From 5d800b274251964016c1b95c2c69bd4c42466ffd Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 15 May 2024 12:32:41 +0000 Subject: [PATCH] Publish Advisories GHSA-2r6x-prf5-8vf9 GHSA-3vwh-qrr4-g3m5 GHSA-439m-pv8v-92q4 GHSA-8g3m-3r6v-j4vx GHSA-9jfj-4qc6-wf64 GHSA-c666-m54v-25m4 GHSA-cr3h-6p3m-86cg GHSA-f4fx-9fx2-ww9h GHSA-g7gx-jvr2-rf7m GHSA-hgg4-qf6j-32hr GHSA-j6wv-5jm4-2jhr GHSA-jxc4-gm3r-9hx3 GHSA-x6mg-9qj5-5465 --- .../GHSA-2r6x-prf5-8vf9.json | 38 +++++++++++++++++ .../GHSA-3vwh-qrr4-g3m5.json | 38 +++++++++++++++++ .../GHSA-439m-pv8v-92q4.json | 38 +++++++++++++++++ .../GHSA-8g3m-3r6v-j4vx.json | 38 +++++++++++++++++ .../GHSA-9jfj-4qc6-wf64.json | 42 +++++++++++++++++++ .../GHSA-c666-m54v-25m4.json | 38 +++++++++++++++++ .../GHSA-cr3h-6p3m-86cg.json | 38 +++++++++++++++++ .../GHSA-f4fx-9fx2-ww9h.json | 38 +++++++++++++++++ .../GHSA-g7gx-jvr2-rf7m.json | 38 +++++++++++++++++ .../GHSA-hgg4-qf6j-32hr.json | 38 +++++++++++++++++ .../GHSA-j6wv-5jm4-2jhr.json | 38 +++++++++++++++++ .../GHSA-jxc4-gm3r-9hx3.json | 38 +++++++++++++++++ .../GHSA-x6mg-9qj5-5465.json | 38 +++++++++++++++++ 13 files changed, 498 insertions(+) create mode 100644 advisories/unreviewed/2024/05/GHSA-2r6x-prf5-8vf9/GHSA-2r6x-prf5-8vf9.json create mode 100644 advisories/unreviewed/2024/05/GHSA-3vwh-qrr4-g3m5/GHSA-3vwh-qrr4-g3m5.json create mode 100644 advisories/unreviewed/2024/05/GHSA-439m-pv8v-92q4/GHSA-439m-pv8v-92q4.json create mode 100644 advisories/unreviewed/2024/05/GHSA-8g3m-3r6v-j4vx/GHSA-8g3m-3r6v-j4vx.json create mode 100644 advisories/unreviewed/2024/05/GHSA-9jfj-4qc6-wf64/GHSA-9jfj-4qc6-wf64.json create mode 100644 advisories/unreviewed/2024/05/GHSA-c666-m54v-25m4/GHSA-c666-m54v-25m4.json create mode 100644 advisories/unreviewed/2024/05/GHSA-cr3h-6p3m-86cg/GHSA-cr3h-6p3m-86cg.json create mode 100644 advisories/unreviewed/2024/05/GHSA-f4fx-9fx2-ww9h/GHSA-f4fx-9fx2-ww9h.json create mode 100644 advisories/unreviewed/2024/05/GHSA-g7gx-jvr2-rf7m/GHSA-g7gx-jvr2-rf7m.json create mode 100644 advisories/unreviewed/2024/05/GHSA-hgg4-qf6j-32hr/GHSA-hgg4-qf6j-32hr.json create mode 100644 advisories/unreviewed/2024/05/GHSA-j6wv-5jm4-2jhr/GHSA-j6wv-5jm4-2jhr.json create mode 100644 advisories/unreviewed/2024/05/GHSA-jxc4-gm3r-9hx3/GHSA-jxc4-gm3r-9hx3.json create mode 100644 advisories/unreviewed/2024/05/GHSA-x6mg-9qj5-5465/GHSA-x6mg-9qj5-5465.json diff --git a/advisories/unreviewed/2024/05/GHSA-2r6x-prf5-8vf9/GHSA-2r6x-prf5-8vf9.json b/advisories/unreviewed/2024/05/GHSA-2r6x-prf5-8vf9/GHSA-2r6x-prf5-8vf9.json new file mode 100644 index 00000000000..9fd621115c1 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-2r6x-prf5-8vf9/GHSA-2r6x-prf5-8vf9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2r6x-prf5-8vf9", + "modified": "2024-05-15T12:31:16Z", + "published": "2024-05-15T12:31:16Z", + "aliases": [ + "CVE-2024-34096" + ], + "details": "Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34096" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/acrobat/apsb24-29.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-15T10:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-3vwh-qrr4-g3m5/GHSA-3vwh-qrr4-g3m5.json b/advisories/unreviewed/2024/05/GHSA-3vwh-qrr4-g3m5/GHSA-3vwh-qrr4-g3m5.json new file mode 100644 index 00000000000..9d03d979334 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-3vwh-qrr4-g3m5/GHSA-3vwh-qrr4-g3m5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3vwh-qrr4-g3m5", + "modified": "2024-05-15T12:31:16Z", + "published": "2024-05-15T12:31:16Z", + "aliases": [ + "CVE-2024-34094" + ], + "details": "Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34094" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/acrobat/apsb24-29.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-15T10:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-439m-pv8v-92q4/GHSA-439m-pv8v-92q4.json b/advisories/unreviewed/2024/05/GHSA-439m-pv8v-92q4/GHSA-439m-pv8v-92q4.json new file mode 100644 index 00000000000..0c076014b60 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-439m-pv8v-92q4/GHSA-439m-pv8v-92q4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-439m-pv8v-92q4", + "modified": "2024-05-15T12:31:17Z", + "published": "2024-05-15T12:31:17Z", + "aliases": [ + "CVE-2024-34101" + ], + "details": "Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34101" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/acrobat/apsb24-29.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-15T10:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-8g3m-3r6v-j4vx/GHSA-8g3m-3r6v-j4vx.json b/advisories/unreviewed/2024/05/GHSA-8g3m-3r6v-j4vx/GHSA-8g3m-3r6v-j4vx.json new file mode 100644 index 00000000000..d1166b1219c --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-8g3m-3r6v-j4vx/GHSA-8g3m-3r6v-j4vx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8g3m-3r6v-j4vx", + "modified": "2024-05-15T12:31:16Z", + "published": "2024-05-15T12:31:16Z", + "aliases": [ + "CVE-2024-30312" + ], + "details": "Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30312" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/acrobat/apsb24-29.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-15T10:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-9jfj-4qc6-wf64/GHSA-9jfj-4qc6-wf64.json b/advisories/unreviewed/2024/05/GHSA-9jfj-4qc6-wf64/GHSA-9jfj-4qc6-wf64.json new file mode 100644 index 00000000000..c486da1ffce --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-9jfj-4qc6-wf64/GHSA-9jfj-4qc6-wf64.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9jfj-4qc6-wf64", + "modified": "2024-05-15T12:31:17Z", + "published": "2024-05-15T12:31:17Z", + "aliases": [ + "CVE-2024-4702" + ], + "details": "The Mega Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button widget in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4702" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3085457/mega-elements-addons-for-elementor" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/3808ca2a-e78e-4118-890b-c22a71f8e855?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-15T12:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-c666-m54v-25m4/GHSA-c666-m54v-25m4.json b/advisories/unreviewed/2024/05/GHSA-c666-m54v-25m4/GHSA-c666-m54v-25m4.json new file mode 100644 index 00000000000..1580d501d1e --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-c666-m54v-25m4/GHSA-c666-m54v-25m4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c666-m54v-25m4", + "modified": "2024-05-15T12:31:16Z", + "published": "2024-05-15T12:31:16Z", + "aliases": [ + "CVE-2024-34097" + ], + "details": "Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34097" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/acrobat/apsb24-29.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-15T10:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-cr3h-6p3m-86cg/GHSA-cr3h-6p3m-86cg.json b/advisories/unreviewed/2024/05/GHSA-cr3h-6p3m-86cg/GHSA-cr3h-6p3m-86cg.json new file mode 100644 index 00000000000..1ec08b5457a --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-cr3h-6p3m-86cg/GHSA-cr3h-6p3m-86cg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cr3h-6p3m-86cg", + "modified": "2024-05-15T12:31:16Z", + "published": "2024-05-15T12:31:16Z", + "aliases": [ + "CVE-2024-34098" + ], + "details": "Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34098" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/acrobat/apsb24-29.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-15T10:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-f4fx-9fx2-ww9h/GHSA-f4fx-9fx2-ww9h.json b/advisories/unreviewed/2024/05/GHSA-f4fx-9fx2-ww9h/GHSA-f4fx-9fx2-ww9h.json new file mode 100644 index 00000000000..1ef66ed31b7 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-f4fx-9fx2-ww9h/GHSA-f4fx-9fx2-ww9h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f4fx-9fx2-ww9h", + "modified": "2024-05-15T12:31:17Z", + "published": "2024-05-15T12:31:17Z", + "aliases": [ + "CVE-2024-34100" + ], + "details": "Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34100" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/acrobat/apsb24-29.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-15T10:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-g7gx-jvr2-rf7m/GHSA-g7gx-jvr2-rf7m.json b/advisories/unreviewed/2024/05/GHSA-g7gx-jvr2-rf7m/GHSA-g7gx-jvr2-rf7m.json new file mode 100644 index 00000000000..2d50c60a0d6 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-g7gx-jvr2-rf7m/GHSA-g7gx-jvr2-rf7m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g7gx-jvr2-rf7m", + "modified": "2024-05-15T12:31:16Z", + "published": "2024-05-15T12:31:16Z", + "aliases": [ + "CVE-2024-34095" + ], + "details": "Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34095" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/acrobat/apsb24-29.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-15T10:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-hgg4-qf6j-32hr/GHSA-hgg4-qf6j-32hr.json b/advisories/unreviewed/2024/05/GHSA-hgg4-qf6j-32hr/GHSA-hgg4-qf6j-32hr.json new file mode 100644 index 00000000000..cbe1fa426f0 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-hgg4-qf6j-32hr/GHSA-hgg4-qf6j-32hr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hgg4-qf6j-32hr", + "modified": "2024-05-15T12:31:16Z", + "published": "2024-05-15T12:31:16Z", + "aliases": [ + "CVE-2024-30311" + ], + "details": "Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30311" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/acrobat/apsb24-29.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-15T10:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-j6wv-5jm4-2jhr/GHSA-j6wv-5jm4-2jhr.json b/advisories/unreviewed/2024/05/GHSA-j6wv-5jm4-2jhr/GHSA-j6wv-5jm4-2jhr.json new file mode 100644 index 00000000000..9253d94696c --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-j6wv-5jm4-2jhr/GHSA-j6wv-5jm4-2jhr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j6wv-5jm4-2jhr", + "modified": "2024-05-15T12:31:17Z", + "published": "2024-05-15T12:31:17Z", + "aliases": [ + "CVE-2024-34099" + ], + "details": "Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34099" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/acrobat/apsb24-29.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-15T10:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-jxc4-gm3r-9hx3/GHSA-jxc4-gm3r-9hx3.json b/advisories/unreviewed/2024/05/GHSA-jxc4-gm3r-9hx3/GHSA-jxc4-gm3r-9hx3.json new file mode 100644 index 00000000000..7623ecfe231 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-jxc4-gm3r-9hx3/GHSA-jxc4-gm3r-9hx3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jxc4-gm3r-9hx3", + "modified": "2024-05-15T12:31:14Z", + "published": "2024-05-15T12:31:14Z", + "aliases": [ + "CVE-2024-30284" + ], + "details": "Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30284" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/acrobat/apsb24-29.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-15T10:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-x6mg-9qj5-5465/GHSA-x6mg-9qj5-5465.json b/advisories/unreviewed/2024/05/GHSA-x6mg-9qj5-5465/GHSA-x6mg-9qj5-5465.json new file mode 100644 index 00000000000..0e0f46bf009 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-x6mg-9qj5-5465/GHSA-x6mg-9qj5-5465.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x6mg-9qj5-5465", + "modified": "2024-05-15T12:31:14Z", + "published": "2024-05-15T12:31:14Z", + "aliases": [ + "CVE-2024-30310" + ], + "details": "Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30310" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/acrobat/apsb24-29.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-15T10:15:10Z" + } +} \ No newline at end of file