Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2024-07-15 18:32:44 +00:00
parent af300b6bbd
commit 41bf847b74
31 changed files with 621 additions and 21 deletions
@@ -36,7 +36,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-287"
],
"severity": "CRITICAL",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7739-w2jj-99pm",
"modified": "2024-06-13T09:31:01Z",
"modified": "2024-07-15T18:31:15Z",
"published": "2024-06-13T09:31:01Z",
"aliases": [
"CVE-2024-4371"
@@ -32,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-502"
],
"severity": "CRITICAL",
"github_reviewed": false,
@@ -40,7 +40,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-94"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-ffxp-mhmm-9288",
"modified": "2024-06-20T03:30:35Z",
"modified": "2024-07-15T18:31:15Z",
"published": "2024-06-20T03:30:35Z",
"aliases": [
"CVE-2024-4626"
@@ -36,7 +36,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -32,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "CRITICAL",
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jf6r-x3pr-jq8x",
"modified": "2024-06-18T18:31:19Z",
"modified": "2024-07-15T18:31:15Z",
"published": "2024-06-18T18:31:19Z",
"aliases": [
"CVE-2024-37803"
],
"details": "Multiple stored cross-site scripting (XSS) vulnerabilities in CodeProjects Health Care hospital Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the fname and lname parameters under the Staff Info page.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-18T17:15:52Z"
@@ -32,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-601"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -36,7 +36,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-862"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -32,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-862"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qpg6-jr93-p3p4",
"modified": "2024-06-20T03:30:35Z",
"modified": "2024-07-15T18:31:15Z",
"published": "2024-06-20T03:30:35Z",
"aliases": [
"CVE-2024-4742"
@@ -32,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "CRITICAL",
"github_reviewed": false,
@@ -40,7 +40,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x5qw-gg87-5754",
"modified": "2024-06-20T03:30:35Z",
"modified": "2024-07-15T18:31:15Z",
"published": "2024-06-20T03:30:35Z",
"aliases": [
"CVE-2024-3602"
@@ -32,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-862"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-22q3-4v32-4m7c",
"modified": "2024-07-15T18:31:15Z",
"published": "2024-07-15T18:31:15Z",
"aliases": [
"CVE-2024-40553"
],
"details": "Tmall_demo v2024.07.03 was discovered to contain an arbitrary file upload via the component uploadUserHeadImage.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40553"
},
{
"type": "WEB",
"url": "https://gitee.com/project_team/Tmall_demo/issues/IAANVC"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-15T16:15:03Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-32vh-ppv4-655g",
"modified": "2024-07-15T18:31:16Z",
"published": "2024-07-15T18:31:16Z",
"aliases": [
"CVE-2024-39827"
],
"details": "Improper input validation in the installer for Zoom Workplace Desktop App for Windows before version 6.0.10 may allow an authenticated user to conduct a denial of service via local access.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39827"
},
{
"type": "WEB",
"url": "https://www.zoom.com/en/trust/security-bulletin/zsb-24024"
}
],
"database_specific": {
"cwe_ids": [
"CWE-20"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-15T18:15:05Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3x52-fw35-w3mf",
"modified": "2024-07-15T18:31:16Z",
"published": "2024-07-15T18:31:16Z",
"aliases": [
"CVE-2024-39821"
],
"details": "Race condition in the installer for Zoom Workplace App for Windows and Zoom Rooms App for Windows may allow an authenticated user to conduct a denial of service via local access.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39821"
},
{
"type": "WEB",
"url": "https://www.zoom.com/en/trust/security-bulletin/zsb-24028"
}
],
"database_specific": {
"cwe_ids": [
"CWE-367"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-15T18:15:04Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4rm3-98rm-pmgw",
"modified": "2024-07-15T18:31:15Z",
"published": "2024-07-15T18:31:15Z",
"aliases": [
"CVE-2024-40554"
],
"details": "An access control issue in Tmall_demo v2024.07.03 allows attackers to obtain sensitive information.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40554"
},
{
"type": "WEB",
"url": "https://gitee.com/project_team/Tmall_demo/issues/IAANYB"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-15T16:15:03Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-73g9-pvg4-g265",
"modified": "2024-07-15T18:31:16Z",
"published": "2024-07-15T18:31:16Z",
"aliases": [
"CVE-2024-40415"
],
"details": "A vulnerability in /goform/SetStaticRouteCfg in the sub_519F4 function in Tenda AX1806 1.0.0.1 firmware leads to stack-based buffer overflow.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40415"
},
{
"type": "WEB",
"url": "https://github.com/Feng-ZZ-pwn/IOT/blob/main/Tenda%20AX_1806/4/SetStaticRouteCfg.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-15T18:15:05Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8hg8-hc8r-qqjh",
"modified": "2024-07-15T18:31:15Z",
"published": "2024-07-15T18:31:15Z",
"aliases": [
"CVE-2024-27238"
],
"details": "Race condition in the installer for some Zoom Apps and SDKs for Windows before version 6.0.0 may allow an authenticated user to conduct a privilege escalation via local access.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27238"
},
{
"type": "WEB",
"url": "https://www.zoom.com/en/trust/security-bulletin/zsb-24021"
}
],
"database_specific": {
"cwe_ids": [
"CWE-367"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-15T18:15:03Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-947j-6w79-84r8",
"modified": "2024-07-15T18:31:15Z",
"published": "2024-07-15T18:31:15Z",
"aliases": [
"CVE-2024-37016"
],
"details": "Mengshen Wireless Door Alarm M70 2024-05-24 allows Authentication Bypass via a Capture-Replay approach.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37016"
},
{
"type": "WEB",
"url": "https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-045.txt"
},
{
"type": "WEB",
"url": "https://www.syss.de/pentest-blog"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-15T18:15:04Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cvpr-vgp2-92p4",
"modified": "2024-07-15T18:31:15Z",
"published": "2024-07-15T18:31:15Z",
"aliases": [
"CVE-2024-40555"
],
"details": "Tmall_demo v2024.07.03 was discovered to contain an arbitrary file upload vulnerability.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40555"
},
{
"type": "WEB",
"url": "https://gitee.com/project_team/Tmall_demo/issues/IAAO1T"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-15T16:15:03Z"
}
}

Some files were not shown because too many files have changed in this diff Show More