Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2024-02-01 06:32:26 +00:00
parent 9369de1351
commit 5fb047d072
28 changed files with 213 additions and 62 deletions
@@ -317,6 +317,10 @@
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2024/01/31/6"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2024/02/01/1"
},
{
"type": "WEB",
"url": "http://www.securityfocus.com/bid/106976"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2fpf-9qrw-vj6r",
"modified": "2024-01-27T00:31:23Z",
"modified": "2024-02-01T06:31:04Z",
"published": "2024-01-27T00:31:23Z",
"aliases": [
"CVE-2024-23506"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-33f3-88p6-j3f9",
"modified": "2024-01-30T15:30:22Z",
"modified": "2024-02-01T06:31:05Z",
"published": "2024-01-30T15:30:22Z",
"aliases": [
"CVE-2024-24324"
],
"details": "TOTOLINK A8000RU v7.1cu.643_B20200521 was discovered to contain a hardcoded password for root stored in /etc/shadow.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-798"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-30T15:15:09Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3qmj-w5mh-5gv3",
"modified": "2024-01-30T15:30:23Z",
"modified": "2024-02-01T06:31:05Z",
"published": "2024-01-30T15:30:23Z",
"aliases": [
"CVE-2024-24329"
],
"details": "TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setPortForwardRules function.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-78"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-30T15:15:09Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3qxr-cm3w-hpmq",
"modified": "2024-01-27T06:30:23Z",
"modified": "2024-02-01T06:31:04Z",
"published": "2024-01-27T06:30:23Z",
"aliases": [
"CVE-2024-0618"
@@ -36,7 +36,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4q7q-5p3p-5fcj",
"modified": "2024-01-30T15:30:23Z",
"modified": "2024-02-01T06:31:05Z",
"published": "2024-01-30T15:30:23Z",
"aliases": [
"CVE-2024-24328"
],
"details": "TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setMacFilterRules function.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-78"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-30T15:15:09Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4q9c-68c7-fxff",
"modified": "2024-01-30T15:30:23Z",
"modified": "2024-02-01T06:31:05Z",
"published": "2024-01-30T15:30:23Z",
"aliases": [
"CVE-2024-24327"
],
"details": "TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the pppoePass parameter in the setIpv6Cfg function.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-78"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-30T15:15:09Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7j85-cwr3-f2w3",
"modified": "2024-01-30T15:30:23Z",
"modified": "2024-02-01T06:31:05Z",
"published": "2024-01-30T15:30:23Z",
"aliases": [
"CVE-2024-24332"
],
"details": "TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the url parameter in the setUrlFilterRules function.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-78"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-30T15:15:09Z"
@@ -32,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9mx6-23q4-mcch",
"modified": "2024-01-27T00:31:23Z",
"modified": "2024-02-01T06:31:04Z",
"published": "2024-01-27T00:31:23Z",
"aliases": [
"CVE-2023-52187"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c2jp-pq2c-g7jh",
"modified": "2024-01-27T06:30:23Z",
"modified": "2024-02-01T06:31:04Z",
"published": "2024-01-27T06:30:23Z",
"aliases": [
"CVE-2023-48202"
],
"details": "Cross-Site Scripting (XSS) vulnerability in Sunlight CMS 8.0.1 allows an authenticated low-privileged user to escalate privileges via a crafted SVG file in the File Manager component.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-27T06:15:47Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cmmq-7g27-wvv8",
"modified": "2024-01-27T06:30:23Z",
"modified": "2024-02-01T06:31:04Z",
"published": "2024-01-27T06:30:23Z",
"aliases": [
"CVE-2024-0697"
@@ -32,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-22"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -32,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g2f8-pfg4-3w3q",
"modified": "2024-01-30T15:30:23Z",
"modified": "2024-02-01T06:31:05Z",
"published": "2024-01-30T15:30:23Z",
"aliases": [
"CVE-2024-24331"
],
"details": "TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setWiFiScheduleCfg function.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-78"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-30T15:15:09Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g5jr-34r4-rv4w",
"modified": "2024-01-29T18:31:48Z",
"modified": "2024-02-01T06:31:04Z",
"published": "2024-01-27T03:30:21Z",
"aliases": [
"CVE-2023-6482"
@@ -28,7 +28,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-321"
"CWE-321",
"CWE-798"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h56c-gcxc-4q77",
"modified": "2024-01-30T15:30:23Z",
"modified": "2024-02-01T06:31:05Z",
"published": "2024-01-30T15:30:23Z",
"aliases": [
"CVE-2024-24333"
],
"details": "TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the desc parameter in the setWiFiAclRules function.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-78"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-30T15:15:09Z"
@@ -29,6 +29,14 @@
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2254396"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/D2FIH77VHY3KCRROCXOT6L27WMZXSJ2G/"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MWQ6BZJ6CV5UAW4VZSKJ6TO4KIW2KWAQ/"
},
{
"type": "WEB",
"url": "https://www.openwall.com/lists/oss-security/2024/01/30/6"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jm98-mxmf-qcjw",
"modified": "2024-01-30T15:30:23Z",
"modified": "2024-02-01T06:31:05Z",
"published": "2024-01-30T15:30:23Z",
"aliases": [
"CVE-2024-24330"
],
"details": "TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the port or enable parameter in the setRemoteCfg function.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-78"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-30T15:15:09Z"
@@ -29,6 +29,14 @@
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2254395"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/D2FIH77VHY3KCRROCXOT6L27WMZXSJ2G/"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MWQ6BZJ6CV5UAW4VZSKJ6TO4KIW2KWAQ/"
},
{
"type": "WEB",
"url": "https://www.openwall.com/lists/oss-security/2024/01/30/6"
@@ -29,6 +29,14 @@
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2249053"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/D2FIH77VHY3KCRROCXOT6L27WMZXSJ2G/"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MWQ6BZJ6CV5UAW4VZSKJ6TO4KIW2KWAQ/"
},
{
"type": "WEB",
"url": "https://www.openwall.com/lists/oss-security/2024/01/30/6"

Some files were not shown because too many files have changed in this diff Show More