mirror of
https://github.com/netbirdio/advisory-database.git
synced 2026-05-22 18:04:22 -07:00
Advisory Database Sync
This commit is contained in:
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-h755-8qp9-cq85",
|
||||
"modified": "2024-04-10T19:54:41Z",
|
||||
"modified": "2024-06-28T18:31:41Z",
|
||||
"published": "2023-07-05T15:30:24Z",
|
||||
"aliases": [
|
||||
"CVE-2023-36665"
|
||||
@@ -97,6 +97,10 @@
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/protobufjs/protobuf.js/releases/tag/protobufjs-v7.2.4"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.netapp.com/advisory/ntap-20240628-0006"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.code-intelligence.com/blog/cve-protobufjs-prototype-pollution-cve-2023-36665"
|
||||
|
||||
@@ -1,14 +1,17 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-2m74-3m4w-28q3",
|
||||
"modified": "2022-05-14T02:31:31Z",
|
||||
"modified": "2024-06-28T18:31:41Z",
|
||||
"published": "2022-05-14T02:31:31Z",
|
||||
"aliases": [
|
||||
"CVE-2014-2817"
|
||||
],
|
||||
"details": "Microsoft Internet Explorer 6 through 11 allows remote attackers to gain privileges via a crafted web site, aka \"Internet Explorer Elevation of Privilege Vulnerability.\"",
|
||||
"severity": [
|
||||
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
|
||||
@@ -1,14 +1,17 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-2qh2-hj3f-rhcf",
|
||||
"modified": "2022-05-17T01:33:53Z",
|
||||
"modified": "2024-06-28T18:31:40Z",
|
||||
"published": "2022-05-17T01:33:53Z",
|
||||
"aliases": [
|
||||
"CVE-2013-3993"
|
||||
],
|
||||
"details": "IBM InfoSphere BigInsights before 2.1.0.3 allows remote authenticated users to bypass intended file and directory restrictions, or access untrusted data or code, via crafted parameters in unspecified API calls.",
|
||||
"severity": [
|
||||
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
@@ -37,7 +40,7 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
"CWE-22"
|
||||
],
|
||||
"severity": "LOW",
|
||||
"github_reviewed": false,
|
||||
|
||||
@@ -1,14 +1,17 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-4wxx-xmrx-3xq9",
|
||||
"modified": "2022-05-14T01:31:24Z",
|
||||
"modified": "2024-06-28T18:31:41Z",
|
||||
"published": "2022-05-14T01:31:24Z",
|
||||
"aliases": [
|
||||
"CVE-2014-4148"
|
||||
],
|
||||
"details": "win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted TrueType font, as exploited in the wild in October 2014, aka \"TrueType Font Parsing Remote Code Execution Vulnerability.\"",
|
||||
"severity": [
|
||||
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
|
||||
@@ -1,14 +1,17 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-5rf9-j2cv-922c",
|
||||
"modified": "2022-05-14T02:30:58Z",
|
||||
"modified": "2024-06-28T18:31:41Z",
|
||||
"published": "2022-05-14T02:30:58Z",
|
||||
"aliases": [
|
||||
"CVE-2014-4077"
|
||||
],
|
||||
"details": "Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, and Office 2007 SP3, when IMJPDCT.EXE (aka IME for Japanese) is installed, allow remote attackers to bypass a sandbox protection mechanism via a crafted PDF document, aka \"Microsoft IME (Japanese) Elevation of Privilege Vulnerability,\" as exploited in the wild in 2014.",
|
||||
"severity": [
|
||||
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
|
||||
@@ -1,14 +1,17 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-5xv2-v332-c8c2",
|
||||
"modified": "2022-05-14T02:30:39Z",
|
||||
"modified": "2024-06-28T18:31:41Z",
|
||||
"published": "2022-05-14T02:30:39Z",
|
||||
"aliases": [
|
||||
"CVE-2014-4123"
|
||||
],
|
||||
"details": "Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka \"Internet Explorer Elevation of Privilege Vulnerability,\" as exploited in the wild in October 2014, a different vulnerability than CVE-2014-4124.",
|
||||
"severity": [
|
||||
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
|
||||
@@ -1,14 +1,17 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-72pp-v9jm-c6xj",
|
||||
"modified": "2022-05-02T06:15:13Z",
|
||||
"modified": "2024-06-28T18:31:40Z",
|
||||
"published": "2022-05-02T06:15:13Z",
|
||||
"aliases": [
|
||||
"CVE-2010-0738"
|
||||
],
|
||||
"details": "The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows remote attackers to send requests to this application's GET handler by using a different method.",
|
||||
"severity": [
|
||||
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
|
||||
@@ -1,14 +1,17 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-8c3c-9q97-wq3f",
|
||||
"modified": "2022-05-17T00:17:52Z",
|
||||
"modified": "2024-06-28T18:31:40Z",
|
||||
"published": "2022-05-17T00:17:52Z",
|
||||
"aliases": [
|
||||
"CVE-2012-1710"
|
||||
],
|
||||
"details": "Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware 10.1.3.5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Designer, a different vulnerability than CVE-2012-1709.",
|
||||
"severity": [
|
||||
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
|
||||
@@ -1,14 +1,17 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-8rrv-3xx7-wmfc",
|
||||
"modified": "2022-05-02T06:15:59Z",
|
||||
"modified": "2024-06-28T18:31:40Z",
|
||||
"published": "2022-05-02T06:15:59Z",
|
||||
"aliases": [
|
||||
"CVE-2010-0840"
|
||||
],
|
||||
"details": "Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the March 2010 CPU. Oracle has not commented on claims from a reliable researcher that this is related to improper checks when executing privileged methods in the Java Runtime Environment (JRE), which allows attackers to execute arbitrary code via (1) an untrusted object that extends the trusted class but has not modified a certain method, or (2) \"a similar trust issue with interfaces,\" aka \"Trusted Methods Chaining Remote Code Execution Vulnerability.\"",
|
||||
"severity": [
|
||||
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
|
||||
@@ -1,14 +1,17 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-8wm7-83p7-m6fh",
|
||||
"modified": "2022-05-14T02:33:20Z",
|
||||
"modified": "2024-06-28T18:31:40Z",
|
||||
"published": "2022-05-14T02:33:20Z",
|
||||
"aliases": [
|
||||
"CVE-2013-3896"
|
||||
],
|
||||
"details": "Microsoft Silverlight 5 before 5.1.20913.0 does not properly validate pointers during access to Silverlight elements, which allows remote attackers to obtain sensitive information via a crafted Silverlight application, aka \"Silverlight Vulnerability.\"",
|
||||
"severity": [
|
||||
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
|
||||
@@ -1,14 +1,17 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-cpx9-g67g-v8c5",
|
||||
"modified": "2022-05-14T02:07:35Z",
|
||||
"modified": "2024-06-28T18:31:41Z",
|
||||
"published": "2022-05-14T02:07:35Z",
|
||||
"aliases": [
|
||||
"CVE-2015-4495"
|
||||
],
|
||||
"details": "The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same Origin Policy, and read arbitrary files or gain privileges, via vectors involving crafted JavaScript code and a native setter, as exploited in the wild in August 2015.",
|
||||
"severity": [
|
||||
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
|
||||
@@ -1,14 +1,17 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-cv93-w72p-jgh2",
|
||||
"modified": "2022-05-14T02:28:03Z",
|
||||
"modified": "2024-06-28T18:31:41Z",
|
||||
"published": "2022-05-14T02:28:03Z",
|
||||
"aliases": [
|
||||
"CVE-2015-2425"
|
||||
],
|
||||
"details": "Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka \"Internet Explorer Memory Corruption Vulnerability,\" a different vulnerability than CVE-2015-2383 and CVE-2015-2384.",
|
||||
"severity": [
|
||||
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
@@ -29,7 +32,8 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-119"
|
||||
"CWE-119",
|
||||
"CWE-787"
|
||||
],
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": false,
|
||||
|
||||
@@ -1,14 +1,17 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-gr4p-px5x-x8jm",
|
||||
"modified": "2022-05-14T02:29:11Z",
|
||||
"modified": "2024-06-28T18:31:41Z",
|
||||
"published": "2022-05-14T02:29:11Z",
|
||||
"aliases": [
|
||||
"CVE-2015-1671"
|
||||
],
|
||||
"details": "The Windows DirectWrite library, as used in Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2; Office 2007 SP3 and 2010 SP2; Live Meeting 2007 Console; Lync 2010; Lync 2010 Attendee; Lync 2013 SP1; Lync Basic 2013 SP1; Silverlight 5 before 5.1.40416.00; and Silverlight 5 Developer Runtime before 5.1.40416.00, allows remote attackers to execute arbitrary code via a crafted TrueType font, aka \"TrueType Font Parsing Vulnerability.\"",
|
||||
"severity": [
|
||||
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
|
||||
@@ -1,14 +1,17 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-m362-frg6-j2v7",
|
||||
"modified": "2022-05-17T03:07:03Z",
|
||||
"modified": "2024-06-28T18:31:40Z",
|
||||
"published": "2022-05-17T03:07:03Z",
|
||||
"aliases": [
|
||||
"CVE-2014-0546"
|
||||
],
|
||||
"details": "Adobe Reader and Acrobat 10.x before 10.1.11 and 11.x before 11.0.08 on Windows allow attackers to bypass a sandbox protection mechanism, and consequently execute native code in a privileged context, via unspecified vectors.",
|
||||
"severity": [
|
||||
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
|
||||
@@ -1,14 +1,17 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-px5j-h582-r6p9",
|
||||
"modified": "2022-05-05T02:48:21Z",
|
||||
"modified": "2024-06-28T18:31:40Z",
|
||||
"published": "2022-05-05T02:48:21Z",
|
||||
"aliases": [
|
||||
"CVE-2013-0074"
|
||||
],
|
||||
"details": "Microsoft Silverlight 5, and 5 Developer Runtime, before 5.1.20125.0 does not properly validate pointers during HTML object rendering, which allows remote attackers to execute arbitrary code via a crafted Silverlight application, aka \"Silverlight Double Dereference Vulnerability.\"",
|
||||
"severity": [
|
||||
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
|
||||
@@ -1,14 +1,17 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-vcwg-4772-7rvx",
|
||||
"modified": "2022-05-02T06:22:44Z",
|
||||
"modified": "2024-06-28T18:31:40Z",
|
||||
"published": "2022-05-02T06:22:44Z",
|
||||
"aliases": [
|
||||
"CVE-2010-1428"
|
||||
],
|
||||
"details": "The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows remote attackers to obtain sensitive information via an unspecified request that uses a different method.",
|
||||
"severity": [
|
||||
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-5gvr-285q-pwc3",
|
||||
"modified": "2024-06-05T18:30:34Z",
|
||||
"modified": "2024-06-28T18:31:42Z",
|
||||
"published": "2024-02-04T15:30:22Z",
|
||||
"aliases": [
|
||||
"CVE-2023-6240"
|
||||
@@ -61,6 +61,10 @@
|
||||
"type": "WEB",
|
||||
"url": "https://people.redhat.com/~hkario/marvin"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.netapp.com/advisory/ntap-20240628-0002"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://securitypitfalls.wordpress.com/2023/10/16/experiment-with-side-channel-attacks-yourself"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-46wg-cm84-p5p3",
|
||||
"modified": "2024-04-27T00:30:38Z",
|
||||
"modified": "2024-06-28T18:31:42Z",
|
||||
"published": "2024-04-27T00:30:38Z",
|
||||
"aliases": [
|
||||
"CVE-2024-2859"
|
||||
@@ -21,6 +21,10 @@
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2859"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.netapp.com/advisory/ntap-20240628-0003"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://support.broadcom.com/external/content/SecurityAdvisories/0/23245"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-9243-vfr2-5rcw",
|
||||
"modified": "2024-04-04T18:30:33Z",
|
||||
"modified": "2024-06-28T18:31:42Z",
|
||||
"published": "2024-04-04T18:30:33Z",
|
||||
"aliases": [
|
||||
"CVE-2023-3454"
|
||||
@@ -21,6 +21,10 @@
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3454"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.netapp.com/advisory/ntap-20240628-0004"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://support.broadcom.com/external/content/SecurityAdvisories/0/23215"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-mq9r-62m5-pjc2",
|
||||
"modified": "2024-04-05T03:30:28Z",
|
||||
"modified": "2024-06-28T18:31:42Z",
|
||||
"published": "2024-04-05T03:30:28Z",
|
||||
"aliases": [
|
||||
"CVE-2023-5973"
|
||||
@@ -21,6 +21,10 @@
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5973"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.netapp.com/advisory/ntap-20240628-0005"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://support.broadcom.com/external/content/SecurityAdvisories/0/23214"
|
||||
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user