Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2025-04-17 21:31:56 +00:00
parent 8324a53159
commit 5ae3398d07
87 changed files with 1569 additions and 124 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4v5x-9m47-cqr2",
"modified": "2025-03-25T21:48:41Z",
"modified": "2025-04-17T21:30:43Z",
"published": "2024-12-09T21:31:02Z",
"withdrawn": "2025-03-25T21:48:41Z",
"aliases": [],
@@ -39,6 +39,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12369"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:3989"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-12369"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6hf5-gqpw-h5ww",
"modified": "2022-01-14T00:03:00Z",
"modified": "2025-04-17T21:30:37Z",
"published": "2022-01-11T00:01:35Z",
"aliases": [
"CVE-2021-32996"
],
"details": "The FANUC R-30iA and R-30iB series controllers are vulnerable to integer coercion errors, which cause the device to crash. A restart is required.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [],
"references": [
{
@@ -21,6 +26,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-192",
"CWE-681"
],
"severity": "HIGH",
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7g9p-cvcv-xgp8",
"modified": "2022-03-05T00:00:58Z",
"modified": "2025-04-17T21:30:37Z",
"published": "2022-02-25T00:00:59Z",
"aliases": [
"CVE-2020-14480"
],
"details": "Due to usernames/passwords being stored in plaintext in Random Access Memory (RAM), a local, authenticated attacker could gain access to certain credentials, including Windows Logon credentials.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [],
"references": [
{
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9h67-gqh5-w6f6",
"modified": "2022-03-05T00:00:58Z",
"modified": "2025-04-17T21:30:37Z",
"published": "2022-02-25T00:00:59Z",
"aliases": [
"CVE-2020-14481"
],
"details": "The DeskLock tool provided with FactoryTalk View SE uses a weak encryption algorithm that may allow a local, authenticated attacker to decipher user credentials, including the Windows user or Windows DeskLock passwords. If the compromised user has an administrative account, an attacker could gain full access to the users operating system and certain components of FactoryTalk View SE.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
@@ -21,6 +26,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-261",
"CWE-326"
],
"severity": "HIGH",
@@ -26,6 +26,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-284",
"CWE-287"
],
"severity": "MODERATE",
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qqc2-6qq8-p574",
"modified": "2022-03-05T00:00:57Z",
"modified": "2025-04-17T21:30:37Z",
"published": "2022-02-25T00:00:59Z",
"aliases": [
"CVE-2020-14478"
],
"details": "A local, authenticated attacker could use an XML External Entity (XXE) attack to exploit weakly configured XML files to access local or remote content. A successful exploit could potentially cause a denial-of-service condition and allow the attacker to arbitrarily read any local file via system-level services.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
}
],
"affected": [],
"references": [
{
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vj77-9g38-f2fm",
"modified": "2022-03-08T00:00:41Z",
"modified": "2025-04-17T21:30:37Z",
"published": "2022-02-25T00:00:59Z",
"aliases": [
"CVE-2020-14502"
],
"details": "The web interface of the 1734-AENTR communication module is vulnerable to stored XSS. A remote, unauthenticated attacker could store a malicious script within the web interface that, when executed, could modify some string values on the homepage of the web interface.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qw5m-v83j-4g26",
"modified": "2022-12-13T12:30:22Z",
"modified": "2025-04-17T21:30:37Z",
"published": "2022-05-24T16:58:17Z",
"aliases": [
"CVE-2019-16905"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7639-pv9r-w8cv",
"modified": "2023-07-24T15:30:25Z",
"modified": "2025-04-17T21:30:37Z",
"published": "2022-06-25T00:00:53Z",
"aliases": [
"CVE-2022-1740"
@@ -26,7 +26,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-269"
"CWE-269",
"CWE-912"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -25,7 +25,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-119"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2x3r-rpmr-wmwh",
"modified": "2022-12-24T06:30:26Z",
"modified": "2025-04-17T21:30:38Z",
"published": "2022-12-20T21:30:17Z",
"aliases": [
"CVE-2022-46312"
@@ -29,7 +29,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-285"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -26,7 +26,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-77"
"CWE-77",
"CWE-78"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -34,6 +34,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-193",
"CWE-787"
],
"severity": "HIGH",
@@ -25,7 +25,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-476"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q8cm-r6w4-28gm",
"modified": "2022-12-22T15:30:21Z",
"modified": "2025-04-17T21:30:38Z",
"published": "2022-12-18T06:31:08Z",
"aliases": [
"CVE-2022-47521"
@@ -27,6 +27,10 @@
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2022/12/msg00031.html"
},
{
"type": "WEB",
"url": "https://lore.kernel.org/r/20221123153543.8568-4-philipturnbull%40github.com"
},
{
"type": "WEB",
"url": "https://lore.kernel.org/r/20221123153543.8568-4-philipturnbull@github.com"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6r47-4376-p42h",
"modified": "2024-04-04T05:30:55Z",
"modified": "2025-04-17T21:30:38Z",
"published": "2023-07-06T19:24:05Z",
"aliases": [
"CVE-2022-47209"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-652f-58jv-j9fp",
"modified": "2024-01-08T15:30:26Z",
"modified": "2025-04-17T21:30:39Z",
"published": "2023-12-29T06:30:30Z",
"aliases": [
"CVE-2023-31300"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9qq8-mmh8-945v",
"modified": "2023-12-27T21:31:00Z",
"modified": "2025-04-17T21:30:38Z",
"published": "2023-12-22T21:30:24Z",
"aliases": [
"CVE-2023-51018"
@@ -25,7 +25,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-94"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fqg5-7rjv-45wh",
"modified": "2023-12-29T06:30:29Z",
"modified": "2025-04-17T21:30:38Z",
"published": "2023-12-29T06:30:29Z",
"aliases": [
"CVE-2023-23443"
],
"details": "\nSome Honor products are affected by type confusion vulnerability, successful exploitation could cause information leak.\n\n",
"details": "Some Honor products are affected by type confusion vulnerability, successful exploitation could cause information leak.",
"severity": [
{
"type": "CVSS_V3",

Some files were not shown because too many files have changed in this diff Show More