diff --git a/advisories/unreviewed/2023/06/GHSA-2w2q-8f37-gjwc/GHSA-2w2q-8f37-gjwc.json b/advisories/unreviewed/2023/06/GHSA-2w2q-8f37-gjwc/GHSA-2w2q-8f37-gjwc.json index 6435fcf6b80..d72e9eba803 100644 --- a/advisories/unreviewed/2023/06/GHSA-2w2q-8f37-gjwc/GHSA-2w2q-8f37-gjwc.json +++ b/advisories/unreviewed/2023/06/GHSA-2w2q-8f37-gjwc/GHSA-2w2q-8f37-gjwc.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-281" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-84c9-8v7x-vgqf/GHSA-84c9-8v7x-vgqf.json b/advisories/unreviewed/2023/06/GHSA-84c9-8v7x-vgqf/GHSA-84c9-8v7x-vgqf.json index 9c9724075eb..fcd49d99e24 100644 --- a/advisories/unreviewed/2023/06/GHSA-84c9-8v7x-vgqf/GHSA-84c9-8v7x-vgqf.json +++ b/advisories/unreviewed/2023/06/GHSA-84c9-8v7x-vgqf/GHSA-84c9-8v7x-vgqf.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-78" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-9j9m-hh45-f28p/GHSA-9j9m-hh45-f28p.json b/advisories/unreviewed/2023/06/GHSA-9j9m-hh45-f28p/GHSA-9j9m-hh45-f28p.json index d83ca45ea3e..347449d3ddf 100644 --- a/advisories/unreviewed/2023/06/GHSA-9j9m-hh45-f28p/GHSA-9j9m-hh45-f28p.json +++ b/advisories/unreviewed/2023/06/GHSA-9j9m-hh45-f28p/GHSA-9j9m-hh45-f28p.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-94" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-9r35-52qr-p89p/GHSA-9r35-52qr-p89p.json b/advisories/unreviewed/2023/06/GHSA-9r35-52qr-p89p/GHSA-9r35-52qr-p89p.json index 5f354fefcd1..08706482acc 100644 --- a/advisories/unreviewed/2023/06/GHSA-9r35-52qr-p89p/GHSA-9r35-52qr-p89p.json +++ b/advisories/unreviewed/2023/06/GHSA-9r35-52qr-p89p/GHSA-9r35-52qr-p89p.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-434" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-fc67-6vc9-r6m2/GHSA-fc67-6vc9-r6m2.json b/advisories/unreviewed/2023/06/GHSA-fc67-6vc9-r6m2/GHSA-fc67-6vc9-r6m2.json index cfddfe5fc30..e1e827c9503 100644 --- a/advisories/unreviewed/2023/06/GHSA-fc67-6vc9-r6m2/GHSA-fc67-6vc9-r6m2.json +++ b/advisories/unreviewed/2023/06/GHSA-fc67-6vc9-r6m2/GHSA-fc67-6vc9-r6m2.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-269" + "CWE-269", + "CWE-863" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-frhp-pv4w-xxj6/GHSA-frhp-pv4w-xxj6.json b/advisories/unreviewed/2023/06/GHSA-frhp-pv4w-xxj6/GHSA-frhp-pv4w-xxj6.json index e1c0a9ac266..5b6e5eb847a 100644 --- a/advisories/unreviewed/2023/06/GHSA-frhp-pv4w-xxj6/GHSA-frhp-pv4w-xxj6.json +++ b/advisories/unreviewed/2023/06/GHSA-frhp-pv4w-xxj6/GHSA-frhp-pv4w-xxj6.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-502" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2023/06/GHSA-gj96-qww7-fqc5/GHSA-gj96-qww7-fqc5.json b/advisories/unreviewed/2023/06/GHSA-gj96-qww7-fqc5/GHSA-gj96-qww7-fqc5.json index b87167fc555..7b92a0a1fd6 100644 --- a/advisories/unreviewed/2023/06/GHSA-gj96-qww7-fqc5/GHSA-gj96-qww7-fqc5.json +++ b/advisories/unreviewed/2023/06/GHSA-gj96-qww7-fqc5/GHSA-gj96-qww7-fqc5.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-346" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-jxvj-g7q4-jgq7/GHSA-jxvj-g7q4-jgq7.json b/advisories/unreviewed/2023/06/GHSA-jxvj-g7q4-jgq7/GHSA-jxvj-g7q4-jgq7.json index 9b5a7dcb5dc..e007967cb6b 100644 --- a/advisories/unreviewed/2023/06/GHSA-jxvj-g7q4-jgq7/GHSA-jxvj-g7q4-jgq7.json +++ b/advisories/unreviewed/2023/06/GHSA-jxvj-g7q4-jgq7/GHSA-jxvj-g7q4-jgq7.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-269" + "CWE-269", + "CWE-863" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-v6w7-994g-3v2r/GHSA-v6w7-994g-3v2r.json b/advisories/unreviewed/2023/06/GHSA-v6w7-994g-3v2r/GHSA-v6w7-994g-3v2r.json index bda7a3719b2..97247f05136 100644 --- a/advisories/unreviewed/2023/06/GHSA-v6w7-994g-3v2r/GHSA-v6w7-994g-3v2r.json +++ b/advisories/unreviewed/2023/06/GHSA-v6w7-994g-3v2r/GHSA-v6w7-994g-3v2r.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-269" + "CWE-269", + "CWE-863" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-wvg2-3xh6-wr4c/GHSA-wvg2-3xh6-wr4c.json b/advisories/unreviewed/2023/06/GHSA-wvg2-3xh6-wr4c/GHSA-wvg2-3xh6-wr4c.json index ff63c5ea738..df02c492d7f 100644 --- a/advisories/unreviewed/2023/06/GHSA-wvg2-3xh6-wr4c/GHSA-wvg2-3xh6-wr4c.json +++ b/advisories/unreviewed/2023/06/GHSA-wvg2-3xh6-wr4c/GHSA-wvg2-3xh6-wr4c.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-94" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/07/GHSA-v46g-6fx7-cp78/GHSA-v46g-6fx7-cp78.json b/advisories/unreviewed/2023/07/GHSA-v46g-6fx7-cp78/GHSA-v46g-6fx7-cp78.json index d308cdec16d..5dc8271b5c2 100644 --- a/advisories/unreviewed/2023/07/GHSA-v46g-6fx7-cp78/GHSA-v46g-6fx7-cp78.json +++ b/advisories/unreviewed/2023/07/GHSA-v46g-6fx7-cp78/GHSA-v46g-6fx7-cp78.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,7 +30,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-290" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-pgqc-xw7p-gm9j/GHSA-pgqc-xw7p-gm9j.json b/advisories/unreviewed/2024/02/GHSA-pgqc-xw7p-gm9j/GHSA-pgqc-xw7p-gm9j.json index 9c19e755774..db4545b3448 100644 --- a/advisories/unreviewed/2024/02/GHSA-pgqc-xw7p-gm9j/GHSA-pgqc-xw7p-gm9j.json +++ b/advisories/unreviewed/2024/02/GHSA-pgqc-xw7p-gm9j/GHSA-pgqc-xw7p-gm9j.json @@ -1,18 +1,19 @@ { "schema_version": "1.4.0", "id": "GHSA-pgqc-xw7p-gm9j", - "modified": "2024-02-18T06:30:31Z", + "modified": "2024-12-04T18:32:33Z", "published": "2024-02-18T06:30:31Z", "aliases": [ "CVE-2023-52371" ], "details": "Vulnerability of null references in the motor module.Successful exploitation of this vulnerability may affect availability.", "severity": [ - - ], - "affected": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,7 +32,7 @@ "cwe_ids": [ "CWE-476" ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-18T04:15:07Z" diff --git a/advisories/unreviewed/2024/03/GHSA-62qm-vc7f-rm93/GHSA-62qm-vc7f-rm93.json b/advisories/unreviewed/2024/03/GHSA-62qm-vc7f-rm93/GHSA-62qm-vc7f-rm93.json index 5ea98ac1ee1..b995254a009 100644 --- a/advisories/unreviewed/2024/03/GHSA-62qm-vc7f-rm93/GHSA-62qm-vc7f-rm93.json +++ b/advisories/unreviewed/2024/03/GHSA-62qm-vc7f-rm93/GHSA-62qm-vc7f-rm93.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-62qm-vc7f-rm93", - "modified": "2024-05-07T06:30:35Z", + "modified": "2024-12-04T18:32:33Z", "published": "2024-03-08T03:31:25Z", "aliases": [ "CVE-2024-23254" ], "details": "The issue was addressed with improved UI handling. This issue is fixed in tvOS 17.4, macOS Sonoma 14.4, visionOS 1.1, iOS 17.4 and iPadOS 17.4, watchOS 10.4, Safari 17.4. A malicious website may exfiltrate audio data cross-origin.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -69,7 +74,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-08T02:15:48Z" diff --git a/advisories/unreviewed/2024/03/GHSA-q9x9-3w42-9w3c/GHSA-q9x9-3w42-9w3c.json b/advisories/unreviewed/2024/03/GHSA-q9x9-3w42-9w3c/GHSA-q9x9-3w42-9w3c.json index 7a3fb73e8cc..962ea1816ad 100644 --- a/advisories/unreviewed/2024/03/GHSA-q9x9-3w42-9w3c/GHSA-q9x9-3w42-9w3c.json +++ b/advisories/unreviewed/2024/03/GHSA-q9x9-3w42-9w3c/GHSA-q9x9-3w42-9w3c.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-q9x9-3w42-9w3c", - "modified": "2024-03-06T00:31:26Z", + "modified": "2024-12-04T18:32:33Z", "published": "2024-03-06T00:31:26Z", "aliases": [ "CVE-2024-1764" ], "details": "Improper privilege management in Just-in-time (JIT) elevation module in Devolutions Server 2023.3.14.0 and earlier allows a user to continue using the elevated privilege even after the expiration under specific circumstances\n\n\n", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-269" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-05T22:15:46Z" diff --git a/advisories/unreviewed/2024/03/GHSA-r72f-rmc7-whwp/GHSA-r72f-rmc7-whwp.json b/advisories/unreviewed/2024/03/GHSA-r72f-rmc7-whwp/GHSA-r72f-rmc7-whwp.json index 85c69cca648..221c2709516 100644 --- a/advisories/unreviewed/2024/03/GHSA-r72f-rmc7-whwp/GHSA-r72f-rmc7-whwp.json +++ b/advisories/unreviewed/2024/03/GHSA-r72f-rmc7-whwp/GHSA-r72f-rmc7-whwp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-r72f-rmc7-whwp", - "modified": "2024-03-14T00:31:05Z", + "modified": "2024-12-04T18:32:34Z", "published": "2024-03-08T03:31:25Z", "aliases": [ "CVE-2024-23290" ], "details": "A logic issue was addressed with improved restrictions. This issue is fixed in tvOS 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, watchOS 10.4. An app may be able to access user-sensitive data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-922" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-08T02:15:50Z" diff --git a/advisories/unreviewed/2024/04/GHSA-46xg-2692-fh7x/GHSA-46xg-2692-fh7x.json b/advisories/unreviewed/2024/04/GHSA-46xg-2692-fh7x/GHSA-46xg-2692-fh7x.json index ac4becb54d8..6feb4e9c98c 100644 --- a/advisories/unreviewed/2024/04/GHSA-46xg-2692-fh7x/GHSA-46xg-2692-fh7x.json +++ b/advisories/unreviewed/2024/04/GHSA-46xg-2692-fh7x/GHSA-46xg-2692-fh7x.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-46xg-2692-fh7x", - "modified": "2024-11-17T15:30:44Z", + "modified": "2024-12-04T18:32:34Z", "published": "2024-04-17T12:32:05Z", "aliases": [ "CVE-2024-26886" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: af_bluetooth: Fix deadlock\n\nAttemting to do sock_lock on .recvmsg may cause a deadlock as shown\nbellow, so instead of using sock_sock this uses sk_receive_queue.lock\non bt_sock_ioctl to avoid the UAF:\n\nINFO: task kworker/u9:1:121 blocked for more than 30 seconds.\n Not tainted 6.7.6-lemon #183\nWorkqueue: hci0 hci_rx_work\nCall Trace:\n \n __schedule+0x37d/0xa00\n schedule+0x32/0xe0\n __lock_sock+0x68/0xa0\n ? __pfx_autoremove_wake_function+0x10/0x10\n lock_sock_nested+0x43/0x50\n l2cap_sock_recv_cb+0x21/0xa0\n l2cap_recv_frame+0x55b/0x30a0\n ? psi_task_switch+0xeb/0x270\n ? finish_task_switch.isra.0+0x93/0x2a0\n hci_rx_work+0x33a/0x3f0\n process_one_work+0x13a/0x2f0\n worker_thread+0x2f0/0x410\n ? __pfx_worker_thread+0x10/0x10\n kthread+0xe0/0x110\n ? __pfx_kthread+0x10/0x10\n ret_from_fork+0x2c/0x50\n ? __pfx_kthread+0x10/0x10\n ret_from_fork_asm+0x1b/0x30\n ", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -40,8 +45,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T11:15:10Z" diff --git a/advisories/unreviewed/2024/04/GHSA-9f97-gpg7-4cqv/GHSA-9f97-gpg7-4cqv.json b/advisories/unreviewed/2024/04/GHSA-9f97-gpg7-4cqv/GHSA-9f97-gpg7-4cqv.json index a0d8056e754..2096bf3b81c 100644 --- a/advisories/unreviewed/2024/04/GHSA-9f97-gpg7-4cqv/GHSA-9f97-gpg7-4cqv.json +++ b/advisories/unreviewed/2024/04/GHSA-9f97-gpg7-4cqv/GHSA-9f97-gpg7-4cqv.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-276" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-mq35-399r-fgc5/GHSA-mq35-399r-fgc5.json b/advisories/unreviewed/2024/04/GHSA-mq35-399r-fgc5/GHSA-mq35-399r-fgc5.json index 761e7d8040d..d4698e2f083 100644 --- a/advisories/unreviewed/2024/04/GHSA-mq35-399r-fgc5/GHSA-mq35-399r-fgc5.json +++ b/advisories/unreviewed/2024/04/GHSA-mq35-399r-fgc5/GHSA-mq35-399r-fgc5.json @@ -1,18 +1,19 @@ { "schema_version": "1.4.0", "id": "GHSA-mq35-399r-fgc5", - "modified": "2024-04-22T15:30:41Z", + "modified": "2024-12-04T18:32:34Z", "published": "2024-04-22T15:30:41Z", "aliases": [ "CVE-2023-38294" ], "details": "Certain software builds for the Itel Vision 3 Turbo Android device contain a vulnerable pre-installed app with a package name of com.transsion.autotest.factory (versionCode='7', versionName='1.8.0(220310_1027)') that allows local third-party apps to execute arbitrary shell commands in its context (system user) due to inadequate access control. No permissions or special privileges are necessary to exploit the vulnerability in the com.transsion.autotest.factory app. No user interaction is required beyond installing and running a third-party app. The vulnerability allows local apps to access sensitive functionality that is generally restricted to pre-installed apps, such as programmatically performing the following actions: granting arbitrary permissions (which can be used to obtain sensitive user data), installing arbitrary apps, video recording the screen, wiping the device (removing the user's apps and data), injecting arbitrary input events, calling emergency phone numbers, disabling apps, accessing notifications, and much more. The confirmed vulnerable software build fingerprints for the Itel Vision 3 Turbo device are as follows: Itel/F6321/itel-S661LP:11/RP1A.201005.001/GL-V92-20230105:user/release-keys, Itel/F6321/itel-S661LP:11/RP1A.201005.001/GL-V86-20221118:user/release-keys, Itel/F6321/itel-S661LP:11/RP1A.201005.001/GL-V78-20221101:user/release-keys, Itel/F6321/itel-S661LP:11/RP1A.201005.001/GL-V64-20220803:user/release-keys, Itel/F6321/itel-S661LP:11/RP1A.201005.001/GL-V61-20220721:user/release-keys, Itel/F6321/itel-S661LP:11/RP1A.201005.001/GL-V58-20220712:user/release-keys, and Itel/F6321/itel-S661LP:11/RP1A.201005.001/GL-V051-20220613:user/release-keys. This malicious app sends a broadcast Intent to the receiver component named com.transsion.autotest.factory/.broadcast.CommandReceiver with the path to a shell script that it creates in its scoped storage directory. Then the com.transsion.autotest.factory app will execute the shell script with \"system\" privileges.", "severity": [ - - ], - "affected": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N" + } ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -29,9 +30,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-276" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-22T15:15:46Z" diff --git a/advisories/unreviewed/2024/05/GHSA-34g4-3jrw-9qgp/GHSA-34g4-3jrw-9qgp.json b/advisories/unreviewed/2024/05/GHSA-34g4-3jrw-9qgp/GHSA-34g4-3jrw-9qgp.json index 725e73a095e..14bc00b2a9b 100644 --- a/advisories/unreviewed/2024/05/GHSA-34g4-3jrw-9qgp/GHSA-34g4-3jrw-9qgp.json +++ b/advisories/unreviewed/2024/05/GHSA-34g4-3jrw-9qgp/GHSA-34g4-3jrw-9qgp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-34g4-3jrw-9qgp", - "modified": "2024-05-01T03:30:31Z", + "modified": "2024-12-04T18:32:34Z", "published": "2024-05-01T03:30:31Z", "aliases": [ "CVE-2024-33766" ], "details": "lunasvg v2.3.9 was discovered to contain an FPE (Floating Point Exception) at blend_transformed_tiled_argb.isra.0.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-369" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-01T03:15:07Z" diff --git a/advisories/unreviewed/2024/05/GHSA-f5r7-653f-66mv/GHSA-f5r7-653f-66mv.json b/advisories/unreviewed/2024/05/GHSA-f5r7-653f-66mv/GHSA-f5r7-653f-66mv.json index 352511f2579..15032e5db78 100644 --- a/advisories/unreviewed/2024/05/GHSA-f5r7-653f-66mv/GHSA-f5r7-653f-66mv.json +++ b/advisories/unreviewed/2024/05/GHSA-f5r7-653f-66mv/GHSA-f5r7-653f-66mv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-f5r7-653f-66mv", - "modified": "2024-05-14T15:32:52Z", + "modified": "2024-12-04T18:32:34Z", "published": "2024-05-14T15:32:52Z", "aliases": [ "CVE-2024-22910" ], "details": "Cross Site Scripting (XSS) vulnerability in CrushFTP v.10.6.0 and v.10.5.5 allows an attacker to execute arbitrary code via a crafted payload.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T14:58:26Z" diff --git a/advisories/unreviewed/2024/05/GHSA-f8gg-2gx7-phw9/GHSA-f8gg-2gx7-phw9.json b/advisories/unreviewed/2024/05/GHSA-f8gg-2gx7-phw9/GHSA-f8gg-2gx7-phw9.json index 69137b929a6..9f0b90b0701 100644 --- a/advisories/unreviewed/2024/05/GHSA-f8gg-2gx7-phw9/GHSA-f8gg-2gx7-phw9.json +++ b/advisories/unreviewed/2024/05/GHSA-f8gg-2gx7-phw9/GHSA-f8gg-2gx7-phw9.json @@ -1,18 +1,19 @@ { "schema_version": "1.4.0", "id": "GHSA-f8gg-2gx7-phw9", - "modified": "2024-05-21T18:31:22Z", + "modified": "2024-12-04T18:32:34Z", "published": "2024-05-21T18:31:22Z", "aliases": [ "CVE-2023-52838" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: imsttfb: fix a resource leak in probe\n\nI've re-written the error handling but the bug is that if init_imstt()\nfails we need to call iounmap(par->cmap_regs).", "severity": [ - - ], - "affected": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -53,9 +54,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-21T16:15:21Z" diff --git a/advisories/unreviewed/2024/05/GHSA-hcr5-hp8w-36q9/GHSA-hcr5-hp8w-36q9.json b/advisories/unreviewed/2024/05/GHSA-hcr5-hp8w-36q9/GHSA-hcr5-hp8w-36q9.json index 8ce1c3aae48..0427ea1afaa 100644 --- a/advisories/unreviewed/2024/05/GHSA-hcr5-hp8w-36q9/GHSA-hcr5-hp8w-36q9.json +++ b/advisories/unreviewed/2024/05/GHSA-hcr5-hp8w-36q9/GHSA-hcr5-hp8w-36q9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hcr5-hp8w-36q9", - "modified": "2024-05-16T15:31:37Z", + "modified": "2024-12-04T18:32:34Z", "published": "2024-05-16T15:31:37Z", "aliases": [ "CVE-2023-46842" ], "details": "Unlike 32-bit PV guests, HVM guests may switch freely between 64-bit and\nother modes. This in particular means that they may set registers used\nto pass 32-bit-mode hypercall arguments to values outside of the range\n32-bit code would be able to set them to.\n\nWhen processing of hypercalls takes a considerable amount of time,\nthe hypervisor may choose to invoke a hypercall continuation. Doing so\ninvolves putting (perhaps updated) hypercall arguments in respective\nregisters. For guests not running in 64-bit mode this further involves\na certain amount of translation of the values.\n\nUnfortunately internal sanity checking of these translated values\nassumes high halves of registers to always be clear when invoking a\nhypercall. When this is found not to be the case, it triggers a\nconsistency check in the hypervisor and causes a crash.\n", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-843" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-16T14:15:08Z" diff --git a/advisories/unreviewed/2024/06/GHSA-4wv7-jg5w-qpfh/GHSA-4wv7-jg5w-qpfh.json b/advisories/unreviewed/2024/06/GHSA-4wv7-jg5w-qpfh/GHSA-4wv7-jg5w-qpfh.json index f970fa90c55..510a507b1ad 100644 --- a/advisories/unreviewed/2024/06/GHSA-4wv7-jg5w-qpfh/GHSA-4wv7-jg5w-qpfh.json +++ b/advisories/unreviewed/2024/06/GHSA-4wv7-jg5w-qpfh/GHSA-4wv7-jg5w-qpfh.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-79", "CWE-80" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/06/GHSA-hx7g-cqpx-p72r/GHSA-hx7g-cqpx-p72r.json b/advisories/unreviewed/2024/06/GHSA-hx7g-cqpx-p72r/GHSA-hx7g-cqpx-p72r.json index c13eac225df..3f103f370ca 100644 --- a/advisories/unreviewed/2024/06/GHSA-hx7g-cqpx-p72r/GHSA-hx7g-cqpx-p72r.json +++ b/advisories/unreviewed/2024/06/GHSA-hx7g-cqpx-p72r/GHSA-hx7g-cqpx-p72r.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-79", "CWE-80" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/07/GHSA-4pj3-gqqh-fxcr/GHSA-4pj3-gqqh-fxcr.json b/advisories/unreviewed/2024/07/GHSA-4pj3-gqqh-fxcr/GHSA-4pj3-gqqh-fxcr.json index 52b274993cc..901d0575682 100644 --- a/advisories/unreviewed/2024/07/GHSA-4pj3-gqqh-fxcr/GHSA-4pj3-gqqh-fxcr.json +++ b/advisories/unreviewed/2024/07/GHSA-4pj3-gqqh-fxcr/GHSA-4pj3-gqqh-fxcr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4pj3-gqqh-fxcr", - "modified": "2024-08-01T15:31:52Z", + "modified": "2024-12-04T18:32:35Z", "published": "2024-07-04T15:30:40Z", "aliases": [ "CVE-2024-39165" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39165" }, + { + "type": "WEB", + "url": "https://synacktiv.com/en/advisories/jpgraph-professional-version-pre-authenticated-remote-code-execution" + }, { "type": "WEB", "url": "https://www.synacktiv.com/advisories/jpgraph-professional-version-pre-authenticated-remote-code-execution" diff --git a/advisories/unreviewed/2024/11/GHSA-33cw-f6c5-2rv7/GHSA-33cw-f6c5-2rv7.json b/advisories/unreviewed/2024/11/GHSA-33cw-f6c5-2rv7/GHSA-33cw-f6c5-2rv7.json index c36720b351c..af6c13a6fd0 100644 --- a/advisories/unreviewed/2024/11/GHSA-33cw-f6c5-2rv7/GHSA-33cw-f6c5-2rv7.json +++ b/advisories/unreviewed/2024/11/GHSA-33cw-f6c5-2rv7/GHSA-33cw-f6c5-2rv7.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-39qg-hhmq-h5px/GHSA-39qg-hhmq-h5px.json b/advisories/unreviewed/2024/11/GHSA-39qg-hhmq-h5px/GHSA-39qg-hhmq-h5px.json index 15bae651dd8..d0f035105f9 100644 --- a/advisories/unreviewed/2024/11/GHSA-39qg-hhmq-h5px/GHSA-39qg-hhmq-h5px.json +++ b/advisories/unreviewed/2024/11/GHSA-39qg-hhmq-h5px/GHSA-39qg-hhmq-h5px.json @@ -50,7 +50,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-5qg6-ph65-pqjq/GHSA-5qg6-ph65-pqjq.json b/advisories/unreviewed/2024/11/GHSA-5qg6-ph65-pqjq/GHSA-5qg6-ph65-pqjq.json index b4af90f5bea..9b8e3adeaea 100644 --- a/advisories/unreviewed/2024/11/GHSA-5qg6-ph65-pqjq/GHSA-5qg6-ph65-pqjq.json +++ b/advisories/unreviewed/2024/11/GHSA-5qg6-ph65-pqjq/GHSA-5qg6-ph65-pqjq.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-6cqf-gqr3-8cr4/GHSA-6cqf-gqr3-8cr4.json b/advisories/unreviewed/2024/11/GHSA-6cqf-gqr3-8cr4/GHSA-6cqf-gqr3-8cr4.json index c24d35992c6..0237b960ff8 100644 --- a/advisories/unreviewed/2024/11/GHSA-6cqf-gqr3-8cr4/GHSA-6cqf-gqr3-8cr4.json +++ b/advisories/unreviewed/2024/11/GHSA-6cqf-gqr3-8cr4/GHSA-6cqf-gqr3-8cr4.json @@ -1,18 +1,19 @@ { "schema_version": "1.4.0", "id": "GHSA-6cqf-gqr3-8cr4", - "modified": "2024-11-26T21:32:25Z", + "modified": "2024-12-04T18:32:35Z", "published": "2024-11-26T21:32:25Z", "aliases": [ "CVE-2024-50942" ], "details": "qiwen-file v1.4.0 was discovered to contain a SQL injection vulnerability via the component /mapper/NoticeMapper.xml.", "severity": [ - - ], - "affected": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -33,9 +34,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-26T21:15:07Z" diff --git a/advisories/unreviewed/2024/11/GHSA-6f7w-r4p9-954c/GHSA-6f7w-r4p9-954c.json b/advisories/unreviewed/2024/11/GHSA-6f7w-r4p9-954c/GHSA-6f7w-r4p9-954c.json index 9ffbe636f23..ce43e7b3428 100644 --- a/advisories/unreviewed/2024/11/GHSA-6f7w-r4p9-954c/GHSA-6f7w-r4p9-954c.json +++ b/advisories/unreviewed/2024/11/GHSA-6f7w-r4p9-954c/GHSA-6f7w-r4p9-954c.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6f7w-r4p9-954c", - "modified": "2024-11-29T15:37:53Z", + "modified": "2024-12-04T18:32:35Z", "published": "2024-11-29T15:37:53Z", "aliases": [ "CVE-2024-48406" ], "details": "Buffer Overflow vulnerability in SunBK201 umicat through v.0.3.2 and fixed in v.0.3.3 allows an attacker to execute arbitrary code via the power(uct_int_t x, uct_int_t n) in src/uct_upstream.c.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-29T15:15:17Z" diff --git a/advisories/unreviewed/2024/11/GHSA-77mr-3x8w-8f7f/GHSA-77mr-3x8w-8f7f.json b/advisories/unreviewed/2024/11/GHSA-77mr-3x8w-8f7f/GHSA-77mr-3x8w-8f7f.json index a24fb2ea747..aed161e3ea5 100644 --- a/advisories/unreviewed/2024/11/GHSA-77mr-3x8w-8f7f/GHSA-77mr-3x8w-8f7f.json +++ b/advisories/unreviewed/2024/11/GHSA-77mr-3x8w-8f7f/GHSA-77mr-3x8w-8f7f.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-7946-g2x4-f8c7/GHSA-7946-g2x4-f8c7.json b/advisories/unreviewed/2024/11/GHSA-7946-g2x4-f8c7/GHSA-7946-g2x4-f8c7.json index 479899dc189..563346b9521 100644 --- a/advisories/unreviewed/2024/11/GHSA-7946-g2x4-f8c7/GHSA-7946-g2x4-f8c7.json +++ b/advisories/unreviewed/2024/11/GHSA-7946-g2x4-f8c7/GHSA-7946-g2x4-f8c7.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-9wf4-422v-6w3j/GHSA-9wf4-422v-6w3j.json b/advisories/unreviewed/2024/11/GHSA-9wf4-422v-6w3j/GHSA-9wf4-422v-6w3j.json index 4aec78a8bce..14fc62c8fa3 100644 --- a/advisories/unreviewed/2024/11/GHSA-9wf4-422v-6w3j/GHSA-9wf4-422v-6w3j.json +++ b/advisories/unreviewed/2024/11/GHSA-9wf4-422v-6w3j/GHSA-9wf4-422v-6w3j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9wf4-422v-6w3j", - "modified": "2024-11-21T21:33:32Z", + "modified": "2024-12-04T18:32:34Z", "published": "2024-11-21T21:33:32Z", "aliases": [ "CVE-2024-51365" ], "details": "An arbitrary file upload vulnerability in the importSettings method of VisiCut v2.1 allows attackers to execute arbitrary code via uploading a crafted Zip file.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-21T20:15:44Z" diff --git a/advisories/unreviewed/2024/11/GHSA-9xh5-35c7-hmjm/GHSA-9xh5-35c7-hmjm.json b/advisories/unreviewed/2024/11/GHSA-9xh5-35c7-hmjm/GHSA-9xh5-35c7-hmjm.json index b67d7ea75a2..40be2800a61 100644 --- a/advisories/unreviewed/2024/11/GHSA-9xh5-35c7-hmjm/GHSA-9xh5-35c7-hmjm.json +++ b/advisories/unreviewed/2024/11/GHSA-9xh5-35c7-hmjm/GHSA-9xh5-35c7-hmjm.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-fjpm-jv87-vx5f/GHSA-fjpm-jv87-vx5f.json b/advisories/unreviewed/2024/11/GHSA-fjpm-jv87-vx5f/GHSA-fjpm-jv87-vx5f.json index a7b1da30546..825431b5e05 100644 --- a/advisories/unreviewed/2024/11/GHSA-fjpm-jv87-vx5f/GHSA-fjpm-jv87-vx5f.json +++ b/advisories/unreviewed/2024/11/GHSA-fjpm-jv87-vx5f/GHSA-fjpm-jv87-vx5f.json @@ -50,7 +50,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-g724-p2vc-8mfg/GHSA-g724-p2vc-8mfg.json b/advisories/unreviewed/2024/11/GHSA-g724-p2vc-8mfg/GHSA-g724-p2vc-8mfg.json index da7e85c1d02..0a23061b299 100644 --- a/advisories/unreviewed/2024/11/GHSA-g724-p2vc-8mfg/GHSA-g724-p2vc-8mfg.json +++ b/advisories/unreviewed/2024/11/GHSA-g724-p2vc-8mfg/GHSA-g724-p2vc-8mfg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-g724-p2vc-8mfg", - "modified": "2024-11-29T15:37:53Z", + "modified": "2024-12-04T18:32:35Z", "published": "2024-11-29T15:37:53Z", "aliases": [ "CVE-2024-36671" ], "details": "nodemcu before v3.0.0-release_20240225 was discovered to contain an integer overflow via the getnum function at /modules/struct.c.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-190" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-29T15:15:17Z" diff --git a/advisories/unreviewed/2024/11/GHSA-ghf3-4f69-3865/GHSA-ghf3-4f69-3865.json b/advisories/unreviewed/2024/11/GHSA-ghf3-4f69-3865/GHSA-ghf3-4f69-3865.json index eec87a2b3aa..4a9dd619318 100644 --- a/advisories/unreviewed/2024/11/GHSA-ghf3-4f69-3865/GHSA-ghf3-4f69-3865.json +++ b/advisories/unreviewed/2024/11/GHSA-ghf3-4f69-3865/GHSA-ghf3-4f69-3865.json @@ -1,18 +1,19 @@ { "schema_version": "1.4.0", "id": "GHSA-ghf3-4f69-3865", - "modified": "2024-11-25T21:30:50Z", + "modified": "2024-12-04T18:32:35Z", "published": "2024-11-25T21:30:50Z", "aliases": [ "CVE-2024-50671" ], "details": "Incorrect access control in Adapt Learning Adapt Authoring Tool <= 0.11.3 allows attackers with Authenticated User roles to obtain email addresses via the \"Get users\" feature. The vulnerability occurs due to a flaw in permission verification logic, where the wildcard character in permitted URLs grants unintended access to endpoints restricted to users with Super Admin roles. This makes it possible for attackers to disclose the email addresses of all users.", "severity": [ - - ], - "affected": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -29,9 +30,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-25T21:15:19Z" diff --git a/advisories/unreviewed/2024/11/GHSA-ghqh-9grh-xvg4/GHSA-ghqh-9grh-xvg4.json b/advisories/unreviewed/2024/11/GHSA-ghqh-9grh-xvg4/GHSA-ghqh-9grh-xvg4.json index 9cf9ba675f1..12144f8ce60 100644 --- a/advisories/unreviewed/2024/11/GHSA-ghqh-9grh-xvg4/GHSA-ghqh-9grh-xvg4.json +++ b/advisories/unreviewed/2024/11/GHSA-ghqh-9grh-xvg4/GHSA-ghqh-9grh-xvg4.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-hc4c-32w7-p2rh/GHSA-hc4c-32w7-p2rh.json b/advisories/unreviewed/2024/11/GHSA-hc4c-32w7-p2rh/GHSA-hc4c-32w7-p2rh.json index 5a9f800cfa8..9e61975bf70 100644 --- a/advisories/unreviewed/2024/11/GHSA-hc4c-32w7-p2rh/GHSA-hc4c-32w7-p2rh.json +++ b/advisories/unreviewed/2024/11/GHSA-hc4c-32w7-p2rh/GHSA-hc4c-32w7-p2rh.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-jv23-26jp-6g6v/GHSA-jv23-26jp-6g6v.json b/advisories/unreviewed/2024/11/GHSA-jv23-26jp-6g6v/GHSA-jv23-26jp-6g6v.json index a13393c3e44..4d2ae2eec40 100644 --- a/advisories/unreviewed/2024/11/GHSA-jv23-26jp-6g6v/GHSA-jv23-26jp-6g6v.json +++ b/advisories/unreviewed/2024/11/GHSA-jv23-26jp-6g6v/GHSA-jv23-26jp-6g6v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jv23-26jp-6g6v", - "modified": "2024-11-07T12:30:35Z", + "modified": "2024-12-04T18:32:34Z", "published": "2024-11-07T12:30:35Z", "aliases": [ "CVE-2024-50157" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/bnxt_re: Avoid CPU lockups due fifo occupancy check loop\n\nDriver waits indefinitely for the fifo occupancy to go below a threshold\nas soon as the pacing interrupt is received. This can cause soft lockup on\none of the processors, if the rate of DB is very high.\n\nAdd a loop count for FPGA and exit the __wait_for_fifo_occupancy_below_th\nif the loop is taking more time. Pacing will be continuing until the\noccupancy is below the threshold. This is ensured by the checks in\nbnxt_re_pacing_timer_exp and further scheduling the work for pacing based\non the fifo occupancy.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -25,7 +30,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-07T10:15:07Z" diff --git a/advisories/unreviewed/2024/11/GHSA-m5x8-5g7c-7x6p/GHSA-m5x8-5g7c-7x6p.json b/advisories/unreviewed/2024/11/GHSA-m5x8-5g7c-7x6p/GHSA-m5x8-5g7c-7x6p.json index 53229d336f9..b2bb592146e 100644 --- a/advisories/unreviewed/2024/11/GHSA-m5x8-5g7c-7x6p/GHSA-m5x8-5g7c-7x6p.json +++ b/advisories/unreviewed/2024/11/GHSA-m5x8-5g7c-7x6p/GHSA-m5x8-5g7c-7x6p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-p4fj-vmm6-h453/GHSA-p4fj-vmm6-h453.json b/advisories/unreviewed/2024/11/GHSA-p4fj-vmm6-h453/GHSA-p4fj-vmm6-h453.json index caab49e11e2..88442ef4edb 100644 --- a/advisories/unreviewed/2024/11/GHSA-p4fj-vmm6-h453/GHSA-p4fj-vmm6-h453.json +++ b/advisories/unreviewed/2024/11/GHSA-p4fj-vmm6-h453/GHSA-p4fj-vmm6-h453.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p4fj-vmm6-h453", - "modified": "2024-11-21T21:33:32Z", + "modified": "2024-12-04T18:32:34Z", "published": "2024-11-21T21:33:32Z", "aliases": [ "CVE-2024-51366" ], "details": "An arbitrary file upload vulnerability in the component \\Roaming\\Omega of OmegaT v6.0.1 allows attackers to execute arbitrary code via uploading a crafted .conf file.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-21T20:15:44Z" diff --git a/advisories/unreviewed/2024/11/GHSA-q59j-vv4j-v33c/GHSA-q59j-vv4j-v33c.json b/advisories/unreviewed/2024/11/GHSA-q59j-vv4j-v33c/GHSA-q59j-vv4j-v33c.json index b850a3e98a5..f94a4ceff98 100644 --- a/advisories/unreviewed/2024/11/GHSA-q59j-vv4j-v33c/GHSA-q59j-vv4j-v33c.json +++ b/advisories/unreviewed/2024/11/GHSA-q59j-vv4j-v33c/GHSA-q59j-vv4j-v33c.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-q59j-vv4j-v33c", - "modified": "2024-11-29T18:34:03Z", + "modified": "2024-12-04T18:32:35Z", "published": "2024-11-29T18:34:03Z", "aliases": [ "CVE-2024-36620" ], "details": "moby v25.0.0 - v26.0.2 is vulnerable to NULL Pointer Dereference via daemon/images/image_history.go.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-29T18:15:07Z" diff --git a/advisories/unreviewed/2024/11/GHSA-q89f-q98p-7vmj/GHSA-q89f-q98p-7vmj.json b/advisories/unreviewed/2024/11/GHSA-q89f-q98p-7vmj/GHSA-q89f-q98p-7vmj.json index b247aeb91d3..65deca510ae 100644 --- a/advisories/unreviewed/2024/11/GHSA-q89f-q98p-7vmj/GHSA-q89f-q98p-7vmj.json +++ b/advisories/unreviewed/2024/11/GHSA-q89f-q98p-7vmj/GHSA-q89f-q98p-7vmj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-q89f-q98p-7vmj", - "modified": "2024-11-29T06:35:29Z", + "modified": "2024-12-04T18:32:35Z", "published": "2024-11-29T06:35:29Z", "aliases": [ "CVE-2024-45495" ], "details": "MSA FieldServer Gateway 5.0.0 through 6.5.2 allows cross-origin WebSocket hijacking.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-346" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-29T05:15:05Z" diff --git a/advisories/unreviewed/2024/12/GHSA-52hr-mg3h-r5h9/GHSA-52hr-mg3h-r5h9.json b/advisories/unreviewed/2024/12/GHSA-52hr-mg3h-r5h9/GHSA-52hr-mg3h-r5h9.json new file mode 100644 index 00000000000..a71c2d72772 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-52hr-mg3h-r5h9/GHSA-52hr-mg3h-r5h9.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-52hr-mg3h-r5h9", + "modified": "2024-12-04T18:32:36Z", + "published": "2024-12-04T18:32:35Z", + "aliases": [ + "CVE-2024-11643" + ], + "details": "The Accessibility by AllAccessible plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'AllAccessible_save_settings' function in all versions up to, and including, 1.3.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11643" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/allaccessible/trunk/allaccessible.php#L249" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3202017" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/bb65d916-7d9e-4562-ab9b-c7ba012a08fb?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-04T16:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-69h8-2gjf-xq29/GHSA-69h8-2gjf-xq29.json b/advisories/unreviewed/2024/12/GHSA-69h8-2gjf-xq29/GHSA-69h8-2gjf-xq29.json index 20736c01efb..648fa2a88f1 100644 --- a/advisories/unreviewed/2024/12/GHSA-69h8-2gjf-xq29/GHSA-69h8-2gjf-xq29.json +++ b/advisories/unreviewed/2024/12/GHSA-69h8-2gjf-xq29/GHSA-69h8-2gjf-xq29.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-426" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/12/GHSA-6q3r-569c-crm7/GHSA-6q3r-569c-crm7.json b/advisories/unreviewed/2024/12/GHSA-6q3r-569c-crm7/GHSA-6q3r-569c-crm7.json new file mode 100644 index 00000000000..3d07fd1205c --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-6q3r-569c-crm7/GHSA-6q3r-569c-crm7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6q3r-569c-crm7", + "modified": "2024-12-04T18:32:34Z", + "published": "2024-12-04T18:32:34Z", + "aliases": [ + "CVE-2024-53432" + ], + "details": "While parsing certain malformed PLY files, PCL version 1.14.1 crashes due to an uncaught std::out_of_range exception in PCLPointCloud2::at. This issue could potentially be exploited to cause a denial-of-service (DoS) attack when processing untrusted PLY files.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53432" + }, + { + "type": "WEB", + "url": "https://github.com/PointCloudLibrary/pcl/issues/6162" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-754" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-21T18:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-6w26-7rr7-96rj/GHSA-6w26-7rr7-96rj.json b/advisories/unreviewed/2024/12/GHSA-6w26-7rr7-96rj/GHSA-6w26-7rr7-96rj.json new file mode 100644 index 00000000000..21070b0ca86 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-6w26-7rr7-96rj/GHSA-6w26-7rr7-96rj.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6w26-7rr7-96rj", + "modified": "2024-12-04T18:32:36Z", + "published": "2024-12-04T18:32:36Z", + "aliases": [ + "CVE-2018-9395" + ], + "details": "In mtk_cfg80211_vendor_packet_keep_alive_start and mtk_cfg80211_vendor_set_config of drivers/misc/mediatek/connectivity/wlan/gen2/os/linux/gl_vendor.c, there is a possible OOB write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9395" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/pixel/2018-06-01" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-04T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-7453-c947-w47g/GHSA-7453-c947-w47g.json b/advisories/unreviewed/2024/12/GHSA-7453-c947-w47g/GHSA-7453-c947-w47g.json index 2d835246255..cb08707a636 100644 --- a/advisories/unreviewed/2024/12/GHSA-7453-c947-w47g/GHSA-7453-c947-w47g.json +++ b/advisories/unreviewed/2024/12/GHSA-7453-c947-w47g/GHSA-7453-c947-w47g.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7453-c947-w47g", - "modified": "2024-12-04T00:31:32Z", + "modified": "2024-12-04T18:32:35Z", "published": "2024-12-04T00:31:32Z", "aliases": [ "CVE-2024-53502" ], "details": "Seecms v4.8 was discovered to contain a SQL injection vulnerability in the SEMCMS_SeoAndTag.php page.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-03T22:15:05Z" diff --git a/advisories/unreviewed/2024/12/GHSA-7vhq-gphw-vgj2/GHSA-7vhq-gphw-vgj2.json b/advisories/unreviewed/2024/12/GHSA-7vhq-gphw-vgj2/GHSA-7vhq-gphw-vgj2.json new file mode 100644 index 00000000000..0da99854670 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-7vhq-gphw-vgj2/GHSA-7vhq-gphw-vgj2.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7vhq-gphw-vgj2", + "modified": "2024-12-04T18:32:36Z", + "published": "2024-12-04T18:32:36Z", + "aliases": [ + "CVE-2024-12149" + ], + "details": "Incorrect permission assignment in temporary access requests component in Devolutions Remote Desktop Manager 2024.3.19.0 and earlier on Windows allows an authenticated user that request temporary permissions on an entry to obtain more privileges than requested.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12149" + }, + { + "type": "WEB", + "url": "https://devolutions.net/security/advisories/DEVO-2024-0017" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-732" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-04T18:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-7xjp-f5xm-j9vm/GHSA-7xjp-f5xm-j9vm.json b/advisories/unreviewed/2024/12/GHSA-7xjp-f5xm-j9vm/GHSA-7xjp-f5xm-j9vm.json new file mode 100644 index 00000000000..58c32c41259 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-7xjp-f5xm-j9vm/GHSA-7xjp-f5xm-j9vm.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7xjp-f5xm-j9vm", + "modified": "2024-12-04T18:32:35Z", + "published": "2024-12-04T18:32:35Z", + "aliases": [ + "CVE-2024-37575" + ], + "details": "The Mister org.mistergroup.shouldianswer application 1.4.264 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the org.mistergroup.shouldianswer.ui.default_dialer.DefaultDialerActivity component.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37575" + }, + { + "type": "WEB", + "url": "https://github.com/actuator/org.mistergroup.shouldianswer" + }, + { + "type": "WEB", + "url": "https://github.com/actuator/org.mistergroup.shouldianswer/blob/main/CVE-2024-37575" + }, + { + "type": "WEB", + "url": "https://play.google.com/store/apps/details?id=org.mistergroup.shouldianswer" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-04T16:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-875c-9gcv-8c6h/GHSA-875c-9gcv-8c6h.json b/advisories/unreviewed/2024/12/GHSA-875c-9gcv-8c6h/GHSA-875c-9gcv-8c6h.json new file mode 100644 index 00000000000..fa3dd152084 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-875c-9gcv-8c6h/GHSA-875c-9gcv-8c6h.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-875c-9gcv-8c6h", + "modified": "2024-12-04T18:32:37Z", + "published": "2024-12-04T18:32:37Z", + "aliases": [ + "CVE-2024-12147" + ], + "details": "A vulnerability was found in Netgear R6900 1.0.1.26_1.0.20. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file upgrade_check.cgi of the component HTTP Header Handler. The manipulation of the argument Content-Length leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12147" + }, + { + "type": "WEB", + "url": "https://github.com/upload000/Hub/blob/main/IOT/Netgear_R6900.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.286873" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.286873" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.451858" + }, + { + "type": "WEB", + "url": "https://www.netgear.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-04T18:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-9g52-r87c-973q/GHSA-9g52-r87c-973q.json b/advisories/unreviewed/2024/12/GHSA-9g52-r87c-973q/GHSA-9g52-r87c-973q.json index 558d4ec8ca7..5b22c151ed7 100644 --- a/advisories/unreviewed/2024/12/GHSA-9g52-r87c-973q/GHSA-9g52-r87c-973q.json +++ b/advisories/unreviewed/2024/12/GHSA-9g52-r87c-973q/GHSA-9g52-r87c-973q.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-863" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/12/GHSA-9jcj-c3px-4jc5/GHSA-9jcj-c3px-4jc5.json b/advisories/unreviewed/2024/12/GHSA-9jcj-c3px-4jc5/GHSA-9jcj-c3px-4jc5.json index 7da04045f4a..ea708c13682 100644 --- a/advisories/unreviewed/2024/12/GHSA-9jcj-c3px-4jc5/GHSA-9jcj-c3px-4jc5.json +++ b/advisories/unreviewed/2024/12/GHSA-9jcj-c3px-4jc5/GHSA-9jcj-c3px-4jc5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9jcj-c3px-4jc5", - "modified": "2024-12-02T15:31:41Z", + "modified": "2024-12-04T18:32:35Z", "published": "2024-12-02T15:31:41Z", "aliases": [ "CVE-2024-10905" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://www.sailpoint.com/security-advisories" + }, + { + "type": "WEB", + "url": "https://www.sailpoint.com/security-advisories/identityiq-improper-access-control-vulnerability-cve-2024-10905" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/12/GHSA-9xph-238r-4vh4/GHSA-9xph-238r-4vh4.json b/advisories/unreviewed/2024/12/GHSA-9xph-238r-4vh4/GHSA-9xph-238r-4vh4.json new file mode 100644 index 00000000000..72b6591fdc5 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-9xph-238r-4vh4/GHSA-9xph-238r-4vh4.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9xph-238r-4vh4", + "modified": "2024-12-04T18:32:36Z", + "published": "2024-12-04T18:32:35Z", + "aliases": [ + "CVE-2024-53614" + ], + "details": "A hardcoded decryption key in Thinkware Cloud APK v4.3.46 allows attackers to access sensitive data and execute arbitrary commands with elevated privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53614" + }, + { + "type": "WEB", + "url": "https://geochen.medium.com/cve-2024-53614-61b48c3b45d6" + }, + { + "type": "WEB", + "url": "http://thinkware.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-798" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-04T16:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-cc44-h482-gj5h/GHSA-cc44-h482-gj5h.json b/advisories/unreviewed/2024/12/GHSA-cc44-h482-gj5h/GHSA-cc44-h482-gj5h.json index edd12634d20..9b7748ec405 100644 --- a/advisories/unreviewed/2024/12/GHSA-cc44-h482-gj5h/GHSA-cc44-h482-gj5h.json +++ b/advisories/unreviewed/2024/12/GHSA-cc44-h482-gj5h/GHSA-cc44-h482-gj5h.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cc44-h482-gj5h", - "modified": "2024-12-02T03:32:59Z", + "modified": "2024-12-04T18:32:35Z", "published": "2024-12-02T03:32:59Z", "aliases": [ "CVE-2024-53605" ], "details": "Incorrect access control in the component content://com.handcent.messaging.provider.MessageProvider/ of Handcent NextSMS v10.9.9.7 allows attackers to access sensitive data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-02T01:15:04Z" diff --git a/advisories/unreviewed/2024/12/GHSA-fr2r-2pc4-h4f4/GHSA-fr2r-2pc4-h4f4.json b/advisories/unreviewed/2024/12/GHSA-fr2r-2pc4-h4f4/GHSA-fr2r-2pc4-h4f4.json new file mode 100644 index 00000000000..055d1ae3ded --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-fr2r-2pc4-h4f4/GHSA-fr2r-2pc4-h4f4.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fr2r-2pc4-h4f4", + "modified": "2024-12-04T18:32:36Z", + "published": "2024-12-04T18:32:36Z", + "aliases": [ + "CVE-2024-12196" + ], + "details": "Incorrect authorization in the permission component in Devolutions Server 2024.3.7.0 and earlier allows an authenticated user to view the password history of an entry without the view password permission.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12196" + }, + { + "type": "WEB", + "url": "https://devolutions.net/security/advisories/DEVO-2024-0017" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-04T18:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-gj29-j7qg-vpf7/GHSA-gj29-j7qg-vpf7.json b/advisories/unreviewed/2024/12/GHSA-gj29-j7qg-vpf7/GHSA-gj29-j7qg-vpf7.json index f8dbd3ece9b..02b90be7f69 100644 --- a/advisories/unreviewed/2024/12/GHSA-gj29-j7qg-vpf7/GHSA-gj29-j7qg-vpf7.json +++ b/advisories/unreviewed/2024/12/GHSA-gj29-j7qg-vpf7/GHSA-gj29-j7qg-vpf7.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-295" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/12/GHSA-hf2h-mjwg-v9r7/GHSA-hf2h-mjwg-v9r7.json b/advisories/unreviewed/2024/12/GHSA-hf2h-mjwg-v9r7/GHSA-hf2h-mjwg-v9r7.json index 053dc17783a..03a199d99b2 100644 --- a/advisories/unreviewed/2024/12/GHSA-hf2h-mjwg-v9r7/GHSA-hf2h-mjwg-v9r7.json +++ b/advisories/unreviewed/2024/12/GHSA-hf2h-mjwg-v9r7/GHSA-hf2h-mjwg-v9r7.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-306" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/12/GHSA-j4cx-gm46-j4hg/GHSA-j4cx-gm46-j4hg.json b/advisories/unreviewed/2024/12/GHSA-j4cx-gm46-j4hg/GHSA-j4cx-gm46-j4hg.json new file mode 100644 index 00000000000..ee94871bd4b --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-j4cx-gm46-j4hg/GHSA-j4cx-gm46-j4hg.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j4cx-gm46-j4hg", + "modified": "2024-12-04T18:32:36Z", + "published": "2024-12-04T18:32:36Z", + "aliases": [ + "CVE-2018-9392" + ], + "details": "In get_binary of vendor/mediatek/proprietary/hardware/connectivity/gps/gps_hal/src/data_coder.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9392" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/pixel/2018-06-01" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-04T18:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-jq9m-23hf-jgfg/GHSA-jq9m-23hf-jgfg.json b/advisories/unreviewed/2024/12/GHSA-jq9m-23hf-jgfg/GHSA-jq9m-23hf-jgfg.json new file mode 100644 index 00000000000..18cd1b03144 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-jq9m-23hf-jgfg/GHSA-jq9m-23hf-jgfg.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jq9m-23hf-jgfg", + "modified": "2024-12-04T18:32:36Z", + "published": "2024-12-04T18:32:36Z", + "aliases": [ + "CVE-2018-9393" + ], + "details": "In procfile_write of drivers/misc/mediatek/connectivity/wlan/gen2/os/linux/gl_proc.c, there is a possible OOB write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9393" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/pixel/2018-06-01" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-04T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-m2gm-rv6f-7h29/GHSA-m2gm-rv6f-7h29.json b/advisories/unreviewed/2024/12/GHSA-m2gm-rv6f-7h29/GHSA-m2gm-rv6f-7h29.json index 89f5402f21b..f5a8145e8d0 100644 --- a/advisories/unreviewed/2024/12/GHSA-m2gm-rv6f-7h29/GHSA-m2gm-rv6f-7h29.json +++ b/advisories/unreviewed/2024/12/GHSA-m2gm-rv6f-7h29/GHSA-m2gm-rv6f-7h29.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-m2gm-rv6f-7h29", - "modified": "2024-12-04T15:31:52Z", + "modified": "2024-12-04T18:32:35Z", "published": "2024-12-04T15:31:52Z", "aliases": [ "CVE-2024-40745" ], "details": "Reflected Cross site scripting vulnerability in Convert Forms component for Joomla in versions before 4.4.6.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-04T15:15:11Z" diff --git a/advisories/unreviewed/2024/12/GHSA-m97p-7pjw-xw7r/GHSA-m97p-7pjw-xw7r.json b/advisories/unreviewed/2024/12/GHSA-m97p-7pjw-xw7r/GHSA-m97p-7pjw-xw7r.json new file mode 100644 index 00000000000..05c3173f1ac --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-m97p-7pjw-xw7r/GHSA-m97p-7pjw-xw7r.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m97p-7pjw-xw7r", + "modified": "2024-12-04T18:32:36Z", + "published": "2024-12-04T18:32:35Z", + "aliases": [ + "CVE-2024-52676" + ], + "details": "Itsourcecode Online Discussion Forum Project v.1.0.0 is vulnerable to Cross Site Scripting (XSS) via /bcc_forum/members/home.php.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52676" + }, + { + "type": "WEB", + "url": "https://github.com/WTIMITW/System-with-Cross-site-Scripting-XSS-" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-04T17:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-p353-cp93-hvp7/GHSA-p353-cp93-hvp7.json b/advisories/unreviewed/2024/12/GHSA-p353-cp93-hvp7/GHSA-p353-cp93-hvp7.json new file mode 100644 index 00000000000..ef4c40d2e59 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-p353-cp93-hvp7/GHSA-p353-cp93-hvp7.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p353-cp93-hvp7", + "modified": "2024-12-04T18:32:36Z", + "published": "2024-12-04T18:32:36Z", + "aliases": [ + "CVE-2024-12148" + ], + "details": "Incorrect authorization in permission validation component in Devolutions Server 2024.3.6.0 and earlier allows an authenticated user to access some reporting endpoints.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12148" + }, + { + "type": "WEB", + "url": "https://devolutions.net/security/advisories/DEVO-2024-0017" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-04T18:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-p5rq-7r6m-x7rf/GHSA-p5rq-7r6m-x7rf.json b/advisories/unreviewed/2024/12/GHSA-p5rq-7r6m-x7rf/GHSA-p5rq-7r6m-x7rf.json new file mode 100644 index 00000000000..a5cececcc64 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-p5rq-7r6m-x7rf/GHSA-p5rq-7r6m-x7rf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p5rq-7r6m-x7rf", + "modified": "2024-12-04T18:32:36Z", + "published": "2024-12-04T18:32:36Z", + "aliases": [ + "CVE-2024-20397" + ], + "details": "A vulnerability in the bootloader of Cisco NX-OS Software could allow an unauthenticated attacker with physical access to an affected device, or an authenticated, local attacker with administrative credentials, to bypass NX-OS image signature verification.\n\nThis vulnerability is due to insecure bootloader settings. An attacker could exploit this vulnerability by executing a series of bootloader commands. A successful exploit could allow the attacker to bypass NX-OS image signature verification and load unverified software.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20397" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nxos-image-sig-bypas-pQDRQvjL" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-04T17:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-p998-wmcc-3j5w/GHSA-p998-wmcc-3j5w.json b/advisories/unreviewed/2024/12/GHSA-p998-wmcc-3j5w/GHSA-p998-wmcc-3j5w.json new file mode 100644 index 00000000000..49a44ec13b7 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-p998-wmcc-3j5w/GHSA-p998-wmcc-3j5w.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p998-wmcc-3j5w", + "modified": "2024-12-04T18:32:36Z", + "published": "2024-12-04T18:32:35Z", + "aliases": [ + "CVE-2018-9394" + ], + "details": "In mtk_p2p_wext_set_key of drivers/misc/mediatek/connectivity/wlan/gen2/os/linux/gl_p2p.c, there is a possible OOB write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9394" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/pixel/2018-06-01" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-04T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-pqj8-xhcx-prxm/GHSA-pqj8-xhcx-prxm.json b/advisories/unreviewed/2024/12/GHSA-pqj8-xhcx-prxm/GHSA-pqj8-xhcx-prxm.json new file mode 100644 index 00000000000..b512066861f --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-pqj8-xhcx-prxm/GHSA-pqj8-xhcx-prxm.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pqj8-xhcx-prxm", + "modified": "2024-12-04T18:32:36Z", + "published": "2024-12-04T18:32:36Z", + "aliases": [ + "CVE-2024-39163" + ], + "details": "binux pyspider up to v0.3.10 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Flask endpoints.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39163" + }, + { + "type": "WEB", + "url": "https://github.com/binux/pyspider/blob/master/pyspider/webui/debug.py#L39" + }, + { + "type": "WEB", + "url": "https://www.sonarsource.com/blog/basic-http-authentication-risk-uncovering-pyspider-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-04T17:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-pwc4-hfx3-7qw8/GHSA-pwc4-hfx3-7qw8.json b/advisories/unreviewed/2024/12/GHSA-pwc4-hfx3-7qw8/GHSA-pwc4-hfx3-7qw8.json index 9b6b90651d2..d06f3374a3b 100644 --- a/advisories/unreviewed/2024/12/GHSA-pwc4-hfx3-7qw8/GHSA-pwc4-hfx3-7qw8.json +++ b/advisories/unreviewed/2024/12/GHSA-pwc4-hfx3-7qw8/GHSA-pwc4-hfx3-7qw8.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-522" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/12/GHSA-w7xj-7rf9-cg4x/GHSA-w7xj-7rf9-cg4x.json b/advisories/unreviewed/2024/12/GHSA-w7xj-7rf9-cg4x/GHSA-w7xj-7rf9-cg4x.json new file mode 100644 index 00000000000..dc1fc7b17ad --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-w7xj-7rf9-cg4x/GHSA-w7xj-7rf9-cg4x.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w7xj-7rf9-cg4x", + "modified": "2024-12-04T18:32:37Z", + "published": "2024-12-04T18:32:37Z", + "aliases": [ + "CVE-2024-48453" + ], + "details": "An issue in INOVANCE AM401_CPU1608TPTN allows a remote attacker to execute arbitrary code via the ExecuteUserProgramUpgrade function", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48453" + }, + { + "type": "WEB", + "url": "https://github.com/N0zoM1z0/CVEs/blob/main/CVE-2024-48453.md" + }, + { + "type": "WEB", + "url": "https://github.com/N0zoM1z0/Vuln-Search/blob/main/INOVANCE%20AM401_CPU1608TPTN%20Unauthorized%20Arbitrary%20Code%20Execution%20Vulnerability.md" + }, + { + "type": "WEB", + "url": "https://www.inovance.com" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-04T18:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-wrvq-q9qh-872j/GHSA-wrvq-q9qh-872j.json b/advisories/unreviewed/2024/12/GHSA-wrvq-q9qh-872j/GHSA-wrvq-q9qh-872j.json new file mode 100644 index 00000000000..7a08c73b98d --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-wrvq-q9qh-872j/GHSA-wrvq-q9qh-872j.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wrvq-q9qh-872j", + "modified": "2024-12-04T18:32:36Z", + "published": "2024-12-04T18:32:36Z", + "aliases": [ + "CVE-2024-37574" + ], + "details": "The GriceMobile com.grice.call application 4.5.2 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.iui.mobile.presentation.MobileActivity.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37574" + }, + { + "type": "WEB", + "url": "https://github.com/actuator/com.grice.call" + }, + { + "type": "WEB", + "url": "https://github.com/actuator/com.grice.call/blob/main/CVE-2024-37574" + }, + { + "type": "WEB", + "url": "https://play.google.com/store/apps/details?id=com.grice.call" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-04T16:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-x8p8-5wfj-x896/GHSA-x8p8-5wfj-x896.json b/advisories/unreviewed/2024/12/GHSA-x8p8-5wfj-x896/GHSA-x8p8-5wfj-x896.json new file mode 100644 index 00000000000..0467e67fa51 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-x8p8-5wfj-x896/GHSA-x8p8-5wfj-x896.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x8p8-5wfj-x896", + "modified": "2024-12-04T18:32:36Z", + "published": "2024-12-04T18:32:36Z", + "aliases": [ + "CVE-2024-12151" + ], + "details": "Incorrect permission assignment in the user migration feature in Devolutions Server 2024.3.8.0 and earlier allows users to retain their old permission sets.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12151" + }, + { + "type": "WEB", + "url": "https://devolutions.net/security/advisories/DEVO-2024-0017" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-732" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-04T18:15:12Z" + } +} \ No newline at end of file