From 52e8a2f23ca818b4f2ad57647479a2ae976c6979 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 8 Aug 2023 18:31:50 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-255q-f9p7-jxj6.json | 38 +++++++++++++++ .../GHSA-2644-f36h-q8x8.json | 9 ++-- .../GHSA-2hvw-r4rp-mjpp.json | 38 +++++++++++++++ .../GHSA-2x4q-vchp-x653.json | 9 ++-- .../GHSA-32hv-227c-chpv.json | 38 +++++++++++++++ .../GHSA-333g-8frm-xc2h.json | 47 +++++++++++++++++++ .../GHSA-3457-9p37-3w4q.json | 38 +++++++++++++++ .../GHSA-35wh-q52w-78vq.json | 38 +++++++++++++++ .../GHSA-3cqw-w427-m45x.json | 9 ++-- .../GHSA-3hhc-gfj2-qgg7.json | 38 +++++++++++++++ .../GHSA-3jf9-p4gc-9h68.json | 38 +++++++++++++++ .../GHSA-3vj2-7455-cq23.json | 38 +++++++++++++++ .../GHSA-4m6r-h473-x99p.json | 47 +++++++++++++++++++ .../GHSA-4mp8-95wg-7xm4.json | 35 ++++++++++++++ .../GHSA-4wv3-22h6-h824.json | 38 +++++++++++++++ .../GHSA-56r2-62gh-h7qr.json | 38 +++++++++++++++ .../GHSA-5qfj-773w-84hp.json | 38 +++++++++++++++ .../GHSA-5vgj-hqrc-gx52.json | 38 +++++++++++++++ .../GHSA-6672-m2hq-hwm4.json | 7 ++- .../GHSA-68pc-r3j9-h8x2.json | 38 +++++++++++++++ .../GHSA-68qp-hp65-rmrq.json | 38 +++++++++++++++ .../GHSA-6cv5-8fpc-p4rh.json | 38 +++++++++++++++ .../GHSA-6f8c-2h4w-727p.json | 47 +++++++++++++++++++ .../GHSA-6h77-2hc9-qm3w.json | 35 ++++++++++++++ .../GHSA-7f8x-49jc-23pr.json | 47 +++++++++++++++++++ .../GHSA-7fjv-53p8-9hhh.json | 39 +++++++++++++++ .../GHSA-7j77-rcrw-mhm8.json | 38 +++++++++++++++ .../GHSA-7p3x-w377-9pq7.json | 35 ++++++++++++++ .../GHSA-7q8x-6cwc-cx3j.json | 1 + .../GHSA-7rh4-mff7-83p7.json | 38 +++++++++++++++ .../GHSA-7vm7-m762-pgv3.json | 38 +++++++++++++++ .../GHSA-7w82-6wqx-9r39.json | 38 +++++++++++++++ .../GHSA-856f-5pr4-jx6q.json | 9 ++-- .../GHSA-8c62-6wcm-89qf.json | 38 +++++++++++++++ .../GHSA-8m9p-3926-gffr.json | 39 +++++++++++++++ .../GHSA-8w6g-5xq3-hvc5.json | 38 +++++++++++++++ .../GHSA-8w7q-cfxq-v32g.json | 38 +++++++++++++++ .../GHSA-95h7-qcfp-8mx9.json | 38 +++++++++++++++ .../GHSA-9f52-rmc2-c4c7.json | 9 ++-- .../GHSA-9gpg-63cp-jr3x.json | 38 +++++++++++++++ .../GHSA-9j64-pxww-55vc.json | 38 +++++++++++++++ .../GHSA-9wg5-4w44-rm5v.json | 7 ++- .../GHSA-c3g4-pf6v-r7hx.json | 38 +++++++++++++++ .../GHSA-c662-mp4g-c23j.json | 38 +++++++++++++++ .../GHSA-c6w6-vvhg-83vr.json | 35 ++++++++++++++ .../GHSA-ccq3-436r-c3g8.json | 38 +++++++++++++++ .../GHSA-cgvx-gc8r-995f.json | 38 +++++++++++++++ .../GHSA-cpgq-9v8g-4fxq.json | 38 +++++++++++++++ .../GHSA-cq3m-ggcc-x7v9.json | 38 +++++++++++++++ .../GHSA-crf4-cpc3-935q.json | 38 +++++++++++++++ .../GHSA-cw67-2mcx-5p7m.json | 38 +++++++++++++++ .../GHSA-cwxh-83m5-5h37.json | 38 +++++++++++++++ .../GHSA-f4r6-49fh-5c4m.json | 38 +++++++++++++++ .../GHSA-f5cr-mp3h-4jjj.json | 38 +++++++++++++++ .../GHSA-f6f3-rrm8-q5r8.json | 35 ++++++++++++++ .../GHSA-f6h3-4j54-4g5g.json | 47 +++++++++++++++++++ .../GHSA-f6j6-4j57-f83g.json | 38 +++++++++++++++ .../GHSA-fff5-q99h-fmwq.json | 47 +++++++++++++++++++ .../GHSA-fg32-9w38-fj64.json | 38 +++++++++++++++ .../GHSA-fhv3-5p89-vfc8.json | 38 +++++++++++++++ .../GHSA-fmj9-qf8f-cprj.json | 38 +++++++++++++++ .../GHSA-fqp6-q28m-cfjh.json | 38 +++++++++++++++ .../GHSA-g48h-r36w-jj6x.json | 38 +++++++++++++++ .../GHSA-g53f-59qq-gfh7.json | 38 +++++++++++++++ .../GHSA-gfcr-pv59-q6p8.json | 38 +++++++++++++++ .../GHSA-gx47-2cwv-p7wc.json | 38 +++++++++++++++ .../GHSA-h45c-25x4-6qq4.json | 38 +++++++++++++++ .../GHSA-h4f6-pvrq-rcr4.json | 38 +++++++++++++++ .../GHSA-hcf3-whvg-qpfq.json | 38 +++++++++++++++ .../GHSA-hfm3-j43v-9h2m.json | 38 +++++++++++++++ .../GHSA-hh4j-cm3f-5mf6.json | 38 +++++++++++++++ .../GHSA-hw2m-jwjq-p5v6.json | 47 +++++++++++++++++++ .../GHSA-hwv5-c9xr-g79c.json | 38 +++++++++++++++ .../GHSA-hx37-jpgw-mp7v.json | 38 +++++++++++++++ .../GHSA-hxpc-gw6v-6gwc.json | 38 +++++++++++++++ .../GHSA-j3hx-c9h6-63vv.json | 38 +++++++++++++++ .../GHSA-j5pp-wfmg-q9jp.json | 38 +++++++++++++++ .../GHSA-j82f-chfp-3hrg.json | 38 +++++++++++++++ .../GHSA-jgvj-jh34-hqv3.json | 7 ++- .../GHSA-jmx3-98vw-w6hq.json | 2 +- .../GHSA-jp4g-93c7-f645.json | 38 +++++++++++++++ .../GHSA-jrpp-v555-xqmp.json | 38 +++++++++++++++ .../GHSA-jxrr-jgx5-rfcg.json | 38 +++++++++++++++ .../GHSA-m5g9-fvqr-h5pp.json | 38 +++++++++++++++ .../GHSA-mf8r-h4c9-q93r.json | 38 +++++++++++++++ .../GHSA-mrhv-v7jg-4384.json | 7 ++- .../GHSA-mv3g-pwv2-rfxp.json | 38 +++++++++++++++ .../GHSA-mw3f-jhxv-c95j.json | 38 +++++++++++++++ .../GHSA-mw4m-m933-3jx3.json | 47 +++++++++++++++++++ .../GHSA-mxh8-v3cx-xp6x.json | 38 +++++++++++++++ .../GHSA-p36c-2mv6-8m8q.json | 2 +- .../GHSA-p4r5-8jr9-cwgv.json | 35 ++++++++++++++ .../GHSA-q9v9-492r-q87w.json | 38 +++++++++++++++ .../GHSA-qh2x-6w4c-qxp3.json | 38 +++++++++++++++ .../GHSA-qqxx-932h-hc2v.json | 47 +++++++++++++++++++ .../GHSA-qv3q-cwv9-r3m3.json | 38 +++++++++++++++ .../GHSA-qv76-4vx5-f24v.json | 38 +++++++++++++++ .../GHSA-qvhv-4pmm-cc4q.json | 38 +++++++++++++++ .../GHSA-qw8j-8xrp-fcf6.json | 38 +++++++++++++++ .../GHSA-r3h2-76p7-jwr7.json | 38 +++++++++++++++ .../GHSA-r47r-3chg-8pxv.json | 38 +++++++++++++++ .../GHSA-rg2c-cfxv-qp6f.json | 46 ++++++++++++++++++ .../GHSA-v2fp-mjm4-pj44.json | 38 +++++++++++++++ .../GHSA-v478-mrrj-9jxx.json | 47 +++++++++++++++++++ .../GHSA-vcw6-g65p-gcjw.json | 35 ++++++++++++++ .../GHSA-vrg5-r47p-62x3.json | 47 +++++++++++++++++++ .../GHSA-vx8f-24wp-mfwj.json | 38 +++++++++++++++ .../GHSA-w5hv-qvq6-g6wg.json | 38 +++++++++++++++ .../GHSA-w5xr-g793-3gjm.json | 47 +++++++++++++++++++ .../GHSA-wc5r-96vx-4jj6.json | 9 ++-- .../GHSA-whhx-jc9m-vw4h.json | 38 +++++++++++++++ .../GHSA-wrw3-qmqw-4x9w.json | 39 +++++++++++++++ .../GHSA-wxv4-gf6x-3gmh.json | 47 +++++++++++++++++++ .../GHSA-x267-8p4f-834v.json | 38 +++++++++++++++ .../GHSA-x8v9-642f-j4vc.json | 2 +- .../GHSA-xq7r-2vx2-8jgj.json | 3 +- .../GHSA-xqp9-w6xm-qf2v.json | 38 +++++++++++++++ .../GHSA-xr6c-7pfv-6vgf.json | 35 ++++++++++++++ 118 files changed, 4080 insertions(+), 30 deletions(-) create mode 100644 advisories/unreviewed/2023/08/GHSA-255q-f9p7-jxj6/GHSA-255q-f9p7-jxj6.json create mode 100644 advisories/unreviewed/2023/08/GHSA-2hvw-r4rp-mjpp/GHSA-2hvw-r4rp-mjpp.json create mode 100644 advisories/unreviewed/2023/08/GHSA-32hv-227c-chpv/GHSA-32hv-227c-chpv.json create mode 100644 advisories/unreviewed/2023/08/GHSA-333g-8frm-xc2h/GHSA-333g-8frm-xc2h.json create mode 100644 advisories/unreviewed/2023/08/GHSA-3457-9p37-3w4q/GHSA-3457-9p37-3w4q.json create mode 100644 advisories/unreviewed/2023/08/GHSA-35wh-q52w-78vq/GHSA-35wh-q52w-78vq.json create mode 100644 advisories/unreviewed/2023/08/GHSA-3hhc-gfj2-qgg7/GHSA-3hhc-gfj2-qgg7.json create mode 100644 advisories/unreviewed/2023/08/GHSA-3jf9-p4gc-9h68/GHSA-3jf9-p4gc-9h68.json create mode 100644 advisories/unreviewed/2023/08/GHSA-3vj2-7455-cq23/GHSA-3vj2-7455-cq23.json create mode 100644 advisories/unreviewed/2023/08/GHSA-4m6r-h473-x99p/GHSA-4m6r-h473-x99p.json create mode 100644 advisories/unreviewed/2023/08/GHSA-4mp8-95wg-7xm4/GHSA-4mp8-95wg-7xm4.json create mode 100644 advisories/unreviewed/2023/08/GHSA-4wv3-22h6-h824/GHSA-4wv3-22h6-h824.json create mode 100644 advisories/unreviewed/2023/08/GHSA-56r2-62gh-h7qr/GHSA-56r2-62gh-h7qr.json create mode 100644 advisories/unreviewed/2023/08/GHSA-5qfj-773w-84hp/GHSA-5qfj-773w-84hp.json create mode 100644 advisories/unreviewed/2023/08/GHSA-5vgj-hqrc-gx52/GHSA-5vgj-hqrc-gx52.json create mode 100644 advisories/unreviewed/2023/08/GHSA-68pc-r3j9-h8x2/GHSA-68pc-r3j9-h8x2.json create mode 100644 advisories/unreviewed/2023/08/GHSA-68qp-hp65-rmrq/GHSA-68qp-hp65-rmrq.json create mode 100644 advisories/unreviewed/2023/08/GHSA-6cv5-8fpc-p4rh/GHSA-6cv5-8fpc-p4rh.json create mode 100644 advisories/unreviewed/2023/08/GHSA-6f8c-2h4w-727p/GHSA-6f8c-2h4w-727p.json create mode 100644 advisories/unreviewed/2023/08/GHSA-6h77-2hc9-qm3w/GHSA-6h77-2hc9-qm3w.json create mode 100644 advisories/unreviewed/2023/08/GHSA-7f8x-49jc-23pr/GHSA-7f8x-49jc-23pr.json create mode 100644 advisories/unreviewed/2023/08/GHSA-7fjv-53p8-9hhh/GHSA-7fjv-53p8-9hhh.json create mode 100644 advisories/unreviewed/2023/08/GHSA-7j77-rcrw-mhm8/GHSA-7j77-rcrw-mhm8.json create mode 100644 advisories/unreviewed/2023/08/GHSA-7p3x-w377-9pq7/GHSA-7p3x-w377-9pq7.json create mode 100644 advisories/unreviewed/2023/08/GHSA-7rh4-mff7-83p7/GHSA-7rh4-mff7-83p7.json create mode 100644 advisories/unreviewed/2023/08/GHSA-7vm7-m762-pgv3/GHSA-7vm7-m762-pgv3.json create mode 100644 advisories/unreviewed/2023/08/GHSA-7w82-6wqx-9r39/GHSA-7w82-6wqx-9r39.json create mode 100644 advisories/unreviewed/2023/08/GHSA-8c62-6wcm-89qf/GHSA-8c62-6wcm-89qf.json create mode 100644 advisories/unreviewed/2023/08/GHSA-8m9p-3926-gffr/GHSA-8m9p-3926-gffr.json create mode 100644 advisories/unreviewed/2023/08/GHSA-8w6g-5xq3-hvc5/GHSA-8w6g-5xq3-hvc5.json create mode 100644 advisories/unreviewed/2023/08/GHSA-8w7q-cfxq-v32g/GHSA-8w7q-cfxq-v32g.json create mode 100644 advisories/unreviewed/2023/08/GHSA-95h7-qcfp-8mx9/GHSA-95h7-qcfp-8mx9.json create mode 100644 advisories/unreviewed/2023/08/GHSA-9gpg-63cp-jr3x/GHSA-9gpg-63cp-jr3x.json create mode 100644 advisories/unreviewed/2023/08/GHSA-9j64-pxww-55vc/GHSA-9j64-pxww-55vc.json create mode 100644 advisories/unreviewed/2023/08/GHSA-c3g4-pf6v-r7hx/GHSA-c3g4-pf6v-r7hx.json create mode 100644 advisories/unreviewed/2023/08/GHSA-c662-mp4g-c23j/GHSA-c662-mp4g-c23j.json create mode 100644 advisories/unreviewed/2023/08/GHSA-c6w6-vvhg-83vr/GHSA-c6w6-vvhg-83vr.json create mode 100644 advisories/unreviewed/2023/08/GHSA-ccq3-436r-c3g8/GHSA-ccq3-436r-c3g8.json create mode 100644 advisories/unreviewed/2023/08/GHSA-cgvx-gc8r-995f/GHSA-cgvx-gc8r-995f.json create mode 100644 advisories/unreviewed/2023/08/GHSA-cpgq-9v8g-4fxq/GHSA-cpgq-9v8g-4fxq.json create mode 100644 advisories/unreviewed/2023/08/GHSA-cq3m-ggcc-x7v9/GHSA-cq3m-ggcc-x7v9.json create mode 100644 advisories/unreviewed/2023/08/GHSA-crf4-cpc3-935q/GHSA-crf4-cpc3-935q.json create mode 100644 advisories/unreviewed/2023/08/GHSA-cw67-2mcx-5p7m/GHSA-cw67-2mcx-5p7m.json create mode 100644 advisories/unreviewed/2023/08/GHSA-cwxh-83m5-5h37/GHSA-cwxh-83m5-5h37.json create mode 100644 advisories/unreviewed/2023/08/GHSA-f4r6-49fh-5c4m/GHSA-f4r6-49fh-5c4m.json create mode 100644 advisories/unreviewed/2023/08/GHSA-f5cr-mp3h-4jjj/GHSA-f5cr-mp3h-4jjj.json create mode 100644 advisories/unreviewed/2023/08/GHSA-f6f3-rrm8-q5r8/GHSA-f6f3-rrm8-q5r8.json create mode 100644 advisories/unreviewed/2023/08/GHSA-f6h3-4j54-4g5g/GHSA-f6h3-4j54-4g5g.json create mode 100644 advisories/unreviewed/2023/08/GHSA-f6j6-4j57-f83g/GHSA-f6j6-4j57-f83g.json create mode 100644 advisories/unreviewed/2023/08/GHSA-fff5-q99h-fmwq/GHSA-fff5-q99h-fmwq.json create mode 100644 advisories/unreviewed/2023/08/GHSA-fg32-9w38-fj64/GHSA-fg32-9w38-fj64.json create mode 100644 advisories/unreviewed/2023/08/GHSA-fhv3-5p89-vfc8/GHSA-fhv3-5p89-vfc8.json create mode 100644 advisories/unreviewed/2023/08/GHSA-fmj9-qf8f-cprj/GHSA-fmj9-qf8f-cprj.json create mode 100644 advisories/unreviewed/2023/08/GHSA-fqp6-q28m-cfjh/GHSA-fqp6-q28m-cfjh.json create mode 100644 advisories/unreviewed/2023/08/GHSA-g48h-r36w-jj6x/GHSA-g48h-r36w-jj6x.json create mode 100644 advisories/unreviewed/2023/08/GHSA-g53f-59qq-gfh7/GHSA-g53f-59qq-gfh7.json create mode 100644 advisories/unreviewed/2023/08/GHSA-gfcr-pv59-q6p8/GHSA-gfcr-pv59-q6p8.json create mode 100644 advisories/unreviewed/2023/08/GHSA-gx47-2cwv-p7wc/GHSA-gx47-2cwv-p7wc.json create mode 100644 advisories/unreviewed/2023/08/GHSA-h45c-25x4-6qq4/GHSA-h45c-25x4-6qq4.json create mode 100644 advisories/unreviewed/2023/08/GHSA-h4f6-pvrq-rcr4/GHSA-h4f6-pvrq-rcr4.json create mode 100644 advisories/unreviewed/2023/08/GHSA-hcf3-whvg-qpfq/GHSA-hcf3-whvg-qpfq.json create mode 100644 advisories/unreviewed/2023/08/GHSA-hfm3-j43v-9h2m/GHSA-hfm3-j43v-9h2m.json create mode 100644 advisories/unreviewed/2023/08/GHSA-hh4j-cm3f-5mf6/GHSA-hh4j-cm3f-5mf6.json create mode 100644 advisories/unreviewed/2023/08/GHSA-hw2m-jwjq-p5v6/GHSA-hw2m-jwjq-p5v6.json create mode 100644 advisories/unreviewed/2023/08/GHSA-hwv5-c9xr-g79c/GHSA-hwv5-c9xr-g79c.json create mode 100644 advisories/unreviewed/2023/08/GHSA-hx37-jpgw-mp7v/GHSA-hx37-jpgw-mp7v.json create mode 100644 advisories/unreviewed/2023/08/GHSA-hxpc-gw6v-6gwc/GHSA-hxpc-gw6v-6gwc.json create mode 100644 advisories/unreviewed/2023/08/GHSA-j3hx-c9h6-63vv/GHSA-j3hx-c9h6-63vv.json create mode 100644 advisories/unreviewed/2023/08/GHSA-j5pp-wfmg-q9jp/GHSA-j5pp-wfmg-q9jp.json create mode 100644 advisories/unreviewed/2023/08/GHSA-j82f-chfp-3hrg/GHSA-j82f-chfp-3hrg.json create mode 100644 advisories/unreviewed/2023/08/GHSA-jp4g-93c7-f645/GHSA-jp4g-93c7-f645.json create mode 100644 advisories/unreviewed/2023/08/GHSA-jrpp-v555-xqmp/GHSA-jrpp-v555-xqmp.json create mode 100644 advisories/unreviewed/2023/08/GHSA-jxrr-jgx5-rfcg/GHSA-jxrr-jgx5-rfcg.json create mode 100644 advisories/unreviewed/2023/08/GHSA-m5g9-fvqr-h5pp/GHSA-m5g9-fvqr-h5pp.json create mode 100644 advisories/unreviewed/2023/08/GHSA-mf8r-h4c9-q93r/GHSA-mf8r-h4c9-q93r.json create mode 100644 advisories/unreviewed/2023/08/GHSA-mv3g-pwv2-rfxp/GHSA-mv3g-pwv2-rfxp.json create mode 100644 advisories/unreviewed/2023/08/GHSA-mw3f-jhxv-c95j/GHSA-mw3f-jhxv-c95j.json create mode 100644 advisories/unreviewed/2023/08/GHSA-mw4m-m933-3jx3/GHSA-mw4m-m933-3jx3.json create mode 100644 advisories/unreviewed/2023/08/GHSA-mxh8-v3cx-xp6x/GHSA-mxh8-v3cx-xp6x.json create mode 100644 advisories/unreviewed/2023/08/GHSA-p4r5-8jr9-cwgv/GHSA-p4r5-8jr9-cwgv.json create mode 100644 advisories/unreviewed/2023/08/GHSA-q9v9-492r-q87w/GHSA-q9v9-492r-q87w.json create mode 100644 advisories/unreviewed/2023/08/GHSA-qh2x-6w4c-qxp3/GHSA-qh2x-6w4c-qxp3.json create mode 100644 advisories/unreviewed/2023/08/GHSA-qqxx-932h-hc2v/GHSA-qqxx-932h-hc2v.json create mode 100644 advisories/unreviewed/2023/08/GHSA-qv3q-cwv9-r3m3/GHSA-qv3q-cwv9-r3m3.json create mode 100644 advisories/unreviewed/2023/08/GHSA-qv76-4vx5-f24v/GHSA-qv76-4vx5-f24v.json create mode 100644 advisories/unreviewed/2023/08/GHSA-qvhv-4pmm-cc4q/GHSA-qvhv-4pmm-cc4q.json create mode 100644 advisories/unreviewed/2023/08/GHSA-qw8j-8xrp-fcf6/GHSA-qw8j-8xrp-fcf6.json create mode 100644 advisories/unreviewed/2023/08/GHSA-r3h2-76p7-jwr7/GHSA-r3h2-76p7-jwr7.json create mode 100644 advisories/unreviewed/2023/08/GHSA-r47r-3chg-8pxv/GHSA-r47r-3chg-8pxv.json create mode 100644 advisories/unreviewed/2023/08/GHSA-rg2c-cfxv-qp6f/GHSA-rg2c-cfxv-qp6f.json create mode 100644 advisories/unreviewed/2023/08/GHSA-v2fp-mjm4-pj44/GHSA-v2fp-mjm4-pj44.json create mode 100644 advisories/unreviewed/2023/08/GHSA-v478-mrrj-9jxx/GHSA-v478-mrrj-9jxx.json create mode 100644 advisories/unreviewed/2023/08/GHSA-vcw6-g65p-gcjw/GHSA-vcw6-g65p-gcjw.json create mode 100644 advisories/unreviewed/2023/08/GHSA-vrg5-r47p-62x3/GHSA-vrg5-r47p-62x3.json create mode 100644 advisories/unreviewed/2023/08/GHSA-vx8f-24wp-mfwj/GHSA-vx8f-24wp-mfwj.json create mode 100644 advisories/unreviewed/2023/08/GHSA-w5hv-qvq6-g6wg/GHSA-w5hv-qvq6-g6wg.json create mode 100644 advisories/unreviewed/2023/08/GHSA-w5xr-g793-3gjm/GHSA-w5xr-g793-3gjm.json create mode 100644 advisories/unreviewed/2023/08/GHSA-whhx-jc9m-vw4h/GHSA-whhx-jc9m-vw4h.json create mode 100644 advisories/unreviewed/2023/08/GHSA-wrw3-qmqw-4x9w/GHSA-wrw3-qmqw-4x9w.json create mode 100644 advisories/unreviewed/2023/08/GHSA-wxv4-gf6x-3gmh/GHSA-wxv4-gf6x-3gmh.json create mode 100644 advisories/unreviewed/2023/08/GHSA-x267-8p4f-834v/GHSA-x267-8p4f-834v.json create mode 100644 advisories/unreviewed/2023/08/GHSA-xqp9-w6xm-qf2v/GHSA-xqp9-w6xm-qf2v.json create mode 100644 advisories/unreviewed/2023/08/GHSA-xr6c-7pfv-6vgf/GHSA-xr6c-7pfv-6vgf.json diff --git a/advisories/unreviewed/2023/08/GHSA-255q-f9p7-jxj6/GHSA-255q-f9p7-jxj6.json b/advisories/unreviewed/2023/08/GHSA-255q-f9p7-jxj6/GHSA-255q-f9p7-jxj6.json new file mode 100644 index 00000000000..7dc56b66541 --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-255q-f9p7-jxj6/GHSA-255q-f9p7-jxj6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-255q-f9p7-jxj6", + "modified": "2023-08-08T18:30:36Z", + "published": "2023-08-08T18:30:36Z", + "aliases": [ + "CVE-2023-36891" + ], + "details": "Microsoft SharePoint Server Spoofing Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36891" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36891" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-2644-f36h-q8x8/GHSA-2644-f36h-q8x8.json b/advisories/unreviewed/2023/08/GHSA-2644-f36h-q8x8/GHSA-2644-f36h-q8x8.json index 742b87467d6..d4dd6e30914 100644 --- a/advisories/unreviewed/2023/08/GHSA-2644-f36h-q8x8/GHSA-2644-f36h-q8x8.json +++ b/advisories/unreviewed/2023/08/GHSA-2644-f36h-q8x8/GHSA-2644-f36h-q8x8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2644-f36h-q8x8", - "modified": "2023-08-03T18:30:35Z", + "modified": "2023-08-08T18:30:35Z", "published": "2023-08-03T18:30:35Z", "aliases": [ "CVE-2023-36217" ], "details": "Cross Site Scripting vulnerability in Xoops CMS v.2.5.10 allows a remote attacker to execute arbitrary code via the category name field of the image manager function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/08/GHSA-2hvw-r4rp-mjpp/GHSA-2hvw-r4rp-mjpp.json b/advisories/unreviewed/2023/08/GHSA-2hvw-r4rp-mjpp/GHSA-2hvw-r4rp-mjpp.json new file mode 100644 index 00000000000..f1b09c6411c --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-2hvw-r4rp-mjpp/GHSA-2hvw-r4rp-mjpp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2hvw-r4rp-mjpp", + "modified": "2023-08-08T18:30:36Z", + "published": "2023-08-08T18:30:36Z", + "aliases": [ + "CVE-2023-36532" + ], + "details": "Buffer overflow in Zoom Clients before 5.14.5 may allow an unauthenticated user to enable a denial of service via network access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36532" + }, + { + "type": "WEB", + "url": "https://explore.zoom.us/en/trust/security/security-bulletin/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-2x4q-vchp-x653/GHSA-2x4q-vchp-x653.json b/advisories/unreviewed/2023/08/GHSA-2x4q-vchp-x653/GHSA-2x4q-vchp-x653.json index e4612199668..cd173276c72 100644 --- a/advisories/unreviewed/2023/08/GHSA-2x4q-vchp-x653/GHSA-2x4q-vchp-x653.json +++ b/advisories/unreviewed/2023/08/GHSA-2x4q-vchp-x653/GHSA-2x4q-vchp-x653.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2x4q-vchp-x653", - "modified": "2023-08-03T06:30:23Z", + "modified": "2023-08-08T18:30:34Z", "published": "2023-08-03T06:30:23Z", "aliases": [ "CVE-2023-38747" ], "details": "Heap-based buffer overflow vulnerability exists in CX-Programmer Included in CX-One CXONE-AL[][]D-V4 V9.80 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code execution may occur.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/08/GHSA-32hv-227c-chpv/GHSA-32hv-227c-chpv.json b/advisories/unreviewed/2023/08/GHSA-32hv-227c-chpv/GHSA-32hv-227c-chpv.json new file mode 100644 index 00000000000..39bba769897 --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-32hv-227c-chpv/GHSA-32hv-227c-chpv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-32hv-227c-chpv", + "modified": "2023-08-08T18:30:37Z", + "published": "2023-08-08T18:30:37Z", + "aliases": [ + "CVE-2023-36905" + ], + "details": "Windows Wireless Wide Area Network Service (WwanSvc) Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36905" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36905" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-333g-8frm-xc2h/GHSA-333g-8frm-xc2h.json b/advisories/unreviewed/2023/08/GHSA-333g-8frm-xc2h/GHSA-333g-8frm-xc2h.json new file mode 100644 index 00000000000..8ed9408cb74 --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-333g-8frm-xc2h/GHSA-333g-8frm-xc2h.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-333g-8frm-xc2h", + "modified": "2023-08-08T18:30:35Z", + "published": "2023-08-08T18:30:35Z", + "aliases": [ + "CVE-2023-38762" + ], + "details": "SQL injection vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to obtain sensitive information via the friendmonths parameter within the /QueryView.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38762" + }, + { + "type": "WEB", + "url": "https://churchcrm.io/" + }, + { + "type": "WEB", + "url": "https://demo.churchcrm.io/master" + }, + { + "type": "WEB", + "url": "https://github.com/0x72303074/CVE-Disclosures" + }, + { + "type": "WEB", + "url": "https://github.com/ChurchCRM/CRM/wiki" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-3457-9p37-3w4q/GHSA-3457-9p37-3w4q.json b/advisories/unreviewed/2023/08/GHSA-3457-9p37-3w4q/GHSA-3457-9p37-3w4q.json new file mode 100644 index 00000000000..b8aac383761 --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-3457-9p37-3w4q/GHSA-3457-9p37-3w4q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3457-9p37-3w4q", + "modified": "2023-08-08T18:30:36Z", + "published": "2023-08-08T18:30:36Z", + "aliases": [ + "CVE-2023-36866" + ], + "details": "Microsoft Office Visio Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36866" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36866" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-35wh-q52w-78vq/GHSA-35wh-q52w-78vq.json b/advisories/unreviewed/2023/08/GHSA-35wh-q52w-78vq/GHSA-35wh-q52w-78vq.json new file mode 100644 index 00000000000..de523ac87d9 --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-35wh-q52w-78vq/GHSA-35wh-q52w-78vq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-35wh-q52w-78vq", + "modified": "2023-08-08T18:30:37Z", + "published": "2023-08-08T18:30:37Z", + "aliases": [ + "CVE-2023-38172" + ], + "details": "Microsoft Message Queuing Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38172" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-38172" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-3cqw-w427-m45x/GHSA-3cqw-w427-m45x.json b/advisories/unreviewed/2023/08/GHSA-3cqw-w427-m45x/GHSA-3cqw-w427-m45x.json index a6d277d5b9f..e8d4583aaef 100644 --- a/advisories/unreviewed/2023/08/GHSA-3cqw-w427-m45x/GHSA-3cqw-w427-m45x.json +++ b/advisories/unreviewed/2023/08/GHSA-3cqw-w427-m45x/GHSA-3cqw-w427-m45x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3cqw-w427-m45x", - "modified": "2023-08-03T06:30:23Z", + "modified": "2023-08-08T18:30:35Z", "published": "2023-08-03T06:30:23Z", "aliases": [ "CVE-2023-38748" ], "details": "Use after free vulnerability exists in CX-Programmer Included in CX-One CXONE-AL[][]D-V4 V9.80 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code execution may occur.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/08/GHSA-3hhc-gfj2-qgg7/GHSA-3hhc-gfj2-qgg7.json b/advisories/unreviewed/2023/08/GHSA-3hhc-gfj2-qgg7/GHSA-3hhc-gfj2-qgg7.json new file mode 100644 index 00000000000..287f077a8b5 --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-3hhc-gfj2-qgg7/GHSA-3hhc-gfj2-qgg7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3hhc-gfj2-qgg7", + "modified": "2023-08-08T18:30:36Z", + "published": "2023-08-08T18:30:36Z", + "aliases": [ + "CVE-2023-36898" + ], + "details": "Tablet Windows User Interface Application Core Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36898" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36898" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-3jf9-p4gc-9h68/GHSA-3jf9-p4gc-9h68.json b/advisories/unreviewed/2023/08/GHSA-3jf9-p4gc-9h68/GHSA-3jf9-p4gc-9h68.json new file mode 100644 index 00000000000..2eddd0457a6 --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-3jf9-p4gc-9h68/GHSA-3jf9-p4gc-9h68.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3jf9-p4gc-9h68", + "modified": "2023-08-08T18:30:36Z", + "published": "2023-08-08T18:30:36Z", + "aliases": [ + "CVE-2023-36540" + ], + "details": "Untrusted search path in the installer for Zoom Desktop Client for Windows before 5.14.5 may allow an authenticated user to enable an escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36540" + }, + { + "type": "WEB", + "url": "https://explore.zoom.us/en/trust/security/security-bulletin/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-426" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-3vj2-7455-cq23/GHSA-3vj2-7455-cq23.json b/advisories/unreviewed/2023/08/GHSA-3vj2-7455-cq23/GHSA-3vj2-7455-cq23.json new file mode 100644 index 00000000000..182413b9bfe --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-3vj2-7455-cq23/GHSA-3vj2-7455-cq23.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3vj2-7455-cq23", + "modified": "2023-08-08T18:30:36Z", + "published": "2023-08-08T18:30:36Z", + "aliases": [ + "CVE-2023-35380" + ], + "details": "Windows Kernel Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35380" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-35380" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-4m6r-h473-x99p/GHSA-4m6r-h473-x99p.json b/advisories/unreviewed/2023/08/GHSA-4m6r-h473-x99p/GHSA-4m6r-h473-x99p.json new file mode 100644 index 00000000000..84b282f2ccb --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-4m6r-h473-x99p/GHSA-4m6r-h473-x99p.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4m6r-h473-x99p", + "modified": "2023-08-08T18:30:35Z", + "published": "2023-08-08T18:30:35Z", + "aliases": [ + "CVE-2023-38770" + ], + "details": "SQL injection vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to obtain sensitive information via the group parameter within the /QueryView.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38770" + }, + { + "type": "WEB", + "url": "https://churchcrm.io/" + }, + { + "type": "WEB", + "url": "https://demo.churchcrm.io/master" + }, + { + "type": "WEB", + "url": "https://github.com/0x72303074/CVE-Disclosures" + }, + { + "type": "WEB", + "url": "https://github.com/ChurchCRM/CRM/wiki" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-4mp8-95wg-7xm4/GHSA-4mp8-95wg-7xm4.json b/advisories/unreviewed/2023/08/GHSA-4mp8-95wg-7xm4/GHSA-4mp8-95wg-7xm4.json new file mode 100644 index 00000000000..6bcf47c44ea --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-4mp8-95wg-7xm4/GHSA-4mp8-95wg-7xm4.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4mp8-95wg-7xm4", + "modified": "2023-08-08T18:30:36Z", + "published": "2023-08-08T18:30:36Z", + "aliases": [ + "CVE-2023-20561" + ], + "details": "\n\n\n\n\n\n\nInsufficient validation of the IOCTL (Input Output Control) input buffer in AMD ?Prof may allow an authenticated user to send an arbitrary address potentially resulting in a Windows crash leading to denial of service.\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-20561" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-7003" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-4wv3-22h6-h824/GHSA-4wv3-22h6-h824.json b/advisories/unreviewed/2023/08/GHSA-4wv3-22h6-h824/GHSA-4wv3-22h6-h824.json new file mode 100644 index 00000000000..2f716226d0c --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-4wv3-22h6-h824/GHSA-4wv3-22h6-h824.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4wv3-22h6-h824", + "modified": "2023-08-08T18:30:37Z", + "published": "2023-08-08T18:30:37Z", + "aliases": [ + "CVE-2023-38182" + ], + "details": "Microsoft Exchange Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38182" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-38182" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-56r2-62gh-h7qr/GHSA-56r2-62gh-h7qr.json b/advisories/unreviewed/2023/08/GHSA-56r2-62gh-h7qr/GHSA-56r2-62gh-h7qr.json new file mode 100644 index 00000000000..cc83fa034c4 --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-56r2-62gh-h7qr/GHSA-56r2-62gh-h7qr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-56r2-62gh-h7qr", + "modified": "2023-08-08T18:30:37Z", + "published": "2023-08-08T18:30:37Z", + "aliases": [ + "CVE-2023-38175" + ], + "details": "Microsoft Windows Defender Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38175" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-38175" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-5qfj-773w-84hp/GHSA-5qfj-773w-84hp.json b/advisories/unreviewed/2023/08/GHSA-5qfj-773w-84hp/GHSA-5qfj-773w-84hp.json new file mode 100644 index 00000000000..f82771d50d4 --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-5qfj-773w-84hp/GHSA-5qfj-773w-84hp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5qfj-773w-84hp", + "modified": "2023-08-08T18:30:36Z", + "published": "2023-08-08T18:30:36Z", + "aliases": [ + "CVE-2023-35383" + ], + "details": "Microsoft Message Queuing Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35383" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-35383" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-5vgj-hqrc-gx52/GHSA-5vgj-hqrc-gx52.json b/advisories/unreviewed/2023/08/GHSA-5vgj-hqrc-gx52/GHSA-5vgj-hqrc-gx52.json new file mode 100644 index 00000000000..89494b5865d --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-5vgj-hqrc-gx52/GHSA-5vgj-hqrc-gx52.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5vgj-hqrc-gx52", + "modified": "2023-08-08T18:30:37Z", + "published": "2023-08-08T18:30:37Z", + "aliases": [ + "CVE-2023-36910" + ], + "details": "Microsoft Message Queuing Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36910" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36910" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-6672-m2hq-hwm4/GHSA-6672-m2hq-hwm4.json b/advisories/unreviewed/2023/08/GHSA-6672-m2hq-hwm4/GHSA-6672-m2hq-hwm4.json index 68a2a099aa7..68430262214 100644 --- a/advisories/unreviewed/2023/08/GHSA-6672-m2hq-hwm4/GHSA-6672-m2hq-hwm4.json +++ b/advisories/unreviewed/2023/08/GHSA-6672-m2hq-hwm4/GHSA-6672-m2hq-hwm4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6672-m2hq-hwm4", - "modified": "2023-08-02T00:30:39Z", + "modified": "2023-08-08T18:30:33Z", "published": "2023-08-02T00:30:39Z", "aliases": [ "CVE-2023-3494" ], "details": "The fwctl driver implements a state machine which is executed when a bhyve guest accesses certain x86 I/O ports. The interface lets the guest copy a string into a buffer resident in the bhyve process' memory. A bug in the state machine implementation can result in a buffer overflowing when copying this string. Malicious, privileged software running in a guest VM can exploit the buffer overflow to achieve code execution on the host in the bhyve userspace process, which typically runs as root, mitigated by the capabilities assigned through the Capsicum sandbox available to the bhyve process.\n\n\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/08/GHSA-68pc-r3j9-h8x2/GHSA-68pc-r3j9-h8x2.json b/advisories/unreviewed/2023/08/GHSA-68pc-r3j9-h8x2/GHSA-68pc-r3j9-h8x2.json new file mode 100644 index 00000000000..fa0cc4ebe3a --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-68pc-r3j9-h8x2/GHSA-68pc-r3j9-h8x2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-68pc-r3j9-h8x2", + "modified": "2023-08-08T18:30:37Z", + "published": "2023-08-08T18:30:37Z", + "aliases": [ + "CVE-2023-38184" + ], + "details": "Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38184" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-38184" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-68qp-hp65-rmrq/GHSA-68qp-hp65-rmrq.json b/advisories/unreviewed/2023/08/GHSA-68qp-hp65-rmrq/GHSA-68qp-hp65-rmrq.json new file mode 100644 index 00000000000..94b58d0c9d2 --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-68qp-hp65-rmrq/GHSA-68qp-hp65-rmrq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-68qp-hp65-rmrq", + "modified": "2023-08-08T18:30:36Z", + "published": "2023-08-08T18:30:36Z", + "aliases": [ + "CVE-2023-36890" + ], + "details": "Microsoft SharePoint Server Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36890" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36890" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-6cv5-8fpc-p4rh/GHSA-6cv5-8fpc-p4rh.json b/advisories/unreviewed/2023/08/GHSA-6cv5-8fpc-p4rh/GHSA-6cv5-8fpc-p4rh.json new file mode 100644 index 00000000000..ffff1e5cf2b --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-6cv5-8fpc-p4rh/GHSA-6cv5-8fpc-p4rh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6cv5-8fpc-p4rh", + "modified": "2023-08-08T18:30:37Z", + "published": "2023-08-08T18:30:37Z", + "aliases": [ + "CVE-2023-39216" + ], + "details": "Improper input validation in Zoom Desktop Client for Windows before 5.14.7 may allow an unauthenticated user to enable an escalation of privilege via network access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-39216" + }, + { + "type": "WEB", + "url": "https://explore.zoom.us/en/trust/security/security-bulletin/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-6f8c-2h4w-727p/GHSA-6f8c-2h4w-727p.json b/advisories/unreviewed/2023/08/GHSA-6f8c-2h4w-727p/GHSA-6f8c-2h4w-727p.json new file mode 100644 index 00000000000..c30782d1cef --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-6f8c-2h4w-727p/GHSA-6f8c-2h4w-727p.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6f8c-2h4w-727p", + "modified": "2023-08-08T18:30:35Z", + "published": "2023-08-08T18:30:35Z", + "aliases": [ + "CVE-2023-38761" + ], + "details": "Cross Site Scripting (XSS) vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to execute arbitrary code via a crafted payload to the systemSettings.php component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38761" + }, + { + "type": "WEB", + "url": "https://churchcrm.io/" + }, + { + "type": "WEB", + "url": "https://demo.churchcrm.io/master" + }, + { + "type": "WEB", + "url": "https://github.com/0x72303074/CVE-Disclosures" + }, + { + "type": "WEB", + "url": "https://github.com/ChurchCRM/CRM/wiki" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-6h77-2hc9-qm3w/GHSA-6h77-2hc9-qm3w.json b/advisories/unreviewed/2023/08/GHSA-6h77-2hc9-qm3w/GHSA-6h77-2hc9-qm3w.json new file mode 100644 index 00000000000..fa2a5e89333 --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-6h77-2hc9-qm3w/GHSA-6h77-2hc9-qm3w.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6h77-2hc9-qm3w", + "modified": "2023-08-08T18:30:36Z", + "published": "2023-08-08T18:30:36Z", + "aliases": [ + "CVE-2023-20588" + ], + "details": "\nA division-by-zero error on some AMD processors can potentially return speculative data resulting in loss of confidentiality. \n\n\n\n\n\n\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-20588" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-7007" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-7f8x-49jc-23pr/GHSA-7f8x-49jc-23pr.json b/advisories/unreviewed/2023/08/GHSA-7f8x-49jc-23pr/GHSA-7f8x-49jc-23pr.json new file mode 100644 index 00000000000..25d44c1b44f --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-7f8x-49jc-23pr/GHSA-7f8x-49jc-23pr.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7f8x-49jc-23pr", + "modified": "2023-08-08T18:30:35Z", + "published": "2023-08-08T18:30:35Z", + "aliases": [ + "CVE-2023-38766" + ], + "details": "Cross Site Scripting (XSS) vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to execute arbitrary code via a crafted payload to the PersonView.php component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38766" + }, + { + "type": "WEB", + "url": "https://churchcrm.io/" + }, + { + "type": "WEB", + "url": "https://demo.churchcrm.io/master" + }, + { + "type": "WEB", + "url": "https://github.com/0x72303074/CVE-Disclosures" + }, + { + "type": "WEB", + "url": "https://github.com/ChurchCRM/CRM/wiki" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-7fjv-53p8-9hhh/GHSA-7fjv-53p8-9hhh.json b/advisories/unreviewed/2023/08/GHSA-7fjv-53p8-9hhh/GHSA-7fjv-53p8-9hhh.json new file mode 100644 index 00000000000..8e371de9fcc --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-7fjv-53p8-9hhh/GHSA-7fjv-53p8-9hhh.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7fjv-53p8-9hhh", + "modified": "2023-08-08T18:30:36Z", + "published": "2023-08-08T18:30:36Z", + "aliases": [ + "CVE-2023-37646" + ], + "details": "An issue in the CAB file extraction function of Bitberry File Opener v23.0 allows attackers to execute a directory traversal.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37646" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Decamark/868e88aa6aae6b8f4a1dc1991efb83ca" + }, + { + "type": "WEB", + "url": "http://bitberry.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-7j77-rcrw-mhm8/GHSA-7j77-rcrw-mhm8.json b/advisories/unreviewed/2023/08/GHSA-7j77-rcrw-mhm8/GHSA-7j77-rcrw-mhm8.json new file mode 100644 index 00000000000..f06ce2be504 --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-7j77-rcrw-mhm8/GHSA-7j77-rcrw-mhm8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7j77-rcrw-mhm8", + "modified": "2023-08-08T18:30:36Z", + "published": "2023-08-08T18:30:36Z", + "aliases": [ + "CVE-2023-35376" + ], + "details": "Microsoft Message Queuing Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35376" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-35376" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-7p3x-w377-9pq7/GHSA-7p3x-w377-9pq7.json b/advisories/unreviewed/2023/08/GHSA-7p3x-w377-9pq7/GHSA-7p3x-w377-9pq7.json new file mode 100644 index 00000000000..474a24bfa5b --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-7p3x-w377-9pq7/GHSA-7p3x-w377-9pq7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7p3x-w377-9pq7", + "modified": "2023-08-08T18:30:36Z", + "published": "2023-08-08T18:30:36Z", + "aliases": [ + "CVE-2023-20556" + ], + "details": "\n\n\n\n\nInsufficient validation of the IOCTL (Input Output Control) input buffer in AMD ?Prof may allow an authenticated user to send an arbitrary buffer potentially resulting in a Windows crash leading to denial of service.\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-20556" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-7003" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-7q8x-6cwc-cx3j/GHSA-7q8x-6cwc-cx3j.json b/advisories/unreviewed/2023/08/GHSA-7q8x-6cwc-cx3j/GHSA-7q8x-6cwc-cx3j.json index f0ddbbb0275..a69e6533e34 100644 --- a/advisories/unreviewed/2023/08/GHSA-7q8x-6cwc-cx3j/GHSA-7q8x-6cwc-cx3j.json +++ b/advisories/unreviewed/2023/08/GHSA-7q8x-6cwc-cx3j/GHSA-7q8x-6cwc-cx3j.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-287", "CWE-305" ], "severity": null, diff --git a/advisories/unreviewed/2023/08/GHSA-7rh4-mff7-83p7/GHSA-7rh4-mff7-83p7.json b/advisories/unreviewed/2023/08/GHSA-7rh4-mff7-83p7/GHSA-7rh4-mff7-83p7.json new file mode 100644 index 00000000000..d800ab0f460 --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-7rh4-mff7-83p7/GHSA-7rh4-mff7-83p7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7rh4-mff7-83p7", + "modified": "2023-08-08T18:30:37Z", + "published": "2023-08-08T18:30:37Z", + "aliases": [ + "CVE-2023-38154" + ], + "details": "Windows Kernel Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38154" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-38154" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-7vm7-m762-pgv3/GHSA-7vm7-m762-pgv3.json b/advisories/unreviewed/2023/08/GHSA-7vm7-m762-pgv3/GHSA-7vm7-m762-pgv3.json new file mode 100644 index 00000000000..3efb1f63458 --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-7vm7-m762-pgv3/GHSA-7vm7-m762-pgv3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7vm7-m762-pgv3", + "modified": "2023-08-08T18:30:37Z", + "published": "2023-08-08T18:30:37Z", + "aliases": [ + "CVE-2023-38186" + ], + "details": "Windows Mobile Device Management Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38186" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-38186" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-7w82-6wqx-9r39/GHSA-7w82-6wqx-9r39.json b/advisories/unreviewed/2023/08/GHSA-7w82-6wqx-9r39/GHSA-7w82-6wqx-9r39.json new file mode 100644 index 00000000000..a7309d18f2a --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-7w82-6wqx-9r39/GHSA-7w82-6wqx-9r39.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7w82-6wqx-9r39", + "modified": "2023-08-08T18:30:36Z", + "published": "2023-08-08T18:30:36Z", + "aliases": [ + "CVE-2023-36882" + ], + "details": "Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36882" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36882" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-856f-5pr4-jx6q/GHSA-856f-5pr4-jx6q.json b/advisories/unreviewed/2023/08/GHSA-856f-5pr4-jx6q/GHSA-856f-5pr4-jx6q.json index 74032ef8976..cf46d0253dc 100644 --- a/advisories/unreviewed/2023/08/GHSA-856f-5pr4-jx6q/GHSA-856f-5pr4-jx6q.json +++ b/advisories/unreviewed/2023/08/GHSA-856f-5pr4-jx6q/GHSA-856f-5pr4-jx6q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-856f-5pr4-jx6q", - "modified": "2023-08-03T18:30:34Z", + "modified": "2023-08-08T18:30:35Z", "published": "2023-08-03T18:30:34Z", "aliases": [ "CVE-2023-25600" ], "details": "An issue was discovered in InsydeH2O. A malicious operating system can tamper with a runtime-writable EFI variable, leading to out-of-bounds memory reads and a denial of service. This is fixed in version 01.01.04.0016.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/08/GHSA-8c62-6wcm-89qf/GHSA-8c62-6wcm-89qf.json b/advisories/unreviewed/2023/08/GHSA-8c62-6wcm-89qf/GHSA-8c62-6wcm-89qf.json new file mode 100644 index 00000000000..d77db5a3cde --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-8c62-6wcm-89qf/GHSA-8c62-6wcm-89qf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8c62-6wcm-89qf", + "modified": "2023-08-08T18:30:36Z", + "published": "2023-08-08T18:30:36Z", + "aliases": [ + "CVE-2023-36877" + ], + "details": "Azure Apache Oozie Spoofing Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36877" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36877" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-8m9p-3926-gffr/GHSA-8m9p-3926-gffr.json b/advisories/unreviewed/2023/08/GHSA-8m9p-3926-gffr/GHSA-8m9p-3926-gffr.json new file mode 100644 index 00000000000..82e99bd3778 --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-8m9p-3926-gffr/GHSA-8m9p-3926-gffr.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8m9p-3926-gffr", + "modified": "2023-08-08T18:30:35Z", + "published": "2023-08-08T18:30:35Z", + "aliases": [ + "CVE-2023-38758" + ], + "details": "Cross Site Scripting vulnerability in wger Project wger Workout Manager v.2.2.0a3 allows a remote attacker to gain privileges via the license_author field in the add-ingredient function in the templates/ingredients/view.html, models/ingredients.py, and views/ingredients.py components.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38758" + }, + { + "type": "WEB", + "url": "https://github.com/0x72303074/CVE-Disclosures" + }, + { + "type": "WEB", + "url": "https://wger.de" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-8w6g-5xq3-hvc5/GHSA-8w6g-5xq3-hvc5.json b/advisories/unreviewed/2023/08/GHSA-8w6g-5xq3-hvc5/GHSA-8w6g-5xq3-hvc5.json new file mode 100644 index 00000000000..8065c88b49d --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-8w6g-5xq3-hvc5/GHSA-8w6g-5xq3-hvc5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8w6g-5xq3-hvc5", + "modified": "2023-08-08T18:30:36Z", + "published": "2023-08-08T18:30:36Z", + "aliases": [ + "CVE-2023-36541" + ], + "details": "Insufficient verification of data authenticity in Zoom Desktop Client for Windows before 5.14.5 may allow an authenticated user to enable an escalation of privilege via network access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36541" + }, + { + "type": "WEB", + "url": "https://explore.zoom.us/en/trust/security/security-bulletin/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-345" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-8w7q-cfxq-v32g/GHSA-8w7q-cfxq-v32g.json b/advisories/unreviewed/2023/08/GHSA-8w7q-cfxq-v32g/GHSA-8w7q-cfxq-v32g.json new file mode 100644 index 00000000000..2c0f8b7519b --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-8w7q-cfxq-v32g/GHSA-8w7q-cfxq-v32g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8w7q-cfxq-v32g", + "modified": "2023-08-08T18:30:36Z", + "published": "2023-08-08T18:30:36Z", + "aliases": [ + "CVE-2023-36897" + ], + "details": "Visual Studio Tools for Office Runtime Spoofing Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36897" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36897" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-95h7-qcfp-8mx9/GHSA-95h7-qcfp-8mx9.json b/advisories/unreviewed/2023/08/GHSA-95h7-qcfp-8mx9/GHSA-95h7-qcfp-8mx9.json new file mode 100644 index 00000000000..6d519cfce03 --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-95h7-qcfp-8mx9/GHSA-95h7-qcfp-8mx9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-95h7-qcfp-8mx9", + "modified": "2023-08-08T18:30:36Z", + "published": "2023-08-08T18:30:36Z", + "aliases": [ + "CVE-2023-36881" + ], + "details": "Azure Apache Ambari Spoofing Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36881" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36881" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-9f52-rmc2-c4c7/GHSA-9f52-rmc2-c4c7.json b/advisories/unreviewed/2023/08/GHSA-9f52-rmc2-c4c7/GHSA-9f52-rmc2-c4c7.json index 51956892fe0..446374c79bf 100644 --- a/advisories/unreviewed/2023/08/GHSA-9f52-rmc2-c4c7/GHSA-9f52-rmc2-c4c7.json +++ b/advisories/unreviewed/2023/08/GHSA-9f52-rmc2-c4c7/GHSA-9f52-rmc2-c4c7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9f52-rmc2-c4c7", - "modified": "2023-08-03T06:30:23Z", + "modified": "2023-08-08T18:30:34Z", "published": "2023-08-03T06:30:23Z", "aliases": [ "CVE-2023-38746" ], "details": "Out-of-bounds read vulnerability/issue exists in CX-Programmer Included in CX-One CXONE-AL[][]D-V4 V9.80 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code execution may occur.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/08/GHSA-9gpg-63cp-jr3x/GHSA-9gpg-63cp-jr3x.json b/advisories/unreviewed/2023/08/GHSA-9gpg-63cp-jr3x/GHSA-9gpg-63cp-jr3x.json new file mode 100644 index 00000000000..a8d5e758251 --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-9gpg-63cp-jr3x/GHSA-9gpg-63cp-jr3x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9gpg-63cp-jr3x", + "modified": "2023-08-08T18:30:36Z", + "published": "2023-08-08T18:30:36Z", + "aliases": [ + "CVE-2023-35368" + ], + "details": "Microsoft Exchange Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35368" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-35368" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-9j64-pxww-55vc/GHSA-9j64-pxww-55vc.json b/advisories/unreviewed/2023/08/GHSA-9j64-pxww-55vc/GHSA-9j64-pxww-55vc.json new file mode 100644 index 00000000000..e1b9437ef8f --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-9j64-pxww-55vc/GHSA-9j64-pxww-55vc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9j64-pxww-55vc", + "modified": "2023-08-08T18:30:37Z", + "published": "2023-08-08T18:30:37Z", + "aliases": [ + "CVE-2023-38167" + ], + "details": "Microsoft Dynamics Business Central Elevation Of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38167" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-38167" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-9wg5-4w44-rm5v/GHSA-9wg5-4w44-rm5v.json b/advisories/unreviewed/2023/08/GHSA-9wg5-4w44-rm5v/GHSA-9wg5-4w44-rm5v.json index 1bebff9af69..77f83f098c6 100644 --- a/advisories/unreviewed/2023/08/GHSA-9wg5-4w44-rm5v/GHSA-9wg5-4w44-rm5v.json +++ b/advisories/unreviewed/2023/08/GHSA-9wg5-4w44-rm5v/GHSA-9wg5-4w44-rm5v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9wg5-4w44-rm5v", - "modified": "2023-08-03T18:30:35Z", + "modified": "2023-08-08T18:30:35Z", "published": "2023-08-03T18:30:35Z", "aliases": [ "CVE-2023-32764" ], "details": "Fabasoft Cloud Enterprise Client 23.3.0.130 allows a user to escalate their privileges to local administrator.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/08/GHSA-c3g4-pf6v-r7hx/GHSA-c3g4-pf6v-r7hx.json b/advisories/unreviewed/2023/08/GHSA-c3g4-pf6v-r7hx/GHSA-c3g4-pf6v-r7hx.json new file mode 100644 index 00000000000..0991dade1dd --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-c3g4-pf6v-r7hx/GHSA-c3g4-pf6v-r7hx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c3g4-pf6v-r7hx", + "modified": "2023-08-08T18:30:36Z", + "published": "2023-08-08T18:30:36Z", + "aliases": [ + "CVE-2023-35372" + ], + "details": "Microsoft Office Visio Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35372" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-35372" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-c662-mp4g-c23j/GHSA-c662-mp4g-c23j.json b/advisories/unreviewed/2023/08/GHSA-c662-mp4g-c23j/GHSA-c662-mp4g-c23j.json new file mode 100644 index 00000000000..4ac64130c5b --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-c662-mp4g-c23j/GHSA-c662-mp4g-c23j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c662-mp4g-c23j", + "modified": "2023-08-08T18:30:36Z", + "published": "2023-08-08T18:30:36Z", + "aliases": [ + "CVE-2023-35378" + ], + "details": "Windows Projected File System Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35378" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-35378" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-c6w6-vvhg-83vr/GHSA-c6w6-vvhg-83vr.json b/advisories/unreviewed/2023/08/GHSA-c6w6-vvhg-83vr/GHSA-c6w6-vvhg-83vr.json new file mode 100644 index 00000000000..a6045d84c18 --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-c6w6-vvhg-83vr/GHSA-c6w6-vvhg-83vr.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c6w6-vvhg-83vr", + "modified": "2023-08-08T18:30:36Z", + "published": "2023-08-08T18:30:36Z", + "aliases": [ + "CVE-2023-20586" + ], + "details": "\nA potential vulnerability was reported in Radeon™ Software Crimson ReLive Edition which may allow escalation of privilege. Radeon™ Software Crimson ReLive Edition falls outside of the security support lifecycle and AMD does not plan to release any mitigations\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-20586" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-6007" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-ccq3-436r-c3g8/GHSA-ccq3-436r-c3g8.json b/advisories/unreviewed/2023/08/GHSA-ccq3-436r-c3g8/GHSA-ccq3-436r-c3g8.json new file mode 100644 index 00000000000..11043851250 --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-ccq3-436r-c3g8/GHSA-ccq3-436r-c3g8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ccq3-436r-c3g8", + "modified": "2023-08-08T18:30:36Z", + "published": "2023-08-08T18:30:36Z", + "aliases": [ + "CVE-2023-36892" + ], + "details": "Microsoft SharePoint Server Spoofing Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36892" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36892" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-cgvx-gc8r-995f/GHSA-cgvx-gc8r-995f.json b/advisories/unreviewed/2023/08/GHSA-cgvx-gc8r-995f/GHSA-cgvx-gc8r-995f.json new file mode 100644 index 00000000000..6f7902b5deb --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-cgvx-gc8r-995f/GHSA-cgvx-gc8r-995f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cgvx-gc8r-995f", + "modified": "2023-08-08T18:30:36Z", + "published": "2023-08-08T18:30:36Z", + "aliases": [ + "CVE-2023-36876" + ], + "details": "Reliability Analysis Metrics Calculation (RacTask) Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36876" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36876" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-cpgq-9v8g-4fxq/GHSA-cpgq-9v8g-4fxq.json b/advisories/unreviewed/2023/08/GHSA-cpgq-9v8g-4fxq/GHSA-cpgq-9v8g-4fxq.json new file mode 100644 index 00000000000..4af6ca10bed --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-cpgq-9v8g-4fxq/GHSA-cpgq-9v8g-4fxq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cpgq-9v8g-4fxq", + "modified": "2023-08-08T18:30:36Z", + "published": "2023-08-08T18:30:36Z", + "aliases": [ + "CVE-2023-36895" + ], + "details": "Microsoft Outlook Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36895" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36895" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-cq3m-ggcc-x7v9/GHSA-cq3m-ggcc-x7v9.json b/advisories/unreviewed/2023/08/GHSA-cq3m-ggcc-x7v9/GHSA-cq3m-ggcc-x7v9.json new file mode 100644 index 00000000000..fa6adc564e4 --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-cq3m-ggcc-x7v9/GHSA-cq3m-ggcc-x7v9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cq3m-ggcc-x7v9", + "modified": "2023-08-08T18:30:36Z", + "published": "2023-08-08T18:30:36Z", + "aliases": [ + "CVE-2023-3522" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in a2 License Portal System allows SQL Injection.This issue affects License Portal System: before 1.48.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3522" + }, + { + "type": "WEB", + "url": "https://www.usom.gov.tr/bildirim/tr-23-0445" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-crf4-cpc3-935q/GHSA-crf4-cpc3-935q.json b/advisories/unreviewed/2023/08/GHSA-crf4-cpc3-935q/GHSA-crf4-cpc3-935q.json new file mode 100644 index 00000000000..962b0265677 --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-crf4-cpc3-935q/GHSA-crf4-cpc3-935q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-crf4-cpc3-935q", + "modified": "2023-08-08T18:30:37Z", + "published": "2023-08-08T18:30:37Z", + "aliases": [ + "CVE-2023-36903" + ], + "details": "Windows System Assessment Tool Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36903" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36903" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-cw67-2mcx-5p7m/GHSA-cw67-2mcx-5p7m.json b/advisories/unreviewed/2023/08/GHSA-cw67-2mcx-5p7m/GHSA-cw67-2mcx-5p7m.json new file mode 100644 index 00000000000..3c8c084cd79 --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-cw67-2mcx-5p7m/GHSA-cw67-2mcx-5p7m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cw67-2mcx-5p7m", + "modified": "2023-08-08T18:30:36Z", + "published": "2023-08-08T18:30:36Z", + "aliases": [ + "CVE-2023-35382" + ], + "details": "Windows Kernel Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35382" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-35382" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-cwxh-83m5-5h37/GHSA-cwxh-83m5-5h37.json b/advisories/unreviewed/2023/08/GHSA-cwxh-83m5-5h37/GHSA-cwxh-83m5-5h37.json new file mode 100644 index 00000000000..94fc16a26d2 --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-cwxh-83m5-5h37/GHSA-cwxh-83m5-5h37.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cwxh-83m5-5h37", + "modified": "2023-08-08T18:30:37Z", + "published": "2023-08-08T18:30:37Z", + "aliases": [ + "CVE-2023-36912" + ], + "details": "Microsoft Message Queuing Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36912" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36912" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-f4r6-49fh-5c4m/GHSA-f4r6-49fh-5c4m.json b/advisories/unreviewed/2023/08/GHSA-f4r6-49fh-5c4m/GHSA-f4r6-49fh-5c4m.json new file mode 100644 index 00000000000..55021c1b6bb --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-f4r6-49fh-5c4m/GHSA-f4r6-49fh-5c4m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f4r6-49fh-5c4m", + "modified": "2023-08-08T18:30:37Z", + "published": "2023-08-08T18:30:37Z", + "aliases": [ + "CVE-2023-36908" + ], + "details": "Windows Hyper-V Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36908" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36908" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-f5cr-mp3h-4jjj/GHSA-f5cr-mp3h-4jjj.json b/advisories/unreviewed/2023/08/GHSA-f5cr-mp3h-4jjj/GHSA-f5cr-mp3h-4jjj.json new file mode 100644 index 00000000000..d6909293c52 --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-f5cr-mp3h-4jjj/GHSA-f5cr-mp3h-4jjj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f5cr-mp3h-4jjj", + "modified": "2023-08-08T18:30:36Z", + "published": "2023-08-08T18:30:36Z", + "aliases": [ + "CVE-2023-36533" + ], + "details": "Uncontrolled resource consumption in Zoom SDKs before 5.14.7 may allow an unauthenticated user to enable a denial of service via network access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36533" + }, + { + "type": "WEB", + "url": "https://explore.zoom.us/en/trust/security/security-bulletin/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-f6f3-rrm8-q5r8/GHSA-f6f3-rrm8-q5r8.json b/advisories/unreviewed/2023/08/GHSA-f6f3-rrm8-q5r8/GHSA-f6f3-rrm8-q5r8.json new file mode 100644 index 00000000000..85f7398af55 --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-f6f3-rrm8-q5r8/GHSA-f6f3-rrm8-q5r8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f6f3-rrm8-q5r8", + "modified": "2023-08-08T18:30:36Z", + "published": "2023-08-08T18:30:36Z", + "aliases": [ + "CVE-2023-20562" + ], + "details": "\n\n\nInsufficient validation in the IOCTL (Input Output Control) input buffer in AMD uProf may allow an authenticated user to load an unsigned driver potentially leading to arbitrary kernel execution.\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-20562" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-7003" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-f6h3-4j54-4g5g/GHSA-f6h3-4j54-4g5g.json b/advisories/unreviewed/2023/08/GHSA-f6h3-4j54-4g5g/GHSA-f6h3-4j54-4g5g.json new file mode 100644 index 00000000000..270a1095399 --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-f6h3-4j54-4g5g/GHSA-f6h3-4j54-4g5g.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f6h3-4j54-4g5g", + "modified": "2023-08-08T18:30:35Z", + "published": "2023-08-08T18:30:35Z", + "aliases": [ + "CVE-2023-38764" + ], + "details": "SQL injection vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to obtain sensitive information via the birthmonth and percls parameters within the /QueryView.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38764" + }, + { + "type": "WEB", + "url": "https://churchcrm.io/" + }, + { + "type": "WEB", + "url": "https://demo.churchcrm.io/master" + }, + { + "type": "WEB", + "url": "https://github.com/0x72303074/CVE-Disclosures" + }, + { + "type": "WEB", + "url": "https://github.com/ChurchCRM/CRM/wiki" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-f6j6-4j57-f83g/GHSA-f6j6-4j57-f83g.json b/advisories/unreviewed/2023/08/GHSA-f6j6-4j57-f83g/GHSA-f6j6-4j57-f83g.json new file mode 100644 index 00000000000..e364167b58a --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-f6j6-4j57-f83g/GHSA-f6j6-4j57-f83g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f6j6-4j57-f83g", + "modified": "2023-08-08T18:30:36Z", + "published": "2023-08-08T18:30:36Z", + "aliases": [ + "CVE-2023-35359" + ], + "details": "Windows Kernel Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35359" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-35359" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-fff5-q99h-fmwq/GHSA-fff5-q99h-fmwq.json b/advisories/unreviewed/2023/08/GHSA-fff5-q99h-fmwq/GHSA-fff5-q99h-fmwq.json new file mode 100644 index 00000000000..b97df219bf2 --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-fff5-q99h-fmwq/GHSA-fff5-q99h-fmwq.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fff5-q99h-fmwq", + "modified": "2023-08-08T18:30:35Z", + "published": "2023-08-08T18:30:35Z", + "aliases": [ + "CVE-2023-38771" + ], + "details": "SQL injection vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to obtain sensitive information via the volopp parameter within the /QueryView.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38771" + }, + { + "type": "WEB", + "url": "https://churchcrm.io/" + }, + { + "type": "WEB", + "url": "https://demo.churchcrm.io/master" + }, + { + "type": "WEB", + "url": "https://github.com/0x72303074/CVE-Disclosures" + }, + { + "type": "WEB", + "url": "https://github.com/ChurchCRM/CRM/wiki" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-fg32-9w38-fj64/GHSA-fg32-9w38-fj64.json b/advisories/unreviewed/2023/08/GHSA-fg32-9w38-fj64/GHSA-fg32-9w38-fj64.json new file mode 100644 index 00000000000..1c64c951de6 --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-fg32-9w38-fj64/GHSA-fg32-9w38-fj64.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fg32-9w38-fj64", + "modified": "2023-08-08T18:30:35Z", + "published": "2023-08-08T18:30:35Z", + "aliases": [ + "CVE-2023-3386" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in a2 Camera Trap Tracking System allows SQL Injection.This issue affects Camera Trap Tracking System: before 3.1905.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3386" + }, + { + "type": "WEB", + "url": "https://www.usom.gov.tr/bildirim/tr-23-0444" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-fhv3-5p89-vfc8/GHSA-fhv3-5p89-vfc8.json b/advisories/unreviewed/2023/08/GHSA-fhv3-5p89-vfc8/GHSA-fhv3-5p89-vfc8.json new file mode 100644 index 00000000000..df252eb673c --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-fhv3-5p89-vfc8/GHSA-fhv3-5p89-vfc8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fhv3-5p89-vfc8", + "modified": "2023-08-08T18:30:36Z", + "published": "2023-08-08T18:30:36Z", + "aliases": [ + "CVE-2023-35386" + ], + "details": "Windows Kernel Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35386" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-35386" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-fmj9-qf8f-cprj/GHSA-fmj9-qf8f-cprj.json b/advisories/unreviewed/2023/08/GHSA-fmj9-qf8f-cprj/GHSA-fmj9-qf8f-cprj.json new file mode 100644 index 00000000000..c2a63f91f12 --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-fmj9-qf8f-cprj/GHSA-fmj9-qf8f-cprj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fmj9-qf8f-cprj", + "modified": "2023-08-08T18:30:37Z", + "published": "2023-08-08T18:30:37Z", + "aliases": [ + "CVE-2023-36904" + ], + "details": "Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36904" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36904" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-fqp6-q28m-cfjh/GHSA-fqp6-q28m-cfjh.json b/advisories/unreviewed/2023/08/GHSA-fqp6-q28m-cfjh/GHSA-fqp6-q28m-cfjh.json new file mode 100644 index 00000000000..95c64eb5ab2 --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-fqp6-q28m-cfjh/GHSA-fqp6-q28m-cfjh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fqp6-q28m-cfjh", + "modified": "2023-08-08T18:30:36Z", + "published": "2023-08-08T18:30:36Z", + "aliases": [ + "CVE-2023-35379" + ], + "details": "Reliability Analysis Metrics Calculation Engine (RACEng) Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35379" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-35379" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-g48h-r36w-jj6x/GHSA-g48h-r36w-jj6x.json b/advisories/unreviewed/2023/08/GHSA-g48h-r36w-jj6x/GHSA-g48h-r36w-jj6x.json new file mode 100644 index 00000000000..3d9bbb7476d --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-g48h-r36w-jj6x/GHSA-g48h-r36w-jj6x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g48h-r36w-jj6x", + "modified": "2023-08-08T18:30:36Z", + "published": "2023-08-08T18:30:36Z", + "aliases": [ + "CVE-2023-36534" + ], + "details": "Path traversal in Zoom Desktop Client for Windows before 5.14.7 may allow an unauthenticated user to enable an escalation of privilege via network access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36534" + }, + { + "type": "WEB", + "url": "https://explore.zoom.us/en/trust/security/security-bulletin/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-g53f-59qq-gfh7/GHSA-g53f-59qq-gfh7.json b/advisories/unreviewed/2023/08/GHSA-g53f-59qq-gfh7/GHSA-g53f-59qq-gfh7.json new file mode 100644 index 00000000000..497091214e1 --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-g53f-59qq-gfh7/GHSA-g53f-59qq-gfh7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g53f-59qq-gfh7", + "modified": "2023-08-08T18:30:36Z", + "published": "2023-08-08T18:30:36Z", + "aliases": [ + "CVE-2023-36893" + ], + "details": "Microsoft Outlook Spoofing Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36893" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36893" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-gfcr-pv59-q6p8/GHSA-gfcr-pv59-q6p8.json b/advisories/unreviewed/2023/08/GHSA-gfcr-pv59-q6p8/GHSA-gfcr-pv59-q6p8.json new file mode 100644 index 00000000000..5e9477a4099 --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-gfcr-pv59-q6p8/GHSA-gfcr-pv59-q6p8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gfcr-pv59-q6p8", + "modified": "2023-08-08T18:30:36Z", + "published": "2023-08-08T18:30:36Z", + "aliases": [ + "CVE-2023-35393" + ], + "details": "Azure Apache Hive Spoofing Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35393" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-35393" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-gx47-2cwv-p7wc/GHSA-gx47-2cwv-p7wc.json b/advisories/unreviewed/2023/08/GHSA-gx47-2cwv-p7wc/GHSA-gx47-2cwv-p7wc.json new file mode 100644 index 00000000000..f09845a1b33 --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-gx47-2cwv-p7wc/GHSA-gx47-2cwv-p7wc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gx47-2cwv-p7wc", + "modified": "2023-08-08T18:30:37Z", + "published": "2023-08-08T18:30:37Z", + "aliases": [ + "CVE-2023-38176" + ], + "details": "Azure Arc-Enabled Servers Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38176" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-38176" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-h45c-25x4-6qq4/GHSA-h45c-25x4-6qq4.json b/advisories/unreviewed/2023/08/GHSA-h45c-25x4-6qq4/GHSA-h45c-25x4-6qq4.json new file mode 100644 index 00000000000..1d84b2522db --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-h45c-25x4-6qq4/GHSA-h45c-25x4-6qq4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h45c-25x4-6qq4", + "modified": "2023-08-08T18:30:37Z", + "published": "2023-08-08T18:30:37Z", + "aliases": [ + "CVE-2023-39217" + ], + "details": "Improper input validation in Zoom SDK’s before 5.14.10 may allow an unauthenticated user to enable a denial of service via network access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-39217" + }, + { + "type": "WEB", + "url": "https://explore.zoom.us/en/trust/security/security-bulletin/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-h4f6-pvrq-rcr4/GHSA-h4f6-pvrq-rcr4.json b/advisories/unreviewed/2023/08/GHSA-h4f6-pvrq-rcr4/GHSA-h4f6-pvrq-rcr4.json new file mode 100644 index 00000000000..02f0ecb17a4 --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-h4f6-pvrq-rcr4/GHSA-h4f6-pvrq-rcr4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h4f6-pvrq-rcr4", + "modified": "2023-08-08T18:30:37Z", + "published": "2023-08-08T18:30:37Z", + "aliases": [ + "CVE-2023-38188" + ], + "details": "Azure Apache Hadoop Spoofing Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38188" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-38188" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-hcf3-whvg-qpfq/GHSA-hcf3-whvg-qpfq.json b/advisories/unreviewed/2023/08/GHSA-hcf3-whvg-qpfq/GHSA-hcf3-whvg-qpfq.json new file mode 100644 index 00000000000..396b0a3d641 --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-hcf3-whvg-qpfq/GHSA-hcf3-whvg-qpfq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hcf3-whvg-qpfq", + "modified": "2023-08-08T18:30:37Z", + "published": "2023-08-08T18:30:37Z", + "aliases": [ + "CVE-2023-39218" + ], + "details": "Client-side enforcement of server-side security in Zoom clients before 5.14.10 may allow a privileged user to enable information disclosure via network access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-39218" + }, + { + "type": "WEB", + "url": "https://explore.zoom.us/en/trust/security/security-bulletin/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-602" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-hfm3-j43v-9h2m/GHSA-hfm3-j43v-9h2m.json b/advisories/unreviewed/2023/08/GHSA-hfm3-j43v-9h2m/GHSA-hfm3-j43v-9h2m.json new file mode 100644 index 00000000000..fe5eac1f48b --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-hfm3-j43v-9h2m/GHSA-hfm3-j43v-9h2m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hfm3-j43v-9h2m", + "modified": "2023-08-08T18:30:37Z", + "published": "2023-08-08T18:30:37Z", + "aliases": [ + "CVE-2023-36914" + ], + "details": "Windows Smart Card Resource Management Server Security Feature Bypass Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36914" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36914" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-hh4j-cm3f-5mf6/GHSA-hh4j-cm3f-5mf6.json b/advisories/unreviewed/2023/08/GHSA-hh4j-cm3f-5mf6/GHSA-hh4j-cm3f-5mf6.json new file mode 100644 index 00000000000..07ecbff2f97 --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-hh4j-cm3f-5mf6/GHSA-hh4j-cm3f-5mf6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hh4j-cm3f-5mf6", + "modified": "2023-08-08T18:30:37Z", + "published": "2023-08-08T18:30:37Z", + "aliases": [ + "CVE-2023-38254" + ], + "details": "Microsoft Message Queuing Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38254" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-38254" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-hw2m-jwjq-p5v6/GHSA-hw2m-jwjq-p5v6.json b/advisories/unreviewed/2023/08/GHSA-hw2m-jwjq-p5v6/GHSA-hw2m-jwjq-p5v6.json new file mode 100644 index 00000000000..17801715f19 --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-hw2m-jwjq-p5v6/GHSA-hw2m-jwjq-p5v6.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hw2m-jwjq-p5v6", + "modified": "2023-08-08T18:30:35Z", + "published": "2023-08-08T18:30:35Z", + "aliases": [ + "CVE-2023-38773" + ], + "details": "SQL injection vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to obtain sensitive information via the volopp1 and volopp2 parameters within the /QueryView.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38773" + }, + { + "type": "WEB", + "url": "https://churchcrm.io/" + }, + { + "type": "WEB", + "url": "https://demo.churchcrm.io/master" + }, + { + "type": "WEB", + "url": "https://github.com/0x72303074/CVE-Disclosures" + }, + { + "type": "WEB", + "url": "https://github.com/ChurchCRM/CRM/wiki" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-hwv5-c9xr-g79c/GHSA-hwv5-c9xr-g79c.json b/advisories/unreviewed/2023/08/GHSA-hwv5-c9xr-g79c/GHSA-hwv5-c9xr-g79c.json new file mode 100644 index 00000000000..20d8f0ee537 --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-hwv5-c9xr-g79c/GHSA-hwv5-c9xr-g79c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hwv5-c9xr-g79c", + "modified": "2023-08-08T18:30:36Z", + "published": "2023-08-08T18:30:36Z", + "aliases": [ + "CVE-2023-36896" + ], + "details": "Microsoft Excel Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36896" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36896" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-hx37-jpgw-mp7v/GHSA-hx37-jpgw-mp7v.json b/advisories/unreviewed/2023/08/GHSA-hx37-jpgw-mp7v/GHSA-hx37-jpgw-mp7v.json new file mode 100644 index 00000000000..22c7fd3f525 --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-hx37-jpgw-mp7v/GHSA-hx37-jpgw-mp7v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hx37-jpgw-mp7v", + "modified": "2023-08-08T18:30:37Z", + "published": "2023-08-08T18:30:37Z", + "aliases": [ + "CVE-2023-38181" + ], + "details": "Microsoft Exchange Server Spoofing Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38181" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-38181" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-hxpc-gw6v-6gwc/GHSA-hxpc-gw6v-6gwc.json b/advisories/unreviewed/2023/08/GHSA-hxpc-gw6v-6gwc/GHSA-hxpc-gw6v-6gwc.json new file mode 100644 index 00000000000..31d65404d5d --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-hxpc-gw6v-6gwc/GHSA-hxpc-gw6v-6gwc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hxpc-gw6v-6gwc", + "modified": "2023-08-08T18:30:37Z", + "published": "2023-08-08T18:30:37Z", + "aliases": [ + "CVE-2023-36913" + ], + "details": "Microsoft Message Queuing Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36913" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36913" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-j3hx-c9h6-63vv/GHSA-j3hx-c9h6-63vv.json b/advisories/unreviewed/2023/08/GHSA-j3hx-c9h6-63vv/GHSA-j3hx-c9h6-63vv.json new file mode 100644 index 00000000000..9de401fe5e9 --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-j3hx-c9h6-63vv/GHSA-j3hx-c9h6-63vv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j3hx-c9h6-63vv", + "modified": "2023-08-08T18:30:36Z", + "published": "2023-08-08T18:30:36Z", + "aliases": [ + "CVE-2023-36889" + ], + "details": "Windows Group Policy Security Feature Bypass Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36889" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36889" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-j5pp-wfmg-q9jp/GHSA-j5pp-wfmg-q9jp.json b/advisories/unreviewed/2023/08/GHSA-j5pp-wfmg-q9jp/GHSA-j5pp-wfmg-q9jp.json new file mode 100644 index 00000000000..09e717b3099 --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-j5pp-wfmg-q9jp/GHSA-j5pp-wfmg-q9jp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j5pp-wfmg-q9jp", + "modified": "2023-08-08T18:30:37Z", + "published": "2023-08-08T18:30:37Z", + "aliases": [ + "CVE-2023-38185" + ], + "details": "Microsoft Exchange Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38185" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-38185" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-j82f-chfp-3hrg/GHSA-j82f-chfp-3hrg.json b/advisories/unreviewed/2023/08/GHSA-j82f-chfp-3hrg/GHSA-j82f-chfp-3hrg.json new file mode 100644 index 00000000000..740ee2aa585 --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-j82f-chfp-3hrg/GHSA-j82f-chfp-3hrg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j82f-chfp-3hrg", + "modified": "2023-08-08T18:30:36Z", + "published": "2023-08-08T18:30:36Z", + "aliases": [ + "CVE-2023-35377" + ], + "details": "Microsoft Message Queuing Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35377" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-35377" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-jgvj-jh34-hqv3/GHSA-jgvj-jh34-hqv3.json b/advisories/unreviewed/2023/08/GHSA-jgvj-jh34-hqv3/GHSA-jgvj-jh34-hqv3.json index f88e0b3c64c..6c9908b995b 100644 --- a/advisories/unreviewed/2023/08/GHSA-jgvj-jh34-hqv3/GHSA-jgvj-jh34-hqv3.json +++ b/advisories/unreviewed/2023/08/GHSA-jgvj-jh34-hqv3/GHSA-jgvj-jh34-hqv3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jgvj-jh34-hqv3", - "modified": "2023-08-03T00:30:15Z", + "modified": "2023-08-08T18:30:34Z", "published": "2023-08-03T00:30:15Z", "aliases": [ "CVE-2023-3329" ], "details": "SpiderControl SCADA Webserver versions 2.08 and prior are vulnerable to path traversal. An attacker with administrative privileges could overwrite files on the webserver using the HMI's upload file feature. This could create size zero files anywhere on the webserver, potentially overwriting system files and creating a denial-of-service condition.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/08/GHSA-jmx3-98vw-w6hq/GHSA-jmx3-98vw-w6hq.json b/advisories/unreviewed/2023/08/GHSA-jmx3-98vw-w6hq/GHSA-jmx3-98vw-w6hq.json index 329a2537daf..1ce6ae5752c 100644 --- a/advisories/unreviewed/2023/08/GHSA-jmx3-98vw-w6hq/GHSA-jmx3-98vw-w6hq.json +++ b/advisories/unreviewed/2023/08/GHSA-jmx3-98vw-w6hq/GHSA-jmx3-98vw-w6hq.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/08/GHSA-jp4g-93c7-f645/GHSA-jp4g-93c7-f645.json b/advisories/unreviewed/2023/08/GHSA-jp4g-93c7-f645/GHSA-jp4g-93c7-f645.json new file mode 100644 index 00000000000..a969fc139fb --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-jp4g-93c7-f645/GHSA-jp4g-93c7-f645.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jp4g-93c7-f645", + "modified": "2023-08-08T18:30:36Z", + "published": "2023-08-08T18:30:36Z", + "aliases": [ + "CVE-2023-29328" + ], + "details": "Microsoft Teams Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29328" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-29328" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-jrpp-v555-xqmp/GHSA-jrpp-v555-xqmp.json b/advisories/unreviewed/2023/08/GHSA-jrpp-v555-xqmp/GHSA-jrpp-v555-xqmp.json new file mode 100644 index 00000000000..c83ec62a91d --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-jrpp-v555-xqmp/GHSA-jrpp-v555-xqmp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jrpp-v555-xqmp", + "modified": "2023-08-08T18:30:36Z", + "published": "2023-08-08T18:30:36Z", + "aliases": [ + "CVE-2023-21709" + ], + "details": "Microsoft Exchange Server Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-21709" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21709" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-jxrr-jgx5-rfcg/GHSA-jxrr-jgx5-rfcg.json b/advisories/unreviewed/2023/08/GHSA-jxrr-jgx5-rfcg/GHSA-jxrr-jgx5-rfcg.json new file mode 100644 index 00000000000..c705090eb17 --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-jxrr-jgx5-rfcg/GHSA-jxrr-jgx5-rfcg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jxrr-jgx5-rfcg", + "modified": "2023-08-08T18:30:36Z", + "published": "2023-08-08T18:30:36Z", + "aliases": [ + "CVE-2023-35388" + ], + "details": "Microsoft Exchange Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35388" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-35388" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-m5g9-fvqr-h5pp/GHSA-m5g9-fvqr-h5pp.json b/advisories/unreviewed/2023/08/GHSA-m5g9-fvqr-h5pp/GHSA-m5g9-fvqr-h5pp.json new file mode 100644 index 00000000000..1a1bdf6e967 --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-m5g9-fvqr-h5pp/GHSA-m5g9-fvqr-h5pp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m5g9-fvqr-h5pp", + "modified": "2023-08-08T18:30:37Z", + "published": "2023-08-08T18:30:37Z", + "aliases": [ + "CVE-2023-38170" + ], + "details": "HEVC Video Extensions Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38170" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-38170" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-mf8r-h4c9-q93r/GHSA-mf8r-h4c9-q93r.json b/advisories/unreviewed/2023/08/GHSA-mf8r-h4c9-q93r/GHSA-mf8r-h4c9-q93r.json new file mode 100644 index 00000000000..1ab3f081d32 --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-mf8r-h4c9-q93r/GHSA-mf8r-h4c9-q93r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mf8r-h4c9-q93r", + "modified": "2023-08-08T18:30:37Z", + "published": "2023-08-08T18:30:37Z", + "aliases": [ + "CVE-2023-36907" + ], + "details": "Windows Cryptographic Services Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36907" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36907" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-mrhv-v7jg-4384/GHSA-mrhv-v7jg-4384.json b/advisories/unreviewed/2023/08/GHSA-mrhv-v7jg-4384/GHSA-mrhv-v7jg-4384.json index 8ce3d428f53..59ed4757015 100644 --- a/advisories/unreviewed/2023/08/GHSA-mrhv-v7jg-4384/GHSA-mrhv-v7jg-4384.json +++ b/advisories/unreviewed/2023/08/GHSA-mrhv-v7jg-4384/GHSA-mrhv-v7jg-4384.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mrhv-v7jg-4384", - "modified": "2023-08-03T00:30:15Z", + "modified": "2023-08-08T18:30:34Z", "published": "2023-08-03T00:30:15Z", "aliases": [ "CVE-2023-39114" ], "details": "ngiflib commit 84a75 was discovered to contain a segmentation violation via the function SDL_LoadAnimatedGif at ngiflibSDL.c. This vulnerability is triggered when running the program SDLaffgif.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/08/GHSA-mv3g-pwv2-rfxp/GHSA-mv3g-pwv2-rfxp.json b/advisories/unreviewed/2023/08/GHSA-mv3g-pwv2-rfxp/GHSA-mv3g-pwv2-rfxp.json new file mode 100644 index 00000000000..97d8e941f7d --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-mv3g-pwv2-rfxp/GHSA-mv3g-pwv2-rfxp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mv3g-pwv2-rfxp", + "modified": "2023-08-08T18:30:37Z", + "published": "2023-08-08T18:30:37Z", + "aliases": [ + "CVE-2023-36909" + ], + "details": "Microsoft Message Queuing Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36909" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36909" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-mw3f-jhxv-c95j/GHSA-mw3f-jhxv-c95j.json b/advisories/unreviewed/2023/08/GHSA-mw3f-jhxv-c95j/GHSA-mw3f-jhxv-c95j.json new file mode 100644 index 00000000000..5509ffe8abd --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-mw3f-jhxv-c95j/GHSA-mw3f-jhxv-c95j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mw3f-jhxv-c95j", + "modified": "2023-08-08T18:30:36Z", + "published": "2023-08-08T18:30:36Z", + "aliases": [ + "CVE-2023-35384" + ], + "details": "Windows HTML Platforms Security Feature Bypass Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35384" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-35384" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-mw4m-m933-3jx3/GHSA-mw4m-m933-3jx3.json b/advisories/unreviewed/2023/08/GHSA-mw4m-m933-3jx3/GHSA-mw4m-m933-3jx3.json new file mode 100644 index 00000000000..5de172b9774 --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-mw4m-m933-3jx3/GHSA-mw4m-m933-3jx3.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mw4m-m933-3jx3", + "modified": "2023-08-08T18:30:35Z", + "published": "2023-08-08T18:30:35Z", + "aliases": [ + "CVE-2023-38760" + ], + "details": "SQL injection vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to obtain sensitive information via the role and gender parameters within the /QueryView.php component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38760" + }, + { + "type": "WEB", + "url": "https://churchcrm.io/" + }, + { + "type": "WEB", + "url": "https://demo.churchcrm.io/master" + }, + { + "type": "WEB", + "url": "https://github.com/0x72303074/CVE-Disclosures" + }, + { + "type": "WEB", + "url": "https://github.com/ChurchCRM/CRM/wiki" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-mxh8-v3cx-xp6x/GHSA-mxh8-v3cx-xp6x.json b/advisories/unreviewed/2023/08/GHSA-mxh8-v3cx-xp6x/GHSA-mxh8-v3cx-xp6x.json new file mode 100644 index 00000000000..4b9f2c1179f --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-mxh8-v3cx-xp6x/GHSA-mxh8-v3cx-xp6x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mxh8-v3cx-xp6x", + "modified": "2023-08-08T18:30:36Z", + "published": "2023-08-08T18:30:36Z", + "aliases": [ + "CVE-2023-29330" + ], + "details": "Microsoft Teams Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29330" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-29330" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-p36c-2mv6-8m8q/GHSA-p36c-2mv6-8m8q.json b/advisories/unreviewed/2023/08/GHSA-p36c-2mv6-8m8q/GHSA-p36c-2mv6-8m8q.json index 6ae771b21ed..59caed7006c 100644 --- a/advisories/unreviewed/2023/08/GHSA-p36c-2mv6-8m8q/GHSA-p36c-2mv6-8m8q.json +++ b/advisories/unreviewed/2023/08/GHSA-p36c-2mv6-8m8q/GHSA-p36c-2mv6-8m8q.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/08/GHSA-p4r5-8jr9-cwgv/GHSA-p4r5-8jr9-cwgv.json b/advisories/unreviewed/2023/08/GHSA-p4r5-8jr9-cwgv/GHSA-p4r5-8jr9-cwgv.json new file mode 100644 index 00000000000..4232762b7c1 --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-p4r5-8jr9-cwgv/GHSA-p4r5-8jr9-cwgv.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p4r5-8jr9-cwgv", + "modified": "2023-08-08T18:30:36Z", + "published": "2023-08-08T18:30:36Z", + "aliases": [ + "CVE-2023-20589" + ], + "details": "\nAn attacker with specialized hardware and physical access to an impacted device may be able to perform a voltage fault injection attack resulting in compromise of the ASP secure boot potentially leading to arbitrary code execution. \n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-20589" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-4005" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-q9v9-492r-q87w/GHSA-q9v9-492r-q87w.json b/advisories/unreviewed/2023/08/GHSA-q9v9-492r-q87w/GHSA-q9v9-492r-q87w.json new file mode 100644 index 00000000000..4d3c2a22868 --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-q9v9-492r-q87w/GHSA-q9v9-492r-q87w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q9v9-492r-q87w", + "modified": "2023-08-08T18:30:36Z", + "published": "2023-08-08T18:30:36Z", + "aliases": [ + "CVE-2023-35381" + ], + "details": "Windows Fax Service Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35381" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-35381" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-qh2x-6w4c-qxp3/GHSA-qh2x-6w4c-qxp3.json b/advisories/unreviewed/2023/08/GHSA-qh2x-6w4c-qxp3/GHSA-qh2x-6w4c-qxp3.json new file mode 100644 index 00000000000..5b522de29bf --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-qh2x-6w4c-qxp3/GHSA-qh2x-6w4c-qxp3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qh2x-6w4c-qxp3", + "modified": "2023-08-08T18:30:37Z", + "published": "2023-08-08T18:30:37Z", + "aliases": [ + "CVE-2023-36900" + ], + "details": "Windows Common Log File System Driver Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36900" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36900" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-qqxx-932h-hc2v/GHSA-qqxx-932h-hc2v.json b/advisories/unreviewed/2023/08/GHSA-qqxx-932h-hc2v/GHSA-qqxx-932h-hc2v.json new file mode 100644 index 00000000000..f354f8d257a --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-qqxx-932h-hc2v/GHSA-qqxx-932h-hc2v.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qqxx-932h-hc2v", + "modified": "2023-08-08T18:30:35Z", + "published": "2023-08-08T18:30:35Z", + "aliases": [ + "CVE-2023-38767" + ], + "details": "SQL injection vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to obtain sensitive information via the 'value' and 'custom' parameters within the /QueryView.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38767" + }, + { + "type": "WEB", + "url": "https://churchcrm.io/" + }, + { + "type": "WEB", + "url": "https://demo.churchcrm.io/master" + }, + { + "type": "WEB", + "url": "https://github.com/0x72303074/CVE-Disclosures" + }, + { + "type": "WEB", + "url": "https://github.com/ChurchCRM/CRM/wiki" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-qv3q-cwv9-r3m3/GHSA-qv3q-cwv9-r3m3.json b/advisories/unreviewed/2023/08/GHSA-qv3q-cwv9-r3m3/GHSA-qv3q-cwv9-r3m3.json new file mode 100644 index 00000000000..888e503a9b4 --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-qv3q-cwv9-r3m3/GHSA-qv3q-cwv9-r3m3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qv3q-cwv9-r3m3", + "modified": "2023-08-08T18:30:36Z", + "published": "2023-08-08T18:30:36Z", + "aliases": [ + "CVE-2023-36535" + ], + "details": "Client-side enforcement of server-side security in Zoom clients before 5.14.10 may allow an authenticated user to enable information disclosure via network access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36535" + }, + { + "type": "WEB", + "url": "https://explore.zoom.us/en/trust/security/security-bulletin/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-602" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-qv76-4vx5-f24v/GHSA-qv76-4vx5-f24v.json b/advisories/unreviewed/2023/08/GHSA-qv76-4vx5-f24v/GHSA-qv76-4vx5-f24v.json new file mode 100644 index 00000000000..56c49da58a3 --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-qv76-4vx5-f24v/GHSA-qv76-4vx5-f24v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qv76-4vx5-f24v", + "modified": "2023-08-08T18:30:36Z", + "published": "2023-08-08T18:30:36Z", + "aliases": [ + "CVE-2023-36894" + ], + "details": "Microsoft SharePoint Server Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36894" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36894" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-qvhv-4pmm-cc4q/GHSA-qvhv-4pmm-cc4q.json b/advisories/unreviewed/2023/08/GHSA-qvhv-4pmm-cc4q/GHSA-qvhv-4pmm-cc4q.json new file mode 100644 index 00000000000..d5e1c994bec --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-qvhv-4pmm-cc4q/GHSA-qvhv-4pmm-cc4q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qvhv-4pmm-cc4q", + "modified": "2023-08-08T18:30:36Z", + "published": "2023-08-08T18:30:36Z", + "aliases": [ + "CVE-2023-35394" + ], + "details": "Azure HDInsight Jupyter Notebook Spoofing Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35394" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-35394" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-qw8j-8xrp-fcf6/GHSA-qw8j-8xrp-fcf6.json b/advisories/unreviewed/2023/08/GHSA-qw8j-8xrp-fcf6/GHSA-qw8j-8xrp-fcf6.json new file mode 100644 index 00000000000..514032646dd --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-qw8j-8xrp-fcf6/GHSA-qw8j-8xrp-fcf6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qw8j-8xrp-fcf6", + "modified": "2023-08-08T18:30:36Z", + "published": "2023-08-08T18:30:36Z", + "aliases": [ + "CVE-2023-36865" + ], + "details": "Microsoft Office Visio Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36865" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36865" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-r3h2-76p7-jwr7/GHSA-r3h2-76p7-jwr7.json b/advisories/unreviewed/2023/08/GHSA-r3h2-76p7-jwr7/GHSA-r3h2-76p7-jwr7.json new file mode 100644 index 00000000000..5307b01f3db --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-r3h2-76p7-jwr7/GHSA-r3h2-76p7-jwr7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r3h2-76p7-jwr7", + "modified": "2023-08-08T18:30:36Z", + "published": "2023-08-08T18:30:36Z", + "aliases": [ + "CVE-2023-35387" + ], + "details": "Windows Bluetooth A2DP driver Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35387" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-35387" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-r47r-3chg-8pxv/GHSA-r47r-3chg-8pxv.json b/advisories/unreviewed/2023/08/GHSA-r47r-3chg-8pxv/GHSA-r47r-3chg-8pxv.json new file mode 100644 index 00000000000..ca7b1ba2b2a --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-r47r-3chg-8pxv/GHSA-r47r-3chg-8pxv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r47r-3chg-8pxv", + "modified": "2023-08-08T18:30:36Z", + "published": "2023-08-08T18:30:36Z", + "aliases": [ + "CVE-2023-36869" + ], + "details": "Azure DevOps Server Spoofing Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36869" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36869" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-rg2c-cfxv-qp6f/GHSA-rg2c-cfxv-qp6f.json b/advisories/unreviewed/2023/08/GHSA-rg2c-cfxv-qp6f/GHSA-rg2c-cfxv-qp6f.json new file mode 100644 index 00000000000..30a9233c30c --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-rg2c-cfxv-qp6f/GHSA-rg2c-cfxv-qp6f.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rg2c-cfxv-qp6f", + "modified": "2023-08-08T18:30:37Z", + "published": "2023-08-08T18:30:37Z", + "aliases": [ + "CVE-2023-3894" + ], + "details": "Those using jackson-dataformats-text to parse TOML data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3894" + }, + { + "type": "WEB", + "url": "https://github.com/FasterXML/jackson-dataformats-text/pull/398" + }, + { + "type": "WEB", + "url": "https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=50083" + }, + { + "type": "WEB", + "url": "https://github.com/FasterXML/jackson-dataformats-text/blob/2.16/release-notes/VERSION-2.x" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-v2fp-mjm4-pj44/GHSA-v2fp-mjm4-pj44.json b/advisories/unreviewed/2023/08/GHSA-v2fp-mjm4-pj44/GHSA-v2fp-mjm4-pj44.json new file mode 100644 index 00000000000..6b217840aef --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-v2fp-mjm4-pj44/GHSA-v2fp-mjm4-pj44.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v2fp-mjm4-pj44", + "modified": "2023-08-08T18:30:37Z", + "published": "2023-08-08T18:30:37Z", + "aliases": [ + "CVE-2023-38169" + ], + "details": "Microsoft OLE DB Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38169" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-38169" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-v478-mrrj-9jxx/GHSA-v478-mrrj-9jxx.json b/advisories/unreviewed/2023/08/GHSA-v478-mrrj-9jxx/GHSA-v478-mrrj-9jxx.json new file mode 100644 index 00000000000..6b59b41b21c --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-v478-mrrj-9jxx/GHSA-v478-mrrj-9jxx.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v478-mrrj-9jxx", + "modified": "2023-08-08T18:30:35Z", + "published": "2023-08-08T18:30:35Z", + "aliases": [ + "CVE-2023-38769" + ], + "details": "SQL injection vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to obtain sensitive information via the searchstring and searchwhat parameters within the /QueryView.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38769" + }, + { + "type": "WEB", + "url": "https://churchcrm.io/" + }, + { + "type": "WEB", + "url": "https://demo.churchcrm.io/master" + }, + { + "type": "WEB", + "url": "https://github.com/0x72303074/CVE-Disclosures" + }, + { + "type": "WEB", + "url": "https://github.com/ChurchCRM/CRM/wiki" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-vcw6-g65p-gcjw/GHSA-vcw6-g65p-gcjw.json b/advisories/unreviewed/2023/08/GHSA-vcw6-g65p-gcjw/GHSA-vcw6-g65p-gcjw.json new file mode 100644 index 00000000000..f404f3ffef5 --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-vcw6-g65p-gcjw/GHSA-vcw6-g65p-gcjw.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vcw6-g65p-gcjw", + "modified": "2023-08-08T18:30:36Z", + "published": "2023-08-08T18:30:36Z", + "aliases": [ + "CVE-2023-20555" + ], + "details": "Insufficient input validation in\nCpmDisplayFeatureSmm may allow an attacker to corrupt SMM memory by overwriting\nan arbitrary bit in an attacker-controlled pointer potentially leading to\narbitrary code execution in SMM.\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-20555" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-4003" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-vrg5-r47p-62x3/GHSA-vrg5-r47p-62x3.json b/advisories/unreviewed/2023/08/GHSA-vrg5-r47p-62x3/GHSA-vrg5-r47p-62x3.json new file mode 100644 index 00000000000..07fb9902781 --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-vrg5-r47p-62x3/GHSA-vrg5-r47p-62x3.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vrg5-r47p-62x3", + "modified": "2023-08-08T18:30:35Z", + "published": "2023-08-08T18:30:35Z", + "aliases": [ + "CVE-2023-38763" + ], + "details": "SQL injection vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to obtain sensitive information via the FundRaiserID parameter within the /FundRaiserEditor.php endpoint.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38763" + }, + { + "type": "WEB", + "url": "https://churchcrm.io/" + }, + { + "type": "WEB", + "url": "https://demo.churchcrm.io/master" + }, + { + "type": "WEB", + "url": "https://github.com/0x72303074/CVE-Disclosures" + }, + { + "type": "WEB", + "url": "https://github.com/ChurchCRM/CRM/wiki" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-vx8f-24wp-mfwj/GHSA-vx8f-24wp-mfwj.json b/advisories/unreviewed/2023/08/GHSA-vx8f-24wp-mfwj/GHSA-vx8f-24wp-mfwj.json new file mode 100644 index 00000000000..f921d70c132 --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-vx8f-24wp-mfwj/GHSA-vx8f-24wp-mfwj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vx8f-24wp-mfwj", + "modified": "2023-08-08T18:30:36Z", + "published": "2023-08-08T18:30:36Z", + "aliases": [ + "CVE-2023-35389" + ], + "details": "Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35389" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-35389" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-w5hv-qvq6-g6wg/GHSA-w5hv-qvq6-g6wg.json b/advisories/unreviewed/2023/08/GHSA-w5hv-qvq6-g6wg/GHSA-w5hv-qvq6-g6wg.json new file mode 100644 index 00000000000..11a06874fce --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-w5hv-qvq6-g6wg/GHSA-w5hv-qvq6-g6wg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w5hv-qvq6-g6wg", + "modified": "2023-08-08T18:30:37Z", + "published": "2023-08-08T18:30:37Z", + "aliases": [ + "CVE-2023-36906" + ], + "details": "Windows Cryptographic Services Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36906" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36906" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-w5xr-g793-3gjm/GHSA-w5xr-g793-3gjm.json b/advisories/unreviewed/2023/08/GHSA-w5xr-g793-3gjm/GHSA-w5xr-g793-3gjm.json new file mode 100644 index 00000000000..54e4000ff35 --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-w5xr-g793-3gjm/GHSA-w5xr-g793-3gjm.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w5xr-g793-3gjm", + "modified": "2023-08-08T18:30:35Z", + "published": "2023-08-08T18:30:35Z", + "aliases": [ + "CVE-2023-38765" + ], + "details": "SQL injection vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to obtain sensitive information via the membermonth parameter within the /QueryView.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38765" + }, + { + "type": "WEB", + "url": "https://churchcrm.io/" + }, + { + "type": "WEB", + "url": "https://demo.churchcrm.io/master" + }, + { + "type": "WEB", + "url": "https://github.com/0x72303074/CVE-Disclosures" + }, + { + "type": "WEB", + "url": "https://github.com/ChurchCRM/CRM/wiki" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-wc5r-96vx-4jj6/GHSA-wc5r-96vx-4jj6.json b/advisories/unreviewed/2023/08/GHSA-wc5r-96vx-4jj6/GHSA-wc5r-96vx-4jj6.json index 78126e0b370..9c5343e3f6b 100644 --- a/advisories/unreviewed/2023/08/GHSA-wc5r-96vx-4jj6/GHSA-wc5r-96vx-4jj6.json +++ b/advisories/unreviewed/2023/08/GHSA-wc5r-96vx-4jj6/GHSA-wc5r-96vx-4jj6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wc5r-96vx-4jj6", - "modified": "2023-08-03T18:30:35Z", + "modified": "2023-08-08T18:30:35Z", "published": "2023-08-03T18:30:35Z", "aliases": [ "CVE-2023-33364" ], "details": "An OS Command injection vulnerability exists in Suprema BioStar 2 before V2.9.1, which allows authenticated users to execute arbitrary OS commands on the BioStar 2 server.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/08/GHSA-whhx-jc9m-vw4h/GHSA-whhx-jc9m-vw4h.json b/advisories/unreviewed/2023/08/GHSA-whhx-jc9m-vw4h/GHSA-whhx-jc9m-vw4h.json new file mode 100644 index 00000000000..d971b479c83 --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-whhx-jc9m-vw4h/GHSA-whhx-jc9m-vw4h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-whhx-jc9m-vw4h", + "modified": "2023-08-08T18:30:36Z", + "published": "2023-08-08T18:30:36Z", + "aliases": [ + "CVE-2023-35385" + ], + "details": "Microsoft Message Queuing Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35385" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-35385" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-wrw3-qmqw-4x9w/GHSA-wrw3-qmqw-4x9w.json b/advisories/unreviewed/2023/08/GHSA-wrw3-qmqw-4x9w/GHSA-wrw3-qmqw-4x9w.json new file mode 100644 index 00000000000..2f212f6efa8 --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-wrw3-qmqw-4x9w/GHSA-wrw3-qmqw-4x9w.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wrw3-qmqw-4x9w", + "modified": "2023-08-08T18:30:35Z", + "published": "2023-08-08T18:30:35Z", + "aliases": [ + "CVE-2023-38759" + ], + "details": "Cross Site Request Forgery (CSRF) vulnerability in wger Project wger Workout Manager 2.2.0a3 allows a remote attacker to gain privileges via the user-management feature in the gym/views/gym.py, templates/gym/reset_user_password.html, templates/user/overview.html, core/views/user.py, and templates/user/preferences.html, core/forms.py components.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38759" + }, + { + "type": "WEB", + "url": "https://github.com/0x72303074/CVE-Disclosures" + }, + { + "type": "WEB", + "url": "https://wger.de" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-wxv4-gf6x-3gmh/GHSA-wxv4-gf6x-3gmh.json b/advisories/unreviewed/2023/08/GHSA-wxv4-gf6x-3gmh/GHSA-wxv4-gf6x-3gmh.json new file mode 100644 index 00000000000..f133cbdb0f5 --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-wxv4-gf6x-3gmh/GHSA-wxv4-gf6x-3gmh.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wxv4-gf6x-3gmh", + "modified": "2023-08-08T18:30:35Z", + "published": "2023-08-08T18:30:35Z", + "aliases": [ + "CVE-2023-38768" + ], + "details": "SQL injection vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to obtain sensitive information via the PropertyID parameter within the /QueryView.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38768" + }, + { + "type": "WEB", + "url": "https://churchcrm.io/" + }, + { + "type": "WEB", + "url": "https://demo.churchcrm.io/master" + }, + { + "type": "WEB", + "url": "https://github.com/0x72303074/CVE-Disclosures" + }, + { + "type": "WEB", + "url": "https://github.com/ChurchCRM/CRM/wiki" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-x267-8p4f-834v/GHSA-x267-8p4f-834v.json b/advisories/unreviewed/2023/08/GHSA-x267-8p4f-834v/GHSA-x267-8p4f-834v.json new file mode 100644 index 00000000000..1babd5b8f9f --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-x267-8p4f-834v/GHSA-x267-8p4f-834v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x267-8p4f-834v", + "modified": "2023-08-08T18:30:36Z", + "published": "2023-08-08T18:30:36Z", + "aliases": [ + "CVE-2023-35371" + ], + "details": "Microsoft Office Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35371" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-35371" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-x8v9-642f-j4vc/GHSA-x8v9-642f-j4vc.json b/advisories/unreviewed/2023/08/GHSA-x8v9-642f-j4vc/GHSA-x8v9-642f-j4vc.json index da3121894ab..5c44c16e0e9 100644 --- a/advisories/unreviewed/2023/08/GHSA-x8v9-642f-j4vc/GHSA-x8v9-642f-j4vc.json +++ b/advisories/unreviewed/2023/08/GHSA-x8v9-642f-j4vc/GHSA-x8v9-642f-j4vc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x8v9-642f-j4vc", - "modified": "2023-08-02T18:30:26Z", + "modified": "2023-08-08T18:30:34Z", "published": "2023-08-02T18:30:26Z", "aliases": [ "CVE-2023-36858" diff --git a/advisories/unreviewed/2023/08/GHSA-xq7r-2vx2-8jgj/GHSA-xq7r-2vx2-8jgj.json b/advisories/unreviewed/2023/08/GHSA-xq7r-2vx2-8jgj/GHSA-xq7r-2vx2-8jgj.json index dc5426c8a22..9c71e275be8 100644 --- a/advisories/unreviewed/2023/08/GHSA-xq7r-2vx2-8jgj/GHSA-xq7r-2vx2-8jgj.json +++ b/advisories/unreviewed/2023/08/GHSA-xq7r-2vx2-8jgj/GHSA-xq7r-2vx2-8jgj.json @@ -40,7 +40,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-22" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/08/GHSA-xqp9-w6xm-qf2v/GHSA-xqp9-w6xm-qf2v.json b/advisories/unreviewed/2023/08/GHSA-xqp9-w6xm-qf2v/GHSA-xqp9-w6xm-qf2v.json new file mode 100644 index 00000000000..6b03682fed7 --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-xqp9-w6xm-qf2v/GHSA-xqp9-w6xm-qf2v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xqp9-w6xm-qf2v", + "modified": "2023-08-08T18:30:37Z", + "published": "2023-08-08T18:30:37Z", + "aliases": [ + "CVE-2023-36911" + ], + "details": "Microsoft Message Queuing Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36911" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36911" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-xr6c-7pfv-6vgf/GHSA-xr6c-7pfv-6vgf.json b/advisories/unreviewed/2023/08/GHSA-xr6c-7pfv-6vgf/GHSA-xr6c-7pfv-6vgf.json new file mode 100644 index 00000000000..fddcbb4bc22 --- /dev/null +++ b/advisories/unreviewed/2023/08/GHSA-xr6c-7pfv-6vgf/GHSA-xr6c-7pfv-6vgf.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xr6c-7pfv-6vgf", + "modified": "2023-08-08T18:30:36Z", + "published": "2023-08-08T18:30:36Z", + "aliases": [ + "CVE-2023-20569" + ], + "details": "\n\n\nA side channel vulnerability on some of the AMD CPUs may allow an attacker to influence the return address prediction. This may result in speculative execution at an attacker-controlled?address, potentially leading to information disclosure.\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-20569" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-7005" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file