diff --git a/advisories/unreviewed/2024/06/GHSA-7664-jhg9-7j9c/GHSA-7664-jhg9-7j9c.json b/advisories/unreviewed/2024/06/GHSA-7664-jhg9-7j9c/GHSA-7664-jhg9-7j9c.json index 31143628153..81bb9736001 100644 --- a/advisories/unreviewed/2024/06/GHSA-7664-jhg9-7j9c/GHSA-7664-jhg9-7j9c.json +++ b/advisories/unreviewed/2024/06/GHSA-7664-jhg9-7j9c/GHSA-7664-jhg9-7j9c.json @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-287" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-7739-w2jj-99pm/GHSA-7739-w2jj-99pm.json b/advisories/unreviewed/2024/06/GHSA-7739-w2jj-99pm/GHSA-7739-w2jj-99pm.json index 090a2f073ed..f6a4790eac2 100644 --- a/advisories/unreviewed/2024/06/GHSA-7739-w2jj-99pm/GHSA-7739-w2jj-99pm.json +++ b/advisories/unreviewed/2024/06/GHSA-7739-w2jj-99pm/GHSA-7739-w2jj-99pm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7739-w2jj-99pm", - "modified": "2024-06-13T09:31:01Z", + "modified": "2024-07-15T18:31:15Z", "published": "2024-06-13T09:31:01Z", "aliases": [ "CVE-2024-4371" @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-502" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-896r-w4m5-qqw8/GHSA-896r-w4m5-qqw8.json b/advisories/unreviewed/2024/06/GHSA-896r-w4m5-qqw8/GHSA-896r-w4m5-qqw8.json index 34cb4d357d2..775181c0b31 100644 --- a/advisories/unreviewed/2024/06/GHSA-896r-w4m5-qqw8/GHSA-896r-w4m5-qqw8.json +++ b/advisories/unreviewed/2024/06/GHSA-896r-w4m5-qqw8/GHSA-896r-w4m5-qqw8.json @@ -40,7 +40,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-ffxp-mhmm-9288/GHSA-ffxp-mhmm-9288.json b/advisories/unreviewed/2024/06/GHSA-ffxp-mhmm-9288/GHSA-ffxp-mhmm-9288.json index d326fb16b88..a8997a433c3 100644 --- a/advisories/unreviewed/2024/06/GHSA-ffxp-mhmm-9288/GHSA-ffxp-mhmm-9288.json +++ b/advisories/unreviewed/2024/06/GHSA-ffxp-mhmm-9288/GHSA-ffxp-mhmm-9288.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-ffxp-mhmm-9288", - "modified": "2024-06-20T03:30:35Z", + "modified": "2024-07-15T18:31:15Z", "published": "2024-06-20T03:30:35Z", "aliases": [ "CVE-2024-4626" @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-g362-xvhf-cmg9/GHSA-g362-xvhf-cmg9.json b/advisories/unreviewed/2024/06/GHSA-g362-xvhf-cmg9/GHSA-g362-xvhf-cmg9.json index 7ac0ac86645..c06124f6a9b 100644 --- a/advisories/unreviewed/2024/06/GHSA-g362-xvhf-cmg9/GHSA-g362-xvhf-cmg9.json +++ b/advisories/unreviewed/2024/06/GHSA-g362-xvhf-cmg9/GHSA-g362-xvhf-cmg9.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-jf6r-x3pr-jq8x/GHSA-jf6r-x3pr-jq8x.json b/advisories/unreviewed/2024/06/GHSA-jf6r-x3pr-jq8x/GHSA-jf6r-x3pr-jq8x.json index 7338f378cc3..a62f9603593 100644 --- a/advisories/unreviewed/2024/06/GHSA-jf6r-x3pr-jq8x/GHSA-jf6r-x3pr-jq8x.json +++ b/advisories/unreviewed/2024/06/GHSA-jf6r-x3pr-jq8x/GHSA-jf6r-x3pr-jq8x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jf6r-x3pr-jq8x", - "modified": "2024-06-18T18:31:19Z", + "modified": "2024-07-15T18:31:15Z", "published": "2024-06-18T18:31:19Z", "aliases": [ "CVE-2024-37803" ], "details": "Multiple stored cross-site scripting (XSS) vulnerabilities in CodeProjects Health Care hospital Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the fname and lname parameters under the Staff Info page.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-18T17:15:52Z" diff --git a/advisories/unreviewed/2024/06/GHSA-jr6w-fhh3-hwv9/GHSA-jr6w-fhh3-hwv9.json b/advisories/unreviewed/2024/06/GHSA-jr6w-fhh3-hwv9/GHSA-jr6w-fhh3-hwv9.json index 8dd58fb669a..e132469a6be 100644 --- a/advisories/unreviewed/2024/06/GHSA-jr6w-fhh3-hwv9/GHSA-jr6w-fhh3-hwv9.json +++ b/advisories/unreviewed/2024/06/GHSA-jr6w-fhh3-hwv9/GHSA-jr6w-fhh3-hwv9.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-601" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-m9j5-qh5w-4336/GHSA-m9j5-qh5w-4336.json b/advisories/unreviewed/2024/06/GHSA-m9j5-qh5w-4336/GHSA-m9j5-qh5w-4336.json index ffca8b95c4a..96216d42185 100644 --- a/advisories/unreviewed/2024/06/GHSA-m9j5-qh5w-4336/GHSA-m9j5-qh5w-4336.json +++ b/advisories/unreviewed/2024/06/GHSA-m9j5-qh5w-4336/GHSA-m9j5-qh5w-4336.json @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-prph-5cfv-59c9/GHSA-prph-5cfv-59c9.json b/advisories/unreviewed/2024/06/GHSA-prph-5cfv-59c9/GHSA-prph-5cfv-59c9.json index 4402b4e4719..20d86c8eb66 100644 --- a/advisories/unreviewed/2024/06/GHSA-prph-5cfv-59c9/GHSA-prph-5cfv-59c9.json +++ b/advisories/unreviewed/2024/06/GHSA-prph-5cfv-59c9/GHSA-prph-5cfv-59c9.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-qpg6-jr93-p3p4/GHSA-qpg6-jr93-p3p4.json b/advisories/unreviewed/2024/06/GHSA-qpg6-jr93-p3p4/GHSA-qpg6-jr93-p3p4.json index de4001171f4..f02f85ba59b 100644 --- a/advisories/unreviewed/2024/06/GHSA-qpg6-jr93-p3p4/GHSA-qpg6-jr93-p3p4.json +++ b/advisories/unreviewed/2024/06/GHSA-qpg6-jr93-p3p4/GHSA-qpg6-jr93-p3p4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qpg6-jr93-p3p4", - "modified": "2024-06-20T03:30:35Z", + "modified": "2024-07-15T18:31:15Z", "published": "2024-06-20T03:30:35Z", "aliases": [ "CVE-2024-4742" @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-vr8g-vr45-38w8/GHSA-vr8g-vr45-38w8.json b/advisories/unreviewed/2024/06/GHSA-vr8g-vr45-38w8/GHSA-vr8g-vr45-38w8.json index ae9c4b64e37..fe69c8fdf5e 100644 --- a/advisories/unreviewed/2024/06/GHSA-vr8g-vr45-38w8/GHSA-vr8g-vr45-38w8.json +++ b/advisories/unreviewed/2024/06/GHSA-vr8g-vr45-38w8/GHSA-vr8g-vr45-38w8.json @@ -40,7 +40,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-x5qw-gg87-5754/GHSA-x5qw-gg87-5754.json b/advisories/unreviewed/2024/06/GHSA-x5qw-gg87-5754/GHSA-x5qw-gg87-5754.json index 11d4d8ae5cc..77203815855 100644 --- a/advisories/unreviewed/2024/06/GHSA-x5qw-gg87-5754/GHSA-x5qw-gg87-5754.json +++ b/advisories/unreviewed/2024/06/GHSA-x5qw-gg87-5754/GHSA-x5qw-gg87-5754.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x5qw-gg87-5754", - "modified": "2024-06-20T03:30:35Z", + "modified": "2024-07-15T18:31:15Z", "published": "2024-06-20T03:30:35Z", "aliases": [ "CVE-2024-3602" @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-22q3-4v32-4m7c/GHSA-22q3-4v32-4m7c.json b/advisories/unreviewed/2024/07/GHSA-22q3-4v32-4m7c/GHSA-22q3-4v32-4m7c.json new file mode 100644 index 00000000000..310e58caf33 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-22q3-4v32-4m7c/GHSA-22q3-4v32-4m7c.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-22q3-4v32-4m7c", + "modified": "2024-07-15T18:31:15Z", + "published": "2024-07-15T18:31:15Z", + "aliases": [ + "CVE-2024-40553" + ], + "details": "Tmall_demo v2024.07.03 was discovered to contain an arbitrary file upload via the component uploadUserHeadImage.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40553" + }, + { + "type": "WEB", + "url": "https://gitee.com/project_team/Tmall_demo/issues/IAANVC" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-15T16:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-32vh-ppv4-655g/GHSA-32vh-ppv4-655g.json b/advisories/unreviewed/2024/07/GHSA-32vh-ppv4-655g/GHSA-32vh-ppv4-655g.json new file mode 100644 index 00000000000..593294cfdd3 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-32vh-ppv4-655g/GHSA-32vh-ppv4-655g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-32vh-ppv4-655g", + "modified": "2024-07-15T18:31:16Z", + "published": "2024-07-15T18:31:16Z", + "aliases": [ + "CVE-2024-39827" + ], + "details": "Improper input validation in the installer for Zoom Workplace Desktop App for Windows before version 6.0.10 may allow an authenticated user to conduct a denial of service via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39827" + }, + { + "type": "WEB", + "url": "https://www.zoom.com/en/trust/security-bulletin/zsb-24024" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-15T18:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-3x52-fw35-w3mf/GHSA-3x52-fw35-w3mf.json b/advisories/unreviewed/2024/07/GHSA-3x52-fw35-w3mf/GHSA-3x52-fw35-w3mf.json new file mode 100644 index 00000000000..782e4a2462f --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-3x52-fw35-w3mf/GHSA-3x52-fw35-w3mf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3x52-fw35-w3mf", + "modified": "2024-07-15T18:31:16Z", + "published": "2024-07-15T18:31:16Z", + "aliases": [ + "CVE-2024-39821" + ], + "details": "Race condition in the installer for Zoom Workplace App for Windows and Zoom Rooms App for Windows may allow an authenticated user to conduct a denial of service via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39821" + }, + { + "type": "WEB", + "url": "https://www.zoom.com/en/trust/security-bulletin/zsb-24028" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-367" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-15T18:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-4rm3-98rm-pmgw/GHSA-4rm3-98rm-pmgw.json b/advisories/unreviewed/2024/07/GHSA-4rm3-98rm-pmgw/GHSA-4rm3-98rm-pmgw.json new file mode 100644 index 00000000000..4560d8a5fdc --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-4rm3-98rm-pmgw/GHSA-4rm3-98rm-pmgw.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4rm3-98rm-pmgw", + "modified": "2024-07-15T18:31:15Z", + "published": "2024-07-15T18:31:15Z", + "aliases": [ + "CVE-2024-40554" + ], + "details": "An access control issue in Tmall_demo v2024.07.03 allows attackers to obtain sensitive information.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40554" + }, + { + "type": "WEB", + "url": "https://gitee.com/project_team/Tmall_demo/issues/IAANYB" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-15T16:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-73g9-pvg4-g265/GHSA-73g9-pvg4-g265.json b/advisories/unreviewed/2024/07/GHSA-73g9-pvg4-g265/GHSA-73g9-pvg4-g265.json new file mode 100644 index 00000000000..d6e98cd06d7 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-73g9-pvg4-g265/GHSA-73g9-pvg4-g265.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-73g9-pvg4-g265", + "modified": "2024-07-15T18:31:16Z", + "published": "2024-07-15T18:31:16Z", + "aliases": [ + "CVE-2024-40415" + ], + "details": "A vulnerability in /goform/SetStaticRouteCfg in the sub_519F4 function in Tenda AX1806 1.0.0.1 firmware leads to stack-based buffer overflow.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40415" + }, + { + "type": "WEB", + "url": "https://github.com/Feng-ZZ-pwn/IOT/blob/main/Tenda%20AX_1806/4/SetStaticRouteCfg.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-15T18:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-8hg8-hc8r-qqjh/GHSA-8hg8-hc8r-qqjh.json b/advisories/unreviewed/2024/07/GHSA-8hg8-hc8r-qqjh/GHSA-8hg8-hc8r-qqjh.json new file mode 100644 index 00000000000..13404ce15e7 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-8hg8-hc8r-qqjh/GHSA-8hg8-hc8r-qqjh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8hg8-hc8r-qqjh", + "modified": "2024-07-15T18:31:15Z", + "published": "2024-07-15T18:31:15Z", + "aliases": [ + "CVE-2024-27238" + ], + "details": "Race condition in the installer for some Zoom Apps and SDKs for Windows before version 6.0.0 may allow an authenticated user to conduct a privilege escalation via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27238" + }, + { + "type": "WEB", + "url": "https://www.zoom.com/en/trust/security-bulletin/zsb-24021" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-367" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-15T18:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-947j-6w79-84r8/GHSA-947j-6w79-84r8.json b/advisories/unreviewed/2024/07/GHSA-947j-6w79-84r8/GHSA-947j-6w79-84r8.json new file mode 100644 index 00000000000..ca6eede0e80 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-947j-6w79-84r8/GHSA-947j-6w79-84r8.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-947j-6w79-84r8", + "modified": "2024-07-15T18:31:15Z", + "published": "2024-07-15T18:31:15Z", + "aliases": [ + "CVE-2024-37016" + ], + "details": "Mengshen Wireless Door Alarm M70 2024-05-24 allows Authentication Bypass via a Capture-Replay approach.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37016" + }, + { + "type": "WEB", + "url": "https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-045.txt" + }, + { + "type": "WEB", + "url": "https://www.syss.de/pentest-blog" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-15T18:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-cvpr-vgp2-92p4/GHSA-cvpr-vgp2-92p4.json b/advisories/unreviewed/2024/07/GHSA-cvpr-vgp2-92p4/GHSA-cvpr-vgp2-92p4.json new file mode 100644 index 00000000000..536aaabec63 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-cvpr-vgp2-92p4/GHSA-cvpr-vgp2-92p4.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cvpr-vgp2-92p4", + "modified": "2024-07-15T18:31:15Z", + "published": "2024-07-15T18:31:15Z", + "aliases": [ + "CVE-2024-40555" + ], + "details": "Tmall_demo v2024.07.03 was discovered to contain an arbitrary file upload vulnerability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40555" + }, + { + "type": "WEB", + "url": "https://gitee.com/project_team/Tmall_demo/issues/IAAO1T" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-15T16:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-gcx5-qrc7-cqmf/GHSA-gcx5-qrc7-cqmf.json b/advisories/unreviewed/2024/07/GHSA-gcx5-qrc7-cqmf/GHSA-gcx5-qrc7-cqmf.json new file mode 100644 index 00000000000..11532276da9 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-gcx5-qrc7-cqmf/GHSA-gcx5-qrc7-cqmf.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gcx5-qrc7-cqmf", + "modified": "2024-07-15T18:31:15Z", + "published": "2024-07-15T18:31:15Z", + "aliases": [ + "CVE-2024-40414" + ], + "details": "A vulnerability in /goform/SetNetControlList in the sub_656BC function in Tenda AX1806 1.0.0.1 firmware leads to stack-based buffer overflow.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40414" + }, + { + "type": "WEB", + "url": "https://github.com/Feng-ZZ-pwn/IOT/blob/main/Tenda%20AX_1806/2/SetNetControlList.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-15T17:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-h943-w3x2-738c/GHSA-h943-w3x2-738c.json b/advisories/unreviewed/2024/07/GHSA-h943-w3x2-738c/GHSA-h943-w3x2-738c.json index 7ac2d726aa9..f22b92d0f6e 100644 --- a/advisories/unreviewed/2024/07/GHSA-h943-w3x2-738c/GHSA-h943-w3x2-738c.json +++ b/advisories/unreviewed/2024/07/GHSA-h943-w3x2-738c/GHSA-h943-w3x2-738c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h943-w3x2-738c", - "modified": "2024-07-15T15:31:02Z", + "modified": "2024-07-15T18:31:15Z", "published": "2024-07-15T15:31:02Z", "aliases": [ "CVE-2024-6716" @@ -28,6 +28,10 @@ { "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2297636" + }, + { + "type": "WEB", + "url": "https://gitlab.com/libtiff/libtiff/-/issues/620" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/07/GHSA-j5r4-872p-2x9r/GHSA-j5r4-872p-2x9r.json b/advisories/unreviewed/2024/07/GHSA-j5r4-872p-2x9r/GHSA-j5r4-872p-2x9r.json new file mode 100644 index 00000000000..5f82c93adba --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-j5r4-872p-2x9r/GHSA-j5r4-872p-2x9r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j5r4-872p-2x9r", + "modified": "2024-07-15T18:31:16Z", + "published": "2024-07-15T18:31:16Z", + "aliases": [ + "CVE-2024-39826" + ], + "details": "Path traversal in Team Chat for some Zoom Workplace Apps and SDKs for Windows may allow an authenticated user to conduct information disclosure via network access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39826" + }, + { + "type": "WEB", + "url": "https://www.zoom.com/en/trust/security-bulletin/zsb-24023" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-367" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-15T18:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-jx2p-c252-qcmr/GHSA-jx2p-c252-qcmr.json b/advisories/unreviewed/2024/07/GHSA-jx2p-c252-qcmr/GHSA-jx2p-c252-qcmr.json index 8991a9e1ea2..a75d1cfe76a 100644 --- a/advisories/unreviewed/2024/07/GHSA-jx2p-c252-qcmr/GHSA-jx2p-c252-qcmr.json +++ b/advisories/unreviewed/2024/07/GHSA-jx2p-c252-qcmr/GHSA-jx2p-c252-qcmr.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-287", "CWE-305" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/07/GHSA-pq37-mvgc-px93/GHSA-pq37-mvgc-px93.json b/advisories/unreviewed/2024/07/GHSA-pq37-mvgc-px93/GHSA-pq37-mvgc-px93.json new file mode 100644 index 00000000000..1c3843b464f --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-pq37-mvgc-px93/GHSA-pq37-mvgc-px93.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pq37-mvgc-px93", + "modified": "2024-07-15T18:31:15Z", + "published": "2024-07-15T18:31:15Z", + "aliases": [ + "CVE-2024-39819" + ], + "details": "Improper privilege management in the installer for some Zoom Workplace Apps and SDKs for Windows may allow an authenticated user to conduct a privilege escalation via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39819" + }, + { + "type": "WEB", + "url": "https://www.zoom.com/en/trust/security-bulletin/zsb-24026" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-15T18:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-pxcv-w3gg-4fc7/GHSA-pxcv-w3gg-4fc7.json b/advisories/unreviewed/2024/07/GHSA-pxcv-w3gg-4fc7/GHSA-pxcv-w3gg-4fc7.json index d4b40f038a5..269e7be72b5 100644 --- a/advisories/unreviewed/2024/07/GHSA-pxcv-w3gg-4fc7/GHSA-pxcv-w3gg-4fc7.json +++ b/advisories/unreviewed/2024/07/GHSA-pxcv-w3gg-4fc7/GHSA-pxcv-w3gg-4fc7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pxcv-w3gg-4fc7", - "modified": "2024-07-10T18:32:17Z", + "modified": "2024-07-15T18:31:15Z", "published": "2024-07-10T18:32:17Z", "aliases": [ "CVE-2024-40412" @@ -18,6 +18,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40412" }, + { + "type": "WEB", + "url": "https://github.com/Feng-ZZ-pwn/IOT/blob/main/Tenda%20AX12/1/README.md" + }, { "type": "WEB", "url": "https://static.tenda.com.cn/tdcweb/download/uploadfile/AX12/V22.03.01.46.zip" diff --git a/advisories/unreviewed/2024/07/GHSA-q37j-wrch-f33f/GHSA-q37j-wrch-f33f.json b/advisories/unreviewed/2024/07/GHSA-q37j-wrch-f33f/GHSA-q37j-wrch-f33f.json new file mode 100644 index 00000000000..08d0d9f3e38 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-q37j-wrch-f33f/GHSA-q37j-wrch-f33f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q37j-wrch-f33f", + "modified": "2024-07-15T18:31:15Z", + "published": "2024-07-15T18:31:15Z", + "aliases": [ + "CVE-2024-27240" + ], + "details": "Improper input validation in the installer for some Zoom Apps for Windows may allow an authenticated user to conduct a privilege escalation via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27240" + }, + { + "type": "WEB", + "url": "https://www.zoom.com/en/trust/security-bulletin/zsb-24019" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-15T18:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-v6g2-fqh9-vg4f/GHSA-v6g2-fqh9-vg4f.json b/advisories/unreviewed/2024/07/GHSA-v6g2-fqh9-vg4f/GHSA-v6g2-fqh9-vg4f.json new file mode 100644 index 00000000000..dce4b654057 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-v6g2-fqh9-vg4f/GHSA-v6g2-fqh9-vg4f.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v6g2-fqh9-vg4f", + "modified": "2024-07-15T18:31:15Z", + "published": "2024-07-15T18:31:15Z", + "aliases": [ + "CVE-2024-40560" + ], + "details": "Tmall_demo before v2024.07.03 was discovered to contain a SQL injection vulnerability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40560" + }, + { + "type": "WEB", + "url": "https://gitee.com/project_team/Tmall_demo/issues/IAAOT1" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-15T16:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-wjcg-c99p-6q65/GHSA-wjcg-c99p-6q65.json b/advisories/unreviewed/2024/07/GHSA-wjcg-c99p-6q65/GHSA-wjcg-c99p-6q65.json new file mode 100644 index 00000000000..c7786a84009 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-wjcg-c99p-6q65/GHSA-wjcg-c99p-6q65.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wjcg-c99p-6q65", + "modified": "2024-07-15T18:31:16Z", + "published": "2024-07-15T18:31:16Z", + "aliases": [ + "CVE-2024-40416" + ], + "details": "A vulnerability in /goform/SetVirtualServerCfg in the sub_6320C function in Tenda AX1806 1.0.0.1 firmware leads to stack-based buffer overflow.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40416" + }, + { + "type": "WEB", + "url": "https://github.com/Feng-ZZ-pwn/IOT/blob/main/Tenda%20AX_1806/3/SetVirtualServerCfg.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-15T18:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-x2w8-7cm9-gp7x/GHSA-x2w8-7cm9-gp7x.json b/advisories/unreviewed/2024/07/GHSA-x2w8-7cm9-gp7x/GHSA-x2w8-7cm9-gp7x.json new file mode 100644 index 00000000000..330afac2b31 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-x2w8-7cm9-gp7x/GHSA-x2w8-7cm9-gp7x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x2w8-7cm9-gp7x", + "modified": "2024-07-15T18:31:15Z", + "published": "2024-07-15T18:31:15Z", + "aliases": [ + "CVE-2024-27241" + ], + "details": "Improper input validation in some Zoom Apps and SDKs may allow an authenticated user to conduct a denial of service via network access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27241" + }, + { + "type": "WEB", + "url": "https://www.zoom.com/en/trust/security-bulletin/zsb-24020" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-15T18:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-xpq2-j352-wchr/GHSA-xpq2-j352-wchr.json b/advisories/unreviewed/2024/07/GHSA-xpq2-j352-wchr/GHSA-xpq2-j352-wchr.json new file mode 100644 index 00000000000..f0b7aa84046 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-xpq2-j352-wchr/GHSA-xpq2-j352-wchr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xpq2-j352-wchr", + "modified": "2024-07-15T18:31:15Z", + "published": "2024-07-15T18:31:15Z", + "aliases": [ + "CVE-2024-39820" + ], + "details": "Uncontrolled search path element in the installer for Zoom Workplace Desktop App for macOS before version 6.0.10 may allow an authenticated user to conduct a denial of service via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39820" + }, + { + "type": "WEB", + "url": "https://www.zoom.com/en/trust/security-bulletin/zsb-24027" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-15T18:15:04Z" + } +} \ No newline at end of file