From 566ab53619a8b17c77e2d0c58809808515bf0703 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 24 Sep 2024 18:33:02 +0000 Subject: [PATCH] Advisory Database Sync --- .../06/GHSA-ffhx-2rrf-9c23/GHSA-ffhx-2rrf-9c23.json | 3 ++- .../09/GHSA-27j9-vfp3-773q/GHSA-27j9-vfp3-773q.json | 11 +++++++---- .../09/GHSA-27vc-rww5-64v8/GHSA-27vc-rww5-64v8.json | 11 +++++++---- .../09/GHSA-2mj4-2m9q-g49h/GHSA-2mj4-2m9q-g49h.json | 11 +++++++---- .../09/GHSA-2qj2-rq28-64cc/GHSA-2qj2-rq28-64cc.json | 11 +++++++---- .../09/GHSA-39hm-m9hv-pfcr/GHSA-39hm-m9hv-pfcr.json | 11 +++++++---- .../09/GHSA-3w22-q3jv-89jw/GHSA-3w22-q3jv-89jw.json | 9 ++++++--- .../09/GHSA-3w5w-2v95-54r9/GHSA-3w5w-2v95-54r9.json | 11 +++++++---- .../09/GHSA-45fw-7wjh-qgj9/GHSA-45fw-7wjh-qgj9.json | 11 +++++++---- .../09/GHSA-45r4-jrvf-27wr/GHSA-45r4-jrvf-27wr.json | 11 +++++++---- .../09/GHSA-47fg-g734-5wff/GHSA-47fg-g734-5wff.json | 11 +++++++---- .../09/GHSA-4hx8-86wp-g993/GHSA-4hx8-86wp-g993.json | 9 ++++++--- .../09/GHSA-4m5g-9h9q-7x5h/GHSA-4m5g-9h9q-7x5h.json | 11 +++++++---- .../09/GHSA-55hv-grg7-hf97/GHSA-55hv-grg7-hf97.json | 11 +++++++---- .../09/GHSA-5rxq-m67m-h24r/GHSA-5rxq-m67m-h24r.json | 9 ++++++--- .../09/GHSA-65q7-86f4-pxh5/GHSA-65q7-86f4-pxh5.json | 11 +++++++---- .../09/GHSA-67cr-pq3q-pqwx/GHSA-67cr-pq3q-pqwx.json | 11 +++++++---- .../09/GHSA-6p22-8x2w-g3r3/GHSA-6p22-8x2w-g3r3.json | 11 +++++++---- .../09/GHSA-735f-p4wh-56vp/GHSA-735f-p4wh-56vp.json | 11 +++++++---- .../09/GHSA-735p-552j-x6p3/GHSA-735p-552j-x6p3.json | 11 +++++++---- .../09/GHSA-73xr-wr9g-3273/GHSA-73xr-wr9g-3273.json | 11 +++++++---- .../09/GHSA-74p7-53wh-h625/GHSA-74p7-53wh-h625.json | 9 ++++++--- .../09/GHSA-7c3x-gh76-g622/GHSA-7c3x-gh76-g622.json | 11 +++++++---- .../09/GHSA-7ghv-w4w7-gjc3/GHSA-7ghv-w4w7-gjc3.json | 11 +++++++---- .../09/GHSA-7jjq-j5wq-j8cv/GHSA-7jjq-j5wq-j8cv.json | 11 +++++++---- .../09/GHSA-8vvc-wfcp-337x/GHSA-8vvc-wfcp-337x.json | 11 +++++++---- .../09/GHSA-923m-rgj5-fgjh/GHSA-923m-rgj5-fgjh.json | 11 +++++++---- .../09/GHSA-94jw-wm22-7fjx/GHSA-94jw-wm22-7fjx.json | 11 +++++++---- .../09/GHSA-963r-9g4m-v5vm/GHSA-963r-9g4m-v5vm.json | 11 +++++++---- .../09/GHSA-96j7-6x53-7368/GHSA-96j7-6x53-7368.json | 9 ++++++--- .../09/GHSA-9g9q-cf56-cfh9/GHSA-9g9q-cf56-cfh9.json | 9 ++++++--- .../09/GHSA-9jxw-6cwc-fv29/GHSA-9jxw-6cwc-fv29.json | 9 ++++++--- .../09/GHSA-9rg3-9338-mwcv/GHSA-9rg3-9338-mwcv.json | 9 ++++++--- .../09/GHSA-c5c4-5r7q-ccqv/GHSA-c5c4-5r7q-ccqv.json | 11 +++++++---- .../09/GHSA-ccw9-q98h-qv5r/GHSA-ccw9-q98h-qv5r.json | 11 +++++++---- .../09/GHSA-cw5r-673r-7ww3/GHSA-cw5r-673r-7ww3.json | 9 ++++++--- .../09/GHSA-cxhr-64cg-3mjp/GHSA-cxhr-64cg-3mjp.json | 11 +++++++---- .../09/GHSA-f826-4hr5-hxxx/GHSA-f826-4hr5-hxxx.json | 11 +++++++---- .../09/GHSA-fgx2-m7jc-63xr/GHSA-fgx2-m7jc-63xr.json | 11 +++++++---- .../09/GHSA-fpgw-4ghq-mm93/GHSA-fpgw-4ghq-mm93.json | 11 +++++++---- .../09/GHSA-fqmh-8xfw-5v84/GHSA-fqmh-8xfw-5v84.json | 11 +++++++---- .../09/GHSA-g2r8-m367-m72p/GHSA-g2r8-m367-m72p.json | 11 +++++++---- .../09/GHSA-gvw8-h5c5-pr3g/GHSA-gvw8-h5c5-pr3g.json | 9 ++++++--- .../09/GHSA-gw53-chv8-4wr2/GHSA-gw53-chv8-4wr2.json | 9 ++++++--- .../09/GHSA-h2pr-ggrm-q7gx/GHSA-h2pr-ggrm-q7gx.json | 11 +++++++---- .../09/GHSA-h498-88jq-wh8m/GHSA-h498-88jq-wh8m.json | 11 +++++++---- .../09/GHSA-h89v-mw4f-7wgj/GHSA-h89v-mw4f-7wgj.json | 9 ++++++--- .../09/GHSA-hx98-qf58-hff9/GHSA-hx98-qf58-hff9.json | 9 ++++++--- .../09/GHSA-j962-w243-6g33/GHSA-j962-w243-6g33.json | 11 +++++++---- .../09/GHSA-jpf3-j9x5-w3ff/GHSA-jpf3-j9x5-w3ff.json | 9 ++++++--- .../09/GHSA-jvcj-gmhm-rfx5/GHSA-jvcj-gmhm-rfx5.json | 9 ++++++--- .../09/GHSA-m38v-7vc8-5x55/GHSA-m38v-7vc8-5x55.json | 11 +++++++---- .../09/GHSA-m548-7rvw-m5fc/GHSA-m548-7rvw-m5fc.json | 9 ++++++--- .../09/GHSA-m67j-wqgc-38f3/GHSA-m67j-wqgc-38f3.json | 11 +++++++---- .../09/GHSA-m9g4-52vh-fwwv/GHSA-m9g4-52vh-fwwv.json | 9 ++++++--- .../09/GHSA-mh89-qc88-2rhh/GHSA-mh89-qc88-2rhh.json | 11 +++++++---- .../09/GHSA-q7q2-gf23-qgjw/GHSA-q7q2-gf23-qgjw.json | 9 ++++++--- .../09/GHSA-qm78-568c-wg6m/GHSA-qm78-568c-wg6m.json | 9 ++++++--- .../09/GHSA-r773-284v-hh8m/GHSA-r773-284v-hh8m.json | 11 +++++++---- .../09/GHSA-v64w-2rh7-3gvr/GHSA-v64w-2rh7-3gvr.json | 9 ++++++--- .../09/GHSA-w7c2-w23x-h6pm/GHSA-w7c2-w23x-h6pm.json | 11 +++++++---- .../09/GHSA-wjmr-4ghf-rh39/GHSA-wjmr-4ghf-rh39.json | 11 +++++++---- .../09/GHSA-x44q-9q24-vjf9/GHSA-x44q-9q24-vjf9.json | 11 +++++++---- .../09/GHSA-x79g-r583-xj83/GHSA-x79g-r583-xj83.json | 9 ++++++--- .../09/GHSA-xhrw-4447-w35f/GHSA-xhrw-4447-w35f.json | 9 ++++++--- .../09/GHSA-xxmj-qmq4-g4j9/GHSA-xxmj-qmq4-g4j9.json | 11 +++++++---- 66 files changed, 435 insertions(+), 239 deletions(-) diff --git a/advisories/unreviewed/2024/06/GHSA-ffhx-2rrf-9c23/GHSA-ffhx-2rrf-9c23.json b/advisories/unreviewed/2024/06/GHSA-ffhx-2rrf-9c23/GHSA-ffhx-2rrf-9c23.json index aca50ad38b1..ceac1bfd6c4 100644 --- a/advisories/unreviewed/2024/06/GHSA-ffhx-2rrf-9c23/GHSA-ffhx-2rrf-9c23.json +++ b/advisories/unreviewed/2024/06/GHSA-ffhx-2rrf-9c23/GHSA-ffhx-2rrf-9c23.json @@ -36,7 +36,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-377" + "CWE-377", + "CWE-59" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-27j9-vfp3-773q/GHSA-27j9-vfp3-773q.json b/advisories/unreviewed/2024/09/GHSA-27j9-vfp3-773q/GHSA-27j9-vfp3-773q.json index 8390f2b8f80..862c63f653f 100644 --- a/advisories/unreviewed/2024/09/GHSA-27j9-vfp3-773q/GHSA-27j9-vfp3-773q.json +++ b/advisories/unreviewed/2024/09/GHSA-27j9-vfp3-773q/GHSA-27j9-vfp3-773q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-27j9-vfp3-773q", - "modified": "2024-09-18T15:30:53Z", + "modified": "2024-09-24T18:31:26Z", "published": "2024-09-18T15:30:53Z", "aliases": [ "CVE-2024-46581" ], "details": "Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sProfName parameter at v2x00.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T15:15:17Z" diff --git a/advisories/unreviewed/2024/09/GHSA-27vc-rww5-64v8/GHSA-27vc-rww5-64v8.json b/advisories/unreviewed/2024/09/GHSA-27vc-rww5-64v8/GHSA-27vc-rww5-64v8.json index ba62c097b0e..43ec8ba363a 100644 --- a/advisories/unreviewed/2024/09/GHSA-27vc-rww5-64v8/GHSA-27vc-rww5-64v8.json +++ b/advisories/unreviewed/2024/09/GHSA-27vc-rww5-64v8/GHSA-27vc-rww5-64v8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-27vc-rww5-64v8", - "modified": "2024-09-18T15:30:52Z", + "modified": "2024-09-24T18:31:26Z", "published": "2024-09-18T15:30:52Z", "aliases": [ "CVE-2024-46557" ], "details": "Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sProfileName parameter at v2x00.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T15:15:16Z" diff --git a/advisories/unreviewed/2024/09/GHSA-2mj4-2m9q-g49h/GHSA-2mj4-2m9q-g49h.json b/advisories/unreviewed/2024/09/GHSA-2mj4-2m9q-g49h/GHSA-2mj4-2m9q-g49h.json index ba872b38b83..d209b3d3534 100644 --- a/advisories/unreviewed/2024/09/GHSA-2mj4-2m9q-g49h/GHSA-2mj4-2m9q-g49h.json +++ b/advisories/unreviewed/2024/09/GHSA-2mj4-2m9q-g49h/GHSA-2mj4-2m9q-g49h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2mj4-2m9q-g49h", - "modified": "2024-09-18T15:30:53Z", + "modified": "2024-09-24T18:31:26Z", "published": "2024-09-18T15:30:53Z", "aliases": [ "CVE-2024-46582" ], "details": "Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sSrvAddr parameter at v2x00.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T15:15:17Z" diff --git a/advisories/unreviewed/2024/09/GHSA-2qj2-rq28-64cc/GHSA-2qj2-rq28-64cc.json b/advisories/unreviewed/2024/09/GHSA-2qj2-rq28-64cc/GHSA-2qj2-rq28-64cc.json index 0caa9b5275a..a0ad9b883e5 100644 --- a/advisories/unreviewed/2024/09/GHSA-2qj2-rq28-64cc/GHSA-2qj2-rq28-64cc.json +++ b/advisories/unreviewed/2024/09/GHSA-2qj2-rq28-64cc/GHSA-2qj2-rq28-64cc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2qj2-rq28-64cc", - "modified": "2024-09-18T15:30:53Z", + "modified": "2024-09-24T18:31:27Z", "published": "2024-09-18T15:30:53Z", "aliases": [ "CVE-2024-46596" ], "details": "Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sAct parameter at v2x00.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T15:15:18Z" diff --git a/advisories/unreviewed/2024/09/GHSA-39hm-m9hv-pfcr/GHSA-39hm-m9hv-pfcr.json b/advisories/unreviewed/2024/09/GHSA-39hm-m9hv-pfcr/GHSA-39hm-m9hv-pfcr.json index 4c57efbc556..999f238a9f4 100644 --- a/advisories/unreviewed/2024/09/GHSA-39hm-m9hv-pfcr/GHSA-39hm-m9hv-pfcr.json +++ b/advisories/unreviewed/2024/09/GHSA-39hm-m9hv-pfcr/GHSA-39hm-m9hv-pfcr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-39hm-m9hv-pfcr", - "modified": "2024-09-18T15:30:52Z", + "modified": "2024-09-24T18:31:25Z", "published": "2024-09-18T15:30:52Z", "aliases": [ "CVE-2024-46554" ], "details": "Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the profname parameter at v2x00.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T15:15:16Z" diff --git a/advisories/unreviewed/2024/09/GHSA-3w22-q3jv-89jw/GHSA-3w22-q3jv-89jw.json b/advisories/unreviewed/2024/09/GHSA-3w22-q3jv-89jw/GHSA-3w22-q3jv-89jw.json index d0036aff27d..1dad1190368 100644 --- a/advisories/unreviewed/2024/09/GHSA-3w22-q3jv-89jw/GHSA-3w22-q3jv-89jw.json +++ b/advisories/unreviewed/2024/09/GHSA-3w22-q3jv-89jw/GHSA-3w22-q3jv-89jw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3w22-q3jv-89jw", - "modified": "2024-09-17T00:31:04Z", + "modified": "2024-09-24T18:31:24Z", "published": "2024-09-17T00:31:04Z", "aliases": [ "CVE-2024-40850" ], "details": "A file access issue was addressed with improved input validation. This issue is fixed in macOS Ventura 13.7, iOS 17.7 and iPadOS 17.7, visionOS 2, watchOS 11, macOS Sequoia 15, iOS 18 and iPadOS 18, macOS Sonoma 14.7, tvOS 18. An app may be able to access user-sensitive data.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -55,7 +58,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T00:15:49Z" diff --git a/advisories/unreviewed/2024/09/GHSA-3w5w-2v95-54r9/GHSA-3w5w-2v95-54r9.json b/advisories/unreviewed/2024/09/GHSA-3w5w-2v95-54r9/GHSA-3w5w-2v95-54r9.json index 974a7ab7996..ed0f2b28814 100644 --- a/advisories/unreviewed/2024/09/GHSA-3w5w-2v95-54r9/GHSA-3w5w-2v95-54r9.json +++ b/advisories/unreviewed/2024/09/GHSA-3w5w-2v95-54r9/GHSA-3w5w-2v95-54r9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3w5w-2v95-54r9", - "modified": "2024-09-18T15:30:52Z", + "modified": "2024-09-24T18:31:25Z", "published": "2024-09-18T15:30:52Z", "aliases": [ "CVE-2024-46553" ], "details": "Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the ipaddrmsk%d parameter at v2x00.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T15:15:16Z" diff --git a/advisories/unreviewed/2024/09/GHSA-45fw-7wjh-qgj9/GHSA-45fw-7wjh-qgj9.json b/advisories/unreviewed/2024/09/GHSA-45fw-7wjh-qgj9/GHSA-45fw-7wjh-qgj9.json index 482296bb117..64750afd247 100644 --- a/advisories/unreviewed/2024/09/GHSA-45fw-7wjh-qgj9/GHSA-45fw-7wjh-qgj9.json +++ b/advisories/unreviewed/2024/09/GHSA-45fw-7wjh-qgj9/GHSA-45fw-7wjh-qgj9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-45fw-7wjh-qgj9", - "modified": "2024-09-18T15:30:52Z", + "modified": "2024-09-24T18:31:26Z", "published": "2024-09-18T15:30:52Z", "aliases": [ "CVE-2024-46558" ], "details": "Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the newProname parameter at v2x00.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T15:15:17Z" diff --git a/advisories/unreviewed/2024/09/GHSA-45r4-jrvf-27wr/GHSA-45r4-jrvf-27wr.json b/advisories/unreviewed/2024/09/GHSA-45r4-jrvf-27wr/GHSA-45r4-jrvf-27wr.json index 546b389eac9..9a9d4943e7c 100644 --- a/advisories/unreviewed/2024/09/GHSA-45r4-jrvf-27wr/GHSA-45r4-jrvf-27wr.json +++ b/advisories/unreviewed/2024/09/GHSA-45r4-jrvf-27wr/GHSA-45r4-jrvf-27wr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-45r4-jrvf-27wr", - "modified": "2024-09-18T15:30:53Z", + "modified": "2024-09-24T18:31:26Z", "published": "2024-09-18T15:30:53Z", "aliases": [ "CVE-2024-46571" ], "details": "Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sPPPSrvNm parameter at fwuser.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T15:15:17Z" diff --git a/advisories/unreviewed/2024/09/GHSA-47fg-g734-5wff/GHSA-47fg-g734-5wff.json b/advisories/unreviewed/2024/09/GHSA-47fg-g734-5wff/GHSA-47fg-g734-5wff.json index de16b2d4723..ab26cb468e4 100644 --- a/advisories/unreviewed/2024/09/GHSA-47fg-g734-5wff/GHSA-47fg-g734-5wff.json +++ b/advisories/unreviewed/2024/09/GHSA-47fg-g734-5wff/GHSA-47fg-g734-5wff.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-47fg-g734-5wff", - "modified": "2024-09-18T09:30:37Z", + "modified": "2024-09-24T18:31:25Z", "published": "2024-09-18T09:30:37Z", "aliases": [ "CVE-2024-46793" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: Intel: Boards: Fix NULL pointer deref in BYT/CHT boards harder\n\nSince commit 13f58267cda3 (\"ASoC: soc.h: don't create dummy Component\nvia COMP_DUMMY()\") dummy codecs declared like this:\n\nSND_SOC_DAILINK_DEF(dummy,\n DAILINK_COMP_ARRAY(COMP_DUMMY()));\n\nexpand to:\n\nstatic struct snd_soc_dai_link_component dummy[] = {\n};\n\nWhich means that dummy is a zero sized array and thus dais[i].codecs should\nnot be dereferenced *at all* since it points to the address of the next\nvariable stored in the data section as the \"dummy\" variable has an address\nbut no size, so even dereferencing dais[0] is already an out of bounds\narray reference.\n\nWhich means that the if (dais[i].codecs->name) check added in\ncommit 7d99a70b6595 (\"ASoC: Intel: Boards: Fix NULL pointer deref\nin BYT/CHT boards\") relies on that the part of the next variable which\nthe name member maps to just happens to be NULL.\n\nWhich apparently so far it usually is, except when it isn't\nand then it results in crashes like this one:\n\n[ 28.795659] BUG: unable to handle page fault for address: 0000000000030011\n...\n[ 28.795780] Call Trace:\n[ 28.795787] \n...\n[ 28.795862] ? strcmp+0x18/0x40\n[ 28.795872] 0xffffffffc150c605\n[ 28.795887] platform_probe+0x40/0xa0\n...\n[ 28.795979] ? __pfx_init_module+0x10/0x10 [snd_soc_sst_bytcr_wm5102]\n\nReally fix things this time around by checking dais.num_codecs != 0.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T08:15:06Z" diff --git a/advisories/unreviewed/2024/09/GHSA-4hx8-86wp-g993/GHSA-4hx8-86wp-g993.json b/advisories/unreviewed/2024/09/GHSA-4hx8-86wp-g993/GHSA-4hx8-86wp-g993.json index cf1d7669934..98ed61902d7 100644 --- a/advisories/unreviewed/2024/09/GHSA-4hx8-86wp-g993/GHSA-4hx8-86wp-g993.json +++ b/advisories/unreviewed/2024/09/GHSA-4hx8-86wp-g993/GHSA-4hx8-86wp-g993.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4hx8-86wp-g993", - "modified": "2024-09-17T00:31:05Z", + "modified": "2024-09-24T18:31:24Z", "published": "2024-09-17T00:31:05Z", "aliases": [ "CVE-2024-44148" ], "details": "This issue was addressed with improved validation of file attributes. This issue is fixed in macOS Sequoia 15. An app may be able to break out of its sandbox.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T00:15:50Z" diff --git a/advisories/unreviewed/2024/09/GHSA-4m5g-9h9q-7x5h/GHSA-4m5g-9h9q-7x5h.json b/advisories/unreviewed/2024/09/GHSA-4m5g-9h9q-7x5h/GHSA-4m5g-9h9q-7x5h.json index 23828d27f90..fefe5c9b5d6 100644 --- a/advisories/unreviewed/2024/09/GHSA-4m5g-9h9q-7x5h/GHSA-4m5g-9h9q-7x5h.json +++ b/advisories/unreviewed/2024/09/GHSA-4m5g-9h9q-7x5h/GHSA-4m5g-9h9q-7x5h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4m5g-9h9q-7x5h", - "modified": "2024-09-17T00:31:05Z", + "modified": "2024-09-24T18:31:24Z", "published": "2024-09-17T00:31:05Z", "aliases": [ "CVE-2024-44149" ], "details": "A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15. An app may be able to access protected user data.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-281" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T00:15:50Z" diff --git a/advisories/unreviewed/2024/09/GHSA-55hv-grg7-hf97/GHSA-55hv-grg7-hf97.json b/advisories/unreviewed/2024/09/GHSA-55hv-grg7-hf97/GHSA-55hv-grg7-hf97.json index 9d220aadbbd..2d2275b24f1 100644 --- a/advisories/unreviewed/2024/09/GHSA-55hv-grg7-hf97/GHSA-55hv-grg7-hf97.json +++ b/advisories/unreviewed/2024/09/GHSA-55hv-grg7-hf97/GHSA-55hv-grg7-hf97.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-55hv-grg7-hf97", - "modified": "2024-09-18T15:30:53Z", + "modified": "2024-09-24T18:31:26Z", "published": "2024-09-18T15:30:53Z", "aliases": [ "CVE-2024-46565" ], "details": "Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sSrvName parameter at service.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T15:15:17Z" diff --git a/advisories/unreviewed/2024/09/GHSA-5rxq-m67m-h24r/GHSA-5rxq-m67m-h24r.json b/advisories/unreviewed/2024/09/GHSA-5rxq-m67m-h24r/GHSA-5rxq-m67m-h24r.json index b8726822b4c..6fdf14eddb8 100644 --- a/advisories/unreviewed/2024/09/GHSA-5rxq-m67m-h24r/GHSA-5rxq-m67m-h24r.json +++ b/advisories/unreviewed/2024/09/GHSA-5rxq-m67m-h24r/GHSA-5rxq-m67m-h24r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5rxq-m67m-h24r", - "modified": "2024-09-17T00:31:05Z", + "modified": "2024-09-24T18:31:24Z", "published": "2024-09-17T00:31:05Z", "aliases": [ "CVE-2024-44153" ], "details": "The issue was addressed with improved permissions logic. This issue is fixed in macOS Sonoma 14.7, macOS Sequoia 15. An app may be able to access user-sensitive data.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T00:15:50Z" diff --git a/advisories/unreviewed/2024/09/GHSA-65q7-86f4-pxh5/GHSA-65q7-86f4-pxh5.json b/advisories/unreviewed/2024/09/GHSA-65q7-86f4-pxh5/GHSA-65q7-86f4-pxh5.json index 014359a50a1..65ecc50adfe 100644 --- a/advisories/unreviewed/2024/09/GHSA-65q7-86f4-pxh5/GHSA-65q7-86f4-pxh5.json +++ b/advisories/unreviewed/2024/09/GHSA-65q7-86f4-pxh5/GHSA-65q7-86f4-pxh5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-65q7-86f4-pxh5", - "modified": "2024-09-18T15:30:53Z", + "modified": "2024-09-24T18:31:26Z", "published": "2024-09-18T15:30:53Z", "aliases": [ "CVE-2024-46593" ], "details": "Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the trapcomm parameter at cgiswm.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T15:15:18Z" diff --git a/advisories/unreviewed/2024/09/GHSA-67cr-pq3q-pqwx/GHSA-67cr-pq3q-pqwx.json b/advisories/unreviewed/2024/09/GHSA-67cr-pq3q-pqwx/GHSA-67cr-pq3q-pqwx.json index 2a56143b80a..6fb1c16e0e2 100644 --- a/advisories/unreviewed/2024/09/GHSA-67cr-pq3q-pqwx/GHSA-67cr-pq3q-pqwx.json +++ b/advisories/unreviewed/2024/09/GHSA-67cr-pq3q-pqwx/GHSA-67cr-pq3q-pqwx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-67cr-pq3q-pqwx", - "modified": "2024-09-18T15:30:52Z", + "modified": "2024-09-24T18:31:25Z", "published": "2024-09-18T15:30:52Z", "aliases": [ "CVE-2024-46552" ], "details": "Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sStRtMskShow parameter at ipstrt.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T15:15:16Z" diff --git a/advisories/unreviewed/2024/09/GHSA-6p22-8x2w-g3r3/GHSA-6p22-8x2w-g3r3.json b/advisories/unreviewed/2024/09/GHSA-6p22-8x2w-g3r3/GHSA-6p22-8x2w-g3r3.json index aa9d771f478..83459457788 100644 --- a/advisories/unreviewed/2024/09/GHSA-6p22-8x2w-g3r3/GHSA-6p22-8x2w-g3r3.json +++ b/advisories/unreviewed/2024/09/GHSA-6p22-8x2w-g3r3/GHSA-6p22-8x2w-g3r3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6p22-8x2w-g3r3", - "modified": "2024-09-18T15:30:53Z", + "modified": "2024-09-24T18:31:26Z", "published": "2024-09-18T15:30:53Z", "aliases": [ "CVE-2024-46583" ], "details": "Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the extRadSrv2 parameter at cgiapp.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T15:15:17Z" diff --git a/advisories/unreviewed/2024/09/GHSA-735f-p4wh-56vp/GHSA-735f-p4wh-56vp.json b/advisories/unreviewed/2024/09/GHSA-735f-p4wh-56vp/GHSA-735f-p4wh-56vp.json index 7635d7ebee8..dffb853fb8e 100644 --- a/advisories/unreviewed/2024/09/GHSA-735f-p4wh-56vp/GHSA-735f-p4wh-56vp.json +++ b/advisories/unreviewed/2024/09/GHSA-735f-p4wh-56vp/GHSA-735f-p4wh-56vp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-735f-p4wh-56vp", - "modified": "2024-09-18T15:30:52Z", + "modified": "2024-09-24T18:31:25Z", "published": "2024-09-18T15:30:52Z", "aliases": [ "CVE-2024-46550" ], "details": "Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the CGIbyFieldName parameter at chglog.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T15:15:16Z" diff --git a/advisories/unreviewed/2024/09/GHSA-735p-552j-x6p3/GHSA-735p-552j-x6p3.json b/advisories/unreviewed/2024/09/GHSA-735p-552j-x6p3/GHSA-735p-552j-x6p3.json index 0e210b57bf8..758d5285382 100644 --- a/advisories/unreviewed/2024/09/GHSA-735p-552j-x6p3/GHSA-735p-552j-x6p3.json +++ b/advisories/unreviewed/2024/09/GHSA-735p-552j-x6p3/GHSA-735p-552j-x6p3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-735p-552j-x6p3", - "modified": "2024-09-18T15:30:52Z", + "modified": "2024-09-24T18:31:26Z", "published": "2024-09-18T15:30:52Z", "aliases": [ "CVE-2024-46559" ], "details": "Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sBPA_UsrNme parameter at inet15.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T15:15:17Z" diff --git a/advisories/unreviewed/2024/09/GHSA-73xr-wr9g-3273/GHSA-73xr-wr9g-3273.json b/advisories/unreviewed/2024/09/GHSA-73xr-wr9g-3273/GHSA-73xr-wr9g-3273.json index 460c1ed8b4e..89cbd1796e3 100644 --- a/advisories/unreviewed/2024/09/GHSA-73xr-wr9g-3273/GHSA-73xr-wr9g-3273.json +++ b/advisories/unreviewed/2024/09/GHSA-73xr-wr9g-3273/GHSA-73xr-wr9g-3273.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-73xr-wr9g-3273", - "modified": "2024-09-18T15:30:53Z", + "modified": "2024-09-24T18:31:26Z", "published": "2024-09-18T15:30:53Z", "aliases": [ "CVE-2024-46589" ], "details": "Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sIpv6AiccuUser parameter at inetipv6.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T15:15:18Z" diff --git a/advisories/unreviewed/2024/09/GHSA-74p7-53wh-h625/GHSA-74p7-53wh-h625.json b/advisories/unreviewed/2024/09/GHSA-74p7-53wh-h625/GHSA-74p7-53wh-h625.json index e759e3207bc..e66d014c659 100644 --- a/advisories/unreviewed/2024/09/GHSA-74p7-53wh-h625/GHSA-74p7-53wh-h625.json +++ b/advisories/unreviewed/2024/09/GHSA-74p7-53wh-h625/GHSA-74p7-53wh-h625.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-74p7-53wh-h625", - "modified": "2024-09-17T00:31:04Z", + "modified": "2024-09-24T18:31:23Z", "published": "2024-09-17T00:31:04Z", "aliases": [ "CVE-2024-40846" ], "details": "The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.7, macOS Sequoia 15. Processing a maliciously crafted video file may lead to unexpected app termination.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T00:15:49Z" diff --git a/advisories/unreviewed/2024/09/GHSA-7c3x-gh76-g622/GHSA-7c3x-gh76-g622.json b/advisories/unreviewed/2024/09/GHSA-7c3x-gh76-g622/GHSA-7c3x-gh76-g622.json index 2efc35e4b22..b97ed739778 100644 --- a/advisories/unreviewed/2024/09/GHSA-7c3x-gh76-g622/GHSA-7c3x-gh76-g622.json +++ b/advisories/unreviewed/2024/09/GHSA-7c3x-gh76-g622/GHSA-7c3x-gh76-g622.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7c3x-gh76-g622", - "modified": "2024-09-18T15:30:52Z", + "modified": "2024-09-24T18:31:25Z", "published": "2024-09-18T15:30:52Z", "aliases": [ "CVE-2024-46551" ], "details": "Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sBPA_Pwd parameter at inet15.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T15:15:16Z" diff --git a/advisories/unreviewed/2024/09/GHSA-7ghv-w4w7-gjc3/GHSA-7ghv-w4w7-gjc3.json b/advisories/unreviewed/2024/09/GHSA-7ghv-w4w7-gjc3/GHSA-7ghv-w4w7-gjc3.json index 598cd24746f..72ca38f16ca 100644 --- a/advisories/unreviewed/2024/09/GHSA-7ghv-w4w7-gjc3/GHSA-7ghv-w4w7-gjc3.json +++ b/advisories/unreviewed/2024/09/GHSA-7ghv-w4w7-gjc3/GHSA-7ghv-w4w7-gjc3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7ghv-w4w7-gjc3", - "modified": "2024-09-18T15:30:53Z", + "modified": "2024-09-24T18:31:26Z", "published": "2024-09-18T15:30:53Z", "aliases": [ "CVE-2024-46586" ], "details": "Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sCloudPass parameter at v2x00.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T15:15:17Z" diff --git a/advisories/unreviewed/2024/09/GHSA-7jjq-j5wq-j8cv/GHSA-7jjq-j5wq-j8cv.json b/advisories/unreviewed/2024/09/GHSA-7jjq-j5wq-j8cv/GHSA-7jjq-j5wq-j8cv.json index dee149ceafb..d9f7a25f213 100644 --- a/advisories/unreviewed/2024/09/GHSA-7jjq-j5wq-j8cv/GHSA-7jjq-j5wq-j8cv.json +++ b/advisories/unreviewed/2024/09/GHSA-7jjq-j5wq-j8cv/GHSA-7jjq-j5wq-j8cv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7jjq-j5wq-j8cv", - "modified": "2024-09-18T15:30:53Z", + "modified": "2024-09-24T18:31:26Z", "published": "2024-09-18T15:30:53Z", "aliases": [ "CVE-2024-46585" ], "details": "Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sProfileName parameter at usergrp.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T15:15:17Z" diff --git a/advisories/unreviewed/2024/09/GHSA-8vvc-wfcp-337x/GHSA-8vvc-wfcp-337x.json b/advisories/unreviewed/2024/09/GHSA-8vvc-wfcp-337x/GHSA-8vvc-wfcp-337x.json index ad91cb6d6e6..d3d4af8ef4d 100644 --- a/advisories/unreviewed/2024/09/GHSA-8vvc-wfcp-337x/GHSA-8vvc-wfcp-337x.json +++ b/advisories/unreviewed/2024/09/GHSA-8vvc-wfcp-337x/GHSA-8vvc-wfcp-337x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8vvc-wfcp-337x", - "modified": "2024-09-18T15:30:53Z", + "modified": "2024-09-24T18:31:26Z", "published": "2024-09-18T15:30:53Z", "aliases": [ "CVE-2024-46594" ], "details": "Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the saveVPNProfile parameter at v2x00.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T15:15:18Z" diff --git a/advisories/unreviewed/2024/09/GHSA-923m-rgj5-fgjh/GHSA-923m-rgj5-fgjh.json b/advisories/unreviewed/2024/09/GHSA-923m-rgj5-fgjh/GHSA-923m-rgj5-fgjh.json index f983f3e513b..310e6798b28 100644 --- a/advisories/unreviewed/2024/09/GHSA-923m-rgj5-fgjh/GHSA-923m-rgj5-fgjh.json +++ b/advisories/unreviewed/2024/09/GHSA-923m-rgj5-fgjh/GHSA-923m-rgj5-fgjh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-923m-rgj5-fgjh", - "modified": "2024-09-18T15:30:53Z", + "modified": "2024-09-24T18:31:26Z", "published": "2024-09-18T15:30:53Z", "aliases": [ "CVE-2024-46580" ], "details": "Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the fid parameter at v2x00.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T15:15:17Z" diff --git a/advisories/unreviewed/2024/09/GHSA-94jw-wm22-7fjx/GHSA-94jw-wm22-7fjx.json b/advisories/unreviewed/2024/09/GHSA-94jw-wm22-7fjx/GHSA-94jw-wm22-7fjx.json index 9119e7dbf04..3b97bb7f5b9 100644 --- a/advisories/unreviewed/2024/09/GHSA-94jw-wm22-7fjx/GHSA-94jw-wm22-7fjx.json +++ b/advisories/unreviewed/2024/09/GHSA-94jw-wm22-7fjx/GHSA-94jw-wm22-7fjx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-94jw-wm22-7fjx", - "modified": "2024-09-18T15:30:53Z", + "modified": "2024-09-24T18:31:27Z", "published": "2024-09-18T15:30:53Z", "aliases": [ "CVE-2024-46597" ], "details": "Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sPubKey parameter at dialin.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T15:15:18Z" diff --git a/advisories/unreviewed/2024/09/GHSA-963r-9g4m-v5vm/GHSA-963r-9g4m-v5vm.json b/advisories/unreviewed/2024/09/GHSA-963r-9g4m-v5vm/GHSA-963r-9g4m-v5vm.json index 87c8a8f178b..02deda42bd1 100644 --- a/advisories/unreviewed/2024/09/GHSA-963r-9g4m-v5vm/GHSA-963r-9g4m-v5vm.json +++ b/advisories/unreviewed/2024/09/GHSA-963r-9g4m-v5vm/GHSA-963r-9g4m-v5vm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-963r-9g4m-v5vm", - "modified": "2024-09-18T15:30:53Z", + "modified": "2024-09-24T18:31:26Z", "published": "2024-09-18T15:30:53Z", "aliases": [ "CVE-2024-46567" ], "details": "Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the iProfileIdx parameter at v2x00.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T15:15:17Z" diff --git a/advisories/unreviewed/2024/09/GHSA-96j7-6x53-7368/GHSA-96j7-6x53-7368.json b/advisories/unreviewed/2024/09/GHSA-96j7-6x53-7368/GHSA-96j7-6x53-7368.json index c5fb0fa8a8e..c80161e3f62 100644 --- a/advisories/unreviewed/2024/09/GHSA-96j7-6x53-7368/GHSA-96j7-6x53-7368.json +++ b/advisories/unreviewed/2024/09/GHSA-96j7-6x53-7368/GHSA-96j7-6x53-7368.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-96j7-6x53-7368", - "modified": "2024-09-17T00:31:06Z", + "modified": "2024-09-24T18:31:24Z", "published": "2024-09-17T00:31:06Z", "aliases": [ "CVE-2024-44186" ], "details": "An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15. An app may be able to access protected user data.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T00:15:51Z" diff --git a/advisories/unreviewed/2024/09/GHSA-9g9q-cf56-cfh9/GHSA-9g9q-cf56-cfh9.json b/advisories/unreviewed/2024/09/GHSA-9g9q-cf56-cfh9/GHSA-9g9q-cf56-cfh9.json index 8f2d14d4325..fd4367fcd88 100644 --- a/advisories/unreviewed/2024/09/GHSA-9g9q-cf56-cfh9/GHSA-9g9q-cf56-cfh9.json +++ b/advisories/unreviewed/2024/09/GHSA-9g9q-cf56-cfh9/GHSA-9g9q-cf56-cfh9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9g9q-cf56-cfh9", - "modified": "2024-09-17T00:31:05Z", + "modified": "2024-09-24T18:31:24Z", "published": "2024-09-17T00:31:05Z", "aliases": [ "CVE-2024-44151" ], "details": "A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Ventura 13.7, macOS Sonoma 14.7, macOS Sequoia 15. An app may be able to modify protected parts of the file system.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T00:15:50Z" diff --git a/advisories/unreviewed/2024/09/GHSA-9jxw-6cwc-fv29/GHSA-9jxw-6cwc-fv29.json b/advisories/unreviewed/2024/09/GHSA-9jxw-6cwc-fv29/GHSA-9jxw-6cwc-fv29.json index 5707346dd72..0587ddfc520 100644 --- a/advisories/unreviewed/2024/09/GHSA-9jxw-6cwc-fv29/GHSA-9jxw-6cwc-fv29.json +++ b/advisories/unreviewed/2024/09/GHSA-9jxw-6cwc-fv29/GHSA-9jxw-6cwc-fv29.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9jxw-6cwc-fv29", - "modified": "2024-09-17T00:31:05Z", + "modified": "2024-09-24T18:31:24Z", "published": "2024-09-17T00:31:05Z", "aliases": [ "CVE-2024-44154" ], "details": "A memory initialization issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.7, macOS Sequoia 15. Processing a maliciously crafted file may lead to unexpected app termination.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T00:15:50Z" diff --git a/advisories/unreviewed/2024/09/GHSA-9rg3-9338-mwcv/GHSA-9rg3-9338-mwcv.json b/advisories/unreviewed/2024/09/GHSA-9rg3-9338-mwcv/GHSA-9rg3-9338-mwcv.json index 8f0d8579105..df0d342155e 100644 --- a/advisories/unreviewed/2024/09/GHSA-9rg3-9338-mwcv/GHSA-9rg3-9338-mwcv.json +++ b/advisories/unreviewed/2024/09/GHSA-9rg3-9338-mwcv/GHSA-9rg3-9338-mwcv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9rg3-9338-mwcv", - "modified": "2024-09-17T00:31:05Z", + "modified": "2024-09-24T18:31:24Z", "published": "2024-09-17T00:31:05Z", "aliases": [ "CVE-2024-44139" ], "details": "The issue was addressed with improved checks. This issue is fixed in iOS 18 and iPadOS 18. An attacker with physical access may be able to access contacts from the lock screen.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T00:15:50Z" diff --git a/advisories/unreviewed/2024/09/GHSA-c5c4-5r7q-ccqv/GHSA-c5c4-5r7q-ccqv.json b/advisories/unreviewed/2024/09/GHSA-c5c4-5r7q-ccqv/GHSA-c5c4-5r7q-ccqv.json index 9fe29d2bfa4..285e09c87b7 100644 --- a/advisories/unreviewed/2024/09/GHSA-c5c4-5r7q-ccqv/GHSA-c5c4-5r7q-ccqv.json +++ b/advisories/unreviewed/2024/09/GHSA-c5c4-5r7q-ccqv/GHSA-c5c4-5r7q-ccqv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c5c4-5r7q-ccqv", - "modified": "2024-09-18T15:30:52Z", + "modified": "2024-09-24T18:31:26Z", "published": "2024-09-18T15:30:52Z", "aliases": [ "CVE-2024-46555" ], "details": "Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the pb parameter at v2x00.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T15:15:16Z" diff --git a/advisories/unreviewed/2024/09/GHSA-ccw9-q98h-qv5r/GHSA-ccw9-q98h-qv5r.json b/advisories/unreviewed/2024/09/GHSA-ccw9-q98h-qv5r/GHSA-ccw9-q98h-qv5r.json index 2c3451cce35..48e0bcefa97 100644 --- a/advisories/unreviewed/2024/09/GHSA-ccw9-q98h-qv5r/GHSA-ccw9-q98h-qv5r.json +++ b/advisories/unreviewed/2024/09/GHSA-ccw9-q98h-qv5r/GHSA-ccw9-q98h-qv5r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-ccw9-q98h-qv5r", - "modified": "2024-09-18T15:30:53Z", + "modified": "2024-09-24T18:31:26Z", "published": "2024-09-18T15:30:53Z", "aliases": [ "CVE-2024-46566" ], "details": "Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sAppName parameter at sslapp.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T15:15:17Z" diff --git a/advisories/unreviewed/2024/09/GHSA-cw5r-673r-7ww3/GHSA-cw5r-673r-7ww3.json b/advisories/unreviewed/2024/09/GHSA-cw5r-673r-7ww3/GHSA-cw5r-673r-7ww3.json index 65c72a68714..a8c4e7930aa 100644 --- a/advisories/unreviewed/2024/09/GHSA-cw5r-673r-7ww3/GHSA-cw5r-673r-7ww3.json +++ b/advisories/unreviewed/2024/09/GHSA-cw5r-673r-7ww3/GHSA-cw5r-673r-7ww3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cw5r-673r-7ww3", - "modified": "2024-09-17T00:31:04Z", + "modified": "2024-09-24T18:31:23Z", "published": "2024-09-17T00:31:04Z", "aliases": [ "CVE-2024-40797" ], "details": "This issue was addressed through improved state management. This issue is fixed in macOS Ventura 13.7, macOS Sonoma 14.7, macOS Sequoia 15. Visiting a malicious website may lead to user interface spoofing.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T00:15:48Z" diff --git a/advisories/unreviewed/2024/09/GHSA-cxhr-64cg-3mjp/GHSA-cxhr-64cg-3mjp.json b/advisories/unreviewed/2024/09/GHSA-cxhr-64cg-3mjp/GHSA-cxhr-64cg-3mjp.json index 499cacc018a..5d94c7d07e0 100644 --- a/advisories/unreviewed/2024/09/GHSA-cxhr-64cg-3mjp/GHSA-cxhr-64cg-3mjp.json +++ b/advisories/unreviewed/2024/09/GHSA-cxhr-64cg-3mjp/GHSA-cxhr-64cg-3mjp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cxhr-64cg-3mjp", - "modified": "2024-09-18T15:30:53Z", + "modified": "2024-09-24T18:31:26Z", "published": "2024-09-18T15:30:53Z", "aliases": [ "CVE-2024-46591" ], "details": "Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sDnsPro parameter at v2x00.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T15:15:18Z" diff --git a/advisories/unreviewed/2024/09/GHSA-f826-4hr5-hxxx/GHSA-f826-4hr5-hxxx.json b/advisories/unreviewed/2024/09/GHSA-f826-4hr5-hxxx/GHSA-f826-4hr5-hxxx.json index 5fa14c766ce..be786703be3 100644 --- a/advisories/unreviewed/2024/09/GHSA-f826-4hr5-hxxx/GHSA-f826-4hr5-hxxx.json +++ b/advisories/unreviewed/2024/09/GHSA-f826-4hr5-hxxx/GHSA-f826-4hr5-hxxx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f826-4hr5-hxxx", - "modified": "2024-09-18T15:30:53Z", + "modified": "2024-09-24T18:31:26Z", "published": "2024-09-18T15:30:53Z", "aliases": [ "CVE-2024-46592" ], "details": "Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the ssidencrypt_5g%d parameter at v2x00.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T15:15:18Z" diff --git a/advisories/unreviewed/2024/09/GHSA-fgx2-m7jc-63xr/GHSA-fgx2-m7jc-63xr.json b/advisories/unreviewed/2024/09/GHSA-fgx2-m7jc-63xr/GHSA-fgx2-m7jc-63xr.json index 7cf9c45fad3..81bbd744661 100644 --- a/advisories/unreviewed/2024/09/GHSA-fgx2-m7jc-63xr/GHSA-fgx2-m7jc-63xr.json +++ b/advisories/unreviewed/2024/09/GHSA-fgx2-m7jc-63xr/GHSA-fgx2-m7jc-63xr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fgx2-m7jc-63xr", - "modified": "2024-09-18T15:30:53Z", + "modified": "2024-09-24T18:31:26Z", "published": "2024-09-18T15:30:53Z", "aliases": [ "CVE-2024-46564" ], "details": "Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sProfileName parameter at fextobj.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T15:15:17Z" diff --git a/advisories/unreviewed/2024/09/GHSA-fpgw-4ghq-mm93/GHSA-fpgw-4ghq-mm93.json b/advisories/unreviewed/2024/09/GHSA-fpgw-4ghq-mm93/GHSA-fpgw-4ghq-mm93.json index c6569100d82..e2ead155fbd 100644 --- a/advisories/unreviewed/2024/09/GHSA-fpgw-4ghq-mm93/GHSA-fpgw-4ghq-mm93.json +++ b/advisories/unreviewed/2024/09/GHSA-fpgw-4ghq-mm93/GHSA-fpgw-4ghq-mm93.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fpgw-4ghq-mm93", - "modified": "2024-09-18T15:30:53Z", + "modified": "2024-09-24T18:31:26Z", "published": "2024-09-18T15:30:53Z", "aliases": [ "CVE-2024-46561" ], "details": "Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the queryret parameter at v2x00.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T15:15:17Z" diff --git a/advisories/unreviewed/2024/09/GHSA-fqmh-8xfw-5v84/GHSA-fqmh-8xfw-5v84.json b/advisories/unreviewed/2024/09/GHSA-fqmh-8xfw-5v84/GHSA-fqmh-8xfw-5v84.json index e607a715442..006eb4e64d2 100644 --- a/advisories/unreviewed/2024/09/GHSA-fqmh-8xfw-5v84/GHSA-fqmh-8xfw-5v84.json +++ b/advisories/unreviewed/2024/09/GHSA-fqmh-8xfw-5v84/GHSA-fqmh-8xfw-5v84.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fqmh-8xfw-5v84", - "modified": "2024-09-18T15:30:52Z", + "modified": "2024-09-24T18:31:26Z", "published": "2024-09-18T15:30:52Z", "aliases": [ "CVE-2024-46560" ], "details": "Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the pub_key parameter at v2x00.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T15:15:17Z" diff --git a/advisories/unreviewed/2024/09/GHSA-g2r8-m367-m72p/GHSA-g2r8-m367-m72p.json b/advisories/unreviewed/2024/09/GHSA-g2r8-m367-m72p/GHSA-g2r8-m367-m72p.json index aa0570cd670..41bc166db6f 100644 --- a/advisories/unreviewed/2024/09/GHSA-g2r8-m367-m72p/GHSA-g2r8-m367-m72p.json +++ b/advisories/unreviewed/2024/09/GHSA-g2r8-m367-m72p/GHSA-g2r8-m367-m72p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g2r8-m367-m72p", - "modified": "2024-09-18T21:30:48Z", + "modified": "2024-09-24T18:31:27Z", "published": "2024-09-18T21:30:48Z", "aliases": [ "CVE-2024-46372" ], "details": "DedeCMS 5.7.115 is vulnerable to Cross Site Scripting (XSS) via the advertisement code box in the advertisement management module.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T21:15:13Z" diff --git a/advisories/unreviewed/2024/09/GHSA-gvw8-h5c5-pr3g/GHSA-gvw8-h5c5-pr3g.json b/advisories/unreviewed/2024/09/GHSA-gvw8-h5c5-pr3g/GHSA-gvw8-h5c5-pr3g.json index 9debe8b447f..8ed41b18108 100644 --- a/advisories/unreviewed/2024/09/GHSA-gvw8-h5c5-pr3g/GHSA-gvw8-h5c5-pr3g.json +++ b/advisories/unreviewed/2024/09/GHSA-gvw8-h5c5-pr3g/GHSA-gvw8-h5c5-pr3g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gvw8-h5c5-pr3g", - "modified": "2024-09-17T00:31:05Z", + "modified": "2024-09-24T18:31:24Z", "published": "2024-09-17T00:31:05Z", "aliases": [ "CVE-2024-44146" ], "details": "A logic issue was addressed with improved file handling. This issue is fixed in macOS Sequoia 15. An app may be able to break out of its sandbox.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T00:15:50Z" diff --git a/advisories/unreviewed/2024/09/GHSA-gw53-chv8-4wr2/GHSA-gw53-chv8-4wr2.json b/advisories/unreviewed/2024/09/GHSA-gw53-chv8-4wr2/GHSA-gw53-chv8-4wr2.json index 5b573ed7d92..4b8efbfc9e1 100644 --- a/advisories/unreviewed/2024/09/GHSA-gw53-chv8-4wr2/GHSA-gw53-chv8-4wr2.json +++ b/advisories/unreviewed/2024/09/GHSA-gw53-chv8-4wr2/GHSA-gw53-chv8-4wr2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gw53-chv8-4wr2", - "modified": "2024-09-17T00:31:04Z", + "modified": "2024-09-24T18:31:24Z", "published": "2024-09-17T00:31:04Z", "aliases": [ "CVE-2024-40847" ], "details": "The issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Ventura 13.7, macOS Sonoma 14.7, macOS Sequoia 15. An app may be able to access sensitive user data.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T00:15:49Z" diff --git a/advisories/unreviewed/2024/09/GHSA-h2pr-ggrm-q7gx/GHSA-h2pr-ggrm-q7gx.json b/advisories/unreviewed/2024/09/GHSA-h2pr-ggrm-q7gx/GHSA-h2pr-ggrm-q7gx.json index c8b78752137..4a0b4f3af50 100644 --- a/advisories/unreviewed/2024/09/GHSA-h2pr-ggrm-q7gx/GHSA-h2pr-ggrm-q7gx.json +++ b/advisories/unreviewed/2024/09/GHSA-h2pr-ggrm-q7gx/GHSA-h2pr-ggrm-q7gx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h2pr-ggrm-q7gx", - "modified": "2024-09-18T15:30:53Z", + "modified": "2024-09-24T18:31:26Z", "published": "2024-09-18T15:30:53Z", "aliases": [ "CVE-2024-46588" ], "details": "Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sProfileName parameter at wizfw.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T15:15:17Z" diff --git a/advisories/unreviewed/2024/09/GHSA-h498-88jq-wh8m/GHSA-h498-88jq-wh8m.json b/advisories/unreviewed/2024/09/GHSA-h498-88jq-wh8m/GHSA-h498-88jq-wh8m.json index 9396e64faab..7c24db48a22 100644 --- a/advisories/unreviewed/2024/09/GHSA-h498-88jq-wh8m/GHSA-h498-88jq-wh8m.json +++ b/advisories/unreviewed/2024/09/GHSA-h498-88jq-wh8m/GHSA-h498-88jq-wh8m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h498-88jq-wh8m", - "modified": "2024-09-17T00:31:04Z", + "modified": "2024-09-24T18:31:23Z", "published": "2024-09-17T00:31:04Z", "aliases": [ "CVE-2024-40791" ], "details": "A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Ventura 13.7, iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macOS Sonoma 14.7, macOS Sequoia 15. An app may be able to access information about a user's contacts.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-532" ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T00:15:48Z" diff --git a/advisories/unreviewed/2024/09/GHSA-h89v-mw4f-7wgj/GHSA-h89v-mw4f-7wgj.json b/advisories/unreviewed/2024/09/GHSA-h89v-mw4f-7wgj/GHSA-h89v-mw4f-7wgj.json index ee27f3d6662..de8a5bb04fd 100644 --- a/advisories/unreviewed/2024/09/GHSA-h89v-mw4f-7wgj/GHSA-h89v-mw4f-7wgj.json +++ b/advisories/unreviewed/2024/09/GHSA-h89v-mw4f-7wgj/GHSA-h89v-mw4f-7wgj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h89v-mw4f-7wgj", - "modified": "2024-09-17T00:31:04Z", + "modified": "2024-09-24T18:31:23Z", "published": "2024-09-17T00:31:04Z", "aliases": [ "CVE-2024-40801" ], "details": "A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.7, macOS Sequoia 15. An app may be able to access protected user data.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T00:15:48Z" diff --git a/advisories/unreviewed/2024/09/GHSA-hx98-qf58-hff9/GHSA-hx98-qf58-hff9.json b/advisories/unreviewed/2024/09/GHSA-hx98-qf58-hff9/GHSA-hx98-qf58-hff9.json index 0530314416a..1668869b680 100644 --- a/advisories/unreviewed/2024/09/GHSA-hx98-qf58-hff9/GHSA-hx98-qf58-hff9.json +++ b/advisories/unreviewed/2024/09/GHSA-hx98-qf58-hff9/GHSA-hx98-qf58-hff9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hx98-qf58-hff9", - "modified": "2024-09-17T00:31:05Z", + "modified": "2024-09-24T18:31:24Z", "published": "2024-09-17T00:31:05Z", "aliases": [ "CVE-2024-44152" ], "details": "A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15. An app may be able to access user-sensitive data.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T00:15:50Z" diff --git a/advisories/unreviewed/2024/09/GHSA-j962-w243-6g33/GHSA-j962-w243-6g33.json b/advisories/unreviewed/2024/09/GHSA-j962-w243-6g33/GHSA-j962-w243-6g33.json index ab0ea24423d..bbc6f178376 100644 --- a/advisories/unreviewed/2024/09/GHSA-j962-w243-6g33/GHSA-j962-w243-6g33.json +++ b/advisories/unreviewed/2024/09/GHSA-j962-w243-6g33/GHSA-j962-w243-6g33.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j962-w243-6g33", - "modified": "2024-09-17T00:31:06Z", + "modified": "2024-09-24T18:31:24Z", "published": "2024-09-17T00:31:06Z", "aliases": [ "CVE-2024-44178" ], "details": "This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Ventura 13.7, macOS Sonoma 14.7, macOS Sequoia 15. An app may be able to modify protected parts of the file system.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-59" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T00:15:51Z" diff --git a/advisories/unreviewed/2024/09/GHSA-jpf3-j9x5-w3ff/GHSA-jpf3-j9x5-w3ff.json b/advisories/unreviewed/2024/09/GHSA-jpf3-j9x5-w3ff/GHSA-jpf3-j9x5-w3ff.json index 7046ef41e54..494b328841a 100644 --- a/advisories/unreviewed/2024/09/GHSA-jpf3-j9x5-w3ff/GHSA-jpf3-j9x5-w3ff.json +++ b/advisories/unreviewed/2024/09/GHSA-jpf3-j9x5-w3ff/GHSA-jpf3-j9x5-w3ff.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jpf3-j9x5-w3ff", - "modified": "2024-09-17T00:31:05Z", + "modified": "2024-09-24T18:31:24Z", "published": "2024-09-17T00:31:05Z", "aliases": [ "CVE-2024-44133" ], "details": "This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15. On MDM managed devices, an app may be able to bypass certain Privacy preferences.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T00:15:50Z" diff --git a/advisories/unreviewed/2024/09/GHSA-jvcj-gmhm-rfx5/GHSA-jvcj-gmhm-rfx5.json b/advisories/unreviewed/2024/09/GHSA-jvcj-gmhm-rfx5/GHSA-jvcj-gmhm-rfx5.json index 1f108c3a04a..7eb0549cea4 100644 --- a/advisories/unreviewed/2024/09/GHSA-jvcj-gmhm-rfx5/GHSA-jvcj-gmhm-rfx5.json +++ b/advisories/unreviewed/2024/09/GHSA-jvcj-gmhm-rfx5/GHSA-jvcj-gmhm-rfx5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jvcj-gmhm-rfx5", - "modified": "2024-09-17T00:31:06Z", + "modified": "2024-09-24T18:31:24Z", "published": "2024-09-17T00:31:05Z", "aliases": [ "CVE-2024-44171" ], "details": "This issue was addressed through improved state management. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, watchOS 11. An attacker with physical access to a locked device may be able to Control Nearby Devices via accessibility features.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T00:15:51Z" diff --git a/advisories/unreviewed/2024/09/GHSA-m38v-7vc8-5x55/GHSA-m38v-7vc8-5x55.json b/advisories/unreviewed/2024/09/GHSA-m38v-7vc8-5x55/GHSA-m38v-7vc8-5x55.json index e22ff8b007d..60a2504f567 100644 --- a/advisories/unreviewed/2024/09/GHSA-m38v-7vc8-5x55/GHSA-m38v-7vc8-5x55.json +++ b/advisories/unreviewed/2024/09/GHSA-m38v-7vc8-5x55/GHSA-m38v-7vc8-5x55.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m38v-7vc8-5x55", - "modified": "2024-09-18T15:30:53Z", + "modified": "2024-09-24T18:31:26Z", "published": "2024-09-18T15:30:53Z", "aliases": [ "CVE-2024-46584" ], "details": "Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the AControlIp1 parameter at acontrol.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T15:15:17Z" diff --git a/advisories/unreviewed/2024/09/GHSA-m548-7rvw-m5fc/GHSA-m548-7rvw-m5fc.json b/advisories/unreviewed/2024/09/GHSA-m548-7rvw-m5fc/GHSA-m548-7rvw-m5fc.json index 132d23c7858..9d1d5766ee4 100644 --- a/advisories/unreviewed/2024/09/GHSA-m548-7rvw-m5fc/GHSA-m548-7rvw-m5fc.json +++ b/advisories/unreviewed/2024/09/GHSA-m548-7rvw-m5fc/GHSA-m548-7rvw-m5fc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m548-7rvw-m5fc", - "modified": "2024-09-17T00:31:04Z", + "modified": "2024-09-24T18:31:23Z", "published": "2024-09-17T00:31:04Z", "aliases": [ "CVE-2024-40844" ], "details": "A privacy issue was addressed with improved handling of temporary files. This issue is fixed in iOS 17.7 and iPadOS 17.7, macOS Ventura 13.7, macOS Sonoma 14.7, macOS Sequoia 15. An app may be able to observe data displayed to the user by Shortcuts.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -39,7 +42,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T00:15:49Z" diff --git a/advisories/unreviewed/2024/09/GHSA-m67j-wqgc-38f3/GHSA-m67j-wqgc-38f3.json b/advisories/unreviewed/2024/09/GHSA-m67j-wqgc-38f3/GHSA-m67j-wqgc-38f3.json index 7a78d4fc8ad..7fd8103422b 100644 --- a/advisories/unreviewed/2024/09/GHSA-m67j-wqgc-38f3/GHSA-m67j-wqgc-38f3.json +++ b/advisories/unreviewed/2024/09/GHSA-m67j-wqgc-38f3/GHSA-m67j-wqgc-38f3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m67j-wqgc-38f3", - "modified": "2024-09-18T15:30:53Z", + "modified": "2024-09-24T18:31:26Z", "published": "2024-09-18T15:30:53Z", "aliases": [ "CVE-2024-46568" ], "details": "Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sPeerId parameter at vpn.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T15:15:17Z" diff --git a/advisories/unreviewed/2024/09/GHSA-m9g4-52vh-fwwv/GHSA-m9g4-52vh-fwwv.json b/advisories/unreviewed/2024/09/GHSA-m9g4-52vh-fwwv/GHSA-m9g4-52vh-fwwv.json index e73ac077f15..dda40222d12 100644 --- a/advisories/unreviewed/2024/09/GHSA-m9g4-52vh-fwwv/GHSA-m9g4-52vh-fwwv.json +++ b/advisories/unreviewed/2024/09/GHSA-m9g4-52vh-fwwv/GHSA-m9g4-52vh-fwwv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m9g4-52vh-fwwv", - "modified": "2024-09-17T00:31:04Z", + "modified": "2024-09-24T18:31:24Z", "published": "2024-09-17T00:31:04Z", "aliases": [ "CVE-2024-40848" ], "details": "A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Ventura 13.7, macOS Sonoma 14.7, macOS Sequoia 15. An attacker may be able to read sensitive information.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T00:15:49Z" diff --git a/advisories/unreviewed/2024/09/GHSA-mh89-qc88-2rhh/GHSA-mh89-qc88-2rhh.json b/advisories/unreviewed/2024/09/GHSA-mh89-qc88-2rhh/GHSA-mh89-qc88-2rhh.json index 1aa086b8c2f..4d59453e1d4 100644 --- a/advisories/unreviewed/2024/09/GHSA-mh89-qc88-2rhh/GHSA-mh89-qc88-2rhh.json +++ b/advisories/unreviewed/2024/09/GHSA-mh89-qc88-2rhh/GHSA-mh89-qc88-2rhh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mh89-qc88-2rhh", - "modified": "2024-09-18T15:30:53Z", + "modified": "2024-09-24T18:31:26Z", "published": "2024-09-18T15:30:53Z", "aliases": [ "CVE-2024-46595" ], "details": "Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the saveitem parameter at lan2lan.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T15:15:18Z" diff --git a/advisories/unreviewed/2024/09/GHSA-q7q2-gf23-qgjw/GHSA-q7q2-gf23-qgjw.json b/advisories/unreviewed/2024/09/GHSA-q7q2-gf23-qgjw/GHSA-q7q2-gf23-qgjw.json index 167c7c6cecc..4bc4dfb42bf 100644 --- a/advisories/unreviewed/2024/09/GHSA-q7q2-gf23-qgjw/GHSA-q7q2-gf23-qgjw.json +++ b/advisories/unreviewed/2024/09/GHSA-q7q2-gf23-qgjw/GHSA-q7q2-gf23-qgjw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q7q2-gf23-qgjw", - "modified": "2024-09-17T00:31:06Z", + "modified": "2024-09-24T18:31:24Z", "published": "2024-09-17T00:31:06Z", "aliases": [ "CVE-2024-44177" ], "details": "A privacy issue was addressed by removing sensitive data. This issue is fixed in macOS Ventura 13.7, macOS Sonoma 14.7, macOS Sequoia 15. An app may be able to access user-sensitive data.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T00:15:51Z" diff --git a/advisories/unreviewed/2024/09/GHSA-qm78-568c-wg6m/GHSA-qm78-568c-wg6m.json b/advisories/unreviewed/2024/09/GHSA-qm78-568c-wg6m/GHSA-qm78-568c-wg6m.json index 370a0355feb..775ef14a64b 100644 --- a/advisories/unreviewed/2024/09/GHSA-qm78-568c-wg6m/GHSA-qm78-568c-wg6m.json +++ b/advisories/unreviewed/2024/09/GHSA-qm78-568c-wg6m/GHSA-qm78-568c-wg6m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qm78-568c-wg6m", - "modified": "2024-09-17T00:31:05Z", + "modified": "2024-09-24T18:31:24Z", "published": "2024-09-17T00:31:05Z", "aliases": [ "CVE-2024-44158" ], "details": "This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 17.7 and iPadOS 17.7, macOS Ventura 13.7, macOS Sonoma 14.7, macOS Sequoia 15. A shortcut may output sensitive user data without consent.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -39,7 +42,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T00:15:50Z" diff --git a/advisories/unreviewed/2024/09/GHSA-r773-284v-hh8m/GHSA-r773-284v-hh8m.json b/advisories/unreviewed/2024/09/GHSA-r773-284v-hh8m/GHSA-r773-284v-hh8m.json index 6019c5ff8be..c1ba56da417 100644 --- a/advisories/unreviewed/2024/09/GHSA-r773-284v-hh8m/GHSA-r773-284v-hh8m.json +++ b/advisories/unreviewed/2024/09/GHSA-r773-284v-hh8m/GHSA-r773-284v-hh8m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r773-284v-hh8m", - "modified": "2024-09-17T00:31:03Z", + "modified": "2024-09-24T18:31:23Z", "published": "2024-09-17T00:31:03Z", "aliases": [ "CVE-2024-27880" ], "details": "An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS 17.7 and iPadOS 17.7, visionOS 2, watchOS 11, macOS Sequoia 15, iOS 18 and iPadOS 18, macOS Sonoma 14.7, tvOS 18. Processing a maliciously crafted file may lead to unexpected app termination.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -49,9 +52,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T00:15:48Z" diff --git a/advisories/unreviewed/2024/09/GHSA-v64w-2rh7-3gvr/GHSA-v64w-2rh7-3gvr.json b/advisories/unreviewed/2024/09/GHSA-v64w-2rh7-3gvr/GHSA-v64w-2rh7-3gvr.json index 09bf117e908..70c49dcf7c3 100644 --- a/advisories/unreviewed/2024/09/GHSA-v64w-2rh7-3gvr/GHSA-v64w-2rh7-3gvr.json +++ b/advisories/unreviewed/2024/09/GHSA-v64w-2rh7-3gvr/GHSA-v64w-2rh7-3gvr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v64w-2rh7-3gvr", - "modified": "2024-09-17T00:31:06Z", + "modified": "2024-09-24T18:31:24Z", "published": "2024-09-17T00:31:06Z", "aliases": [ "CVE-2024-44182" ], "details": "This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Ventura 13.7, macOS Sonoma 14.7, macOS Sequoia 15. An app may be able to access sensitive data logged when a shortcut fails to launch another app.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T00:15:51Z" diff --git a/advisories/unreviewed/2024/09/GHSA-w7c2-w23x-h6pm/GHSA-w7c2-w23x-h6pm.json b/advisories/unreviewed/2024/09/GHSA-w7c2-w23x-h6pm/GHSA-w7c2-w23x-h6pm.json index 6b97521906c..aba2a04b269 100644 --- a/advisories/unreviewed/2024/09/GHSA-w7c2-w23x-h6pm/GHSA-w7c2-w23x-h6pm.json +++ b/advisories/unreviewed/2024/09/GHSA-w7c2-w23x-h6pm/GHSA-w7c2-w23x-h6pm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w7c2-w23x-h6pm", - "modified": "2024-09-18T15:30:52Z", + "modified": "2024-09-24T18:31:25Z", "published": "2024-09-18T15:30:52Z", "aliases": [ "CVE-2024-46556" ], "details": "Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sInRCSecret0 parameter at v2x00.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T15:15:16Z" diff --git a/advisories/unreviewed/2024/09/GHSA-wjmr-4ghf-rh39/GHSA-wjmr-4ghf-rh39.json b/advisories/unreviewed/2024/09/GHSA-wjmr-4ghf-rh39/GHSA-wjmr-4ghf-rh39.json index 62c9a320300..3b52770eb79 100644 --- a/advisories/unreviewed/2024/09/GHSA-wjmr-4ghf-rh39/GHSA-wjmr-4ghf-rh39.json +++ b/advisories/unreviewed/2024/09/GHSA-wjmr-4ghf-rh39/GHSA-wjmr-4ghf-rh39.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wjmr-4ghf-rh39", - "modified": "2024-09-17T00:31:06Z", + "modified": "2024-09-24T18:31:25Z", "published": "2024-09-17T00:31:06Z", "aliases": [ "CVE-2024-44190" ], "details": "A path handling issue was addressed with improved validation. This issue is fixed in macOS Ventura 13.7, macOS Sonoma 14.7, macOS Sequoia 15. An app may be able to read arbitrary files.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T00:15:52Z" diff --git a/advisories/unreviewed/2024/09/GHSA-x44q-9q24-vjf9/GHSA-x44q-9q24-vjf9.json b/advisories/unreviewed/2024/09/GHSA-x44q-9q24-vjf9/GHSA-x44q-9q24-vjf9.json index 7be650b7f45..7f00b0bb865 100644 --- a/advisories/unreviewed/2024/09/GHSA-x44q-9q24-vjf9/GHSA-x44q-9q24-vjf9.json +++ b/advisories/unreviewed/2024/09/GHSA-x44q-9q24-vjf9/GHSA-x44q-9q24-vjf9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x44q-9q24-vjf9", - "modified": "2024-09-17T00:31:06Z", + "modified": "2024-09-24T18:31:25Z", "published": "2024-09-17T00:31:06Z", "aliases": [ "CVE-2024-44198" ], "details": "An integer overflow was addressed through improved input validation. This issue is fixed in visionOS 2, watchOS 11, macOS Sequoia 15, iOS 18 and iPadOS 18, tvOS 18. Processing maliciously crafted web content may lead to an unexpected process crash.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-190" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T00:15:52Z" diff --git a/advisories/unreviewed/2024/09/GHSA-x79g-r583-xj83/GHSA-x79g-r583-xj83.json b/advisories/unreviewed/2024/09/GHSA-x79g-r583-xj83/GHSA-x79g-r583-xj83.json index 0886082fac9..5509488b676 100644 --- a/advisories/unreviewed/2024/09/GHSA-x79g-r583-xj83/GHSA-x79g-r583-xj83.json +++ b/advisories/unreviewed/2024/09/GHSA-x79g-r583-xj83/GHSA-x79g-r583-xj83.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x79g-r583-xj83", - "modified": "2024-09-17T00:31:05Z", + "modified": "2024-09-24T18:31:24Z", "published": "2024-09-17T00:31:05Z", "aliases": [ "CVE-2024-44134" ], "details": "This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15. An app may be able to read sensitive location information.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T00:15:50Z" diff --git a/advisories/unreviewed/2024/09/GHSA-xhrw-4447-w35f/GHSA-xhrw-4447-w35f.json b/advisories/unreviewed/2024/09/GHSA-xhrw-4447-w35f/GHSA-xhrw-4447-w35f.json index e2ceb0ca274..33f44c011fd 100644 --- a/advisories/unreviewed/2024/09/GHSA-xhrw-4447-w35f/GHSA-xhrw-4447-w35f.json +++ b/advisories/unreviewed/2024/09/GHSA-xhrw-4447-w35f/GHSA-xhrw-4447-w35f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xhrw-4447-w35f", - "modified": "2024-09-17T00:31:04Z", + "modified": "2024-09-24T18:31:23Z", "published": "2024-09-17T00:31:04Z", "aliases": [ "CVE-2024-40845" ], "details": "The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.7, macOS Sequoia 15. Processing a maliciously crafted video file may lead to unexpected app termination.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T00:15:49Z" diff --git a/advisories/unreviewed/2024/09/GHSA-xxmj-qmq4-g4j9/GHSA-xxmj-qmq4-g4j9.json b/advisories/unreviewed/2024/09/GHSA-xxmj-qmq4-g4j9/GHSA-xxmj-qmq4-g4j9.json index df43fb238ba..19d602d0497 100644 --- a/advisories/unreviewed/2024/09/GHSA-xxmj-qmq4-g4j9/GHSA-xxmj-qmq4-g4j9.json +++ b/advisories/unreviewed/2024/09/GHSA-xxmj-qmq4-g4j9/GHSA-xxmj-qmq4-g4j9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xxmj-qmq4-g4j9", - "modified": "2024-09-18T15:30:53Z", + "modified": "2024-09-24T18:31:27Z", "published": "2024-09-18T15:30:53Z", "aliases": [ "CVE-2024-46598" ], "details": "Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the iprofileidx parameter at dialin.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T15:15:18Z"