mirror of
https://github.com/netbirdio/advisory-database.git
synced 2026-05-22 18:04:22 -07:00
Advisory Database Sync
This commit is contained in:
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-2fq4-2pvp-hvr5",
|
||||
"modified": "2023-11-06T03:30:28Z",
|
||||
"modified": "2024-10-01T21:31:32Z",
|
||||
"published": "2023-08-09T09:30:32Z",
|
||||
"aliases": [
|
||||
"CVE-2022-47185"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-6cx7-2m7q-5fh3",
|
||||
"modified": "2024-01-31T18:31:19Z",
|
||||
"modified": "2024-10-01T21:31:33Z",
|
||||
"published": "2023-08-15T18:31:33Z",
|
||||
"aliases": [
|
||||
"CVE-2023-4357"
|
||||
@@ -48,7 +48,7 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
"CWE-20"
|
||||
],
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": false,
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-jcg7-j3jq-wp4r",
|
||||
"modified": "2023-11-06T03:30:28Z",
|
||||
"modified": "2024-10-01T21:31:32Z",
|
||||
"published": "2023-08-09T09:30:32Z",
|
||||
"aliases": [
|
||||
"CVE-2023-33934"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-mjq9-8vf6-qh49",
|
||||
"modified": "2024-01-31T18:31:19Z",
|
||||
"modified": "2024-10-01T21:31:32Z",
|
||||
"published": "2023-08-15T18:31:33Z",
|
||||
"aliases": [
|
||||
"CVE-2023-4353"
|
||||
@@ -48,6 +48,7 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-122",
|
||||
"CWE-787"
|
||||
],
|
||||
"severity": "HIGH",
|
||||
|
||||
@@ -28,6 +28,7 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-20",
|
||||
"CWE-787"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-6v6c-gc45-x65c",
|
||||
"modified": "2024-08-21T15:30:49Z",
|
||||
"modified": "2024-10-01T21:31:33Z",
|
||||
"published": "2024-02-12T15:30:23Z",
|
||||
"aliases": [
|
||||
"CVE-2024-1062"
|
||||
@@ -45,6 +45,10 @@
|
||||
"type": "WEB",
|
||||
"url": "https://access.redhat.com/errata/RHSA-2024:5690"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://access.redhat.com/errata/RHSA-2024:7458"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://access.redhat.com/security/cve/CVE-2024-1062"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-9h7v-6cr6-hcpx",
|
||||
"modified": "2024-09-11T12:30:51Z",
|
||||
"modified": "2024-10-01T21:31:33Z",
|
||||
"published": "2024-06-18T12:30:41Z",
|
||||
"aliases": [
|
||||
"CVE-2024-5953"
|
||||
@@ -53,6 +53,10 @@
|
||||
"type": "WEB",
|
||||
"url": "https://access.redhat.com/errata/RHSA-2024:6576"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://access.redhat.com/errata/RHSA-2024:7458"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://access.redhat.com/security/cve/CVE-2024-5953"
|
||||
|
||||
@@ -44,7 +44,8 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-121"
|
||||
"CWE-121",
|
||||
"CWE-787"
|
||||
],
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": false,
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-gc6q-hh4v-5gvq",
|
||||
"modified": "2024-07-11T18:31:12Z",
|
||||
"modified": "2024-10-01T21:31:33Z",
|
||||
"published": "2024-07-11T00:32:51Z",
|
||||
"aliases": [
|
||||
"CVE-2024-39560"
|
||||
|
||||
@@ -1,14 +1,17 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-cc36-87rj-xmc4",
|
||||
"modified": "2024-09-25T18:31:21Z",
|
||||
"modified": "2024-10-01T21:31:33Z",
|
||||
"published": "2024-09-25T18:31:21Z",
|
||||
"aliases": [
|
||||
"CVE-2024-41445"
|
||||
],
|
||||
"details": "Library MDF (mdflib) v2.1 is vulnerable to a heap-based buffer overread via a crafted mdf4 file is parsed using the ReadData function",
|
||||
"severity": [
|
||||
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
@@ -25,9 +28,9 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
"CWE-787"
|
||||
],
|
||||
"severity": null,
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-09-25T17:15:18Z"
|
||||
|
||||
@@ -1,14 +1,17 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-p5fp-56mj-rxm3",
|
||||
"modified": "2024-09-25T18:31:20Z",
|
||||
"modified": "2024-10-01T21:31:33Z",
|
||||
"published": "2024-09-25T18:31:20Z",
|
||||
"aliases": [
|
||||
"CVE-2024-7421"
|
||||
],
|
||||
"details": "An information exposure in Devolutions Remote Desktop Manager 2024.2.20.0 and earlier on Windows allows local attackers with access to system logs to obtain session credentials via passwords included in command-line arguments when launching WinSCP sessions",
|
||||
"severity": [
|
||||
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
@@ -27,7 +30,7 @@
|
||||
"cwe_ids": [
|
||||
"CWE-532"
|
||||
],
|
||||
"severity": null,
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-09-25T16:15:11Z"
|
||||
|
||||
@@ -1,14 +1,17 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-x829-m68r-85mm",
|
||||
"modified": "2024-09-25T15:31:13Z",
|
||||
"modified": "2024-10-01T21:31:33Z",
|
||||
"published": "2024-09-25T15:31:12Z",
|
||||
"aliases": [
|
||||
"CVE-2024-22892"
|
||||
],
|
||||
"details": "OpenSlides 4.0.15 was discovered to be using a weak hashing algorithm to store passwords.",
|
||||
"severity": [
|
||||
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
@@ -25,9 +28,9 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
"CWE-326"
|
||||
],
|
||||
"severity": null,
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-09-25T15:15:13Z"
|
||||
|
||||
@@ -0,0 +1,39 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-34fm-4fgc-9w37",
|
||||
"modified": "2024-10-01T21:31:34Z",
|
||||
"published": "2024-10-01T21:31:34Z",
|
||||
"aliases": [
|
||||
"CVE-2024-46082"
|
||||
],
|
||||
"details": "Scriptcase v.9.10.023 and before is vulnerable to Cross Site Scripting (XSS) in nm_cor.php via the form and field parameters.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46082"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://blog.hawktesters.com/zero-day-alert-scriptcase-vulnerabilities-rce"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://blog.hawktesters.com/zero-day-alert-scriptcase-vulnerabilities-xss"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-10-01T21:15:06Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,42 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-3h3x-2hwv-hr52",
|
||||
"modified": "2024-10-01T21:31:34Z",
|
||||
"published": "2024-10-01T21:31:34Z",
|
||||
"aliases": [
|
||||
"CVE-2024-9355"
|
||||
],
|
||||
"details": "A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed buffer to be returned in FIPS mode. It may also be possible to force a false positive match between non-equal hashes when comparing a trusted computed hmac sum to an untrusted input sum if an attacker can send a zeroed buffer in place of a pre-computed sum. It is also possible to force a derived key to be all zeros instead of an unpredictable value. This may have follow-on implications for the Go TLS stack.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9355"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://access.redhat.com/security/cve/CVE-2024-9355"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2315719"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-457"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-10-01T19:15:09Z"
|
||||
}
|
||||
}
|
||||
@@ -1,14 +1,17 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-482v-6rp2-p55w",
|
||||
"modified": "2024-10-01T18:31:18Z",
|
||||
"modified": "2024-10-01T21:31:34Z",
|
||||
"published": "2024-10-01T18:31:18Z",
|
||||
"aliases": [
|
||||
"CVE-2024-25660"
|
||||
],
|
||||
"details": "The WebDAV service in Infinera TNMS (Transcend Network Management System) 19.10.3 allows a low-privileged remote attacker to conduct unauthorized file operations, because of execution with unnecessary privileges.",
|
||||
"severity": [
|
||||
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
@@ -25,9 +28,9 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
"CWE-266"
|
||||
],
|
||||
"severity": null,
|
||||
"severity": "CRITICAL",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-10-01T16:15:09Z"
|
||||
|
||||
@@ -0,0 +1,39 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-5wwp-5xg3-xwh6",
|
||||
"modified": "2024-10-01T21:31:34Z",
|
||||
"published": "2024-10-01T21:31:34Z",
|
||||
"aliases": [
|
||||
"CVE-2024-31835"
|
||||
],
|
||||
"details": "Cross Site Scripting vulnerability in flatpress CMS Flatpress v1.3 allows a remote attacker to execute arbitrary code via a crafted payload to the file name parameter.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31835"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://drive.google.com/file/d/1OthtP87MduNTYur_p0RZv3moY8CrBcaM/view"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/paragbagul111/CVE-2024-31835"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-10-01T19:15:07Z"
|
||||
}
|
||||
}
|
||||
@@ -1,14 +1,17 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-667m-43f5-gwwr",
|
||||
"modified": "2024-10-01T18:31:18Z",
|
||||
"modified": "2024-10-01T21:31:34Z",
|
||||
"published": "2024-10-01T18:31:18Z",
|
||||
"aliases": [
|
||||
"CVE-2024-9396"
|
||||
],
|
||||
"details": "It is currently unknown if this issue is exploitable but a condition may arise where the structured clone of certain objects could lead to memory corruption. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.",
|
||||
"severity": [
|
||||
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
@@ -41,9 +44,9 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
"CWE-119"
|
||||
],
|
||||
"severity": null,
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-10-01T16:15:10Z"
|
||||
|
||||
@@ -0,0 +1,39 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-7cj2-6wfj-9p3m",
|
||||
"modified": "2024-10-01T21:31:34Z",
|
||||
"published": "2024-10-01T21:31:34Z",
|
||||
"aliases": [
|
||||
"CVE-2024-46084"
|
||||
],
|
||||
"details": "Scriptcase 9.10.023 and before is vulnerable to Remote Code Execution (RCE) via the nm_unzip function.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46084"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://blog.hawktesters.com/zero-day-alert-scriptcase-vulnerabilities-rce"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "http://scriptcase.com"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-10-01T21:15:06Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,35 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-7m36-cp6h-v658",
|
||||
"modified": "2024-10-01T21:31:34Z",
|
||||
"published": "2024-10-01T21:31:34Z",
|
||||
"aliases": [
|
||||
"CVE-2024-46080"
|
||||
],
|
||||
"details": "Scriptcase v9.10.023 and before is vulnerable to Remote Code Execution (RCE) via the nm_zip function.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46080"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://blog.hawktesters.com/zero-day-alert-scriptcase-vulnerabilities-rce"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-10-01T21:15:06Z"
|
||||
}
|
||||
}
|
||||
@@ -1,14 +1,17 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-94mm-6r76-6pgh",
|
||||
"modified": "2024-10-01T18:31:19Z",
|
||||
"modified": "2024-10-01T21:31:34Z",
|
||||
"published": "2024-10-01T18:31:19Z",
|
||||
"aliases": [
|
||||
"CVE-2024-9403"
|
||||
],
|
||||
"details": "Memory safety bugs present in Firefox 130. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 131 and Thunderbird < 131.",
|
||||
"severity": [
|
||||
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
@@ -35,7 +38,7 @@
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-10-01T16:15:11Z"
|
||||
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user