From 4dcc318c494c23856c31442a0b27fc4be3e03255 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Sun, 18 Feb 2024 06:31:51 +0000 Subject: [PATCH] Publish Advisories GHSA-25vc-3hfp-rp87 GHSA-45ch-2h92-cc35 GHSA-6r3r-qjm5-8fvp GHSA-c22v-83jg-hp9r GHSA-c6gq-r463-842g GHSA-cq73-wfw9-gvq8 GHSA-gqvq-6r9g-ff5p GHSA-jrx7-rgwc-w944 GHSA-pgqc-xw7p-gm9j GHSA-pj8m-c5v2-vf9w GHSA-qmxh-c3qm-vmrf GHSA-v8p7-prvv-wvf5 --- .../GHSA-25vc-3hfp-rp87.json | 39 +++++++++++++++++++ .../GHSA-45ch-2h92-cc35.json | 39 +++++++++++++++++++ .../GHSA-6r3r-qjm5-8fvp.json | 39 +++++++++++++++++++ .../GHSA-c22v-83jg-hp9r.json | 39 +++++++++++++++++++ .../GHSA-c6gq-r463-842g.json | 39 +++++++++++++++++++ .../GHSA-cq73-wfw9-gvq8.json | 39 +++++++++++++++++++ .../GHSA-gqvq-6r9g-ff5p.json | 39 +++++++++++++++++++ .../GHSA-jrx7-rgwc-w944.json | 39 +++++++++++++++++++ .../GHSA-pgqc-xw7p-gm9j.json | 39 +++++++++++++++++++ .../GHSA-pj8m-c5v2-vf9w.json | 39 +++++++++++++++++++ .../GHSA-qmxh-c3qm-vmrf.json | 39 +++++++++++++++++++ .../GHSA-v8p7-prvv-wvf5.json | 39 +++++++++++++++++++ 12 files changed, 468 insertions(+) create mode 100644 advisories/unreviewed/2024/02/GHSA-25vc-3hfp-rp87/GHSA-25vc-3hfp-rp87.json create mode 100644 advisories/unreviewed/2024/02/GHSA-45ch-2h92-cc35/GHSA-45ch-2h92-cc35.json create mode 100644 advisories/unreviewed/2024/02/GHSA-6r3r-qjm5-8fvp/GHSA-6r3r-qjm5-8fvp.json create mode 100644 advisories/unreviewed/2024/02/GHSA-c22v-83jg-hp9r/GHSA-c22v-83jg-hp9r.json create mode 100644 advisories/unreviewed/2024/02/GHSA-c6gq-r463-842g/GHSA-c6gq-r463-842g.json create mode 100644 advisories/unreviewed/2024/02/GHSA-cq73-wfw9-gvq8/GHSA-cq73-wfw9-gvq8.json create mode 100644 advisories/unreviewed/2024/02/GHSA-gqvq-6r9g-ff5p/GHSA-gqvq-6r9g-ff5p.json create mode 100644 advisories/unreviewed/2024/02/GHSA-jrx7-rgwc-w944/GHSA-jrx7-rgwc-w944.json create mode 100644 advisories/unreviewed/2024/02/GHSA-pgqc-xw7p-gm9j/GHSA-pgqc-xw7p-gm9j.json create mode 100644 advisories/unreviewed/2024/02/GHSA-pj8m-c5v2-vf9w/GHSA-pj8m-c5v2-vf9w.json create mode 100644 advisories/unreviewed/2024/02/GHSA-qmxh-c3qm-vmrf/GHSA-qmxh-c3qm-vmrf.json create mode 100644 advisories/unreviewed/2024/02/GHSA-v8p7-prvv-wvf5/GHSA-v8p7-prvv-wvf5.json diff --git a/advisories/unreviewed/2024/02/GHSA-25vc-3hfp-rp87/GHSA-25vc-3hfp-rp87.json b/advisories/unreviewed/2024/02/GHSA-25vc-3hfp-rp87/GHSA-25vc-3hfp-rp87.json new file mode 100644 index 00000000000..9b3dc2a3801 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-25vc-3hfp-rp87/GHSA-25vc-3hfp-rp87.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-25vc-3hfp-rp87", + "modified": "2024-02-18T06:30:31Z", + "published": "2024-02-18T06:30:31Z", + "aliases": [ + "CVE-2023-52369" + ], + "details": "Stack overflow vulnerability in the NFC module.Successful exploitation of this vulnerability may affect service availability and integrity.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52369" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/2" + }, + { + "type": "WEB", + "url": "https://device.harmonyos.com/cn/docs/security/update/security-bulletins-202402-0000001834855405" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-18T04:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-45ch-2h92-cc35/GHSA-45ch-2h92-cc35.json b/advisories/unreviewed/2024/02/GHSA-45ch-2h92-cc35/GHSA-45ch-2h92-cc35.json new file mode 100644 index 00000000000..2005ee3fa1f --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-45ch-2h92-cc35/GHSA-45ch-2h92-cc35.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-45ch-2h92-cc35", + "modified": "2024-02-18T06:30:32Z", + "published": "2024-02-18T06:30:32Z", + "aliases": [ + "CVE-2023-52375" + ], + "details": "Permission control vulnerability in the WindowManagerServices module.Successful exploitation of this vulnerability may affect availability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52375" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/2" + }, + { + "type": "WEB", + "url": "https://device.harmonyos.com/cn/docs/security/update/security-bulletins-202402-0000001834855405" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-18T06:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-6r3r-qjm5-8fvp/GHSA-6r3r-qjm5-8fvp.json b/advisories/unreviewed/2024/02/GHSA-6r3r-qjm5-8fvp/GHSA-6r3r-qjm5-8fvp.json new file mode 100644 index 00000000000..c60ce394afe --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-6r3r-qjm5-8fvp/GHSA-6r3r-qjm5-8fvp.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6r3r-qjm5-8fvp", + "modified": "2024-02-18T06:30:32Z", + "published": "2024-02-18T06:30:32Z", + "aliases": [ + "CVE-2023-52376" + ], + "details": "Information management vulnerability in the Gallery module.Successful exploitation of this vulnerability may affect service confidentiality.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52376" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/2" + }, + { + "type": "WEB", + "url": "https://device.harmonyos.com/cn/docs/security/update/security-bulletins-202402-0000001834855405" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-18T06:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-c22v-83jg-hp9r/GHSA-c22v-83jg-hp9r.json b/advisories/unreviewed/2024/02/GHSA-c22v-83jg-hp9r/GHSA-c22v-83jg-hp9r.json new file mode 100644 index 00000000000..22ba4523945 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-c22v-83jg-hp9r/GHSA-c22v-83jg-hp9r.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c22v-83jg-hp9r", + "modified": "2024-02-18T06:30:31Z", + "published": "2024-02-18T06:30:31Z", + "aliases": [ + "CVE-2023-52373" + ], + "details": "Vulnerability of permission verification in the content sharing pop-up module.Successful exploitation of this vulnerability may cause unauthorized file sharing.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52373" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/2" + }, + { + "type": "WEB", + "url": "https://device.harmonyos.com/cn/docs/security/update/security-bulletins-202402-0000001834855405" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-18T04:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-c6gq-r463-842g/GHSA-c6gq-r463-842g.json b/advisories/unreviewed/2024/02/GHSA-c6gq-r463-842g/GHSA-c6gq-r463-842g.json new file mode 100644 index 00000000000..09cea7f084a --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-c6gq-r463-842g/GHSA-c6gq-r463-842g.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c6gq-r463-842g", + "modified": "2024-02-18T06:30:31Z", + "published": "2024-02-18T06:30:31Z", + "aliases": [ + "CVE-2023-52367" + ], + "details": "Vulnerability of improper access control in the media library module.Successful exploitation of this vulnerability may affect service availability and integrity.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52367" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/2" + }, + { + "type": "WEB", + "url": "https://device.harmonyos.com/cn/docs/security/update/security-bulletins-202402-0000001834855405" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-18T04:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-cq73-wfw9-gvq8/GHSA-cq73-wfw9-gvq8.json b/advisories/unreviewed/2024/02/GHSA-cq73-wfw9-gvq8/GHSA-cq73-wfw9-gvq8.json new file mode 100644 index 00000000000..6b31d3e9b90 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-cq73-wfw9-gvq8/GHSA-cq73-wfw9-gvq8.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cq73-wfw9-gvq8", + "modified": "2024-02-18T06:30:31Z", + "published": "2024-02-18T06:30:31Z", + "aliases": [ + "CVE-2023-52366" + ], + "details": "Out-of-bounds read vulnerability in the smart activity recognition module.Successful exploitation of this vulnerability may cause features to perform abnormally.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52366" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/2" + }, + { + "type": "WEB", + "url": "https://device.harmonyos.com/cn/docs/security/update/security-bulletins-202402-0000001834855405" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-18T04:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-gqvq-6r9g-ff5p/GHSA-gqvq-6r9g-ff5p.json b/advisories/unreviewed/2024/02/GHSA-gqvq-6r9g-ff5p/GHSA-gqvq-6r9g-ff5p.json new file mode 100644 index 00000000000..a296d79ff06 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-gqvq-6r9g-ff5p/GHSA-gqvq-6r9g-ff5p.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gqvq-6r9g-ff5p", + "modified": "2024-02-18T06:30:32Z", + "published": "2024-02-18T06:30:32Z", + "aliases": [ + "CVE-2023-52377" + ], + "details": "Vulnerability of input data not being verified in the cellular data module.Successful exploitation of this vulnerability may cause out-of-bounds access.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52377" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/2" + }, + { + "type": "WEB", + "url": "https://device.harmonyos.com/cn/docs/security/update/security-bulletins-202402-0000001834855405" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-18T06:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-jrx7-rgwc-w944/GHSA-jrx7-rgwc-w944.json b/advisories/unreviewed/2024/02/GHSA-jrx7-rgwc-w944/GHSA-jrx7-rgwc-w944.json new file mode 100644 index 00000000000..924f945aad4 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-jrx7-rgwc-w944/GHSA-jrx7-rgwc-w944.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jrx7-rgwc-w944", + "modified": "2024-02-18T06:30:31Z", + "published": "2024-02-18T06:30:31Z", + "aliases": [ + "CVE-2023-52370" + ], + "details": "Stack overflow vulnerability in the network acceleration module.Successful exploitation of this vulnerability may cause unauthorized file access.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52370" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/2" + }, + { + "type": "WEB", + "url": "https://device.harmonyos.com/cn/docs/security/update/security-bulletins-202402-0000001834855405" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-18T04:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-pgqc-xw7p-gm9j/GHSA-pgqc-xw7p-gm9j.json b/advisories/unreviewed/2024/02/GHSA-pgqc-xw7p-gm9j/GHSA-pgqc-xw7p-gm9j.json new file mode 100644 index 00000000000..9c19e755774 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-pgqc-xw7p-gm9j/GHSA-pgqc-xw7p-gm9j.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pgqc-xw7p-gm9j", + "modified": "2024-02-18T06:30:31Z", + "published": "2024-02-18T06:30:31Z", + "aliases": [ + "CVE-2023-52371" + ], + "details": "Vulnerability of null references in the motor module.Successful exploitation of this vulnerability may affect availability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52371" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/2" + }, + { + "type": "WEB", + "url": "https://device.harmonyos.com/cn/docs/security/update/security-bulletins-202402-0000001834855405" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-18T04:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-pj8m-c5v2-vf9w/GHSA-pj8m-c5v2-vf9w.json b/advisories/unreviewed/2024/02/GHSA-pj8m-c5v2-vf9w/GHSA-pj8m-c5v2-vf9w.json new file mode 100644 index 00000000000..5b2fa9adee3 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-pj8m-c5v2-vf9w/GHSA-pj8m-c5v2-vf9w.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pj8m-c5v2-vf9w", + "modified": "2024-02-18T06:30:31Z", + "published": "2024-02-18T06:30:31Z", + "aliases": [ + "CVE-2023-52372" + ], + "details": "Vulnerability of input parameter verification in the motor module.Successful exploitation of this vulnerability may affect availability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52372" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/2" + }, + { + "type": "WEB", + "url": "https://device.harmonyos.com/cn/docs/security/update/security-bulletins-202402-0000001834855405" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-18T04:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-qmxh-c3qm-vmrf/GHSA-qmxh-c3qm-vmrf.json b/advisories/unreviewed/2024/02/GHSA-qmxh-c3qm-vmrf/GHSA-qmxh-c3qm-vmrf.json new file mode 100644 index 00000000000..1dd4360b7fc --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-qmxh-c3qm-vmrf/GHSA-qmxh-c3qm-vmrf.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qmxh-c3qm-vmrf", + "modified": "2024-02-18T06:30:32Z", + "published": "2024-02-18T06:30:32Z", + "aliases": [ + "CVE-2023-52374" + ], + "details": "Permission control vulnerability in the package management module.Successful exploitation of this vulnerability may affect service confidentiality.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52374" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/2" + }, + { + "type": "WEB", + "url": "https://https://device.harmonyos.com/cn/docs/security/update/security-bulletins-202402-0000001834855405" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-18T04:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-v8p7-prvv-wvf5/GHSA-v8p7-prvv-wvf5.json b/advisories/unreviewed/2024/02/GHSA-v8p7-prvv-wvf5/GHSA-v8p7-prvv-wvf5.json new file mode 100644 index 00000000000..1eb50f54dd4 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-v8p7-prvv-wvf5/GHSA-v8p7-prvv-wvf5.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v8p7-prvv-wvf5", + "modified": "2024-02-18T06:30:31Z", + "published": "2024-02-18T06:30:31Z", + "aliases": [ + "CVE-2023-52368" + ], + "details": "Input verification vulnerability in the account module.Successful exploitation of this vulnerability may cause features to perform abnormally.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52368" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/2" + }, + { + "type": "WEB", + "url": "https://device.harmonyos.com/cn/docs/security/update/security-bulletins-202402-0000001834855405" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-18T04:15:07Z" + } +} \ No newline at end of file