From 4c94525d527df3688fe5fcbdc85cc8ec9ba3a483 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Sun, 10 Nov 2024 06:31:50 +0000 Subject: [PATCH] Publish Advisories GHSA-g9hm-qffx-jwjh GHSA-wg4p-5ghf-r8w7 GHSA-xh2w-4r3v-jgq5 --- .../GHSA-g9hm-qffx-jwjh.json | 58 +++++++++++++++++++ .../GHSA-wg4p-5ghf-r8w7.json | 54 +++++++++++++++++ .../GHSA-xh2w-4r3v-jgq5.json | 58 +++++++++++++++++++ 3 files changed, 170 insertions(+) create mode 100644 advisories/unreviewed/2024/11/GHSA-g9hm-qffx-jwjh/GHSA-g9hm-qffx-jwjh.json create mode 100644 advisories/unreviewed/2024/11/GHSA-wg4p-5ghf-r8w7/GHSA-wg4p-5ghf-r8w7.json create mode 100644 advisories/unreviewed/2024/11/GHSA-xh2w-4r3v-jgq5/GHSA-xh2w-4r3v-jgq5.json diff --git a/advisories/unreviewed/2024/11/GHSA-g9hm-qffx-jwjh/GHSA-g9hm-qffx-jwjh.json b/advisories/unreviewed/2024/11/GHSA-g9hm-qffx-jwjh/GHSA-g9hm-qffx-jwjh.json new file mode 100644 index 00000000000..6c94847122f --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-g9hm-qffx-jwjh/GHSA-g9hm-qffx-jwjh.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g9hm-qffx-jwjh", + "modified": "2024-11-10T06:30:44Z", + "published": "2024-11-10T06:30:44Z", + "aliases": [ + "CVE-2024-11047" + ], + "details": "A vulnerability was found in D-Link DI-8003 16.07.16A1. It has been declared as critical. Affected by this vulnerability is the function upgrade_filter_asp of the file /upgrade_filter.asp. The manipulation of the argument path leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11047" + }, + { + "type": "WEB", + "url": "https://github.com/theRaz0r/iot-mycve/blob/main/Dlink_DI8003_stackoverflow/Dlink_DI8003_stackoverflow.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.283633" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.283633" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.434931" + }, + { + "type": "WEB", + "url": "https://www.dlink.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-10T04:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-wg4p-5ghf-r8w7/GHSA-wg4p-5ghf-r8w7.json b/advisories/unreviewed/2024/11/GHSA-wg4p-5ghf-r8w7/GHSA-wg4p-5ghf-r8w7.json new file mode 100644 index 00000000000..d1e64766a71 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-wg4p-5ghf-r8w7/GHSA-wg4p-5ghf-r8w7.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wg4p-5ghf-r8w7", + "modified": "2024-11-10T06:30:44Z", + "published": "2024-11-10T06:30:44Z", + "aliases": [ + "CVE-2024-11049" + ], + "details": "A vulnerability classified as problematic has been found in ZKTeco ZKBio Time 9.0.1. Affected is an unknown function of the file /auth_files/photo/ of the component Image File Handler. The manipulation leads to direct request. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11049" + }, + { + "type": "WEB", + "url": "https://gist.githubusercontent.com/whiteman007/f7a85252fed91deff6eb3f20596710b0/raw/b7c8a7f53d3316cfd2da1cae9bcf583d923860b7/biotime%25209.0.1" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.283662" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.283662" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.435034" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-425" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-10T06:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-xh2w-4r3v-jgq5/GHSA-xh2w-4r3v-jgq5.json b/advisories/unreviewed/2024/11/GHSA-xh2w-4r3v-jgq5/GHSA-xh2w-4r3v-jgq5.json new file mode 100644 index 00000000000..9aaf13bf367 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-xh2w-4r3v-jgq5/GHSA-xh2w-4r3v-jgq5.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xh2w-4r3v-jgq5", + "modified": "2024-11-10T06:30:44Z", + "published": "2024-11-10T06:30:44Z", + "aliases": [ + "CVE-2024-11048" + ], + "details": "A vulnerability was found in D-Link DI-8003 16.07.16A1. It has been rated as critical. Affected by this issue is the function dbsrv_asp of the file /dbsrv.asp. The manipulation of the argument str leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11048" + }, + { + "type": "WEB", + "url": "https://github.com/theRaz0r/iot-mycve/blob/main/Dlink_DI8003_stackoverflow/Dlink-DI8003-stackoverflow-dbsrv.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.283634" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.283634" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.434936" + }, + { + "type": "WEB", + "url": "https://www.dlink.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-10T04:15:16Z" + } +} \ No newline at end of file