diff --git a/advisories/github-reviewed/2018/06/GHSA-pr3h-jjhj-573x/GHSA-pr3h-jjhj-573x.json b/advisories/github-reviewed/2018/06/GHSA-pr3h-jjhj-573x/GHSA-pr3h-jjhj-573x.json index 4de72ddd2bc..5266b136f32 100644 --- a/advisories/github-reviewed/2018/06/GHSA-pr3h-jjhj-573x/GHSA-pr3h-jjhj-573x.json +++ b/advisories/github-reviewed/2018/06/GHSA-pr3h-jjhj-573x/GHSA-pr3h-jjhj-573x.json @@ -109,10 +109,6 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2018:2745" }, - { - "type": "ADVISORY", - "url": "https://github.com/advisories/GHSA-pr3h-jjhj-573x" - }, { "type": "PACKAGE", "url": "https://github.com/rails/sprockets" diff --git a/advisories/github-reviewed/2018/09/GHSA-pj7m-g53m-7638/GHSA-pj7m-g53m-7638.json b/advisories/github-reviewed/2018/09/GHSA-pj7m-g53m-7638/GHSA-pj7m-g53m-7638.json index d43272dc052..03e44f94822 100644 --- a/advisories/github-reviewed/2018/09/GHSA-pj7m-g53m-7638/GHSA-pj7m-g53m-7638.json +++ b/advisories/github-reviewed/2018/09/GHSA-pj7m-g53m-7638/GHSA-pj7m-g53m-7638.json @@ -1,12 +1,12 @@ { "schema_version": "1.3.0", "id": "GHSA-pj7m-g53m-7638", - "modified": "2021-06-15T16:33:23Z", + "modified": "2023-01-23T21:30:26Z", "published": "2018-09-13T15:49:56Z", "aliases": [ "CVE-2018-14041" ], - "summary": "Moderate severity vulnerability that affects bootstrap", + "summary": "Bootstrap Cross-site Scripting vulnerability", "details": "In Bootstrap before 4.1.2, XSS is possible in the data-target property of scrollspy. This is similar to CVE-2018-14042.", "severity": [ { @@ -80,8 +80,8 @@ "url": "https://blog.getbootstrap.com/2018/07/12/bootstrap-4-1-2/" }, { - "type": "ADVISORY", - "url": "https://github.com/advisories/GHSA-pj7m-g53m-7638" + "type": "PACKAGE", + "url": "https://github.com/twbs/bootstrap" }, { "type": "WEB", diff --git a/advisories/github-reviewed/2019/01/GHSA-ph58-4vrj-w6hr/GHSA-ph58-4vrj-w6hr.json b/advisories/github-reviewed/2019/01/GHSA-ph58-4vrj-w6hr/GHSA-ph58-4vrj-w6hr.json index 7baba3b3cce..2ca115ab2d8 100644 --- a/advisories/github-reviewed/2019/01/GHSA-ph58-4vrj-w6hr/GHSA-ph58-4vrj-w6hr.json +++ b/advisories/github-reviewed/2019/01/GHSA-ph58-4vrj-w6hr/GHSA-ph58-4vrj-w6hr.json @@ -1,12 +1,12 @@ { "schema_version": "1.3.0", "id": "GHSA-ph58-4vrj-w6hr", - "modified": "2021-07-26T21:49:18Z", + "modified": "2023-01-23T21:29:22Z", "published": "2019-01-17T13:57:56Z", "aliases": [ "CVE-2018-20677" ], - "summary": "XSS vulnerability that affects bootstrap", + "summary": "bootstrap Cross-site Scripting vulnerability", "details": "In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property.", "severity": [ { @@ -85,8 +85,8 @@ "url": "https://blog.getbootstrap.com/2018/12/13/bootstrap-3-4-0/" }, { - "type": "ADVISORY", - "url": "https://github.com/advisories/GHSA-ph58-4vrj-w6hr" + "type": "PACKAGE", + "url": "https://github.com/twbs/bootstrap" }, { "type": "WEB", diff --git a/advisories/unreviewed/2022/05/GHSA-vqxq-jmxf-f53r/GHSA-vqxq-jmxf-f53r.json b/advisories/unreviewed/2022/05/GHSA-vqxq-jmxf-f53r/GHSA-vqxq-jmxf-f53r.json index 76a1bd83219..7f383349227 100644 --- a/advisories/unreviewed/2022/05/GHSA-vqxq-jmxf-f53r/GHSA-vqxq-jmxf-f53r.json +++ b/advisories/unreviewed/2022/05/GHSA-vqxq-jmxf-f53r/GHSA-vqxq-jmxf-f53r.json @@ -1,7 +1,7 @@ { "schema_version": "1.3.0", "id": "GHSA-vqxq-jmxf-f53r", - "modified": "2022-05-14T01:44:07Z", + "modified": "2023-01-23T21:30:26Z", "published": "2022-05-14T01:44:07Z", "aliases": [ "CVE-2018-18439" diff --git a/advisories/unreviewed/2022/09/GHSA-qc3c-r429-gpgf/GHSA-qc3c-r429-gpgf.json b/advisories/unreviewed/2022/09/GHSA-qc3c-r429-gpgf/GHSA-qc3c-r429-gpgf.json index 195a9e2ebda..5cc2f453df6 100644 --- a/advisories/unreviewed/2022/09/GHSA-qc3c-r429-gpgf/GHSA-qc3c-r429-gpgf.json +++ b/advisories/unreviewed/2022/09/GHSA-qc3c-r429-gpgf/GHSA-qc3c-r429-gpgf.json @@ -1,7 +1,7 @@ { "schema_version": "1.3.0", "id": "GHSA-qc3c-r429-gpgf", - "modified": "2022-09-30T00:00:43Z", + "modified": "2023-01-23T21:30:25Z", "published": "2022-09-25T00:00:26Z", "aliases": [ "CVE-2022-35252" @@ -32,6 +32,14 @@ { "type": "WEB", "url": "https://security.netapp.com/advisory/ntap-20220930-0005/" + }, + { + "type": "WEB", + "url": "https://support.apple.com/kb/HT213603" + }, + { + "type": "WEB", + "url": "https://support.apple.com/kb/HT213604" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/10/GHSA-6295-5j29-3cc8/GHSA-6295-5j29-3cc8.json b/advisories/unreviewed/2022/10/GHSA-6295-5j29-3cc8/GHSA-6295-5j29-3cc8.json index ba892fe4328..8e84bd88e29 100644 --- a/advisories/unreviewed/2022/10/GHSA-6295-5j29-3cc8/GHSA-6295-5j29-3cc8.json +++ b/advisories/unreviewed/2022/10/GHSA-6295-5j29-3cc8/GHSA-6295-5j29-3cc8.json @@ -1,7 +1,7 @@ { "schema_version": "1.3.0", "id": "GHSA-6295-5j29-3cc8", - "modified": "2022-11-01T19:00:32Z", + "modified": "2023-01-23T21:30:25Z", "published": "2022-10-29T12:00:31Z", "aliases": [ "CVE-2022-42916" @@ -45,6 +45,14 @@ "type": "WEB", "url": "https://security.netapp.com/advisory/ntap-20221209-0010/" }, + { + "type": "WEB", + "url": "https://support.apple.com/kb/HT213604" + }, + { + "type": "WEB", + "url": "https://support.apple.com/kb/HT213605" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2022/12/21/1" diff --git a/advisories/unreviewed/2022/10/GHSA-98w6-hw73-ph8m/GHSA-98w6-hw73-ph8m.json b/advisories/unreviewed/2022/10/GHSA-98w6-hw73-ph8m/GHSA-98w6-hw73-ph8m.json index bb65e00c311..5fe5ab58824 100644 --- a/advisories/unreviewed/2022/10/GHSA-98w6-hw73-ph8m/GHSA-98w6-hw73-ph8m.json +++ b/advisories/unreviewed/2022/10/GHSA-98w6-hw73-ph8m/GHSA-98w6-hw73-ph8m.json @@ -1,7 +1,7 @@ { "schema_version": "1.3.0", "id": "GHSA-98w6-hw73-ph8m", - "modified": "2022-11-01T12:00:37Z", + "modified": "2023-01-23T21:30:25Z", "published": "2022-10-30T12:00:28Z", "aliases": [ "CVE-2022-42915" @@ -44,6 +44,14 @@ { "type": "WEB", "url": "https://security.netapp.com/advisory/ntap-20221209-0010/" + }, + { + "type": "WEB", + "url": "https://support.apple.com/kb/HT213604" + }, + { + "type": "WEB", + "url": "https://support.apple.com/kb/HT213605" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/10/GHSA-vwcr-hcq5-36jr/GHSA-vwcr-hcq5-36jr.json b/advisories/unreviewed/2022/10/GHSA-vwcr-hcq5-36jr/GHSA-vwcr-hcq5-36jr.json index ac49929bbcf..a0f8b9e47e6 100644 --- a/advisories/unreviewed/2022/10/GHSA-vwcr-hcq5-36jr/GHSA-vwcr-hcq5-36jr.json +++ b/advisories/unreviewed/2022/10/GHSA-vwcr-hcq5-36jr/GHSA-vwcr-hcq5-36jr.json @@ -1,7 +1,7 @@ { "schema_version": "1.3.0", "id": "GHSA-vwcr-hcq5-36jr", - "modified": "2022-10-28T19:00:34Z", + "modified": "2023-01-23T21:30:25Z", "published": "2022-10-27T12:00:27Z", "aliases": [ "CVE-2022-3705" @@ -45,6 +45,10 @@ "type": "WEB", "url": "https://security.netapp.com/advisory/ntap-20221223-0004/" }, + { + "type": "WEB", + "url": "https://support.apple.com/kb/HT213605" + }, { "type": "WEB", "url": "https://vuldb.com/?id.212324" diff --git a/advisories/unreviewed/2022/11/GHSA-4385-m364-47g5/GHSA-4385-m364-47g5.json b/advisories/unreviewed/2022/11/GHSA-4385-m364-47g5/GHSA-4385-m364-47g5.json index 1a13465c3ac..2addfbd737e 100644 --- a/advisories/unreviewed/2022/11/GHSA-4385-m364-47g5/GHSA-4385-m364-47g5.json +++ b/advisories/unreviewed/2022/11/GHSA-4385-m364-47g5/GHSA-4385-m364-47g5.json @@ -1,7 +1,7 @@ { "schema_version": "1.3.0", "id": "GHSA-4385-m364-47g5", - "modified": "2022-11-02T19:00:28Z", + "modified": "2023-01-23T21:30:25Z", "published": "2022-11-02T12:00:41Z", "aliases": [ "CVE-2022-32915" @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://support.apple.com/en-us/HT213488" + }, + { + "type": "WEB", + "url": "https://support.apple.com/kb/HT213604" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/12/GHSA-grfr-78m7-q35q/GHSA-grfr-78m7-q35q.json b/advisories/unreviewed/2022/12/GHSA-grfr-78m7-q35q/GHSA-grfr-78m7-q35q.json index a1b1a90025a..2cff6934923 100644 --- a/advisories/unreviewed/2022/12/GHSA-grfr-78m7-q35q/GHSA-grfr-78m7-q35q.json +++ b/advisories/unreviewed/2022/12/GHSA-grfr-78m7-q35q/GHSA-grfr-78m7-q35q.json @@ -1,7 +1,7 @@ { "schema_version": "1.3.0", "id": "GHSA-grfr-78m7-q35q", - "modified": "2022-12-08T15:30:24Z", + "modified": "2023-01-23T21:30:25Z", "published": "2022-12-06T00:30:16Z", "aliases": [ "CVE-2022-32221" @@ -32,6 +32,14 @@ { "type": "WEB", "url": "https://security.netapp.com/advisory/ntap-20230110-0006/" + }, + { + "type": "WEB", + "url": "https://support.apple.com/kb/HT213604" + }, + { + "type": "WEB", + "url": "https://support.apple.com/kb/HT213605" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/12/GHSA-pv52-98qj-pq55/GHSA-pv52-98qj-pq55.json b/advisories/unreviewed/2022/12/GHSA-pv52-98qj-pq55/GHSA-pv52-98qj-pq55.json index 45db6aa5794..3f860c0d353 100644 --- a/advisories/unreviewed/2022/12/GHSA-pv52-98qj-pq55/GHSA-pv52-98qj-pq55.json +++ b/advisories/unreviewed/2022/12/GHSA-pv52-98qj-pq55/GHSA-pv52-98qj-pq55.json @@ -1,7 +1,7 @@ { "schema_version": "1.3.0", "id": "GHSA-pv52-98qj-pq55", - "modified": "2022-12-07T15:30:29Z", + "modified": "2023-01-23T21:30:25Z", "published": "2022-12-06T00:30:16Z", "aliases": [ "CVE-2022-35260" @@ -32,6 +32,14 @@ { "type": "WEB", "url": "https://security.netapp.com/advisory/ntap-20230110-0006/" + }, + { + "type": "WEB", + "url": "https://support.apple.com/kb/HT213604" + }, + { + "type": "WEB", + "url": "https://support.apple.com/kb/HT213605" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/01/GHSA-23mc-xgfj-48f2/GHSA-23mc-xgfj-48f2.json b/advisories/unreviewed/2023/01/GHSA-23mc-xgfj-48f2/GHSA-23mc-xgfj-48f2.json index 6b60cde7cad..ababba1aef9 100644 --- a/advisories/unreviewed/2023/01/GHSA-23mc-xgfj-48f2/GHSA-23mc-xgfj-48f2.json +++ b/advisories/unreviewed/2023/01/GHSA-23mc-xgfj-48f2/GHSA-23mc-xgfj-48f2.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-23mc-xgfj-48f2", - "modified": "2023-01-14T03:30:22Z", + "modified": "2023-01-23T21:30:25Z", "published": "2023-01-14T03:30:22Z", "aliases": [ "CVE-2023-22853" ], "details": "Tiki before 24.1, when feature_create_webhelp is enabled, allows lib/structures/structlib.php PHP Object Injection because of an eval.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/01/GHSA-2m7g-9m2h-fmjg/GHSA-2m7g-9m2h-fmjg.json b/advisories/unreviewed/2023/01/GHSA-2m7g-9m2h-fmjg/GHSA-2m7g-9m2h-fmjg.json index 846cc81b770..0fd17da9079 100644 --- a/advisories/unreviewed/2023/01/GHSA-2m7g-9m2h-fmjg/GHSA-2m7g-9m2h-fmjg.json +++ b/advisories/unreviewed/2023/01/GHSA-2m7g-9m2h-fmjg/GHSA-2m7g-9m2h-fmjg.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-2m7g-9m2h-fmjg", - "modified": "2023-01-17T18:30:44Z", + "modified": "2023-01-23T21:30:25Z", "published": "2023-01-17T18:30:44Z", "aliases": [ "CVE-2023-0337" ], "details": "Cross-site Scripting (XSS) - Reflected in GitHub repository lirantal/daloradius prior to master-branch.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/01/GHSA-2q53-9vqw-6g35/GHSA-2q53-9vqw-6g35.json b/advisories/unreviewed/2023/01/GHSA-2q53-9vqw-6g35/GHSA-2q53-9vqw-6g35.json index 34afe91c1dd..6bb7b8242f8 100644 --- a/advisories/unreviewed/2023/01/GHSA-2q53-9vqw-6g35/GHSA-2q53-9vqw-6g35.json +++ b/advisories/unreviewed/2023/01/GHSA-2q53-9vqw-6g35/GHSA-2q53-9vqw-6g35.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-2q53-9vqw-6g35", - "modified": "2023-01-13T18:30:17Z", + "modified": "2023-01-23T21:30:26Z", "published": "2023-01-13T18:30:17Z", "aliases": [ "CVE-2023-0221" ], "details": "Product security bypass vulnerability in ACC prior to version 8.3.4 allows a locally logged-in attacker with administrator privileges to bypass the execution controls provided by ACC using the utilman program.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/01/GHSA-326f-jv9v-g2jj/GHSA-326f-jv9v-g2jj.json b/advisories/unreviewed/2023/01/GHSA-326f-jv9v-g2jj/GHSA-326f-jv9v-g2jj.json index 1a52963382b..9e70ae3dcf6 100644 --- a/advisories/unreviewed/2023/01/GHSA-326f-jv9v-g2jj/GHSA-326f-jv9v-g2jj.json +++ b/advisories/unreviewed/2023/01/GHSA-326f-jv9v-g2jj/GHSA-326f-jv9v-g2jj.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-326f-jv9v-g2jj", - "modified": "2023-01-13T06:30:24Z", + "modified": "2023-01-23T21:30:26Z", "published": "2023-01-13T06:30:24Z", "aliases": [ "CVE-2022-42288" ], "details": "NVIDIA BMC contains a vulnerability in IPMI handler, where an unauthorized attacker can use certain oracles to guess a valid BMC username, which may lead to an information disclosure.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-203" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/01/GHSA-445m-q5mj-2gj6/GHSA-445m-q5mj-2gj6.json b/advisories/unreviewed/2023/01/GHSA-445m-q5mj-2gj6/GHSA-445m-q5mj-2gj6.json index bb4c3533d6f..3909392aa3f 100644 --- a/advisories/unreviewed/2023/01/GHSA-445m-q5mj-2gj6/GHSA-445m-q5mj-2gj6.json +++ b/advisories/unreviewed/2023/01/GHSA-445m-q5mj-2gj6/GHSA-445m-q5mj-2gj6.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-445m-q5mj-2gj6", - "modified": "2023-01-13T03:30:18Z", + "modified": "2023-01-23T21:30:26Z", "published": "2023-01-13T03:30:18Z", "aliases": [ "CVE-2022-48258" ], "details": "In Eternal Terminal 6.2.1, etserver and etclient have world-readable logfiles.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/01/GHSA-55rv-pc53-r9qq/GHSA-55rv-pc53-r9qq.json b/advisories/unreviewed/2023/01/GHSA-55rv-pc53-r9qq/GHSA-55rv-pc53-r9qq.json index dd902dba0bc..6d46e03b36c 100644 --- a/advisories/unreviewed/2023/01/GHSA-55rv-pc53-r9qq/GHSA-55rv-pc53-r9qq.json +++ b/advisories/unreviewed/2023/01/GHSA-55rv-pc53-r9qq/GHSA-55rv-pc53-r9qq.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-55rv-pc53-r9qq", - "modified": "2023-01-17T18:30:44Z", + "modified": "2023-01-23T21:30:25Z", "published": "2023-01-17T18:30:44Z", "aliases": [ "CVE-2023-0338" ], "details": "Cross-site Scripting (XSS) - Reflected in GitHub repository lirantal/daloradius prior to master-branch.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/01/GHSA-56x3-c65v-wgm6/GHSA-56x3-c65v-wgm6.json b/advisories/unreviewed/2023/01/GHSA-56x3-c65v-wgm6/GHSA-56x3-c65v-wgm6.json index 0b24f07eb4f..bd5a349c37f 100644 --- a/advisories/unreviewed/2023/01/GHSA-56x3-c65v-wgm6/GHSA-56x3-c65v-wgm6.json +++ b/advisories/unreviewed/2023/01/GHSA-56x3-c65v-wgm6/GHSA-56x3-c65v-wgm6.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-56x3-c65v-wgm6", - "modified": "2023-01-13T21:30:26Z", + "modified": "2023-01-23T21:30:26Z", "published": "2023-01-13T21:30:26Z", "aliases": [ "CVE-2017-20169" ], "details": "A vulnerability, which was classified as critical, has been found in GGGGGGGG ToN-MasterServer. Affected by this issue is some unknown functionality of the file public_html/irc_updater/svr_request_pub.php. The manipulation leads to sql injection. The name of the patch is 3a4c7e6d51bf95760820e3245e06c6e321a7168a. It is recommended to apply a patch to fix this issue. VDB-218306 is the identifier assigned to this vulnerability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/01/GHSA-58r3-74qh-jvw5/GHSA-58r3-74qh-jvw5.json b/advisories/unreviewed/2023/01/GHSA-58r3-74qh-jvw5/GHSA-58r3-74qh-jvw5.json index e219b0e29d5..9ec824faeec 100644 --- a/advisories/unreviewed/2023/01/GHSA-58r3-74qh-jvw5/GHSA-58r3-74qh-jvw5.json +++ b/advisories/unreviewed/2023/01/GHSA-58r3-74qh-jvw5/GHSA-58r3-74qh-jvw5.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-58r3-74qh-jvw5", - "modified": "2023-01-14T03:30:22Z", + "modified": "2023-01-23T21:30:25Z", "published": "2023-01-14T03:30:22Z", "aliases": [ "CVE-2023-22852" ], "details": "Tiki through 25.0 allows CSRF attacks that are related to tiki-importer.php and tiki-import_sheet.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/01/GHSA-5r4m-496r-7wqm/GHSA-5r4m-496r-7wqm.json b/advisories/unreviewed/2023/01/GHSA-5r4m-496r-7wqm/GHSA-5r4m-496r-7wqm.json index adb81000fbd..a518f5dd3eb 100644 --- a/advisories/unreviewed/2023/01/GHSA-5r4m-496r-7wqm/GHSA-5r4m-496r-7wqm.json +++ b/advisories/unreviewed/2023/01/GHSA-5r4m-496r-7wqm/GHSA-5r4m-496r-7wqm.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-5r4m-496r-7wqm", - "modified": "2023-01-17T18:30:43Z", + "modified": "2023-01-23T21:30:26Z", "published": "2023-01-17T18:30:43Z", "aliases": [ "CVE-2022-41858" ], "details": "A flaw was found in the Linux kernel. A NULL pointer dereference may occur while a slip driver is in progress to detach in sl_tx_timeout in drivers/net/slip/slip.c. This issue could allow an attacker to crash the system or leak internal kernel information.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/01/GHSA-6fm4-9v93-v7gg/GHSA-6fm4-9v93-v7gg.json b/advisories/unreviewed/2023/01/GHSA-6fm4-9v93-v7gg/GHSA-6fm4-9v93-v7gg.json index e87c1ed5db7..969179b603b 100644 --- a/advisories/unreviewed/2023/01/GHSA-6fm4-9v93-v7gg/GHSA-6fm4-9v93-v7gg.json +++ b/advisories/unreviewed/2023/01/GHSA-6fm4-9v93-v7gg/GHSA-6fm4-9v93-v7gg.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-6fm4-9v93-v7gg", - "modified": "2023-01-13T06:30:22Z", + "modified": "2023-01-23T21:30:24Z", "published": "2023-01-13T06:30:22Z", "aliases": [ "CVE-2021-46872" ], "details": "An issue was discovered in Nim before 1.6.2. The RST module of the Nim language stdlib, as used in NimForum and other products, permits the javascript: URI scheme and thus can lead to XSS in some applications. (Nim versions 1.6.2 and later are fixed; there may be backports of the fix to some earlier versions. NimForum 2.2.0 is fixed.)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/01/GHSA-73jp-p4j5-5wmx/GHSA-73jp-p4j5-5wmx.json b/advisories/unreviewed/2023/01/GHSA-73jp-p4j5-5wmx/GHSA-73jp-p4j5-5wmx.json index e289544183e..ed79076f8cd 100644 --- a/advisories/unreviewed/2023/01/GHSA-73jp-p4j5-5wmx/GHSA-73jp-p4j5-5wmx.json +++ b/advisories/unreviewed/2023/01/GHSA-73jp-p4j5-5wmx/GHSA-73jp-p4j5-5wmx.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-73jp-p4j5-5wmx", - "modified": "2023-01-17T18:30:43Z", + "modified": "2023-01-23T21:30:26Z", "published": "2023-01-17T18:30:43Z", "aliases": [ "CVE-2022-4121" ], "details": "In libetpan a null pointer dereference in mailimap_mailbox_data_status_free in low-level/imap/mailimap_types.c was found that could lead to a remote denial of service or other potential consequences.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/01/GHSA-7p2f-9vw3-7j56/GHSA-7p2f-9vw3-7j56.json b/advisories/unreviewed/2023/01/GHSA-7p2f-9vw3-7j56/GHSA-7p2f-9vw3-7j56.json index 2e9a26090e5..dbf782fce60 100644 --- a/advisories/unreviewed/2023/01/GHSA-7p2f-9vw3-7j56/GHSA-7p2f-9vw3-7j56.json +++ b/advisories/unreviewed/2023/01/GHSA-7p2f-9vw3-7j56/GHSA-7p2f-9vw3-7j56.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-7p2f-9vw3-7j56", - "modified": "2023-01-17T21:30:22Z", + "modified": "2023-01-23T21:30:26Z", "published": "2023-01-17T21:30:22Z", "aliases": [ "CVE-2023-22624" ], "details": "Zoho ManageEngine Exchange Reporter Plus before 5708 allows attackers to conduct XXE attacks.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-611" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/01/GHSA-7pcg-jp63-83f5/GHSA-7pcg-jp63-83f5.json b/advisories/unreviewed/2023/01/GHSA-7pcg-jp63-83f5/GHSA-7pcg-jp63-83f5.json index 361e9eb1c37..f333a2e3e44 100644 --- a/advisories/unreviewed/2023/01/GHSA-7pcg-jp63-83f5/GHSA-7pcg-jp63-83f5.json +++ b/advisories/unreviewed/2023/01/GHSA-7pcg-jp63-83f5/GHSA-7pcg-jp63-83f5.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-7pcg-jp63-83f5", - "modified": "2023-01-13T03:30:19Z", + "modified": "2023-01-23T21:30:26Z", "published": "2023-01-13T03:30:19Z", "aliases": [ "CVE-2022-3160" ], "details": "The APDFL.dll contains an out-of-bounds write past the fixed-length heap-based buffer while parsing specially crafted PDF files. This could allow an attacker to execute code in the context of the current process.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,10 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/01/GHSA-7rw7-m7rf-3h77/GHSA-7rw7-m7rf-3h77.json b/advisories/unreviewed/2023/01/GHSA-7rw7-m7rf-3h77/GHSA-7rw7-m7rf-3h77.json index 8de9ecd9b26..3e29fbac844 100644 --- a/advisories/unreviewed/2023/01/GHSA-7rw7-m7rf-3h77/GHSA-7rw7-m7rf-3h77.json +++ b/advisories/unreviewed/2023/01/GHSA-7rw7-m7rf-3h77/GHSA-7rw7-m7rf-3h77.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-7rw7-m7rf-3h77", - "modified": "2023-01-13T00:30:38Z", + "modified": "2023-01-23T21:30:26Z", "published": "2023-01-13T00:30:38Z", "aliases": [ "CVE-2022-42704" ], "details": "A cross-site scripting (XSS) vulnerability in Employee Service Center (esc) and Service Portal (sp) in ServiceNow Quebec, Rome, and San Diego allows remote attackers to inject arbitrary web script via the Standard Ticket Conversations widget.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/01/GHSA-7rxf-234p-2f7w/GHSA-7rxf-234p-2f7w.json b/advisories/unreviewed/2023/01/GHSA-7rxf-234p-2f7w/GHSA-7rxf-234p-2f7w.json index 023353c1b13..b92f8183388 100644 --- a/advisories/unreviewed/2023/01/GHSA-7rxf-234p-2f7w/GHSA-7rxf-234p-2f7w.json +++ b/advisories/unreviewed/2023/01/GHSA-7rxf-234p-2f7w/GHSA-7rxf-234p-2f7w.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-7rxf-234p-2f7w", - "modified": "2023-01-13T18:30:16Z", + "modified": "2023-01-23T21:30:26Z", "published": "2023-01-13T18:30:16Z", "aliases": [ "CVE-2009-10001" ], "details": "A vulnerability classified as problematic was found in jianlinwei cool-php-captcha up to 0.2. This vulnerability affects unknown code of the file example-form.php. The manipulation of the argument captcha with the input %3Cscript%3Ealert(1)%3C/script%3E leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 0.3 is able to address this issue. The name of the patch is c84fb6b153bebaf228feee0cbf50728d27ae3f80. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-218296.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -43,7 +46,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/01/GHSA-9526-g73c-89rr/GHSA-9526-g73c-89rr.json b/advisories/unreviewed/2023/01/GHSA-9526-g73c-89rr/GHSA-9526-g73c-89rr.json index c634d7a63ec..a7021786e8f 100644 --- a/advisories/unreviewed/2023/01/GHSA-9526-g73c-89rr/GHSA-9526-g73c-89rr.json +++ b/advisories/unreviewed/2023/01/GHSA-9526-g73c-89rr/GHSA-9526-g73c-89rr.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-9526-g73c-89rr", - "modified": "2023-01-13T03:30:18Z", + "modified": "2023-01-23T21:30:26Z", "published": "2023-01-13T03:30:18Z", "aliases": [ "CVE-2022-48257" ], "details": "In Eternal Terminal 6.2.1, etserver and etclient have predictable logfile names in /tmp.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/01/GHSA-96f5-4j7x-gc4x/GHSA-96f5-4j7x-gc4x.json b/advisories/unreviewed/2023/01/GHSA-96f5-4j7x-gc4x/GHSA-96f5-4j7x-gc4x.json index a8994f2bdaa..f76dbd60cfe 100644 --- a/advisories/unreviewed/2023/01/GHSA-96f5-4j7x-gc4x/GHSA-96f5-4j7x-gc4x.json +++ b/advisories/unreviewed/2023/01/GHSA-96f5-4j7x-gc4x/GHSA-96f5-4j7x-gc4x.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-96f5-4j7x-gc4x", - "modified": "2023-01-17T18:30:43Z", + "modified": "2023-01-23T21:30:26Z", "published": "2023-01-17T18:30:43Z", "aliases": [ "CVE-2022-3091" ], "details": "RONDS EPM version 1.19.5 has a vulnerability in which a function could allow unauthenticated users to leak credentials. In some circumstances, an attacker can exploit this vulnerability to execute operating system (OS) commands.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-200" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/01/GHSA-9rx4-v8w3-r8ff/GHSA-9rx4-v8w3-r8ff.json b/advisories/unreviewed/2023/01/GHSA-9rx4-v8w3-r8ff/GHSA-9rx4-v8w3-r8ff.json index 6276f325cbe..aa79ce1d84b 100644 --- a/advisories/unreviewed/2023/01/GHSA-9rx4-v8w3-r8ff/GHSA-9rx4-v8w3-r8ff.json +++ b/advisories/unreviewed/2023/01/GHSA-9rx4-v8w3-r8ff/GHSA-9rx4-v8w3-r8ff.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-9rx4-v8w3-r8ff", - "modified": "2023-01-17T21:30:21Z", + "modified": "2023-01-23T21:30:26Z", "published": "2023-01-17T21:30:21Z", "aliases": [ "CVE-2022-46475" ], "details": "D-Link DIR 645A1 1.06B01_Beta01 was discovered to contain a stack overflow via the service= variable in the genacgi_main function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/01/GHSA-chp6-wqp3-f3gg/GHSA-chp6-wqp3-f3gg.json b/advisories/unreviewed/2023/01/GHSA-chp6-wqp3-f3gg/GHSA-chp6-wqp3-f3gg.json index b777503e76a..4655a9aeb52 100644 --- a/advisories/unreviewed/2023/01/GHSA-chp6-wqp3-f3gg/GHSA-chp6-wqp3-f3gg.json +++ b/advisories/unreviewed/2023/01/GHSA-chp6-wqp3-f3gg/GHSA-chp6-wqp3-f3gg.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-chp6-wqp3-f3gg", - "modified": "2023-01-17T21:30:21Z", + "modified": "2023-01-23T21:30:26Z", "published": "2023-01-17T21:30:21Z", "aliases": [ "CVE-2023-0122" ], "details": "A NULL pointer dereference vulnerability in the Linux kernel NVMe functionality, in nvmet_setup_auth(), allows an attacker to perform a Pre-Auth Denial of Service (DoS) attack on a remote machine. Affected versions v6.0-rc1 to v6.0-rc3, fixed in v6.0-rc4.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-476" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/01/GHSA-cmq9-w454-24mf/GHSA-cmq9-w454-24mf.json b/advisories/unreviewed/2023/01/GHSA-cmq9-w454-24mf/GHSA-cmq9-w454-24mf.json index 0c80fa24fd3..b81c376c229 100644 --- a/advisories/unreviewed/2023/01/GHSA-cmq9-w454-24mf/GHSA-cmq9-w454-24mf.json +++ b/advisories/unreviewed/2023/01/GHSA-cmq9-w454-24mf/GHSA-cmq9-w454-24mf.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-cmq9-w454-24mf", - "modified": "2023-01-17T21:30:21Z", + "modified": "2023-01-23T21:30:26Z", "published": "2023-01-17T21:30:21Z", "aliases": [ "CVE-2022-47929" ], "details": "In the Linux kernel before 6.1.6, a NULL pointer dereference bug in the traffic control subsystem allows an unprivileged user to trigger a denial of service (system crash) via a crafted traffic control configuration that is set up with \"tc qdisc\" and \"tc class\" commands. This affects qdisc_graft in net/sched/sch_api.c.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/01/GHSA-fj75-7hqx-qp2c/GHSA-fj75-7hqx-qp2c.json b/advisories/unreviewed/2023/01/GHSA-fj75-7hqx-qp2c/GHSA-fj75-7hqx-qp2c.json new file mode 100644 index 00000000000..7e2bb79b139 --- /dev/null +++ b/advisories/unreviewed/2023/01/GHSA-fj75-7hqx-qp2c/GHSA-fj75-7hqx-qp2c.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-fj75-7hqx-qp2c", + "modified": "2023-01-23T21:30:24Z", + "published": "2023-01-23T21:30:24Z", + "aliases": [ + "CVE-2023-23560" + ], + "details": "In certain Lexmark products through 2023-01-12, SSRF can occur because of a lack of input validation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23560" + }, + { + "type": "WEB", + "url": "https://publications.lexmark.com/publications/security-alerts/CVE-2023-23560.pdf" + }, + { + "type": "WEB", + "url": "https://support.lexmark.com/alerts/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/01/GHSA-fx39-w9qr-mppw/GHSA-fx39-w9qr-mppw.json b/advisories/unreviewed/2023/01/GHSA-fx39-w9qr-mppw/GHSA-fx39-w9qr-mppw.json index 9adc841a9b4..75df8038a69 100644 --- a/advisories/unreviewed/2023/01/GHSA-fx39-w9qr-mppw/GHSA-fx39-w9qr-mppw.json +++ b/advisories/unreviewed/2023/01/GHSA-fx39-w9qr-mppw/GHSA-fx39-w9qr-mppw.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-fx39-w9qr-mppw", - "modified": "2023-01-13T21:30:26Z", + "modified": "2023-01-23T21:30:25Z", "published": "2023-01-13T21:30:26Z", "aliases": [ "CVE-2015-10042" ], "details": "** UNSUPPPORTED WHEN ASSIGNED **** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical was found in Dovgalyuk AIBattle. Affected by this vulnerability is the function registerUser of the file site/procedures.php. The manipulation of the argument postLogin leads to sql injection. The name of the patch is 448e9880aac18ae7832f8d065e03e46ce0f1d3e3. It is recommended to apply a patch to fix this issue. The identifier VDB-218305 was assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/01/GHSA-g64c-rxmq-vwm7/GHSA-g64c-rxmq-vwm7.json b/advisories/unreviewed/2023/01/GHSA-g64c-rxmq-vwm7/GHSA-g64c-rxmq-vwm7.json index 13642a5d233..2b7661362b5 100644 --- a/advisories/unreviewed/2023/01/GHSA-g64c-rxmq-vwm7/GHSA-g64c-rxmq-vwm7.json +++ b/advisories/unreviewed/2023/01/GHSA-g64c-rxmq-vwm7/GHSA-g64c-rxmq-vwm7.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-g64c-rxmq-vwm7", - "modified": "2023-01-17T21:30:22Z", + "modified": "2023-01-23T21:30:26Z", "published": "2023-01-17T21:30:22Z", "aliases": [ "CVE-2015-10063" ], "details": "A vulnerability was found in saemorris TheRadSystem and classified as critical. This issue affects the function redirect of the file _login.php. The manipulation of the argument user/pass leads to sql injection. The attack may be initiated remotely. The name of the patch is bfba26bd34af31648a11af35a0bb66f1948752a6. It is recommended to apply a patch to fix this issue. The identifier VDB-218453 was assigned to this vulnerability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/01/GHSA-gf4p-9cqm-vwpj/GHSA-gf4p-9cqm-vwpj.json b/advisories/unreviewed/2023/01/GHSA-gf4p-9cqm-vwpj/GHSA-gf4p-9cqm-vwpj.json index 917cc239b3e..056c29b988a 100644 --- a/advisories/unreviewed/2023/01/GHSA-gf4p-9cqm-vwpj/GHSA-gf4p-9cqm-vwpj.json +++ b/advisories/unreviewed/2023/01/GHSA-gf4p-9cqm-vwpj/GHSA-gf4p-9cqm-vwpj.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-gf4p-9cqm-vwpj", - "modified": "2023-01-13T03:30:19Z", + "modified": "2023-01-23T21:30:26Z", "published": "2023-01-13T03:30:19Z", "aliases": [ "CVE-2022-3159" ], "details": "The APDFL.dll contains a stack-based buffer overflow vulnerability that could be triggered while parsing specially crafted PDF files. This could allow an attacker to execute code in the context of the current process.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,10 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/01/GHSA-j9cj-vhg7-rwqr/GHSA-j9cj-vhg7-rwqr.json b/advisories/unreviewed/2023/01/GHSA-j9cj-vhg7-rwqr/GHSA-j9cj-vhg7-rwqr.json new file mode 100644 index 00000000000..5e699df2ef0 --- /dev/null +++ b/advisories/unreviewed/2023/01/GHSA-j9cj-vhg7-rwqr/GHSA-j9cj-vhg7-rwqr.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-j9cj-vhg7-rwqr", + "modified": "2023-01-23T21:30:25Z", + "published": "2023-01-23T21:30:25Z", + "aliases": [ + "CVE-2023-22960" + ], + "details": "Lexmark products through 2023-01-10 have Improper Control of Interaction Frequency.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22960" + }, + { + "type": "WEB", + "url": "https://publications.lexmark.com/publications/security-alerts/CVE-2023-22960.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/01/GHSA-mjh5-rrhw-qhv4/GHSA-mjh5-rrhw-qhv4.json b/advisories/unreviewed/2023/01/GHSA-mjh5-rrhw-qhv4/GHSA-mjh5-rrhw-qhv4.json index cb4f153e5c3..6e1b8da94ef 100644 --- a/advisories/unreviewed/2023/01/GHSA-mjh5-rrhw-qhv4/GHSA-mjh5-rrhw-qhv4.json +++ b/advisories/unreviewed/2023/01/GHSA-mjh5-rrhw-qhv4/GHSA-mjh5-rrhw-qhv4.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-mjh5-rrhw-qhv4", - "modified": "2023-01-13T03:30:18Z", + "modified": "2023-01-23T21:30:26Z", "published": "2023-01-13T03:30:18Z", "aliases": [ "CVE-2023-23559" ], "details": "In rndis_query_oid in drivers/net/wireless/rndis_wlan.c in the Linux kernel through 6.1.5, there is an integer overflow in an addition.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-190" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/01/GHSA-mjp7-9x9w-g68j/GHSA-mjp7-9x9w-g68j.json b/advisories/unreviewed/2023/01/GHSA-mjp7-9x9w-g68j/GHSA-mjp7-9x9w-g68j.json index af732ede3f5..8c857d68895 100644 --- a/advisories/unreviewed/2023/01/GHSA-mjp7-9x9w-g68j/GHSA-mjp7-9x9w-g68j.json +++ b/advisories/unreviewed/2023/01/GHSA-mjp7-9x9w-g68j/GHSA-mjp7-9x9w-g68j.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-mjp7-9x9w-g68j", - "modified": "2023-01-13T21:30:27Z", + "modified": "2023-01-23T21:30:26Z", "published": "2023-01-13T21:30:27Z", "aliases": [ "CVE-2023-0295" ], "details": "The Launchpad plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of its settings parameters in versions up to, and including, 1.0.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/01/GHSA-q63c-hwh7-h8pw/GHSA-q63c-hwh7-h8pw.json b/advisories/unreviewed/2023/01/GHSA-q63c-hwh7-h8pw/GHSA-q63c-hwh7-h8pw.json index 611cbef06b4..d333925af0b 100644 --- a/advisories/unreviewed/2023/01/GHSA-q63c-hwh7-h8pw/GHSA-q63c-hwh7-h8pw.json +++ b/advisories/unreviewed/2023/01/GHSA-q63c-hwh7-h8pw/GHSA-q63c-hwh7-h8pw.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-q63c-hwh7-h8pw", - "modified": "2023-01-17T18:30:43Z", + "modified": "2023-01-23T21:30:26Z", "published": "2023-01-17T18:30:43Z", "aliases": [ "CVE-2022-2893" ], "details": "RONDS EPM version 1.19.5 does not properly validate the filename parameter, which could allow an unauthorized user to specify file paths and download files.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-22" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/01/GHSA-qcvx-f4h4-vx9h/GHSA-qcvx-f4h4-vx9h.json b/advisories/unreviewed/2023/01/GHSA-qcvx-f4h4-vx9h/GHSA-qcvx-f4h4-vx9h.json index 86b131f4fec..4cbb7a23a15 100644 --- a/advisories/unreviewed/2023/01/GHSA-qcvx-f4h4-vx9h/GHSA-qcvx-f4h4-vx9h.json +++ b/advisories/unreviewed/2023/01/GHSA-qcvx-f4h4-vx9h/GHSA-qcvx-f4h4-vx9h.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-qcvx-f4h4-vx9h", - "modified": "2023-01-13T06:30:22Z", + "modified": "2023-01-23T21:30:26Z", "published": "2023-01-13T06:30:22Z", "aliases": [ "CVE-2022-42268" ], "details": "Omniverse Kit contains a vulnerability in the reference applications Create, Audio2Face, Isaac Sim, View, Code, and Machinima. These applications allow executable Python code to be embedded in Universal Scene Description (USD) files to customize all aspects of a scene. If a user opens a USD file that contains embedded Python code in one of these applications, the embedded Python code automatically runs with the privileges of the user who opened the file. As a result, an unprivileged remote attacker could craft a USD file containing malicious Python code and persuade a local user to open the file, which may lead to information disclosure, data tampering, and denial of service.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/01/GHSA-r472-pwr3-9939/GHSA-r472-pwr3-9939.json b/advisories/unreviewed/2023/01/GHSA-r472-pwr3-9939/GHSA-r472-pwr3-9939.json new file mode 100644 index 00000000000..f298fc82397 --- /dev/null +++ b/advisories/unreviewed/2023/01/GHSA-r472-pwr3-9939/GHSA-r472-pwr3-9939.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-r472-pwr3-9939", + "modified": "2023-01-23T21:30:26Z", + "published": "2023-01-23T21:30:26Z", + "aliases": [ + "CVE-2023-23824" + ], + "details": "Auth. SQL Injection (SQLi) vulnerability in WP-TopBar <= 5.36 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23824" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-topbar/wordpress-wp-topbar-plugin-5-36-sql-injection?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/01/GHSA-rc4w-f7j9-xw22/GHSA-rc4w-f7j9-xw22.json b/advisories/unreviewed/2023/01/GHSA-rc4w-f7j9-xw22/GHSA-rc4w-f7j9-xw22.json index 21c5af10bfb..e0638cbf2c2 100644 --- a/advisories/unreviewed/2023/01/GHSA-rc4w-f7j9-xw22/GHSA-rc4w-f7j9-xw22.json +++ b/advisories/unreviewed/2023/01/GHSA-rc4w-f7j9-xw22/GHSA-rc4w-f7j9-xw22.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-rc4w-f7j9-xw22", - "modified": "2023-01-13T15:30:27Z", + "modified": "2023-01-23T21:30:26Z", "published": "2023-01-13T15:30:27Z", "aliases": [ "CVE-2023-0287" ], "details": "A vulnerability was found in ityouknow favorites-web. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Comment Handler. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-218294 is the identifier assigned to this vulnerability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/01/GHSA-vj8w-gmcx-c68x/GHSA-vj8w-gmcx-c68x.json b/advisories/unreviewed/2023/01/GHSA-vj8w-gmcx-c68x/GHSA-vj8w-gmcx-c68x.json index e21ef699eaf..5a4e76f932a 100644 --- a/advisories/unreviewed/2023/01/GHSA-vj8w-gmcx-c68x/GHSA-vj8w-gmcx-c68x.json +++ b/advisories/unreviewed/2023/01/GHSA-vj8w-gmcx-c68x/GHSA-vj8w-gmcx-c68x.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-vj8w-gmcx-c68x", - "modified": "2023-01-13T18:30:17Z", + "modified": "2023-01-23T21:30:26Z", "published": "2023-01-13T18:30:17Z", "aliases": [ "CVE-2009-10002" ], "details": "A vulnerability, which was classified as problematic, has been found in dpup fittr-flickr. This issue affects some unknown processing of the file fittr-flickr/features/easy-exif.js of the component EXIF Preview Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The name of the patch is 08875dd8a2e5d0d16568bb0d67cb4328062fccde. It is recommended to apply a patch to fix this issue. The identifier VDB-218297 was assigned to this vulnerability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/01/GHSA-x3rw-7xfq-v6g9/GHSA-x3rw-7xfq-v6g9.json b/advisories/unreviewed/2023/01/GHSA-x3rw-7xfq-v6g9/GHSA-x3rw-7xfq-v6g9.json index 97d4ec2b1b9..533fb111bc8 100644 --- a/advisories/unreviewed/2023/01/GHSA-x3rw-7xfq-v6g9/GHSA-x3rw-7xfq-v6g9.json +++ b/advisories/unreviewed/2023/01/GHSA-x3rw-7xfq-v6g9/GHSA-x3rw-7xfq-v6g9.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-x3rw-7xfq-v6g9", - "modified": "2023-01-13T00:30:38Z", + "modified": "2023-01-23T21:30:26Z", "published": "2023-01-13T00:30:38Z", "aliases": [ "CVE-2023-22598" ], "details": "InHand Networks InRouter 302, prior to version IR302 V3.5.56, and InRouter 615, prior to version InRouter6XX-S-V2.3.0.r5542, contain vulnerability CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'). An unauthorized user with privileged access to the local web interface or the cloud account managing the affected devices could push a specially crafted configuration update file to gain root access. This could lead to remote code execution with root privileges.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-78" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file