Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2023-10-27 21:31:38 +00:00
parent bfc9f49fbc
commit 5eea39ec33
66 changed files with 2011 additions and 19 deletions
@@ -21,6 +21,14 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2019-9199"
},
{
"type": "WEB",
"url": "https://github.com/jjanku/podofo/commit/ada821df68fb0bf673840ed525daf4ec709dbfd9"
},
{
"type": "WEB",
"url": "https://github.com/mksdev/podofo/commit/1400a9aaf611299b9a56aa2abeb158918b9743c8"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CIC2EXSSMBT3MY2HY42IIY4BUQS2SVYB/"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-42mr-mfcr-7jqh",
"modified": "2023-07-06T19:24:05Z",
"modified": "2023-10-27T21:30:20Z",
"published": "2023-07-06T19:24:05Z",
"aliases": [
"CVE-2022-43557"
],
"details": "The BD BodyGuard™ infusion pumps specified allow for access through the RS-232 (serial) port interface. If exploited, threat actors with physical access, specialized equipment and knowledge may be able to configure or disable the pump. No electronic protected health information (ePHI), protected health information (PHI) or personally identifiable information (PII) is stored in the pump.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H"
}
],
"affected": [
@@ -25,7 +28,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-1299",
"CWE-287"
],
"severity": null,
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-433q-36rv-j5jj",
"modified": "2023-10-27T00:30:18Z",
"modified": "2023-10-27T21:30:21Z",
"published": "2023-07-06T19:24:11Z",
"aliases": [
"CVE-2023-0053"
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2962-mm2g-265c",
"modified": "2023-10-27T21:30:23Z",
"published": "2023-10-27T21:30:23Z",
"aliases": [
"CVE-2023-40120"
],
"details": "In multiple locations, there is a possible way to bypass user notification of foreground services due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40120"
},
{
"type": "WEB",
"url": "https://android.googlesource.com/platform/frameworks/base/+/d26544e5a4fd554b790b4d0c5964d9e95d9e626b"
},
{
"type": "WEB",
"url": "https://source.android.com/security/bulletin/2023-10-01"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2mqf-694r-32x9",
"modified": "2023-10-27T21:30:23Z",
"published": "2023-10-27T21:30:23Z",
"aliases": [
"CVE-2023-46208"
],
"details": "Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in StylemixThemes Motors Car Dealer, Classifieds & Listing plugin <= 1.4.6 versions.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46208"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/vulnerability/motors-car-dealership-classified-listings/wordpress-motors-car-dealer-classifieds-listing-plugin-1-4-6-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,46 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2q2c-7wf9-f9c2",
"modified": "2023-10-27T21:30:23Z",
"published": "2023-10-27T21:30:23Z",
"aliases": [
"CVE-2023-5828"
],
"details": "A vulnerability was found in Nanning Ontall Longxing Industrial Development Zone Project Construction and Installation Management System up to 20231026. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file login.aspx. The manipulation of the argument tbxUserName leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-243727.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5828"
},
{
"type": "WEB",
"url": "https://github.com/Echosssy/-SQL-injection/blob/main/%E5%8D%97%E5%AE%81%E5%B8%82%E5%AE%89%E6%8B%93%E8%BD%AF%E4%BB%B6%E6%9C%89%E9%99%90%E5%85%AC%E5%8F%B8SQL%20injection.doc"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.243727"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.243727"
}
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,43 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3856-cjch-9cv8",
"modified": "2023-10-27T21:30:23Z",
"published": "2023-10-27T21:30:23Z",
"aliases": [
"CVE-2023-40117"
],
"details": "In resetSettingsLocked of SettingsProvider.java, there is a possible lockscreen bypass due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40117"
},
{
"type": "WEB",
"url": "https://android.googlesource.com/platform/frameworks/base/+/ff86ff28cf82124f8e65833a2dd8c319aea08945"
},
{
"type": "WEB",
"url": "https://android.googlesource.com/platform/packages/apps/Settings/+/11815817de2f2d70fe842b108356a1bc75d44ffb"
},
{
"type": "WEB",
"url": "https://source.android.com/security/bulletin/2023-10-01"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -32,7 +32,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-122"
"CWE-122",
"CWE-787"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3c9r-8wrp-84w3",
"modified": "2023-10-27T21:30:23Z",
"published": "2023-10-27T21:30:23Z",
"aliases": [
"CVE-2023-40129"
],
"details": "In build_read_multi_rsp of gatt_sr.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40129"
},
{
"type": "WEB",
"url": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/c0151aa3ba76c785b32c7f9d16c98febe53017b1"
},
{
"type": "WEB",
"url": "https://source.android.com/security/bulletin/2023-10-01"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3g2w-rhvj-j46g",
"modified": "2023-10-27T21:30:23Z",
"published": "2023-10-27T21:30:23Z",
"aliases": [
"CVE-2022-3700"
],
"details": "A Time of Check Time of Use (TOCTOU) vulnerability was reported in the Lenovo Vantage SystemUpdate Plugin version 2.0.0.212 and earlier that could allow a local attacker to delete arbitrary files.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-3700"
},
{
"type": "WEB",
"url": "https://support.lenovo.com/us/en/product_security/LEN-94532"
}
],
"database_specific": {
"cwe_ids": [
"CWE-367"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3j55-7hc5-m8vh",
"modified": "2023-10-27T21:30:24Z",
"published": "2023-10-27T21:30:24Z",
"aliases": [
"CVE-2023-46510"
],
"details": "An issue in ZIONCOM (Hong Kong) Technology Limited A7000R v.4.1cu.4154 allows an attacker to execute arbitrary code via the cig-bin/cstecgi.cgi to the settings/setPasswordCfg function.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46510"
},
{
"type": "WEB",
"url": "https://gist.github.com/ATonysan/58ace23d539981441bca16ce0f7585e2"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3m8h-rcx6-p525",
"modified": "2023-10-27T21:30:23Z",
"published": "2023-10-27T21:30:23Z",
"aliases": [
"CVE-2023-40135"
],
"details": "In applyCustomDescription of SaveUi.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40135"
},
{
"type": "WEB",
"url": "https://android.googlesource.com/platform/frameworks/base/+/08becc8c600f14c5529115cc1a1e0c97cd503f33"
},
{
"type": "WEB",
"url": "https://source.android.com/security/bulletin/2023-10-01"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -32,6 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-1321",
"CWE-79"
],
"severity": null,
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3rv4-77xr-w6jx",
"modified": "2023-10-27T21:30:23Z",
"published": "2023-10-27T21:30:23Z",
"aliases": [
"CVE-2022-3681"
],
"details": "A vulnerability has been identified in the MR2600 router v1.0.18 and earlier that could allow an attacker within range of the wireless network to successfully brute force the WPS pin, potentially allowing them unauthorized access to a wireless network.\n ",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-3681"
},
{
"type": "WEB",
"url": "https://web.archive.org/web/20230317174952/https://help.motorolanetwork.com/hc/en-us/articles/9933302506523"
}
],
"database_specific": {
"cwe_ids": [
"CWE-287"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3xhx-7chp-7wq6",
"modified": "2023-10-27T21:30:23Z",
"published": "2023-10-27T21:30:23Z",
"aliases": [
"CVE-2023-44480"
],
"details": "Leave Management System Project v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'setcasualleave' parameter of the admin/setleaves.php resource does not validate the characters received and they are sent unfiltered to the database.\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-44480"
},
{
"type": "WEB",
"url": "https://fluidattacks.com/advisories/martin/"
},
{
"type": "WEB",
"url": "https://projectworlds.in/"
}
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-47qj-rqv2-98f2",
"modified": "2023-10-27T21:30:23Z",
"published": "2023-10-27T21:30:23Z",
"aliases": [
"CVE-2023-46852"
],
"details": "In Memcached before 1.6.22, a buffer overflow exists when processing multiget requests in proxy mode, if there are many spaces after the \"get\" substring.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46852"
},
{
"type": "WEB",
"url": "https://github.com/memcached/memcached/commit/76a6c363c18cfe7b6a1524ae64202ac9db330767"
},
{
"type": "WEB",
"url": "https://github.com/memcached/memcached/compare/1.6.21...1.6.22"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4j6r-mf7f-44jq",
"modified": "2023-10-21T09:30:25Z",
"modified": "2023-10-27T21:30:22Z",
"published": "2023-10-21T09:30:25Z",
"aliases": [
"CVE-2023-46054"
],
"details": "Cross Site Scripting (XSS) vulnerability in WBCE CMS v.1.6.1 and before allows a remote attacker to escalate privileges via a crafted script to the website_footer parameter in the admin/settings/save.php component.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -25,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": null,
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4mwj-qxcc-x2p8",
"modified": "2023-10-23T21:30:58Z",
"modified": "2023-10-27T21:30:22Z",
"published": "2023-10-23T21:30:58Z",
"aliases": [
"CVE-2023-27149"
],
"details": "A stored cross-site scripting (XSS) vulnerability in Enhancesoft osTicket v1.17.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Label input parameter when updating a custom list.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -25,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": null,
"github_reviewed": false,
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-549w-5fgc-66mp",
"modified": "2023-10-27T21:30:23Z",
"published": "2023-10-27T21:30:23Z",
"aliases": [
"CVE-2023-46509"
],
"details": "An issue in Contec SolarView Compact v.6.0 and before allows an attacker to execute arbitrary code via the texteditor.php component.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46509"
},
{
"type": "WEB",
"url": "https://gist.github.com/ATonysan/d6f72e9eb90407d64bed4566aa80afb1#file-cve-2023-46509"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -21,6 +21,10 @@
{
"type": "WEB",
"url": "https://blog.leakix.net/2023/10/vinchin-backup-rce-chain/"
},
{
"type": "WEB",
"url": "http://seclists.org/fulldisclosure/2023/Oct/31"
}
],
"database_specific": {

Some files were not shown because too many files have changed in this diff Show More