From 57f95008f0bbde68098232fc832cf1ad254c1a68 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 20 May 2024 18:33:09 +0000 Subject: [PATCH] Publish Advisories GHSA-3c77-6pw4-hr87 GHSA-448x-875q-xjq4 GHSA-4w7m-g8vh-4gh7 GHSA-5f97-h2c2-826q GHSA-5vcp-m87w-9x8h GHSA-6gvx-hwp2-7mfq GHSA-74qv-wwr5-wmm5 GHSA-7chq-mr2c-3p6c GHSA-8vr4-h4rr-8ph6 GHSA-c39h-h953-m887 GHSA-g3q2-vcjq-rgrc GHSA-hp7j-hj47-34vh GHSA-jrwf-88rv-m9xr GHSA-qxjr-363m-qwfv GHSA-rv8j-7qfw-8mr3 GHSA-v8r8-56x7-prx6 GHSA-wx4v-qgjj-9f5j GHSA-xcxv-fxc3-wxmc GHSA-xhvq-7mc2-jx9w --- .../GHSA-3c77-6pw4-hr87.json | 38 +++++++++++++++++++ .../GHSA-448x-875q-xjq4.json | 38 +++++++++++++++++++ .../GHSA-4w7m-g8vh-4gh7.json | 35 +++++++++++++++++ .../GHSA-5f97-h2c2-826q.json | 35 +++++++++++++++++ .../GHSA-5vcp-m87w-9x8h.json | 38 +++++++++++++++++++ .../GHSA-6gvx-hwp2-7mfq.json | 35 +++++++++++++++++ .../GHSA-74qv-wwr5-wmm5.json | 35 +++++++++++++++++ .../GHSA-7chq-mr2c-3p6c.json | 38 +++++++++++++++++++ .../GHSA-8vr4-h4rr-8ph6.json | 35 +++++++++++++++++ .../GHSA-c39h-h953-m887.json | 35 +++++++++++++++++ .../GHSA-g3q2-vcjq-rgrc.json | 35 +++++++++++++++++ .../GHSA-hp7j-hj47-34vh.json | 2 +- .../GHSA-jrwf-88rv-m9xr.json | 35 +++++++++++++++++ .../GHSA-qxjr-363m-qwfv.json | 38 +++++++++++++++++++ .../GHSA-rv8j-7qfw-8mr3.json | 35 +++++++++++++++++ .../GHSA-v8r8-56x7-prx6.json | 35 +++++++++++++++++ .../GHSA-wx4v-qgjj-9f5j.json | 35 +++++++++++++++++ .../GHSA-xcxv-fxc3-wxmc.json | 35 +++++++++++++++++ .../GHSA-xhvq-7mc2-jx9w.json | 38 +++++++++++++++++++ 19 files changed, 649 insertions(+), 1 deletion(-) create mode 100644 advisories/unreviewed/2024/05/GHSA-3c77-6pw4-hr87/GHSA-3c77-6pw4-hr87.json create mode 100644 advisories/unreviewed/2024/05/GHSA-448x-875q-xjq4/GHSA-448x-875q-xjq4.json create mode 100644 advisories/unreviewed/2024/05/GHSA-4w7m-g8vh-4gh7/GHSA-4w7m-g8vh-4gh7.json create mode 100644 advisories/unreviewed/2024/05/GHSA-5f97-h2c2-826q/GHSA-5f97-h2c2-826q.json create mode 100644 advisories/unreviewed/2024/05/GHSA-5vcp-m87w-9x8h/GHSA-5vcp-m87w-9x8h.json create mode 100644 advisories/unreviewed/2024/05/GHSA-6gvx-hwp2-7mfq/GHSA-6gvx-hwp2-7mfq.json create mode 100644 advisories/unreviewed/2024/05/GHSA-74qv-wwr5-wmm5/GHSA-74qv-wwr5-wmm5.json create mode 100644 advisories/unreviewed/2024/05/GHSA-7chq-mr2c-3p6c/GHSA-7chq-mr2c-3p6c.json create mode 100644 advisories/unreviewed/2024/05/GHSA-8vr4-h4rr-8ph6/GHSA-8vr4-h4rr-8ph6.json create mode 100644 advisories/unreviewed/2024/05/GHSA-c39h-h953-m887/GHSA-c39h-h953-m887.json create mode 100644 advisories/unreviewed/2024/05/GHSA-g3q2-vcjq-rgrc/GHSA-g3q2-vcjq-rgrc.json create mode 100644 advisories/unreviewed/2024/05/GHSA-jrwf-88rv-m9xr/GHSA-jrwf-88rv-m9xr.json create mode 100644 advisories/unreviewed/2024/05/GHSA-qxjr-363m-qwfv/GHSA-qxjr-363m-qwfv.json create mode 100644 advisories/unreviewed/2024/05/GHSA-rv8j-7qfw-8mr3/GHSA-rv8j-7qfw-8mr3.json create mode 100644 advisories/unreviewed/2024/05/GHSA-v8r8-56x7-prx6/GHSA-v8r8-56x7-prx6.json create mode 100644 advisories/unreviewed/2024/05/GHSA-wx4v-qgjj-9f5j/GHSA-wx4v-qgjj-9f5j.json create mode 100644 advisories/unreviewed/2024/05/GHSA-xcxv-fxc3-wxmc/GHSA-xcxv-fxc3-wxmc.json create mode 100644 advisories/unreviewed/2024/05/GHSA-xhvq-7mc2-jx9w/GHSA-xhvq-7mc2-jx9w.json diff --git a/advisories/unreviewed/2024/05/GHSA-3c77-6pw4-hr87/GHSA-3c77-6pw4-hr87.json b/advisories/unreviewed/2024/05/GHSA-3c77-6pw4-hr87/GHSA-3c77-6pw4-hr87.json new file mode 100644 index 00000000000..dac7680cb63 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-3c77-6pw4-hr87/GHSA-3c77-6pw4-hr87.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3c77-6pw4-hr87", + "modified": "2024-05-20T18:31:22Z", + "published": "2024-05-20T18:31:22Z", + "aliases": [ + "CVE-2023-49332" + ], + "details": "Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection while adding file shares.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49332" + }, + { + "type": "WEB", + "url": "https://www.manageengine.com/products/active-directory-audit/sqlfix-7271.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-20T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-448x-875q-xjq4/GHSA-448x-875q-xjq4.json b/advisories/unreviewed/2024/05/GHSA-448x-875q-xjq4/GHSA-448x-875q-xjq4.json new file mode 100644 index 00000000000..09af523a52c --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-448x-875q-xjq4/GHSA-448x-875q-xjq4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-448x-875q-xjq4", + "modified": "2024-05-20T18:31:22Z", + "published": "2024-05-20T18:31:22Z", + "aliases": [ + "CVE-2023-49331" + ], + "details": "Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection in the aggregate reports search option.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49331" + }, + { + "type": "WEB", + "url": "https://www.manageengine.com/products/active-directory-audit/sqlfix-7271.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-20T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-4w7m-g8vh-4gh7/GHSA-4w7m-g8vh-4gh7.json b/advisories/unreviewed/2024/05/GHSA-4w7m-g8vh-4gh7/GHSA-4w7m-g8vh-4gh7.json new file mode 100644 index 00000000000..e94dd02bb98 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-4w7m-g8vh-4gh7/GHSA-4w7m-g8vh-4gh7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4w7m-g8vh-4gh7", + "modified": "2024-05-20T18:31:23Z", + "published": "2024-05-20T18:31:23Z", + "aliases": [ + "CVE-2024-35576" + ], + "details": "Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function formSetIptv.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35576" + }, + { + "type": "WEB", + "url": "https://detailed-stetson-767.notion.site/Tenda-AX1806-Buffer-Overflow-in-formSetIptv-cebf9202122a4582ae86c5253b3f6da3?pvs=4" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-20T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-5f97-h2c2-826q/GHSA-5f97-h2c2-826q.json b/advisories/unreviewed/2024/05/GHSA-5f97-h2c2-826q/GHSA-5f97-h2c2-826q.json new file mode 100644 index 00000000000..235656477cd --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-5f97-h2c2-826q/GHSA-5f97-h2c2-826q.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5f97-h2c2-826q", + "modified": "2024-05-20T18:31:23Z", + "published": "2024-05-20T18:31:23Z", + "aliases": [ + "CVE-2024-29651" + ], + "details": "A Prototype Pollution issue in API Dev Tools json-schema-ref-parser v.11.0.0 and v.11.1.0 allows a remote attacker to execute arbitrary code via the bundle()`, `parse()`, `resolve()`, `dereference() functions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29651" + }, + { + "type": "WEB", + "url": "https://gist.github.com/tariqhawis/5db76b38112bba756615b688c32409ad" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-20T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-5vcp-m87w-9x8h/GHSA-5vcp-m87w-9x8h.json b/advisories/unreviewed/2024/05/GHSA-5vcp-m87w-9x8h/GHSA-5vcp-m87w-9x8h.json new file mode 100644 index 00000000000..ef05b9c0f25 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-5vcp-m87w-9x8h/GHSA-5vcp-m87w-9x8h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5vcp-m87w-9x8h", + "modified": "2024-05-20T18:31:23Z", + "published": "2024-05-20T18:31:23Z", + "aliases": [ + "CVE-2023-49334" + ], + "details": "Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL Injection while exporting a full summary report.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49334" + }, + { + "type": "WEB", + "url": "https://www.manageengine.com/products/active-directory-audit/sqlfix-7271.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-20T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-6gvx-hwp2-7mfq/GHSA-6gvx-hwp2-7mfq.json b/advisories/unreviewed/2024/05/GHSA-6gvx-hwp2-7mfq/GHSA-6gvx-hwp2-7mfq.json new file mode 100644 index 00000000000..900a963bed1 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-6gvx-hwp2-7mfq/GHSA-6gvx-hwp2-7mfq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6gvx-hwp2-7mfq", + "modified": "2024-05-20T18:31:23Z", + "published": "2024-05-20T18:31:23Z", + "aliases": [ + "CVE-2024-31714" + ], + "details": "Buffer Overflow vulnerability in Waxlab wax v.0.9-3 and before allows an attacker to cause a denial of service via the Lua library component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31714" + }, + { + "type": "WEB", + "url": "https://github.com/lakemoon602/vuln/blob/main/wax.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-20T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-74qv-wwr5-wmm5/GHSA-74qv-wwr5-wmm5.json b/advisories/unreviewed/2024/05/GHSA-74qv-wwr5-wmm5/GHSA-74qv-wwr5-wmm5.json new file mode 100644 index 00000000000..afa34221464 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-74qv-wwr5-wmm5/GHSA-74qv-wwr5-wmm5.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-74qv-wwr5-wmm5", + "modified": "2024-05-20T18:31:22Z", + "published": "2024-05-20T18:31:22Z", + "aliases": [ + "CVE-2024-34947" + ], + "details": "Quanxun Huiju Network Technology (Beijing) Co.,Ltd IK-Q3000 3.7.10 x64 Build202401261655 was discovered to be vulnerable to an ICMP redirect attack.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34947" + }, + { + "type": "WEB", + "url": "https://gist.github.com/wuyuhang422/56f1e03fad8b91a3c979093f53cbbe7a" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-20T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-7chq-mr2c-3p6c/GHSA-7chq-mr2c-3p6c.json b/advisories/unreviewed/2024/05/GHSA-7chq-mr2c-3p6c/GHSA-7chq-mr2c-3p6c.json new file mode 100644 index 00000000000..7903c94c21a --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-7chq-mr2c-3p6c/GHSA-7chq-mr2c-3p6c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7chq-mr2c-3p6c", + "modified": "2024-05-20T18:31:22Z", + "published": "2024-05-20T18:31:22Z", + "aliases": [ + "CVE-2023-49333" + ], + "details": "Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection in the dashboard graph feature.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49333" + }, + { + "type": "WEB", + "url": "https://www.manageengine.com/products/active-directory-audit/sqlfix-7271.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-20T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-8vr4-h4rr-8ph6/GHSA-8vr4-h4rr-8ph6.json b/advisories/unreviewed/2024/05/GHSA-8vr4-h4rr-8ph6/GHSA-8vr4-h4rr-8ph6.json new file mode 100644 index 00000000000..ee13e0766e8 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-8vr4-h4rr-8ph6/GHSA-8vr4-h4rr-8ph6.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8vr4-h4rr-8ph6", + "modified": "2024-05-20T18:31:23Z", + "published": "2024-05-20T18:31:23Z", + "aliases": [ + "CVE-2024-24293" + ], + "details": "A Prototype Pollution issue in MiguelCastillo @bit/loader v.10.0.3 allows an attacker to execute arbitrary code via the M function e argument in index.js.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24293" + }, + { + "type": "WEB", + "url": "https://gist.github.com/tariqhawis/986fb1c9da6be526fb2656ba8d194b7f" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-20T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-c39h-h953-m887/GHSA-c39h-h953-m887.json b/advisories/unreviewed/2024/05/GHSA-c39h-h953-m887/GHSA-c39h-h953-m887.json new file mode 100644 index 00000000000..f6197cdc16d --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-c39h-h953-m887/GHSA-c39h-h953-m887.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c39h-h953-m887", + "modified": "2024-05-20T18:31:22Z", + "published": "2024-05-20T18:31:22Z", + "aliases": [ + "CVE-2024-34948" + ], + "details": "An issue in Quanxun Huiju Network Technology(Beijing) Co.,Ltd IK-Q3000 3.7.10 x64 Build202401261655 allows attackers to cause a Denial of Service (DoS) when attempting to make TCP connections.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34948" + }, + { + "type": "WEB", + "url": "https://gist.github.com/wuyuhang422/8de771b0b4538eb6fa23cf8282061209" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-20T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-g3q2-vcjq-rgrc/GHSA-g3q2-vcjq-rgrc.json b/advisories/unreviewed/2024/05/GHSA-g3q2-vcjq-rgrc/GHSA-g3q2-vcjq-rgrc.json new file mode 100644 index 00000000000..1abc7d4995e --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-g3q2-vcjq-rgrc/GHSA-g3q2-vcjq-rgrc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g3q2-vcjq-rgrc", + "modified": "2024-05-20T18:31:22Z", + "published": "2024-05-20T18:31:22Z", + "aliases": [ + "CVE-2024-24294" + ], + "details": "A Prototype Pollution issue in Blackprint @blackprint/engine v.0.9.0 allows an attacker to execute arbitrary code via the _utils.setDeepProperty function of engine.min.js.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24294" + }, + { + "type": "WEB", + "url": "https://gist.github.com/mestrtee/d1eb6e1f7c6dd60d8838c3e56cab634d" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-20T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-hp7j-hj47-34vh/GHSA-hp7j-hj47-34vh.json b/advisories/unreviewed/2024/05/GHSA-hp7j-hj47-34vh/GHSA-hp7j-hj47-34vh.json index b2e71d15838..845549e1c77 100644 --- a/advisories/unreviewed/2024/05/GHSA-hp7j-hj47-34vh/GHSA-hp7j-hj47-34vh.json +++ b/advisories/unreviewed/2024/05/GHSA-hp7j-hj47-34vh/GHSA-hp7j-hj47-34vh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hp7j-hj47-34vh", - "modified": "2024-05-20T15:31:44Z", + "modified": "2024-05-20T18:31:21Z", "published": "2024-05-20T15:31:44Z", "aliases": [ "CVE-2023-49330" diff --git a/advisories/unreviewed/2024/05/GHSA-jrwf-88rv-m9xr/GHSA-jrwf-88rv-m9xr.json b/advisories/unreviewed/2024/05/GHSA-jrwf-88rv-m9xr/GHSA-jrwf-88rv-m9xr.json new file mode 100644 index 00000000000..a8be4b65f72 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-jrwf-88rv-m9xr/GHSA-jrwf-88rv-m9xr.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jrwf-88rv-m9xr", + "modified": "2024-05-20T18:31:24Z", + "published": "2024-05-20T18:31:24Z", + "aliases": [ + "CVE-2024-35578" + ], + "details": "Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function formSetIptv.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35578" + }, + { + "type": "WEB", + "url": "https://detailed-stetson-767.notion.site/Tenda-AX1806-Buffer-Overflow-in-formSetIptv-cebf9202122a4582ae86c5253b3f6da3?pvs=4" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-20T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-qxjr-363m-qwfv/GHSA-qxjr-363m-qwfv.json b/advisories/unreviewed/2024/05/GHSA-qxjr-363m-qwfv/GHSA-qxjr-363m-qwfv.json new file mode 100644 index 00000000000..e31409edfbf --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-qxjr-363m-qwfv/GHSA-qxjr-363m-qwfv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qxjr-363m-qwfv", + "modified": "2024-05-20T18:31:22Z", + "published": "2024-05-20T18:31:22Z", + "aliases": [ + "CVE-2024-0401" + ], + "details": "ASUS routers supporting custom OpenVPN profiles are vulnerable to a code execution vulnerability. An authenticated and remote attacker can execute arbitrary operating system commands by uploading a crafted OVPN profile. Known affected routers include ASUS ExpertWiFi, ASUS RT-AX55, ASUS RT-AX58U, ASUS RT-AC67U, ASUS RT-AC68R, ASUS RT-AC68U, ASUS RT-AX86, ASUS RT-AC86U, ASUS RT-AX88U, and ASUS RT-AX3000.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0401" + }, + { + "type": "WEB", + "url": "https://vulncheck.com/advisories/asus-ovpn-rce" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-20T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-rv8j-7qfw-8mr3/GHSA-rv8j-7qfw-8mr3.json b/advisories/unreviewed/2024/05/GHSA-rv8j-7qfw-8mr3/GHSA-rv8j-7qfw-8mr3.json new file mode 100644 index 00000000000..36c819ec13f --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-rv8j-7qfw-8mr3/GHSA-rv8j-7qfw-8mr3.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rv8j-7qfw-8mr3", + "modified": "2024-05-20T18:31:24Z", + "published": "2024-05-20T18:31:24Z", + "aliases": [ + "CVE-2024-35580" + ], + "details": "Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function formSetIptv.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35580" + }, + { + "type": "WEB", + "url": "https://detailed-stetson-767.notion.site/Tenda-AX1806-Buffer-Overflow-in-formSetIptv-cebf9202122a4582ae86c5253b3f6da3?pvs=4" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-20T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-v8r8-56x7-prx6/GHSA-v8r8-56x7-prx6.json b/advisories/unreviewed/2024/05/GHSA-v8r8-56x7-prx6/GHSA-v8r8-56x7-prx6.json new file mode 100644 index 00000000000..4bd6ea4ac19 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-v8r8-56x7-prx6/GHSA-v8r8-56x7-prx6.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v8r8-56x7-prx6", + "modified": "2024-05-20T18:31:23Z", + "published": "2024-05-20T18:31:23Z", + "aliases": [ + "CVE-2024-34193" + ], + "details": "smanga 3.2.7 does not filter the file parameter at the PHP/get file flow.php interface, resulting in a path traversal vulnerability that can cause arbitrary file reading.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34193" + }, + { + "type": "WEB", + "url": "https://github.com/vulreport3r/cve-reports/blob/main/Smanga_has_an_arbitrary_file_read_vulnerability/report.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-20T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-wx4v-qgjj-9f5j/GHSA-wx4v-qgjj-9f5j.json b/advisories/unreviewed/2024/05/GHSA-wx4v-qgjj-9f5j/GHSA-wx4v-qgjj-9f5j.json new file mode 100644 index 00000000000..0769edd78fd --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-wx4v-qgjj-9f5j/GHSA-wx4v-qgjj-9f5j.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wx4v-qgjj-9f5j", + "modified": "2024-05-20T18:31:24Z", + "published": "2024-05-20T18:31:24Z", + "aliases": [ + "CVE-2024-35579" + ], + "details": "Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function formSetIptv.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35579" + }, + { + "type": "WEB", + "url": "https://detailed-stetson-767.notion.site/Tenda-AX1806-Buffer-Overflow-in-formSetIptv-cebf9202122a4582ae86c5253b3f6da3?pvs=4" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-20T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-xcxv-fxc3-wxmc/GHSA-xcxv-fxc3-wxmc.json b/advisories/unreviewed/2024/05/GHSA-xcxv-fxc3-wxmc/GHSA-xcxv-fxc3-wxmc.json new file mode 100644 index 00000000000..ef965055430 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-xcxv-fxc3-wxmc/GHSA-xcxv-fxc3-wxmc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xcxv-fxc3-wxmc", + "modified": "2024-05-20T18:31:23Z", + "published": "2024-05-20T18:31:23Z", + "aliases": [ + "CVE-2024-35571" + ], + "details": "Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function formSetIptv.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35571" + }, + { + "type": "WEB", + "url": "https://detailed-stetson-767.notion.site/Tenda-AX1806-Buffer-Overflow-in-formSetIptv-cebf9202122a4582ae86c5253b3f6da3?pvs=4" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-20T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-xhvq-7mc2-jx9w/GHSA-xhvq-7mc2-jx9w.json b/advisories/unreviewed/2024/05/GHSA-xhvq-7mc2-jx9w/GHSA-xhvq-7mc2-jx9w.json new file mode 100644 index 00000000000..ad5d06bfd84 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-xhvq-7mc2-jx9w/GHSA-xhvq-7mc2-jx9w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xhvq-7mc2-jx9w", + "modified": "2024-05-20T18:31:23Z", + "published": "2024-05-20T18:31:23Z", + "aliases": [ + "CVE-2023-49335" + ], + "details": "Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection while getting file server details.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49335" + }, + { + "type": "WEB", + "url": "https://www.manageengine.com/products/active-directory-audit/sqlfix-7271.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-20T18:15:10Z" + } +} \ No newline at end of file