From 56984234033e73ebc70d4ddf57963c7e15c026e3 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 1 Oct 2024 21:33:07 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-2fq4-2pvp-hvr5.json | 2 +- .../GHSA-6cx7-2m7q-5fh3.json | 4 +- .../GHSA-jcg7-j3jq-wp4r.json | 2 +- .../GHSA-mjq9-8vf6-qh49.json | 3 +- .../GHSA-rhcf-rv63-774j.json | 1 + .../GHSA-6v6c-gc45-x65c.json | 6 ++- .../GHSA-9h7v-6cr6-hcpx.json | 6 ++- .../GHSA-c685-q6wp-j7wq.json | 3 +- .../GHSA-gc6q-hh4v-5gvq.json | 2 +- .../GHSA-cc36-87rj-xmc4.json | 11 ++-- .../GHSA-p5fp-56mj-rxm3.json | 9 ++-- .../GHSA-x829-m68r-85mm.json | 11 ++-- .../GHSA-34fm-4fgc-9w37.json | 39 +++++++++++++++ .../GHSA-3h3x-2hwv-hr52.json | 42 ++++++++++++++++ .../GHSA-482v-6rp2-p55w.json | 11 ++-- .../GHSA-5wwp-5xg3-xwh6.json | 39 +++++++++++++++ .../GHSA-667m-43f5-gwwr.json | 11 ++-- .../GHSA-7cj2-6wfj-9p3m.json | 39 +++++++++++++++ .../GHSA-7m36-cp6h-v658.json | 35 +++++++++++++ .../GHSA-94mm-6r76-6pgh.json | 9 ++-- .../GHSA-99rj-hj9g-wrcv.json | 11 ++-- .../GHSA-9gjr-hc3c-4w38.json | 38 ++++++++++++++ .../GHSA-fc27-6qvc-xq94.json | 11 ++-- .../GHSA-fhqq-8f65-5xfc.json | 42 ++++++++++++++++ .../GHSA-gxrc-fm43-25gv.json | 11 ++-- .../GHSA-h4hg-6856-qv2j.json | 38 ++++++++++++++ .../GHSA-hc6r-wpfc-q7m8.json | 11 ++-- .../GHSA-jq66-g5qg-w7wf.json | 42 ++++++++++++++++ .../GHSA-m4rx-3qxq-mgjf.json | 11 ++-- .../GHSA-mc76-5925-c5p6.json | 50 +++++++++++++++++++ .../GHSA-pggh-h238-4qvj.json | 50 +++++++++++++++++++ .../GHSA-r28p-rpv4-w54r.json | 11 ++-- .../GHSA-rmm7-6q86-gphj.json | 38 ++++++++++++++ .../GHSA-v5jv-g2mh-7rmh.json | 35 +++++++++++++ .../GHSA-xxc2-5537-pj53.json | 11 ++-- 35 files changed, 636 insertions(+), 59 deletions(-) create mode 100644 advisories/unreviewed/2024/10/GHSA-34fm-4fgc-9w37/GHSA-34fm-4fgc-9w37.json create mode 100644 advisories/unreviewed/2024/10/GHSA-3h3x-2hwv-hr52/GHSA-3h3x-2hwv-hr52.json create mode 100644 advisories/unreviewed/2024/10/GHSA-5wwp-5xg3-xwh6/GHSA-5wwp-5xg3-xwh6.json create mode 100644 advisories/unreviewed/2024/10/GHSA-7cj2-6wfj-9p3m/GHSA-7cj2-6wfj-9p3m.json create mode 100644 advisories/unreviewed/2024/10/GHSA-7m36-cp6h-v658/GHSA-7m36-cp6h-v658.json create mode 100644 advisories/unreviewed/2024/10/GHSA-9gjr-hc3c-4w38/GHSA-9gjr-hc3c-4w38.json create mode 100644 advisories/unreviewed/2024/10/GHSA-fhqq-8f65-5xfc/GHSA-fhqq-8f65-5xfc.json create mode 100644 advisories/unreviewed/2024/10/GHSA-h4hg-6856-qv2j/GHSA-h4hg-6856-qv2j.json create mode 100644 advisories/unreviewed/2024/10/GHSA-jq66-g5qg-w7wf/GHSA-jq66-g5qg-w7wf.json create mode 100644 advisories/unreviewed/2024/10/GHSA-mc76-5925-c5p6/GHSA-mc76-5925-c5p6.json create mode 100644 advisories/unreviewed/2024/10/GHSA-pggh-h238-4qvj/GHSA-pggh-h238-4qvj.json create mode 100644 advisories/unreviewed/2024/10/GHSA-rmm7-6q86-gphj/GHSA-rmm7-6q86-gphj.json create mode 100644 advisories/unreviewed/2024/10/GHSA-v5jv-g2mh-7rmh/GHSA-v5jv-g2mh-7rmh.json diff --git a/advisories/unreviewed/2023/08/GHSA-2fq4-2pvp-hvr5/GHSA-2fq4-2pvp-hvr5.json b/advisories/unreviewed/2023/08/GHSA-2fq4-2pvp-hvr5/GHSA-2fq4-2pvp-hvr5.json index ce10d3e3f44..27fa28b7526 100644 --- a/advisories/unreviewed/2023/08/GHSA-2fq4-2pvp-hvr5/GHSA-2fq4-2pvp-hvr5.json +++ b/advisories/unreviewed/2023/08/GHSA-2fq4-2pvp-hvr5/GHSA-2fq4-2pvp-hvr5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2fq4-2pvp-hvr5", - "modified": "2023-11-06T03:30:28Z", + "modified": "2024-10-01T21:31:32Z", "published": "2023-08-09T09:30:32Z", "aliases": [ "CVE-2022-47185" diff --git a/advisories/unreviewed/2023/08/GHSA-6cx7-2m7q-5fh3/GHSA-6cx7-2m7q-5fh3.json b/advisories/unreviewed/2023/08/GHSA-6cx7-2m7q-5fh3/GHSA-6cx7-2m7q-5fh3.json index 0ac988f3292..40f277705db 100644 --- a/advisories/unreviewed/2023/08/GHSA-6cx7-2m7q-5fh3/GHSA-6cx7-2m7q-5fh3.json +++ b/advisories/unreviewed/2023/08/GHSA-6cx7-2m7q-5fh3/GHSA-6cx7-2m7q-5fh3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6cx7-2m7q-5fh3", - "modified": "2024-01-31T18:31:19Z", + "modified": "2024-10-01T21:31:33Z", "published": "2023-08-15T18:31:33Z", "aliases": [ "CVE-2023-4357" @@ -48,7 +48,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-20" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/08/GHSA-jcg7-j3jq-wp4r/GHSA-jcg7-j3jq-wp4r.json b/advisories/unreviewed/2023/08/GHSA-jcg7-j3jq-wp4r/GHSA-jcg7-j3jq-wp4r.json index 0726606244e..a54927969f5 100644 --- a/advisories/unreviewed/2023/08/GHSA-jcg7-j3jq-wp4r/GHSA-jcg7-j3jq-wp4r.json +++ b/advisories/unreviewed/2023/08/GHSA-jcg7-j3jq-wp4r/GHSA-jcg7-j3jq-wp4r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jcg7-j3jq-wp4r", - "modified": "2023-11-06T03:30:28Z", + "modified": "2024-10-01T21:31:32Z", "published": "2023-08-09T09:30:32Z", "aliases": [ "CVE-2023-33934" diff --git a/advisories/unreviewed/2023/08/GHSA-mjq9-8vf6-qh49/GHSA-mjq9-8vf6-qh49.json b/advisories/unreviewed/2023/08/GHSA-mjq9-8vf6-qh49/GHSA-mjq9-8vf6-qh49.json index 18e5c4ad172..2dca9ad86c0 100644 --- a/advisories/unreviewed/2023/08/GHSA-mjq9-8vf6-qh49/GHSA-mjq9-8vf6-qh49.json +++ b/advisories/unreviewed/2023/08/GHSA-mjq9-8vf6-qh49/GHSA-mjq9-8vf6-qh49.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mjq9-8vf6-qh49", - "modified": "2024-01-31T18:31:19Z", + "modified": "2024-10-01T21:31:32Z", "published": "2023-08-15T18:31:33Z", "aliases": [ "CVE-2023-4353" @@ -48,6 +48,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-122", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/09/GHSA-rhcf-rv63-774j/GHSA-rhcf-rv63-774j.json b/advisories/unreviewed/2023/09/GHSA-rhcf-rv63-774j/GHSA-rhcf-rv63-774j.json index b8b46f32457..0f9625a9f8f 100644 --- a/advisories/unreviewed/2023/09/GHSA-rhcf-rv63-774j/GHSA-rhcf-rv63-774j.json +++ b/advisories/unreviewed/2023/09/GHSA-rhcf-rv63-774j/GHSA-rhcf-rv63-774j.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-20", "CWE-787" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/02/GHSA-6v6c-gc45-x65c/GHSA-6v6c-gc45-x65c.json b/advisories/unreviewed/2024/02/GHSA-6v6c-gc45-x65c/GHSA-6v6c-gc45-x65c.json index 6b71da7cdec..8fcab6cce20 100644 --- a/advisories/unreviewed/2024/02/GHSA-6v6c-gc45-x65c/GHSA-6v6c-gc45-x65c.json +++ b/advisories/unreviewed/2024/02/GHSA-6v6c-gc45-x65c/GHSA-6v6c-gc45-x65c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6v6c-gc45-x65c", - "modified": "2024-08-21T15:30:49Z", + "modified": "2024-10-01T21:31:33Z", "published": "2024-02-12T15:30:23Z", "aliases": [ "CVE-2024-1062" @@ -45,6 +45,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:5690" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:7458" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-1062" diff --git a/advisories/unreviewed/2024/06/GHSA-9h7v-6cr6-hcpx/GHSA-9h7v-6cr6-hcpx.json b/advisories/unreviewed/2024/06/GHSA-9h7v-6cr6-hcpx/GHSA-9h7v-6cr6-hcpx.json index 8fd0d7f388a..0907332ff71 100644 --- a/advisories/unreviewed/2024/06/GHSA-9h7v-6cr6-hcpx/GHSA-9h7v-6cr6-hcpx.json +++ b/advisories/unreviewed/2024/06/GHSA-9h7v-6cr6-hcpx/GHSA-9h7v-6cr6-hcpx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9h7v-6cr6-hcpx", - "modified": "2024-09-11T12:30:51Z", + "modified": "2024-10-01T21:31:33Z", "published": "2024-06-18T12:30:41Z", "aliases": [ "CVE-2024-5953" @@ -53,6 +53,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:6576" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:7458" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-5953" diff --git a/advisories/unreviewed/2024/07/GHSA-c685-q6wp-j7wq/GHSA-c685-q6wp-j7wq.json b/advisories/unreviewed/2024/07/GHSA-c685-q6wp-j7wq/GHSA-c685-q6wp-j7wq.json index 353394ffb11..6920a9c1888 100644 --- a/advisories/unreviewed/2024/07/GHSA-c685-q6wp-j7wq/GHSA-c685-q6wp-j7wq.json +++ b/advisories/unreviewed/2024/07/GHSA-c685-q6wp-j7wq/GHSA-c685-q6wp-j7wq.json @@ -44,7 +44,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-gc6q-hh4v-5gvq/GHSA-gc6q-hh4v-5gvq.json b/advisories/unreviewed/2024/07/GHSA-gc6q-hh4v-5gvq/GHSA-gc6q-hh4v-5gvq.json index 1fa2cc1f58b..9ce01e2f76e 100644 --- a/advisories/unreviewed/2024/07/GHSA-gc6q-hh4v-5gvq/GHSA-gc6q-hh4v-5gvq.json +++ b/advisories/unreviewed/2024/07/GHSA-gc6q-hh4v-5gvq/GHSA-gc6q-hh4v-5gvq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gc6q-hh4v-5gvq", - "modified": "2024-07-11T18:31:12Z", + "modified": "2024-10-01T21:31:33Z", "published": "2024-07-11T00:32:51Z", "aliases": [ "CVE-2024-39560" diff --git a/advisories/unreviewed/2024/09/GHSA-cc36-87rj-xmc4/GHSA-cc36-87rj-xmc4.json b/advisories/unreviewed/2024/09/GHSA-cc36-87rj-xmc4/GHSA-cc36-87rj-xmc4.json index 809441ae911..7c46098e97a 100644 --- a/advisories/unreviewed/2024/09/GHSA-cc36-87rj-xmc4/GHSA-cc36-87rj-xmc4.json +++ b/advisories/unreviewed/2024/09/GHSA-cc36-87rj-xmc4/GHSA-cc36-87rj-xmc4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cc36-87rj-xmc4", - "modified": "2024-09-25T18:31:21Z", + "modified": "2024-10-01T21:31:33Z", "published": "2024-09-25T18:31:21Z", "aliases": [ "CVE-2024-41445" ], "details": "Library MDF (mdflib) v2.1 is vulnerable to a heap-based buffer overread via a crafted mdf4 file is parsed using the ReadData function", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-25T17:15:18Z" diff --git a/advisories/unreviewed/2024/09/GHSA-p5fp-56mj-rxm3/GHSA-p5fp-56mj-rxm3.json b/advisories/unreviewed/2024/09/GHSA-p5fp-56mj-rxm3/GHSA-p5fp-56mj-rxm3.json index a14c2f323f0..eca2e3dc8e9 100644 --- a/advisories/unreviewed/2024/09/GHSA-p5fp-56mj-rxm3/GHSA-p5fp-56mj-rxm3.json +++ b/advisories/unreviewed/2024/09/GHSA-p5fp-56mj-rxm3/GHSA-p5fp-56mj-rxm3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p5fp-56mj-rxm3", - "modified": "2024-09-25T18:31:20Z", + "modified": "2024-10-01T21:31:33Z", "published": "2024-09-25T18:31:20Z", "aliases": [ "CVE-2024-7421" ], "details": "An information exposure in Devolutions Remote Desktop Manager 2024.2.20.0 and earlier on Windows allows local attackers with access to system logs to obtain session credentials via passwords included in command-line arguments when launching WinSCP sessions", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-532" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-25T16:15:11Z" diff --git a/advisories/unreviewed/2024/09/GHSA-x829-m68r-85mm/GHSA-x829-m68r-85mm.json b/advisories/unreviewed/2024/09/GHSA-x829-m68r-85mm/GHSA-x829-m68r-85mm.json index 6a27a26face..8193e90a9c4 100644 --- a/advisories/unreviewed/2024/09/GHSA-x829-m68r-85mm/GHSA-x829-m68r-85mm.json +++ b/advisories/unreviewed/2024/09/GHSA-x829-m68r-85mm/GHSA-x829-m68r-85mm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x829-m68r-85mm", - "modified": "2024-09-25T15:31:13Z", + "modified": "2024-10-01T21:31:33Z", "published": "2024-09-25T15:31:12Z", "aliases": [ "CVE-2024-22892" ], "details": "OpenSlides 4.0.15 was discovered to be using a weak hashing algorithm to store passwords.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-326" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-25T15:15:13Z" diff --git a/advisories/unreviewed/2024/10/GHSA-34fm-4fgc-9w37/GHSA-34fm-4fgc-9w37.json b/advisories/unreviewed/2024/10/GHSA-34fm-4fgc-9w37/GHSA-34fm-4fgc-9w37.json new file mode 100644 index 00000000000..4e0fe9e6247 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-34fm-4fgc-9w37/GHSA-34fm-4fgc-9w37.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-34fm-4fgc-9w37", + "modified": "2024-10-01T21:31:34Z", + "published": "2024-10-01T21:31:34Z", + "aliases": [ + "CVE-2024-46082" + ], + "details": "Scriptcase v.9.10.023 and before is vulnerable to Cross Site Scripting (XSS) in nm_cor.php via the form and field parameters.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46082" + }, + { + "type": "WEB", + "url": "https://blog.hawktesters.com/zero-day-alert-scriptcase-vulnerabilities-rce" + }, + { + "type": "WEB", + "url": "https://blog.hawktesters.com/zero-day-alert-scriptcase-vulnerabilities-xss" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-01T21:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-3h3x-2hwv-hr52/GHSA-3h3x-2hwv-hr52.json b/advisories/unreviewed/2024/10/GHSA-3h3x-2hwv-hr52/GHSA-3h3x-2hwv-hr52.json new file mode 100644 index 00000000000..eb467fd90b1 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-3h3x-2hwv-hr52/GHSA-3h3x-2hwv-hr52.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3h3x-2hwv-hr52", + "modified": "2024-10-01T21:31:34Z", + "published": "2024-10-01T21:31:34Z", + "aliases": [ + "CVE-2024-9355" + ], + "details": "A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed buffer to be returned in FIPS mode. It may also be possible to force a false positive match between non-equal hashes when comparing a trusted computed hmac sum to an untrusted input sum if an attacker can send a zeroed buffer in place of a pre-computed sum.  It is also possible to force a derived key to be all zeros instead of an unpredictable value.  This may have follow-on implications for the Go TLS stack.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9355" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-9355" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2315719" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-457" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-01T19:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-482v-6rp2-p55w/GHSA-482v-6rp2-p55w.json b/advisories/unreviewed/2024/10/GHSA-482v-6rp2-p55w/GHSA-482v-6rp2-p55w.json index b2b1b85d836..ec51729291e 100644 --- a/advisories/unreviewed/2024/10/GHSA-482v-6rp2-p55w/GHSA-482v-6rp2-p55w.json +++ b/advisories/unreviewed/2024/10/GHSA-482v-6rp2-p55w/GHSA-482v-6rp2-p55w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-482v-6rp2-p55w", - "modified": "2024-10-01T18:31:18Z", + "modified": "2024-10-01T21:31:34Z", "published": "2024-10-01T18:31:18Z", "aliases": [ "CVE-2024-25660" ], "details": "The WebDAV service in Infinera TNMS (Transcend Network Management System) 19.10.3 allows a low-privileged remote attacker to conduct unauthorized file operations, because of execution with unnecessary privileges.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-266" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-01T16:15:09Z" diff --git a/advisories/unreviewed/2024/10/GHSA-5wwp-5xg3-xwh6/GHSA-5wwp-5xg3-xwh6.json b/advisories/unreviewed/2024/10/GHSA-5wwp-5xg3-xwh6/GHSA-5wwp-5xg3-xwh6.json new file mode 100644 index 00000000000..8776ebfdf40 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-5wwp-5xg3-xwh6/GHSA-5wwp-5xg3-xwh6.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5wwp-5xg3-xwh6", + "modified": "2024-10-01T21:31:34Z", + "published": "2024-10-01T21:31:34Z", + "aliases": [ + "CVE-2024-31835" + ], + "details": "Cross Site Scripting vulnerability in flatpress CMS Flatpress v1.3 allows a remote attacker to execute arbitrary code via a crafted payload to the file name parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31835" + }, + { + "type": "WEB", + "url": "https://drive.google.com/file/d/1OthtP87MduNTYur_p0RZv3moY8CrBcaM/view" + }, + { + "type": "WEB", + "url": "https://github.com/paragbagul111/CVE-2024-31835" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-01T19:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-667m-43f5-gwwr/GHSA-667m-43f5-gwwr.json b/advisories/unreviewed/2024/10/GHSA-667m-43f5-gwwr/GHSA-667m-43f5-gwwr.json index d166bc3941e..a8ba39c9104 100644 --- a/advisories/unreviewed/2024/10/GHSA-667m-43f5-gwwr/GHSA-667m-43f5-gwwr.json +++ b/advisories/unreviewed/2024/10/GHSA-667m-43f5-gwwr/GHSA-667m-43f5-gwwr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-667m-43f5-gwwr", - "modified": "2024-10-01T18:31:18Z", + "modified": "2024-10-01T21:31:34Z", "published": "2024-10-01T18:31:18Z", "aliases": [ "CVE-2024-9396" ], "details": "It is currently unknown if this issue is exploitable but a condition may arise where the structured clone of certain objects could lead to memory corruption. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-119" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-01T16:15:10Z" diff --git a/advisories/unreviewed/2024/10/GHSA-7cj2-6wfj-9p3m/GHSA-7cj2-6wfj-9p3m.json b/advisories/unreviewed/2024/10/GHSA-7cj2-6wfj-9p3m/GHSA-7cj2-6wfj-9p3m.json new file mode 100644 index 00000000000..03276c3f62a --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-7cj2-6wfj-9p3m/GHSA-7cj2-6wfj-9p3m.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7cj2-6wfj-9p3m", + "modified": "2024-10-01T21:31:34Z", + "published": "2024-10-01T21:31:34Z", + "aliases": [ + "CVE-2024-46084" + ], + "details": "Scriptcase 9.10.023 and before is vulnerable to Remote Code Execution (RCE) via the nm_unzip function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46084" + }, + { + "type": "WEB", + "url": "https://blog.hawktesters.com/zero-day-alert-scriptcase-vulnerabilities-rce" + }, + { + "type": "WEB", + "url": "http://scriptcase.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-01T21:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-7m36-cp6h-v658/GHSA-7m36-cp6h-v658.json b/advisories/unreviewed/2024/10/GHSA-7m36-cp6h-v658/GHSA-7m36-cp6h-v658.json new file mode 100644 index 00000000000..2035a6b5bc9 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-7m36-cp6h-v658/GHSA-7m36-cp6h-v658.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7m36-cp6h-v658", + "modified": "2024-10-01T21:31:34Z", + "published": "2024-10-01T21:31:34Z", + "aliases": [ + "CVE-2024-46080" + ], + "details": "Scriptcase v9.10.023 and before is vulnerable to Remote Code Execution (RCE) via the nm_zip function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46080" + }, + { + "type": "WEB", + "url": "https://blog.hawktesters.com/zero-day-alert-scriptcase-vulnerabilities-rce" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-01T21:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-94mm-6r76-6pgh/GHSA-94mm-6r76-6pgh.json b/advisories/unreviewed/2024/10/GHSA-94mm-6r76-6pgh/GHSA-94mm-6r76-6pgh.json index 5520f7709e3..19da3fc5529 100644 --- a/advisories/unreviewed/2024/10/GHSA-94mm-6r76-6pgh/GHSA-94mm-6r76-6pgh.json +++ b/advisories/unreviewed/2024/10/GHSA-94mm-6r76-6pgh/GHSA-94mm-6r76-6pgh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-94mm-6r76-6pgh", - "modified": "2024-10-01T18:31:19Z", + "modified": "2024-10-01T21:31:34Z", "published": "2024-10-01T18:31:19Z", "aliases": [ "CVE-2024-9403" ], "details": "Memory safety bugs present in Firefox 130. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 131 and Thunderbird < 131.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-01T16:15:11Z" diff --git a/advisories/unreviewed/2024/10/GHSA-99rj-hj9g-wrcv/GHSA-99rj-hj9g-wrcv.json b/advisories/unreviewed/2024/10/GHSA-99rj-hj9g-wrcv/GHSA-99rj-hj9g-wrcv.json index 8bc21c27fda..d0456e0eaf6 100644 --- a/advisories/unreviewed/2024/10/GHSA-99rj-hj9g-wrcv/GHSA-99rj-hj9g-wrcv.json +++ b/advisories/unreviewed/2024/10/GHSA-99rj-hj9g-wrcv/GHSA-99rj-hj9g-wrcv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-99rj-hj9g-wrcv", - "modified": "2024-10-01T18:31:19Z", + "modified": "2024-10-01T21:31:34Z", "published": "2024-10-01T18:31:19Z", "aliases": [ "CVE-2024-9400" ], "details": "A potential memory corruption vulnerability could be triggered if an attacker had the ability to trigger an OOM at a specific moment during JIT compilation. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-119" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-01T16:15:11Z" diff --git a/advisories/unreviewed/2024/10/GHSA-9gjr-hc3c-4w38/GHSA-9gjr-hc3c-4w38.json b/advisories/unreviewed/2024/10/GHSA-9gjr-hc3c-4w38/GHSA-9gjr-hc3c-4w38.json new file mode 100644 index 00000000000..a8256d8bf25 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-9gjr-hc3c-4w38/GHSA-9gjr-hc3c-4w38.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9gjr-hc3c-4w38", + "modified": "2024-10-01T21:31:34Z", + "published": "2024-10-01T21:31:34Z", + "aliases": [ + "CVE-2024-46083" + ], + "details": "Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS). An authenticated user can craft malicious payloads using the messages feature, which allows the injection of malicious code into any user's account on the platform. It is important to note that regular users can trigger actions for administrator users.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46083" + }, + { + "type": "WEB", + "url": "https://blog.hawktesters.com/zero-day-alert-scriptcase-vulnerabilities-xss" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-01T19:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-fc27-6qvc-xq94/GHSA-fc27-6qvc-xq94.json b/advisories/unreviewed/2024/10/GHSA-fc27-6qvc-xq94/GHSA-fc27-6qvc-xq94.json index ce37d86410a..7e320e5098a 100644 --- a/advisories/unreviewed/2024/10/GHSA-fc27-6qvc-xq94/GHSA-fc27-6qvc-xq94.json +++ b/advisories/unreviewed/2024/10/GHSA-fc27-6qvc-xq94/GHSA-fc27-6qvc-xq94.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fc27-6qvc-xq94", - "modified": "2024-10-01T18:31:19Z", + "modified": "2024-10-01T21:31:34Z", "published": "2024-10-01T18:31:19Z", "aliases": [ "CVE-2024-9401" ], "details": "Memory safety bugs present in Firefox 130, Firefox ESR 115.15, Firefox ESR 128.2, and Thunderbird 128.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Firefox ESR < 115.16, Thunderbird < 128.3, and Thunderbird < 131.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-119" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-01T16:15:11Z" diff --git a/advisories/unreviewed/2024/10/GHSA-fhqq-8f65-5xfc/GHSA-fhqq-8f65-5xfc.json b/advisories/unreviewed/2024/10/GHSA-fhqq-8f65-5xfc/GHSA-fhqq-8f65-5xfc.json new file mode 100644 index 00000000000..97da52a533c --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-fhqq-8f65-5xfc/GHSA-fhqq-8f65-5xfc.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fhqq-8f65-5xfc", + "modified": "2024-10-01T21:31:35Z", + "published": "2024-10-01T21:31:35Z", + "aliases": [ + "CVE-2024-9407" + ], + "details": "A vulnerability exists in the bind-propagation option of the Dockerfile RUN --mount instruction. The system does not properly validate the input passed to this option, allowing users to pass arbitrary parameters to the mount instruction. This issue can be exploited to mount sensitive directories from the host into a container during the build process and, in some cases, modify the contents of those mounted files. Even if SELinux is used, this vulnerability can bypass its protection by allowing the source directory to be relabeled to give the container access to host files.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9407" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-9407" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2315887" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-01T21:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-gxrc-fm43-25gv/GHSA-gxrc-fm43-25gv.json b/advisories/unreviewed/2024/10/GHSA-gxrc-fm43-25gv/GHSA-gxrc-fm43-25gv.json index 4cd0634628b..fe97f8d1f9c 100644 --- a/advisories/unreviewed/2024/10/GHSA-gxrc-fm43-25gv/GHSA-gxrc-fm43-25gv.json +++ b/advisories/unreviewed/2024/10/GHSA-gxrc-fm43-25gv/GHSA-gxrc-fm43-25gv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gxrc-fm43-25gv", - "modified": "2024-10-01T15:32:05Z", + "modified": "2024-10-01T21:31:33Z", "published": "2024-10-01T15:32:05Z", "aliases": [ "CVE-2024-44744" ], "details": "An issue in Malwarebytes Premium Security v5.0.0.883 allows attackers to execute arbitrary code via placing crafted binaries into unspecified directories.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-01T14:15:05Z" diff --git a/advisories/unreviewed/2024/10/GHSA-h4hg-6856-qv2j/GHSA-h4hg-6856-qv2j.json b/advisories/unreviewed/2024/10/GHSA-h4hg-6856-qv2j/GHSA-h4hg-6856-qv2j.json new file mode 100644 index 00000000000..3acc103fd90 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-h4hg-6856-qv2j/GHSA-h4hg-6856-qv2j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h4hg-6856-qv2j", + "modified": "2024-10-01T21:31:34Z", + "published": "2024-10-01T21:31:34Z", + "aliases": [ + "CVE-2024-46081" + ], + "details": "Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS). An authenticated user can craft malicious payloads in the To-Do List. The assigned user will trigger a stored XSS, which is particularly dangerous because tasks are assigned to various users on the platform.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46081" + }, + { + "type": "WEB", + "url": "https://blog.hawktesters.com/zero-day-alert-scriptcase-vulnerabilities-xss" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-01T19:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-hc6r-wpfc-q7m8/GHSA-hc6r-wpfc-q7m8.json b/advisories/unreviewed/2024/10/GHSA-hc6r-wpfc-q7m8/GHSA-hc6r-wpfc-q7m8.json index 6b43e2a9ad7..2d2fc8006b0 100644 --- a/advisories/unreviewed/2024/10/GHSA-hc6r-wpfc-q7m8/GHSA-hc6r-wpfc-q7m8.json +++ b/advisories/unreviewed/2024/10/GHSA-hc6r-wpfc-q7m8/GHSA-hc6r-wpfc-q7m8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hc6r-wpfc-q7m8", - "modified": "2024-10-01T18:31:18Z", + "modified": "2024-10-01T21:31:34Z", "published": "2024-10-01T18:31:18Z", "aliases": [ "CVE-2024-9392" ], "details": "A compromised content process could have allowed for the arbitrary loading of cross-origin pages. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Firefox ESR < 115.16, Thunderbird < 128.3, and Thunderbird < 131.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -49,9 +52,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-346" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-01T16:15:10Z" diff --git a/advisories/unreviewed/2024/10/GHSA-jq66-g5qg-w7wf/GHSA-jq66-g5qg-w7wf.json b/advisories/unreviewed/2024/10/GHSA-jq66-g5qg-w7wf/GHSA-jq66-g5qg-w7wf.json new file mode 100644 index 00000000000..abbb17a1df4 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-jq66-g5qg-w7wf/GHSA-jq66-g5qg-w7wf.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jq66-g5qg-w7wf", + "modified": "2024-10-01T21:31:34Z", + "published": "2024-10-01T21:31:34Z", + "aliases": [ + "CVE-2024-42514" + ], + "details": "A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.1.0.4 could allow an unauthenticated attacker to conduct an unauthorized access attack due to inadequate access control checks. A successful exploit could allow an attacker to access sensitive information and send unauthorized messages.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42514" + }, + { + "type": "WEB", + "url": "https://www.mitel.com/support/security-advisories" + }, + { + "type": "WEB", + "url": "https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-24-0024" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-01T19:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-m4rx-3qxq-mgjf/GHSA-m4rx-3qxq-mgjf.json b/advisories/unreviewed/2024/10/GHSA-m4rx-3qxq-mgjf/GHSA-m4rx-3qxq-mgjf.json index 90850116649..886cac417ce 100644 --- a/advisories/unreviewed/2024/10/GHSA-m4rx-3qxq-mgjf/GHSA-m4rx-3qxq-mgjf.json +++ b/advisories/unreviewed/2024/10/GHSA-m4rx-3qxq-mgjf/GHSA-m4rx-3qxq-mgjf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m4rx-3qxq-mgjf", - "modified": "2024-10-01T15:32:09Z", + "modified": "2024-10-01T21:31:33Z", "published": "2024-10-01T15:32:09Z", "aliases": [ "CVE-2024-44610" ], "details": "PCAN-Ethernet Gateway FD before 1.3.0 and PCAN-Ethernet Gateway before 2.11.0 are vulnerable to Command injection.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-01T15:15:08Z" diff --git a/advisories/unreviewed/2024/10/GHSA-mc76-5925-c5p6/GHSA-mc76-5925-c5p6.json b/advisories/unreviewed/2024/10/GHSA-mc76-5925-c5p6/GHSA-mc76-5925-c5p6.json new file mode 100644 index 00000000000..b07badb9a7a --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-mc76-5925-c5p6/GHSA-mc76-5925-c5p6.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mc76-5925-c5p6", + "modified": "2024-10-01T21:31:34Z", + "published": "2024-10-01T21:31:34Z", + "aliases": [ + "CVE-2024-9341" + ], + "details": "A flaw was found in Go. When FIPS mode is enabled on a system, container runtimes may incorrectly handle certain file paths due to improper validation in the containers/common Go library. This flaw allows an attacker to exploit symbolic links and trick the system into mounting sensitive host directories inside a container. This issue also allows attackers to access critical host files, bypassing the intended isolation between containers and the host system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9341" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-9341" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2315691" + }, + { + "type": "WEB", + "url": "https://github.com/containers/common/blob/384f77532f67afc8a73d8e0c4adb0d195df57714/pkg/subscriptions/subscriptions.go#L169" + }, + { + "type": "WEB", + "url": "https://github.com/containers/common/blob/384f77532f67afc8a73d8e0c4adb0d195df57714/pkg/subscriptions/subscriptions.go#L349" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-01T19:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-pggh-h238-4qvj/GHSA-pggh-h238-4qvj.json b/advisories/unreviewed/2024/10/GHSA-pggh-h238-4qvj/GHSA-pggh-h238-4qvj.json new file mode 100644 index 00000000000..ac2cc8e15e8 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-pggh-h238-4qvj/GHSA-pggh-h238-4qvj.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pggh-h238-4qvj", + "modified": "2024-10-01T21:31:34Z", + "published": "2024-10-01T21:31:34Z", + "aliases": [ + "CVE-2024-9411" + ], + "details": "A vulnerability classified as problematic has been found in OFCMS 1.1.2. This affects the function add of the file /admin/system/dict/add.json?sqlid=system.dict.save. The manipulation of the argument dict_value leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9411" + }, + { + "type": "WEB", + "url": "https://gitee.com/oufu/ofcms/issues/IATECW" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.278973" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.278973" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-01T20:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-r28p-rpv4-w54r/GHSA-r28p-rpv4-w54r.json b/advisories/unreviewed/2024/10/GHSA-r28p-rpv4-w54r/GHSA-r28p-rpv4-w54r.json index 45ff3d47dc8..16cfe584074 100644 --- a/advisories/unreviewed/2024/10/GHSA-r28p-rpv4-w54r/GHSA-r28p-rpv4-w54r.json +++ b/advisories/unreviewed/2024/10/GHSA-r28p-rpv4-w54r/GHSA-r28p-rpv4-w54r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r28p-rpv4-w54r", - "modified": "2024-10-01T18:31:19Z", + "modified": "2024-10-01T21:31:34Z", "published": "2024-10-01T18:31:19Z", "aliases": [ "CVE-2024-9402" ], "details": "Memory safety bugs present in Firefox 130, Firefox ESR 128.2, and Thunderbird 128.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-119" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-01T16:15:11Z" diff --git a/advisories/unreviewed/2024/10/GHSA-rmm7-6q86-gphj/GHSA-rmm7-6q86-gphj.json b/advisories/unreviewed/2024/10/GHSA-rmm7-6q86-gphj/GHSA-rmm7-6q86-gphj.json new file mode 100644 index 00000000000..2003922d22e --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-rmm7-6q86-gphj/GHSA-rmm7-6q86-gphj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rmm7-6q86-gphj", + "modified": "2024-10-01T21:31:34Z", + "published": "2024-10-01T21:31:34Z", + "aliases": [ + "CVE-2024-46079" + ], + "details": "Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS) in proj_new.php via the Descricao parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46079" + }, + { + "type": "WEB", + "url": "https://blog.hawktesters.com/zero-day-alert-scriptcase-vulnerabilities-xss" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-01T19:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-v5jv-g2mh-7rmh/GHSA-v5jv-g2mh-7rmh.json b/advisories/unreviewed/2024/10/GHSA-v5jv-g2mh-7rmh/GHSA-v5jv-g2mh-7rmh.json new file mode 100644 index 00000000000..542244826b5 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-v5jv-g2mh-7rmh/GHSA-v5jv-g2mh-7rmh.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v5jv-g2mh-7rmh", + "modified": "2024-10-01T21:31:34Z", + "published": "2024-10-01T21:31:34Z", + "aliases": [ + "CVE-2024-45999" + ], + "details": "A SQL Injection vulnerability was discovered in Cloudlog 2.6.15, specifically within the get_station_info()function located in the file /application/models/Oqrs_model.php. The vulnerability is exploitable via the station_id parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45999" + }, + { + "type": "WEB", + "url": "https://chiggerlor.substack.com/p/cve-2024-45999" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-01T20:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-xxc2-5537-pj53/GHSA-xxc2-5537-pj53.json b/advisories/unreviewed/2024/10/GHSA-xxc2-5537-pj53/GHSA-xxc2-5537-pj53.json index d2ce0b41c84..336222d9d98 100644 --- a/advisories/unreviewed/2024/10/GHSA-xxc2-5537-pj53/GHSA-xxc2-5537-pj53.json +++ b/advisories/unreviewed/2024/10/GHSA-xxc2-5537-pj53/GHSA-xxc2-5537-pj53.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xxc2-5537-pj53", - "modified": "2024-10-01T18:31:18Z", + "modified": "2024-10-01T21:31:33Z", "published": "2024-10-01T18:31:18Z", "aliases": [ "CVE-2024-25659" ], "details": "In Infinera TNMS (Transcend Network Management System) 19.10.3, an insecure default configuration of the internal SFTP server on Linux servers allows remote attacker to access files and directories outside the SFTP user home directory.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-01T16:15:09Z"