4g9-wjfm.json b/advisories/unreviewed/2023/03/GHSA-8cm2-f4g9-wjfm/GHSA-8cm2-f4g9-wjfm.json new file mode 100644 index 00000000000..dc3deddcdf6 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-8cm2-f4g9-wjfm/GHSA-8cm2-f4g9-wjfm.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8cm2-f4g9-wjfm", + "modified": "2023-03-28T21:30:20Z", + "published": "2023-03-28T21:30:20Z", + "aliases": [ + "CVE-2022-23121" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the parse_entries function. The issue results from the lack of proper error handling when parsing AppleDouble entries. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-15819.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-23121" + }, + { + "type": "WEB", + "url": "https://netatalk.sourceforge.io/3.1/ReleaseNotes3.1.13.html" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-527/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-755" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-8hcp-5m8x-6x78/GHSA-8hcp-5m8x-6x78.json b/advisories/unreviewed/2023/03/GHSA-8hcp-5m8x-6x78/GHSA-8hcp-5m8x-6x78.json new file mode 100644 index 00000000000..876949eb545 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-8hcp-5m8x-6x78/GHSA-8hcp-5m8x-6x78.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8hcp-5m8x-6x78", + "modified": "2023-03-28T21:30:19Z", + "published": "2023-03-28T21:30:19Z", + "aliases": [ + "CVE-2023-25900" + ], + "details": "Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25900" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/dimension/apsb23-20.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-8q3v-wq9h-7767/GHSA-8q3v-wq9h-7767.json b/advisories/unreviewed/2023/03/GHSA-8q3v-wq9h-7767/GHSA-8q3v-wq9h-7767.json new file mode 100644 index 00000000000..5ea51f230a4 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-8q3v-wq9h-7767/GHSA-8q3v-wq9h-7767.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8q3v-wq9h-7767", + "modified": "2023-03-28T21:30:18Z", + "published": "2023-03-28T21:30:18Z", + "aliases": [ + "CVE-2023-26343" + ], + "details": "Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26343" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/dimension/apsb23-20.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-8rqh-6cxp-qmqj/GHSA-8rqh-6cxp-qmqj.json b/advisories/unreviewed/2023/03/GHSA-8rqh-6cxp-qmqj/GHSA-8rqh-6cxp-qmqj.json new file mode 100644 index 00000000000..341950c65ca --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-8rqh-6cxp-qmqj/GHSA-8rqh-6cxp-qmqj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8rqh-6cxp-qmqj", + "modified": "2023-03-28T21:30:18Z", + "published": "2023-03-28T21:30:18Z", + "aliases": [ + "CVE-2023-26351" + ], + "details": "Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26351" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/dimension/apsb23-20.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-8x8m-c4qf-453q/GHSA-8x8m-c4qf-453q.json b/advisories/unreviewed/2023/03/GHSA-8x8m-c4qf-453q/GHSA-8x8m-c4qf-453q.json new file mode 100644 index 00000000000..63dcac2ec0c --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-8x8m-c4qf-453q/GHSA-8x8m-c4qf-453q.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8x8m-c4qf-453q", + "modified": "2023-03-28T21:30:20Z", + "published": "2023-03-28T21:30:20Z", + "aliases": [ + "CVE-2022-23123" + ], + "details": "This vulnerability allows remote attackers to disclose sensitive information on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the getdirparams method. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of root. Was ZDI-CAN-15830.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-23123" + }, + { + "type": "WEB", + "url": "https://netatalk.sourceforge.io/3.1/ReleaseNotes3.1.13.html" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-528/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-94w5-83fg-vhgc/GHSA-94w5-83fg-vhgc.json b/advisories/unreviewed/2023/03/GHSA-94w5-83fg-vhgc/GHSA-94w5-83fg-vhgc.json new file mode 100644 index 00000000000..cf09957f214 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-94w5-83fg-vhgc/GHSA-94w5-83fg-vhgc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-94w5-83fg-vhgc", + "modified": "2023-03-28T21:30:18Z", + "published": "2023-03-28T21:30:17Z", + "aliases": [ + "CVE-2023-28395" + ], + "details": "Osprey Pump Controller version 1.01 is vulnerable to a weak session token generation algorithm that can be predicted and can aid in authentication and authorization bypass. This may allow an attacker to hijack a session by predicting the session id and gain unauthorized access to the product.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28395" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-23-082-06" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-9c49-3qrv-gxfp/GHSA-9c49-3qrv-gxfp.json b/advisories/unreviewed/2023/03/GHSA-9c49-3qrv-gxfp/GHSA-9c49-3qrv-gxfp.json index 94c71320c5d..fb081d25401 100644 --- a/advisories/unreviewed/2023/03/GHSA-9c49-3qrv-gxfp/GHSA-9c49-3qrv-gxfp.json +++ b/advisories/unreviewed/2023/03/GHSA-9c49-3qrv-gxfp/GHSA-9c49-3qrv-gxfp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9c49-3qrv-gxfp", - "modified": "2023-03-22T21:30:16Z", + "modified": "2023-03-28T21:30:20Z", "published": "2023-03-22T21:30:16Z", "aliases": [ "CVE-2023-28662" ], "details": "The Gift Cards (Gift Vouchers and Packages) WordPress Plugin, version <= 4.3.1, is affected by an unauthenticated SQL injection vulnerability in the template parameter in the wpgv_doajax_voucher_pdf_save_func action.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-22T21:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-9gx3-68p2-gppf/GHSA-9gx3-68p2-gppf.json b/advisories/unreviewed/2023/03/GHSA-9gx3-68p2-gppf/GHSA-9gx3-68p2-gppf.json new file mode 100644 index 00000000000..be2989eac71 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-9gx3-68p2-gppf/GHSA-9gx3-68p2-gppf.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9gx3-68p2-gppf", + "modified": "2023-03-28T21:30:16Z", + "published": "2023-03-28T21:30:16Z", + "aliases": [ + "CVE-2023-28375" + ], + "details": "Osprey Pump Controller version 1.01 is vulnerable to an unauthenticated file disclosure. Using a GET parameter, attackers can disclose arbitrary files on the affected device and disclose sensitive and system information.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28375" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-23-082-06" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T21:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-9mqw-qgfr-x8hp/GHSA-9mqw-qgfr-x8hp.json b/advisories/unreviewed/2023/03/GHSA-9mqw-qgfr-x8hp/GHSA-9mqw-qgfr-x8hp.json new file mode 100644 index 00000000000..3ad48affcfe --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-9mqw-qgfr-x8hp/GHSA-9mqw-qgfr-x8hp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9mqw-qgfr-x8hp", + "modified": "2023-03-28T21:30:19Z", + "published": "2023-03-28T21:30:19Z", + "aliases": [ + "CVE-2023-25894" + ], + "details": "Adobe Dimension versions 3.4.7 (and earlier) is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25894" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/dimension/apsb23-20.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-9rvq-gvfr-jc9c/GHSA-9rvq-gvfr-jc9c.json b/advisories/unreviewed/2023/03/GHSA-9rvq-gvfr-jc9c/GHSA-9rvq-gvfr-jc9c.json new file mode 100644 index 00000000000..664a1710106 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-9rvq-gvfr-jc9c/GHSA-9rvq-gvfr-jc9c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9rvq-gvfr-jc9c", + "modified": "2023-03-28T21:30:19Z", + "published": "2023-03-28T21:30:19Z", + "aliases": [ + "CVE-2023-25885" + ], + "details": "Adobe Dimension versions 3.4.7 (and earlier) is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25885" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/dimension/apsb23-20.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-9v46-jrv7-p6fh/GHSA-9v46-jrv7-p6fh.json b/advisories/unreviewed/2023/03/GHSA-9v46-jrv7-p6fh/GHSA-9v46-jrv7-p6fh.json new file mode 100644 index 00000000000..1e4e32f8d6d --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-9v46-jrv7-p6fh/GHSA-9v46-jrv7-p6fh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9v46-jrv7-p6fh", + "modified": "2023-03-28T21:30:19Z", + "published": "2023-03-28T21:30:19Z", + "aliases": [ + "CVE-2023-26329" + ], + "details": "Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26329" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/dimension/apsb23-20.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-9xf5-74jv-q5q9/GHSA-9xf5-74jv-q5q9.json b/advisories/unreviewed/2023/03/GHSA-9xf5-74jv-q5q9/GHSA-9xf5-74jv-q5q9.json new file mode 100644 index 00000000000..afe1ab2327e --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-9xf5-74jv-q5q9/GHSA-9xf5-74jv-q5q9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9xf5-74jv-q5q9", + "modified": "2023-03-28T21:30:19Z", + "published": "2023-03-28T21:30:19Z", + "aliases": [ + "CVE-2023-25891" + ], + "details": "Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25891" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/dimension/apsb23-20.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-9xmf-4p3w-hc8w/GHSA-9xmf-4p3w-hc8w.json b/advisories/unreviewed/2023/03/GHSA-9xmf-4p3w-hc8w/GHSA-9xmf-4p3w-hc8w.json index 191dd2db00f..e6e92bbb4ec 100644 --- a/advisories/unreviewed/2023/03/GHSA-9xmf-4p3w-hc8w/GHSA-9xmf-4p3w-hc8w.json +++ b/advisories/unreviewed/2023/03/GHSA-9xmf-4p3w-hc8w/GHSA-9xmf-4p3w-hc8w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9xmf-4p3w-hc8w", - "modified": "2023-03-23T21:30:17Z", + "modified": "2023-03-28T21:30:17Z", "published": "2023-03-23T21:30:17Z", "aliases": [ "CVE-2023-28611" ], "details": "Incorrect authorization in OMICRON StationGuard 1.10 through 2.20 and StationScout 1.30 through 2.20 allows an attacker to bypass intended access restrictions.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-23T21:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-c4jr-vjm4-27hq/GHSA-c4jr-vjm4-27hq.json b/advisories/unreviewed/2023/03/GHSA-c4jr-vjm4-27hq/GHSA-c4jr-vjm4-27hq.json new file mode 100644 index 00000000000..da70f44c123 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-c4jr-vjm4-27hq/GHSA-c4jr-vjm4-27hq.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c4jr-vjm4-27hq", + "modified": "2023-03-28T21:30:20Z", + "published": "2023-03-28T21:30:20Z", + "aliases": [ + "CVE-2023-25721" + ], + "details": "Veracode Scan Jenkins Plugin before 23.3.19.0, when the \"Connect using proxy\" option is enabled and configured with proxy credentials and when the Jenkins global system setting debug is enabled and when a scan is configured for remote agent jobs, allows users (with access to view the job log) to discover proxy credentials.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25721" + }, + { + "type": "WEB", + "url": "https://docs.veracode.com/updates/r/c_all_int#veracode-jenkins-plugin-233190" + }, + { + "type": "WEB", + "url": "https://veracode.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-c4mr-95m6-w2mf/GHSA-c4mr-95m6-w2mf.json b/advisories/unreviewed/2023/03/GHSA-c4mr-95m6-w2mf/GHSA-c4mr-95m6-w2mf.json new file mode 100644 index 00000000000..d2dc2b4e1f2 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-c4mr-95m6-w2mf/GHSA-c4mr-95m6-w2mf.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c4mr-95m6-w2mf", + "modified": "2023-03-28T21:30:19Z", + "published": "2023-03-28T21:30:19Z", + "aliases": [ + "CVE-2023-26071" + ], + "details": "An issue was discovered in MCUBO ICT through 10.12.4 (aka 6.0.2). An Observable Response Discrepancy can occur under the login web page. In particular, the web application provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor. That allow an unauthorized actor to perform User Enumeration attacks.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26071" + }, + { + "type": "WEB", + "url": "https://www.gruppotim.it/it/footer/red-team.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-c55h-3vqx-vr2v/GHSA-c55h-3vqx-vr2v.json b/advisories/unreviewed/2023/03/GHSA-c55h-3vqx-vr2v/GHSA-c55h-3vqx-vr2v.json new file mode 100644 index 00000000000..74e1abc2a89 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-c55h-3vqx-vr2v/GHSA-c55h-3vqx-vr2v.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c55h-3vqx-vr2v", + "modified": "2023-03-28T21:30:20Z", + "published": "2023-03-28T21:30:20Z", + "aliases": [ + "CVE-2022-0650" + ], + "details": "This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link TL-WR940N 3.20.1 Build 200316 Rel.34392n (5553) routers. Authentication is required to exploit this vulnerability. The specific flaw exists within the httpd service, which listens on TCP port 80 by default. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-13993.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-0650" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-407/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-c5vq-cgx6-878h/GHSA-c5vq-cgx6-878h.json b/advisories/unreviewed/2023/03/GHSA-c5vq-cgx6-878h/GHSA-c5vq-cgx6-878h.json index a9db8dca057..7f0b1b8ba68 100644 --- a/advisories/unreviewed/2023/03/GHSA-c5vq-cgx6-878h/GHSA-c5vq-cgx6-878h.json +++ b/advisories/unreviewed/2023/03/GHSA-c5vq-cgx6-878h/GHSA-c5vq-cgx6-878h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c5vq-cgx6-878h", - "modified": "2023-03-24T00:30:15Z", + "modified": "2023-03-28T21:30:17Z", "published": "2023-03-24T00:30:15Z", "aliases": [ "CVE-2020-24857" ], "details": "Cross Site Scripting vulnerabilty found in IXPManager v.5.6.0 allows attackers to excute arbitrary code via the looking glass component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-23T22:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-c9mm-8hj7-wg4j/GHSA-c9mm-8hj7-wg4j.json b/advisories/unreviewed/2023/03/GHSA-c9mm-8hj7-wg4j/GHSA-c9mm-8hj7-wg4j.json new file mode 100644 index 00000000000..35d9de20c79 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-c9mm-8hj7-wg4j/GHSA-c9mm-8hj7-wg4j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c9mm-8hj7-wg4j", + "modified": "2023-03-28T21:30:18Z", + "published": "2023-03-28T21:30:18Z", + "aliases": [ + "CVE-2023-26334" + ], + "details": "Adobe Dimension versions 3.4.7 (and earlier) is affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26334" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/dimension/apsb23-20.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-824" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-cm9f-v3w6-mpwh/GHSA-cm9f-v3w6-mpwh.json b/advisories/unreviewed/2023/03/GHSA-cm9f-v3w6-mpwh/GHSA-cm9f-v3w6-mpwh.json new file mode 100644 index 00000000000..df84ae30438 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-cm9f-v3w6-mpwh/GHSA-cm9f-v3w6-mpwh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cm9f-v3w6-mpwh", + "modified": "2023-03-28T21:30:18Z", + "published": "2023-03-28T21:30:18Z", + "aliases": [ + "CVE-2023-26341" + ], + "details": "Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26341" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/dimension/apsb23-20.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-cmhp-wmw8-6hrq/GHSA-cmhp-wmw8-6hrq.json b/advisories/unreviewed/2023/03/GHSA-cmhp-wmw8-6hrq/GHSA-cmhp-wmw8-6hrq.json new file mode 100644 index 00000000000..8885151b976 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-cmhp-wmw8-6hrq/GHSA-cmhp-wmw8-6hrq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cmhp-wmw8-6hrq", + "modified": "2023-03-28T21:30:19Z", + "published": "2023-03-28T21:30:19Z", + "aliases": [ + "CVE-2023-26328" + ], + "details": "Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26328" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/dimension/apsb23-20.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-cmj4-9f9m-cm6v/GHSA-cmj4-9f9m-cm6v.json b/advisories/unreviewed/2023/03/GHSA-cmj4-9f9m-cm6v/GHSA-cmj4-9f9m-cm6v.json index b460219ad09..10c372ccb94 100644 --- a/advisories/unreviewed/2023/03/GHSA-cmj4-9f9m-cm6v/GHSA-cmj4-9f9m-cm6v.json +++ b/advisories/unreviewed/2023/03/GHSA-cmj4-9f9m-cm6v/GHSA-cmj4-9f9m-cm6v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cmj4-9f9m-cm6v", - "modified": "2023-03-24T21:30:50Z", + "modified": "2023-03-28T21:30:17Z", "published": "2023-03-24T21:30:50Z", "aliases": [ "CVE-2023-20977" ], "details": "In btm_ble_read_remote_features_complete of btm_ble_gap.cc, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure if the firmware were compromised with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-254445952", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-24T20:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-cmvc-r236-g4fp/GHSA-cmvc-r236-g4fp.json b/advisories/unreviewed/2023/03/GHSA-cmvc-r236-g4fp/GHSA-cmvc-r236-g4fp.json index 72fc23d8216..15f862f4526 100644 --- a/advisories/unreviewed/2023/03/GHSA-cmvc-r236-g4fp/GHSA-cmvc-r236-g4fp.json +++ b/advisories/unreviewed/2023/03/GHSA-cmvc-r236-g4fp/GHSA-cmvc-r236-g4fp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cmvc-r236-g4fp", - "modified": "2023-03-22T21:30:15Z", + "modified": "2023-03-28T21:30:20Z", "published": "2023-03-22T21:30:15Z", "aliases": [ "CVE-2023-28667" ], "details": "The Lead Generated WordPress Plugin, version <= 1.23, was affected by an unauthenticated insecure deserialization issue. The tve_labels parameter of the tve_api_form_submit action is passed to the PHP unserialize() function without being sanitized or verified, and as a result could lead to PHP object injection, which when combined with certain class implementations / gadget chains could be leveraged to perform a variety of malicious actions granted a POP chain is also present.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-502" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-22T21:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-f2fq-wf2r-6w4v/GHSA-f2fq-wf2r-6w4v.json b/advisories/unreviewed/2023/03/GHSA-f2fq-wf2r-6w4v/GHSA-f2fq-wf2r-6w4v.json index b74b7c45d7f..b5d772e73d1 100644 --- a/advisories/unreviewed/2023/03/GHSA-f2fq-wf2r-6w4v/GHSA-f2fq-wf2r-6w4v.json +++ b/advisories/unreviewed/2023/03/GHSA-f2fq-wf2r-6w4v/GHSA-f2fq-wf2r-6w4v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f2fq-wf2r-6w4v", - "modified": "2023-03-24T21:30:49Z", + "modified": "2023-03-28T21:30:21Z", "published": "2023-03-24T21:30:49Z", "aliases": [ "CVE-2022-42499" ], "details": "In sms_SendMmCpErrMsg of sms_MmConManagement.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-242001391References: N/A", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-24T20:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-f3f4-gqch-h8hj/GHSA-f3f4-gqch-h8hj.json b/advisories/unreviewed/2023/03/GHSA-f3f4-gqch-h8hj/GHSA-f3f4-gqch-h8hj.json new file mode 100644 index 00000000000..97000f0f091 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-f3f4-gqch-h8hj/GHSA-f3f4-gqch-h8hj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f3f4-gqch-h8hj", + "modified": "2023-03-28T21:30:17Z", + "published": "2023-03-28T21:30:17Z", + "aliases": [ + "CVE-2023-26348" + ], + "details": "Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26348" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/dimension/apsb23-20.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-f9p9-jv2m-5p2j/GHSA-f9p9-jv2m-5p2j.json b/advisories/unreviewed/2023/03/GHSA-f9p9-jv2m-5p2j/GHSA-f9p9-jv2m-5p2j.json index 0c1a86e0e66..06b2d9b9971 100644 --- a/advisories/unreviewed/2023/03/GHSA-f9p9-jv2m-5p2j/GHSA-f9p9-jv2m-5p2j.json +++ b/advisories/unreviewed/2023/03/GHSA-f9p9-jv2m-5p2j/GHSA-f9p9-jv2m-5p2j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f9p9-jv2m-5p2j", - "modified": "2023-03-23T03:30:25Z", + "modified": "2023-03-28T21:30:18Z", "published": "2023-03-23T03:30:25Z", "aliases": [ "CVE-2022-30037" ], "details": "XunRuiCMS v4.3.3 to v4.5.1 vulnerable to PHP file write and CMS PHP file inclusion, allows attackers to execute arbitrary php code, via the add function in cron.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-829" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-23T02:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-fjrv-vx9m-4jpj/GHSA-fjrv-vx9m-4jpj.json b/advisories/unreviewed/2023/03/GHSA-fjrv-vx9m-4jpj/GHSA-fjrv-vx9m-4jpj.json new file mode 100644 index 00000000000..9f269b157b0 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-fjrv-vx9m-4jpj/GHSA-fjrv-vx9m-4jpj.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fjrv-vx9m-4jpj", + "modified": "2023-03-28T21:30:20Z", + "published": "2023-03-28T21:30:20Z", + "aliases": [ + "CVE-2023-25722" + ], + "details": "A credential-leak issue was discovered in related Veracode products before 2023-03-27. Veracode Scan Jenkins Plugin before 23.3.19.0, when configured for remote agent jobs, invokes the Veracode Java API Wrapper in a manner that allows local users (with OS-level access of the Jenkins remote) to discover Veracode API credentials by listing the process and its arguments. Veracode Scan Jenkins Plugin before 23.3.19.0, when configured for remote agent jobs and when the \"Connect using proxy\" option is enabled and configured with proxy credentials, allows local users of the Jenkins remote to discover proxy credentials by listing the process and its arguments. Veracode Azure DevOps Extension before 3.20.0 invokes the Veracode Java API Wrapper in a manner that allows local users (with OS-level access to the Azure DevOps Services cloud infrastructure or Azure DevOps Server) to discover Veracode API credentials by listing the process and its arguments. Veracode Azure DevOps Extension before 3.20.0, when configured with proxy credentials, allows users (with shell access to the Azure DevOps Services cloud infrastructure or Azure DevOps Server) to discover proxy credentials by listing the process and its arguments.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25722" + }, + { + "type": "WEB", + "url": "https://docs.veracode.com/updates/r/c_all_int#veracode-jenkins-plugin-233190" + }, + { + "type": "WEB", + "url": "https://veracode.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-fpf8-q39w-v7gm/GHSA-fpf8-q39w-v7gm.json b/advisories/unreviewed/2023/03/GHSA-fpf8-q39w-v7gm/GHSA-fpf8-q39w-v7gm.json new file mode 100644 index 00000000000..c4e343e862a --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-fpf8-q39w-v7gm/GHSA-fpf8-q39w-v7gm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fpf8-q39w-v7gm", + "modified": "2023-03-28T21:30:19Z", + "published": "2023-03-28T21:30:19Z", + "aliases": [ + "CVE-2023-25895" + ], + "details": "Adobe Dimension versions 3.4.7 (and earlier) is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25895" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/dimension/apsb23-20.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-fr2q-h4vv-r9cc/GHSA-fr2q-h4vv-r9cc.json b/advisories/unreviewed/2023/03/GHSA-fr2q-h4vv-r9cc/GHSA-fr2q-h4vv-r9cc.json new file mode 100644 index 00000000000..19fd7514624 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-fr2q-h4vv-r9cc/GHSA-fr2q-h4vv-r9cc.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fr2q-h4vv-r9cc", + "modified": "2023-03-28T21:30:20Z", + "published": "2023-03-28T21:30:20Z", + "aliases": [ + "CVE-2022-23122" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the setfilparams function. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-15837.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-23122" + }, + { + "type": "WEB", + "url": "https://netatalk.sourceforge.io/3.1/ReleaseNotes3.1.13.html" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-529/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-fv63-w4rc-jg74/GHSA-fv63-w4rc-jg74.json b/advisories/unreviewed/2023/03/GHSA-fv63-w4rc-jg74/GHSA-fv63-w4rc-jg74.json new file mode 100644 index 00000000000..feb2586c572 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-fv63-w4rc-jg74/GHSA-fv63-w4rc-jg74.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fv63-w4rc-jg74", + "modified": "2023-03-28T21:30:20Z", + "published": "2023-03-28T21:30:20Z", + "aliases": [ + "CVE-2022-23125" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the copyapplfile function. When parsing the len element, the process does not properly validate the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-15869.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-23125" + }, + { + "type": "WEB", + "url": "https://netatalk.sourceforge.io/3.1/ReleaseNotes3.1.13.html" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-526/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-g3c3-6h58-gpf9/GHSA-g3c3-6h58-gpf9.json b/advisories/unreviewed/2023/03/GHSA-g3c3-6h58-gpf9/GHSA-g3c3-6h58-gpf9.json index 8d6a74063da..e27e06b7648 100644 --- a/advisories/unreviewed/2023/03/GHSA-g3c3-6h58-gpf9/GHSA-g3c3-6h58-gpf9.json +++ b/advisories/unreviewed/2023/03/GHSA-g3c3-6h58-gpf9/GHSA-g3c3-6h58-gpf9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g3c3-6h58-gpf9", - "modified": "2023-03-24T21:30:50Z", + "modified": "2023-03-28T21:30:20Z", "published": "2023-03-24T21:30:50Z", "aliases": [ "CVE-2023-20956" ], "details": "In Import of C2SurfaceSyncObj.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12L Android-13Android ID: A-240140929", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-24T20:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-g4g4-p4fp-3fwg/GHSA-g4g4-p4fp-3fwg.json b/advisories/unreviewed/2023/03/GHSA-g4g4-p4fp-3fwg/GHSA-g4g4-p4fp-3fwg.json new file mode 100644 index 00000000000..858bd39e7ab --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-g4g4-p4fp-3fwg/GHSA-g4g4-p4fp-3fwg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g4g4-p4fp-3fwg", + "modified": "2023-03-28T21:30:17Z", + "published": "2023-03-28T21:30:17Z", + "aliases": [ + "CVE-2023-26356" + ], + "details": "Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26356" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/dimension/apsb23-20.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-g4vf-g2vq-w8mm/GHSA-g4vf-g2vq-w8mm.json b/advisories/unreviewed/2023/03/GHSA-g4vf-g2vq-w8mm/GHSA-g4vf-g2vq-w8mm.json new file mode 100644 index 00000000000..4a537993fbf --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-g4vf-g2vq-w8mm/GHSA-g4vf-g2vq-w8mm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g4vf-g2vq-w8mm", + "modified": "2023-03-28T21:30:18Z", + "published": "2023-03-28T21:30:18Z", + "aliases": [ + "CVE-2023-26337" + ], + "details": "Adobe Dimension versions 3.4.7 (and earlier) is affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26337" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/dimension/apsb23-20.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-g6wq-j869-5p24/GHSA-g6wq-j869-5p24.json b/advisories/unreviewed/2023/03/GHSA-g6wq-j869-5p24/GHSA-g6wq-j869-5p24.json new file mode 100644 index 00000000000..cc02313d2be --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-g6wq-j869-5p24/GHSA-g6wq-j869-5p24.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g6wq-j869-5p24", + "modified": "2023-03-28T21:30:18Z", + "published": "2023-03-28T21:30:18Z", + "aliases": [ + "CVE-2023-26332" + ], + "details": "Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26332" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/dimension/apsb23-20.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-g9jv-f7hr-g75x/GHSA-g9jv-f7hr-g75x.json b/advisories/unreviewed/2023/03/GHSA-g9jv-f7hr-g75x/GHSA-g9jv-f7hr-g75x.json index 9dea5999979..5baf16d9e27 100644 --- a/advisories/unreviewed/2023/03/GHSA-g9jv-f7hr-g75x/GHSA-g9jv-f7hr-g75x.json +++ b/advisories/unreviewed/2023/03/GHSA-g9jv-f7hr-g75x/GHSA-g9jv-f7hr-g75x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g9jv-f7hr-g75x", - "modified": "2023-03-23T03:30:25Z", + "modified": "2023-03-28T21:30:20Z", "published": "2023-03-23T03:30:25Z", "aliases": [ "CVE-2023-24655" ], "details": "Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the name parameter under the Profile Update function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-23T01:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-gqc6-rvh5-fvj3/GHSA-gqc6-rvh5-fvj3.json b/advisories/unreviewed/2023/03/GHSA-gqc6-rvh5-fvj3/GHSA-gqc6-rvh5-fvj3.json new file mode 100644 index 00000000000..6b4d9050742 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-gqc6-rvh5-fvj3/GHSA-gqc6-rvh5-fvj3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gqc6-rvh5-fvj3", + "modified": "2023-03-28T21:30:17Z", + "published": "2023-03-28T21:30:17Z", + "aliases": [ + "CVE-2023-26354" + ], + "details": "Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26354" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/dimension/apsb23-20.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-h56j-23jq-w46f/GHSA-h56j-23jq-w46f.json b/advisories/unreviewed/2023/03/GHSA-h56j-23jq-w46f/GHSA-h56j-23jq-w46f.json new file mode 100644 index 00000000000..92f1c86127d --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-h56j-23jq-w46f/GHSA-h56j-23jq-w46f.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h56j-23jq-w46f", + "modified": "2023-03-28T21:30:16Z", + "published": "2023-03-28T21:30:16Z", + "aliases": [ + "CVE-2023-28718" + ], + "details": "Osprey Pump Controller version 1.01 allows users to perform certain actions via HTTP requests without performing any checks to verify the requests. This may allow an attacker to perform certain actions with administrative privileges if a logged-in user visits a malicious website.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28718" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-23-082-06" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T21:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-h939-f8q4-79v2/GHSA-h939-f8q4-79v2.json b/advisories/unreviewed/2023/03/GHSA-h939-f8q4-79v2/GHSA-h939-f8q4-79v2.json new file mode 100644 index 00000000000..f349ca7d358 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-h939-f8q4-79v2/GHSA-h939-f8q4-79v2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h939-f8q4-79v2", + "modified": "2023-03-28T21:30:17Z", + "published": "2023-03-28T21:30:17Z", + "aliases": [ + "CVE-2023-26349" + ], + "details": "Adobe Dimension versions 3.4.7 (and earlier) is affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26349" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/dimension/apsb23-20.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-h9qg-478x-rpf8/GHSA-h9qg-478x-rpf8.json b/advisories/unreviewed/2023/03/GHSA-h9qg-478x-rpf8/GHSA-h9qg-478x-rpf8.json new file mode 100644 index 00000000000..9f500c10e07 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-h9qg-478x-rpf8/GHSA-h9qg-478x-rpf8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h9qg-478x-rpf8", + "modified": "2023-03-28T21:30:19Z", + "published": "2023-03-28T21:30:19Z", + "aliases": [ + "CVE-2023-25901" + ], + "details": "Adobe Dimension versions 3.4.7 (and earlier) is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25901" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/dimension/apsb23-20.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-hcfr-353h-rgfw/GHSA-hcfr-353h-rgfw.json b/advisories/unreviewed/2023/03/GHSA-hcfr-353h-rgfw/GHSA-hcfr-353h-rgfw.json new file mode 100644 index 00000000000..aafacc54d4c --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-hcfr-353h-rgfw/GHSA-hcfr-353h-rgfw.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hcfr-353h-rgfw", + "modified": "2023-03-28T21:30:16Z", + "published": "2023-03-28T21:30:16Z", + "aliases": [ + "CVE-2023-1675" + ], + "details": "A vulnerability was found in SourceCodester School Registration and Fee System 1.0. It has been classified as critical. Affected is an unknown function of the file /bilal final/edit_stud.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-224232.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1675" + }, + { + "type": "WEB", + "url": "https://github.com/saintone98/bug_report/blob/main/vendors/hemedy99/School%20Registration%20and%20Fee%20System/SQLi-2.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.224232" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.224232" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T21:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-hfcw-j543-xjp3/GHSA-hfcw-j543-xjp3.json b/advisories/unreviewed/2023/03/GHSA-hfcw-j543-xjp3/GHSA-hfcw-j543-xjp3.json new file mode 100644 index 00000000000..b9475da93d4 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-hfcw-j543-xjp3/GHSA-hfcw-j543-xjp3.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hfcw-j543-xjp3", + "modified": "2023-03-28T21:30:20Z", + "published": "2023-03-28T21:30:20Z", + "aliases": [ + "CVE-2022-46387" + ], + "details": "ConEmu through 220807 and Cmder before 1.3.21 report the title of the terminal, including control characters, which allows an attacker to change the title and then execute it as commands.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46387" + }, + { + "type": "WEB", + "url": "https://gist.github.com/dgl/05ca60cdc7efc9e47bbc58d0c952635e" + }, + { + "type": "WEB", + "url": "https://github.com/cmderdev/cmder/blob/master/CHANGELOG.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-hq4v-9j7v-jcvr/GHSA-hq4v-9j7v-jcvr.json b/advisories/unreviewed/2023/03/GHSA-hq4v-9j7v-jcvr/GHSA-hq4v-9j7v-jcvr.json new file mode 100644 index 00000000000..bd174697e12 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-hq4v-9j7v-jcvr/GHSA-hq4v-9j7v-jcvr.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hq4v-9j7v-jcvr", + "modified": "2023-03-28T21:30:20Z", + "published": "2023-03-28T21:30:20Z", + "aliases": [ + "CVE-2022-24674" + ], + "details": "This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Canon imageCLASS MF644Cdw 10.02 printers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the privet API. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-15834.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-24674" + }, + { + "type": "WEB", + "url": "https://www.usa.canon.com/internet/portal/us/home/support/product-advisories/detail/canon-laser-printer-and-small-office-multifunctional-printer-measure-against-buffer-overflow/" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-516/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-hq6q-hjw7-9j5j/GHSA-hq6q-hjw7-9j5j.json b/advisories/unreviewed/2023/03/GHSA-hq6q-hjw7-9j5j/GHSA-hq6q-hjw7-9j5j.json new file mode 100644 index 00000000000..f72065bda9b --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-hq6q-hjw7-9j5j/GHSA-hq6q-hjw7-9j5j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hq6q-hjw7-9j5j", + "modified": "2023-03-28T21:30:19Z", + "published": "2023-03-28T21:30:19Z", + "aliases": [ + "CVE-2023-25898" + ], + "details": "Adobe Dimension versions 3.4.7 (and earlier) is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25898" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/dimension/apsb23-20.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-hx23-xvvm-5p68/GHSA-hx23-xvvm-5p68.json b/advisories/unreviewed/2023/03/GHSA-hx23-xvvm-5p68/GHSA-hx23-xvvm-5p68.json index cb8056ae426..43c6162f6e5 100644 --- a/advisories/unreviewed/2023/03/GHSA-hx23-xvvm-5p68/GHSA-hx23-xvvm-5p68.json +++ b/advisories/unreviewed/2023/03/GHSA-hx23-xvvm-5p68/GHSA-hx23-xvvm-5p68.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hx23-xvvm-5p68", - "modified": "2023-03-23T03:30:25Z", + "modified": "2023-03-28T21:30:18Z", "published": "2023-03-23T03:30:25Z", "aliases": [ "CVE-2023-28470" ], "details": "In Couchbase Server 5 through 7 before 7.1.4, the nsstats endpoint is accessible without authentication.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-306" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-23T01:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-hxx7-8jpf-2vg3/GHSA-hxx7-8jpf-2vg3.json b/advisories/unreviewed/2023/03/GHSA-hxx7-8jpf-2vg3/GHSA-hxx7-8jpf-2vg3.json index 9f03bba303a..4a004e14576 100644 --- a/advisories/unreviewed/2023/03/GHSA-hxx7-8jpf-2vg3/GHSA-hxx7-8jpf-2vg3.json +++ b/advisories/unreviewed/2023/03/GHSA-hxx7-8jpf-2vg3/GHSA-hxx7-8jpf-2vg3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hxx7-8jpf-2vg3", - "modified": "2023-03-24T21:30:50Z", + "modified": "2023-03-28T21:30:21Z", "published": "2023-03-24T21:30:50Z", "aliases": [ "CVE-2023-20962" ], "details": "In getSliceEndItem of MediaVolumePreferenceController.java, there is a possible way to start foreground activity from the background due to an unsafe PendingIntent. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-256590210", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-24T20:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-j2hq-24xq-xcjr/GHSA-j2hq-24xq-xcjr.json b/advisories/unreviewed/2023/03/GHSA-j2hq-24xq-xcjr/GHSA-j2hq-24xq-xcjr.json new file mode 100644 index 00000000000..10ab5d1a1df --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-j2hq-24xq-xcjr/GHSA-j2hq-24xq-xcjr.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j2hq-24xq-xcjr", + "modified": "2023-03-28T21:30:20Z", + "published": "2023-03-28T21:30:20Z", + "aliases": [ + "CVE-2022-0194" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the ad_addcomment function. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-15876.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-0194" + }, + { + "type": "WEB", + "url": "https://netatalk.sourceforge.io/3.1/ReleaseNotes3.1.13.html" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-530/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-j2jp-w6cv-6rcr/GHSA-j2jp-w6cv-6rcr.json b/advisories/unreviewed/2023/03/GHSA-j2jp-w6cv-6rcr/GHSA-j2jp-w6cv-6rcr.json index f398ccc7dcc..4e837fabd97 100644 --- a/advisories/unreviewed/2023/03/GHSA-j2jp-w6cv-6rcr/GHSA-j2jp-w6cv-6rcr.json +++ b/advisories/unreviewed/2023/03/GHSA-j2jp-w6cv-6rcr/GHSA-j2jp-w6cv-6rcr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j2jp-w6cv-6rcr", - "modified": "2023-03-24T21:30:50Z", + "modified": "2023-03-28T21:30:20Z", "published": "2023-03-24T21:30:50Z", "aliases": [ "CVE-2023-20972" ], "details": "In btm_vendor_specific_evt of btm_devctl.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-255304665", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-119" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-24T20:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-j658-jwc9-69qv/GHSA-j658-jwc9-69qv.json b/advisories/unreviewed/2023/03/GHSA-j658-jwc9-69qv/GHSA-j658-jwc9-69qv.json index aa6368a74e1..6568c695a33 100644 --- a/advisories/unreviewed/2023/03/GHSA-j658-jwc9-69qv/GHSA-j658-jwc9-69qv.json +++ b/advisories/unreviewed/2023/03/GHSA-j658-jwc9-69qv/GHSA-j658-jwc9-69qv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j658-jwc9-69qv", - "modified": "2023-03-23T00:30:16Z", + "modified": "2023-03-28T21:30:20Z", "published": "2023-03-23T00:30:16Z", "aliases": [ "CVE-2023-27060" ], "details": "LightCMS v1.3.7 was discovered to contain a remote code execution (RCE) vulnerability via the image:make function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-22T22:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-j8w3-r4h4-vrwq/GHSA-j8w3-r4h4-vrwq.json b/advisories/unreviewed/2023/03/GHSA-j8w3-r4h4-vrwq/GHSA-j8w3-r4h4-vrwq.json new file mode 100644 index 00000000000..ae1bc8089bb --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-j8w3-r4h4-vrwq/GHSA-j8w3-r4h4-vrwq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j8w3-r4h4-vrwq", + "modified": "2023-03-28T21:30:19Z", + "published": "2023-03-28T21:30:19Z", + "aliases": [ + "CVE-2023-25893" + ], + "details": "Adobe Dimension versions 3.4.7 (and earlier) is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25893" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/dimension/apsb23-20.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-jjm7-p4mp-w379/GHSA-jjm7-p4mp-w379.json b/advisories/unreviewed/2023/03/GHSA-jjm7-p4mp-w379/GHSA-jjm7-p4mp-w379.json new file mode 100644 index 00000000000..a933a27e587 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-jjm7-p4mp-w379/GHSA-jjm7-p4mp-w379.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jjm7-p4mp-w379", + "modified": "2023-03-28T21:30:17Z", + "published": "2023-03-28T21:30:17Z", + "aliases": [ + "CVE-2023-26353" + ], + "details": "Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26353" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/dimension/apsb23-20.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-jjvh-3jw8-6rjg/GHSA-jjvh-3jw8-6rjg.json b/advisories/unreviewed/2023/03/GHSA-jjvh-3jw8-6rjg/GHSA-jjvh-3jw8-6rjg.json new file mode 100644 index 00000000000..f7e33c583b1 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-jjvh-3jw8-6rjg/GHSA-jjvh-3jw8-6rjg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jjvh-3jw8-6rjg", + "modified": "2023-03-28T21:30:19Z", + "published": "2023-03-28T21:30:19Z", + "aliases": [ + "CVE-2023-25889" + ], + "details": "Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25889" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/dimension/apsb23-20.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-jmpx-chh3-j32m/GHSA-jmpx-chh3-j32m.json b/advisories/unreviewed/2023/03/GHSA-jmpx-chh3-j32m/GHSA-jmpx-chh3-j32m.json new file mode 100644 index 00000000000..e86f7929e7d --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-jmpx-chh3-j32m/GHSA-jmpx-chh3-j32m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jmpx-chh3-j32m", + "modified": "2023-03-28T21:30:19Z", + "published": "2023-03-28T21:30:19Z", + "aliases": [ + "CVE-2023-25906" + ], + "details": "Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25906" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/dimension/apsb23-20.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-jr63-2x64-j533/GHSA-jr63-2x64-j533.json b/advisories/unreviewed/2023/03/GHSA-jr63-2x64-j533/GHSA-jr63-2x64-j533.json index 642b73779dc..1602e1e9f73 100644 --- a/advisories/unreviewed/2023/03/GHSA-jr63-2x64-j533/GHSA-jr63-2x64-j533.json +++ b/advisories/unreviewed/2023/03/GHSA-jr63-2x64-j533/GHSA-jr63-2x64-j533.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jr63-2x64-j533", - "modified": "2023-03-24T21:30:49Z", + "modified": "2023-03-28T21:30:21Z", "published": "2023-03-24T21:30:49Z", "aliases": [ "CVE-2022-42500" ], "details": "In OEM_OnRequest of sced.cpp, there is a possible shell command execution due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-239701389References: N/A", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-20" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-24T20:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-m6w8-x5rf-59xw/GHSA-m6w8-x5rf-59xw.json b/advisories/unreviewed/2023/03/GHSA-m6w8-x5rf-59xw/GHSA-m6w8-x5rf-59xw.json new file mode 100644 index 00000000000..fc2ba408d2e --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-m6w8-x5rf-59xw/GHSA-m6w8-x5rf-59xw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m6w8-x5rf-59xw", + "modified": "2023-03-28T21:30:19Z", + "published": "2023-03-28T21:30:19Z", + "aliases": [ + "CVE-2023-25892" + ], + "details": "Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25892" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/dimension/apsb23-20.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-m79g-73hm-2964/GHSA-m79g-73hm-2964.json b/advisories/unreviewed/2023/03/GHSA-m79g-73hm-2964/GHSA-m79g-73hm-2964.json new file mode 100644 index 00000000000..12fc06e9be0 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-m79g-73hm-2964/GHSA-m79g-73hm-2964.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m79g-73hm-2964", + "modified": "2023-03-28T21:30:16Z", + "published": "2023-03-28T21:30:16Z", + "aliases": [ + "CVE-2023-24304" + ], + "details": "Improper input validation in the PDF.dll plugin of IrfanView v4.60 allows attackers to execute arbitrary code via opening a crafted PDF file.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-24304" + }, + { + "type": "WEB", + "url": "https://www.sit.fraunhofer.de/CVE-2023-24304/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T21:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-m7h8-gfjf-c6w3/GHSA-m7h8-gfjf-c6w3.json b/advisories/unreviewed/2023/03/GHSA-m7h8-gfjf-c6w3/GHSA-m7h8-gfjf-c6w3.json new file mode 100644 index 00000000000..46d9fd7831f --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-m7h8-gfjf-c6w3/GHSA-m7h8-gfjf-c6w3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m7h8-gfjf-c6w3", + "modified": "2023-03-28T21:30:18Z", + "published": "2023-03-28T21:30:18Z", + "aliases": [ + "CVE-2023-26338" + ], + "details": "Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26338" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/dimension/apsb23-20.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-mgpq-xcpc-pc9g/GHSA-mgpq-xcpc-pc9g.json b/advisories/unreviewed/2023/03/GHSA-mgpq-xcpc-pc9g/GHSA-mgpq-xcpc-pc9g.json new file mode 100644 index 00000000000..9fcb8d788dc --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-mgpq-xcpc-pc9g/GHSA-mgpq-xcpc-pc9g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mgpq-xcpc-pc9g", + "modified": "2023-03-28T21:30:19Z", + "published": "2023-03-28T21:30:19Z", + "aliases": [ + "CVE-2023-25905" + ], + "details": "Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25905" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/dimension/apsb23-20.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-p275-389j-xxfj/GHSA-p275-389j-xxfj.json b/advisories/unreviewed/2023/03/GHSA-p275-389j-xxfj/GHSA-p275-389j-xxfj.json new file mode 100644 index 00000000000..27d3d606aa0 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-p275-389j-xxfj/GHSA-p275-389j-xxfj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p275-389j-xxfj", + "modified": "2023-03-28T21:30:19Z", + "published": "2023-03-28T21:30:19Z", + "aliases": [ + "CVE-2023-25903" + ], + "details": "Adobe Dimension versions 3.4.7 (and earlier) is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25903" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/dimension/apsb23-20.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-190" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-p365-9mq8-7r2q/GHSA-p365-9mq8-7r2q.json b/advisories/unreviewed/2023/03/GHSA-p365-9mq8-7r2q/GHSA-p365-9mq8-7r2q.json new file mode 100644 index 00000000000..494e7dd8a9b --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-p365-9mq8-7r2q/GHSA-p365-9mq8-7r2q.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p365-9mq8-7r2q", + "modified": "2023-03-28T21:30:20Z", + "published": "2023-03-28T21:30:20Z", + "aliases": [ + "CVE-2022-24672" + ], + "details": "This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Canon imageCLASS MF644Cdw 10.02 printers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the CADM service. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-15802.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-24672" + }, + { + "type": "WEB", + "url": "https://www.usa.canon.com/support/canon-product-advisories/canon-laser-printer-inkjet-printer-and-small-office-multifunctio" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-514/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-p9j2-j9m5-p2jw/GHSA-p9j2-j9m5-p2jw.json b/advisories/unreviewed/2023/03/GHSA-p9j2-j9m5-p2jw/GHSA-p9j2-j9m5-p2jw.json new file mode 100644 index 00000000000..01b8a65b802 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-p9j2-j9m5-p2jw/GHSA-p9j2-j9m5-p2jw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p9j2-j9m5-p2jw", + "modified": "2023-03-28T21:30:19Z", + "published": "2023-03-28T21:30:19Z", + "aliases": [ + "CVE-2023-25897" + ], + "details": "Adobe Dimension versions 3.4.7 (and earlier) is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25897" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/dimension/apsb23-20.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-pf92-gg69-86qp/GHSA-pf92-gg69-86qp.json b/advisories/unreviewed/2023/03/GHSA-pf92-gg69-86qp/GHSA-pf92-gg69-86qp.json index bc77311f094..31f20fe006f 100644 --- a/advisories/unreviewed/2023/03/GHSA-pf92-gg69-86qp/GHSA-pf92-gg69-86qp.json +++ b/advisories/unreviewed/2023/03/GHSA-pf92-gg69-86qp/GHSA-pf92-gg69-86qp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pf92-gg69-86qp", - "modified": "2023-03-23T00:30:17Z", + "modified": "2023-03-28T21:30:20Z", "published": "2023-03-23T00:30:17Z", "aliases": [ "CVE-2022-43863" ], "details": "IBM QRadar SIEM 7.4 and 7.5 is vulnerable to privilege escalation, allowing a user with some admin capabilities to gain additional admin capabilities. IBM X-Force ID: 239425.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,10 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-269" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-22T22:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-pfrj-5j69-m8f2/GHSA-pfrj-5j69-m8f2.json b/advisories/unreviewed/2023/03/GHSA-pfrj-5j69-m8f2/GHSA-pfrj-5j69-m8f2.json new file mode 100644 index 00000000000..91ec3584d84 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-pfrj-5j69-m8f2/GHSA-pfrj-5j69-m8f2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pfrj-5j69-m8f2", + "modified": "2023-03-28T21:30:18Z", + "published": "2023-03-28T21:30:18Z", + "aliases": [ + "CVE-2023-26330" + ], + "details": "Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26330" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/dimension/apsb23-20.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-pgv5-rjwj-wrcc/GHSA-pgv5-rjwj-wrcc.json b/advisories/unreviewed/2023/03/GHSA-pgv5-rjwj-wrcc/GHSA-pgv5-rjwj-wrcc.json new file mode 100644 index 00000000000..a79b437e6db --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-pgv5-rjwj-wrcc/GHSA-pgv5-rjwj-wrcc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pgv5-rjwj-wrcc", + "modified": "2023-03-28T21:30:19Z", + "published": "2023-03-28T21:30:19Z", + "aliases": [ + "CVE-2023-25882" + ], + "details": "Adobe Dimension versions 3.4.7 (and earlier) is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25882" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/dimension/apsb23-20.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-phc6-xm52-m68r/GHSA-phc6-xm52-m68r.json b/advisories/unreviewed/2023/03/GHSA-phc6-xm52-m68r/GHSA-phc6-xm52-m68r.json index f04773b8a7b..5f5b55e9687 100644 --- a/advisories/unreviewed/2023/03/GHSA-phc6-xm52-m68r/GHSA-phc6-xm52-m68r.json +++ b/advisories/unreviewed/2023/03/GHSA-phc6-xm52-m68r/GHSA-phc6-xm52-m68r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-phc6-xm52-m68r", - "modified": "2023-03-24T21:30:50Z", + "modified": "2023-03-28T21:30:21Z", "published": "2023-03-24T21:30:50Z", "aliases": [ "CVE-2023-20960" ], "details": "In launchDeepLinkIntentToRight of SettingsHomepageActivity.java, there is a possible way to launch arbitrary activities due to improper input validation. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12L Android-13Android ID: A-250589026", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-20" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-24T20:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-pv32-p5w7-p69h/GHSA-pv32-p5w7-p69h.json b/advisories/unreviewed/2023/03/GHSA-pv32-p5w7-p69h/GHSA-pv32-p5w7-p69h.json new file mode 100644 index 00000000000..5053999f936 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-pv32-p5w7-p69h/GHSA-pv32-p5w7-p69h.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pv32-p5w7-p69h", + "modified": "2023-03-28T21:30:20Z", + "published": "2023-03-28T21:30:20Z", + "aliases": [ + "CVE-2022-1230" + ], + "details": "This vulnerability allows local attackers to execute arbitrary code on affected installations of Samsung Galaxy S21 prior to 4.5.40.5 phones. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handling of redirections. An attacker can force a redirection to a site that serves malicious content. An attacker can leverage this in conjunction with other vulnerabilities to escalate privileges and execute arbitrary code in the context of the current user. Was ZDI-CAN-15918.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1230" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-621/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-px3r-mm7x-5xq2/GHSA-px3r-mm7x-5xq2.json b/advisories/unreviewed/2023/03/GHSA-px3r-mm7x-5xq2/GHSA-px3r-mm7x-5xq2.json index d51289ce7fe..9be1b19f772 100644 --- a/advisories/unreviewed/2023/03/GHSA-px3r-mm7x-5xq2/GHSA-px3r-mm7x-5xq2.json +++ b/advisories/unreviewed/2023/03/GHSA-px3r-mm7x-5xq2/GHSA-px3r-mm7x-5xq2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-px3r-mm7x-5xq2", - "modified": "2023-03-24T00:30:15Z", + "modified": "2023-03-28T21:30:16Z", "published": "2023-03-24T00:30:15Z", "aliases": [ "CVE-2023-24787" ], "details": "RESERVED churchcrm v4.5.3 was discovered to contain a SQL injection vulnerability via the Event parameter at /churchcrm/EventAttendance.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-23T22:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-q2vh-h27p-9r2q/GHSA-q2vh-h27p-9r2q.json b/advisories/unreviewed/2023/03/GHSA-q2vh-h27p-9r2q/GHSA-q2vh-h27p-9r2q.json new file mode 100644 index 00000000000..6ef80dbe829 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-q2vh-h27p-9r2q/GHSA-q2vh-h27p-9r2q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q2vh-h27p-9r2q", + "modified": "2023-03-28T21:30:20Z", + "published": "2023-03-28T21:30:20Z", + "aliases": [ + "CVE-2023-25879" + ], + "details": "Adobe Dimension versions 3.4.7 (and earlier) is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25879" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/dimension/apsb23-20.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-q5rj-8vxp-f8g2/GHSA-q5rj-8vxp-f8g2.json b/advisories/unreviewed/2023/03/GHSA-q5rj-8vxp-f8g2/GHSA-q5rj-8vxp-f8g2.json new file mode 100644 index 00000000000..ae5b5bd0486 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-q5rj-8vxp-f8g2/GHSA-q5rj-8vxp-f8g2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q5rj-8vxp-f8g2", + "modified": "2023-03-28T21:30:18Z", + "published": "2023-03-28T21:30:18Z", + "aliases": [ + "CVE-2023-26333" + ], + "details": "Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26333" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/dimension/apsb23-20.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-qc6x-2435-2vfr/GHSA-qc6x-2435-2vfr.json b/advisories/unreviewed/2023/03/GHSA-qc6x-2435-2vfr/GHSA-qc6x-2435-2vfr.json new file mode 100644 index 00000000000..eeaaa56fa49 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-qc6x-2435-2vfr/GHSA-qc6x-2435-2vfr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qc6x-2435-2vfr", + "modified": "2023-03-28T21:30:18Z", + "published": "2023-03-28T21:30:18Z", + "aliases": [ + "CVE-2023-26346" + ], + "details": "Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26346" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/dimension/apsb23-20.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-qmhg-2cm5-r44c/GHSA-qmhg-2cm5-r44c.json b/advisories/unreviewed/2023/03/GHSA-qmhg-2cm5-r44c/GHSA-qmhg-2cm5-r44c.json new file mode 100644 index 00000000000..86134b83f34 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-qmhg-2cm5-r44c/GHSA-qmhg-2cm5-r44c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qmhg-2cm5-r44c", + "modified": "2023-03-28T21:30:17Z", + "published": "2023-03-28T21:30:17Z", + "aliases": [ + "CVE-2023-26350" + ], + "details": "Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26350" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/dimension/apsb23-20.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-qmwv-362w-25hm/GHSA-qmwv-362w-25hm.json b/advisories/unreviewed/2023/03/GHSA-qmwv-362w-25hm/GHSA-qmwv-362w-25hm.json new file mode 100644 index 00000000000..541f4810dac --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-qmwv-362w-25hm/GHSA-qmwv-362w-25hm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qmwv-362w-25hm", + "modified": "2023-03-28T21:30:19Z", + "published": "2023-03-28T21:30:19Z", + "aliases": [ + "CVE-2023-25904" + ], + "details": "Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25904" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/dimension/apsb23-20.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-qppx-wxgc-54v3/GHSA-qppx-wxgc-54v3.json b/advisories/unreviewed/2023/03/GHSA-qppx-wxgc-54v3/GHSA-qppx-wxgc-54v3.json new file mode 100644 index 00000000000..44067d4f45d --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-qppx-wxgc-54v3/GHSA-qppx-wxgc-54v3.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qppx-wxgc-54v3", + "modified": "2023-03-28T21:30:20Z", + "published": "2023-03-28T21:30:20Z", + "aliases": [ + "CVE-2022-1229" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.2.034. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of IFC files. Crafted data in an IFC file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16581.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1229" + }, + { + "type": "WEB", + "url": "https://www.bentley.com/en/common-vulnerability-exposure/be-2022-0006" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-615/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-qv37-j9p9-3g8w/GHSA-qv37-j9p9-3g8w.json b/advisories/unreviewed/2023/03/GHSA-qv37-j9p9-3g8w/GHSA-qv37-j9p9-3g8w.json new file mode 100644 index 00000000000..74e72b39849 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-qv37-j9p9-3g8w/GHSA-qv37-j9p9-3g8w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qv37-j9p9-3g8w", + "modified": "2023-03-28T21:30:18Z", + "published": "2023-03-28T21:30:18Z", + "aliases": [ + "CVE-2023-26339" + ], + "details": "Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26339" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/dimension/apsb23-20.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-r2cg-xhr2-rg9g/GHSA-r2cg-xhr2-rg9g.json b/advisories/unreviewed/2023/03/GHSA-r2cg-xhr2-rg9g/GHSA-r2cg-xhr2-rg9g.json new file mode 100644 index 00000000000..2b12228eaf6 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-r2cg-xhr2-rg9g/GHSA-r2cg-xhr2-rg9g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r2cg-xhr2-rg9g", + "modified": "2023-03-28T21:30:18Z", + "published": "2023-03-28T21:30:18Z", + "aliases": [ + "CVE-2023-26336" + ], + "details": "Adobe Dimension versions 3.4.7 (and earlier) is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26336" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/dimension/apsb23-20.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-rcjf-5cjm-p5q4/GHSA-rcjf-5cjm-p5q4.json b/advisories/unreviewed/2023/03/GHSA-rcjf-5cjm-p5q4/GHSA-rcjf-5cjm-p5q4.json index c42bb505a82..16660085e9f 100644 --- a/advisories/unreviewed/2023/03/GHSA-rcjf-5cjm-p5q4/GHSA-rcjf-5cjm-p5q4.json +++ b/advisories/unreviewed/2023/03/GHSA-rcjf-5cjm-p5q4/GHSA-rcjf-5cjm-p5q4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rcjf-5cjm-p5q4", - "modified": "2023-03-23T00:30:17Z", + "modified": "2023-03-28T21:30:20Z", "published": "2023-03-23T00:30:17Z", "aliases": [ "CVE-2023-27054" ], "details": "A cross-site scripting (XSS) vulnerability in MiroTalk P2P before commit f535b35 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter under the settings module.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-22T22:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-rx7p-v2jr-jjc3/GHSA-rx7p-v2jr-jjc3.json b/advisories/unreviewed/2023/03/GHSA-rx7p-v2jr-jjc3/GHSA-rx7p-v2jr-jjc3.json new file mode 100644 index 00000000000..ffede6d01a6 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-rx7p-v2jr-jjc3/GHSA-rx7p-v2jr-jjc3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rx7p-v2jr-jjc3", + "modified": "2023-03-28T21:30:19Z", + "published": "2023-03-28T21:30:19Z", + "aliases": [ + "CVE-2023-25896" + ], + "details": "Adobe Dimension versions 3.4.7 (and earlier) is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25896" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/dimension/apsb23-20.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-v2r3-58v8-7v46/GHSA-v2r3-58v8-7v46.json b/advisories/unreviewed/2023/03/GHSA-v2r3-58v8-7v46/GHSA-v2r3-58v8-7v46.json new file mode 100644 index 00000000000..b03a47d2258 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-v2r3-58v8-7v46/GHSA-v2r3-58v8-7v46.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v2r3-58v8-7v46", + "modified": "2023-03-28T21:30:18Z", + "published": "2023-03-28T21:30:18Z", + "aliases": [ + "CVE-2023-26344" + ], + "details": "Adobe Dimension versions 3.4.7 (and earlier) is affected by an Access of Uninitialized Pointer vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26344" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/dimension/apsb23-20.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-824" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-vc65-wp33-6q6w/GHSA-vc65-wp33-6q6w.json b/advisories/unreviewed/2023/03/GHSA-vc65-wp33-6q6w/GHSA-vc65-wp33-6q6w.json new file mode 100644 index 00000000000..560f46dc0de --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-vc65-wp33-6q6w/GHSA-vc65-wp33-6q6w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vc65-wp33-6q6w", + "modified": "2023-03-28T21:30:19Z", + "published": "2023-03-28T21:30:19Z", + "aliases": [ + "CVE-2023-25890" + ], + "details": "Adobe Dimension versions 3.4.7 (and earlier) is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25890" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/dimension/apsb23-20.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-vqxq-2jqq-9chr/GHSA-vqxq-2jqq-9chr.json b/advisories/unreviewed/2023/03/GHSA-vqxq-2jqq-9chr/GHSA-vqxq-2jqq-9chr.json new file mode 100644 index 00000000000..edec5572cc9 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-vqxq-2jqq-9chr/GHSA-vqxq-2jqq-9chr.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vqxq-2jqq-9chr", + "modified": "2023-03-28T21:30:20Z", + "published": "2023-03-28T21:30:20Z", + "aliases": [ + "CVE-2022-24352" + ], + "details": "This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link AC1750 prior to 211210 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the NetUSB.ko kernel module. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-15773.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-24352" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-262/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-vwx5-xxq8-8699/GHSA-vwx5-xxq8-8699.json b/advisories/unreviewed/2023/03/GHSA-vwx5-xxq8-8699/GHSA-vwx5-xxq8-8699.json new file mode 100644 index 00000000000..612bff71ede --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-vwx5-xxq8-8699/GHSA-vwx5-xxq8-8699.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vwx5-xxq8-8699", + "modified": "2023-03-28T21:30:17Z", + "published": "2023-03-28T21:30:17Z", + "aliases": [ + "CVE-2023-1674" + ], + "details": "A vulnerability was found in SourceCodester School Registration and Fee System 1.0 and classified as critical. This issue affects some unknown processing of the file /bilal final/login.php of the component POST Parameter Handler. The manipulation of the argument username leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-224231.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1674" + }, + { + "type": "WEB", + "url": "https://github.com/saintone98/bug_report/blob/main/vendors/hemedy99/School%20Registration%20and%20Fee%20System/SQLi-1.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.224231" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.224231" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T21:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-w3qh-r4q8-mpvq/GHSA-w3qh-r4q8-mpvq.json b/advisories/unreviewed/2023/03/GHSA-w3qh-r4q8-mpvq/GHSA-w3qh-r4q8-mpvq.json new file mode 100644 index 00000000000..58d2cbccc6f --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-w3qh-r4q8-mpvq/GHSA-w3qh-r4q8-mpvq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w3qh-r4q8-mpvq", + "modified": "2023-03-28T21:30:19Z", + "published": "2023-03-28T21:30:19Z", + "aliases": [ + "CVE-2023-25888" + ], + "details": "Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25888" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/dimension/apsb23-20.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-w554-444w-32f7/GHSA-w554-444w-32f7.json b/advisories/unreviewed/2023/03/GHSA-w554-444w-32f7/GHSA-w554-444w-32f7.json new file mode 100644 index 00000000000..50dd35e6f10 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-w554-444w-32f7/GHSA-w554-444w-32f7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w554-444w-32f7", + "modified": "2023-03-28T21:30:16Z", + "published": "2023-03-28T21:30:16Z", + "aliases": [ + "CVE-2023-27394" + ], + "details": "Osprey Pump Controller version 1.01 is vulnerable an unauthenticated OS command injection vulnerability. This can be exploited to inject and execute arbitrary shell commands through a HTTP GET parameter called by DataLogView.php, EventsView.php and AlarmsView.php scripts.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27394" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-23-082-06" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T21:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-w5cr-gcpx-w5wp/GHSA-w5cr-gcpx-w5wp.json b/advisories/unreviewed/2023/03/GHSA-w5cr-gcpx-w5wp/GHSA-w5cr-gcpx-w5wp.json index 2a49e1e5f13..851a64ec64e 100644 --- a/advisories/unreviewed/2023/03/GHSA-w5cr-gcpx-w5wp/GHSA-w5cr-gcpx-w5wp.json +++ b/advisories/unreviewed/2023/03/GHSA-w5cr-gcpx-w5wp/GHSA-w5cr-gcpx-w5wp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w5cr-gcpx-w5wp", - "modified": "2023-03-24T21:30:50Z", + "modified": "2023-03-28T21:30:17Z", "published": "2023-03-24T21:30:50Z", "aliases": [ "CVE-2023-20976" ], "details": "In getConfirmationMessage of DefaultAutofillPicker.java, there is a possible way to mislead the user to select default autofill application due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-216117246", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-20" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-24T20:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-w85v-q239-vpx6/GHSA-w85v-q239-vpx6.json b/advisories/unreviewed/2023/03/GHSA-w85v-q239-vpx6/GHSA-w85v-q239-vpx6.json new file mode 100644 index 00000000000..af3e68a5f7d --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-w85v-q239-vpx6/GHSA-w85v-q239-vpx6.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w85v-q239-vpx6", + "modified": "2023-03-28T21:30:20Z", + "published": "2023-03-28T21:30:20Z", + "aliases": [ + "CVE-2022-24673" + ], + "details": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Canon imageCLASS MF644Cdw 10.02 printers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of the SLP protocol. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-15845.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-24673" + }, + { + "type": "WEB", + "url": "https://www.usa.canon.com/support/canon-product-advisories/canon-laser-printer-inkjet-printer-and-small-office-multifunctional-printer-measure-against-buffer-overflow" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-515/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-wfw9-4xc8-gxcw/GHSA-wfw9-4xc8-gxcw.json b/advisories/unreviewed/2023/03/GHSA-wfw9-4xc8-gxcw/GHSA-wfw9-4xc8-gxcw.json index 0076e1880e2..148b3c6f354 100644 --- a/advisories/unreviewed/2023/03/GHSA-wfw9-4xc8-gxcw/GHSA-wfw9-4xc8-gxcw.json +++ b/advisories/unreviewed/2023/03/GHSA-wfw9-4xc8-gxcw/GHSA-wfw9-4xc8-gxcw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wfw9-4xc8-gxcw", - "modified": "2023-03-24T21:30:50Z", + "modified": "2023-03-28T21:30:20Z", "published": "2023-03-24T21:30:50Z", "aliases": [ "CVE-2023-20957" ], "details": "In onAttach of SettingsPreferenceFragment.java, there is a possible bypass of Factory Reset Protections due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12LAndroid ID: A-258422561", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-24T20:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-wh45-gmf6-6g2x/GHSA-wh45-gmf6-6g2x.json b/advisories/unreviewed/2023/03/GHSA-wh45-gmf6-6g2x/GHSA-wh45-gmf6-6g2x.json new file mode 100644 index 00000000000..f87fb57744f --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-wh45-gmf6-6g2x/GHSA-wh45-gmf6-6g2x.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wh45-gmf6-6g2x", + "modified": "2023-03-28T21:30:17Z", + "published": "2023-03-28T21:30:17Z", + "aliases": [ + "CVE-2020-8889" + ], + "details": "The ShipStation.com plugin 1.0 for CS-Cart allows remote attackers to obtain sensitive information (via action=export) because a typo results in a successful comparison of a blank password and NULL.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-8889" + }, + { + "type": "WEB", + "url": "https://www.jerdiggity.com/node/869" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T21:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-wmh3-5pfq-qpp8/GHSA-wmh3-5pfq-qpp8.json b/advisories/unreviewed/2023/03/GHSA-wmh3-5pfq-qpp8/GHSA-wmh3-5pfq-qpp8.json index fc48a4f9860..c7469bd62a8 100644 --- a/advisories/unreviewed/2023/03/GHSA-wmh3-5pfq-qpp8/GHSA-wmh3-5pfq-qpp8.json +++ b/advisories/unreviewed/2023/03/GHSA-wmh3-5pfq-qpp8/GHSA-wmh3-5pfq-qpp8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wmh3-5pfq-qpp8", - "modified": "2023-03-23T00:30:16Z", + "modified": "2023-03-28T21:30:20Z", "published": "2023-03-23T00:30:16Z", "aliases": [ "CVE-2023-27100" ], "details": "Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22.05.1 and pfSense CE software v2.6.0 allows attackers to bypass brute force protection mechanisms via crafted web requests.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-307" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-22T23:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-wp9w-gqpp-fxxm/GHSA-wp9w-gqpp-fxxm.json b/advisories/unreviewed/2023/03/GHSA-wp9w-gqpp-fxxm/GHSA-wp9w-gqpp-fxxm.json index 90cbe4848ce..3b9859aecbe 100644 --- a/advisories/unreviewed/2023/03/GHSA-wp9w-gqpp-fxxm/GHSA-wp9w-gqpp-fxxm.json +++ b/advisories/unreviewed/2023/03/GHSA-wp9w-gqpp-fxxm/GHSA-wp9w-gqpp-fxxm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wp9w-gqpp-fxxm", - "modified": "2023-03-24T21:30:50Z", + "modified": "2023-03-28T21:30:17Z", "published": "2023-03-24T21:30:50Z", "aliases": [ "CVE-2023-20979" ], "details": "In BtaAvCo::GetNextSourceDataPacket of bta_av_co.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-259939364", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-24T20:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-x44c-8ff5-763p/GHSA-x44c-8ff5-763p.json b/advisories/unreviewed/2023/03/GHSA-x44c-8ff5-763p/GHSA-x44c-8ff5-763p.json index 46a13eabb51..380343b09c3 100644 --- a/advisories/unreviewed/2023/03/GHSA-x44c-8ff5-763p/GHSA-x44c-8ff5-763p.json +++ b/advisories/unreviewed/2023/03/GHSA-x44c-8ff5-763p/GHSA-x44c-8ff5-763p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x44c-8ff5-763p", - "modified": "2023-03-24T21:30:50Z", + "modified": "2023-03-28T21:30:20Z", "published": "2023-03-24T21:30:50Z", "aliases": [ "CVE-2023-20969" ], "details": "In multiple locations of p2p_iface.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-262236313", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-24T20:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-x72v-4hv8-67wx/GHSA-x72v-4hv8-67wx.json b/advisories/unreviewed/2023/03/GHSA-x72v-4hv8-67wx/GHSA-x72v-4hv8-67wx.json new file mode 100644 index 00000000000..600a9bd1b0c --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-x72v-4hv8-67wx/GHSA-x72v-4hv8-67wx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x72v-4hv8-67wx", + "modified": "2023-03-28T21:30:17Z", + "published": "2023-03-28T21:30:17Z", + "aliases": [ + "CVE-2023-26355" + ], + "details": "Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26355" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/dimension/apsb23-20.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-x7mm-wcg8-vfr4/GHSA-x7mm-wcg8-vfr4.json b/advisories/unreviewed/2023/03/GHSA-x7mm-wcg8-vfr4/GHSA-x7mm-wcg8-vfr4.json index d94d82f6f84..7d5d6c706d9 100644 --- a/advisories/unreviewed/2023/03/GHSA-x7mm-wcg8-vfr4/GHSA-x7mm-wcg8-vfr4.json +++ b/advisories/unreviewed/2023/03/GHSA-x7mm-wcg8-vfr4/GHSA-x7mm-wcg8-vfr4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x7mm-wcg8-vfr4", - "modified": "2023-03-24T21:30:49Z", + "modified": "2023-03-28T21:30:21Z", "published": "2023-03-24T21:30:49Z", "aliases": [ "CVE-2022-42498" ], "details": "In Pixel cellular firmware, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-240662453References: N/A", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-24T20:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-x86m-ppmc-4jv6/GHSA-x86m-ppmc-4jv6.json b/advisories/unreviewed/2023/03/GHSA-x86m-ppmc-4jv6/GHSA-x86m-ppmc-4jv6.json new file mode 100644 index 00000000000..2e032eb0f97 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-x86m-ppmc-4jv6/GHSA-x86m-ppmc-4jv6.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x86m-ppmc-4jv6", + "modified": "2023-03-28T21:30:16Z", + "published": "2023-03-28T21:30:16Z", + "aliases": [ + "CVE-2023-27886" + ], + "details": "Osprey Pump Controller version 1.01 is vulnerable to an unauthenticated OS command injection vulnerability. This can be exploited to inject and execute arbitrary shell commands through a HTTP POST parameter called by index.php script.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27886" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-23-082-06" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T21:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-x87g-c9hf-v5x3/GHSA-x87g-c9hf-v5x3.json b/advisories/unreviewed/2023/03/GHSA-x87g-c9hf-v5x3/GHSA-x87g-c9hf-v5x3.json new file mode 100644 index 00000000000..d8b136834cf --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-x87g-c9hf-v5x3/GHSA-x87g-c9hf-v5x3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x87g-c9hf-v5x3", + "modified": "2023-03-28T21:30:19Z", + "published": "2023-03-28T21:30:19Z", + "aliases": [ + "CVE-2023-25907" + ], + "details": "Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25907" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/dimension/apsb23-20.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-xc2w-wxjv-gww7/GHSA-xc2w-wxjv-gww7.json b/advisories/unreviewed/2023/03/GHSA-xc2w-wxjv-gww7/GHSA-xc2w-wxjv-gww7.json index bd0176f031c..380ab77557e 100644 --- a/advisories/unreviewed/2023/03/GHSA-xc2w-wxjv-gww7/GHSA-xc2w-wxjv-gww7.json +++ b/advisories/unreviewed/2023/03/GHSA-xc2w-wxjv-gww7/GHSA-xc2w-wxjv-gww7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xc2w-wxjv-gww7", - "modified": "2023-03-23T03:30:25Z", + "modified": "2023-03-28T21:30:20Z", "published": "2023-03-23T03:30:25Z", "aliases": [ "CVE-2022-28494" ], "details": "TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 is discovered to contain a command injection vulnerability in the setUpgradeFW function via the filename parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-23T01:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-xcqw-6vv4-r6mv/GHSA-xcqw-6vv4-r6mv.json b/advisories/unreviewed/2023/03/GHSA-xcqw-6vv4-r6mv/GHSA-xcqw-6vv4-r6mv.json new file mode 100644 index 00000000000..dcf17ac7f6f --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-xcqw-6vv4-r6mv/GHSA-xcqw-6vv4-r6mv.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xcqw-6vv4-r6mv", + "modified": "2023-03-28T21:30:21Z", + "published": "2023-03-28T21:30:21Z", + "aliases": [ + "CVE-2022-24973" + ], + "details": "This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link TL-WR940N 3.20.1 Build 200316 Rel.34392n (5553) routers. Authentication is required to exploit this vulnerability. The specific flaw exists within the httpd service, which listens on TCP port 80 by default. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-13992.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-24973" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-406/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-xhcg-fx4c-m8q6/GHSA-xhcg-fx4c-m8q6.json b/advisories/unreviewed/2023/03/GHSA-xhcg-fx4c-m8q6/GHSA-xhcg-fx4c-m8q6.json new file mode 100644 index 00000000000..73e2d74d1df --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-xhcg-fx4c-m8q6/GHSA-xhcg-fx4c-m8q6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xhcg-fx4c-m8q6", + "modified": "2023-03-28T21:30:17Z", + "published": "2023-03-28T21:30:17Z", + "aliases": [ + "CVE-2023-26352" + ], + "details": "Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26352" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/dimension/apsb23-20.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-xm9j-54hw-p785/GHSA-xm9j-54hw-p785.json b/advisories/unreviewed/2023/03/GHSA-xm9j-54hw-p785/GHSA-xm9j-54hw-p785.json new file mode 100644 index 00000000000..26d5fa7e8b6 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-xm9j-54hw-p785/GHSA-xm9j-54hw-p785.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xm9j-54hw-p785", + "modified": "2023-03-28T21:30:16Z", + "published": "2023-03-28T21:30:16Z", + "aliases": [ + "CVE-2023-24308" + ], + "details": "A potential memory vulnerability due to insufficient input validation in PDFXEditCore.x64.dll in PDF-XChange Editor version 9.3 by Tracker Software may allow attackers to execute code when a user opens a crafted PDF file. The issue occurs when handling a large number of objects in a PDF file.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-24308" + }, + { + "type": "WEB", + "url": "https://www.sit.fraunhofer.de/cve-2023-24308/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T21:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-xp9f-x7wr-8cp4/GHSA-xp9f-x7wr-8cp4.json b/advisories/unreviewed/2023/03/GHSA-xp9f-x7wr-8cp4/GHSA-xp9f-x7wr-8cp4.json new file mode 100644 index 00000000000..47b18f64252 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-xp9f-x7wr-8cp4/GHSA-xp9f-x7wr-8cp4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xp9f-x7wr-8cp4", + "modified": "2023-03-28T21:30:20Z", + "published": "2023-03-28T21:30:20Z", + "aliases": [ + "CVE-2023-25880" + ], + "details": "Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25880" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/dimension/apsb23-20.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-xpqc-2xj6-mrm4/GHSA-xpqc-2xj6-mrm4.json b/advisories/unreviewed/2023/03/GHSA-xpqc-2xj6-mrm4/GHSA-xpqc-2xj6-mrm4.json new file mode 100644 index 00000000000..f0f9c118225 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-xpqc-2xj6-mrm4/GHSA-xpqc-2xj6-mrm4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xpqc-2xj6-mrm4", + "modified": "2023-03-28T21:30:19Z", + "published": "2023-03-28T21:30:19Z", + "aliases": [ + "CVE-2023-26327" + ], + "details": "Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26327" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/dimension/apsb23-20.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-xrg5-9qxv-fc56/GHSA-xrg5-9qxv-fc56.json b/advisories/unreviewed/2023/03/GHSA-xrg5-9qxv-fc56/GHSA-xrg5-9qxv-fc56.json index 82b272ba9d6..eab6ed45dc7 100644 --- a/advisories/unreviewed/2023/03/GHSA-xrg5-9qxv-fc56/GHSA-xrg5-9qxv-fc56.json +++ b/advisories/unreviewed/2023/03/GHSA-xrg5-9qxv-fc56/GHSA-xrg5-9qxv-fc56.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xrg5-9qxv-fc56", - "modified": "2023-03-23T03:30:25Z", + "modified": "2023-03-28T21:30:20Z", "published": "2023-03-23T03:30:25Z", "aliases": [ "CVE-2023-26088" ], "details": "In Malwarebytes before 4.5.23, a symbolic link may be used delete any arbitrary file on the system by exploiting the local quarantine system. It can also lead to privilege escalation in certain scenarios.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-59" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-23T01:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-xrxp-wj2g-wrxj/GHSA-xrxp-wj2g-wrxj.json b/advisories/unreviewed/2023/03/GHSA-xrxp-wj2g-wrxj/GHSA-xrxp-wj2g-wrxj.json new file mode 100644 index 00000000000..13a40d077f1 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-xrxp-wj2g-wrxj/GHSA-xrxp-wj2g-wrxj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xrxp-wj2g-wrxj", + "modified": "2023-03-28T21:30:19Z", + "published": "2023-03-28T21:30:19Z", + "aliases": [ + "CVE-2023-25884" + ], + "details": "Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25884" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/dimension/apsb23-20.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-xxmg-8g8r-g92f/GHSA-xxmg-8g8r-g92f.json b/advisories/unreviewed/2023/03/GHSA-xxmg-8g8r-g92f/GHSA-xxmg-8g8r-g92f.json new file mode 100644 index 00000000000..773fc26085d --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-xxmg-8g8r-g92f/GHSA-xxmg-8g8r-g92f.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xxmg-8g8r-g92f", + "modified": "2023-03-28T21:30:16Z", + "published": "2023-03-28T21:30:16Z", + "aliases": [ + "CVE-2023-28398" + ], + "details": "Osprey Pump Controller version 1.01 could allow an unauthenticated user to create an account and bypass authentication, thereby gaining unauthorized access to the system. A threat actor could exploit this vulnerability to create a user account without providing valid credentials. A threat actor who successfully exploits this vulnerability could gain access to the pump controller and cause disruption in operation, modify data, or shut down the controller.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28398" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-23-082-06" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T21:15:00Z" + } +} \ No newline at end of file