diff --git a/advisories/unreviewed/2023/05/GHSA-3rm8-425f-x7q5/GHSA-3rm8-425f-x7q5.json b/advisories/unreviewed/2023/05/GHSA-3rm8-425f-x7q5/GHSA-3rm8-425f-x7q5.json new file mode 100644 index 00000000000..8c36190a40f --- /dev/null +++ b/advisories/unreviewed/2023/05/GHSA-3rm8-425f-x7q5/GHSA-3rm8-425f-x7q5.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3rm8-425f-x7q5", + "modified": "2023-05-03T00:30:50Z", + "published": "2023-05-03T00:30:50Z", + "aliases": [ + "CVE-2023-2468" + ], + "details": "Inappropriate implementation in PictureInPicture in Google Chrome prior to 113.0.5672.63 allowed a remote attacker who had compromised the renderer process to obfuscate the security UI via a crafted HTML page. (Chromium security severity: Low)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2468" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2023/05/stable-channel-update-for-desktop.html" + }, + { + "type": "WEB", + "url": "https://crbug.com/1416380" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/05/GHSA-424v-hqh5-m4mw/GHSA-424v-hqh5-m4mw.json b/advisories/unreviewed/2023/05/GHSA-424v-hqh5-m4mw/GHSA-424v-hqh5-m4mw.json new file mode 100644 index 00000000000..5df1ef9831b --- /dev/null +++ b/advisories/unreviewed/2023/05/GHSA-424v-hqh5-m4mw/GHSA-424v-hqh5-m4mw.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-424v-hqh5-m4mw", + "modified": "2023-05-03T00:30:50Z", + "published": "2023-05-03T00:30:50Z", + "aliases": [ + "CVE-2023-2464" + ], + "details": "Inappropriate implementation in PictureInPicture in Google Chrome prior to 113.0.5672.63 allowed an attacker who convinced a user to install a malicious extension to perform an origin spoof in the security UI via a crafted HTML page. (Chromium security severity: Medium)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2464" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2023/05/stable-channel-update-for-desktop.html" + }, + { + "type": "WEB", + "url": "https://crbug.com/1418549" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/05/GHSA-47c7-cvw8-8xg6/GHSA-47c7-cvw8-8xg6.json b/advisories/unreviewed/2023/05/GHSA-47c7-cvw8-8xg6/GHSA-47c7-cvw8-8xg6.json new file mode 100644 index 00000000000..7873e526364 --- /dev/null +++ b/advisories/unreviewed/2023/05/GHSA-47c7-cvw8-8xg6/GHSA-47c7-cvw8-8xg6.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-47c7-cvw8-8xg6", + "modified": "2023-05-03T00:30:50Z", + "published": "2023-05-03T00:30:50Z", + "aliases": [ + "CVE-2023-2466" + ], + "details": "Inappropriate implementation in Prompts in Google Chrome prior to 113.0.5672.63 allowed a remote attacker to spoof the contents of the security UI via a crafted HTML page. (Chromium security severity: Low)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2466" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2023/05/stable-channel-update-for-desktop.html" + }, + { + "type": "WEB", + "url": "https://crbug.com/1385714" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/05/GHSA-4rf6-pvq6-2g27/GHSA-4rf6-pvq6-2g27.json b/advisories/unreviewed/2023/05/GHSA-4rf6-pvq6-2g27/GHSA-4rf6-pvq6-2g27.json new file mode 100644 index 00000000000..3b9942a35fc --- /dev/null +++ b/advisories/unreviewed/2023/05/GHSA-4rf6-pvq6-2g27/GHSA-4rf6-pvq6-2g27.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4rf6-pvq6-2g27", + "modified": "2023-05-03T00:30:50Z", + "published": "2023-05-03T00:30:50Z", + "aliases": [ + "CVE-2023-2465" + ], + "details": "Inappropriate implementation in CORS in Google Chrome prior to 113.0.5672.63 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2465" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2023/05/stable-channel-update-for-desktop.html" + }, + { + "type": "WEB", + "url": "https://crbug.com/1399862" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/05/GHSA-6cmv-m333-v5r3/GHSA-6cmv-m333-v5r3.json b/advisories/unreviewed/2023/05/GHSA-6cmv-m333-v5r3/GHSA-6cmv-m333-v5r3.json new file mode 100644 index 00000000000..072fb83cb9c --- /dev/null +++ b/advisories/unreviewed/2023/05/GHSA-6cmv-m333-v5r3/GHSA-6cmv-m333-v5r3.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6cmv-m333-v5r3", + "modified": "2023-05-03T00:30:49Z", + "published": "2023-05-03T00:30:49Z", + "aliases": [ + "CVE-2023-2461" + ], + "details": "Use after free in OS Inputs in Google Chrome on ChromeOS prior to 113.0.5672.63 allowed a remote attacker who convinced a user to enage in specific UI interaction to potentially exploit heap corruption via crafted UI interaction. (Chromium security severity: Medium)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2461" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2023/05/stable-channel-update-for-desktop.html" + }, + { + "type": "WEB", + "url": "https://crbug.com/1350561" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/05/GHSA-8wr4-8458-346q/GHSA-8wr4-8458-346q.json b/advisories/unreviewed/2023/05/GHSA-8wr4-8458-346q/GHSA-8wr4-8458-346q.json new file mode 100644 index 00000000000..118249bdadf --- /dev/null +++ b/advisories/unreviewed/2023/05/GHSA-8wr4-8458-346q/GHSA-8wr4-8458-346q.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8wr4-8458-346q", + "modified": "2023-05-03T00:30:50Z", + "published": "2023-05-03T00:30:50Z", + "aliases": [ + "CVE-2023-2467" + ], + "details": "Inappropriate implementation in Prompts in Google Chrome on Android prior to 113.0.5672.63 allowed a remote attacker to bypass permissions restrictions via a crafted HTML page. (Chromium security severity: Low)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2467" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2023/05/stable-channel-update-for-desktop.html" + }, + { + "type": "WEB", + "url": "https://crbug.com/1413586" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/05/GHSA-cxc2-7h6p-cw24/GHSA-cxc2-7h6p-cw24.json b/advisories/unreviewed/2023/05/GHSA-cxc2-7h6p-cw24/GHSA-cxc2-7h6p-cw24.json new file mode 100644 index 00000000000..c9e4cfa029e --- /dev/null +++ b/advisories/unreviewed/2023/05/GHSA-cxc2-7h6p-cw24/GHSA-cxc2-7h6p-cw24.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cxc2-7h6p-cw24", + "modified": "2023-05-03T00:30:50Z", + "published": "2023-05-03T00:30:50Z", + "aliases": [ + "CVE-2023-2463" + ], + "details": "Inappropriate implementation in Full Screen Mode in Google Chrome on Android prior to 113.0.5672.63 allowed a remote attacker to hide the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2463" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2023/05/stable-channel-update-for-desktop.html" + }, + { + "type": "WEB", + "url": "https://crbug.com/1406120" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/05/GHSA-f7q6-9j7x-vrpp/GHSA-f7q6-9j7x-vrpp.json b/advisories/unreviewed/2023/05/GHSA-f7q6-9j7x-vrpp/GHSA-f7q6-9j7x-vrpp.json new file mode 100644 index 00000000000..201b0b412c3 --- /dev/null +++ b/advisories/unreviewed/2023/05/GHSA-f7q6-9j7x-vrpp/GHSA-f7q6-9j7x-vrpp.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f7q6-9j7x-vrpp", + "modified": "2023-05-03T00:30:49Z", + "published": "2023-05-03T00:30:49Z", + "aliases": [ + "CVE-2023-2459" + ], + "details": "Inappropriate implementation in Prompts in Google Chrome prior to 113.0.5672.63 allowed a remote attacker to bypass permission restrictions via a crafted HTML page. (Chromium security severity: Medium)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2459" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2023/05/stable-channel-update-for-desktop.html" + }, + { + "type": "WEB", + "url": "https://crbug.com/1423304" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/05/GHSA-hvcr-qmgp-4wp3/GHSA-hvcr-qmgp-4wp3.json b/advisories/unreviewed/2023/05/GHSA-hvcr-qmgp-4wp3/GHSA-hvcr-qmgp-4wp3.json new file mode 100644 index 00000000000..f13c410cbbb --- /dev/null +++ b/advisories/unreviewed/2023/05/GHSA-hvcr-qmgp-4wp3/GHSA-hvcr-qmgp-4wp3.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hvcr-qmgp-4wp3", + "modified": "2023-05-03T00:30:49Z", + "published": "2023-05-03T00:30:49Z", + "aliases": [ + "CVE-2023-2460" + ], + "details": "Insufficient validation of untrusted input in Extensions in Google Chrome prior to 113.0.5672.63 allowed an attacker who convinced a user to install a malicious extension to bypass file access checks via a crafted HTML page. (Chromium security severity: Medium)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2460" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2023/05/stable-channel-update-for-desktop.html" + }, + { + "type": "WEB", + "url": "https://crbug.com/1419732" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/05/GHSA-j438-r4pg-w4g3/GHSA-j438-r4pg-w4g3.json b/advisories/unreviewed/2023/05/GHSA-j438-r4pg-w4g3/GHSA-j438-r4pg-w4g3.json new file mode 100644 index 00000000000..59db6bbed8b --- /dev/null +++ b/advisories/unreviewed/2023/05/GHSA-j438-r4pg-w4g3/GHSA-j438-r4pg-w4g3.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j438-r4pg-w4g3", + "modified": "2023-05-03T00:30:50Z", + "published": "2023-05-03T00:30:50Z", + "aliases": [ + "CVE-2023-2462" + ], + "details": "Inappropriate implementation in Prompts in Google Chrome prior to 113.0.5672.63 allowed a remote attacker to obfuscate main origin data via a crafted HTML page. (Chromium security severity: Medium)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2462" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2023/05/stable-channel-update-for-desktop.html" + }, + { + "type": "WEB", + "url": "https://crbug.com/1375133" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file