From 483eeeb1ec2f0c2642de4fb79916413a62971e59 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 8 Aug 2024 18:32:49 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-frcq-c5pr-jg4q.json | 11 ++-- .../GHSA-px8r-9qv3-6525.json | 11 ++-- .../GHSA-6cjw-2w3q-pv7g.json | 11 ++-- .../GHSA-7xjx-6mf4-7xgc.json | 11 ++-- .../GHSA-8wq2-m78j-qq93.json | 2 +- .../GHSA-97rm-7vq8-qwj2.json | 2 +- .../GHSA-h47h-5hqh-63xw.json | 11 ++-- .../GHSA-8g8j-p6r7-xj34.json | 11 ++-- .../GHSA-c473-m4mh-crhw.json | 11 ++-- .../GHSA-gx5g-rjjv-754q.json | 2 +- .../GHSA-jmpm-75w8-qgjx.json | 3 +- .../GHSA-r8x8-rv8c-j266.json | 11 ++-- .../GHSA-rvfp-m6f3-8v6h.json | 11 ++-- .../GHSA-wx4v-qgjj-9f5j.json | 11 ++-- .../GHSA-4rvm-m82p-p79p.json | 2 +- .../GHSA-5729-2v3w-2h7m.json | 6 ++- .../GHSA-62hv-vfr8-65mw.json | 6 ++- .../GHSA-9r6p-56h8-7v76.json | 6 ++- .../GHSA-gh8f-3437-7ch5.json | 6 ++- .../GHSA-grm8-7p8f-2rp6.json | 11 ++-- .../GHSA-j4fv-r5w9-h675.json | 10 +++- .../GHSA-rp92-93hq-c7q8.json | 6 ++- .../GHSA-3vvq-h94f-pm68.json | 11 ++-- .../GHSA-57hr-r2gg-fqr9.json | 11 ++-- .../GHSA-6fvv-3vw6-wp7c.json | 11 ++-- .../GHSA-8qxj-f84c-r77w.json | 11 ++-- .../GHSA-cm3g-9rxc-2598.json | 11 ++-- .../GHSA-f5xx-949w-7ch3.json | 11 ++-- .../GHSA-f6mg-hq7f-jw2j.json | 2 +- .../GHSA-jvmg-77fx-pxw2.json | 11 ++-- .../GHSA-x274-3j7p-qfpp.json | 11 ++-- .../GHSA-x35g-752c-r3xh.json | 11 ++-- .../GHSA-28pp-675x-rf35.json | 46 +++++++++++++++++ .../GHSA-2hrx-xx6v-c3v2.json | 38 ++++++++++++++ .../GHSA-5gj6-wwjq-frjh.json | 38 ++++++++++++++ .../GHSA-6jjg-3cm7-jjfj.json | 46 +++++++++++++++++ .../GHSA-6w5f-w9gf-qv9r.json | 42 ++++++++++++++++ .../GHSA-743g-pfwq-r4wv.json | 38 ++++++++++++++ .../GHSA-757v-57mw-8gq9.json | 39 +++++++++++++++ .../GHSA-7jrj-xq8x-h553.json | 11 ++-- .../GHSA-898x-8mpw-mjf8.json | 38 ++++++++++++++ .../GHSA-8h54-xh89-c57v.json | 46 +++++++++++++++++ .../GHSA-c9w5-xr92-cpm7.json | 39 +++++++++++++++ .../GHSA-m578-pv52-h53w.json | 2 +- .../GHSA-mj2x-c9j2-vp7g.json | 39 +++++++++++++++ .../GHSA-p9q4-cppj-78gq.json | 35 +++++++++++++ .../GHSA-pqx2-f9cx-8825.json | 38 ++++++++++++++ .../GHSA-pwxm-h2xg-rwv6.json | 11 ++-- .../GHSA-qrrm-xwcc-693j.json | 42 ++++++++++++++++ .../GHSA-qx4x-h5xp-mmqx.json | 39 +++++++++++++++ .../GHSA-vfcg-vh6j-gg8j.json | 9 ++-- .../GHSA-w6j6-w6jx-vf2r.json | 50 +++++++++++++++++++ .../GHSA-w8qw-wpmq-q46h.json | 38 ++++++++++++++ .../GHSA-whp7-r8fh-f38c.json | 38 ++++++++++++++ .../GHSA-x6j3-2cg8-g68w.json | 39 +++++++++++++++ .../GHSA-xg77-wrvc-q75c.json | 2 +- .../GHSA-xvgc-j98h-3v9x.json | 39 +++++++++++++++ 57 files changed, 1010 insertions(+), 105 deletions(-) create mode 100644 advisories/unreviewed/2024/08/GHSA-28pp-675x-rf35/GHSA-28pp-675x-rf35.json create mode 100644 advisories/unreviewed/2024/08/GHSA-2hrx-xx6v-c3v2/GHSA-2hrx-xx6v-c3v2.json create mode 100644 advisories/unreviewed/2024/08/GHSA-5gj6-wwjq-frjh/GHSA-5gj6-wwjq-frjh.json create mode 100644 advisories/unreviewed/2024/08/GHSA-6jjg-3cm7-jjfj/GHSA-6jjg-3cm7-jjfj.json create mode 100644 advisories/unreviewed/2024/08/GHSA-6w5f-w9gf-qv9r/GHSA-6w5f-w9gf-qv9r.json create mode 100644 advisories/unreviewed/2024/08/GHSA-743g-pfwq-r4wv/GHSA-743g-pfwq-r4wv.json create mode 100644 advisories/unreviewed/2024/08/GHSA-757v-57mw-8gq9/GHSA-757v-57mw-8gq9.json create mode 100644 advisories/unreviewed/2024/08/GHSA-898x-8mpw-mjf8/GHSA-898x-8mpw-mjf8.json create mode 100644 advisories/unreviewed/2024/08/GHSA-8h54-xh89-c57v/GHSA-8h54-xh89-c57v.json create mode 100644 advisories/unreviewed/2024/08/GHSA-c9w5-xr92-cpm7/GHSA-c9w5-xr92-cpm7.json create mode 100644 advisories/unreviewed/2024/08/GHSA-mj2x-c9j2-vp7g/GHSA-mj2x-c9j2-vp7g.json create mode 100644 advisories/unreviewed/2024/08/GHSA-p9q4-cppj-78gq/GHSA-p9q4-cppj-78gq.json create mode 100644 advisories/unreviewed/2024/08/GHSA-pqx2-f9cx-8825/GHSA-pqx2-f9cx-8825.json create mode 100644 advisories/unreviewed/2024/08/GHSA-qrrm-xwcc-693j/GHSA-qrrm-xwcc-693j.json create mode 100644 advisories/unreviewed/2024/08/GHSA-qx4x-h5xp-mmqx/GHSA-qx4x-h5xp-mmqx.json create mode 100644 advisories/unreviewed/2024/08/GHSA-w6j6-w6jx-vf2r/GHSA-w6j6-w6jx-vf2r.json create mode 100644 advisories/unreviewed/2024/08/GHSA-w8qw-wpmq-q46h/GHSA-w8qw-wpmq-q46h.json create mode 100644 advisories/unreviewed/2024/08/GHSA-whp7-r8fh-f38c/GHSA-whp7-r8fh-f38c.json create mode 100644 advisories/unreviewed/2024/08/GHSA-x6j3-2cg8-g68w/GHSA-x6j3-2cg8-g68w.json create mode 100644 advisories/unreviewed/2024/08/GHSA-xvgc-j98h-3v9x/GHSA-xvgc-j98h-3v9x.json diff --git a/advisories/unreviewed/2024/03/GHSA-frcq-c5pr-jg4q/GHSA-frcq-c5pr-jg4q.json b/advisories/unreviewed/2024/03/GHSA-frcq-c5pr-jg4q/GHSA-frcq-c5pr-jg4q.json index a44379f6108..38d6c71fd21 100644 --- a/advisories/unreviewed/2024/03/GHSA-frcq-c5pr-jg4q/GHSA-frcq-c5pr-jg4q.json +++ b/advisories/unreviewed/2024/03/GHSA-frcq-c5pr-jg4q/GHSA-frcq-c5pr-jg4q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-frcq-c5pr-jg4q", - "modified": "2024-03-27T00:30:55Z", + "modified": "2024-08-08T18:31:18Z", "published": "2024-03-27T00:30:55Z", "aliases": [ "CVE-2023-50702" ], "details": "Sikka SSCWindowsService 5 2023-09-14 executes a program as LocalSystem but allows full control by low-privileged users (and low-privileged users have write access to %PROGRAMDATA%\\SSCService). Consequently, low-privileged users can execute arbitrary code as LocalSystem.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-26T23:15:46Z" diff --git a/advisories/unreviewed/2024/03/GHSA-px8r-9qv3-6525/GHSA-px8r-9qv3-6525.json b/advisories/unreviewed/2024/03/GHSA-px8r-9qv3-6525/GHSA-px8r-9qv3-6525.json index c65ee482c2d..73901da9053 100644 --- a/advisories/unreviewed/2024/03/GHSA-px8r-9qv3-6525/GHSA-px8r-9qv3-6525.json +++ b/advisories/unreviewed/2024/03/GHSA-px8r-9qv3-6525/GHSA-px8r-9qv3-6525.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-px8r-9qv3-6525", - "modified": "2024-03-06T00:31:27Z", + "modified": "2024-08-08T18:31:18Z", "published": "2024-03-06T00:31:27Z", "aliases": [ "CVE-2024-27765" ], "details": "Directory Traversal vulnerability in Jeewms v.3.7 and before allows a remote attacker to obtain sensitive information via the cgformTemplateController component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-05T23:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-6cjw-2w3q-pv7g/GHSA-6cjw-2w3q-pv7g.json b/advisories/unreviewed/2024/04/GHSA-6cjw-2w3q-pv7g/GHSA-6cjw-2w3q-pv7g.json index 4e4427edddf..6229777ec9a 100644 --- a/advisories/unreviewed/2024/04/GHSA-6cjw-2w3q-pv7g/GHSA-6cjw-2w3q-pv7g.json +++ b/advisories/unreviewed/2024/04/GHSA-6cjw-2w3q-pv7g/GHSA-6cjw-2w3q-pv7g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6cjw-2w3q-pv7g", - "modified": "2024-06-10T18:30:55Z", + "modified": "2024-08-08T18:31:19Z", "published": "2024-04-19T18:31:15Z", "aliases": [ "CVE-2023-50008" ], "details": "Buffer Overflow vulnerability in Ffmpeg v.n6.1-3-g466799d4f5 allows a local attacker to execute arbitrary code via the av_malloc function in libavutil/mem.c:105:9 component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-19T17:15:52Z" diff --git a/advisories/unreviewed/2024/04/GHSA-7xjx-6mf4-7xgc/GHSA-7xjx-6mf4-7xgc.json b/advisories/unreviewed/2024/04/GHSA-7xjx-6mf4-7xgc/GHSA-7xjx-6mf4-7xgc.json index bd69850ab61..31ecfeb90c9 100644 --- a/advisories/unreviewed/2024/04/GHSA-7xjx-6mf4-7xgc/GHSA-7xjx-6mf4-7xgc.json +++ b/advisories/unreviewed/2024/04/GHSA-7xjx-6mf4-7xgc/GHSA-7xjx-6mf4-7xgc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7xjx-6mf4-7xgc", - "modified": "2024-04-18T21:30:31Z", + "modified": "2024-08-08T18:31:19Z", "published": "2024-04-18T21:30:31Z", "aliases": [ "CVE-2024-30923" ], "details": "SQL Injection vulnerability in DerbyNet v9.0 and below allows a remote attacker to execute arbitrary code via the where Clause in Racer Document Rendering", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-18T21:15:07Z" diff --git a/advisories/unreviewed/2024/04/GHSA-8wq2-m78j-qq93/GHSA-8wq2-m78j-qq93.json b/advisories/unreviewed/2024/04/GHSA-8wq2-m78j-qq93/GHSA-8wq2-m78j-qq93.json index 4b652ca0ea3..40afa7205df 100644 --- a/advisories/unreviewed/2024/04/GHSA-8wq2-m78j-qq93/GHSA-8wq2-m78j-qq93.json +++ b/advisories/unreviewed/2024/04/GHSA-8wq2-m78j-qq93/GHSA-8wq2-m78j-qq93.json @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-119" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-97rm-7vq8-qwj2/GHSA-97rm-7vq8-qwj2.json b/advisories/unreviewed/2024/04/GHSA-97rm-7vq8-qwj2/GHSA-97rm-7vq8-qwj2.json index 8120a5b90af..54b14306da2 100644 --- a/advisories/unreviewed/2024/04/GHSA-97rm-7vq8-qwj2/GHSA-97rm-7vq8-qwj2.json +++ b/advisories/unreviewed/2024/04/GHSA-97rm-7vq8-qwj2/GHSA-97rm-7vq8-qwj2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-97rm-7vq8-qwj2", - "modified": "2024-04-17T18:31:34Z", + "modified": "2024-08-08T18:31:19Z", "published": "2024-04-17T18:31:34Z", "aliases": [ "CVE-2023-5397" diff --git a/advisories/unreviewed/2024/04/GHSA-h47h-5hqh-63xw/GHSA-h47h-5hqh-63xw.json b/advisories/unreviewed/2024/04/GHSA-h47h-5hqh-63xw/GHSA-h47h-5hqh-63xw.json index 1094c0403fa..712cec5671e 100644 --- a/advisories/unreviewed/2024/04/GHSA-h47h-5hqh-63xw/GHSA-h47h-5hqh-63xw.json +++ b/advisories/unreviewed/2024/04/GHSA-h47h-5hqh-63xw/GHSA-h47h-5hqh-63xw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h47h-5hqh-63xw", - "modified": "2024-04-26T06:30:32Z", + "modified": "2024-08-08T18:31:19Z", "published": "2024-04-26T06:30:32Z", "aliases": [ "CVE-2024-22633" ], "details": "Setor Informatica Sistema Inteligente para Laboratorios (S.I.L.) 388 was discovered to contain a remote code execution (RCE) vulnerability via the hprinter parameter. This vulnerability is triggered via a crafted POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-26T04:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-8g8j-p6r7-xj34/GHSA-8g8j-p6r7-xj34.json b/advisories/unreviewed/2024/05/GHSA-8g8j-p6r7-xj34/GHSA-8g8j-p6r7-xj34.json index e2b9d44be85..ef59057d0e9 100644 --- a/advisories/unreviewed/2024/05/GHSA-8g8j-p6r7-xj34/GHSA-8g8j-p6r7-xj34.json +++ b/advisories/unreviewed/2024/05/GHSA-8g8j-p6r7-xj34/GHSA-8g8j-p6r7-xj34.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8g8j-p6r7-xj34", - "modified": "2024-05-22T09:31:45Z", + "modified": "2024-08-08T18:31:19Z", "published": "2024-05-22T09:31:45Z", "aliases": [ "CVE-2021-47449" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nice: fix locking for Tx timestamp tracking flush\n\nCommit 4dd0d5c33c3e (\"ice: add lock around Tx timestamp tracker flush\")\nadded a lock around the Tx timestamp tracker flow which is used to\ncleanup any left over SKBs and prepare for device removal.\n\nThis lock is problematic because it is being held around a call to\nice_clear_phy_tstamp. The clear function takes a mutex to send a PHY\nwrite command to firmware. This could lead to a deadlock if the mutex\nactually sleeps, and causes the following warning on a kernel with\npreemption debugging enabled:\n\n[ 715.419426] BUG: sleeping function called from invalid context at kernel/locking/mutex.c:573\n[ 715.427900] in_atomic(): 1, irqs_disabled(): 0, non_block: 0, pid: 3100, name: rmmod\n[ 715.435652] INFO: lockdep is turned off.\n[ 715.439591] Preemption disabled at:\n[ 715.439594] [<0000000000000000>] 0x0\n[ 715.446678] CPU: 52 PID: 3100 Comm: rmmod Tainted: G W OE 5.15.0-rc4+ #42 bdd7ec3018e725f159ca0d372ce8c2c0e784891c\n[ 715.458058] Hardware name: Intel Corporation S2600STQ/S2600STQ, BIOS SE5C620.86B.02.01.0010.010620200716 01/06/2020\n[ 715.468483] Call Trace:\n[ 715.470940] dump_stack_lvl+0x6a/0x9a\n[ 715.474613] ___might_sleep.cold+0x224/0x26a\n[ 715.478895] __mutex_lock+0xb3/0x1440\n[ 715.482569] ? stack_depot_save+0x378/0x500\n[ 715.486763] ? ice_sq_send_cmd+0x78/0x14c0 [ice 9a7e1ec00971c89ecd3fe0d4dc7da2b3786a421d]\n[ 715.494979] ? kfree+0xc1/0x520\n[ 715.498128] ? mutex_lock_io_nested+0x12a0/0x12a0\n[ 715.502837] ? kasan_set_free_info+0x20/0x30\n[ 715.507110] ? __kasan_slab_free+0x10b/0x140\n[ 715.511385] ? slab_free_freelist_hook+0xc7/0x220\n[ 715.516092] ? kfree+0xc1/0x520\n[ 715.519235] ? ice_deinit_lag+0x16c/0x220 [ice 9a7e1ec00971c89ecd3fe0d4dc7da2b3786a421d]\n[ 715.527359] ? ice_remove+0x1cf/0x6a0 [ice 9a7e1ec00971c89ecd3fe0d4dc7da2b3786a421d]\n[ 715.535133] ? pci_device_remove+0xab/0x1d0\n[ 715.539318] ? __device_release_driver+0x35b/0x690\n[ 715.544110] ? driver_detach+0x214/0x2f0\n[ 715.548035] ? bus_remove_driver+0x11d/0x2f0\n[ 715.552309] ? pci_unregister_driver+0x26/0x250\n[ 715.556840] ? ice_module_exit+0xc/0x2f [ice 9a7e1ec00971c89ecd3fe0d4dc7da2b3786a421d]\n[ 715.564799] ? __do_sys_delete_module.constprop.0+0x2d8/0x4e0\n[ 715.570554] ? do_syscall_64+0x3b/0x90\n[ 715.574303] ? entry_SYSCALL_64_after_hwframe+0x44/0xae\n[ 715.579529] ? start_flush_work+0x542/0x8f0\n[ 715.583719] ? ice_sq_send_cmd+0x78/0x14c0 [ice 9a7e1ec00971c89ecd3fe0d4dc7da2b3786a421d]\n[ 715.591923] ice_sq_send_cmd+0x78/0x14c0 [ice 9a7e1ec00971c89ecd3fe0d4dc7da2b3786a421d]\n[ 715.599960] ? wait_for_completion_io+0x250/0x250\n[ 715.604662] ? lock_acquire+0x196/0x200\n[ 715.608504] ? do_raw_spin_trylock+0xa5/0x160\n[ 715.612864] ice_sbq_rw_reg+0x1e6/0x2f0 [ice 9a7e1ec00971c89ecd3fe0d4dc7da2b3786a421d]\n[ 715.620813] ? ice_reset+0x130/0x130 [ice 9a7e1ec00971c89ecd3fe0d4dc7da2b3786a421d]\n[ 715.628497] ? __debug_check_no_obj_freed+0x1e8/0x3c0\n[ 715.633550] ? trace_hardirqs_on+0x1c/0x130\n[ 715.637748] ice_write_phy_reg_e810+0x70/0xf0 [ice 9a7e1ec00971c89ecd3fe0d4dc7da2b3786a421d]\n[ 715.646220] ? do_raw_spin_trylock+0xa5/0x160\n[ 715.650581] ? ice_ptp_release+0x910/0x910 [ice 9a7e1ec00971c89ecd3fe0d4dc7da2b3786a421d]\n[ 715.658797] ? ice_ptp_release+0x255/0x910 [ice 9a7e1ec00971c89ecd3fe0d4dc7da2b3786a421d]\n[ 715.667013] ice_clear_phy_tstamp+0x2c/0x110 [ice 9a7e1ec00971c89ecd3fe0d4dc7da2b3786a421d]\n[ 715.675403] ice_ptp_release+0x408/0x910 [ice 9a7e1ec00971c89ecd3fe0d4dc7da2b3786a421d]\n[ 715.683440] ice_remove+0x560/0x6a0 [ice 9a7e1ec00971c89ecd3fe0d4dc7da2b3786a421d]\n[ 715.691037] ? _raw_spin_unlock_irqrestore+0x46/0x73\n[ 715.696005] pci_device_remove+0xab/0x1d0\n[ 715.700018] __device_release_driver+0x35b/0x690\n[ 715.704637] driver_detach+0x214/0x2f0\n[ 715.708389] bus_remove_driver+0x11d/0x2f0\n[ 715.712489] pci_unregister_driver+0x26/0x250\n[ 71\n---truncated---", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-129" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-22T07:15:10Z" diff --git a/advisories/unreviewed/2024/05/GHSA-c473-m4mh-crhw/GHSA-c473-m4mh-crhw.json b/advisories/unreviewed/2024/05/GHSA-c473-m4mh-crhw/GHSA-c473-m4mh-crhw.json index 708c949dd0a..bc63eeda549 100644 --- a/advisories/unreviewed/2024/05/GHSA-c473-m4mh-crhw/GHSA-c473-m4mh-crhw.json +++ b/advisories/unreviewed/2024/05/GHSA-c473-m4mh-crhw/GHSA-c473-m4mh-crhw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c473-m4mh-crhw", - "modified": "2024-05-14T18:31:02Z", + "modified": "2024-08-08T18:31:19Z", "published": "2024-05-14T18:31:02Z", "aliases": [ "CVE-2024-35009" ], "details": "idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/share_switch.php?mudi=switch&dataType=&fieldName=state&fieldName2=state&tabName=banner&dataID=6.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T16:17:30Z" diff --git a/advisories/unreviewed/2024/05/GHSA-gx5g-rjjv-754q/GHSA-gx5g-rjjv-754q.json b/advisories/unreviewed/2024/05/GHSA-gx5g-rjjv-754q/GHSA-gx5g-rjjv-754q.json index c173d61997d..bc2bee8498e 100644 --- a/advisories/unreviewed/2024/05/GHSA-gx5g-rjjv-754q/GHSA-gx5g-rjjv-754q.json +++ b/advisories/unreviewed/2024/05/GHSA-gx5g-rjjv-754q/GHSA-gx5g-rjjv-754q.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-jmpm-75w8-qgjx/GHSA-jmpm-75w8-qgjx.json b/advisories/unreviewed/2024/05/GHSA-jmpm-75w8-qgjx/GHSA-jmpm-75w8-qgjx.json index 37d08028228..2c9e61d1234 100644 --- a/advisories/unreviewed/2024/05/GHSA-jmpm-75w8-qgjx/GHSA-jmpm-75w8-qgjx.json +++ b/advisories/unreviewed/2024/05/GHSA-jmpm-75w8-qgjx/GHSA-jmpm-75w8-qgjx.json @@ -40,7 +40,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-1264" + "CWE-1264", + "CWE-400" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-r8x8-rv8c-j266/GHSA-r8x8-rv8c-j266.json b/advisories/unreviewed/2024/05/GHSA-r8x8-rv8c-j266/GHSA-r8x8-rv8c-j266.json index 7c8f2287d9a..c1e0c2e7aa4 100644 --- a/advisories/unreviewed/2024/05/GHSA-r8x8-rv8c-j266/GHSA-r8x8-rv8c-j266.json +++ b/advisories/unreviewed/2024/05/GHSA-r8x8-rv8c-j266/GHSA-r8x8-rv8c-j266.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r8x8-rv8c-j266", - "modified": "2024-06-10T18:31:03Z", + "modified": "2024-08-08T18:31:19Z", "published": "2024-05-18T21:30:35Z", "aliases": [ "CVE-2024-36048" ], "details": "QAbstractOAuth in Qt Network Authorization in Qt before 5.15.17, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.6, and 6.6.x through 6.7.x before 6.7.1 uses only the time to seed the PRNG, which may result in guessable values.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-335" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-18T21:15:47Z" diff --git a/advisories/unreviewed/2024/05/GHSA-rvfp-m6f3-8v6h/GHSA-rvfp-m6f3-8v6h.json b/advisories/unreviewed/2024/05/GHSA-rvfp-m6f3-8v6h/GHSA-rvfp-m6f3-8v6h.json index 403b802a01d..180f707f969 100644 --- a/advisories/unreviewed/2024/05/GHSA-rvfp-m6f3-8v6h/GHSA-rvfp-m6f3-8v6h.json +++ b/advisories/unreviewed/2024/05/GHSA-rvfp-m6f3-8v6h/GHSA-rvfp-m6f3-8v6h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rvfp-m6f3-8v6h", - "modified": "2024-05-14T18:30:49Z", + "modified": "2024-08-08T18:31:19Z", "published": "2024-05-14T18:30:49Z", "aliases": [ "CVE-2024-34230" ], "details": "A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the System Information parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:38:37Z" diff --git a/advisories/unreviewed/2024/05/GHSA-wx4v-qgjj-9f5j/GHSA-wx4v-qgjj-9f5j.json b/advisories/unreviewed/2024/05/GHSA-wx4v-qgjj-9f5j/GHSA-wx4v-qgjj-9f5j.json index 0769edd78fd..3ae3bc98ed4 100644 --- a/advisories/unreviewed/2024/05/GHSA-wx4v-qgjj-9f5j/GHSA-wx4v-qgjj-9f5j.json +++ b/advisories/unreviewed/2024/05/GHSA-wx4v-qgjj-9f5j/GHSA-wx4v-qgjj-9f5j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wx4v-qgjj-9f5j", - "modified": "2024-05-20T18:31:24Z", + "modified": "2024-08-08T18:31:19Z", "published": "2024-05-20T18:31:24Z", "aliases": [ "CVE-2024-35579" ], "details": "Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function formSetIptv.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-20T18:15:10Z" diff --git a/advisories/unreviewed/2024/06/GHSA-4rvm-m82p-p79p/GHSA-4rvm-m82p-p79p.json b/advisories/unreviewed/2024/06/GHSA-4rvm-m82p-p79p/GHSA-4rvm-m82p-p79p.json index f63fc2ba8cd..fe923f09b4e 100644 --- a/advisories/unreviewed/2024/06/GHSA-4rvm-m82p-p79p/GHSA-4rvm-m82p-p79p.json +++ b/advisories/unreviewed/2024/06/GHSA-4rvm-m82p-p79p/GHSA-4rvm-m82p-p79p.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-5729-2v3w-2h7m/GHSA-5729-2v3w-2h7m.json b/advisories/unreviewed/2024/06/GHSA-5729-2v3w-2h7m/GHSA-5729-2v3w-2h7m.json index 546046f4e3d..b2583a3276f 100644 --- a/advisories/unreviewed/2024/06/GHSA-5729-2v3w-2h7m/GHSA-5729-2v3w-2h7m.json +++ b/advisories/unreviewed/2024/06/GHSA-5729-2v3w-2h7m/GHSA-5729-2v3w-2h7m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5729-2v3w-2h7m", - "modified": "2024-06-18T12:30:42Z", + "modified": "2024-08-08T18:31:19Z", "published": "2024-06-18T12:30:42Z", "aliases": [ "CVE-2024-6110" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/06/GHSA-62hv-vfr8-65mw/GHSA-62hv-vfr8-65mw.json b/advisories/unreviewed/2024/06/GHSA-62hv-vfr8-65mw/GHSA-62hv-vfr8-65mw.json index b7a01efe28d..d16b8343c0c 100644 --- a/advisories/unreviewed/2024/06/GHSA-62hv-vfr8-65mw/GHSA-62hv-vfr8-65mw.json +++ b/advisories/unreviewed/2024/06/GHSA-62hv-vfr8-65mw/GHSA-62hv-vfr8-65mw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-62hv-vfr8-65mw", - "modified": "2024-06-17T21:31:11Z", + "modified": "2024-08-08T18:31:19Z", "published": "2024-06-17T21:31:11Z", "aliases": [ "CVE-2024-6065" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/06/GHSA-9r6p-56h8-7v76/GHSA-9r6p-56h8-7v76.json b/advisories/unreviewed/2024/06/GHSA-9r6p-56h8-7v76/GHSA-9r6p-56h8-7v76.json index 88741863dde..78b14c5533c 100644 --- a/advisories/unreviewed/2024/06/GHSA-9r6p-56h8-7v76/GHSA-9r6p-56h8-7v76.json +++ b/advisories/unreviewed/2024/06/GHSA-9r6p-56h8-7v76/GHSA-9r6p-56h8-7v76.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9r6p-56h8-7v76", - "modified": "2024-06-17T21:31:11Z", + "modified": "2024-08-08T18:31:19Z", "published": "2024-06-17T21:31:11Z", "aliases": [ "CVE-2024-6066" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/06/GHSA-gh8f-3437-7ch5/GHSA-gh8f-3437-7ch5.json b/advisories/unreviewed/2024/06/GHSA-gh8f-3437-7ch5/GHSA-gh8f-3437-7ch5.json index 76f71fa4f6f..82835137f63 100644 --- a/advisories/unreviewed/2024/06/GHSA-gh8f-3437-7ch5/GHSA-gh8f-3437-7ch5.json +++ b/advisories/unreviewed/2024/06/GHSA-gh8f-3437-7ch5/GHSA-gh8f-3437-7ch5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gh8f-3437-7ch5", - "modified": "2024-06-18T00:31:24Z", + "modified": "2024-08-08T18:31:19Z", "published": "2024-06-18T00:31:24Z", "aliases": [ "CVE-2024-6067" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/06/GHSA-grm8-7p8f-2rp6/GHSA-grm8-7p8f-2rp6.json b/advisories/unreviewed/2024/06/GHSA-grm8-7p8f-2rp6/GHSA-grm8-7p8f-2rp6.json index ff489f28d57..5f057796d7b 100644 --- a/advisories/unreviewed/2024/06/GHSA-grm8-7p8f-2rp6/GHSA-grm8-7p8f-2rp6.json +++ b/advisories/unreviewed/2024/06/GHSA-grm8-7p8f-2rp6/GHSA-grm8-7p8f-2rp6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-grm8-7p8f-2rp6", - "modified": "2024-06-14T18:31:45Z", + "modified": "2024-08-08T18:31:19Z", "published": "2024-06-14T18:31:45Z", "aliases": [ "CVE-2024-36597" ], "details": "Aegon Life v1.0 was discovered to contain a SQL injection vulnerability via the client_id parameter at clientStatus.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-14T18:15:27Z" diff --git a/advisories/unreviewed/2024/06/GHSA-j4fv-r5w9-h675/GHSA-j4fv-r5w9-h675.json b/advisories/unreviewed/2024/06/GHSA-j4fv-r5w9-h675/GHSA-j4fv-r5w9-h675.json index 0a43962d7e8..39dc71149b4 100644 --- a/advisories/unreviewed/2024/06/GHSA-j4fv-r5w9-h675/GHSA-j4fv-r5w9-h675.json +++ b/advisories/unreviewed/2024/06/GHSA-j4fv-r5w9-h675/GHSA-j4fv-r5w9-h675.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j4fv-r5w9-h675", - "modified": "2024-07-03T18:46:58Z", + "modified": "2024-08-08T18:31:19Z", "published": "2024-06-26T06:30:29Z", "aliases": [ "CVE-2024-34580" @@ -29,10 +29,18 @@ "type": "WEB", "url": "https://github.com/zmanion/Vulnerabilities/blob/main/CVE-2024-21893.md" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/po2gocnw4gtf4boy5mmjb54g62qhbrl9" + }, { "type": "WEB", "url": "https://santuario.apache.org/download.html" }, + { + "type": "WEB", + "url": "https://shibboleth.atlassian.net/wiki/spaces/DEV/pages/3726671873/Santuario" + }, { "type": "WEB", "url": "https://www.sonatype.com/blog/the-exploited-ivanti-connect-ssrf-vulnerability-stems-from-xmltooling-oss-library" diff --git a/advisories/unreviewed/2024/06/GHSA-rp92-93hq-c7q8/GHSA-rp92-93hq-c7q8.json b/advisories/unreviewed/2024/06/GHSA-rp92-93hq-c7q8/GHSA-rp92-93hq-c7q8.json index ac4f7e3521f..30d1d15a100 100644 --- a/advisories/unreviewed/2024/06/GHSA-rp92-93hq-c7q8/GHSA-rp92-93hq-c7q8.json +++ b/advisories/unreviewed/2024/06/GHSA-rp92-93hq-c7q8/GHSA-rp92-93hq-c7q8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rp92-93hq-c7q8", - "modified": "2024-06-18T03:34:26Z", + "modified": "2024-08-08T18:31:19Z", "published": "2024-06-18T03:34:26Z", "aliases": [ "CVE-2024-6084" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/07/GHSA-3vvq-h94f-pm68/GHSA-3vvq-h94f-pm68.json b/advisories/unreviewed/2024/07/GHSA-3vvq-h94f-pm68/GHSA-3vvq-h94f-pm68.json index bc94dbaa950..26cf65b3d7b 100644 --- a/advisories/unreviewed/2024/07/GHSA-3vvq-h94f-pm68/GHSA-3vvq-h94f-pm68.json +++ b/advisories/unreviewed/2024/07/GHSA-3vvq-h94f-pm68/GHSA-3vvq-h94f-pm68.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3vvq-h94f-pm68", - "modified": "2024-07-29T18:30:38Z", + "modified": "2024-08-08T18:31:20Z", "published": "2024-07-29T18:30:38Z", "aliases": [ "CVE-2024-41093" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: avoid using null object of framebuffer\n\nInstead of using state->fb->obj[0] directly, get object from framebuffer\nby calling drm_gem_fb_get_obj() and return error code when object is\nnull to avoid using null object of framebuffer.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T16:15:04Z" diff --git a/advisories/unreviewed/2024/07/GHSA-57hr-r2gg-fqr9/GHSA-57hr-r2gg-fqr9.json b/advisories/unreviewed/2024/07/GHSA-57hr-r2gg-fqr9/GHSA-57hr-r2gg-fqr9.json index a6007ace0be..4f091f542ef 100644 --- a/advisories/unreviewed/2024/07/GHSA-57hr-r2gg-fqr9/GHSA-57hr-r2gg-fqr9.json +++ b/advisories/unreviewed/2024/07/GHSA-57hr-r2gg-fqr9/GHSA-57hr-r2gg-fqr9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-57hr-r2gg-fqr9", - "modified": "2024-07-29T18:30:38Z", + "modified": "2024-08-08T18:31:20Z", "published": "2024-07-29T18:30:38Z", "aliases": [ "CVE-2024-41089" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/nouveau/dispnv04: fix null pointer dereference in nv17_tv_get_hd_modes\n\nIn nv17_tv_get_hd_modes(), the return value of drm_mode_duplicate() is\nassigned to mode, which will lead to a possible NULL pointer dereference\non failure of drm_mode_duplicate(). The same applies to drm_cvt_mode().\nAdd a check to avoid null pointer dereference.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T16:15:04Z" diff --git a/advisories/unreviewed/2024/07/GHSA-6fvv-3vw6-wp7c/GHSA-6fvv-3vw6-wp7c.json b/advisories/unreviewed/2024/07/GHSA-6fvv-3vw6-wp7c/GHSA-6fvv-3vw6-wp7c.json index 39d9c856929..8113516aaeb 100644 --- a/advisories/unreviewed/2024/07/GHSA-6fvv-3vw6-wp7c/GHSA-6fvv-3vw6-wp7c.json +++ b/advisories/unreviewed/2024/07/GHSA-6fvv-3vw6-wp7c/GHSA-6fvv-3vw6-wp7c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6fvv-3vw6-wp7c", - "modified": "2024-07-29T18:30:39Z", + "modified": "2024-08-08T18:31:20Z", "published": "2024-07-29T18:30:38Z", "aliases": [ "CVE-2024-41092" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/i915/gt: Fix potential UAF by revoke of fence registers\n\nCI has been sporadically reporting the following issue triggered by\nigt@i915_selftest@live@hangcheck on ADL-P and similar machines:\n\n<6> [414.049203] i915: Running intel_hangcheck_live_selftests/igt_reset_evict_fence\n...\n<6> [414.068804] i915 0000:00:02.0: [drm] GT0: GUC: submission enabled\n<6> [414.068812] i915 0000:00:02.0: [drm] GT0: GUC: SLPC enabled\n<3> [414.070354] Unable to pin Y-tiled fence; err:-4\n<3> [414.071282] i915_vma_revoke_fence:301 GEM_BUG_ON(!i915_active_is_idle(&fence->active))\n...\n<4>[ 609.603992] ------------[ cut here ]------------\n<2>[ 609.603995] kernel BUG at drivers/gpu/drm/i915/gt/intel_ggtt_fencing.c:301!\n<4>[ 609.604003] invalid opcode: 0000 [#1] PREEMPT SMP NOPTI\n<4>[ 609.604006] CPU: 0 PID: 268 Comm: kworker/u64:3 Tainted: G U W 6.9.0-CI_DRM_14785-g1ba62f8cea9c+ #1\n<4>[ 609.604008] Hardware name: Intel Corporation Alder Lake Client Platform/AlderLake-P DDR4 RVP, BIOS RPLPFWI1.R00.4035.A00.2301200723 01/20/2023\n<4>[ 609.604010] Workqueue: i915 __i915_gem_free_work [i915]\n<4>[ 609.604149] RIP: 0010:i915_vma_revoke_fence+0x187/0x1f0 [i915]\n...\n<4>[ 609.604271] Call Trace:\n<4>[ 609.604273] \n...\n<4>[ 609.604716] __i915_vma_evict+0x2e9/0x550 [i915]\n<4>[ 609.604852] __i915_vma_unbind+0x7c/0x160 [i915]\n<4>[ 609.604977] force_unbind+0x24/0xa0 [i915]\n<4>[ 609.605098] i915_vma_destroy+0x2f/0xa0 [i915]\n<4>[ 609.605210] __i915_gem_object_pages_fini+0x51/0x2f0 [i915]\n<4>[ 609.605330] __i915_gem_free_objects.isra.0+0x6a/0xc0 [i915]\n<4>[ 609.605440] process_scheduled_works+0x351/0x690\n...\n\nIn the past, there were similar failures reported by CI from other IGT\ntests, observed on other platforms.\n\nBefore commit 63baf4f3d587 (\"drm/i915/gt: Only wait for GPU activity\nbefore unbinding a GGTT fence\"), i915_vma_revoke_fence() was waiting for\nidleness of vma->active via fence_update(). That commit introduced\nvma->fence->active in order for the fence_update() to be able to wait\nselectively on that one instead of vma->active since only idleness of\nfence registers was needed. But then, another commit 0d86ee35097a\n(\"drm/i915/gt: Make fence revocation unequivocal\") replaced the call to\nfence_update() in i915_vma_revoke_fence() with only fence_write(), and\nalso added that GEM_BUG_ON(!i915_active_is_idle(&fence->active)) in front.\nNo justification was provided on why we might then expect idleness of\nvma->fence->active without first waiting on it.\n\nThe issue can be potentially caused by a race among revocation of fence\nregisters on one side and sequential execution of signal callbacks invoked\non completion of a request that was using them on the other, still\nprocessed in parallel to revocation of those fence registers. Fix it by\nwaiting for idleness of vma->fence->active in i915_vma_revoke_fence().\n\n(cherry picked from commit 24bb052d3dd499c5956abad5f7d8e4fd07da7fb1)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T16:15:04Z" diff --git a/advisories/unreviewed/2024/07/GHSA-8qxj-f84c-r77w/GHSA-8qxj-f84c-r77w.json b/advisories/unreviewed/2024/07/GHSA-8qxj-f84c-r77w/GHSA-8qxj-f84c-r77w.json index fc14ce05fdb..e93c88e872a 100644 --- a/advisories/unreviewed/2024/07/GHSA-8qxj-f84c-r77w/GHSA-8qxj-f84c-r77w.json +++ b/advisories/unreviewed/2024/07/GHSA-8qxj-f84c-r77w/GHSA-8qxj-f84c-r77w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8qxj-f84c-r77w", - "modified": "2024-07-29T15:30:41Z", + "modified": "2024-08-08T18:31:19Z", "published": "2024-07-29T15:30:41Z", "aliases": [ "CVE-2024-41038" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfirmware: cs_dsp: Prevent buffer overrun when processing V2 alg headers\n\nCheck that all fields of a V2 algorithm header fit into the available\nfirmware data buffer.\n\nThe wmfw V2 format introduced variable-length strings in the algorithm\nblock header. This means the overall header length is variable, and the\nposition of most fields varies depending on the length of the string\nfields. Each field must be checked to ensure that it does not overflow\nthe firmware data buffer.\n\nAs this ia bugfix patch, the fixes avoid making any significant change to\nthe existing code. This makes it easier to review and less likely to\nintroduce new bugs.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T15:15:12Z" diff --git a/advisories/unreviewed/2024/07/GHSA-cm3g-9rxc-2598/GHSA-cm3g-9rxc-2598.json b/advisories/unreviewed/2024/07/GHSA-cm3g-9rxc-2598/GHSA-cm3g-9rxc-2598.json index 16f18894edc..007d3a358d1 100644 --- a/advisories/unreviewed/2024/07/GHSA-cm3g-9rxc-2598/GHSA-cm3g-9rxc-2598.json +++ b/advisories/unreviewed/2024/07/GHSA-cm3g-9rxc-2598/GHSA-cm3g-9rxc-2598.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cm3g-9rxc-2598", - "modified": "2024-07-29T18:30:39Z", + "modified": "2024-08-08T18:31:20Z", "published": "2024-07-29T18:30:38Z", "aliases": [ "CVE-2024-41098" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nata: libata-core: Fix null pointer dereference on error\n\nIf the ata_port_alloc() call in ata_host_alloc() fails,\nata_host_release() will get called.\n\nHowever, the code in ata_host_release() tries to free ata_port struct\nmembers unconditionally, which can lead to the following:\n\nBUG: unable to handle page fault for address: 0000000000003990\nPGD 0 P4D 0\nOops: Oops: 0000 [#1] PREEMPT SMP NOPTI\nCPU: 10 PID: 594 Comm: (udev-worker) Not tainted 6.10.0-rc5 #44\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.3-2.fc40 04/01/2014\nRIP: 0010:ata_host_release.cold+0x2f/0x6e [libata]\nCode: e4 4d 63 f4 44 89 e2 48 c7 c6 90 ad 32 c0 48 c7 c7 d0 70 33 c0 49 83 c6 0e 41\nRSP: 0018:ffffc90000ebb968 EFLAGS: 00010246\nRAX: 0000000000000041 RBX: ffff88810fb52e78 RCX: 0000000000000000\nRDX: 0000000000000000 RSI: ffff88813b3218c0 RDI: ffff88813b3218c0\nRBP: ffff88810fb52e40 R08: 0000000000000000 R09: 6c65725f74736f68\nR10: ffffc90000ebb738 R11: 73692033203a746e R12: 0000000000000004\nR13: 0000000000000000 R14: 0000000000000011 R15: 0000000000000006\nFS: 00007f6cc55b9980(0000) GS:ffff88813b300000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 0000000000003990 CR3: 00000001122a2000 CR4: 0000000000750ef0\nPKRU: 55555554\nCall Trace:\n \n ? __die_body.cold+0x19/0x27\n ? page_fault_oops+0x15a/0x2f0\n ? exc_page_fault+0x7e/0x180\n ? asm_exc_page_fault+0x26/0x30\n ? ata_host_release.cold+0x2f/0x6e [libata]\n ? ata_host_release.cold+0x2f/0x6e [libata]\n release_nodes+0x35/0xb0\n devres_release_group+0x113/0x140\n ata_host_alloc+0xed/0x120 [libata]\n ata_host_alloc_pinfo+0x14/0xa0 [libata]\n ahci_init_one+0x6c9/0xd20 [ahci]\n\nDo not access ata_port struct members unconditionally.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T16:15:04Z" diff --git a/advisories/unreviewed/2024/07/GHSA-f5xx-949w-7ch3/GHSA-f5xx-949w-7ch3.json b/advisories/unreviewed/2024/07/GHSA-f5xx-949w-7ch3/GHSA-f5xx-949w-7ch3.json index a24effefc3a..33d3d47110b 100644 --- a/advisories/unreviewed/2024/07/GHSA-f5xx-949w-7ch3/GHSA-f5xx-949w-7ch3.json +++ b/advisories/unreviewed/2024/07/GHSA-f5xx-949w-7ch3/GHSA-f5xx-949w-7ch3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f5xx-949w-7ch3", - "modified": "2024-07-29T18:30:38Z", + "modified": "2024-08-08T18:31:20Z", "published": "2024-07-29T18:30:38Z", "aliases": [ "CVE-2024-41096" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nPCI/MSI: Fix UAF in msi_capability_init\n\nKFENCE reports the following UAF:\n\n BUG: KFENCE: use-after-free read in __pci_enable_msi_range+0x2c0/0x488\n\n Use-after-free read at 0x0000000024629571 (in kfence-#12):\n __pci_enable_msi_range+0x2c0/0x488\n pci_alloc_irq_vectors_affinity+0xec/0x14c\n pci_alloc_irq_vectors+0x18/0x28\n\n kfence-#12: 0x0000000008614900-0x00000000e06c228d, size=104, cache=kmalloc-128\n\n allocated by task 81 on cpu 7 at 10.808142s:\n __kmem_cache_alloc_node+0x1f0/0x2bc\n kmalloc_trace+0x44/0x138\n msi_alloc_desc+0x3c/0x9c\n msi_domain_insert_msi_desc+0x30/0x78\n msi_setup_msi_desc+0x13c/0x184\n __pci_enable_msi_range+0x258/0x488\n pci_alloc_irq_vectors_affinity+0xec/0x14c\n pci_alloc_irq_vectors+0x18/0x28\n\n freed by task 81 on cpu 7 at 10.811436s:\n msi_domain_free_descs+0xd4/0x10c\n msi_domain_free_locked.part.0+0xc0/0x1d8\n msi_domain_alloc_irqs_all_locked+0xb4/0xbc\n pci_msi_setup_msi_irqs+0x30/0x4c\n __pci_enable_msi_range+0x2a8/0x488\n pci_alloc_irq_vectors_affinity+0xec/0x14c\n pci_alloc_irq_vectors+0x18/0x28\n\nDescriptor allocation done in:\n__pci_enable_msi_range\n msi_capability_init\n msi_setup_msi_desc\n msi_insert_msi_desc\n msi_domain_insert_msi_desc\n msi_alloc_desc\n ...\n\nFreed in case of failure in __msi_domain_alloc_locked()\n__pci_enable_msi_range\n msi_capability_init\n pci_msi_setup_msi_irqs\n msi_domain_alloc_irqs_all_locked\n msi_domain_alloc_locked\n __msi_domain_alloc_locked => fails\n msi_domain_free_locked\n ...\n\nThat failure propagates back to pci_msi_setup_msi_irqs() in\nmsi_capability_init() which accesses the descriptor for unmasking in the\nerror exit path.\n\nCure it by copying the descriptor and using the copy for the error exit path\nunmask operation.\n\n[ tglx: Massaged change log ]", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T16:15:04Z" diff --git a/advisories/unreviewed/2024/07/GHSA-f6mg-hq7f-jw2j/GHSA-f6mg-hq7f-jw2j.json b/advisories/unreviewed/2024/07/GHSA-f6mg-hq7f-jw2j/GHSA-f6mg-hq7f-jw2j.json index 9e398d67d27..b1adb5691e3 100644 --- a/advisories/unreviewed/2024/07/GHSA-f6mg-hq7f-jw2j/GHSA-f6mg-hq7f-jw2j.json +++ b/advisories/unreviewed/2024/07/GHSA-f6mg-hq7f-jw2j/GHSA-f6mg-hq7f-jw2j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f6mg-hq7f-jw2j", - "modified": "2024-08-01T15:32:05Z", + "modified": "2024-08-08T18:31:19Z", "published": "2024-07-18T12:30:52Z", "aliases": [ "CVE-2024-40898" diff --git a/advisories/unreviewed/2024/07/GHSA-jvmg-77fx-pxw2/GHSA-jvmg-77fx-pxw2.json b/advisories/unreviewed/2024/07/GHSA-jvmg-77fx-pxw2/GHSA-jvmg-77fx-pxw2.json index 8afddb78920..b07e6d8d08a 100644 --- a/advisories/unreviewed/2024/07/GHSA-jvmg-77fx-pxw2/GHSA-jvmg-77fx-pxw2.json +++ b/advisories/unreviewed/2024/07/GHSA-jvmg-77fx-pxw2/GHSA-jvmg-77fx-pxw2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jvmg-77fx-pxw2", - "modified": "2024-07-29T15:30:41Z", + "modified": "2024-08-08T18:31:19Z", "published": "2024-07-29T15:30:41Z", "aliases": [ "CVE-2024-41037" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: SOF: Intel: hda: fix null deref on system suspend entry\n\nWhen system enters suspend with an active stream, SOF core\ncalls hw_params_upon_resume(). On Intel platforms with HDA DMA used\nto manage the link DMA, this leads to call chain of\n\n hda_dsp_set_hw_params_upon_resume()\n -> hda_dsp_dais_suspend()\n -> hda_dai_suspend()\n -> hda_ipc4_post_trigger()\n\nA bug is hit in hda_dai_suspend() as hda_link_dma_cleanup() is run first,\nwhich clears hext_stream->link_substream, and then hda_ipc4_post_trigger()\nis called with a NULL snd_pcm_substream pointer.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T15:15:12Z" diff --git a/advisories/unreviewed/2024/07/GHSA-x274-3j7p-qfpp/GHSA-x274-3j7p-qfpp.json b/advisories/unreviewed/2024/07/GHSA-x274-3j7p-qfpp/GHSA-x274-3j7p-qfpp.json index 40ccc420505..7ef600e5cdb 100644 --- a/advisories/unreviewed/2024/07/GHSA-x274-3j7p-qfpp/GHSA-x274-3j7p-qfpp.json +++ b/advisories/unreviewed/2024/07/GHSA-x274-3j7p-qfpp/GHSA-x274-3j7p-qfpp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x274-3j7p-qfpp", - "modified": "2024-07-29T18:30:39Z", + "modified": "2024-08-08T18:31:20Z", "published": "2024-07-29T18:30:38Z", "aliases": [ "CVE-2024-41095" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/nouveau/dispnv04: fix null pointer dereference in nv17_tv_get_ld_modes\n\nIn nv17_tv_get_ld_modes(), the return value of drm_mode_duplicate() is\nassigned to mode, which will lead to a possible NULL pointer dereference\non failure of drm_mode_duplicate(). Add a check to avoid npd.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T16:15:04Z" diff --git a/advisories/unreviewed/2024/07/GHSA-x35g-752c-r3xh/GHSA-x35g-752c-r3xh.json b/advisories/unreviewed/2024/07/GHSA-x35g-752c-r3xh/GHSA-x35g-752c-r3xh.json index 54bcbb022de..2a274259bac 100644 --- a/advisories/unreviewed/2024/07/GHSA-x35g-752c-r3xh/GHSA-x35g-752c-r3xh.json +++ b/advisories/unreviewed/2024/07/GHSA-x35g-752c-r3xh/GHSA-x35g-752c-r3xh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x35g-752c-r3xh", - "modified": "2024-07-29T18:30:38Z", + "modified": "2024-08-08T18:31:20Z", "published": "2024-07-29T18:30:38Z", "aliases": [ "CVE-2024-41087" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nata: libata-core: Fix double free on error\n\nIf e.g. the ata_port_alloc() call in ata_host_alloc() fails, we will jump\nto the err_out label, which will call devres_release_group().\ndevres_release_group() will trigger a call to ata_host_release().\nata_host_release() calls kfree(host), so executing the kfree(host) in\nata_host_alloc() will lead to a double free:\n\nkernel BUG at mm/slub.c:553!\nOops: invalid opcode: 0000 [#1] PREEMPT SMP NOPTI\nCPU: 11 PID: 599 Comm: (udev-worker) Not tainted 6.10.0-rc5 #47\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.3-2.fc40 04/01/2014\nRIP: 0010:kfree+0x2cf/0x2f0\nCode: 5d 41 5e 41 5f 5d e9 80 d6 ff ff 4d 89 f1 41 b8 01 00 00 00 48 89 d9 48 89 da\nRSP: 0018:ffffc90000f377f0 EFLAGS: 00010246\nRAX: ffff888112b1f2c0 RBX: ffff888112b1f2c0 RCX: ffff888112b1f320\nRDX: 000000000000400b RSI: ffffffffc02c9de5 RDI: ffff888112b1f2c0\nRBP: ffffc90000f37830 R08: 0000000000000000 R09: 0000000000000000\nR10: ffffc90000f37610 R11: 617461203a736b6e R12: ffffea00044ac780\nR13: ffff888100046400 R14: ffffffffc02c9de5 R15: 0000000000000006\nFS: 00007f2f1cabe980(0000) GS:ffff88813b380000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007f2f1c3acf75 CR3: 0000000111724000 CR4: 0000000000750ef0\nPKRU: 55555554\nCall Trace:\n \n ? __die_body.cold+0x19/0x27\n ? die+0x2e/0x50\n ? do_trap+0xca/0x110\n ? do_error_trap+0x6a/0x90\n ? kfree+0x2cf/0x2f0\n ? exc_invalid_op+0x50/0x70\n ? kfree+0x2cf/0x2f0\n ? asm_exc_invalid_op+0x1a/0x20\n ? ata_host_alloc+0xf5/0x120 [libata]\n ? ata_host_alloc+0xf5/0x120 [libata]\n ? kfree+0x2cf/0x2f0\n ata_host_alloc+0xf5/0x120 [libata]\n ata_host_alloc_pinfo+0x14/0xa0 [libata]\n ahci_init_one+0x6c9/0xd20 [ahci]\n\nEnsure that we will not call kfree(host) twice, by performing the kfree()\nonly if the devres_open_group() call failed.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-415" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T16:15:04Z" diff --git a/advisories/unreviewed/2024/08/GHSA-28pp-675x-rf35/GHSA-28pp-675x-rf35.json b/advisories/unreviewed/2024/08/GHSA-28pp-675x-rf35/GHSA-28pp-675x-rf35.json new file mode 100644 index 00000000000..c9548e49445 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-28pp-675x-rf35/GHSA-28pp-675x-rf35.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-28pp-675x-rf35", + "modified": "2024-08-08T18:31:20Z", + "published": "2024-08-08T18:31:20Z", + "aliases": [ + "CVE-2024-39287" + ], + "details": "Dorsett Controls Central Server update server has potential information \nleaks with an unprotected file that contains passwords and API keys.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39287" + }, + { + "type": "WEB", + "url": "https://portal.dtscada.com/#/security-bulletins?bulletin=1" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-221-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-08T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-2hrx-xx6v-c3v2/GHSA-2hrx-xx6v-c3v2.json b/advisories/unreviewed/2024/08/GHSA-2hrx-xx6v-c3v2/GHSA-2hrx-xx6v-c3v2.json new file mode 100644 index 00000000000..c0e7be22d27 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-2hrx-xx6v-c3v2/GHSA-2hrx-xx6v-c3v2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2hrx-xx6v-c3v2", + "modified": "2024-08-08T18:31:20Z", + "published": "2024-08-08T18:31:20Z", + "aliases": [ + "CVE-2024-7480" + ], + "details": "An Improper access control vulnerability was found in Avaya Aura System Manager which could allow a command-line interface (CLI) user with administrative privileges to read arbitrary files on the system. Affected versions include 10.1.x.x and 10.2.x.x. Versions prior to 10.1 are end of manufacturer support.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7480" + }, + { + "type": "WEB", + "url": "https://download.avaya.com/css/public/documents/101091159" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-08T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-5gj6-wwjq-frjh/GHSA-5gj6-wwjq-frjh.json b/advisories/unreviewed/2024/08/GHSA-5gj6-wwjq-frjh/GHSA-5gj6-wwjq-frjh.json new file mode 100644 index 00000000000..b63133eb175 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-5gj6-wwjq-frjh/GHSA-5gj6-wwjq-frjh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5gj6-wwjq-frjh", + "modified": "2024-08-08T18:31:20Z", + "published": "2024-08-08T18:31:20Z", + "aliases": [ + "CVE-2024-0108" + ], + "details": "NVIDIA Jetson Linux contains a vulnerability in NvGPU where error handling paths in GPU MMU mapping code fail to clean up a failed mapping attempt. A successful exploit of this vulnerability may lead to denial of service, code execution, and escalation of privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0108" + }, + { + "type": "WEB", + "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5555" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-755" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-08T17:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-6jjg-3cm7-jjfj/GHSA-6jjg-3cm7-jjfj.json b/advisories/unreviewed/2024/08/GHSA-6jjg-3cm7-jjfj/GHSA-6jjg-3cm7-jjfj.json new file mode 100644 index 00000000000..1a89f594e25 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-6jjg-3cm7-jjfj/GHSA-6jjg-3cm7-jjfj.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6jjg-3cm7-jjfj", + "modified": "2024-08-08T18:31:21Z", + "published": "2024-08-08T18:31:21Z", + "aliases": [ + "CVE-2024-42493" + ], + "details": "Dorsett Controls InfoScan is vulnerable due to a leak of possible \nsensitive information through the response headers and the rendered \nJavaScript prior to user login.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42493" + }, + { + "type": "WEB", + "url": "https://portal.dtscada.com/#/security-bulletins?bulletin=1" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-221-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-08T18:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-6w5f-w9gf-qv9r/GHSA-6w5f-w9gf-qv9r.json b/advisories/unreviewed/2024/08/GHSA-6w5f-w9gf-qv9r/GHSA-6w5f-w9gf-qv9r.json new file mode 100644 index 00000000000..cbfdc34d762 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-6w5f-w9gf-qv9r/GHSA-6w5f-w9gf-qv9r.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6w5f-w9gf-qv9r", + "modified": "2024-08-08T18:31:20Z", + "published": "2024-08-08T18:31:20Z", + "aliases": [ + "CVE-2024-41238" + ], + "details": "A SQL injection vulnerability in /smsa/student_login.php in Kashipara Responsive School Management System v1.0 allows an attacker to execute arbitrary SQL commands via the \"username\" parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41238" + }, + { + "type": "WEB", + "url": "https://github.com/takekaramey/CVE_Writeup/blob/main/Kashipara/Responsive%20School%20Management%20System%20v3.2.0/SQL%20Injection%20-%20Student.pdf" + }, + { + "type": "WEB", + "url": "https://www.kashipara.com/project/php/12362/responsive-school-management-system-php-project-source-code" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-08T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-743g-pfwq-r4wv/GHSA-743g-pfwq-r4wv.json b/advisories/unreviewed/2024/08/GHSA-743g-pfwq-r4wv/GHSA-743g-pfwq-r4wv.json new file mode 100644 index 00000000000..50f05e0a8d4 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-743g-pfwq-r4wv/GHSA-743g-pfwq-r4wv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-743g-pfwq-r4wv", + "modified": "2024-08-08T18:31:20Z", + "published": "2024-08-08T18:31:20Z", + "aliases": [ + "CVE-2024-0101" + ], + "details": "NVIDIA Mellanox OS, ONYX, Skyway, MetroX-2 and MetroX-3 XC contain a vulnerability in ipfilter, where improper ipfilter definitions could enable an attacker to cause a failure by attacking the switch. A successful exploit of this vulnerability might lead to denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0101" + }, + { + "type": "WEB", + "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5559" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-693" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-08T17:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-757v-57mw-8gq9/GHSA-757v-57mw-8gq9.json b/advisories/unreviewed/2024/08/GHSA-757v-57mw-8gq9/GHSA-757v-57mw-8gq9.json new file mode 100644 index 00000000000..773a9f0641c --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-757v-57mw-8gq9/GHSA-757v-57mw-8gq9.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-757v-57mw-8gq9", + "modified": "2024-08-08T18:31:20Z", + "published": "2024-08-08T18:31:20Z", + "aliases": [ + "CVE-2023-24063" + ], + "details": "Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR10 fails to validate /etc/mtab during the Pre-Boot Authorization (PBA) process. This can be exploited by a physical attacker who is able to manipulate the contents of the system's hard disk.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-24063" + }, + { + "type": "WEB", + "url": "https://media.defcon.org/DEF%20CON%2032/DEF%20CON%2032%20presentations/DEF%20CON%2032%20-%20Matt%20Burch%20-%20Where%E2%80%99s%20the%20Money%20-%20Defeating%20ATM%20Disk%20Encryption-white%20paper.pdf" + }, + { + "type": "WEB", + "url": "https://www.dieboldnixdorf.com/en-us/banking/portfolio/software/security" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-08T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-7jrj-xq8x-h553/GHSA-7jrj-xq8x-h553.json b/advisories/unreviewed/2024/08/GHSA-7jrj-xq8x-h553/GHSA-7jrj-xq8x-h553.json index 79b14bb2365..b1758282a14 100644 --- a/advisories/unreviewed/2024/08/GHSA-7jrj-xq8x-h553/GHSA-7jrj-xq8x-h553.json +++ b/advisories/unreviewed/2024/08/GHSA-7jrj-xq8x-h553/GHSA-7jrj-xq8x-h553.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7jrj-xq8x-h553", - "modified": "2024-08-07T00:30:47Z", + "modified": "2024-08-08T18:31:20Z", "published": "2024-08-06T15:30:53Z", "aliases": [ "CVE-2024-7522" ], "details": "Editor code failed to check an attribute value. This could have led to an out-of-bounds read. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, and Firefox ESR < 128.1.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-06T13:15:57Z" diff --git a/advisories/unreviewed/2024/08/GHSA-898x-8mpw-mjf8/GHSA-898x-8mpw-mjf8.json b/advisories/unreviewed/2024/08/GHSA-898x-8mpw-mjf8/GHSA-898x-8mpw-mjf8.json new file mode 100644 index 00000000000..47f0b805a85 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-898x-8mpw-mjf8/GHSA-898x-8mpw-mjf8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-898x-8mpw-mjf8", + "modified": "2024-08-08T18:31:20Z", + "published": "2024-08-08T18:31:20Z", + "aliases": [ + "CVE-2024-7477" + ], + "details": "A SQL injection vulnerability was found which could allow a command line interface (CLI) user with administrative privileges to execute arbitrary queries against the Avaya Aura System Manager database. \n\nAffected versions include 10.1.x.x and 10.2.x.x. Versions prior to 10.1 are end of manufacturer support.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7477" + }, + { + "type": "WEB", + "url": "https://download.avaya.com/css/public/documents/101091159" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-08T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-8h54-xh89-c57v/GHSA-8h54-xh89-c57v.json b/advisories/unreviewed/2024/08/GHSA-8h54-xh89-c57v/GHSA-8h54-xh89-c57v.json new file mode 100644 index 00000000000..bfcc7c50a2c --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-8h54-xh89-c57v/GHSA-8h54-xh89-c57v.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8h54-xh89-c57v", + "modified": "2024-08-08T18:31:21Z", + "published": "2024-08-08T18:31:21Z", + "aliases": [ + "CVE-2024-42408" + ], + "details": "The InfoScan client download page can be intercepted with a proxy, to \nexpose filenames located on the system, which could lead to additional \ninformation exposure.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42408" + }, + { + "type": "WEB", + "url": "https://portal.dtscada.com/#/security-bulletins?bulletin=1" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-221-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-08T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-c9w5-xr92-cpm7/GHSA-c9w5-xr92-cpm7.json b/advisories/unreviewed/2024/08/GHSA-c9w5-xr92-cpm7/GHSA-c9w5-xr92-cpm7.json new file mode 100644 index 00000000000..76e985ede72 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-c9w5-xr92-cpm7/GHSA-c9w5-xr92-cpm7.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c9w5-xr92-cpm7", + "modified": "2024-08-08T18:31:20Z", + "published": "2024-08-08T18:31:20Z", + "aliases": [ + "CVE-2023-28865" + ], + "details": "Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR15, 4.0.0 SR05, 4.1.0 SR03, and 4.2.0 SR02 fails to validate the directory contents of certain directories (e.g., ensuring the expected hash sum) during the Pre-Boot Authorization (PBA) process. This can be exploited by a physical attacker who is able to manipulate the contents of the system's hard disk.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28865" + }, + { + "type": "WEB", + "url": "https://media.defcon.org/DEF%20CON%2032/DEF%20CON%2032%20presentations/DEF%20CON%2032%20-%20Matt%20Burch%20-%20Where%E2%80%99s%20the%20Money%20-%20Defeating%20ATM%20Disk%20Encryption-white%20paper.pdf" + }, + { + "type": "WEB", + "url": "https://www.dieboldnixdorf.com/en-us/banking/portfolio/software/security" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-08T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-m578-pv52-h53w/GHSA-m578-pv52-h53w.json b/advisories/unreviewed/2024/08/GHSA-m578-pv52-h53w/GHSA-m578-pv52-h53w.json index 46adc277e2e..97011445f89 100644 --- a/advisories/unreviewed/2024/08/GHSA-m578-pv52-h53w/GHSA-m578-pv52-h53w.json +++ b/advisories/unreviewed/2024/08/GHSA-m578-pv52-h53w/GHSA-m578-pv52-h53w.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-295" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-mj2x-c9j2-vp7g/GHSA-mj2x-c9j2-vp7g.json b/advisories/unreviewed/2024/08/GHSA-mj2x-c9j2-vp7g/GHSA-mj2x-c9j2-vp7g.json new file mode 100644 index 00000000000..d7fa2e51983 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-mj2x-c9j2-vp7g/GHSA-mj2x-c9j2-vp7g.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mj2x-c9j2-vp7g", + "modified": "2024-08-08T18:31:20Z", + "published": "2024-08-08T18:31:20Z", + "aliases": [ + "CVE-2023-40261" + ], + "details": "Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR17, 4.0.0 SR07, 4.1.0 SR04, 4.2.0 SR04, and 4.3.0 SR03 fails to validate file attributes during the Pre-Boot Authorization (PBA) process. This can be exploited by a physical attacker who is able to manipulate the contents of the system's hard disk.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40261" + }, + { + "type": "WEB", + "url": "https://media.defcon.org/DEF%20CON%2032/DEF%20CON%2032%20presentations/DEF%20CON%2032%20-%20Matt%20Burch%20-%20Where%E2%80%99s%20the%20Money%20-%20Defeating%20ATM%20Disk%20Encryption-white%20paper.pdf" + }, + { + "type": "WEB", + "url": "https://www.dieboldnixdorf.com/en-us/banking/portfolio/software/security" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-08T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-p9q4-cppj-78gq/GHSA-p9q4-cppj-78gq.json b/advisories/unreviewed/2024/08/GHSA-p9q4-cppj-78gq/GHSA-p9q4-cppj-78gq.json new file mode 100644 index 00000000000..c70781924ac --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-p9q4-cppj-78gq/GHSA-p9q4-cppj-78gq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p9q4-cppj-78gq", + "modified": "2024-08-08T18:31:20Z", + "published": "2024-08-08T18:31:20Z", + "aliases": [ + "CVE-2024-37382" + ], + "details": "An issue discovered in import host feature in Ab Initio Metadata Hub and Authorization Gateway before 4.3.1.1 allows attackers to run arbitrary code via crafted modification of server configuration.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37382" + }, + { + "type": "WEB", + "url": "https://www.abinitio.com/en/security-advisories/ab-2024-003" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-08T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-pqx2-f9cx-8825/GHSA-pqx2-f9cx-8825.json b/advisories/unreviewed/2024/08/GHSA-pqx2-f9cx-8825/GHSA-pqx2-f9cx-8825.json new file mode 100644 index 00000000000..667b3b3580a --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-pqx2-f9cx-8825/GHSA-pqx2-f9cx-8825.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pqx2-f9cx-8825", + "modified": "2024-08-08T18:31:20Z", + "published": "2024-08-08T18:31:20Z", + "aliases": [ + "CVE-2024-0102" + ], + "details": "NVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvdisasm, where an attacker can cause an out-of-bounds read issue by deceiving a user into reading a malformed ELF file. A successful exploit of this vulnerability might lead to denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0102" + }, + { + "type": "WEB", + "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5548" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-08T17:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-pwxm-h2xg-rwv6/GHSA-pwxm-h2xg-rwv6.json b/advisories/unreviewed/2024/08/GHSA-pwxm-h2xg-rwv6/GHSA-pwxm-h2xg-rwv6.json index e3518a8ca2a..e855134e8cb 100644 --- a/advisories/unreviewed/2024/08/GHSA-pwxm-h2xg-rwv6/GHSA-pwxm-h2xg-rwv6.json +++ b/advisories/unreviewed/2024/08/GHSA-pwxm-h2xg-rwv6/GHSA-pwxm-h2xg-rwv6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pwxm-h2xg-rwv6", - "modified": "2024-08-07T18:30:41Z", + "modified": "2024-08-08T18:31:20Z", "published": "2024-08-02T21:31:34Z", "aliases": [ "CVE-2024-38889" ], "details": "An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform SQL Injection due to improper neutralization of special elements used in an SQL command.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-02T20:17:00Z" diff --git a/advisories/unreviewed/2024/08/GHSA-qrrm-xwcc-693j/GHSA-qrrm-xwcc-693j.json b/advisories/unreviewed/2024/08/GHSA-qrrm-xwcc-693j/GHSA-qrrm-xwcc-693j.json new file mode 100644 index 00000000000..75e4fd9e9ab --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-qrrm-xwcc-693j/GHSA-qrrm-xwcc-693j.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qrrm-xwcc-693j", + "modified": "2024-08-08T18:31:20Z", + "published": "2024-08-08T18:31:20Z", + "aliases": [ + "CVE-2024-41161" + ], + "details": "Use of hard-coded credentials vulnerability affecting Vonets industrial wifi bridge relays and WiFi bridge repeaters, software versions \n3.3.23.6.9 and prior, enables an unauthenticated remote attacker to \nbypass authentication using hard-coded administrator credentials. These \naccounts cannot be disabled.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41161" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-214-08" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-798" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-08T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-qx4x-h5xp-mmqx/GHSA-qx4x-h5xp-mmqx.json b/advisories/unreviewed/2024/08/GHSA-qx4x-h5xp-mmqx/GHSA-qx4x-h5xp-mmqx.json new file mode 100644 index 00000000000..31f952e51b1 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-qx4x-h5xp-mmqx/GHSA-qx4x-h5xp-mmqx.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qx4x-h5xp-mmqx", + "modified": "2024-08-08T18:31:20Z", + "published": "2024-08-08T18:31:20Z", + "aliases": [ + "CVE-2023-24064" + ], + "details": "Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR4 fails to validate /etc/initab during the Pre-Boot Authorization (PBA) process. This can be exploited by a physical attacker who is able to manipulate the contents of the system's hard disk.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-24064" + }, + { + "type": "WEB", + "url": "https://media.defcon.org/DEF%20CON%2032/DEF%20CON%2032%20presentations/DEF%20CON%2032%20-%20Matt%20Burch%20-%20Where%E2%80%99s%20the%20Money%20-%20Defeating%20ATM%20Disk%20Encryption-white%20paper.pdf" + }, + { + "type": "WEB", + "url": "https://www.dieboldnixdorf.com/en-us/banking/portfolio/software/security" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-08T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-vfcg-vh6j-gg8j/GHSA-vfcg-vh6j-gg8j.json b/advisories/unreviewed/2024/08/GHSA-vfcg-vh6j-gg8j/GHSA-vfcg-vh6j-gg8j.json index 5a7a7c4f638..c343dc528c9 100644 --- a/advisories/unreviewed/2024/08/GHSA-vfcg-vh6j-gg8j/GHSA-vfcg-vh6j-gg8j.json +++ b/advisories/unreviewed/2024/08/GHSA-vfcg-vh6j-gg8j/GHSA-vfcg-vh6j-gg8j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vfcg-vh6j-gg8j", - "modified": "2024-08-08T15:31:31Z", + "modified": "2024-08-08T18:31:20Z", "published": "2024-08-08T15:31:30Z", "aliases": [ "CVE-2024-3659" ], "details": "Firmware in KAON AR2140 routers prior to version 4.2.16 is vulnerable to a shell command injection via sending a crafted request to one of the endpoints.\nIn order to exploit this vulnerability, one has to have access to the administrative portal of the router.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-77" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-08T13:15:13Z" diff --git a/advisories/unreviewed/2024/08/GHSA-w6j6-w6jx-vf2r/GHSA-w6j6-w6jx-vf2r.json b/advisories/unreviewed/2024/08/GHSA-w6j6-w6jx-vf2r/GHSA-w6j6-w6jx-vf2r.json new file mode 100644 index 00000000000..8d5e8527dd9 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-w6j6-w6jx-vf2r/GHSA-w6j6-w6jx-vf2r.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w6j6-w6jx-vf2r", + "modified": "2024-08-08T18:31:20Z", + "published": "2024-08-08T18:31:20Z", + "aliases": [ + "CVE-2024-7394" + ], + "details": "Concrete CMS versions 9 through 9.3.2 and below 8.5.18 are vulnerable to Stored XSS in getAttributeSetName().  A rogue administrator could inject malicious code. The Concrete CMS team gave this a CVSS v3.1 rank of 2 with vector AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:N https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator  and a CVSS v4.0 rank of 1.8 with vector CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N . Thanks, m3dium for reporting.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7394" + }, + { + "type": "WEB", + "url": "https://github.com/concretecms/concretecms/pull/12166" + }, + { + "type": "WEB", + "url": "https://github.com/concretecms/concretecms/commit/c08d9671cec4e7afdabb547339c4bc0bed8eab06" + }, + { + "type": "WEB", + "url": "https://documentation.concretecms.org/9-x/developers/introduction/version-history/933-release-notes?pk_vid=e367a434ef4830491723055753d52041" + }, + { + "type": "WEB", + "url": "https://documentation.concretecms.org/developers/introduction/version-history/8518-release-notes?pk_vid=e367a434ef4830491723055758d52041" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-08T17:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-w8qw-wpmq-q46h/GHSA-w8qw-wpmq-q46h.json b/advisories/unreviewed/2024/08/GHSA-w8qw-wpmq-q46h/GHSA-w8qw-wpmq-q46h.json new file mode 100644 index 00000000000..deb86ee6566 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-w8qw-wpmq-q46h/GHSA-w8qw-wpmq-q46h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w8qw-wpmq-q46h", + "modified": "2024-08-08T18:31:20Z", + "published": "2024-08-08T18:31:20Z", + "aliases": [ + "CVE-2024-0107" + ], + "details": "NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0107" + }, + { + "type": "WEB", + "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5557" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-08T17:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-whp7-r8fh-f38c/GHSA-whp7-r8fh-f38c.json b/advisories/unreviewed/2024/08/GHSA-whp7-r8fh-f38c/GHSA-whp7-r8fh-f38c.json new file mode 100644 index 00000000000..1c9c425cfb4 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-whp7-r8fh-f38c/GHSA-whp7-r8fh-f38c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-whp7-r8fh-f38c", + "modified": "2024-08-08T18:31:20Z", + "published": "2024-08-08T18:31:20Z", + "aliases": [ + "CVE-2024-0104" + ], + "details": "NVIDIA Mellanox OS, ONYX, Skyway, MetroX-2 and MetroX-3 XC contain a vulnerability in the LDAP AAA component, where a user can cause improper access. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and escalation of privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0104" + }, + { + "type": "WEB", + "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5559" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-08T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-x6j3-2cg8-g68w/GHSA-x6j3-2cg8-g68w.json b/advisories/unreviewed/2024/08/GHSA-x6j3-2cg8-g68w/GHSA-x6j3-2cg8-g68w.json new file mode 100644 index 00000000000..daa3099abb2 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-x6j3-2cg8-g68w/GHSA-x6j3-2cg8-g68w.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x6j3-2cg8-g68w", + "modified": "2024-08-08T18:31:20Z", + "published": "2024-08-08T18:31:20Z", + "aliases": [ + "CVE-2023-33206" + ], + "details": "Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR16, 4.0.0 SR06, 4.1.0 SR04, 4.2.0 SR03, and 4.3.0 SR01 fails to validate symlinks during the Pre-Boot Authorization (PBA) process. This can be exploited by a physical attacker who is able to manipulate the contents of the system's hard disk.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33206" + }, + { + "type": "WEB", + "url": "https://media.defcon.org/DEF%20CON%2032/DEF%20CON%2032%20presentations/DEF%20CON%2032%20-%20Matt%20Burch%20-%20Where%E2%80%99s%20the%20Money%20-%20Defeating%20ATM%20Disk%20Encryption-white%20paper.pdf" + }, + { + "type": "WEB", + "url": "https://www.dieboldnixdorf.com/en-us/banking/portfolio/software/security" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-08T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-xg77-wrvc-q75c/GHSA-xg77-wrvc-q75c.json b/advisories/unreviewed/2024/08/GHSA-xg77-wrvc-q75c/GHSA-xg77-wrvc-q75c.json index 237f48427b7..506840aa58a 100644 --- a/advisories/unreviewed/2024/08/GHSA-xg77-wrvc-q75c/GHSA-xg77-wrvc-q75c.json +++ b/advisories/unreviewed/2024/08/GHSA-xg77-wrvc-q75c/GHSA-xg77-wrvc-q75c.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-xvgc-j98h-3v9x/GHSA-xvgc-j98h-3v9x.json b/advisories/unreviewed/2024/08/GHSA-xvgc-j98h-3v9x/GHSA-xvgc-j98h-3v9x.json new file mode 100644 index 00000000000..b7f1ad34e51 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-xvgc-j98h-3v9x/GHSA-xvgc-j98h-3v9x.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xvgc-j98h-3v9x", + "modified": "2024-08-08T18:31:20Z", + "published": "2024-08-08T18:31:20Z", + "aliases": [ + "CVE-2023-24062" + ], + "details": "Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR12, 4.0.0 SR04, 4.1.0 SR02, and 4.2.0 SR01 fails to validate the directory structure of the root file system during the Pre-Boot Authorization (PBA) process. This can be exploited by a physical attacker who is able to manipulate the contents of the system's hard disk.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-24062" + }, + { + "type": "WEB", + "url": "https://media.defcon.org/DEF%20CON%2032/DEF%20CON%2032%20presentations/DEF%20CON%2032%20-%20Matt%20Burch%20-%20Where%E2%80%99s%20the%20Money%20-%20Defeating%20ATM%20Disk%20Encryption-white%20paper.pdf" + }, + { + "type": "WEB", + "url": "https://www.dieboldnixdorf.com/en-us/banking/portfolio/software/security" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-08T18:15:09Z" + } +} \ No newline at end of file