diff --git a/advisories/unreviewed/2023/09/GHSA-98gc-8mj5-cc3r/GHSA-98gc-8mj5-cc3r.json b/advisories/unreviewed/2023/09/GHSA-98gc-8mj5-cc3r/GHSA-98gc-8mj5-cc3r.json index 51ab1bb4e03..728e6599d90 100644 --- a/advisories/unreviewed/2023/09/GHSA-98gc-8mj5-cc3r/GHSA-98gc-8mj5-cc3r.json +++ b/advisories/unreviewed/2023/09/GHSA-98gc-8mj5-cc3r/GHSA-98gc-8mj5-cc3r.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-291", "CWE-345", "CWE-348" ], diff --git a/advisories/unreviewed/2023/10/GHSA-8rjv-5mg2-wp52/GHSA-8rjv-5mg2-wp52.json b/advisories/unreviewed/2023/10/GHSA-8rjv-5mg2-wp52/GHSA-8rjv-5mg2-wp52.json index 8ce7080a3b4..11dc7f5813b 100644 --- a/advisories/unreviewed/2023/10/GHSA-8rjv-5mg2-wp52/GHSA-8rjv-5mg2-wp52.json +++ b/advisories/unreviewed/2023/10/GHSA-8rjv-5mg2-wp52/GHSA-8rjv-5mg2-wp52.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-p4hf-76x7-9vqg/GHSA-p4hf-76x7-9vqg.json b/advisories/unreviewed/2023/10/GHSA-p4hf-76x7-9vqg/GHSA-p4hf-76x7-9vqg.json index ca0774928cb..c69d64b8152 100644 --- a/advisories/unreviewed/2023/10/GHSA-p4hf-76x7-9vqg/GHSA-p4hf-76x7-9vqg.json +++ b/advisories/unreviewed/2023/10/GHSA-p4hf-76x7-9vqg/GHSA-p4hf-76x7-9vqg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p4hf-76x7-9vqg", - "modified": "2024-04-04T08:01:32Z", + "modified": "2024-09-20T18:32:23Z", "published": "2023-10-03T00:30:26Z", "aliases": [ "CVE-2023-28372" @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/12/GHSA-269h-hc79-qjpf/GHSA-269h-hc79-qjpf.json b/advisories/unreviewed/2023/12/GHSA-269h-hc79-qjpf/GHSA-269h-hc79-qjpf.json index dbf3fad411d..d3548ae183f 100644 --- a/advisories/unreviewed/2023/12/GHSA-269h-hc79-qjpf/GHSA-269h-hc79-qjpf.json +++ b/advisories/unreviewed/2023/12/GHSA-269h-hc79-qjpf/GHSA-269h-hc79-qjpf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-269h-hc79-qjpf", - "modified": "2023-12-06T21:30:57Z", + "modified": "2024-09-20T18:32:23Z", "published": "2023-12-01T00:31:01Z", "aliases": [ "CVE-2023-46389" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46389" }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-247-01" + }, { "type": "WEB", "url": "https://www.txone.com/blog/ten-unpatched-vulnerabilities-in-building-automation-products-identified-by-txone-networks" diff --git a/advisories/unreviewed/2023/12/GHSA-3h9p-fmw3-6wpv/GHSA-3h9p-fmw3-6wpv.json b/advisories/unreviewed/2023/12/GHSA-3h9p-fmw3-6wpv/GHSA-3h9p-fmw3-6wpv.json index f962b575194..158a0d17324 100644 --- a/advisories/unreviewed/2023/12/GHSA-3h9p-fmw3-6wpv/GHSA-3h9p-fmw3-6wpv.json +++ b/advisories/unreviewed/2023/12/GHSA-3h9p-fmw3-6wpv/GHSA-3h9p-fmw3-6wpv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3h9p-fmw3-6wpv", - "modified": "2023-12-06T21:30:57Z", + "modified": "2024-09-20T18:32:23Z", "published": "2023-12-01T00:31:00Z", "aliases": [ "CVE-2023-46386" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46386" }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-247-01" + }, { "type": "WEB", "url": "https://www.txone.com/blog/ten-unpatched-vulnerabilities-in-building-automation-products-identified-by-txone-networks" diff --git a/advisories/unreviewed/2023/12/GHSA-74f3-25qj-395v/GHSA-74f3-25qj-395v.json b/advisories/unreviewed/2023/12/GHSA-74f3-25qj-395v/GHSA-74f3-25qj-395v.json index 50612ba7e31..b84f93d6e35 100644 --- a/advisories/unreviewed/2023/12/GHSA-74f3-25qj-395v/GHSA-74f3-25qj-395v.json +++ b/advisories/unreviewed/2023/12/GHSA-74f3-25qj-395v/GHSA-74f3-25qj-395v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-74f3-25qj-395v", - "modified": "2023-12-06T21:30:57Z", + "modified": "2024-09-20T18:32:23Z", "published": "2023-12-01T00:31:00Z", "aliases": [ "CVE-2023-46387" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46387" }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-247-01" + }, { "type": "WEB", "url": "https://www.txone.com/blog/ten-unpatched-vulnerabilities-in-building-automation-products-identified-by-txone-networks" diff --git a/advisories/unreviewed/2023/12/GHSA-85qr-ggvx-pgjx/GHSA-85qr-ggvx-pgjx.json b/advisories/unreviewed/2023/12/GHSA-85qr-ggvx-pgjx/GHSA-85qr-ggvx-pgjx.json index edff3415b47..efe027aec23 100644 --- a/advisories/unreviewed/2023/12/GHSA-85qr-ggvx-pgjx/GHSA-85qr-ggvx-pgjx.json +++ b/advisories/unreviewed/2023/12/GHSA-85qr-ggvx-pgjx/GHSA-85qr-ggvx-pgjx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-85qr-ggvx-pgjx", - "modified": "2023-12-06T21:30:57Z", + "modified": "2024-09-20T18:32:23Z", "published": "2023-12-01T00:31:00Z", "aliases": [ "CVE-2023-46383" @@ -29,6 +29,10 @@ "type": "WEB", "url": "https://seclists.org/fulldisclosure/2023/Nov/6" }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-247-01" + }, { "type": "WEB", "url": "https://www.txone.com/blog/ten-unpatched-vulnerabilities-in-building-automation-products-identified-by-txone-networks" diff --git a/advisories/unreviewed/2023/12/GHSA-9vjx-qhgp-wfvm/GHSA-9vjx-qhgp-wfvm.json b/advisories/unreviewed/2023/12/GHSA-9vjx-qhgp-wfvm/GHSA-9vjx-qhgp-wfvm.json index 567a3e68448..d138da8d36d 100644 --- a/advisories/unreviewed/2023/12/GHSA-9vjx-qhgp-wfvm/GHSA-9vjx-qhgp-wfvm.json +++ b/advisories/unreviewed/2023/12/GHSA-9vjx-qhgp-wfvm/GHSA-9vjx-qhgp-wfvm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9vjx-qhgp-wfvm", - "modified": "2023-12-06T21:30:57Z", + "modified": "2024-09-20T18:32:23Z", "published": "2023-12-01T00:31:00Z", "aliases": [ "CVE-2023-46384" @@ -29,6 +29,10 @@ "type": "WEB", "url": "https://seclists.org/fulldisclosure/2023/Nov/6" }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-247-01" + }, { "type": "WEB", "url": "https://www.txone.com/blog/ten-unpatched-vulnerabilities-in-building-automation-products-identified-by-txone-networks" diff --git a/advisories/unreviewed/2023/12/GHSA-w8fp-3787-pwgj/GHSA-w8fp-3787-pwgj.json b/advisories/unreviewed/2023/12/GHSA-w8fp-3787-pwgj/GHSA-w8fp-3787-pwgj.json index 1d594396455..b9e194abccb 100644 --- a/advisories/unreviewed/2023/12/GHSA-w8fp-3787-pwgj/GHSA-w8fp-3787-pwgj.json +++ b/advisories/unreviewed/2023/12/GHSA-w8fp-3787-pwgj/GHSA-w8fp-3787-pwgj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w8fp-3787-pwgj", - "modified": "2023-12-06T21:30:57Z", + "modified": "2024-09-20T18:32:23Z", "published": "2023-12-01T00:31:00Z", "aliases": [ "CVE-2023-46388" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46388" }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-247-01" + }, { "type": "WEB", "url": "https://www.txone.com/blog/ten-unpatched-vulnerabilities-in-building-automation-products-identified-by-txone-networks" diff --git a/advisories/unreviewed/2023/12/GHSA-whp9-r49x-695c/GHSA-whp9-r49x-695c.json b/advisories/unreviewed/2023/12/GHSA-whp9-r49x-695c/GHSA-whp9-r49x-695c.json index 2359440bf9d..838c435a117 100644 --- a/advisories/unreviewed/2023/12/GHSA-whp9-r49x-695c/GHSA-whp9-r49x-695c.json +++ b/advisories/unreviewed/2023/12/GHSA-whp9-r49x-695c/GHSA-whp9-r49x-695c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-whp9-r49x-695c", - "modified": "2023-12-06T21:30:57Z", + "modified": "2024-09-20T18:32:23Z", "published": "2023-12-01T00:31:00Z", "aliases": [ "CVE-2023-46385" @@ -29,6 +29,10 @@ "type": "WEB", "url": "https://seclists.org/fulldisclosure/2023/Nov/6" }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-247-01" + }, { "type": "WEB", "url": "https://www.txone.com/blog/ten-unpatched-vulnerabilities-in-building-automation-products-identified-by-txone-networks" diff --git a/advisories/unreviewed/2024/04/GHSA-xr37-jcv5-cqxv/GHSA-xr37-jcv5-cqxv.json b/advisories/unreviewed/2024/04/GHSA-xr37-jcv5-cqxv/GHSA-xr37-jcv5-cqxv.json index e3cc114c035..36581f5a2d8 100644 --- a/advisories/unreviewed/2024/04/GHSA-xr37-jcv5-cqxv/GHSA-xr37-jcv5-cqxv.json +++ b/advisories/unreviewed/2024/04/GHSA-xr37-jcv5-cqxv/GHSA-xr37-jcv5-cqxv.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-312" + "CWE-312", + "CWE-327" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-3j9f-4r3c-964g/GHSA-3j9f-4r3c-964g.json b/advisories/unreviewed/2024/09/GHSA-3j9f-4r3c-964g/GHSA-3j9f-4r3c-964g.json index 2b6b6d14007..98433d6c1b8 100644 --- a/advisories/unreviewed/2024/09/GHSA-3j9f-4r3c-964g/GHSA-3j9f-4r3c-964g.json +++ b/advisories/unreviewed/2024/09/GHSA-3j9f-4r3c-964g/GHSA-3j9f-4r3c-964g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3j9f-4r3c-964g", - "modified": "2024-09-20T12:31:51Z", + "modified": "2024-09-20T18:32:25Z", "published": "2024-09-18T09:30:38Z", "aliases": [ "CVE-2024-46797" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\npowerpc/qspinlock: Fix deadlock in MCS queue\n\nIf an interrupt occurs in queued_spin_lock_slowpath() after we increment\nqnodesp->count and before node->lock is initialized, another CPU might\nsee stale lock values in get_tail_qnode(). If the stale lock value happens\nto match the lock on that CPU, then we write to the \"next\" pointer of\nthe wrong qnode. This causes a deadlock as the former CPU, once it becomes\nthe head of the MCS queue, will spin indefinitely until it's \"next\" pointer\nis set by its successor in the queue.\n\nRunning stress-ng on a 16 core (16EC/16VP) shared LPAR, results in\noccasional lockups similar to the following:\n\n $ stress-ng --all 128 --vm-bytes 80% --aggressive \\\n --maximize --oomable --verify --syslog \\\n --metrics --times --timeout 5m\n\n watchdog: CPU 15 Hard LOCKUP\n ......\n NIP [c0000000000b78f4] queued_spin_lock_slowpath+0x1184/0x1490\n LR [c000000001037c5c] _raw_spin_lock+0x6c/0x90\n Call Trace:\n 0xc000002cfffa3bf0 (unreliable)\n _raw_spin_lock+0x6c/0x90\n raw_spin_rq_lock_nested.part.135+0x4c/0xd0\n sched_ttwu_pending+0x60/0x1f0\n __flush_smp_call_function_queue+0x1dc/0x670\n smp_ipi_demux_relaxed+0xa4/0x100\n xive_muxed_ipi_action+0x20/0x40\n __handle_irq_event_percpu+0x80/0x240\n handle_irq_event_percpu+0x2c/0x80\n handle_percpu_irq+0x84/0xd0\n generic_handle_irq+0x54/0x80\n __do_irq+0xac/0x210\n __do_IRQ+0x74/0xd0\n 0x0\n do_IRQ+0x8c/0x170\n hardware_interrupt_common_virt+0x29c/0x2a0\n --- interrupt: 500 at queued_spin_lock_slowpath+0x4b8/0x1490\n ......\n NIP [c0000000000b6c28] queued_spin_lock_slowpath+0x4b8/0x1490\n LR [c000000001037c5c] _raw_spin_lock+0x6c/0x90\n --- interrupt: 500\n 0xc0000029c1a41d00 (unreliable)\n _raw_spin_lock+0x6c/0x90\n futex_wake+0x100/0x260\n do_futex+0x21c/0x2a0\n sys_futex+0x98/0x270\n system_call_exception+0x14c/0x2f0\n system_call_vectored_common+0x15c/0x2ec\n\nThe following code flow illustrates how the deadlock occurs.\nFor the sake of brevity, assume that both locks (A and B) are\ncontended and we call the queued_spin_lock_slowpath() function.\n\n CPU0 CPU1\n ---- ----\n spin_lock_irqsave(A) |\n spin_unlock_irqrestore(A) |\n spin_lock(B) |\n | |\n ▼ |\n id = qnodesp->count++; |\n (Note that nodes[0].lock == A) |\n | |\n ▼ |\n Interrupt |\n (happens before \"nodes[0].lock = B\") |\n | |\n ▼ |\n spin_lock_irqsave(A) |\n | |\n ▼ |\n id = qnodesp->count++ |\n nodes[1].lock = A |\n | |\n ▼ |\n Tail of MCS queue |\n | spin_lock_irqsave(A)\n ▼ |\n Head of MCS queue ▼\n | CPU0 is previous tail\n ▼ |\n Spin indefinitely ▼\n (until \"nodes[1].next != NULL\") prev = get_tail_qnode(A, CPU0)\n |\n ▼\n prev == &qnodes[CPU0].nodes[0]\n (as qnodes\n---truncated---", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-667" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T08:15:06Z" diff --git a/advisories/unreviewed/2024/09/GHSA-3mwh-qccg-vxm7/GHSA-3mwh-qccg-vxm7.json b/advisories/unreviewed/2024/09/GHSA-3mwh-qccg-vxm7/GHSA-3mwh-qccg-vxm7.json index 47372e28122..9948fc17aa5 100644 --- a/advisories/unreviewed/2024/09/GHSA-3mwh-qccg-vxm7/GHSA-3mwh-qccg-vxm7.json +++ b/advisories/unreviewed/2024/09/GHSA-3mwh-qccg-vxm7/GHSA-3mwh-qccg-vxm7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3mwh-qccg-vxm7", - "modified": "2024-09-18T09:30:36Z", + "modified": "2024-09-20T18:32:25Z", "published": "2024-09-18T09:30:35Z", "aliases": [ "CVE-2024-46721" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\napparmor: fix possible NULL pointer dereference\n\nprofile->parent->dents[AAFS_PROF_DIR] could be NULL only if its parent is made\nfrom __create_missing_ancestors(..) and 'ent->old' is NULL in\naa_replace_profiles(..).\nIn that case, it must return an error code and the code, -ENOENT represents\nits state that the path of its parent is not existed yet.\n\nBUG: kernel NULL pointer dereference, address: 0000000000000030\nPGD 0 P4D 0\nPREEMPT SMP PTI\nCPU: 4 PID: 3362 Comm: apparmor_parser Not tainted 6.8.0-24-generic #24\nHardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.15.0-1 04/01/2014\nRIP: 0010:aafs_create.constprop.0+0x7f/0x130\nCode: 4c 63 e0 48 83 c4 18 4c 89 e0 5b 41 5c 41 5d 41 5e 41 5f 5d 31 d2 31 c9 31 f6 31 ff 45 31 c0 45 31 c9 45 31 d2 c3 cc cc cc cc <4d> 8b 55 30 4d 8d ba a0 00 00 00 4c 89 55 c0 4c 89 ff e8 7a 6a ae\nRSP: 0018:ffffc9000b2c7c98 EFLAGS: 00010246\nRAX: 0000000000000000 RBX: 00000000000041ed RCX: 0000000000000000\nRDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000\nRBP: ffffc9000b2c7cd8 R08: 0000000000000000 R09: 0000000000000000\nR10: 0000000000000000 R11: 0000000000000000 R12: ffffffff82baac10\nR13: 0000000000000000 R14: 0000000000000000 R15: 0000000000000000\nFS: 00007be9f22cf740(0000) GS:ffff88817bc00000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 0000000000000030 CR3: 0000000134b08000 CR4: 00000000000006f0\nCall Trace:\n \n ? show_regs+0x6d/0x80\n ? __die+0x24/0x80\n ? page_fault_oops+0x99/0x1b0\n ? kernelmode_fixup_or_oops+0xb2/0x140\n ? __bad_area_nosemaphore+0x1a5/0x2c0\n ? find_vma+0x34/0x60\n ? bad_area_nosemaphore+0x16/0x30\n ? do_user_addr_fault+0x2a2/0x6b0\n ? exc_page_fault+0x83/0x1b0\n ? asm_exc_page_fault+0x27/0x30\n ? aafs_create.constprop.0+0x7f/0x130\n ? aafs_create.constprop.0+0x51/0x130\n __aafs_profile_mkdir+0x3d6/0x480\n aa_replace_profiles+0x83f/0x1270\n policy_update+0xe3/0x180\n profile_load+0xbc/0x150\n ? rw_verify_area+0x47/0x140\n vfs_write+0x100/0x480\n ? __x64_sys_openat+0x55/0xa0\n ? syscall_exit_to_user_mode+0x86/0x260\n ksys_write+0x73/0x100\n __x64_sys_write+0x19/0x30\n x64_sys_call+0x7e/0x25c0\n do_syscall_64+0x7f/0x180\n entry_SYSCALL_64_after_hwframe+0x78/0x80\nRIP: 0033:0x7be9f211c574\nCode: c7 00 16 00 00 00 b8 ff ff ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 f3 0f 1e fa 80 3d d5 ea 0e 00 00 74 13 b8 01 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 54 c3 0f 1f 00 55 48 89 e5 48 83 ec 20 48 89\nRSP: 002b:00007ffd26f2b8c8 EFLAGS: 00000202 ORIG_RAX: 0000000000000001\nRAX: ffffffffffffffda RBX: 00005d504415e200 RCX: 00007be9f211c574\nRDX: 0000000000001fc1 RSI: 00005d504418bc80 RDI: 0000000000000004\nRBP: 0000000000001fc1 R08: 0000000000001fc1 R09: 0000000080000000\nR10: 0000000000000000 R11: 0000000000000202 R12: 00005d504418bc80\nR13: 0000000000000004 R14: 00007ffd26f2b9b0 R15: 00007ffd26f2ba30\n \nModules linked in: snd_seq_dummy snd_hrtimer qrtr snd_hda_codec_generic snd_hda_intel snd_intel_dspcfg snd_intel_sdw_acpi snd_hda_codec snd_hda_core snd_hwdep snd_pcm snd_seq_midi snd_seq_midi_event snd_rawmidi snd_seq snd_seq_device i2c_i801 snd_timer i2c_smbus qxl snd soundcore drm_ttm_helper lpc_ich ttm joydev input_leds serio_raw mac_hid binfmt_misc msr parport_pc ppdev lp parport efi_pstore nfnetlink dmi_sysfs qemu_fw_cfg ip_tables x_tables autofs4 hid_generic usbhid hid ahci libahci psmouse virtio_rng xhci_pci xhci_pci_renesas\nCR2: 0000000000000030\n---[ end trace 0000000000000000 ]---\nRIP: 0010:aafs_create.constprop.0+0x7f/0x130\nCode: 4c 63 e0 48 83 c4 18 4c 89 e0 5b 41 5c 41 5d 41 5e 41 5f 5d 31 d2 31 c9 31 f6 31 ff 45 31 c0 45 31 c9 45 31 d2 c3 cc cc cc cc <4d> 8b 55 30 4d 8d ba a0 00 00 00 4c 89 55 c0 4c 89 ff e8 7a 6a ae\nRSP: 0018:ffffc9000b2c7c98 EFLAGS: 00010246\nRAX: 0000000000000000 RBX: 00000000000041ed RCX: 0000000000000000\nRDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000\nRBP: ffffc9000b2c7cd8 R08: 0000000000000000 R09: 0000000000000000\nR10: 0000\n---truncated---", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T07:15:03Z" diff --git a/advisories/unreviewed/2024/09/GHSA-3qp4-gg3j-84xj/GHSA-3qp4-gg3j-84xj.json b/advisories/unreviewed/2024/09/GHSA-3qp4-gg3j-84xj/GHSA-3qp4-gg3j-84xj.json new file mode 100644 index 00000000000..34b96c4398f --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-3qp4-gg3j-84xj/GHSA-3qp4-gg3j-84xj.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3qp4-gg3j-84xj", + "modified": "2024-09-20T18:32:26Z", + "published": "2024-09-20T18:32:26Z", + "aliases": [ + "CVE-2024-9038" + ], + "details": "A vulnerability classified as problematic was found in Codezips Online Shopping Portal 1.0. Affected by this vulnerability is an unknown functionality of the file insert-product.php. The manipulation of the argument productimage1/productimage2/productimage3 leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9038" + }, + { + "type": "WEB", + "url": "https://github.com/L1OudFd8cl09/CVE/blob/main/20_09_2024_b.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.278209" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.278209" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.411466" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-20T16:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-4vcr-9h4j-55f8/GHSA-4vcr-9h4j-55f8.json b/advisories/unreviewed/2024/09/GHSA-4vcr-9h4j-55f8/GHSA-4vcr-9h4j-55f8.json new file mode 100644 index 00000000000..190209df12d --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-4vcr-9h4j-55f8/GHSA-4vcr-9h4j-55f8.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4vcr-9h4j-55f8", + "modified": "2024-09-20T18:32:26Z", + "published": "2024-09-20T18:32:26Z", + "aliases": [ + "CVE-2024-37879" + ], + "details": "Improper input validation in /admin/config/save in User-friendly SVN (USVN) before v1.0.12 and below allows administrators to execute arbitrary code via the fields \"siteTitle\", \"siteIco\" and \"siteLogo\".", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37879" + }, + { + "type": "WEB", + "url": "https://github.com/usvn/usvn/commit/6b4678954fca9635154743b95ff9c8947cf5f46f" + }, + { + "type": "WEB", + "url": "https://github.com/usvn/usvn/releases/tag/1.0.12" + }, + { + "type": "WEB", + "url": "https://www.usvn.info/2024/06/09/usvn-1.0.12" + }, + { + "type": "WEB", + "url": "https://www.usvn.info/news.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-20T17:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-7486-6g6r-5cxf/GHSA-7486-6g6r-5cxf.json b/advisories/unreviewed/2024/09/GHSA-7486-6g6r-5cxf/GHSA-7486-6g6r-5cxf.json new file mode 100644 index 00000000000..4ccb3761d2e --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-7486-6g6r-5cxf/GHSA-7486-6g6r-5cxf.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7486-6g6r-5cxf", + "modified": "2024-09-20T18:32:27Z", + "published": "2024-09-20T18:32:27Z", + "aliases": [ + "CVE-2024-42697" + ], + "details": "Cross Site Scripting vulnerability in Leotheme Leo Product Search Module v.2.1.6 and earlier allows a remote attacker to execute arbitrary code via the q parameter of the product search function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42697" + }, + { + "type": "WEB", + "url": "https://github.com/JustDinooo/CVEs/blob/main/CVE-2024-42697/poc.txt" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-20T18:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-786c-r55j-68wj/GHSA-786c-r55j-68wj.json b/advisories/unreviewed/2024/09/GHSA-786c-r55j-68wj/GHSA-786c-r55j-68wj.json index bd46675af65..30f8e59da53 100644 --- a/advisories/unreviewed/2024/09/GHSA-786c-r55j-68wj/GHSA-786c-r55j-68wj.json +++ b/advisories/unreviewed/2024/09/GHSA-786c-r55j-68wj/GHSA-786c-r55j-68wj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-786c-r55j-68wj", - "modified": "2024-09-18T09:30:38Z", + "modified": "2024-09-20T18:32:26Z", "published": "2024-09-18T09:30:38Z", "aliases": [ "CVE-2024-46801" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nlibfs: fix get_stashed_dentry()\n\nget_stashed_dentry() tries to optimistically retrieve a stashed dentry\nfrom a provided location. It needs to ensure to hold rcu lock before it\ndereference the stashed location to prevent UAF issues. Use\nrcu_dereference() instead of READ_ONCE() it's effectively equivalent\nwith some lockdep bells and whistles and it communicates clearly that\nthis expects rcu protection.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T08:15:06Z" diff --git a/advisories/unreviewed/2024/09/GHSA-7ccw-f88q-2crh/GHSA-7ccw-f88q-2crh.json b/advisories/unreviewed/2024/09/GHSA-7ccw-f88q-2crh/GHSA-7ccw-f88q-2crh.json index 9ac461b15d7..3ac349af4da 100644 --- a/advisories/unreviewed/2024/09/GHSA-7ccw-f88q-2crh/GHSA-7ccw-f88q-2crh.json +++ b/advisories/unreviewed/2024/09/GHSA-7ccw-f88q-2crh/GHSA-7ccw-f88q-2crh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7ccw-f88q-2crh", - "modified": "2024-09-18T09:30:35Z", + "modified": "2024-09-20T18:32:25Z", "published": "2024-09-18T09:30:35Z", "aliases": [ "CVE-2024-46719" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: typec: ucsi: Fix null pointer dereference in trace\n\nucsi_register_altmode checks IS_ERR for the alt pointer and treats\nNULL as valid. When CONFIG_TYPEC_DP_ALTMODE is not enabled,\nucsi_register_displayport returns NULL which causes a NULL pointer\ndereference in trace. Rather than return NULL, call\ntypec_port_register_altmode to register DisplayPort alternate mode\nas a non-controllable mode when CONFIG_TYPEC_DP_ALTMODE is not enabled.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -49,9 +52,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T07:15:03Z" diff --git a/advisories/unreviewed/2024/09/GHSA-7v6r-jgcw-v2j9/GHSA-7v6r-jgcw-v2j9.json b/advisories/unreviewed/2024/09/GHSA-7v6r-jgcw-v2j9/GHSA-7v6r-jgcw-v2j9.json index f7493d08c65..28cc6a60111 100644 --- a/advisories/unreviewed/2024/09/GHSA-7v6r-jgcw-v2j9/GHSA-7v6r-jgcw-v2j9.json +++ b/advisories/unreviewed/2024/09/GHSA-7v6r-jgcw-v2j9/GHSA-7v6r-jgcw-v2j9.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-284" + "CWE-284", + "CWE-639" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-7xv2-675g-4wq2/GHSA-7xv2-675g-4wq2.json b/advisories/unreviewed/2024/09/GHSA-7xv2-675g-4wq2/GHSA-7xv2-675g-4wq2.json new file mode 100644 index 00000000000..e1fef22fa5f --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-7xv2-675g-4wq2/GHSA-7xv2-675g-4wq2.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7xv2-675g-4wq2", + "modified": "2024-09-20T18:32:26Z", + "published": "2024-09-20T18:32:26Z", + "aliases": [ + "CVE-2023-47480" + ], + "details": "An issue in Pure Data 0.54-0 and fixed in 0.54-1 allows a local attacker to escalate privileges via the set*id () function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47480" + }, + { + "type": "WEB", + "url": "https://github.com/pure-data/pure-data/issues/2063" + }, + { + "type": "WEB", + "url": "https://github.com/pure-data/pure-data/commit/0b5e467b8728b3ed56e1a8ee5b367ce78e7e6e5d" + }, + { + "type": "WEB", + "url": "https://puredata.info" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-20T17:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-84q8-hphj-4r7w/GHSA-84q8-hphj-4r7w.json b/advisories/unreviewed/2024/09/GHSA-84q8-hphj-4r7w/GHSA-84q8-hphj-4r7w.json new file mode 100644 index 00000000000..2194cc1353a --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-84q8-hphj-4r7w/GHSA-84q8-hphj-4r7w.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-84q8-hphj-4r7w", + "modified": "2024-09-20T18:32:27Z", + "published": "2024-09-20T18:32:27Z", + "aliases": [ + "CVE-2024-45489" + ], + "details": "Arc before 2024-08-26 allows remote code execution in JavaScript boosts. Boosts that run JavaScript cannot be shared by default; however, it is possible to create or update a boost using another user's ID. This installs the boost in the victim's browser and runs arbitrary Javascript on that browser in a privileged context.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45489" + }, + { + "type": "WEB", + "url": "https://kibty.town/blog/arc" + }, + { + "type": "WEB", + "url": "https://news.ycombinator.com/item?id=41597250" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-20T17:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-94w6-j9m3-vpw3/GHSA-94w6-j9m3-vpw3.json b/advisories/unreviewed/2024/09/GHSA-94w6-j9m3-vpw3/GHSA-94w6-j9m3-vpw3.json index 6c2ff7e38d9..9992b877ebc 100644 --- a/advisories/unreviewed/2024/09/GHSA-94w6-j9m3-vpw3/GHSA-94w6-j9m3-vpw3.json +++ b/advisories/unreviewed/2024/09/GHSA-94w6-j9m3-vpw3/GHSA-94w6-j9m3-vpw3.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-319", "CWE-614" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/09/GHSA-967j-x656-wr8m/GHSA-967j-x656-wr8m.json b/advisories/unreviewed/2024/09/GHSA-967j-x656-wr8m/GHSA-967j-x656-wr8m.json index 92719778ef2..8355441b8a0 100644 --- a/advisories/unreviewed/2024/09/GHSA-967j-x656-wr8m/GHSA-967j-x656-wr8m.json +++ b/advisories/unreviewed/2024/09/GHSA-967j-x656-wr8m/GHSA-967j-x656-wr8m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-967j-x656-wr8m", - "modified": "2024-09-18T09:30:36Z", + "modified": "2024-09-20T18:32:25Z", "published": "2024-09-18T09:30:36Z", "aliases": [ "CVE-2024-46722" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: fix mc_data out-of-bounds read warning\n\nClear warning that read mc_data[i-1] may out-of-bounds.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T07:15:03Z" diff --git a/advisories/unreviewed/2024/09/GHSA-9hw6-9frh-hxrg/GHSA-9hw6-9frh-hxrg.json b/advisories/unreviewed/2024/09/GHSA-9hw6-9frh-hxrg/GHSA-9hw6-9frh-hxrg.json index 422ab99b237..bd4804a0ae1 100644 --- a/advisories/unreviewed/2024/09/GHSA-9hw6-9frh-hxrg/GHSA-9hw6-9frh-hxrg.json +++ b/advisories/unreviewed/2024/09/GHSA-9hw6-9frh-hxrg/GHSA-9hw6-9frh-hxrg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9hw6-9frh-hxrg", - "modified": "2024-09-13T06:30:43Z", + "modified": "2024-09-20T18:32:24Z", "published": "2024-09-13T06:30:43Z", "aliases": [ "CVE-2024-46689" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsoc: qcom: cmd-db: Map shared memory as WC, not WB\n\nLinux does not write into cmd-db region. This region of memory is write\nprotected by XPU. XPU may sometime falsely detect clean cache eviction\nas \"write\" into the write protected region leading to secure interrupt\nwhich causes an endless loop somewhere in Trust Zone.\n\nThe only reason it is working right now is because Qualcomm Hypervisor\nmaps the same region as Non-Cacheable memory in Stage 2 translation\ntables. The issue manifests if we want to use another hypervisor (like\nXen or KVM), which does not know anything about those specific mappings.\n\nChanging the mapping of cmd-db memory from MEMREMAP_WB to MEMREMAP_WT/WC\nremoves dependency on correct mappings in Stage 2 tables. This patch\nfixes the issue by updating the mapping to MEMREMAP_WC.\n\nI tested this on SA8155P with Xen.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -49,9 +52,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-13T06:15:13Z" diff --git a/advisories/unreviewed/2024/09/GHSA-9mqv-4j44-5r92/GHSA-9mqv-4j44-5r92.json b/advisories/unreviewed/2024/09/GHSA-9mqv-4j44-5r92/GHSA-9mqv-4j44-5r92.json index bd8c2ca1573..0580b3d73fb 100644 --- a/advisories/unreviewed/2024/09/GHSA-9mqv-4j44-5r92/GHSA-9mqv-4j44-5r92.json +++ b/advisories/unreviewed/2024/09/GHSA-9mqv-4j44-5r92/GHSA-9mqv-4j44-5r92.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9mqv-4j44-5r92", - "modified": "2024-09-18T09:30:35Z", + "modified": "2024-09-20T18:32:25Z", "published": "2024-09-18T09:30:35Z", "aliases": [ "CVE-2024-46720" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: fix dereference after null check\n\ncheck the pointer hive before use.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T07:15:03Z" diff --git a/advisories/unreviewed/2024/09/GHSA-cx7m-fcgf-9rj4/GHSA-cx7m-fcgf-9rj4.json b/advisories/unreviewed/2024/09/GHSA-cx7m-fcgf-9rj4/GHSA-cx7m-fcgf-9rj4.json index f0d1d73c6e4..d222c1f3530 100644 --- a/advisories/unreviewed/2024/09/GHSA-cx7m-fcgf-9rj4/GHSA-cx7m-fcgf-9rj4.json +++ b/advisories/unreviewed/2024/09/GHSA-cx7m-fcgf-9rj4/GHSA-cx7m-fcgf-9rj4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cx7m-fcgf-9rj4", - "modified": "2024-09-18T09:30:37Z", + "modified": "2024-09-20T18:32:25Z", "published": "2024-09-18T09:30:37Z", "aliases": [ "CVE-2024-46791" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: mcp251x: fix deadlock if an interrupt occurs during mcp251x_open\n\nThe mcp251x_hw_wake() function is called with the mpc_lock mutex held and\ndisables the interrupt handler so that no interrupts can be processed while\nwaking the device. If an interrupt has already occurred then waiting for\nthe interrupt handler to complete will deadlock because it will be trying\nto acquire the same mutex.\n\nCPU0 CPU1\n---- ----\nmcp251x_open()\n mutex_lock(&priv->mcp_lock)\n request_threaded_irq()\n \n mcp251x_can_ist()\n mutex_lock(&priv->mcp_lock)\n mcp251x_hw_wake()\n disable_irq() <-- deadlock\n\nUse disable_irq_nosync() instead because the interrupt handler does\neverything while holding the mutex so it doesn't matter if it's still\nrunning.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-667" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T08:15:06Z" diff --git a/advisories/unreviewed/2024/09/GHSA-gq2h-v95x-f5xp/GHSA-gq2h-v95x-f5xp.json b/advisories/unreviewed/2024/09/GHSA-gq2h-v95x-f5xp/GHSA-gq2h-v95x-f5xp.json new file mode 100644 index 00000000000..552eac65f59 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-gq2h-v95x-f5xp/GHSA-gq2h-v95x-f5xp.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gq2h-v95x-f5xp", + "modified": "2024-09-20T18:32:27Z", + "published": "2024-09-20T18:32:27Z", + "aliases": [ + "CVE-2024-9041" + ], + "details": "A vulnerability has been found in SourceCodester Best House Rental Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /ajax.php?action=update_account. The manipulation of the argument firstname/lastname/email leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9041" + }, + { + "type": "WEB", + "url": "https://github.com/para-paradise/webray.com.cn/blob/main/Best%20house%20rental%20management%20system%20project%20in%20php/Best%20house%20rental%20management%20system%20update_account%20time-based%20SQL%20Injection%20Vulnerability.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.278212" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.278212" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.411502" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-20T17:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-gwcv-998j-qccx/GHSA-gwcv-998j-qccx.json b/advisories/unreviewed/2024/09/GHSA-gwcv-998j-qccx/GHSA-gwcv-998j-qccx.json index 383dc0abd9d..58e3054e840 100644 --- a/advisories/unreviewed/2024/09/GHSA-gwcv-998j-qccx/GHSA-gwcv-998j-qccx.json +++ b/advisories/unreviewed/2024/09/GHSA-gwcv-998j-qccx/GHSA-gwcv-998j-qccx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gwcv-998j-qccx", - "modified": "2024-09-18T09:30:38Z", + "modified": "2024-09-20T18:32:26Z", "published": "2024-09-18T09:30:38Z", "aliases": [ "CVE-2024-46800" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsch/netem: fix use after free in netem_dequeue\n\nIf netem_dequeue() enqueues packet to inner qdisc and that qdisc\nreturns __NET_XMIT_STOLEN. The packet is dropped but\nqdisc_tree_reduce_backlog() is not called to update the parent's\nq.qlen, leading to the similar use-after-free as Commit\ne04991a48dbaf382 (\"netem: fix return value if duplicate enqueue\nfails\")\n\nCommands to trigger KASAN UaF:\n\nip link add type dummy\nip link set lo up\nip link set dummy0 up\ntc qdisc add dev lo parent root handle 1: drr\ntc filter add dev lo parent 1: basic classid 1:1\ntc class add dev lo classid 1:1 drr\ntc qdisc add dev lo parent 1:1 handle 2: netem\ntc qdisc add dev lo parent 2: handle 3: drr\ntc filter add dev lo parent 3: basic classid 3:1 action mirred egress\nredirect dev dummy0\ntc class add dev lo classid 3:1 drr\nping -c1 -W0.01 localhost # Trigger bug\ntc class del dev lo classid 1:1\ntc class add dev lo classid 1:1 drr\nping -c1 -W0.01 localhost # UaF", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T08:15:06Z" diff --git a/advisories/unreviewed/2024/09/GHSA-gxvv-xx83-rmg6/GHSA-gxvv-xx83-rmg6.json b/advisories/unreviewed/2024/09/GHSA-gxvv-xx83-rmg6/GHSA-gxvv-xx83-rmg6.json index ebc4d235e94..435f4fb9f09 100644 --- a/advisories/unreviewed/2024/09/GHSA-gxvv-xx83-rmg6/GHSA-gxvv-xx83-rmg6.json +++ b/advisories/unreviewed/2024/09/GHSA-gxvv-xx83-rmg6/GHSA-gxvv-xx83-rmg6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gxvv-xx83-rmg6", - "modified": "2024-09-18T09:30:36Z", + "modified": "2024-09-20T18:32:25Z", "published": "2024-09-18T09:30:36Z", "aliases": [ "CVE-2024-46724" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: Fix out-of-bounds read of df_v1_7_channel_number\n\nCheck the fb_channel_number range to avoid the array out-of-bounds\nread error", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T07:15:03Z" diff --git a/advisories/unreviewed/2024/09/GHSA-hg4p-55w9-888w/GHSA-hg4p-55w9-888w.json b/advisories/unreviewed/2024/09/GHSA-hg4p-55w9-888w/GHSA-hg4p-55w9-888w.json index 9249268f592..12891c6c2c7 100644 --- a/advisories/unreviewed/2024/09/GHSA-hg4p-55w9-888w/GHSA-hg4p-55w9-888w.json +++ b/advisories/unreviewed/2024/09/GHSA-hg4p-55w9-888w/GHSA-hg4p-55w9-888w.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hg4p-55w9-888w", - "modified": "2024-09-16T15:32:46Z", + "modified": "2024-09-20T18:32:25Z", "published": "2024-09-16T15:32:46Z", "aliases": [ "CVE-2024-6401" ], "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SFS Consulting InsureE GL allows SQL Injection.This issue affects InsureE GL: before 4.6.2.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" @@ -21,6 +25,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6401" }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.277555" + }, { "type": "WEB", "url": "https://www.usom.gov.tr/bildirim/tr-24-1475" diff --git a/advisories/unreviewed/2024/09/GHSA-jvc3-w86j-mcg3/GHSA-jvc3-w86j-mcg3.json b/advisories/unreviewed/2024/09/GHSA-jvc3-w86j-mcg3/GHSA-jvc3-w86j-mcg3.json index 88b0970d1e5..dc9139de738 100644 --- a/advisories/unreviewed/2024/09/GHSA-jvc3-w86j-mcg3/GHSA-jvc3-w86j-mcg3.json +++ b/advisories/unreviewed/2024/09/GHSA-jvc3-w86j-mcg3/GHSA-jvc3-w86j-mcg3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jvc3-w86j-mcg3", - "modified": "2024-09-18T09:30:36Z", + "modified": "2024-09-20T18:32:25Z", "published": "2024-09-18T09:30:36Z", "aliases": [ "CVE-2024-46743" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nof/irq: Prevent device address out-of-bounds read in interrupt map walk\n\nWhen of_irq_parse_raw() is invoked with a device address smaller than\nthe interrupt parent node (from #address-cells property), KASAN detects\nthe following out-of-bounds read when populating the initial match table\n(dyndbg=\"func of_irq_parse_* +p\"):\n\n OF: of_irq_parse_one: dev=/soc@0/picasso/watchdog, index=0\n OF: parent=/soc@0/pci@878000000000/gpio0@17,0, intsize=2\n OF: intspec=4\n OF: of_irq_parse_raw: ipar=/soc@0/pci@878000000000/gpio0@17,0, size=2\n OF: -> addrsize=3\n ==================================================================\n BUG: KASAN: slab-out-of-bounds in of_irq_parse_raw+0x2b8/0x8d0\n Read of size 4 at addr ffffff81beca5608 by task bash/764\n\n CPU: 1 PID: 764 Comm: bash Tainted: G O 6.1.67-484c613561-nokia_sm_arm64 #1\n Hardware name: Unknown Unknown Product/Unknown Product, BIOS 2023.01-12.24.03-dirty 01/01/2023\n Call trace:\n dump_backtrace+0xdc/0x130\n show_stack+0x1c/0x30\n dump_stack_lvl+0x6c/0x84\n print_report+0x150/0x448\n kasan_report+0x98/0x140\n __asan_load4+0x78/0xa0\n of_irq_parse_raw+0x2b8/0x8d0\n of_irq_parse_one+0x24c/0x270\n parse_interrupts+0xc0/0x120\n of_fwnode_add_links+0x100/0x2d0\n fw_devlink_parse_fwtree+0x64/0xc0\n device_add+0xb38/0xc30\n of_device_add+0x64/0x90\n of_platform_device_create_pdata+0xd0/0x170\n of_platform_bus_create+0x244/0x600\n of_platform_notify+0x1b0/0x254\n blocking_notifier_call_chain+0x9c/0xd0\n __of_changeset_entry_notify+0x1b8/0x230\n __of_changeset_apply_notify+0x54/0xe4\n of_overlay_fdt_apply+0xc04/0xd94\n ...\n\n The buggy address belongs to the object at ffffff81beca5600\n which belongs to the cache kmalloc-128 of size 128\n The buggy address is located 8 bytes inside of\n 128-byte region [ffffff81beca5600, ffffff81beca5680)\n\n The buggy address belongs to the physical page:\n page:00000000230d3d03 refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x1beca4\n head:00000000230d3d03 order:1 compound_mapcount:0 compound_pincount:0\n flags: 0x8000000000010200(slab|head|zone=2)\n raw: 8000000000010200 0000000000000000 dead000000000122 ffffff810000c300\n raw: 0000000000000000 0000000000200020 00000001ffffffff 0000000000000000\n page dumped because: kasan: bad access detected\n\n Memory state around the buggy address:\n ffffff81beca5500: 04 fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc\n ffffff81beca5580: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc\n >ffffff81beca5600: 00 fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc\n ^\n ffffff81beca5680: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc\n ffffff81beca5700: 00 00 00 00 00 00 fc fc fc fc fc fc fc fc fc fc\n ==================================================================\n OF: -> got it !\n\nPrevent the out-of-bounds read by copying the device address into a\nbuffer of sufficient size.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T08:15:03Z" diff --git a/advisories/unreviewed/2024/09/GHSA-m62g-7v8j-3fwc/GHSA-m62g-7v8j-3fwc.json b/advisories/unreviewed/2024/09/GHSA-m62g-7v8j-3fwc/GHSA-m62g-7v8j-3fwc.json index ab394ada7ad..a2349524757 100644 --- a/advisories/unreviewed/2024/09/GHSA-m62g-7v8j-3fwc/GHSA-m62g-7v8j-3fwc.json +++ b/advisories/unreviewed/2024/09/GHSA-m62g-7v8j-3fwc/GHSA-m62g-7v8j-3fwc.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-m849-gvp2-qmmr/GHSA-m849-gvp2-qmmr.json b/advisories/unreviewed/2024/09/GHSA-m849-gvp2-qmmr/GHSA-m849-gvp2-qmmr.json index f1e7408a9c2..9fec0bc4cb7 100644 --- a/advisories/unreviewed/2024/09/GHSA-m849-gvp2-qmmr/GHSA-m849-gvp2-qmmr.json +++ b/advisories/unreviewed/2024/09/GHSA-m849-gvp2-qmmr/GHSA-m849-gvp2-qmmr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m849-gvp2-qmmr", - "modified": "2024-09-18T09:30:38Z", + "modified": "2024-09-20T18:32:25Z", "published": "2024-09-18T09:30:37Z", "aliases": [ "CVE-2024-46795" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: unset the binding mark of a reused connection\n\nSteve French reported null pointer dereference error from sha256 lib.\ncifs.ko can send session setup requests on reused connection.\nIf reused connection is used for binding session, conn->binding can\nstill remain true and generate_preauth_hash() will not set\nsess->Preauth_HashValue and it will be NULL.\nIt is used as a material to create an encryption key in\nksmbd_gen_smb311_encryptionkey. ->Preauth_HashValue cause null pointer\ndereference error from crypto_shash_update().\n\nBUG: kernel NULL pointer dereference, address: 0000000000000000\n#PF: supervisor read access in kernel mode\n#PF: error_code(0x0000) - not-present page\nPGD 0 P4D 0\nOops: 0000 [#1] PREEMPT SMP PTI\nCPU: 8 PID: 429254 Comm: kworker/8:39\nHardware name: LENOVO 20MAS08500/20MAS08500, BIOS N2CET69W (1.52 )\nWorkqueue: ksmbd-io handle_ksmbd_work [ksmbd]\nRIP: 0010:lib_sha256_base_do_update.isra.0+0x11e/0x1d0 [sha256_ssse3]\n\n? show_regs+0x6d/0x80\n? __die+0x24/0x80\n? page_fault_oops+0x99/0x1b0\n? do_user_addr_fault+0x2ee/0x6b0\n? exc_page_fault+0x83/0x1b0\n? asm_exc_page_fault+0x27/0x30\n? __pfx_sha256_transform_rorx+0x10/0x10 [sha256_ssse3]\n? lib_sha256_base_do_update.isra.0+0x11e/0x1d0 [sha256_ssse3]\n? __pfx_sha256_transform_rorx+0x10/0x10 [sha256_ssse3]\n? __pfx_sha256_transform_rorx+0x10/0x10 [sha256_ssse3]\n_sha256_update+0x77/0xa0 [sha256_ssse3]\nsha256_avx2_update+0x15/0x30 [sha256_ssse3]\ncrypto_shash_update+0x1e/0x40\nhmac_update+0x12/0x20\ncrypto_shash_update+0x1e/0x40\ngenerate_key+0x234/0x380 [ksmbd]\ngenerate_smb3encryptionkey+0x40/0x1c0 [ksmbd]\nksmbd_gen_smb311_encryptionkey+0x72/0xa0 [ksmbd]\nntlm_authenticate.isra.0+0x423/0x5d0 [ksmbd]\nsmb2_sess_setup+0x952/0xaa0 [ksmbd]\n__process_request+0xa3/0x1d0 [ksmbd]\n__handle_ksmbd_work+0x1c4/0x2f0 [ksmbd]\nhandle_ksmbd_work+0x2d/0xa0 [ksmbd]\nprocess_one_work+0x16c/0x350\nworker_thread+0x306/0x440\n? __pfx_worker_thread+0x10/0x10\nkthread+0xef/0x120\n? __pfx_kthread+0x10/0x10\nret_from_fork+0x44/0x70\n? __pfx_kthread+0x10/0x10\nret_from_fork_asm+0x1b/0x30\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T08:15:06Z" diff --git a/advisories/unreviewed/2024/09/GHSA-m8jr-w275-x227/GHSA-m8jr-w275-x227.json b/advisories/unreviewed/2024/09/GHSA-m8jr-w275-x227/GHSA-m8jr-w275-x227.json index 936a128ebbf..da7ee98f22b 100644 --- a/advisories/unreviewed/2024/09/GHSA-m8jr-w275-x227/GHSA-m8jr-w275-x227.json +++ b/advisories/unreviewed/2024/09/GHSA-m8jr-w275-x227/GHSA-m8jr-w275-x227.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m8jr-w275-x227", - "modified": "2024-09-18T09:30:38Z", + "modified": "2024-09-20T18:32:25Z", "published": "2024-09-18T09:30:37Z", "aliases": [ "CVE-2024-46796" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix double put of @cfile in smb2_set_path_size()\n\nIf smb2_compound_op() is called with a valid @cfile and returned\n-EINVAL, we need to call cifs_get_writable_path() before retrying it\nas the reference of @cfile was already dropped by previous call.\n\nThis fixes the following KASAN splat when running fstests generic/013\nagainst Windows Server 2022:\n\n CIFS: Attempting to mount //w22-fs0/scratch\n run fstests generic/013 at 2024-09-02 19:48:59\n ==================================================================\n BUG: KASAN: slab-use-after-free in detach_if_pending+0xab/0x200\n Write of size 8 at addr ffff88811f1a3730 by task kworker/3:2/176\n\n CPU: 3 UID: 0 PID: 176 Comm: kworker/3:2 Not tainted 6.11.0-rc6 #2\n Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-2.fc40\n 04/01/2014\n Workqueue: cifsoplockd cifs_oplock_break [cifs]\n Call Trace:\n \n dump_stack_lvl+0x5d/0x80\n ? detach_if_pending+0xab/0x200\n print_report+0x156/0x4d9\n ? detach_if_pending+0xab/0x200\n ? __virt_addr_valid+0x145/0x300\n ? __phys_addr+0x46/0x90\n ? detach_if_pending+0xab/0x200\n kasan_report+0xda/0x110\n ? detach_if_pending+0xab/0x200\n detach_if_pending+0xab/0x200\n timer_delete+0x96/0xe0\n ? __pfx_timer_delete+0x10/0x10\n ? rcu_is_watching+0x20/0x50\n try_to_grab_pending+0x46/0x3b0\n __cancel_work+0x89/0x1b0\n ? __pfx___cancel_work+0x10/0x10\n ? kasan_save_track+0x14/0x30\n cifs_close_deferred_file+0x110/0x2c0 [cifs]\n ? __pfx_cifs_close_deferred_file+0x10/0x10 [cifs]\n ? __pfx_down_read+0x10/0x10\n cifs_oplock_break+0x4c1/0xa50 [cifs]\n ? __pfx_cifs_oplock_break+0x10/0x10 [cifs]\n ? lock_is_held_type+0x85/0xf0\n ? mark_held_locks+0x1a/0x90\n process_one_work+0x4c6/0x9f0\n ? find_held_lock+0x8a/0xa0\n ? __pfx_process_one_work+0x10/0x10\n ? lock_acquired+0x220/0x550\n ? __list_add_valid_or_report+0x37/0x100\n worker_thread+0x2e4/0x570\n ? __kthread_parkme+0xd1/0xf0\n ? __pfx_worker_thread+0x10/0x10\n kthread+0x17f/0x1c0\n ? kthread+0xda/0x1c0\n ? __pfx_kthread+0x10/0x10\n ret_from_fork+0x31/0x60\n ? __pfx_kthread+0x10/0x10\n ret_from_fork_asm+0x1a/0x30\n \n\n Allocated by task 1118:\n kasan_save_stack+0x30/0x50\n kasan_save_track+0x14/0x30\n __kasan_kmalloc+0xaa/0xb0\n cifs_new_fileinfo+0xc8/0x9d0 [cifs]\n cifs_atomic_open+0x467/0x770 [cifs]\n lookup_open.isra.0+0x665/0x8b0\n path_openat+0x4c3/0x1380\n do_filp_open+0x167/0x270\n do_sys_openat2+0x129/0x160\n __x64_sys_creat+0xad/0xe0\n do_syscall_64+0xbb/0x1d0\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\n Freed by task 83:\n kasan_save_stack+0x30/0x50\n kasan_save_track+0x14/0x30\n kasan_save_free_info+0x3b/0x70\n poison_slab_object+0xe9/0x160\n __kasan_slab_free+0x32/0x50\n kfree+0xf2/0x300\n process_one_work+0x4c6/0x9f0\n worker_thread+0x2e4/0x570\n kthread+0x17f/0x1c0\n ret_from_fork+0x31/0x60\n ret_from_fork_asm+0x1a/0x30\n\n Last potentially related work creation:\n kasan_save_stack+0x30/0x50\n __kasan_record_aux_stack+0xad/0xc0\n insert_work+0x29/0xe0\n __queue_work+0x5ea/0x760\n queue_work_on+0x6d/0x90\n _cifsFileInfo_put+0x3f6/0x770 [cifs]\n smb2_compound_op+0x911/0x3940 [cifs]\n smb2_set_path_size+0x228/0x270 [cifs]\n cifs_set_file_size+0x197/0x460 [cifs]\n cifs_setattr+0xd9c/0x14b0 [cifs]\n notify_change+0x4e3/0x740\n do_truncate+0xfa/0x180\n vfs_truncate+0x195/0x200\n __x64_sys_truncate+0x109/0x150\n do_syscall_64+0xbb/0x1d0\n entry_SYSCALL_64_after_hwframe+0x77/0x7f", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T08:15:06Z" diff --git a/advisories/unreviewed/2024/09/GHSA-mqjq-8h5p-w29m/GHSA-mqjq-8h5p-w29m.json b/advisories/unreviewed/2024/09/GHSA-mqjq-8h5p-w29m/GHSA-mqjq-8h5p-w29m.json new file mode 100644 index 00000000000..26c49218085 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-mqjq-8h5p-w29m/GHSA-mqjq-8h5p-w29m.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mqjq-8h5p-w29m", + "modified": "2024-09-20T18:32:26Z", + "published": "2024-09-20T18:32:26Z", + "aliases": [ + "CVE-2024-9039" + ], + "details": "A vulnerability, which was classified as critical, has been found in SourceCodester Best House Rental Management System 1.0. Affected by this issue is some unknown functionality of the file /ajax.php?action=signup. The manipulation of the argument firstname/lastname/email leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9039" + }, + { + "type": "WEB", + "url": "https://github.com/para-paradise/webray.com.cn/blob/main/Best%20house%20rental%20management%20system%20project%20in%20php/Best%20house%20rental%20management%20system%20signup%20time-based%20SQL%20Injection%20Vulnerability.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.278210" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.278210" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.411471" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-20T16:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-p42p-v9g2-2qc5/GHSA-p42p-v9g2-2qc5.json b/advisories/unreviewed/2024/09/GHSA-p42p-v9g2-2qc5/GHSA-p42p-v9g2-2qc5.json index e767c2ba291..aa2cbbf501d 100644 --- a/advisories/unreviewed/2024/09/GHSA-p42p-v9g2-2qc5/GHSA-p42p-v9g2-2qc5.json +++ b/advisories/unreviewed/2024/09/GHSA-p42p-v9g2-2qc5/GHSA-p42p-v9g2-2qc5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p42p-v9g2-2qc5", - "modified": "2024-09-10T15:31:05Z", + "modified": "2024-09-20T18:32:24Z", "published": "2024-09-10T15:31:05Z", "aliases": [ "CVE-2024-45323" diff --git a/advisories/unreviewed/2024/09/GHSA-p6pf-4j65-mvw8/GHSA-p6pf-4j65-mvw8.json b/advisories/unreviewed/2024/09/GHSA-p6pf-4j65-mvw8/GHSA-p6pf-4j65-mvw8.json index 2ab3b9529f3..164ab84d8d7 100644 --- a/advisories/unreviewed/2024/09/GHSA-p6pf-4j65-mvw8/GHSA-p6pf-4j65-mvw8.json +++ b/advisories/unreviewed/2024/09/GHSA-p6pf-4j65-mvw8/GHSA-p6pf-4j65-mvw8.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p6pf-4j65-mvw8", - "modified": "2024-09-06T18:31:34Z", + "modified": "2024-09-20T18:32:24Z", "published": "2024-09-06T18:31:34Z", "aliases": [ "CVE-2024-32763" ], "details": "A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute code via a network.\n\nWe have already fixed the vulnerability in the following versions:\nQTS 5.1.8.2823 build 20240712 and later\nQuTS hero h5.1.8.2823 build 20240712 and later", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/09/GHSA-pcj5-c4v2-hq4g/GHSA-pcj5-c4v2-hq4g.json b/advisories/unreviewed/2024/09/GHSA-pcj5-c4v2-hq4g/GHSA-pcj5-c4v2-hq4g.json new file mode 100644 index 00000000000..fc0c870fdf5 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-pcj5-c4v2-hq4g/GHSA-pcj5-c4v2-hq4g.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pcj5-c4v2-hq4g", + "modified": "2024-09-20T18:32:27Z", + "published": "2024-09-20T18:32:27Z", + "aliases": [ + "CVE-2024-9040" + ], + "details": "A vulnerability, which was classified as problematic, was found in code-projects Blood Bank Management System 1.0. This affects an unknown part of the component Password Handler. The manipulation leads to cleartext storage in a file or on disk. An attack has to be approached locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9040" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.278211" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.278211" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-313" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-20T17:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-pfgc-2q82-vggq/GHSA-pfgc-2q82-vggq.json b/advisories/unreviewed/2024/09/GHSA-pfgc-2q82-vggq/GHSA-pfgc-2q82-vggq.json index 1918227319d..ef1d367c872 100644 --- a/advisories/unreviewed/2024/09/GHSA-pfgc-2q82-vggq/GHSA-pfgc-2q82-vggq.json +++ b/advisories/unreviewed/2024/09/GHSA-pfgc-2q82-vggq/GHSA-pfgc-2q82-vggq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pfgc-2q82-vggq", - "modified": "2024-09-13T06:30:43Z", + "modified": "2024-09-20T18:32:24Z", "published": "2024-09-13T06:30:43Z", "aliases": [ "CVE-2024-46690" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: fix nfsd4_deleg_getattr_conflict in presence of third party lease\n\nIt is not safe to dereference fl->c.flc_owner without first confirming\nfl->fl_lmops is the expected manager. nfsd4_deleg_getattr_conflict()\ntests fl_lmops but largely ignores the result and assumes that flc_owner\nis an nfs4_delegation anyway. This is wrong.\n\nWith this patch we restore the \"!= &nfsd_lease_mng_ops\" case to behave\nas it did before the change mentioned below. This is the same as the\ncurrent code, but without any reference to a possible delegation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-13T06:15:13Z" diff --git a/advisories/unreviewed/2024/09/GHSA-qf44-c626-28f4/GHSA-qf44-c626-28f4.json b/advisories/unreviewed/2024/09/GHSA-qf44-c626-28f4/GHSA-qf44-c626-28f4.json index e4a23b403de..09e6e1b3874 100644 --- a/advisories/unreviewed/2024/09/GHSA-qf44-c626-28f4/GHSA-qf44-c626-28f4.json +++ b/advisories/unreviewed/2024/09/GHSA-qf44-c626-28f4/GHSA-qf44-c626-28f4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qf44-c626-28f4", - "modified": "2024-09-13T06:30:42Z", + "modified": "2024-09-20T18:32:24Z", "published": "2024-09-13T06:30:42Z", "aliases": [ "CVE-2024-46675" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: dwc3: core: Prevent USB core invalid event buffer address access\n\nThis commit addresses an issue where the USB core could access an\ninvalid event buffer address during runtime suspend, potentially causing\nSMMU faults and other memory issues in Exynos platforms. The problem\narises from the following sequence.\n 1. In dwc3_gadget_suspend, there is a chance of a timeout when\n moving the USB core to the halt state after clearing the\n run/stop bit by software.\n 2. In dwc3_core_exit, the event buffer is cleared regardless of\n the USB core's status, which may lead to an SMMU faults and\n other memory issues. if the USB core tries to access the event\n buffer address.\n\nTo prevent this hardware quirk on Exynos platforms, this commit ensures\nthat the event buffer address is not cleared by software when the USB\ncore is active during runtime suspend by checking its status before\nclearing the buffer address.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -55,7 +58,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-13T06:15:12Z" diff --git a/advisories/unreviewed/2024/09/GHSA-rh54-7qq9-x5v8/GHSA-rh54-7qq9-x5v8.json b/advisories/unreviewed/2024/09/GHSA-rh54-7qq9-x5v8/GHSA-rh54-7qq9-x5v8.json index 9d8d6d6fcb9..1d402e5facb 100644 --- a/advisories/unreviewed/2024/09/GHSA-rh54-7qq9-x5v8/GHSA-rh54-7qq9-x5v8.json +++ b/advisories/unreviewed/2024/09/GHSA-rh54-7qq9-x5v8/GHSA-rh54-7qq9-x5v8.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rh54-7qq9-x5v8", - "modified": "2024-09-16T15:32:47Z", + "modified": "2024-09-20T18:32:25Z", "published": "2024-09-16T15:32:46Z", "aliases": [ "CVE-2024-7098" ], "details": "Improper Restriction of XML External Entity Reference vulnerability in SFS Consulting ww.Winsure allows XML Injection.This issue affects ww.Winsure: before 4.6.2.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:L/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/09/GHSA-v977-rccx-6678/GHSA-v977-rccx-6678.json b/advisories/unreviewed/2024/09/GHSA-v977-rccx-6678/GHSA-v977-rccx-6678.json index d68467f2a4a..4b6510d785b 100644 --- a/advisories/unreviewed/2024/09/GHSA-v977-rccx-6678/GHSA-v977-rccx-6678.json +++ b/advisories/unreviewed/2024/09/GHSA-v977-rccx-6678/GHSA-v977-rccx-6678.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v977-rccx-6678", - "modified": "2024-09-18T09:30:38Z", + "modified": "2024-09-20T18:32:25Z", "published": "2024-09-18T09:30:38Z", "aliases": [ "CVE-2024-46798" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: dapm: Fix UAF for snd_soc_pcm_runtime object\n\nWhen using kernel with the following extra config,\n\n - CONFIG_KASAN=y\n - CONFIG_KASAN_GENERIC=y\n - CONFIG_KASAN_INLINE=y\n - CONFIG_KASAN_VMALLOC=y\n - CONFIG_FRAME_WARN=4096\n\nkernel detects that snd_pcm_suspend_all() access a freed\n'snd_soc_pcm_runtime' object when the system is suspended, which\nleads to a use-after-free bug:\n\n[ 52.047746] BUG: KASAN: use-after-free in snd_pcm_suspend_all+0x1a8/0x270\n[ 52.047765] Read of size 1 at addr ffff0000b9434d50 by task systemd-sleep/2330\n\n[ 52.047785] Call trace:\n[ 52.047787] dump_backtrace+0x0/0x3c0\n[ 52.047794] show_stack+0x34/0x50\n[ 52.047797] dump_stack_lvl+0x68/0x8c\n[ 52.047802] print_address_description.constprop.0+0x74/0x2c0\n[ 52.047809] kasan_report+0x210/0x230\n[ 52.047815] __asan_report_load1_noabort+0x3c/0x50\n[ 52.047820] snd_pcm_suspend_all+0x1a8/0x270\n[ 52.047824] snd_soc_suspend+0x19c/0x4e0\n\nThe snd_pcm_sync_stop() has a NULL check on 'substream->runtime' before\nmaking any access. So we need to always set 'substream->runtime' to NULL\neverytime we kfree() it.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -49,9 +52,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T08:15:06Z" diff --git a/advisories/unreviewed/2024/09/GHSA-vpw4-xpvg-hf99/GHSA-vpw4-xpvg-hf99.json b/advisories/unreviewed/2024/09/GHSA-vpw4-xpvg-hf99/GHSA-vpw4-xpvg-hf99.json index 01863831fca..c17964de44a 100644 --- a/advisories/unreviewed/2024/09/GHSA-vpw4-xpvg-hf99/GHSA-vpw4-xpvg-hf99.json +++ b/advisories/unreviewed/2024/09/GHSA-vpw4-xpvg-hf99/GHSA-vpw4-xpvg-hf99.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vpw4-xpvg-hf99", - "modified": "2024-09-18T09:30:36Z", + "modified": "2024-09-20T18:32:25Z", "published": "2024-09-18T09:30:36Z", "aliases": [ "CVE-2024-46747" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: cougar: fix slab-out-of-bounds Read in cougar_report_fixup\n\nreport_fixup for the Cougar 500k Gaming Keyboard was not verifying\nthat the report descriptor size was correct before accessing it", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T08:15:03Z" diff --git a/advisories/unreviewed/2024/09/GHSA-vxfc-g29g-39m5/GHSA-vxfc-g29g-39m5.json b/advisories/unreviewed/2024/09/GHSA-vxfc-g29g-39m5/GHSA-vxfc-g29g-39m5.json index 66fb4e9fdfe..9aef98abf4d 100644 --- a/advisories/unreviewed/2024/09/GHSA-vxfc-g29g-39m5/GHSA-vxfc-g29g-39m5.json +++ b/advisories/unreviewed/2024/09/GHSA-vxfc-g29g-39m5/GHSA-vxfc-g29g-39m5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vxfc-g29g-39m5", - "modified": "2024-09-18T09:30:36Z", + "modified": "2024-09-20T18:32:25Z", "published": "2024-09-18T09:30:36Z", "aliases": [ "CVE-2024-46723" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: fix ucode out-of-bounds read warning\n\nClear warning that read ucode[] may out-of-bounds.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T07:15:03Z" diff --git a/advisories/unreviewed/2024/09/GHSA-whq8-5442-qhw7/GHSA-whq8-5442-qhw7.json b/advisories/unreviewed/2024/09/GHSA-whq8-5442-qhw7/GHSA-whq8-5442-qhw7.json new file mode 100644 index 00000000000..e87f3e10458 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-whq8-5442-qhw7/GHSA-whq8-5442-qhw7.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-whq8-5442-qhw7", + "modified": "2024-09-20T18:32:27Z", + "published": "2024-09-20T18:32:27Z", + "aliases": [ + "CVE-2024-8612" + ], + "details": "A flaw was found in QEMU, in the virtio-scsi, virtio-blk, and virtio-crypto devices. The size for virtqueue_push as set in virtio_scsi_complete_req / virtio_blk_req_complete / virito_crypto_req_complete could be larger than the true size of the data which has been sent to guest. Once virtqueue_push() finally calls dma_memory_unmap to ummap the in_iov, it may call the address_space_write function to write back the data. Some uninitialized data may exist in the bounce.buffer, leading to an information leak.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8612" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-8612" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2313760" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-20T18:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-xh89-f5vr-hmhw/GHSA-xh89-f5vr-hmhw.json b/advisories/unreviewed/2024/09/GHSA-xh89-f5vr-hmhw/GHSA-xh89-f5vr-hmhw.json new file mode 100644 index 00000000000..004deda4a70 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-xh89-f5vr-hmhw/GHSA-xh89-f5vr-hmhw.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xh89-f5vr-hmhw", + "modified": "2024-09-20T18:32:26Z", + "published": "2024-09-20T18:32:26Z", + "aliases": [ + "CVE-2024-46652" + ], + "details": "Tenda AC8v4 V16.03.34.06 has a stack overflow vulnerability in the fromAdvSetMacMtuWan function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46652" + }, + { + "type": "WEB", + "url": "https://github.com/zp9080/Tenda/blob/main/Tenda-AC8v4%20V16.03.34.06-fromAdvSetMacMtuWan/overview.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-20T16:15:05Z" + } +} \ No newline at end of file