diff --git a/advisories/unreviewed/2024/07/GHSA-2268-w43v-j544/GHSA-2268-w43v-j544.json b/advisories/unreviewed/2024/07/GHSA-2268-w43v-j544/GHSA-2268-w43v-j544.json new file mode 100644 index 00000000000..c9f7aaf1c20 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-2268-w43v-j544/GHSA-2268-w43v-j544.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2268-w43v-j544", + "modified": "2024-07-03T18:48:32Z", + "published": "2024-07-03T18:48:32Z", + "aliases": [ + "CVE-2024-5887" + ], + "details": "Cross-Site Request Forgery (CSRF) in stitionai/devika", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5887" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/aa4f1c38-5b38-4cdc-91e1-68d3ec2350f2" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-03T18:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-8w32-6chg-qv5f/GHSA-8w32-6chg-qv5f.json b/advisories/unreviewed/2024/07/GHSA-8w32-6chg-qv5f/GHSA-8w32-6chg-qv5f.json new file mode 100644 index 00000000000..de357557304 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-8w32-6chg-qv5f/GHSA-8w32-6chg-qv5f.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8w32-6chg-qv5f", + "modified": "2024-07-03T18:48:29Z", + "published": "2024-07-03T18:48:29Z", + "aliases": [ + "CVE-2024-29509" + ], + "details": "Artifex Ghostscript before 10.03.0 has a heap-based overflow when PDFPassword (e.g., for runpdf) has a \\000 byte in the middle.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29509" + }, + { + "type": "WEB", + "url": "https://bugs.ghostscript.com/show_bug.cgi?id=707510" + }, + { + "type": "WEB", + "url": "https://git.ghostscript.com/?p=ghostpdl.git%3Bh=917b3a71fb20748965254631199ad98210d6c2fb" + }, + { + "type": "WEB", + "url": "https://www.openwall.com/lists/oss-security/2024/07/03/7" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-03T18:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-f8j4-pwp4-c58m/GHSA-f8j4-pwp4-c58m.json b/advisories/unreviewed/2024/07/GHSA-f8j4-pwp4-c58m/GHSA-f8j4-pwp4-c58m.json new file mode 100644 index 00000000000..e5ad5880792 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-f8j4-pwp4-c58m/GHSA-f8j4-pwp4-c58m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f8j4-pwp4-c58m", + "modified": "2024-07-03T18:48:31Z", + "published": "2024-07-03T18:48:31Z", + "aliases": [ + "CVE-2024-5821" + ], + "details": "Improper Access Control in stitionai/devika", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5821" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/6b729046-b9e1-4fa2-a0c5-603745a6db6b" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-03T18:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-g5x6-xpv4-w4mm/GHSA-g5x6-xpv4-w4mm.json b/advisories/unreviewed/2024/07/GHSA-g5x6-xpv4-w4mm/GHSA-g5x6-xpv4-w4mm.json new file mode 100644 index 00000000000..63f5f8412cb --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-g5x6-xpv4-w4mm/GHSA-g5x6-xpv4-w4mm.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g5x6-xpv4-w4mm", + "modified": "2024-07-03T18:48:29Z", + "published": "2024-07-03T18:48:29Z", + "aliases": [ + "CVE-2024-29506" + ], + "details": "Artifex Ghostscript before 10.03.0 has a stack-based buffer overflow in the pdfi_apply_filter() function via a long PDF filter name.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29506" + }, + { + "type": "WEB", + "url": "https://bugs.ghostscript.com/show_bug.cgi?id=707510" + }, + { + "type": "WEB", + "url": "https://git.ghostscript.com/?p=ghostpdl.git%3Bh=77dc7f699beba606937b7ea23b50cf5974fa64b1" + }, + { + "type": "WEB", + "url": "https://www.openwall.com/lists/oss-security/2024/07/03/7" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-03T18:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-g8p4-4qgr-rf4f/GHSA-g8p4-4qgr-rf4f.json b/advisories/unreviewed/2024/07/GHSA-g8p4-4qgr-rf4f/GHSA-g8p4-4qgr-rf4f.json new file mode 100644 index 00000000000..60a6cf76c9b --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-g8p4-4qgr-rf4f/GHSA-g8p4-4qgr-rf4f.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g8p4-4qgr-rf4f", + "modified": "2024-07-03T18:48:28Z", + "published": "2024-07-03T18:48:28Z", + "aliases": [ + "CVE-2023-52169" + ], + "details": "The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains an out-of-bounds read that allows an attacker to read beyond the intended buffer. The bytes read beyond the intended buffer are presented as a part of a filename listed in the file system image. This has security relevance in some known web-service use cases where untrusted users can upload files and have them extracted by a server-side 7-Zip process.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52169" + }, + { + "type": "WEB", + "url": "https://sourceforge.net/p/sevenzip/bugs/2402" + }, + { + "type": "WEB", + "url": "https://www.openwall.com/lists/oss-security/2024/07/03/10" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-03T18:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-qh94-pjxq-88v7/GHSA-qh94-pjxq-88v7.json b/advisories/unreviewed/2024/07/GHSA-qh94-pjxq-88v7/GHSA-qh94-pjxq-88v7.json new file mode 100644 index 00000000000..29a52249a08 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-qh94-pjxq-88v7/GHSA-qh94-pjxq-88v7.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qh94-pjxq-88v7", + "modified": "2024-07-03T18:48:27Z", + "published": "2024-07-03T18:48:27Z", + "aliases": [ + "CVE-2024-39844" + ], + "details": "In ZNC before 1.9.1, remote code execution can occur in modtcl via a KICK.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39844" + }, + { + "type": "WEB", + "url": "https://github.com/znc/znc/releases/tag/znc-1.9.1" + }, + { + "type": "WEB", + "url": "https://wiki.znc.in/Category:ChangeLog" + }, + { + "type": "WEB", + "url": "https://wiki.znc.in/ChangeLog/1.9.1" + }, + { + "type": "WEB", + "url": "https://www.openwall.com/lists/oss-security/2024/07/03/9" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-03T17:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-w2wv-53w9-5r3r/GHSA-w2wv-53w9-5r3r.json b/advisories/unreviewed/2024/07/GHSA-w2wv-53w9-5r3r/GHSA-w2wv-53w9-5r3r.json new file mode 100644 index 00000000000..386e49a2403 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-w2wv-53w9-5r3r/GHSA-w2wv-53w9-5r3r.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w2wv-53w9-5r3r", + "modified": "2024-07-03T18:48:30Z", + "published": "2024-07-03T18:48:30Z", + "aliases": [ + "CVE-2024-29508" + ], + "details": "Artifex Ghostscript before 10.0.3.0 has a heap-based pointer disclosure (observable in a constructed BaseFont name) in the function pdf_base_font_alloc.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29508" + }, + { + "type": "WEB", + "url": "https://bugs.ghostscript.com/show_bug.cgi?id=707510" + }, + { + "type": "WEB", + "url": "https://git.ghostscript.com/?p=ghostpdl.git%3Bh=ff1013a0ab485b66783b70145e342a82c670906a" + }, + { + "type": "WEB", + "url": "https://www.openwall.com/lists/oss-security/2024/07/03/7" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-03T18:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-wgw3-5w65-2g45/GHSA-wgw3-5w65-2g45.json b/advisories/unreviewed/2024/07/GHSA-wgw3-5w65-2g45/GHSA-wgw3-5w65-2g45.json new file mode 100644 index 00000000000..72fd92a74fc --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-wgw3-5w65-2g45/GHSA-wgw3-5w65-2g45.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wgw3-5w65-2g45", + "modified": "2024-07-03T18:48:28Z", + "published": "2024-07-03T18:48:28Z", + "aliases": [ + "CVE-2023-52168" + ], + "details": "The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains a heap-based buffer overflow that allows an attacker to overwrite two bytes at multiple offsets beyond the allocated buffer size: buffer+512*i-2, for i=9, i=10, i=11, etc.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52168" + }, + { + "type": "WEB", + "url": "https://sourceforge.net/p/sevenzip/bugs/2402" + }, + { + "type": "WEB", + "url": "https://www.openwall.com/lists/oss-security/2024/07/03/10" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-03T18:15:04Z" + } +} \ No newline at end of file