diff --git a/advisories/github-reviewed/2023/07/GHSA-h755-8qp9-cq85/GHSA-h755-8qp9-cq85.json b/advisories/github-reviewed/2023/07/GHSA-h755-8qp9-cq85/GHSA-h755-8qp9-cq85.json index f791c72db00..fa6edb2bf92 100644 --- a/advisories/github-reviewed/2023/07/GHSA-h755-8qp9-cq85/GHSA-h755-8qp9-cq85.json +++ b/advisories/github-reviewed/2023/07/GHSA-h755-8qp9-cq85/GHSA-h755-8qp9-cq85.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h755-8qp9-cq85", - "modified": "2024-04-10T19:54:41Z", + "modified": "2024-06-28T18:31:41Z", "published": "2023-07-05T15:30:24Z", "aliases": [ "CVE-2023-36665" @@ -97,6 +97,10 @@ "type": "WEB", "url": "https://github.com/protobufjs/protobuf.js/releases/tag/protobufjs-v7.2.4" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240628-0006" + }, { "type": "WEB", "url": "https://www.code-intelligence.com/blog/cve-protobufjs-prototype-pollution-cve-2023-36665" diff --git a/advisories/unreviewed/2022/05/GHSA-2m74-3m4w-28q3/GHSA-2m74-3m4w-28q3.json b/advisories/unreviewed/2022/05/GHSA-2m74-3m4w-28q3/GHSA-2m74-3m4w-28q3.json index 53f4c3c7390..806230d2022 100644 --- a/advisories/unreviewed/2022/05/GHSA-2m74-3m4w-28q3/GHSA-2m74-3m4w-28q3.json +++ b/advisories/unreviewed/2022/05/GHSA-2m74-3m4w-28q3/GHSA-2m74-3m4w-28q3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2m74-3m4w-28q3", - "modified": "2022-05-14T02:31:31Z", + "modified": "2024-06-28T18:31:41Z", "published": "2022-05-14T02:31:31Z", "aliases": [ "CVE-2014-2817" ], "details": "Microsoft Internet Explorer 6 through 11 allows remote attackers to gain privileges via a crafted web site, aka \"Internet Explorer Elevation of Privilege Vulnerability.\"", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-2qh2-hj3f-rhcf/GHSA-2qh2-hj3f-rhcf.json b/advisories/unreviewed/2022/05/GHSA-2qh2-hj3f-rhcf/GHSA-2qh2-hj3f-rhcf.json index 6406a1a30e2..edf4304d733 100644 --- a/advisories/unreviewed/2022/05/GHSA-2qh2-hj3f-rhcf/GHSA-2qh2-hj3f-rhcf.json +++ b/advisories/unreviewed/2022/05/GHSA-2qh2-hj3f-rhcf/GHSA-2qh2-hj3f-rhcf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2qh2-hj3f-rhcf", - "modified": "2022-05-17T01:33:53Z", + "modified": "2024-06-28T18:31:40Z", "published": "2022-05-17T01:33:53Z", "aliases": [ "CVE-2013-3993" ], "details": "IBM InfoSphere BigInsights before 2.1.0.3 allows remote authenticated users to bypass intended file and directory restrictions, or access untrusted data or code, via crafted parameters in unspecified API calls.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -37,7 +40,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-4wxx-xmrx-3xq9/GHSA-4wxx-xmrx-3xq9.json b/advisories/unreviewed/2022/05/GHSA-4wxx-xmrx-3xq9/GHSA-4wxx-xmrx-3xq9.json index ca7f14c5c3f..fa36880273e 100644 --- a/advisories/unreviewed/2022/05/GHSA-4wxx-xmrx-3xq9/GHSA-4wxx-xmrx-3xq9.json +++ b/advisories/unreviewed/2022/05/GHSA-4wxx-xmrx-3xq9/GHSA-4wxx-xmrx-3xq9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4wxx-xmrx-3xq9", - "modified": "2022-05-14T01:31:24Z", + "modified": "2024-06-28T18:31:41Z", "published": "2022-05-14T01:31:24Z", "aliases": [ "CVE-2014-4148" ], "details": "win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted TrueType font, as exploited in the wild in October 2014, aka \"TrueType Font Parsing Remote Code Execution Vulnerability.\"", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-5rf9-j2cv-922c/GHSA-5rf9-j2cv-922c.json b/advisories/unreviewed/2022/05/GHSA-5rf9-j2cv-922c/GHSA-5rf9-j2cv-922c.json index c2fc90c1a6e..fb5ab50f366 100644 --- a/advisories/unreviewed/2022/05/GHSA-5rf9-j2cv-922c/GHSA-5rf9-j2cv-922c.json +++ b/advisories/unreviewed/2022/05/GHSA-5rf9-j2cv-922c/GHSA-5rf9-j2cv-922c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5rf9-j2cv-922c", - "modified": "2022-05-14T02:30:58Z", + "modified": "2024-06-28T18:31:41Z", "published": "2022-05-14T02:30:58Z", "aliases": [ "CVE-2014-4077" ], "details": "Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, and Office 2007 SP3, when IMJPDCT.EXE (aka IME for Japanese) is installed, allow remote attackers to bypass a sandbox protection mechanism via a crafted PDF document, aka \"Microsoft IME (Japanese) Elevation of Privilege Vulnerability,\" as exploited in the wild in 2014.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-5xv2-v332-c8c2/GHSA-5xv2-v332-c8c2.json b/advisories/unreviewed/2022/05/GHSA-5xv2-v332-c8c2/GHSA-5xv2-v332-c8c2.json index 9922100681e..e5ccfe0568c 100644 --- a/advisories/unreviewed/2022/05/GHSA-5xv2-v332-c8c2/GHSA-5xv2-v332-c8c2.json +++ b/advisories/unreviewed/2022/05/GHSA-5xv2-v332-c8c2/GHSA-5xv2-v332-c8c2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5xv2-v332-c8c2", - "modified": "2022-05-14T02:30:39Z", + "modified": "2024-06-28T18:31:41Z", "published": "2022-05-14T02:30:39Z", "aliases": [ "CVE-2014-4123" ], "details": "Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka \"Internet Explorer Elevation of Privilege Vulnerability,\" as exploited in the wild in October 2014, a different vulnerability than CVE-2014-4124.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-72pp-v9jm-c6xj/GHSA-72pp-v9jm-c6xj.json b/advisories/unreviewed/2022/05/GHSA-72pp-v9jm-c6xj/GHSA-72pp-v9jm-c6xj.json index d3236c14eb1..b51f5030d6a 100644 --- a/advisories/unreviewed/2022/05/GHSA-72pp-v9jm-c6xj/GHSA-72pp-v9jm-c6xj.json +++ b/advisories/unreviewed/2022/05/GHSA-72pp-v9jm-c6xj/GHSA-72pp-v9jm-c6xj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-72pp-v9jm-c6xj", - "modified": "2022-05-02T06:15:13Z", + "modified": "2024-06-28T18:31:40Z", "published": "2022-05-02T06:15:13Z", "aliases": [ "CVE-2010-0738" ], "details": "The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows remote attackers to send requests to this application's GET handler by using a different method.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-8c3c-9q97-wq3f/GHSA-8c3c-9q97-wq3f.json b/advisories/unreviewed/2022/05/GHSA-8c3c-9q97-wq3f/GHSA-8c3c-9q97-wq3f.json index 90d063eaa52..93e48d9030a 100644 --- a/advisories/unreviewed/2022/05/GHSA-8c3c-9q97-wq3f/GHSA-8c3c-9q97-wq3f.json +++ b/advisories/unreviewed/2022/05/GHSA-8c3c-9q97-wq3f/GHSA-8c3c-9q97-wq3f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8c3c-9q97-wq3f", - "modified": "2022-05-17T00:17:52Z", + "modified": "2024-06-28T18:31:40Z", "published": "2022-05-17T00:17:52Z", "aliases": [ "CVE-2012-1710" ], "details": "Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware 10.1.3.5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Designer, a different vulnerability than CVE-2012-1709.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-8rrv-3xx7-wmfc/GHSA-8rrv-3xx7-wmfc.json b/advisories/unreviewed/2022/05/GHSA-8rrv-3xx7-wmfc/GHSA-8rrv-3xx7-wmfc.json index f76a177ff5a..9f01d5251e1 100644 --- a/advisories/unreviewed/2022/05/GHSA-8rrv-3xx7-wmfc/GHSA-8rrv-3xx7-wmfc.json +++ b/advisories/unreviewed/2022/05/GHSA-8rrv-3xx7-wmfc/GHSA-8rrv-3xx7-wmfc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8rrv-3xx7-wmfc", - "modified": "2022-05-02T06:15:59Z", + "modified": "2024-06-28T18:31:40Z", "published": "2022-05-02T06:15:59Z", "aliases": [ "CVE-2010-0840" ], "details": "Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the March 2010 CPU. Oracle has not commented on claims from a reliable researcher that this is related to improper checks when executing privileged methods in the Java Runtime Environment (JRE), which allows attackers to execute arbitrary code via (1) an untrusted object that extends the trusted class but has not modified a certain method, or (2) \"a similar trust issue with interfaces,\" aka \"Trusted Methods Chaining Remote Code Execution Vulnerability.\"", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-8wm7-83p7-m6fh/GHSA-8wm7-83p7-m6fh.json b/advisories/unreviewed/2022/05/GHSA-8wm7-83p7-m6fh/GHSA-8wm7-83p7-m6fh.json index 20032d2d19d..bffae5e1d82 100644 --- a/advisories/unreviewed/2022/05/GHSA-8wm7-83p7-m6fh/GHSA-8wm7-83p7-m6fh.json +++ b/advisories/unreviewed/2022/05/GHSA-8wm7-83p7-m6fh/GHSA-8wm7-83p7-m6fh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8wm7-83p7-m6fh", - "modified": "2022-05-14T02:33:20Z", + "modified": "2024-06-28T18:31:40Z", "published": "2022-05-14T02:33:20Z", "aliases": [ "CVE-2013-3896" ], "details": "Microsoft Silverlight 5 before 5.1.20913.0 does not properly validate pointers during access to Silverlight elements, which allows remote attackers to obtain sensitive information via a crafted Silverlight application, aka \"Silverlight Vulnerability.\"", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-cpx9-g67g-v8c5/GHSA-cpx9-g67g-v8c5.json b/advisories/unreviewed/2022/05/GHSA-cpx9-g67g-v8c5/GHSA-cpx9-g67g-v8c5.json index f10ad22c70d..d66713621e4 100644 --- a/advisories/unreviewed/2022/05/GHSA-cpx9-g67g-v8c5/GHSA-cpx9-g67g-v8c5.json +++ b/advisories/unreviewed/2022/05/GHSA-cpx9-g67g-v8c5/GHSA-cpx9-g67g-v8c5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cpx9-g67g-v8c5", - "modified": "2022-05-14T02:07:35Z", + "modified": "2024-06-28T18:31:41Z", "published": "2022-05-14T02:07:35Z", "aliases": [ "CVE-2015-4495" ], "details": "The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same Origin Policy, and read arbitrary files or gain privileges, via vectors involving crafted JavaScript code and a native setter, as exploited in the wild in August 2015.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-cv93-w72p-jgh2/GHSA-cv93-w72p-jgh2.json b/advisories/unreviewed/2022/05/GHSA-cv93-w72p-jgh2/GHSA-cv93-w72p-jgh2.json index b6ae375cdb1..8ba821b0b22 100644 --- a/advisories/unreviewed/2022/05/GHSA-cv93-w72p-jgh2/GHSA-cv93-w72p-jgh2.json +++ b/advisories/unreviewed/2022/05/GHSA-cv93-w72p-jgh2/GHSA-cv93-w72p-jgh2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cv93-w72p-jgh2", - "modified": "2022-05-14T02:28:03Z", + "modified": "2024-06-28T18:31:41Z", "published": "2022-05-14T02:28:03Z", "aliases": [ "CVE-2015-2425" ], "details": "Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka \"Internet Explorer Memory Corruption Vulnerability,\" a different vulnerability than CVE-2015-2383 and CVE-2015-2384.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-gr4p-px5x-x8jm/GHSA-gr4p-px5x-x8jm.json b/advisories/unreviewed/2022/05/GHSA-gr4p-px5x-x8jm/GHSA-gr4p-px5x-x8jm.json index 79a913009fa..2e1f92b97c4 100644 --- a/advisories/unreviewed/2022/05/GHSA-gr4p-px5x-x8jm/GHSA-gr4p-px5x-x8jm.json +++ b/advisories/unreviewed/2022/05/GHSA-gr4p-px5x-x8jm/GHSA-gr4p-px5x-x8jm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gr4p-px5x-x8jm", - "modified": "2022-05-14T02:29:11Z", + "modified": "2024-06-28T18:31:41Z", "published": "2022-05-14T02:29:11Z", "aliases": [ "CVE-2015-1671" ], "details": "The Windows DirectWrite library, as used in Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2; Office 2007 SP3 and 2010 SP2; Live Meeting 2007 Console; Lync 2010; Lync 2010 Attendee; Lync 2013 SP1; Lync Basic 2013 SP1; Silverlight 5 before 5.1.40416.00; and Silverlight 5 Developer Runtime before 5.1.40416.00, allows remote attackers to execute arbitrary code via a crafted TrueType font, aka \"TrueType Font Parsing Vulnerability.\"", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-m362-frg6-j2v7/GHSA-m362-frg6-j2v7.json b/advisories/unreviewed/2022/05/GHSA-m362-frg6-j2v7/GHSA-m362-frg6-j2v7.json index 16848e4d0da..5fbed9f34cd 100644 --- a/advisories/unreviewed/2022/05/GHSA-m362-frg6-j2v7/GHSA-m362-frg6-j2v7.json +++ b/advisories/unreviewed/2022/05/GHSA-m362-frg6-j2v7/GHSA-m362-frg6-j2v7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m362-frg6-j2v7", - "modified": "2022-05-17T03:07:03Z", + "modified": "2024-06-28T18:31:40Z", "published": "2022-05-17T03:07:03Z", "aliases": [ "CVE-2014-0546" ], "details": "Adobe Reader and Acrobat 10.x before 10.1.11 and 11.x before 11.0.08 on Windows allow attackers to bypass a sandbox protection mechanism, and consequently execute native code in a privileged context, via unspecified vectors.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-px5j-h582-r6p9/GHSA-px5j-h582-r6p9.json b/advisories/unreviewed/2022/05/GHSA-px5j-h582-r6p9/GHSA-px5j-h582-r6p9.json index a17200ba97e..7832dd73c80 100644 --- a/advisories/unreviewed/2022/05/GHSA-px5j-h582-r6p9/GHSA-px5j-h582-r6p9.json +++ b/advisories/unreviewed/2022/05/GHSA-px5j-h582-r6p9/GHSA-px5j-h582-r6p9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-px5j-h582-r6p9", - "modified": "2022-05-05T02:48:21Z", + "modified": "2024-06-28T18:31:40Z", "published": "2022-05-05T02:48:21Z", "aliases": [ "CVE-2013-0074" ], "details": "Microsoft Silverlight 5, and 5 Developer Runtime, before 5.1.20125.0 does not properly validate pointers during HTML object rendering, which allows remote attackers to execute arbitrary code via a crafted Silverlight application, aka \"Silverlight Double Dereference Vulnerability.\"", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-vcwg-4772-7rvx/GHSA-vcwg-4772-7rvx.json b/advisories/unreviewed/2022/05/GHSA-vcwg-4772-7rvx/GHSA-vcwg-4772-7rvx.json index 576d18c4860..df34315c9c3 100644 --- a/advisories/unreviewed/2022/05/GHSA-vcwg-4772-7rvx/GHSA-vcwg-4772-7rvx.json +++ b/advisories/unreviewed/2022/05/GHSA-vcwg-4772-7rvx/GHSA-vcwg-4772-7rvx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vcwg-4772-7rvx", - "modified": "2022-05-02T06:22:44Z", + "modified": "2024-06-28T18:31:40Z", "published": "2022-05-02T06:22:44Z", "aliases": [ "CVE-2010-1428" ], "details": "The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows remote attackers to obtain sensitive information via an unspecified request that uses a different method.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2024/02/GHSA-5gvr-285q-pwc3/GHSA-5gvr-285q-pwc3.json b/advisories/unreviewed/2024/02/GHSA-5gvr-285q-pwc3/GHSA-5gvr-285q-pwc3.json index a120525bc54..31558dc00d2 100644 --- a/advisories/unreviewed/2024/02/GHSA-5gvr-285q-pwc3/GHSA-5gvr-285q-pwc3.json +++ b/advisories/unreviewed/2024/02/GHSA-5gvr-285q-pwc3/GHSA-5gvr-285q-pwc3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5gvr-285q-pwc3", - "modified": "2024-06-05T18:30:34Z", + "modified": "2024-06-28T18:31:42Z", "published": "2024-02-04T15:30:22Z", "aliases": [ "CVE-2023-6240" @@ -61,6 +61,10 @@ "type": "WEB", "url": "https://people.redhat.com/~hkario/marvin" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240628-0002" + }, { "type": "WEB", "url": "https://securitypitfalls.wordpress.com/2023/10/16/experiment-with-side-channel-attacks-yourself" diff --git a/advisories/unreviewed/2024/04/GHSA-46wg-cm84-p5p3/GHSA-46wg-cm84-p5p3.json b/advisories/unreviewed/2024/04/GHSA-46wg-cm84-p5p3/GHSA-46wg-cm84-p5p3.json index a09065c3638..004c8bc6611 100644 --- a/advisories/unreviewed/2024/04/GHSA-46wg-cm84-p5p3/GHSA-46wg-cm84-p5p3.json +++ b/advisories/unreviewed/2024/04/GHSA-46wg-cm84-p5p3/GHSA-46wg-cm84-p5p3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-46wg-cm84-p5p3", - "modified": "2024-04-27T00:30:38Z", + "modified": "2024-06-28T18:31:42Z", "published": "2024-04-27T00:30:38Z", "aliases": [ "CVE-2024-2859" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2859" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240628-0003" + }, { "type": "WEB", "url": "https://support.broadcom.com/external/content/SecurityAdvisories/0/23245" diff --git a/advisories/unreviewed/2024/04/GHSA-9243-vfr2-5rcw/GHSA-9243-vfr2-5rcw.json b/advisories/unreviewed/2024/04/GHSA-9243-vfr2-5rcw/GHSA-9243-vfr2-5rcw.json index ccfff2d3a9a..7cd6c921469 100644 --- a/advisories/unreviewed/2024/04/GHSA-9243-vfr2-5rcw/GHSA-9243-vfr2-5rcw.json +++ b/advisories/unreviewed/2024/04/GHSA-9243-vfr2-5rcw/GHSA-9243-vfr2-5rcw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9243-vfr2-5rcw", - "modified": "2024-04-04T18:30:33Z", + "modified": "2024-06-28T18:31:42Z", "published": "2024-04-04T18:30:33Z", "aliases": [ "CVE-2023-3454" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3454" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240628-0004" + }, { "type": "WEB", "url": "https://support.broadcom.com/external/content/SecurityAdvisories/0/23215" diff --git a/advisories/unreviewed/2024/04/GHSA-mq9r-62m5-pjc2/GHSA-mq9r-62m5-pjc2.json b/advisories/unreviewed/2024/04/GHSA-mq9r-62m5-pjc2/GHSA-mq9r-62m5-pjc2.json index a0b83dee307..755d622bc04 100644 --- a/advisories/unreviewed/2024/04/GHSA-mq9r-62m5-pjc2/GHSA-mq9r-62m5-pjc2.json +++ b/advisories/unreviewed/2024/04/GHSA-mq9r-62m5-pjc2/GHSA-mq9r-62m5-pjc2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mq9r-62m5-pjc2", - "modified": "2024-04-05T03:30:28Z", + "modified": "2024-06-28T18:31:42Z", "published": "2024-04-05T03:30:28Z", "aliases": [ "CVE-2023-5973" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5973" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240628-0005" + }, { "type": "WEB", "url": "https://support.broadcom.com/external/content/SecurityAdvisories/0/23214" diff --git a/advisories/unreviewed/2024/06/GHSA-336q-x7w8-cw7q/GHSA-336q-x7w8-cw7q.json b/advisories/unreviewed/2024/06/GHSA-336q-x7w8-cw7q/GHSA-336q-x7w8-cw7q.json new file mode 100644 index 00000000000..5de60474132 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-336q-x7w8-cw7q/GHSA-336q-x7w8-cw7q.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-336q-x7w8-cw7q", + "modified": "2024-06-28T18:31:42Z", + "published": "2024-06-28T18:31:42Z", + "aliases": [ + "CVE-2024-6402" + ], + "details": "A vulnerability classified as critical was found in Tenda A301 15.13.08.12. Affected by this vulnerability is the function fromSetWirelessRepeat of the file /goform/SetOnlineDevName. The manipulation of the argument devName leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-269947. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6402" + }, + { + "type": "WEB", + "url": "https://github.com/General-Offensive/iot_vuldb/blob/main/Tenda/A301/formSetDeviceName_devName.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.269947" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.269947" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.360696" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-28T17:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-4q2x-2wp6-7jhh/GHSA-4q2x-2wp6-7jhh.json b/advisories/unreviewed/2024/06/GHSA-4q2x-2wp6-7jhh/GHSA-4q2x-2wp6-7jhh.json new file mode 100644 index 00000000000..8c74386c2b6 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-4q2x-2wp6-7jhh/GHSA-4q2x-2wp6-7jhh.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4q2x-2wp6-7jhh", + "modified": "2024-06-28T18:31:42Z", + "published": "2024-06-28T18:31:42Z", + "aliases": [ + "CVE-2024-6403" + ], + "details": "A vulnerability, which was classified as critical, has been found in Tenda A301 15.13.08.12. Affected by this issue is the function formWifiBasicSet of the file /goform/SetOnlineDevName. The manipulation of the argument devName leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-269948. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6403" + }, + { + "type": "WEB", + "url": "https://github.com/General-Offensive/iot_vuldb/blob/main/Tenda/A301/formSetDeviceName_devName.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.269948" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.269948" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.360752" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-28T17:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-4qqh-789f-3w2h/GHSA-4qqh-789f-3w2h.json b/advisories/unreviewed/2024/06/GHSA-4qqh-789f-3w2h/GHSA-4qqh-789f-3w2h.json new file mode 100644 index 00000000000..7c9e96e3af6 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-4qqh-789f-3w2h/GHSA-4qqh-789f-3w2h.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4qqh-789f-3w2h", + "modified": "2024-06-28T18:31:42Z", + "published": "2024-06-28T18:31:42Z", + "aliases": [ + "CVE-2024-31912" + ], + "details": "IBM MQ 9.3 LTS and 9.3 CD could allow an authenticated user to escalate their privileges under certain configurations due to incorrect privilege assignment. IBM X-Force ID: 289894.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31912" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/289894" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7158072" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-28T18:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-8pf8-f3wp-vf64/GHSA-8pf8-f3wp-vf64.json b/advisories/unreviewed/2024/06/GHSA-8pf8-f3wp-vf64/GHSA-8pf8-f3wp-vf64.json new file mode 100644 index 00000000000..2d4a8829976 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-8pf8-f3wp-vf64/GHSA-8pf8-f3wp-vf64.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8pf8-f3wp-vf64", + "modified": "2024-06-28T18:31:42Z", + "published": "2024-06-28T18:31:42Z", + "aliases": [ + "CVE-2024-31919" + ], + "details": "IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS and 9.3 CD, in certain configurations, is vulnerable to a denial of service attack caused by an error processing messages when an API Exit using MQBUFMH is used. IBM X-Force ID: 290259.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31919" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/290259" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7157979" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-770" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-28T18:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-hmmx-2r82-7fgw/GHSA-hmmx-2r82-7fgw.json b/advisories/unreviewed/2024/06/GHSA-hmmx-2r82-7fgw/GHSA-hmmx-2r82-7fgw.json new file mode 100644 index 00000000000..56d4111ffe8 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-hmmx-2r82-7fgw/GHSA-hmmx-2r82-7fgw.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hmmx-2r82-7fgw", + "modified": "2024-06-28T18:31:42Z", + "published": "2024-06-28T18:31:42Z", + "aliases": [ + "CVE-2024-35139" + ], + "details": "IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to obtain sensitive information from the container due to incorrect default permissions. IBM X-Force ID: 292415.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35139" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/292415" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7158790" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-276" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-28T16:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-jhrr-7ggp-3gv3/GHSA-jhrr-7ggp-3gv3.json b/advisories/unreviewed/2024/06/GHSA-jhrr-7ggp-3gv3/GHSA-jhrr-7ggp-3gv3.json new file mode 100644 index 00000000000..81de628ba76 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-jhrr-7ggp-3gv3/GHSA-jhrr-7ggp-3gv3.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jhrr-7ggp-3gv3", + "modified": "2024-06-28T18:31:42Z", + "published": "2024-06-28T18:31:42Z", + "aliases": [ + "CVE-2024-35137" + ], + "details": "IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to possibly elevate their privileges due to sensitive configuration information being exposed. IBM X-Force ID: 292413.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35137" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/292413" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7158790" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-258" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-28T16:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-w9jv-g8j2-wmhm/GHSA-w9jv-g8j2-wmhm.json b/advisories/unreviewed/2024/06/GHSA-w9jv-g8j2-wmhm/GHSA-w9jv-g8j2-wmhm.json new file mode 100644 index 00000000000..8b892b48de8 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-w9jv-g8j2-wmhm/GHSA-w9jv-g8j2-wmhm.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w9jv-g8j2-wmhm", + "modified": "2024-06-28T18:31:42Z", + "published": "2024-06-28T18:31:42Z", + "aliases": [ + "CVE-2024-35155" + ], + "details": "IBM MQ Console 9.3 LTS and 9.3 CD could disclose could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 292765.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35155" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/292765" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7158059" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-209" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-28T18:15:04Z" + } +} \ No newline at end of file